OSS TanbouSign in with GitHub

configure encrypted host and site connections with IKEv2 and IPsec

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
2,997
Primary language
C
License
Not determined
Repository last updated
Oct 2, 2026
On this page

Overview

strongSwan implements IKEv2 and IPsec to encrypt host and site traffic. It combines certificate or shared-key authentication with swanctl connection configuration.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Manage IKE negotiation and IPsec traffic

strongSwan manages key exchange, peer authentication, and IPsec security associations. Plugins and swanctl.conf configure certificates, algorithms, peers, and traffic selectors.

Sources: [1][3]

Best fit

Separate credential preparation from connection work

The bundled pki command creates keys, CA certificates, requests, and host certificates. Subject and issuer can be inspected without initiating a connection.

Sources: [4][5][6][7]

Before adoption

Validate privileges, routes, and peers in deployment

A real tunnel needs kernel IPsec support, network configuration, and usually administrative privileges. Certificate inspection does not prove connectivity, routing, or firewall passage. The repository is GPLv2 with some separately licensed code.

Sources: [1][8]

Official sources

  1. [1]strongSwan 6.1.0 README(2026-10-05)
  2. [2]strongSwan 6.1.0 release(2026-10-05)
  3. [3]swanctl.conf reference(2026-10-05)
  4. [4]pki --gen manual(2026-10-05)
  5. [5]pki --self manual(2026-10-05)
  6. [6]pki --issue manual(2026-10-05)
  7. [7]pki --print manual(2026-10-05)
  8. [8]strongSwan licensing(2026-10-05)
  9. [9]strongSwan GitHub metadata(2026-10-05)
Supplemental curator note

strongSwan fits teams that need certificate-based IPsec VPN configurations. Validate PKI artifacts in isolation, then confirm peers, routes, and privileges before touching a real network.

Try it in 3 steps

  1. 1

    Verify the fixed release and pki

    Requires Git and strongSwan pki. No VPN or firewall state is changed.

    git clone --depth 1 --branch 6.1.0 https://github.com/strongswan/strongswan.git && cd strongswan && test -f src/pki/man/pki---gen.1.in && test -f src/pki/man/pki---issue.1.in && command -v pki >/dev/null
  2. 2

    Create an isolated demonstration CA

    Generate an RSA key and self-signed CA in an owner-only temporary directory.

    pki_demo_dir=$(mktemp -d "${TMPDIR:-/tmp}/strongswan-pki.XXXXXX") && chmod 700 "$pki_demo_dir" && cd "$pki_demo_dir" && umask 077 && pki --gen --type rsa --size 3072 --outform pem > ca-key.pem && pki --self --ca --lifetime 3650 --in ca-key.pem --type rsa --dn "CN=OSS Tanbou Demo CA" --outform pem > ca-cert.pem
  3. 3

    Issue and inspect a host certificate

    Create a 30-day host certificate and inspect subject and issuer. No tunnel is started.

    pki --gen --type rsa --size 3072 --outform pem > host-key.pem && pki --req --in host-key.pem --type rsa --dn "CN=host.example.test" --san host.example.test --outform pem > host-req.pem && pki --issue --cacert ca-cert.pem --cakey ca-key.pem --type pkcs10 --in host-req.pem --lifetime 30 --flag serverAuth --outform pem > host-cert.pem && pki --print --in host-cert.pem | grep -F "CN=host.example.test" && pki --print --in host-cert.pem | grep -F "CN=OSS Tanbou Demo CA"
Check the official README

Growth

Growth trends · Last 30 days

2,997 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
32
Open PRs
69

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • vpn
  • strongswan
  • ipsec
  • ikev2
  • vpn-client
  • vpn-server
Stars
2,997
Forks
942
Watchers
108
Open issues
107
Contributors
119
Owner type
Organization
Primary language
C
License
Not determined
Repository last updated
Oct 2, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?