SLES-15-010036 - The SUSE operating system must use FIPS 140-3-approved cryptographic algorithms for IP tunnels.

Information

Overriding the systemwide cryptographic policy makes the behavior of the Libreswan service violate expectations and makes system configuration more fragmented.

Solution

Configure the SUSE operating system so that Libreswan uses the systemwide cryptographic policy.

Add the following line to "/etc/ipsec.conf":

include /etc/crypto-policies/back-ends/libreswan.config

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SLES_15_V2R8_STIG.zip