We are happy to announce the release of strongSwan 5.9.3, which supports IKE encryption via TKM, adds more algorithms to the wolfssl plugin and brings several other new features and fixes.
The Trusted Key Manager (TKM) and strongSwan's corresponding IKE daemon charon-tkm gained support to encrypt IKE messages. That way, the IKE daemon won't see any key material at all.
By adding support for AES-ECB, SHA-3 and SHAKE-256 even more other plugins can be disabled when relying on wolfSSL as cryptographic backend.
CKA_TRUSTED
, which previously depended on a version check.