mirror of
https://github.com/gentoo-mirror/gentoo.git
synced 2026-08-06 00:48:18 -07:00
net-vpn/strongswan: add 6.0.7
Signed-off-by: Dennis Eisele <kernlpanic@dennis-eisele.de> Part-of: https://github.com/gentoo/gentoo/pull/46420 Closes: https://github.com/gentoo/gentoo/pull/46420 Signed-off-by: Sam James <sam@gentoo.org>
This commit is contained in:
@@ -3,3 +3,5 @@ DIST strongswan-6.0.4.tar.bz2 4915290 BLAKE2B 2291900bda3e679cb68f35e44fe20011d8
|
||||
DIST strongswan-6.0.4.tar.bz2.sig 659 BLAKE2B 9f52de2eaa6e72841df39e51c118ab932bf134aef5de3691933891e3878e12f80508b036e6f075a9ff2f3bb42d4c37431cbbad96c9db7c7ba82b744c5bbea94f SHA512 a78cc6d7630aee51c0bd0268c5ceb1723a90275a6466a9f4e0b0e6cc1a3ad25ea0ea075cf09f3db0495e3e1a792ff483c16ffe9101839bb4a9fa261b3e38696f
|
||||
DIST strongswan-6.0.6.tar.bz2 4936540 BLAKE2B 0d98b9230029c6a02f56a7ce7393b2d241dc77880bcae8affb0280a75c190ce96a8727fa079ae46540115f0dbfc3228799742faddccab0e2cbe86f4934e8e23a SHA512 4f8abadeaa750589b2352260726e74e70dd6ec789e8a218d339fe83223d6427e13ebbae279b97e96a96787ccdc38ac1a6cec684ff544fa0b4f8fb16159afad84
|
||||
DIST strongswan-6.0.6.tar.bz2.sig 659 BLAKE2B a439888aa38833c1bb1dfe82a122f0b5b80c2e20bf766c1f8819e01bdee724490f658b9cacee83e420402d153bc94b9e9d9f7061979612ea6907d690434ad0de SHA512 bd487c7e141d9d8cb8ee9f01e8531254848a9640bbe41631d27f8d13c99328d9ed4830f9696d2a4f096da32d7dc0af3e9229a27d17d44ab022fb2e8e55c27f3b
|
||||
DIST strongswan-6.0.7.tar.bz2 4939164 BLAKE2B 503973ad437545ebae12297fefea80a6e0e3d9db8781cadc1dc37bfe8dcd8895c4442bf4a3b6f84051ae14ee1024471c4b3d5a5ac99036122d08413ddf3923c8 SHA512 1d10b0eaf39072db1d7f5237661e71c81107bb0bdea6a4bcbdff0c54eb7f72d6487f78c91a6f527c69ff20f9ee611d7e8cedcec4c5cc65d53ecc4301e1353240
|
||||
DIST strongswan-6.0.7.tar.bz2.sig 659 BLAKE2B 06db584efd5658f555d2f04328dc88b48621bf91590c5bfcef628fc0a31337fb10458e40ac027cbd7a98ac515e4d0271623028197b5e592390e8fa5a6bcde4aa SHA512 3206fa1c8e5457252734f7bf1254ff70f1ccf0d9541f978e9daa8b9d6dee4bf240fdce64df50967781068138b60f30ff220e3e8f118989c55fac6c0ff5882ecf
|
||||
|
||||
261
net-vpn/strongswan/strongswan-6.0.7.ebuild
Normal file
261
net-vpn/strongswan/strongswan-6.0.7.ebuild
Normal file
@@ -0,0 +1,261 @@
|
||||
# Copyright 1999-2026 Gentoo Authors
|
||||
# Distributed under the terms of the GNU General Public License v2
|
||||
|
||||
EAPI="8"
|
||||
|
||||
VERIFY_SIG_OPENPGP_KEY_PATH=/usr/share/openpgp-keys/strongswan.asc
|
||||
inherit systemd verify-sig
|
||||
|
||||
DESCRIPTION="IPsec-based VPN solution, supporting IKEv1/IKEv2 and MOBIKE"
|
||||
HOMEPAGE="https://www.strongswan.org/"
|
||||
SRC_URI="
|
||||
https://download.strongswan.org/${P}.tar.bz2
|
||||
verify-sig? ( https://download.strongswan.org/${P}.tar.bz2.sig )
|
||||
"
|
||||
|
||||
LICENSE="GPL-2 RSA DES"
|
||||
SLOT="0"
|
||||
KEYWORDS="~amd64 ~arm ~arm64 ~ppc ~ppc64 ~riscv ~x86"
|
||||
IUSE="+caps curl +constraints debug dhcp eap farp gcrypt +gmp ldap mysql networkmanager +non-root +openssl selinux sqlite systemd pam pkcs11"
|
||||
|
||||
STRONGSWAN_PLUGINS_STD="aes cmac curve25519 des dnskey drbg eap-radius fips-prf gcm hmac led lookip md5 nonce pem pgp
|
||||
pkcs1 pkcs7 pkcs8 pkcs12 pubkey random rc2 revocation sha1 sha2 sshkey systime-fix stroke unity vici x509 xcbc"
|
||||
STRONGSWAN_PLUGINS_OPT_DISABLE="kdf"
|
||||
STRONGSWAN_PLUGINS_OPT="acert af-alg agent addrblock aesni botan blowfish bypass-lan
|
||||
ccm chapoly connmark ctr error-notify forecast files gcm ha ipseckey md4 mgf1
|
||||
openxpki padlock rdrand save-keys sha3 soup test-vectors unbound whitelist xauth-noauth"
|
||||
|
||||
for mod in $STRONGSWAN_PLUGINS_STD; do
|
||||
IUSE="${IUSE} +strongswan_plugins_${mod}"
|
||||
done
|
||||
|
||||
for mod in $STRONGSWAN_PLUGINS_OPT_DISABLE; do
|
||||
IUSE="${IUSE} strongswan_plugins_${mod}"
|
||||
done
|
||||
|
||||
for mod in $STRONGSWAN_PLUGINS_OPT; do
|
||||
IUSE="${IUSE} strongswan_plugins_${mod}"
|
||||
done
|
||||
|
||||
COMMON_DEPEND="
|
||||
non-root? (
|
||||
acct-user/ipsec
|
||||
acct-group/ipsec
|
||||
)
|
||||
dev-libs/glib:2
|
||||
gmp? ( >=dev-libs/gmp-4.1.5:= )
|
||||
gcrypt? (
|
||||
dev-libs/libgcrypt:=
|
||||
dev-libs/libgpg-error
|
||||
)
|
||||
caps? ( sys-libs/libcap )
|
||||
curl? ( net-misc/curl )
|
||||
ldap? ( net-nds/openldap:= )
|
||||
openssl? ( >=dev-libs/openssl-0.9.8:=[-bindist(-)] )
|
||||
mysql? ( dev-db/mysql-connector-c:= )
|
||||
sqlite? ( >=dev-db/sqlite-3.3.1:3 )
|
||||
systemd? ( sys-apps/systemd )
|
||||
networkmanager? ( net-misc/networkmanager )
|
||||
pam? ( sys-libs/pam )
|
||||
strongswan_plugins_botan? ( dev-libs/botan:3= )
|
||||
strongswan_plugins_connmark? ( net-firewall/iptables:= )
|
||||
strongswan_plugins_forecast? ( net-firewall/iptables:= )
|
||||
strongswan_plugins_soup? ( net-libs/libsoup:3.0 )
|
||||
strongswan_plugins_unbound? ( net-dns/unbound:= net-libs/ldns:= )
|
||||
"
|
||||
DEPEND="
|
||||
${COMMON_DEPEND}
|
||||
virtual/linux-sources
|
||||
sys-kernel/linux-headers
|
||||
"
|
||||
RDEPEND="
|
||||
${COMMON_DEPEND}
|
||||
virtual/logger
|
||||
sys-apps/iproute2
|
||||
!net-vpn/libreswan
|
||||
selinux? ( sec-policy/selinux-ipsec )
|
||||
"
|
||||
BDEPEND="
|
||||
verify-sig? ( sec-keys/openpgp-keys-strongswan )
|
||||
"
|
||||
|
||||
UGID="ipsec"
|
||||
|
||||
src_configure() {
|
||||
local myeconfargs=(
|
||||
--disable-static
|
||||
--enable-ikev1
|
||||
--enable-ikev2
|
||||
--enable-swanctl
|
||||
--enable-socket-dynamic
|
||||
--enable-cmd
|
||||
$(use_enable curl)
|
||||
$(use_enable constraints)
|
||||
$(use_enable ldap)
|
||||
$(use_enable debug leak-detective)
|
||||
$(use_enable dhcp)
|
||||
$(use_enable eap eap-sim)
|
||||
$(use_enable eap eap-sim-file)
|
||||
$(use_enable eap eap-simaka-sql)
|
||||
$(use_enable eap eap-simaka-pseudonym)
|
||||
$(use_enable eap eap-simaka-reauth)
|
||||
$(use_enable eap eap-identity)
|
||||
$(use_enable eap eap-md5)
|
||||
$(use_enable eap eap-aka)
|
||||
$(use_enable eap eap-aka-3gpp2)
|
||||
$(use_enable eap md4)
|
||||
$(use_enable eap eap-mschapv2)
|
||||
$(use_enable eap eap-radius)
|
||||
$(use_enable eap eap-tls)
|
||||
$(use_enable eap eap-ttls)
|
||||
$(use_enable eap xauth-eap)
|
||||
$(use_enable eap eap-dynamic)
|
||||
$(use_enable farp)
|
||||
$(use_enable gmp)
|
||||
$(use_enable gcrypt)
|
||||
$(use_enable mysql)
|
||||
$(use_enable networkmanager nm)
|
||||
$(use_enable openssl)
|
||||
$(use_enable pam xauth-pam)
|
||||
$(use_enable pkcs11)
|
||||
$(use_enable sqlite)
|
||||
$(use_enable systemd)
|
||||
$(use_with caps capabilities libcap)
|
||||
--with-piddir=/run
|
||||
--with-systemdsystemunitdir="$(systemd_get_systemunitdir)"
|
||||
)
|
||||
|
||||
if use non-root; then
|
||||
myeconfargs+=(
|
||||
--with-user=${UGID}
|
||||
--with-group=${UGID}
|
||||
)
|
||||
fi
|
||||
|
||||
# If a user has already enabled db support, those plugins will
|
||||
# most likely be desired as well. Besides they don't impose new
|
||||
# dependencies and come at no cost (except for space).
|
||||
if use mysql || use sqlite; then
|
||||
myeconfargs+=(
|
||||
--enable-attr-sql
|
||||
--enable-sql
|
||||
)
|
||||
fi
|
||||
|
||||
# strongSwan builds and installs static libs by default which are
|
||||
# useless to the user (and to strongSwan for that matter) because no
|
||||
# header files or alike get installed... so disabling them is safe.
|
||||
if use pam && use eap; then
|
||||
myeconfargs+=( --enable-eap-gtc )
|
||||
else
|
||||
myeconfargs+=( --disable-eap-gtc )
|
||||
fi
|
||||
|
||||
for mod in $STRONGSWAN_PLUGINS_STD; do
|
||||
use strongswan_plugins_${mod} && myeconfargs+=( --enable-${mod} )
|
||||
done
|
||||
|
||||
for mod in $STRONGSWAN_PLUGINS_OPT_DISABLE; do
|
||||
! use strongswan_plugins_${mod} && myeconfargs+=( --disable-${mod} )
|
||||
done
|
||||
|
||||
for mod in $STRONGSWAN_PLUGINS_OPT; do
|
||||
use strongswan_plugins_${mod} && myeconfargs+=( --enable-${mod} )
|
||||
done
|
||||
|
||||
econf "${myeconfargs[@]}"
|
||||
}
|
||||
|
||||
src_install() {
|
||||
emake DESTDIR="${D}" install
|
||||
|
||||
if ! use systemd; then
|
||||
rm -rf "${ED}"/lib/systemd || die "Failed removing systemd lib."
|
||||
fi
|
||||
|
||||
doinitd "${FILESDIR}"/ipsec
|
||||
|
||||
local dir_ugid
|
||||
if use non-root && use strongswan_plugins_stroke; then
|
||||
if [ -f /etc/ipsec.conf ]; then
|
||||
fowners ${UGID}:${UGID} \
|
||||
/etc/ipsec.conf
|
||||
fi
|
||||
|
||||
fowners ${UGID}:${UGID} \
|
||||
/etc/strongswan.conf
|
||||
|
||||
dir_ugid="${UGID}"
|
||||
else
|
||||
dir_ugid="root"
|
||||
fi
|
||||
|
||||
diropts -m 0750 -o ${dir_ugid} -g ${dir_ugid}
|
||||
dodir /etc/ipsec.d \
|
||||
/etc/ipsec.d/aacerts \
|
||||
/etc/ipsec.d/acerts \
|
||||
/etc/ipsec.d/cacerts \
|
||||
/etc/ipsec.d/certs \
|
||||
/etc/ipsec.d/crls \
|
||||
/etc/ipsec.d/ocspcerts \
|
||||
/etc/ipsec.d/private \
|
||||
/etc/ipsec.d/reqs
|
||||
|
||||
dodoc NEWS README TODO
|
||||
|
||||
# shared libs are used only internally and there are no static libs,
|
||||
# so it's safe to get rid of the .la files
|
||||
find "${D}" -name '*.la' -delete || die "Failed to remove .la files."
|
||||
}
|
||||
|
||||
pkg_postinst() {
|
||||
if ! use openssl && ! use gcrypt; then
|
||||
elog
|
||||
elog "${PN} has been compiled without both OpenSSL and libgcrypt support."
|
||||
elog "Please note that this might effect availability and speed of some"
|
||||
elog "cryptographic features. You are advised to enable the OpenSSL plugin."
|
||||
elif ! use openssl; then
|
||||
elog
|
||||
elog "${PN} has been compiled without the OpenSSL plugin. This might effect"
|
||||
elog "availability and speed of some cryptographic features. There will be"
|
||||
elog "no support for Elliptic Curve Cryptography (Diffie-Hellman groups 19-21,"
|
||||
elog "25, 26) and ECDSA."
|
||||
fi
|
||||
if ! use caps && ! use non-root; then
|
||||
ewarn
|
||||
ewarn "You have decided to run ${PN} with root privileges and built it"
|
||||
ewarn "without support for POSIX capability dropping. It is generally"
|
||||
ewarn "strongly suggested that you reconsider- especially if you intend"
|
||||
ewarn "to run ${PN} as server with a public ip address."
|
||||
ewarn
|
||||
ewarn "You should re-emerge ${PN} with at least the 'caps' USE flag enabled."
|
||||
ewarn
|
||||
fi
|
||||
if use non-root; then
|
||||
elog
|
||||
elog "${PN} has been installed without superuser privileges (USE=non-root)."
|
||||
elog "This imposes a few limitations mainly to the daemon 'charon' in"
|
||||
elog "regards of the use of iptables."
|
||||
elog
|
||||
elog "Please carefully read: http://wiki.strongswan.org/projects/strongswan/wiki/ReducedPrivileges"
|
||||
elog
|
||||
elog "Thus if you require to specify a custom updown"
|
||||
elog "script to charon which requires superuser privileges, you"
|
||||
elog "can work around this limitation by using sudo to grant the"
|
||||
elog "user \"ipsec\" the appropriate rights."
|
||||
elog "For example (the default case):"
|
||||
elog "/etc/sudoers:"
|
||||
elog " ipsec ALL=(ALL) NOPASSWD: SETENV: /usr/sbin/ipsec"
|
||||
elog "Under the specific connection block in /etc/ipsec.conf:"
|
||||
elog " leftupdown=\"sudo -E ipsec _updown iptables\""
|
||||
elog
|
||||
fi
|
||||
elog
|
||||
elog "Make sure you have _all_ required kernel modules available including"
|
||||
elog "the appropriate cryptographic algorithms. A list is available at:"
|
||||
elog " https://wiki.strongswan.org/projects/strongswan/wiki/KernelModules"
|
||||
elog
|
||||
elog "The up-to-date manual is available online at:"
|
||||
elog " https://wiki.strongswan.org/"
|
||||
elog
|
||||
}
|
||||
Reference in New Issue
Block a user