# Copyright 2017 Julien Durillon # Distributed under the terms of the GNU General Public License v2 require systemd-service SUMMARY="IPsec-based VPN solution focused on security and ease of use, supporting IKEv1/IKEv2 and MOBIKE" HOMEPAGE="https://www.strongswan.org/" DOWNLOADS="https://download.strongswan.org/${PNV}.tar.bz2" LICENCES="GPL-2 RSA DES" SLOT="0" PLATFORMS="~amd64" MYOPTIONS=" botan caps constraints [[ description = [ Advanced X509 constraint checking plugin. ] ]] curl [[ description = [ Fetch files via libcurl ] ]] debug dhcp eap [[ description = [ Enable all EAP modules ] ]] farp [[ description = [ ARP faking plugin that responds to ARP requests to peers virtual IP ] ]] gcrypt gmp kernel-libipsec [[ description = [ User space IPsec implementation. ] ]] kernel-pfkey [[ description = [ PF_KEY kernel interface ] ]] ldap [[ description = [ Fetch files via libldap ] ]] mysql mysql? ( ( providers: mariadb percona ) [[ *description = [ mysql database provider ] number-selected = exactly-one ]] ) networkmanager pam pkcs11 sqlite stroke [[ description = [ Legacy stroke configuration backend (ipsec.conf, ipsec command) ] ]] systemd ( plugins: blowfish ccm [[ description = [ CCM Authenticated Encryption with Associated Data wrapper plugin ] ]] ctr [[ description = [ Counter mode wrapper plugin ] ]] gcm ha [[ description = [ High availability cluster plugin ] ]] ipseckey [[ description = [ IPSECKEY authentication plugin ] ]] led [[ description = [ Control LEDs on IKEv2 activity using the kernel LED subsystem ] ]] lookip [[ description = [ Fast virtual IP lookup and notification plugin ] ]] ml [[ description = [ Module-Lattice-based (ML-KEM) post-quantum key exchange plugin ] ]] padlock [[ description = [ VIA Padlock crypto plugin ] ]] rdrand [[ description = [ Intel RDRAND random generator plugin ] ]] systime-fix [[ description = [ Handle cert lifetimes with invalid system time gracefully ] ]] unity [[ description = [ Cisco Unity extension plugin ] ]] whitelist ) ( providers: libressl openssl ) [[ number-selected = exactly-one ]] " DEPENDENCIES=" build+run: !net-misc/openswan sys-kernel/linux-headers sys-libs/pam botan? ( dev-libs/botan:= ) caps? ( sys-libs/libcap ) curl? ( net-misc/curl ) gcrypt? ( dev-libs/libgcrypt:0 ) gmp? ( dev-libs/gmp:=[>=4.1.5] ) ldap? ( net-directory/openldap ) mysql? ( providers:mariadb? ( dev-db/mariadb ) providers:percona? ( dev-db/Percona-Server:= ) ) networkmanager? ( net-apps/NetworkManager ) providers:libressl? ( dev-libs/libressl:= ) providers:openssl? ( dev-libs/openssl:= ) sqlite? ( dev-db/sqlite:3[>=3.3.1] ) systemd? ( sys-apps/systemd ) run: sys-apps/iproute2 group/ipsec " BUGS_TO="julien.durillon@gmail.com" DEFAULT_SRC_CONFIGURE_PARAMS=( --enable-chapoly --enable-ikev1 --enable-ikev2 --enable-kernel-netlink --enable-socket-dynamic --enable-swanctl --enable-vici --enable-xauth-pam --disable-cert-enroll --disable-cert-enroll-timer --disable-openxpki --disable-static --with-group=ipsec ) DEFAULT_SRC_CONFIGURE_OPTION_WITHS=( "caps capabilities /usr/$(exhost --target)" "systemd systemdsystemunitdir ${SYSTEMDSYSTEMUNITDIR}" ) DEFAULT_SRC_CONFIGURE_OPTION_ENABLES=( botan constraints curl 'debug leak-detective' dhcp eap 'eap eap-gtc' 'eap eap-sim' 'eap eap-sim-file' 'eap eap-simaka-sql' 'eap eap-simaka-pseudonym' 'eap eap-simaka-reauth' 'eap eap-identity' 'eap eap-md5' 'eap eap-aka' 'eap eap-aka-3gpp2' 'eap fips-prf' 'eap md4' 'eap eap-mschapv2' 'eap eap-radius' 'eap eap-tls' 'eap xauth-eap' farp gcrypt gmp kernel-libipsec kernel-pfkey ldap mysql 'mysql attr-sql' 'mysql sql' 'networkmanager nm' pkcs11 sqlite 'sqlite attr-sql' 'sqlite sql' stroke systemd plugins:led plugins:lookip plugins:systime-fix plugins:unity plugins:blowfish plugins:ccm plugins:ctr plugins:gcm plugins:ha plugins:ipseckey plugins:ml plugins:padlock plugins:rdrand plugins:whitelist providers:openssl 'providers:libressl openssl' ) src_install() { default edo find "${IMAGE}"/usr/$(exhost --target) -name '*.la' -delete if option stroke ; then keepdir /etc/ipsec.d/{aacerts,acerts,cacerts,certs,crls,ocspcerts,private,reqs} fi keepdir /etc/swanctl/{conf.d,ecdsa,pkcs12,pkcs8,private,pubkey,rsa,x509,x509aa,x509ac,x509ca,x509crl,x509ocsp} }