Hi, > my workaround is to store all client certificate in aacert directory. If you haven't seen it, a patch bringing PKCS#7 support has been integrated and will be part of 5.0.2. If you want to give it try right now, you can build the developer release at [1]. Regards Martin [1]http://download.strongswan.org/strongswan-5.0.2dr4.tar.bz2