<feed xmlns='http://www.w3.org/2005/Atom'>
<title>packages/net/strongswan/files/usr/libexec, branch master</title>
<subtitle>Mirror of packages feed</subtitle>
<id>https://git.openwrt.org/feed/packages/atom?h=master</id>
<link rel='self' href='https://git.openwrt.org/feed/packages/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/'/>
<updated>2026-09-30T09:58:51Z</updated>
<entry>
<title>strongswan: rename child local/remote_subnet to local/remote_ts</title>
<updated>2026-09-30T09:58:51Z</updated>
<author>
<name>Florian Eckert</name>
</author>
<published>2026-09-28T11:54:27Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=b2f6de780d82d83f8302a50885d77f62bfa45428'/>
<id>urn:sha1:b2f6de780d82d83f8302a50885d77f62bfa45428</id>
<content type='text'>
The swanctl.conf child options are called local_ts and remote_ts
(traffic selectors), but the UCI config used local_subnet and
remote_subnet for them. Rename the UCI options in the swanctl init
script to match the swanctl.conf naming, so the config maps 1:1 to
what strongSwan actually expects.

Since this changes the UCI option names, existing configurations
would silently lose their traffic selectors after an upgrade. Add
migrate_child_subnet_to_ts() to the ipsec-to-swanctl migration
script. For each child section it moves the values of local_subnet
and remote_subnet into the local_ts and remote_ts lists and removes
the old options.

Signed-off-by: Florian Eckert &lt;fe@dev.tdt.de&gt;
</content>
</entry>
<entry>
<title>strongswan: move local and remote into own uci sections</title>
<updated>2026-09-30T09:58:51Z</updated>
<author>
<name>Florian Eckert</name>
</author>
<published>2026-09-21T14:57:22Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=e5e31986517861006cb8bbf0d2a307d296ac877b'/>
<id>urn:sha1:e5e31986517861006cb8bbf0d2a307d296ac877b</id>
<content type='text'>
The local and remote authentication configuration was stored as flat
options on the connection section. This cannot represent IKEv2 multiple
authentication rounds, where more than one local/remote pair is needed.

Move the options into dedicated 'local' and 'remote' uci sections which
are referenced from the connection via the 'list local' and 'list
remote' options. Multiple sections per connection are now possible and
each pair is emitted as one authentication round.

The generated swanctl.conf names the rounds positionally: the first
local/remote section is emitted as 'local'/'remote', the following ones
as 'local2'/'remote2' and so on.

The 'authentication_method' option moves to the new sections as 'auth'.
The local side of an EAP connection still defaults to pubkey.

The migration script converts an existing connection into one local and
one remote section:

- 'local_identifier'  -&gt; local 'id'
- 'local_cert'        -&gt; local 'certs'
- 'local_key'         -&gt; local 'key'
- 'remote_identifier' -&gt; remote 'id'
- 'remote_ca_certs'   -&gt; remote 'cacerts' (list)
- 'eap_id'            -&gt; remote 'eap_id'

Signed-off-by: Florian Eckert &lt;fe@dev.tdt.de&gt;
</content>
</entry>
<entry>
<title>strongswan: use global secret/authority uci sections</title>
<updated>2026-09-30T09:58:51Z</updated>
<author>
<name>Florian Eckert</name>
</author>
<published>2026-09-21T13:20:50Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=ac80ae3fe97c629261365ad5d8da27e6f9f18c43'/>
<id>urn:sha1:ac80ae3fe97c629261365ad5d8da27e6f9f18c43</id>
<content type='text'>
Remove the per-connection 'authorities' and 'secrets' blocks generated
inline in config_connection. Pre-shared keys and CA certificates are
now provided via the global 'secret' and 'authority' uci sections, which
prepare_env renders into their own swanctl.conf entries.

The migrate script converts the old per-connection settings into these
new global sections:

- psk connections: 'pre_shared_key' is moved into a 'secret' section
  with type='ike', keeping the local/remote identifiers as an 'id' list
- pubkey connections: 'ca_cert' is moved into an 'authority' section
  with the matching 'cacert' option

Both options are removed from the connection section afterwards.

Signed-off-by: Florian Eckert &lt;fe@dev.tdt.de&gt;
</content>
</entry>
<entry>
<title>strongswan: replace mschapv2_secrets with generic secret type</title>
<updated>2026-09-30T09:58:51Z</updated>
<author>
<name>Florian Eckert</name>
</author>
<published>2026-09-21T12:35:07Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=7561ce78193b2a77a072bf345f6d61c9a3eaf1f5'/>
<id>urn:sha1:7561ce78193b2a77a072bf345f6d61c9a3eaf1f5</id>
<content type='text'>
Add a generic uci 'secret' section type to swanctl handling, replacing
the dedicated 'mschapv2_secrets' section in prepare_env. The secret kind
is selected via a new 'type' uci option and maps to the matching swanctl
secrets subsection (the section prefix equals the type value):

- eap, xauth, ntlm, ike, ppk: &lt;type&gt;-&lt;name&gt; { id ...; secret }
- private, rsa, ecdsa, pkcs8, pkcs12: &lt;type&gt;-&lt;name&gt; { file ...; secret }
- token: token-&lt;name&gt; { handle, slot, module, pin }

The 'id' option is a uci list element for the eap/xauth/ntlm/ike/ppk
types and emits one 'id' line per entry, matching swanctl's support for
multiple identities per secret.

The legacy path stays unchanged and keeps generating EAP secrets from
the 'mschapv2_secrets' section via legacy_config_mschapv2_secret.

The migrate script now converts 'mschapv2_secrets' sections into
generic 'secret' sections setting type='eap' and turning 'id' into a
list element.

Signed-off-by: Florian Eckert &lt;fe@dev.tdt.de&gt;
</content>
</entry>
<entry>
<title>strongswan: rename uci remote section type to connection</title>
<updated>2026-09-30T09:58:51Z</updated>
<author>
<name>Florian Eckert</name>
</author>
<published>2026-09-18T14:16:35Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=fe46e1435bbb35f2781c15f3af1e68f866082855'/>
<id>urn:sha1:fe46e1435bbb35f2781c15f3af1e68f866082855</id>
<content type='text'>
The 'remote' section type in '/etc/config/ipsec' is a misnomer, since
it defines the whole IPsec connection (IKE peer and children), not just
the remote end. Rename it to 'connection' to align with the swanctl
'connections' terminology.

Rename config_remote() to config_connection() and iterate the
'connection' type in swanctl.init.

Add a migrate_remote_to_connection migration step that renames existing
'remote' sections to 'connection'.

Signed-off-by: Florian Eckert &lt;fe@dev.tdt.de
</content>
</entry>
<entry>
<title>strongswan: support optional UCI session staging in migrate-ipsec-to-swanctl</title>
<updated>2026-09-30T09:58:51Z</updated>
<author>
<name>Florian Eckert</name>
</author>
<published>2026-09-25T14:06:48Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=d5f33e6410cfd9b30d0b25702663e7b67695925d'/>
<id>urn:sha1:d5f33e6410cfd9b30d0b25702663e7b67695925d</id>
<content type='text'>
Let the caller pass an optional session ID as the first argument to
main(). If one is given, the migration is performed inside a LuCI
transaction session: the resulting /tmp/.uci/ipsec delta is moved to
/tmp/run/rpcd/uci-${session} at the end instead of being applied to the
running config directly. This allows LuCI to preview and apply the
ipsec-to-swanctl migration through its normal session workflow, rather
than forcing an immediate, uncoordinated commit of /etc/config/ipsec.

Drop the 'uci commit ipsec' calls scattered through the individual
migration functions, since committing is now the caller's
responsibility. Also add -q to the uci calls that were missing it, so
errors are suppressed consistently.

Signed-off-by: Florian Eckert &lt;fe@dev.tdt.de&gt;
</content>
</entry>
<entry>
<title>strongswan: add migrate command to swanctl.init</title>
<updated>2026-09-30T09:58:51Z</updated>
<author>
<name>Florian Eckert</name>
</author>
<published>2026-09-18T05:42:06Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=24d9cac253f1c6f9356b8d89a5b104547a5f930a'/>
<id>urn:sha1:24d9cac253f1c6f9356b8d89a5b104547a5f930a</id>
<content type='text'>
Now that the ipsec-to-swanctl migration is no longer executed
automatically on boot, expose it through the init script so it can be
invoked on demand via '/etc/init.d/swanctl migrate'.

Also harden the migration script: abort with an error if
'/etc/config/ipsec' does not exist. Keep a copy of the original
configuration in '/etc/config/ipsec_bak' before starting.

Signed-off-by: Florian Eckert &lt;fe@dev.tdt.de&gt;
</content>
</entry>
<entry>
<title>strongswan: stop automatic migration via uci-defaults</title>
<updated>2026-09-30T09:58:51Z</updated>
<author>
<name>Florian Eckert</name>
</author>
<published>2026-09-18T05:22:30Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=76c6805c540e4473191dc530c3adb87a670ba6ca'/>
<id>urn:sha1:76c6805c540e4473191dc530c3adb87a670ba6ca</id>
<content type='text'>
The migration of the legacy '/etc/config/ipsec' UCI configuration to
the new '/etc/config/swanctl' format cannot be performed fully
automatically: it rewrites the user's configuration and must be
triggered and acknowledged by the user.

Remove the automatic migration hook that was installed as an
uci-defaults script (executed once on first boot or installation) and
instead ship the migration utility as a regular binary at
'/usr/libexec/strongswan/migrate-ipsec-to-swanctl'. From now on the
migration is only run on demand.

Signed-off-by: Florian Eckert &lt;fe@dev.tdt.de&gt;
</content>
</entry>
</feed>
