Add tls_verify_hosts and tls_try_verify_hosts to smtp transport, GnuTLS.
[exim.git] / test / confs / 5600
CommitLineData
f5d78688
JH
1# Exim test configuration 5600
2# OCSP stapling, server
3
4CRL=
5
6exim_path = EXIM_PATH
7host_lookup_order = bydns
8primary_hostname = server1.example.com
9rfc1413_query_timeout = 0s
10spool_directory = DIR/spool
11log_file_path = DIR/spool/log/%slog
12gecos_pattern = ""
13gecos_name = CALLER_NAME
14
15# ----- Main settings -----
16
17acl_smtp_rcpt = check_recipient
18
19log_selector = +tls_peerdn
20
21queue_only
22queue_run_in_order
23
24tls_advertise_hosts = *
25
26tls_certificate = DIR/aux-fixed/exim-ca/example.com/server1.example.com/server1.example.com.pem
27tls_privatekey = DIR/aux-fixed/exim-ca/example.com/server1.example.com/server1.example.com.unlocked.key
28
29tls_verify_hosts = HOSTIPV4
30tls_try_verify_hosts = *
31tls_verify_certificates = DIR/aux-fixed/cert2
32tls_crl = CRL
33tls_ocsp_file = OCSP
34
35
36# ------ ACL ------
37
38begin acl
39
40check_recipient:
41 deny message = certificate not verified: peerdn=$tls_peerdn
42 ! verify = certificate
43 accept
44
45
46# ----- Routers -----
47
48begin routers
49
50abc:
51 driver = accept
52 retry_use_local_part
53 transport = local_delivery
54
55
56# ----- Transports -----
57
58begin transports
59
60local_delivery:
61 driver = appendfile
62 file = DIR/test-mail/$local_part
63 headers_add = TLS: cipher=$tls_cipher peerdn=$tls_peerdn
64 user = CALLER
65
66# End