[strongSwan] parsed ID_PROT response 0 [ KE No ]

Andreas Steffen andreas.steffen at strongswan.org
Tue Aug 2 15:14:46 CEST 2016

actually if OPENSSL_NO_ECDH is set during the OpenSSL library build
then the ECC DH groups should not be available to the openssl plugin:


What OpenSSL version are you using (openssl version)?


On 08/02/2016 03:06 PM, Andreas Steffen wrote:
> Hi Lakshmi,
> it seems that your OpenSSL libcrypto library has not been built with
> ECC (Elliptic Curve Cryptography) support.
> Regards
> Andreas
> On 08/02/2016 02:27 PM, Lakshmi Prasanna wrote:
>> Hi Andreas,
>> Glad, that "  ipsec start --nofork" helped. 
>> I see that the charon crashed with the following error: 
>> */usr/libexec/ipsec/charon: symbol lookup error:
>> /usr/lib/ipsec/plugins/libstrongswan-openssl.so: undefined symbol:
>> EC_POINT_is_on_curve*
>> *charon has died -- restart scheduled (5sec)*
>> Even though openssl is shown as part of the loaded configs, this error
>> seems to get hit. Is there anything that I am possibly missing whike
>> compiling?
>> -Lakshmi

Andreas Steffen                         andreas.steffen at strongswan.org
strongSwan - the Open Source VPN Solution!          www.strongswan.org
Institute for Internet Technologies and Applications
University of Applied Sciences Rapperswil
CH-8640 Rapperswil (Switzerland)

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4275 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://lists.strongswan.org/pipermail/users/attachments/20160802/4b20796d/attachment-0001.bin>

More information about the Users mailing list