Hi Harri, > I had hoped that putting the whole chain into /etc/ipsec.d/certs/mycert.pem > would help, but apparently it doesn't. strongSwan reads only the first certificate from PEM encoded files. So put them in separate files. Regards, Tobias