fixup! WIP: allow_insecure_tainted_data
[users/heiko/exim.git] / test / confs / 0900
index df1540cfb523dd6e336c64b30034b1580e684256..2409f395ec4b19b2e6708c0e99065fe8edfb45f0 100644 (file)
@@ -6,6 +6,7 @@ ALLOW=
 
 exim_path = EXIM_PATH
 keep_environment =
 
 exim_path = EXIM_PATH
 keep_environment =
+add_environment = SSLKEYLOGFILE=DIR/spool/sslkeys
 host_lookup_order = bydns
 spool_directory = DIR/spool
 log_file_path = DIR/spool/log/SERVER%slog
 host_lookup_order = bydns
 spool_directory = DIR/spool
 log_file_path = DIR/spool/log/SERVER%slog
@@ -37,14 +38,13 @@ queue_only
 smtp_receive_timeout = 2s
 
 .ifdef _HAVE_DKIM
 smtp_receive_timeout = 2s
 
 .ifdef _HAVE_DKIM
-log_selector = +received_recipients +dkim_verbose
+log_selector = +received_recipients +millisec +dkim_verbose
 .else
 .else
-log_selector = +received_recipients
+log_selector = +received_recipients +millisec
 .endif
 
 .ifdef _OPT_MAIN_TLS_CERTIFICATE
 .endif
 
 .ifdef _OPT_MAIN_TLS_CERTIFICATE
-tls_certificate = ${if eq {SERVER}{server}{DIR/aux-fixed/cert1}fail}
-tls_privatekey = ${if eq {SERVER}{server}{DIR/aux-fixed/cert1}fail}
+tls_certificate = DIR/aux-fixed/cert1
 .endif
 
 ALLOW
 .endif
 
 ALLOW
@@ -107,6 +107,8 @@ remote_smtp:
   hosts =      127.0.0.1
   port =       PORT_S
   hosts_try_fastopen = :
   hosts =      127.0.0.1
   port =       PORT_S
   hosts_try_fastopen = :
+  tls_verify_certificates = DIR/aux-fixed/cert1
+  tls_verify_cert_hostnames =
   allow_localhost
   command_timeout = 2s
   final_timeout = 2s
   allow_localhost
   command_timeout = 2s
   final_timeout = 2s
@@ -116,6 +118,8 @@ remote_smtp_dkim:
   hosts =      127.0.0.1
   port =       PORT_S
   hosts_try_fastopen = :
   hosts =      127.0.0.1
   port =       PORT_S
   hosts_try_fastopen = :
+  tls_verify_certificates = DIR/aux-fixed/cert1
+  tls_verify_cert_hostnames =
   allow_localhost
   command_timeout = 2s
   final_timeout = 2s
   allow_localhost
   command_timeout = 2s
   final_timeout = 2s