OpenSSL: Fix client-side tls_verify_cert_hostnames behaviour
[users/heiko/exim.git] / test / confs / 2127
1 # Exim test configuration 2127
2
3 SERVER =
4
5 .include DIR/aux-var/tls_conf_prefix
6
7 primary_hostname = myhost.test.ex
8
9 # ----- Main settings -----
10
11 acl_smtp_rcpt = accept
12
13 queue_only
14 queue_run_in_order
15
16 tls_advertise_hosts = *
17 tls_certificate = DIR/aux-fixed/cert1
18 tls_try_verify_hosts = 127.0.0.1
19 tls_verify_hosts = HOSTIPV4
20 tls_verify_certificates = DIR/aux-fixed/cert1
21
22 tls_require_ciphers = -ALL:kRSA
23 .ifdef _OPT_OPENSSL_NO_TLSV1_3_X
24 openssl_options = +no_tlsv1_3
25 .endif
26 # ----- Routers -----
27
28 begin routers
29
30 client:
31   driver = accept
32   condition = ${if eq {SERVER}{server}{no}{yes}}
33   retry_use_local_part
34   transport = send_to_server
35
36 server:
37   driver = accept
38   retry_use_local_part
39   transport = local_delivery
40
41
42 # ----- Transports -----
43
44 begin transports
45
46 local_delivery:
47   driver = appendfile
48   file = DIR/test-mail/${bless:$local_part}
49   headers_add = TLS: cipher=$tls_cipher peerdn=$tls_peerdn
50   user = CALLER
51
52 send_to_server:
53   driver = smtp
54   allow_localhost
55   hosts = ${if eq{$local_part}{userx}{127.0.0.1}{HOSTIPV4}}
56   port = PORT_D
57   hosts_try_fastopen =  :
58   tls_verify_certificates =     DIR/aux-fixed/cert1
59   tls_verify_cert_hostnames =   :
60
61 # End