DANE: fix TA-mode verify under GnuTLS. Bug 2311
[exim.git] / test / confs / 5651
index 19f16d03dd4f5e531e13096a78b7ca9f6cb7ced7..5803c3ce9e3706de2dd2e4466b9cf6f6eab7132e 100644 (file)
@@ -3,15 +3,9 @@
 
 SERVER =
 
 
 SERVER =
 
-exim_path = EXIM_PATH
-host_lookup_order = bydns
-primary_hostname = server1.example.com
-rfc1413_query_timeout = 0s
-spool_directory = DIR/spool
-log_file_path = DIR/spool/log/SERVER%slog
-gecos_pattern = ""
-gecos_name = CALLER_NAME
+.include DIR/aux-var/tls_conf_prefix
 
 
+primary_hostname = server1.example.com
 
 # ----- Main settings -----
 
 
 # ----- Main settings -----
 
@@ -35,7 +29,7 @@ tls_privatekey = ${if eq {SERVER}{server}\
 fail}
 
 # from cmdline define
 fail}
 
 # from cmdline define
-tls_ocsp_file = OCSP
+tls_ocsp_file = OPT
 
 
 # ------ ACL ------
 
 
 # ------ ACL ------
@@ -116,6 +110,7 @@ send_to_server3:
   helo_data = helo.data.changed
   #tls_verify_certificates = DIR/aux-fixed/exim-ca/example.com/server1.example.com/ca_chain.pem
   tls_verify_certificates = DIR/aux-fixed/exim-ca/example.com/CA/CA.pem
   helo_data = helo.data.changed
   #tls_verify_certificates = DIR/aux-fixed/exim-ca/example.com/server1.example.com/ca_chain.pem
   tls_verify_certificates = DIR/aux-fixed/exim-ca/example.com/CA/CA.pem
+  tls_try_verify_hosts =
   tls_verify_cert_hostnames =
   hosts_require_tls =  *
   hosts_require_ocsp = *
   tls_verify_cert_hostnames =
   hosts_require_tls =  *
   hosts_require_ocsp = *