Skip to main content
Ubuntu confines charon with AppArmor. Add the installed Futurex paths before you restart strongSwan.

Add the local policy

The temporary PEM rules allow FxChlibs to prepare its client-authentication material during module initialization.

Reload and verify the policy

The final command must not return a denial for a Futurex module, configuration, TLS, log, or temporary authentication path.
If you install the endpoint unit in different directories, add those exact paths to the local override. Do not copy the example paths without matching your installation.