DANE: handle servefail for TLSA during Rverify. Bug 3030
[exim.git] / test / confs / 5803
1 # Exim test configuration 5801
2 # DANE common
3
4 SERVER=
5
6 .include DIR/aux-var/tls_conf_prefix
7
8 primary_hostname = myhost.test.ex
9
10 # ----- Main settings -----
11
12 acl_smtp_rcpt = accept verify = recipient/callout
13
14 log_selector =  +received_recipients +tls_certificate_verified +tls_sni
15
16 queue_run_in_order
17
18 tls_advertise_hosts = *
19 .ifdef _HAVE_GNUTLS
20 # needed to force generation
21 tls_dhparam = historic
22 .endif
23
24 CDIR1 = DIR/aux-fixed/exim-ca/example.net/server1.example.net
25 CDIR2 = DIR/aux-fixed/exim-ca/example.com/server1.example.com
26
27
28 tls_certificate = CDIR2/fullchain.pem
29 tls_privatekey =  CDIR2/server1.example.com.unlocked.key
30
31 # ----- Routers -----
32
33 begin routers
34
35 client:
36   driver =      dnslookup
37   condition =   ${if eq {SERVER}{}}
38   dnssec_request_domains = *
39   self =        send
40   transport =   send_to_server
41   errors_to =   ""
42
43 server:
44   driver =      redirect
45   data =        :blackhole:
46
47
48 # ----- Transports -----
49
50 begin transports
51
52 send_to_server:
53   driver =              smtp
54   allow_localhost
55   port =                PORT_D
56   hosts_try_fastopen =  :
57
58   hosts_try_dane =      *
59   tls_verify_certificates =
60
61
62
63 # ----- Retry -----
64
65
66 begin retry
67
68 * * F,5d,10s
69
70
71 # End