Libreswan Documentation

Logo

Libreswan's Online Documentation

View the Project on GitHub libreswan/libreswan.github.io

Support
FAQ Common Error Messages
History
Implemented Standards
Kernel Support
HOWTO Additional ipsec.conf documentation
AWS Mesh
brendans Road Warrior Setup at Home
Configuration examples
Confuse !?@: github wiki
Enterprise cloud encryption
Entropy matters
EoIP shared ethernet LAN using IPsec
High Availability Fallover VPN in AWS
Host to host VPN
Host to host VPN with PSK
Libreswan as client to a Cisco ASA or VPN3000 server
Microsoft Azure configuration
Migrate from IKEv1 DPD to IKEv2 LIVENESS
Opportunistic IPsec
Opportunistic IPsec using LetsEncrypt
Pluto and DNSSEC
Read status output
Route based VPN
SElinux and Labeled IPsec VPN
Subnet extrusion
Subnet to subnet using NAT
Subnet to subnet VPN
Subnet to subnet VPN with PSK
Unauthenticated Opportunistic IPsec
Using Apache to serve PKCS
Using NSS Hardware Tokens
Using NSS with libreswan
VPN server for remote clients using IKEv2
VPN server for remote clients using IKEv2 split VPN
GSoC 2027 Code Project Ideas DRAFT
Contributor Guidance DRAFT
Completed Projects 2026 RFC 9593 Announcing Supported Authentication Methods in IKEv2
2026 Improve the ACQUIRE to IKE policy lookup
2026 Add HOST TO HOST Support on BSD
2021 RFC 8420 Add EdDSA Signature Authentication Support to IKEv2
2020 Session Resumption
2020 IKEv2 Interop testing with OpenBSD
2020 IKE Intermediate Exchange
2019 Libreswan Opportunistic IPsec using LetsEncrypt
2018 RSA PSS Support in compliance with RFC 7427 and RFC 8247
2018 RFC 7427 Add ECDSA Signature Authentication Support to IKEv2
2018 RFC 5685 Redirect Mechanism
2018 Managing Interface
2017 TCP encapsulation of IKE and IPsec
2017 RFC 7427 Add Signature Authentication Support to IKEv2
2017 Postquantum Preshared Keys
Presentations
IRC
Hacking Documentation
Git, GitHub, and Pull Requests
Merging GitHub Pull Requests
Programming Conventions
Testing Docker
KVM 1. Setup The Host
2. Configure Testing
3. Compile Libreswan
4. Test Libreswan
5. Accessing The Console
6. Maintenance and Internals
Bisecting
Debugging Pluto
Logging In Using SSH
Performance
Running A Custom Kernel
Running A Single Test
Running In The Background
Setup a Web Server
Testing Old Branches
Updating Test Results
Namespace Magic
Namespaces
Topology
Internals 3.14 X509
Benchmarking and Performance testing
Cipher suites and algorithm support
Cloud OE ideas
Compiling with AddressSanitizer
Compliance of RFC 7427 Signature Authentication in IKEv2
Coverity
Cryptographic Acceleration
Developer links strongswan android
Discouraged or forbidden C functions
IKEv2 Child SA
IKEv2 CP and EAP support
Introduction
Libreswan xfrm kernel support
Logging cleanup
New OE
Pluto
Pluto packet processing
Proposed ipsec ca command
Retransmit timings
Road Map
SAref code
Setting up system for debug logging
stf status
Testing 2017 Next Generation
Unbound
Uncrustify
Use Cases and Requirements document for ECC ECDSA support
Use Cases and Requirements document
XFRM Interface Development Notes
XFRM pCPU
XFRM pCPU RSS
Security Crypto boundary and certification
Libreswan and Heartbleed
Libreswan and TunnelCrack
Reporting a Vulnerability
Vulnerabilities
Meetups 2013 Helsinki
2014 San Francisco
2014 Toronto
2018 Toronto
Obsolete HOWTOs IKEv1 XAUTH with FreeOTP and FreeIPA
IKEv1 XAUTH with Google Authenticator One Time Passwords
Route based VPN using VTI
Testing Namespace
VPN server for remote clients using IKEv1 with L2TP
VPN server for remote clients using IKEv1 XAUTH with Certificates
VPN server for remote clients using IKEv1 XAUTH with PSK

The following tables list the RFCs, drafts and standards related to IKE and IPsec.

An overview of IKE and IPsec related RFC’s is available in RFC 6071.

Implementation status can be:

Status Description
vN.N first implementation, see comments for limitations
in-progress by who, and date of last time this file was updated
yes-please very high on our wish list, interested?
N/A not applicable
X not really interested

Current and Proposed IP Security Maintenance and Extensions Working Group (IPSECME) RFCs

IPSECME Internet-Drafts Active with the IESG

I.e., about to be adopted, likely in last call.

This table should track the “Active with the IESG Internet-Drafts” section of the IPSECME documents page.

Standard Area Description Status Comments
RFC TBD IKE Downgrade Prevention for the Internet Key Exchange Protocol Version 2 (IKEv2) in-progress Vinnu124
2026-05-29, In Last Call (ends 2026-06-12)
RFC TBD IKE Signature Authentication in the Internet Key Exchange Version 2 (IKEv2) using PQC in-progress Sahana
2026-04-14, Publication Requested
RFC TBD IKE Post-quantum Key Exchange with ML-KEM in the Internet Key Exchange Protocol Version 2 (IKEv2) v5.4 2026-03-15, In Last Call (ends 2026-06-15)

This table is a sorted merge of two tables.

This table should track the “RFCs” and “Related RFCs” sections of the IPSECME documents page.

Standard Area Description Status Comments  
RFC 9867 IKE Mixing Preshared Keys in the IKE_INTERMEDIATE and CREATE_CHILD_SA Exchanges of the Internet Key Exchange Protocol Version 2 (IKEv2) for Post-Quantum Security v5.2 IKE_INTERMEDIATE: v5.2
CREATE_CHILD_SA: to-be-done
 
RFC 9838 IKE Group Key Management Using the Internet Key Exchange Protocol Version 2 (IKEv2)      
RFC 9827 IKE Renaming the Extended Sequence Numbers (ESN) Transform Type in the Internet Key Exchange Protocol Version 2 (IKEv2) v5.4    
RFC 9611 IKE Internet Key Exchange Protocol Version 2 (IKEv2) Support for Per-Resource Child Security Associations (SAs) in-progress omoris  
RFC 9593 IKE Announcing Supported Authentication Methods in the Internet Key Exchange Protocol Version 2 (IKEv2) in-progress fazzel vukasink  
RFC 9478 IKE Labeled IPsec Traffic Selector Support for the Internet Key Exchange Protocol Version 2 (IKEv2) v4.4    
RFC 9464 IKE Internet Key Exchange Protocol Version 2 (IKEv2) Configuration for Encrypted DNS      
RFC 9395 IKE Deprecation of the Internet Key Exchange Version 1 (IKEv1) Protocol and Obsoleted Algorithms      
RFC 9370 IKE Multiple Key Exchanges in the Internet Key Exchange Protocol Version 2 (IKEv2) v5.4
in-progress
addke1: v5.4
IKE_INTERMEDIATE: v4.0
IKE_FOLLOW_UP_KE (IKE): v5.4
IKE_FOLLOW_UP_KE (Child): daiki
 
RFC 9349 IKE Definitions of Managed Objects for IP Traffic Flow Security      
RFC 9348 IKE A YANG Data Model for IP Traffic Flow Security      
RFC 9347 IKE Aggregation and Fragmentation Mode for Encapsulating Security Payload (ESP) and Its Use for IP Traffic Flow Security (IP-TFS) v5.2    
RFC 9329 IKE TCP Encapsulation of Internet Key Exchange Protocol (IKE) and IPsec Packets v4.0   Updated RFC 8229?
RFC 9242 IKE Intermediate Exchange in the Internet Key Exchange Protocol Version 2 (IKEv2) v4.0    
RFC 9227 IKE Using GOST Ciphers in the Encapsulating Security Payload (ESP) and Internet Key Exchange Version 2 (IKEv2) Protocols      
RFC 8983 IKE Internet Key Exchange Protocol Version 2 (IKEv2) Notification Status Types for IPv4/IPv6 Coexistence      
RFC 8784 IKE Mixing Preshared Keys in the Internet Key Exchange Protocol Version 2 (IKEv2) for Post-quantum Security v3.28    
RFC 8750 IKE Implicit Initialization Vector (IV) for Counter-Based Ciphers in Encapsulating Security Payload (ESP)      
RFC 8598 IKE Split DNS Configuration for the Internet Key Exchange Protocol Version 2 (IKEv2)      
RFC 8420 IKE Using the Edwards-Curve Digital Signature Algorithm (EdDSA) in the Internet Key Exchange Protocol Version 2 (IKEv2) v5.4 Limited by NSS  
RFC 8247 IKE Algorithm Implementation Requirements and Usage Guidance for the Internet Key Exchange Protocol Version 2 (IKEv2)      
RFC 8229 IKE TCP Encapsulation of IKE and IPsec Packets v4.0 Updated by RFC 9329  
RFC 8221 IPsec Cryptographic Algorithm Implementation Requirements and Usage Guidance for Encapsulating Security Payload (ESP) and Authentication Header (AH)      
RFC 8031 IKE Curve25519 and Curve448 for the Internet Key Exchange Protocol Version 2 (IKEv2) Key Agreement v3.25 Curve25519 (dh31): v3.25
Curve448 (dh32): Needs NSS support
 
RFC 8019 IKE Protecting Internet Key Exchange Protocol Version 2 (IKEv2) Implementations from Distributed Denial-of-Service Attacks      
RFC 7791 IKE Cloning the IKE Security Association in the Internet Key Exchange Protocol Version 2 (IKEv2)      
RFC 7634 IKE “ChaCha20, Poly1305, and Their Use in the Internet Key Exchange Protocol (IKE) and IPsec” v3.26    
RFC 7619 IKE The NULL Authentication Method in the Internet Key Exchange Protocol Version 2 (IKEv2) v2.x    
RFC 7427 IKE Signature Authentication in the Internet Key Exchange Version 2 (IKEv2) v3.26 aka DIGSIG  
RFC 7383 IKE Internet Key Exchange Protocol Version 2 (IKEv2) Message Fragmentation v3.14    
RFC 7321 IPsec Cryptographic Algorithm Implementation Requirements and Usage Guidance for Encapsulating Security Payload (ESP) and Authentication Header (AH)      
RFC 7296 IKE Internet Key Exchange Protocol Version 2 (IKEv2) yes    
RFC 7018 IPsec Auto-Discovery VPN Problem Statement and Requirements      
RFC 6989 IKE Additional Diffie-Hellman Tests for the Internet Key Exchange Protocol Version 2 (IKEv2) N/A    
RFC 6867 IKE An Internet Key Exchange Protocol Version 2 (IKEv2) Extension to Support EAP Re-authentication Protocol (ERP)      
RFC 6631 IKE Password Authenticated Connection Establishment with the Internet Key Exchange Protocol version 2 (IKEv2)      
RFC 6628 IKE Efficient Augmented Password-Only Authentication and Key Exchange for IKEv2      
RFC 6617 IKE Secure Pre-Shared Key (PSK) Authentication for the Internet Key Exchange Protocol (IKE)      
RFC 6479 IPsec IPsec Anti-Replay Algorithm without Bit Shifting N/A kernel  
RFC 6467 IKE Secure Password Framework for Internet Key Exchange Version 2 (IKEv2)      
RFC 6380 IPsec Suite B Profile for Internet Protocol Security (IPsec) v    
RFC 6379 IPsec Suite B Cryptographic Suites for IPsec v Not all ciphers are implemented  
RFC 6311 IKE Protocol Support for High Availability of IKEv2/IPsec      
RFC 6290 IKE A Quick Crash Detection Method for the Internet Key Exchange Protocol (IKE)      
RFC 6071 IKE IP Security (IPsec) and Internet Key Exchange (IKE) Document Roadmap      
RFC 6027 IKE IPsec Cluster Problem Statement      
RFC 6023 IKE A Childless Initiation of the Internet Key Exchange Version 2 (IKEv2) Security Association (SA)      
RFC 5998 IKE An Extension for EAP-Only Authentication in IKEv2 v4.7 server only  
RFC 5996 IKE Internet Key Exchange Protocol Version 2 (IKEv2)   Obsolete, see RFC 7296  
RFC 5930 IKE Using Advanced Encryption Standard Counter Mode (AES-CTR) with the Internet Key Exchange version 02 (IKEv2) Protocol v3.14    
RFC 5903 IKE Elliptic Curve Groups modulo a Prime (ECP Groups) for IKE and IKEv2 v3.20 added to defaults in v3.28  
RFC 5879 IPsec Heuristics for Detecting ESP-NULL Packets N/A kernel  
RFC 5857 IKE IKEv2 Extensions to Support Robust Header Compression over IPsec      
RFC 5840 IPsec Wrapped Encapsulating Security Payload (ESP) for Traffic Visibility X    
RFC 5739 IKE IPv6 Configuration in Internet Key Exchange Protocol Version 2 (IKEv2)      
RFC 5723 IKE Internet Key Exchange Protocol Version 2 (IKEv2) Session Resumption v5.2    
RFC 5685 IKE Redirect Mechanism for the Internet Key Exchange Protocol Version 2 (IKEv2) v3.28    
RFC 5660 IPsec IPsec Channels: Connection Latching X    
RFC 5529 IPsec Modes of Operation for Camellia for Use with IPsec v3.11    
RFC 5282 IKE Using Authenticated Encryption Algorithms with the Encrypted Payload of the Internet Key Exchange version 2 (IKEv2) Protocol v3.7    
RFC 5114 IPsec Additional Diffie-Hellman Groups for Use with IETF Standards v3.20 secp256r1 (dh19): v3.20
secp384r1 (dh20): v3.20
secp521r1 (dh21): v3.20
dh22: v2.x
dh23: v2.x
dh24: v2.x
dh25: to-be-done
dh26: to-be-done
 
RFC 4868 IPsec Using HMAC-SHA-256, HMAC-SHA-384, and HMAC-SHA-512 with IPsec v3.14    
RFC 4806 IKE Online Certificate Status Protocol (OCSP) Extensions to IKEv2 v3.19 Uses NSS  
RFC 4754 IKE IKE and IKEv2 Authentication Using the Elliptic Curve Digital Signature Algorithm (ECDSA) v3.28 Discouraged, use SECKEY
still neded by Android and microsoft?
 
RFC 4739 IKE Multiple Authentication Exchanges in the Internet Key Exchange (IKEv2) Protocol      
RFC 4615 IKE The Advanced Encryption Standard-Cipher-based Message Authentication Code-Pseudo-Random Function-128 (AES-CMAC-PRF-128) Algorithm for the Internet Key Exchange Protocol (IKE) v3.25    
RFC 4555 IKE IKEv2 Mobility and Multihoming Protocol (MOBIKE) v3.25 “Additional Addresses” not supported  
RFC 4543 IPsec The Use of Galois Message Authentication Code (GMAC) in IPsec ESP and AH X Kernel support is availble, ike support is not  
RFC 4494 IPsec The AES-CMAC-96 Algorithm and Its Use with IPsec X    
RFC 4478 IKE Repeated Authentication in Internet Key Exchange (IKEv2) Protocol      
RFC 4434 IKE The AES-XCBC-PRF-128 Algorithm for the Internet Key Exchange Protocol (IKE) v3.25    
RFC 4309 IPsec Using Advanced Encryption Standard (AES) CCM Mode with IPsec ESP v3.7    
RFC 4308 IPsec Cryptographic Suites for IPsec      
RFC 4304 IPsec Extended Sequence Number (ESN) Addendum to IPsec DOI for ISAKMP v3.17    
RFC 4303 IPsec IP Encapsulating Security Payload (ESP) v2.x Obsoletes: 2406  
RFC 4302 IPsec IP Authentication Header (AH) v2.x Obsoletes: 2402  
RFC 4301 IPsec Security Architecture for the Internet Protocol v2.x    
RFC 4106 IPsec The Use of Galois/Counter Mode (GCM) in IPsec ESP v3.17    
RFC 3948 IPsec UDP Encapsulation of IPsec ESP Packets v2.x    
RFC 3686 IPsec Using Advanced Encryption Standard (AES) Counter Mode With IPsec Encapsulating Security Payload (ESP) v    
RFC 3602 IPsec The AES-CBC Cipher Algorithm and Its Use with IPsec v2.x    
RFC 3566 IPsec The AES-XCBC-MAC-96 Algorithm and Its Use With IPsec v2.x    
RFC 3526 IKE More Modular Exponential (MODP) Diffie-Hellman groups for Internet Key Exchange (IKE)      
RFC 2451 IPsec The ESP CBC-Mode Cipher Algorithms v2.x    
RFC 2410 IPsec The NULL Encryption Algorithm and Its Use With IPsec v2.x    
RFC 2405 IPsec The ESP DES-CBC Cipher Algorithm With Explicit IV v2.x    
RFC 2404 IPsec The Use of HMAC-SHA-1-96 within ESP and AH v2.x    
RFC 2403 IPsec The Use of HMAC-MD5-96 within ESP and AH v2.x    
RFC 2104 IKE HMAC: Keyed-Hashing for Message Authentication v2.x    

Active IPSECME Internet Drafts

This table should track the “Active Internet-Drafts “ section of the the IPSECME documents page.

Standard Area Description Status Comments
draft IKE IKEv2 negotiation for Bound End-to-End Tunnel (BEET) mode ESP    
draft IKE Separate Transports for IKE and ESP    
draft IPsec Encrypted ESP Echo Protocol    
draft IKE IKEv2 Support for Child SA PFS Policy Information in-progress paul
draft IKE Use of Variable-Length Output Pseudo-Random Functions (PRFs) in the Internet Key Exchange Protocol Version 2 (IKEv2)    
draft IPsec A Bound End-to-End Tunnel (BEET) mode for ESP    
draft IKE Optimized Rekeys in the Internet Key Exchange Protocol Version 2 (IKEv2) in-progress paul
draft IKE Post-quantum Hybrid Key Exchange in IKEv2 with FrodoKEM    
draft IPsec Enhanced Encapsulating Security Payload (EESP)    
draft IKE IKEv2 negotiation for Enhanced Encapsulating Security Payload (EESP)    
draft IPsec ESP Echo Protocol    
draft IPsec ESP Header Compression with Diet-ESP    
draft IKE Internet Key Exchange version 2 (IKEv2) extension for Header Compression Profile (HCP)    
draft IKE Use of SHA-3 in the Internet Key Exchange Protocol Version 2 (IKEv2) and IPsec    

RFCs from Other Working Groups and/or Sponsored by Area Directors

IKEv2 Specific RFCs

Standard Area Description Status Comments
RFC 7815 IKE Minimal Internet Key Exchange Version 2 (IKEv2) Initiator Implementation   This is a really just a subset of RFC 7296: Internet Key Exchange Protocol Version 2 (IKEv2)
RFC 7670 IKE Generic Raw Public-Key Support for IKEv2 v3.26 This defines the material used by RFC 7427: Signature Authentication in the Internet Key Exchange Version 2 (IKEv2)
RFC 7651   3GPP IP Multimedia Subsystems (IMS) Option for the Internet Key Exchange Protocol Version 2 (IKEv2)    
RFC 6954 IKE Using the Elliptic Curve Cryptography (ECC) Brainpool Curves for the Internet Key Exchange Protocol Version 2 (IKEv2)    
RFC 6932   Brainpool Elliptic Curves for the IKE Group Description Registry    

EAP

Standard Area Description Status Comments
RFC 9190 EAP EAP-TLS 1.3: Using the Extensible Authentication Protocol with TLS 1.3 v4.7 server only
RFC 5998 EAP An Extension for EAP-Only Authentication in IKEv2 v4.7 server only
RFC 5216 EAP The EAP-TLS Authentication Protocol v4.7 server only, Updated by RFC 9190
RFC 3748 EAP Extensible Authentication Protocol (EAP)    
RFC 2716 EAP PPP EAP TLS Authentication Protocol   Obsolete, see RFC 5216

Certificates and PKIX

Standard Area Description Status Comments
RFC 4945 PKIX The Internet IP Security PKI Profile of IKEv1/ISAKMP, IKEv2, and PKIX v2.x Changed to NSS in v3.14

PF KEY V2

Standard Area Description Status Comments
RFC 2367 PFKEYv2 PF_KEY Key Management API, Version 2 v4.7 SADB messages to set up kernel state on BSD machines
draft-schilcher-mobike-pfkey-extension-01 PFKEYv2 MOBIKE Extensions for PF_KEY v4.7 also defines KAME’s SPD extensions to set up kernel policy on BSD machine
  PFKEYv2 PF_KEY Extensions for IPsec Policy Management in KAME Stack   Post to KAME mailing list about PF KEY

Cryptography: AEAD, Public Keys (formats, standards, DNS records) …

Standard Area Description Status Comments
RFC 8813   Clarifications for Elliptic Curve Cryptography Subject Public Key Information    
RFC 7468   Textual Encodings of PKIX, PKCS, and CMS Structures v ipsec showhostkey --pem outputs Textual Encoding of Subject Public Key Info
RFC 6605   Elliptic Curve Digital Signature Algorithm (DSA) for DNSSEC   ipsec --ipseckey and ipseckey --{left,right} both dump ECDSA keys using the format described in 4. DNSKEY and RRSIG Resource Records for ECDSA
RFC 5280   Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile   See 4.1.2.7. Subject Public Key Info
RFC 4648   The Base16, Base32, and Base64 Data Encodings v see datatot()
RFC 4034   Resource Records for the DNS Security Extensions    
RFC 4025   A Method for Storing IPsec Keying Material in DNS v ipsec showhostkey --ipseckey outputs the text for an IPSECKEY RR record:
Algorithm 1, DSA: RFC 2536 2. DSA KEY Resource Records
Algorithm 2, RSA: RFC 3110 2. RSA Public KEY Resource Records
Algorithm 3, ECDSA:RFC 6605 4. DNSKEY and RRSIG Resource Records for ECDSA
Algorithm 4 will probably use RFC 5280 4.1.2.7. Subject Public Key Info
RFC 3110   RSA/SHA-1 SIGs and RSA KEYs in the Domain Name System (DNS) v ipsec --ipseckey and ipseckey --{left,right} dump RSA keys using the format described in RFC 3112 2. RSA Public KEY Resource Records
RFC 2536   DSA KEYs and SIGs in the Domain Name System (DNS)   This won’t be implemented.
RFC 1421   Privacy Enhancement for Internet Electronic Mail: Part I: Message Encryption and Authentication Procedures   Origins of PEM format
draft-irtf-cfrg-aead-limits   Usage Limits on AEAD Algorithms   Hopefully answers the question of what limits to place on AEAD.

Obsolete IKEv1 RFCs

Standard Area Description Status Comments
RFC 3947 IKEv1 Negotiation of NAT-Traversal in the IKE v known as “NATT” or “ESPinUDP”
RFC 3706 IKEv1 A Traffic-Based Method of Detecting Dead Internet Key Exchange (IKE) Peers v known as “DPD”; IKEv2’s equivalent is “liveness”
RFC 3526 IKEv1 More Modular Exponential (MODP) Diffie-Hellman groups v  
RFC 2409 IKEv1 Internet Key Exchange (IKE) v Revised Mode not implemented
RFC 2408 IKEv1 Internet Security Association and Key Management Protocol (ISAKMP) v  
RFC 2407 IKEv1 IPsec Domain of Interpretation for ISAKMP (IPsec DoI) v  
draft-dukes-ike-mode-cfg MODECFG The ISAKMP Configuration Method v  
draft-ietf-ipsec-isakmp-xauth XAUTH Extended Authentication within ISAKMP/Oakley (XAUTH) v  
draft-jenkins-ipsec-rekeying IKEv1 IPsec Re-keying Issues v Implementation differs on some point but accomplishes the same
draft-ietf-ipsec-isakmp-hybrid-auth IKEv1 A Hybrid Authentication Mode for IKE X