Linux workstation

Debian 12 (Bookworm) native package

libreswan

Internet Key Exchange daemon

Packages / Debian 12 (Bookworm) / net / libreswan

Package: libreswan (4.10-2+deb12u1)

Maintainers:

Daniel Kahn Gillmor

External Resources:

Homepage: [libreswan.org]

Internet Key Exchange daemon

Other Packages Related to libreswan:

  • dep: [dns-root-data]

    DNS root hints and DNSSEC trust anchor

  • dep: host

    Package not available

  • dep: [iproute2]

    networking and traffic control tools

  • dep: iproute (>= 20071016)

    Package not available

  • dep: [iptables]

    administration tools for packet filtering and NAT

  • dep: [libnss3-tools]

    Network Security Service tools

  • dep: [libaudit1] (>= 1:2.2.1)

    Dynamic library for security auditing

  • dep: [libc6] (>= 2.34)

    GNU C Library: Shared libraries

  • dep: [libcap-ng0] (>= 0.7.9)

    alternate POSIX capabilities library

  • dep: [libcrypt1] (>= 1:4.1.0)

    libcrypt shared library

  • dep: [libcurl3-nss] (>= 7.23.1)

    easy-to-use client-side URL transfer library (NSS flavour)

  • dep: [libevent-core-2.1-7] (>= 2.1.8-stable)

    Asynchronous event notification library (core)

  • dep: [libevent-pthreads-2.1-7] (>= 2.1.8-stable)

    Asynchronous event notification library (pthreads)

  • dep: [libldap-2.5-0] (>= 2.5.4)

    OpenLDAP libraries

  • dep: [libldns3] (>= 1.7.1)

    ldns library for DNS programming - shared library

  • dep: [libnspr4] (>= 2:4.9-2~)

    NetScape Portable Runtime Library

  • dep: [libnss3] (>= 2:3.38)

    Network Security Service libraries

  • dep: [libpam0g] (>= 0.99.7.1)

    Pluggable Authentication Modules library

  • dep: [libselinux1] (>= 3.1~)

    SELinux runtime shared libraries

  • dep: [libsystemd0]

    systemd utility library

  • dep: [libunbound8] (>= 1.8.0)

    library implementing DNS resolution and validation

  • rec: [python3]

    interactive high-level object-oriented language (default python3 version)

Download libreswan

ArchitecturePackage SizeInstalled SizeFiles
amd641.2 MiB6.0 MiB[list of files]
arm641.1 MiB6.6 MiB[list of files]

Package file paths (113)

Paths come from the repository package-file index for the observed builds. They describe archive/package associations, not every file that will exist on a running system after maintainer scripts, alternatives, generated state, diversions, or installation choices.

  • /etc/ipsec.conf
  • /etc/ipsec.d/policies/block
  • /etc/ipsec.d/policies/clear
  • /etc/ipsec.d/policies/clear-or-private
  • /etc/ipsec.d/policies/portexcludes.conf
  • /etc/ipsec.d/policies/private
  • /etc/ipsec.d/policies/private-or-clear
  • /etc/ipsec.secrets
  • /etc/logcheck/ignore.d.paranoid/libreswan
  • /etc/logcheck/ignore.d.server/libreswan
  • /etc/logcheck/ignore.d.workstation/libreswan
  • /etc/logrotate.d/libreswan
  • /etc/pam.d/pluto
  • /lib/systemd/system/ipsec.service
  • /lib/systemd/system-preset/90-libreswan.preset
  • /usr/libexec/ipsec/addconn
  • /usr/libexec/ipsec/algparse
  • /usr/libexec/ipsec/asn1check
  • /usr/libexec/ipsec/auto
  • /usr/libexec/ipsec/barf
  • /usr/libexec/ipsec/cavp
  • /usr/libexec/ipsec/dncheck
  • /usr/libexec/ipsec/ecdsasigkey
  • /usr/libexec/ipsec/enumcheck
  • /usr/libexec/ipsec/getpeercon_server
  • /usr/libexec/ipsec/hunkcheck
  • /usr/libexec/ipsec/_import_crl
  • /usr/libexec/ipsec/ipcheck
  • /usr/libexec/ipsec/jambufcheck
  • /usr/libexec/ipsec/keyidcheck
  • /usr/libexec/ipsec/letsencrypt
  • /usr/libexec/ipsec/look
  • /usr/libexec/ipsec/newhostkey
  • /usr/libexec/ipsec/pluto
  • /usr/libexec/ipsec/_plutorun
  • /usr/libexec/ipsec/readwriteconf
  • /usr/libexec/ipsec/rsasigkey
  • /usr/libexec/ipsec/_secretcensor
  • /usr/libexec/ipsec/setup
  • /usr/libexec/ipsec/show
  • /usr/libexec/ipsec/showhostkey
  • /usr/libexec/ipsec/showroute
  • /usr/libexec/ipsec/_stackmanager
  • /usr/libexec/ipsec/timecheck
  • /usr/libexec/ipsec/_unbound-hook
  • /usr/libexec/ipsec/_updown
  • /usr/libexec/ipsec/_updown.xfrm
  • /usr/libexec/ipsec/vendoridcheck
  • /usr/libexec/ipsec/verify
  • /usr/libexec/ipsec/whack
  • /usr/lib/tmpfiles.d/libreswan.conf
  • /usr/sbin/ipsec
  • /usr/share/doc/libreswan/changelog.Debian.gz
  • /usr/share/doc/libreswan/changelog.gz
  • /usr/share/doc/libreswan/copyright
  • /usr/share/doc/libreswan/CREDITS
  • /usr/share/doc/libreswan/examples/hub-spoke.conf
  • /usr/share/doc/libreswan/examples/ipv6.conf
  • /usr/share/doc/libreswan/examples/l2tp-cert.conf
  • /usr/share/doc/libreswan/examples/l2tp-psk.conf
  • /usr/share/doc/libreswan/examples/linux-linux.conf
  • /usr/share/doc/libreswan/examples/oe-authnull.conf
  • /usr/share/doc/libreswan/examples/oe-dnssec-client.conf
  • /usr/share/doc/libreswan/examples/oe-dnssec-server.conf
  • /usr/share/doc/libreswan/examples/oe-exclude-dns.conf
  • /usr/share/doc/libreswan/examples/oe-letsencrypt-client.conf
  • /usr/share/doc/libreswan/examples/oe-letsencrypt-README.txt
  • /usr/share/doc/libreswan/examples/oe-letsencrypt-server.conf
  • /usr/share/doc/libreswan/examples/oe-upgrade-authnull.conf
  • /usr/share/doc/libreswan/examples/sysctl.conf
  • /usr/share/doc/libreswan/examples/xauth.conf
  • /usr/share/doc/libreswan/ipsec.conf-sample
  • /usr/share/doc/libreswan/ipsec.secrets-sample
  • /usr/share/doc/libreswan/NEWS.Debian.gz
  • /usr/share/doc/libreswan/README.Debian
  • /usr/share/doc/libreswan/README.md.gz
  • /usr/share/doc/libreswan/README.nss.gz
  • /usr/share/doc/libreswan/README.rfcs.gz
  • /usr/share/doc/libreswan/README.x509
  • /usr/share/doc/libreswan/README.XAUTH
  • /usr/share/doc/libreswan/TODO.Debian
  • /usr/share/lintian/overrides/libreswan
  • /usr/share/man/man5/ipsec.conf.5.gz
  • /usr/share/man/man5/ipsec.secrets.5.gz
  • /usr/share/man/man8/ipsec.8.gz
  • /usr/share/man/man8/ipsec_addconn.8.gz
  • /usr/share/man/man8/ipsec_auto.8.gz
  • /usr/share/man/man8/ipsec_barf.8.gz
  • /usr/share/man/man8/ipsec_checknss.8.gz
  • /usr/share/man/man8/ipsec_ecdsasigkey.8.gz
  • /usr/share/man/man8/ipsec_import.8.gz
  • /usr/share/man/man8/ipsec__import_crl.8.gz
  • /usr/share/man/man8/ipsec_initnss.8.gz
  • /usr/share/man/man8/ipsec_letsencrypt.8.gz
  • /usr/share/man/man8/ipsec_look.8.gz
  • /usr/share/man/man8/ipsec_newhostkey.8.gz
  • /usr/share/man/man8/ipsec_pluto.8.gz
  • /usr/share/man/man8/ipsec__plutorun.8.gz
  • /usr/share/man/man8/ipsec_readwriteconf.8.gz
  • /usr/share/man/man8/ipsec_rsasigkey.8.gz
  • /usr/share/man/man8/ipsec__secretcensor.8.gz
  • /usr/share/man/man8/ipsec_setup.8.gz
  • /usr/share/man/man8/ipsec_show.8.gz
  • /usr/share/man/man8/ipsec_showhostkey.8.gz
  • /usr/share/man/man8/ipsec_showroute.8.gz
  • /usr/share/man/man8/ipsec__stackmanager.8.gz
  • /usr/share/man/man8/ipsec__unbound-hook.8.gz
  • /usr/share/man/man8/ipsec__updown.8.gz
  • /usr/share/man/man8/ipsec__updown.xfrm.8.gz
  • /usr/share/man/man8/ipsec_vendorid.8.gz
  • /usr/share/man/man8/ipsec_verify.8.gz
  • /usr/share/man/man8/ipsec_whack.8.gz
  • /usr/share/man/man8/pluto.8.gz

Field source: Debian 12 (Bookworm) main amd64 revision bookworm-main-amd64:9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5

Use this package

OpenFactory can boot this operating system in a browser VM, or start a build that includes the native package name from this record.

Versions, suites, and repositories

Each row is recorded package-index metadata for one version, architecture, suite, and repository. Names, URLs, and sizes are source-reported; a link is a potentially mutable retrieval location, not an OpenFactory redistribution claim or proof that OpenFactory retained the artifact bytes.

VersionReleaseArchitectureRepositoryPackage sizeInstalled sizePublisher repository artifact
4.10-2+deb12u1bookworm / mainamd64Debian 12 · main · amd641.2 MiB6.0 MiBpool/main/libr/libreswan/libreswan_4.10-2+deb12u1_amd64.deb
4.10-2+deb12u1bookworm / mainarm64Debian 12 · main · arm641.1 MiB6.6 MiBpool/main/libr/libreswan/libreswan_4.10-2+deb12u1_arm64.deb

Field source: Debian 12 (Bookworm) main amd64 revision bookworm-main-amd64:9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5

Checksums and observation dates

For an APT source, signature verification authenticates the repository metadata chain and the Packages index containing this source-reported artifact digest. It does not certify package safety.

4.10-2+deb12u1 / amd64Observed Sep 1, 2026 to Sep 1, 2026

Verification status: Metadata observed; artifact bytes were not independently fetched or hashed by this catalog import. The digest below is source-reported.

Source-reported sha256: fb19a0992a00180e06c031f59e0b15efb504e64b0c7e49feee5e6740937fb1e8

After downloading that exact artifact, compare its bytes with the source-reported expected digest:

printf '%s %s\n' 'fb19a0992a00180e06c031f59e0b15efb504e64b0c7e49feee5e6740937fb1e8' 'libreswan_4.10-2+deb12u1_amd64.deb' | sha256sum --check --strict -

A match establishes equality with the repository metadata value. It does not establish safety or catalog-side artifact retrieval.

Field source: Debian 12 (Bookworm) main amd64 revision bookworm-main-amd64:9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5

4.10-2+deb12u1 / arm64Observed Sep 1, 2026 to Sep 1, 2026

Verification status: Metadata observed; artifact bytes were not independently fetched or hashed by this catalog import. The digest below is source-reported.

Source-reported sha256: 9e4c6b19097cb00525b4d634c0de232018c8762e9ea8dc38cfcd7f2d2f7bf5d9

After downloading that exact artifact, compare its bytes with the source-reported expected digest:

printf '%s %s\n' '9e4c6b19097cb00525b4d634c0de232018c8762e9ea8dc38cfcd7f2d2f7bf5d9' 'libreswan_4.10-2+deb12u1_arm64.deb' | sha256sum --check --strict -

A match establishes equality with the repository metadata value. It does not establish safety or catalog-side artifact retrieval.

Field source: Debian 12 (Bookworm) main arm64 revision bookworm-main-arm64:2ddb1737692e8c45c53e8d57c0ce4cd21c78c5703b830c3226b1423566a06c00

Catalog record completeness

The completeness score measures metadata coverage, not software quality, security, compatibility, or suitability.

Summary and description
25/25
Artifact path and source digest
25/25
Dependency metadata
15/15
Package-file index
15/15
Homepage
5/5
License text
0/5
Source package or maintainer
10/10

Recorded total: 95/100

Field source: Debian 12 (Bookworm) main amd64 revision bookworm-main-amd64:9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5, Debian 12 (Bookworm) main arm64 revision bookworm-main-arm64:2ddb1737692e8c45c53e8d57c0ce4cd21c78c5703b830c3226b1423566a06c00. The cross-OS mapping is catalog-derived from the source-reported homepage; it does not establish authorship or publisher identity

Sources and provenance

Field-source links above resolve here. Each source entry names the metadata publisher, trust tier, exact snapshot revision, signature result, and observation time; catalog-derived mappings are labeled separately.

  • Authoritative source; repository metadata signature verified, revision bookworm-main-amd64:9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    77737fa4b34f2693e982cc9ee35736816c35a7778fc2d326cc1bbf5b301fe1aa
    Signer fingerprint
    4CB50190207B4758A3F73A796ED0E7B82643E131
    Keyring revision
    debian-archive-keyring.gpg
    SHA-256 506b815cbb32d9b6066b4a2aa524071e071761e7e7f68c3ac74f3061ba852017
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 1, 2026
    Signed Release → package-index hash linkage

    Path: main/binary-amd64/Packages.xz
    Expected SHA-256: 9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5
    Observed SHA-256: 9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5
    Result: match verified

  • Authoritative source; repository metadata signature verified, revision bookworm-main-arm64:2ddb1737692e8c45c53e8d57c0ce4cd21c78c5703b830c3226b1423566a06c00

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    77737fa4b34f2693e982cc9ee35736816c35a7778fc2d326cc1bbf5b301fe1aa
    Signer fingerprint
    4CB50190207B4758A3F73A796ED0E7B82643E131
    Keyring revision
    debian-archive-keyring.gpg
    SHA-256 506b815cbb32d9b6066b4a2aa524071e071761e7e7f68c3ac74f3061ba852017
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 1, 2026
    Signed Release → package-index hash linkage

    Path: main/binary-arm64/Packages.xz
    Expected SHA-256: 2ddb1737692e8c45c53e8d57c0ce4cd21c78c5703b830c3226b1423566a06c00
    Observed SHA-256: 2ddb1737692e8c45c53e8d57c0ce4cd21c78c5703b830c3226b1423566a06c00
    Result: match verified

libreswan Package for Debian 12 (Bookworm) | OpenFactory