I got something pretty close to work - it's not psk but certificate auth
+ xauth otp. From the strongswan logs it really looked like the
fortigate did xauth in a totally separate phase from phase1+phase2
because I would actually go further in the con...