-
-tls_require_ciphers = ${if eq{$sender_host_address}{HOSTIPV4}\
- {IDEA-CBC-MD5}{!RSA_AES_256:DES-CBC3-SHA}}
-
-# Set certificate only if server
-
-tls_certificate = ${if eq {SERVER}{server}{DIR/aux-fixed/cert1}fail}
-tls_privatekey = ${if eq {SERVER}{server}{DIR/aux-fixed/cert1}fail}
+tls_require_ciphers = NORMAL:-VERS-ALL:+VERS-TLS1.2:-MAC-ALL:+SHA256
+tls_certificate = DIR/aux-fixed/cert1