@saper Auth wouldn't work until I encoded the host name in the subject alternative name. Strongswan seemed to ignore the CN field.