diff --git a/.github/workflows/test_set_1.yml b/.github/workflows/test_set_1.yml
index 077479a..14f98ef 100644
--- a/.github/workflows/test_set_1.yml
+++ b/.github/workflows/test_set_1.yml
@@ -241,6 +241,7 @@ jobs:
           ls -ld /etc/ipsec.d/vpnclient.sswan
           ls -ld /etc/ipsec.d/vpnclient.p12
           pk12util -W "" -l /etc/ipsec.d/vpnclient.p12
+          pk12util -W "" -l /etc/ipsec.d/vpnclient.p12 | grep AES-256 && exit 1
 
           restart_ipsec
           grep pluto "$log1" | tail -n 20
@@ -258,6 +259,7 @@ jobs:
           ls -ld /etc/ipsec.d/vpnclient2.sswan
           ls -ld /etc/ipsec.d/vpnclient2.p12
           pk12util -W "" -l /etc/ipsec.d/vpnclient2.p12
+          pk12util -W "" -l /etc/ipsec.d/vpnclient2.p12 | grep AES-256 && exit 1
 
           rm -f /etc/ipsec.d/vpnclient2*
           bash ikev2.sh <<ANSWERS
@@ -270,6 +272,7 @@ jobs:
           ls -ld /etc/ipsec.d/vpnclient2.sswan
           ls -ld /etc/ipsec.d/vpnclient2.p12
           pk12util -W "" -l /etc/ipsec.d/vpnclient2.p12
+          pk12util -W "" -l /etc/ipsec.d/vpnclient2.p12 | grep AES-256 && exit 1
 
           bash ikev2.sh <<ANSWERS
           3
@@ -435,12 +438,15 @@ jobs:
           config_file="/etc/ipsec.d/.vpnconfig"
           p12_pw=$(grep -s '^IKEV2_CONFIG_PASSWORD=.\+' "$config_file" | tail -n 1 | cut -f2- -d= | sed -e "s/^'//" -e "s/'$//")
           pk12util -W "$p12_pw" -l /etc/ipsec.d/vpnclient.p12
+          pk12util -W "$p12_pw" -l /etc/ipsec.d/vpnclient.p12 | grep AES-256 && exit 1
 
           bash ikev2.sh --addclient vpnclient2
           pk12util -W "$p12_pw" -l /etc/ipsec.d/vpnclient2.p12
+          pk12util -W "$p12_pw" -l /etc/ipsec.d/vpnclient2.p12 | grep AES-256 && exit 1
 
           bash ikev2.sh --exportclient vpnclient2
           pk12util -W "$p12_pw" -l /etc/ipsec.d/vpnclient2.p12
+          pk12util -W "$p12_pw" -l /etc/ipsec.d/vpnclient2.p12 | grep AES-256 && exit 1
 
           bash ikev2.sh --removeikev2 <<ANSWERS
           y
diff --git a/.github/workflows/test_set_2.yml b/.github/workflows/test_set_2.yml
index 61a9c58..a394064 100644
--- a/.github/workflows/test_set_2.yml
+++ b/.github/workflows/test_set_2.yml
@@ -225,6 +225,7 @@ jobs:
           ls -ld /etc/ipsec.d/vpnclient.sswan
           ls -ld /etc/ipsec.d/vpnclient.p12
           pk12util -W "" -l /etc/ipsec.d/vpnclient.p12
+          pk12util -W "" -l /etc/ipsec.d/vpnclient.p12 | grep AES-256 && exit 1
 
           restart_ipsec
           grep pluto "$log1" | tail -n 20
@@ -242,6 +243,7 @@ jobs:
           ls -ld /etc/ipsec.d/vpnclient2.sswan
           ls -ld /etc/ipsec.d/vpnclient2.p12
           pk12util -W "" -l /etc/ipsec.d/vpnclient2.p12
+          pk12util -W "" -l /etc/ipsec.d/vpnclient2.p12 | grep AES-256 && exit 1
 
           rm -f /etc/ipsec.d/vpnclient2*
           bash ikev2.sh <<ANSWERS
@@ -254,6 +256,7 @@ jobs:
           ls -ld /etc/ipsec.d/vpnclient2.sswan
           ls -ld /etc/ipsec.d/vpnclient2.p12
           pk12util -W "" -l /etc/ipsec.d/vpnclient2.p12
+          pk12util -W "" -l /etc/ipsec.d/vpnclient2.p12 | grep AES-256 && exit 1
 
           bash ikev2.sh <<ANSWERS
           3
@@ -424,12 +427,15 @@ jobs:
           config_file="/etc/ipsec.d/.vpnconfig"
           p12_pw=$(grep -s '^IKEV2_CONFIG_PASSWORD=.\+' "$config_file" | tail -n 1 | cut -f2- -d= | sed -e "s/^'//" -e "s/'$//")
           pk12util -W "$p12_pw" -l /etc/ipsec.d/vpnclient.p12
+          pk12util -W "$p12_pw" -l /etc/ipsec.d/vpnclient.p12 | grep AES-256 && exit 1
 
           bash ikev2.sh --addclient vpnclient2
           pk12util -W "$p12_pw" -l /etc/ipsec.d/vpnclient2.p12
+          pk12util -W "$p12_pw" -l /etc/ipsec.d/vpnclient2.p12 | grep AES-256 && exit 1
 
           bash ikev2.sh --exportclient vpnclient2
           pk12util -W "$p12_pw" -l /etc/ipsec.d/vpnclient2.p12
+          pk12util -W "$p12_pw" -l /etc/ipsec.d/vpnclient2.p12 | grep AES-256 && exit 1
 
           bash ikev2.sh --removeikev2 <<ANSWERS
           y