Summary
The swanctl configuration supports an option named "send_cert" that can be set to "always" to force the server's certificate to be presented even if the client doesn't request it.
Use case
Enabling this option seems to be necessary to get Apple devices to successfully connect to an IKEv2 VPN.
Additional information
I initially worked around the issue using a post-commit hook, but now I've got a patch that I'd like to send upstream.