Where Does StrongSwan Store Config on Linux?
Where StrongSwan keeps swanctl and legacy ipsec configs on Linux, and which tool reads which files..
Last updated
StrongSwan configuration splits by management interface. Modern setups use swanctl.conf and includes under /etc/swanctl, loaded through vici commands. Legacy setups use ipsec.conf, ipsec.secrets, and ipsec.d through the starter process. Both trees coexist during migrations.
Certificates and keys sit in subfolders beside the configs, referenced by filename from connection stanzas. Loading is explicit: files on disk do nothing until swanctl pushes them into charon. New deployments should skip the legacy tree entirely.
Where StrongSwan stores this, by platform
/etc/swanctl/swanctl.conf
Modern connection, secret, pool, and certificate tree loaded via swanctl commands. Legacy ipsec.conf setups live beside it during migration. Files take effect only after explicit load commands push them into the daemon.
Frequently asked questions
how do I add a StrongSwan connection
Edit swanctl.conf and included files under /etc/swanctl, then load with swanctl --load-conns and --load-creds. Certificates live in x509 and private subfolders beside the config. Validate syntax before restarting the daemon.
ipsec.conf vs swanctl.conf, which one
Keep both trees during migration: stroke reads ipsec.conf while vici reads swanctl.conf. New deployments should use swanctl only. The documented migration path converts stanza by stanza rather than by script.
where do certificates go
Store private keys under the private folder with strict permissions and reference them by filename in connections. CA certificates go in x509ca, endpoint certs in x509. The load-creds step pushes them into the daemon; files alone change nothing.
Notice an outdated path? Let us know.