# TLS server: mandatory, optional, and revoked certificates gnutls munge gnutls_unexpected exim -DSERVER=server -bd -oX PORT_D **** # No certificate, certificate required client-gnutls HOSTIPV4 PORT_D ??? 220 ehlo rhu1.barb ??? 250- ??? 250- ??? 250- ??? 250- ??? 250- ??? 250 starttls ??? 220 **** # No certificate, certificate optional at TLS time, required by ACL client-gnutls 127.0.0.1 PORT_D ??? 220 ehlo rhu2.barb ??? 250- ??? 250- ??? 250- ??? 250- ??? 250- ??? 250 starttls ??? 220 helo rhu2tls.barb ??? 250 mail from: ??? 250 rcpt to: ??? 550 quit ??? 221 **** # Good certificate, certificate required client-gnutls HOSTIPV4 PORT_D aux-fixed/cert2 aux-fixed/cert2 ??? 220 ehlo rhu3.barb ??? 250- ??? 250- ??? 250- ??? 250- ??? 250- ??? 250 starttls ??? 220 mail from: ??? 250 rcpt to: ??? 250 quit ??? 221 **** # Good certificate, certificate optional at TLS time, checked by ACL client-gnutls 127.0.0.1 PORT_D aux-fixed/cert2 aux-fixed/cert2 ??? 220 ehlo rhu4.barb ??? 250- ??? 250- ??? 250- ??? 250- ??? 250- ??? 250 starttls ??? 220 mail from: ??? 250 rcpt to: ??? 250 quit ??? 221 **** # Bad certificate, certificate required client-gnutls HOSTIPV4 PORT_D aux-fixed/cert1 aux-fixed/cert1 ??? 220 ehlo rhu5.barb ??? 250- ??? 250- ??? 250- ??? 250- ??? 250- ??? 250 starttls ??? 220 **** # Bad certificate, certificate optional at TLS time, reject at ACL time client-gnutls 127.0.0.1 PORT_D aux-fixed/cert1 aux-fixed/cert1 ??? 220 ehlo rhu6.barb ??? 250- ??? 250- ??? 250- ??? 250- ??? 250- ??? 250 starttls ??? 220 mail from: ??? 250 rcpt to: ??? 550- ??? 550 quit ??? 221 **** killdaemon exim -DCRL=DIR/aux-fixed/crl.pem -DSERVER=server -bd -oX PORT_D **** # Good but revoked certificate, certificate required client-gnutls HOSTIPV4 PORT_D aux-fixed/cert2 aux-fixed/cert2 ??? 220 ehlo rhu7.barb ??? 250- ??? 250- ??? 250- ??? 250- ??? 250- ??? 250 starttls ??? 220 **** # Revoked certificate, certificate optional at TLS time, reject at ACL time client-gnutls 127.0.0.1 PORT_D aux-fixed/cert1 aux-fixed/cert1 ??? 220 ehlo rhu8.barb ??? 250- ??? 250- ??? 250- ??? 250- ??? 250- ??? 250 starttls ??? 220 mail from: ??? 250 rcpt to: ??? 550- ??? 550 quit ??? 221 **** killdaemon