[strongSwan] question regarding using smart card authentication with IKEv1

Andreas Steffen andreas.steffen at strongswan.org
Tue Mar 6 13:15:22 CET 2012

Hello Ana,

yes, you can load any third party PKCS#11 dynamic library using
the pkcs11module parameter in the config setup section of ipsec.conf.
Excerpt from the ipsec.conf man page:

  pkcs11module = <lib>

  defines the path during run-time to a dynamically loadable PKCS#11
  library. Overrides any path defined during compile-time using the
  --pkcs11-module configure option.

Kind Regards


On 06.03.2012 11:57, Ana Andjelic wrote:
> Hi everybody,
> I just want to know weather it is possible to use other PKCS#11 module
> for interaction with smart cards besides opensc with pluto IKEv1
> roadworrior as VPN client. If yes, what configuration changes are necessary?
> Thanks for your help!
> Ana 

Andreas Steffen                         andreas.steffen at strongswan.org
strongSwan - the Linux VPN Solution!                www.strongswan.org
Institute for Internet Technologies and Applications
University of Applied Sciences Rapperswil
CH-8640 Rapperswil (Switzerland)

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4489 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://lists.strongswan.org/pipermail/users/attachments/20120306/1c0c8910/attachment.bin>

More information about the Users mailing list