net-vpn/strongswan: add 6.0.7

Signed-off-by: Dennis Eisele <kernlpanic@dennis-eisele.de>
Part-of: https://github.com/gentoo/gentoo/pull/46420
Closes: https://github.com/gentoo/gentoo/pull/46420
Signed-off-by: Sam James <sam@gentoo.org>
This commit is contained in:
Dennis Eisele
2026-06-12 18:52:55 +02:00
committed by Sam James
parent cbc92f10e2
commit 42e71877b4
2 changed files with 263 additions and 0 deletions

View File

@@ -3,3 +3,5 @@ DIST strongswan-6.0.4.tar.bz2 4915290 BLAKE2B 2291900bda3e679cb68f35e44fe20011d8
DIST strongswan-6.0.4.tar.bz2.sig 659 BLAKE2B 9f52de2eaa6e72841df39e51c118ab932bf134aef5de3691933891e3878e12f80508b036e6f075a9ff2f3bb42d4c37431cbbad96c9db7c7ba82b744c5bbea94f SHA512 a78cc6d7630aee51c0bd0268c5ceb1723a90275a6466a9f4e0b0e6cc1a3ad25ea0ea075cf09f3db0495e3e1a792ff483c16ffe9101839bb4a9fa261b3e38696f
DIST strongswan-6.0.6.tar.bz2 4936540 BLAKE2B 0d98b9230029c6a02f56a7ce7393b2d241dc77880bcae8affb0280a75c190ce96a8727fa079ae46540115f0dbfc3228799742faddccab0e2cbe86f4934e8e23a SHA512 4f8abadeaa750589b2352260726e74e70dd6ec789e8a218d339fe83223d6427e13ebbae279b97e96a96787ccdc38ac1a6cec684ff544fa0b4f8fb16159afad84
DIST strongswan-6.0.6.tar.bz2.sig 659 BLAKE2B a439888aa38833c1bb1dfe82a122f0b5b80c2e20bf766c1f8819e01bdee724490f658b9cacee83e420402d153bc94b9e9d9f7061979612ea6907d690434ad0de SHA512 bd487c7e141d9d8cb8ee9f01e8531254848a9640bbe41631d27f8d13c99328d9ed4830f9696d2a4f096da32d7dc0af3e9229a27d17d44ab022fb2e8e55c27f3b
DIST strongswan-6.0.7.tar.bz2 4939164 BLAKE2B 503973ad437545ebae12297fefea80a6e0e3d9db8781cadc1dc37bfe8dcd8895c4442bf4a3b6f84051ae14ee1024471c4b3d5a5ac99036122d08413ddf3923c8 SHA512 1d10b0eaf39072db1d7f5237661e71c81107bb0bdea6a4bcbdff0c54eb7f72d6487f78c91a6f527c69ff20f9ee611d7e8cedcec4c5cc65d53ecc4301e1353240
DIST strongswan-6.0.7.tar.bz2.sig 659 BLAKE2B 06db584efd5658f555d2f04328dc88b48621bf91590c5bfcef628fc0a31337fb10458e40ac027cbd7a98ac515e4d0271623028197b5e592390e8fa5a6bcde4aa SHA512 3206fa1c8e5457252734f7bf1254ff70f1ccf0d9541f978e9daa8b9d6dee4bf240fdce64df50967781068138b60f30ff220e3e8f118989c55fac6c0ff5882ecf

View File

@@ -0,0 +1,261 @@
# Copyright 1999-2026 Gentoo Authors
# Distributed under the terms of the GNU General Public License v2
EAPI="8"
VERIFY_SIG_OPENPGP_KEY_PATH=/usr/share/openpgp-keys/strongswan.asc
inherit systemd verify-sig
DESCRIPTION="IPsec-based VPN solution, supporting IKEv1/IKEv2 and MOBIKE"
HOMEPAGE="https://www.strongswan.org/"
SRC_URI="
https://download.strongswan.org/${P}.tar.bz2
verify-sig? ( https://download.strongswan.org/${P}.tar.bz2.sig )
"
LICENSE="GPL-2 RSA DES"
SLOT="0"
KEYWORDS="~amd64 ~arm ~arm64 ~ppc ~ppc64 ~riscv ~x86"
IUSE="+caps curl +constraints debug dhcp eap farp gcrypt +gmp ldap mysql networkmanager +non-root +openssl selinux sqlite systemd pam pkcs11"
STRONGSWAN_PLUGINS_STD="aes cmac curve25519 des dnskey drbg eap-radius fips-prf gcm hmac led lookip md5 nonce pem pgp
pkcs1 pkcs7 pkcs8 pkcs12 pubkey random rc2 revocation sha1 sha2 sshkey systime-fix stroke unity vici x509 xcbc"
STRONGSWAN_PLUGINS_OPT_DISABLE="kdf"
STRONGSWAN_PLUGINS_OPT="acert af-alg agent addrblock aesni botan blowfish bypass-lan
ccm chapoly connmark ctr error-notify forecast files gcm ha ipseckey md4 mgf1
openxpki padlock rdrand save-keys sha3 soup test-vectors unbound whitelist xauth-noauth"
for mod in $STRONGSWAN_PLUGINS_STD; do
IUSE="${IUSE} +strongswan_plugins_${mod}"
done
for mod in $STRONGSWAN_PLUGINS_OPT_DISABLE; do
IUSE="${IUSE} strongswan_plugins_${mod}"
done
for mod in $STRONGSWAN_PLUGINS_OPT; do
IUSE="${IUSE} strongswan_plugins_${mod}"
done
COMMON_DEPEND="
non-root? (
acct-user/ipsec
acct-group/ipsec
)
dev-libs/glib:2
gmp? ( >=dev-libs/gmp-4.1.5:= )
gcrypt? (
dev-libs/libgcrypt:=
dev-libs/libgpg-error
)
caps? ( sys-libs/libcap )
curl? ( net-misc/curl )
ldap? ( net-nds/openldap:= )
openssl? ( >=dev-libs/openssl-0.9.8:=[-bindist(-)] )
mysql? ( dev-db/mysql-connector-c:= )
sqlite? ( >=dev-db/sqlite-3.3.1:3 )
systemd? ( sys-apps/systemd )
networkmanager? ( net-misc/networkmanager )
pam? ( sys-libs/pam )
strongswan_plugins_botan? ( dev-libs/botan:3= )
strongswan_plugins_connmark? ( net-firewall/iptables:= )
strongswan_plugins_forecast? ( net-firewall/iptables:= )
strongswan_plugins_soup? ( net-libs/libsoup:3.0 )
strongswan_plugins_unbound? ( net-dns/unbound:= net-libs/ldns:= )
"
DEPEND="
${COMMON_DEPEND}
virtual/linux-sources
sys-kernel/linux-headers
"
RDEPEND="
${COMMON_DEPEND}
virtual/logger
sys-apps/iproute2
!net-vpn/libreswan
selinux? ( sec-policy/selinux-ipsec )
"
BDEPEND="
verify-sig? ( sec-keys/openpgp-keys-strongswan )
"
UGID="ipsec"
src_configure() {
local myeconfargs=(
--disable-static
--enable-ikev1
--enable-ikev2
--enable-swanctl
--enable-socket-dynamic
--enable-cmd
$(use_enable curl)
$(use_enable constraints)
$(use_enable ldap)
$(use_enable debug leak-detective)
$(use_enable dhcp)
$(use_enable eap eap-sim)
$(use_enable eap eap-sim-file)
$(use_enable eap eap-simaka-sql)
$(use_enable eap eap-simaka-pseudonym)
$(use_enable eap eap-simaka-reauth)
$(use_enable eap eap-identity)
$(use_enable eap eap-md5)
$(use_enable eap eap-aka)
$(use_enable eap eap-aka-3gpp2)
$(use_enable eap md4)
$(use_enable eap eap-mschapv2)
$(use_enable eap eap-radius)
$(use_enable eap eap-tls)
$(use_enable eap eap-ttls)
$(use_enable eap xauth-eap)
$(use_enable eap eap-dynamic)
$(use_enable farp)
$(use_enable gmp)
$(use_enable gcrypt)
$(use_enable mysql)
$(use_enable networkmanager nm)
$(use_enable openssl)
$(use_enable pam xauth-pam)
$(use_enable pkcs11)
$(use_enable sqlite)
$(use_enable systemd)
$(use_with caps capabilities libcap)
--with-piddir=/run
--with-systemdsystemunitdir="$(systemd_get_systemunitdir)"
)
if use non-root; then
myeconfargs+=(
--with-user=${UGID}
--with-group=${UGID}
)
fi
# If a user has already enabled db support, those plugins will
# most likely be desired as well. Besides they don't impose new
# dependencies and come at no cost (except for space).
if use mysql || use sqlite; then
myeconfargs+=(
--enable-attr-sql
--enable-sql
)
fi
# strongSwan builds and installs static libs by default which are
# useless to the user (and to strongSwan for that matter) because no
# header files or alike get installed... so disabling them is safe.
if use pam && use eap; then
myeconfargs+=( --enable-eap-gtc )
else
myeconfargs+=( --disable-eap-gtc )
fi
for mod in $STRONGSWAN_PLUGINS_STD; do
use strongswan_plugins_${mod} && myeconfargs+=( --enable-${mod} )
done
for mod in $STRONGSWAN_PLUGINS_OPT_DISABLE; do
! use strongswan_plugins_${mod} && myeconfargs+=( --disable-${mod} )
done
for mod in $STRONGSWAN_PLUGINS_OPT; do
use strongswan_plugins_${mod} && myeconfargs+=( --enable-${mod} )
done
econf "${myeconfargs[@]}"
}
src_install() {
emake DESTDIR="${D}" install
if ! use systemd; then
rm -rf "${ED}"/lib/systemd || die "Failed removing systemd lib."
fi
doinitd "${FILESDIR}"/ipsec
local dir_ugid
if use non-root && use strongswan_plugins_stroke; then
if [ -f /etc/ipsec.conf ]; then
fowners ${UGID}:${UGID} \
/etc/ipsec.conf
fi
fowners ${UGID}:${UGID} \
/etc/strongswan.conf
dir_ugid="${UGID}"
else
dir_ugid="root"
fi
diropts -m 0750 -o ${dir_ugid} -g ${dir_ugid}
dodir /etc/ipsec.d \
/etc/ipsec.d/aacerts \
/etc/ipsec.d/acerts \
/etc/ipsec.d/cacerts \
/etc/ipsec.d/certs \
/etc/ipsec.d/crls \
/etc/ipsec.d/ocspcerts \
/etc/ipsec.d/private \
/etc/ipsec.d/reqs
dodoc NEWS README TODO
# shared libs are used only internally and there are no static libs,
# so it's safe to get rid of the .la files
find "${D}" -name '*.la' -delete || die "Failed to remove .la files."
}
pkg_postinst() {
if ! use openssl && ! use gcrypt; then
elog
elog "${PN} has been compiled without both OpenSSL and libgcrypt support."
elog "Please note that this might effect availability and speed of some"
elog "cryptographic features. You are advised to enable the OpenSSL plugin."
elif ! use openssl; then
elog
elog "${PN} has been compiled without the OpenSSL plugin. This might effect"
elog "availability and speed of some cryptographic features. There will be"
elog "no support for Elliptic Curve Cryptography (Diffie-Hellman groups 19-21,"
elog "25, 26) and ECDSA."
fi
if ! use caps && ! use non-root; then
ewarn
ewarn "You have decided to run ${PN} with root privileges and built it"
ewarn "without support for POSIX capability dropping. It is generally"
ewarn "strongly suggested that you reconsider- especially if you intend"
ewarn "to run ${PN} as server with a public ip address."
ewarn
ewarn "You should re-emerge ${PN} with at least the 'caps' USE flag enabled."
ewarn
fi
if use non-root; then
elog
elog "${PN} has been installed without superuser privileges (USE=non-root)."
elog "This imposes a few limitations mainly to the daemon 'charon' in"
elog "regards of the use of iptables."
elog
elog "Please carefully read: http://wiki.strongswan.org/projects/strongswan/wiki/ReducedPrivileges"
elog
elog "Thus if you require to specify a custom updown"
elog "script to charon which requires superuser privileges, you"
elog "can work around this limitation by using sudo to grant the"
elog "user \"ipsec\" the appropriate rights."
elog "For example (the default case):"
elog "/etc/sudoers:"
elog " ipsec ALL=(ALL) NOPASSWD: SETENV: /usr/sbin/ipsec"
elog "Under the specific connection block in /etc/ipsec.conf:"
elog " leftupdown=\"sudo -E ipsec _updown iptables\""
elog
fi
elog
elog "Make sure you have _all_ required kernel modules available including"
elog "the appropriate cryptographic algorithms. A list is available at:"
elog " https://wiki.strongswan.org/projects/strongswan/wiki/KernelModules"
elog
elog "The up-to-date manual is available online at:"
elog " https://wiki.strongswan.org/"
elog
}