fixup! WIP: allow_insecure_tainted_data
[users/heiko/exim.git] / test / confs / 0900
index 6816ef8c9c86a498e480fd7f8478010794cd74e2..2409f395ec4b19b2e6708c0e99065fe8edfb45f0 100644 (file)
@@ -6,6 +6,7 @@ ALLOW=
 
 exim_path = EXIM_PATH
 keep_environment =
 
 exim_path = EXIM_PATH
 keep_environment =
+add_environment = SSLKEYLOGFILE=DIR/spool/sslkeys
 host_lookup_order = bydns
 spool_directory = DIR/spool
 log_file_path = DIR/spool/log/SERVER%slog
 host_lookup_order = bydns
 spool_directory = DIR/spool
 log_file_path = DIR/spool/log/SERVER%slog
@@ -13,6 +14,15 @@ gecos_pattern = ""
 gecos_name = CALLER_NAME
 chunking_advertise_hosts = *
 tls_advertise_hosts = ${if eq {SRV}{tls} {*}}
 gecos_name = CALLER_NAME
 chunking_advertise_hosts = *
 tls_advertise_hosts = ${if eq {SRV}{tls} {*}}
+.ifdef _HAVE_REQTLS
+tls_advertise_requiretls = :
+.endif
+.ifdef _HAVE_PIPE_CONNECT
+pipelining_connect_advertise_hosts = :
+.endif
+.ifdef _HAVE_DMARC
+dmarc_tld_file =
+.endif
 
 
 # ----- Main settings -----
 
 
 # ----- Main settings -----
@@ -26,10 +36,16 @@ acl_smtp_data = check_data
 trusted_users = CALLER
 queue_only
 smtp_receive_timeout = 2s
 trusted_users = CALLER
 queue_only
 smtp_receive_timeout = 2s
-log_selector = +received_recipients
 
 
-tls_certificate = ${if eq {SERVER}{server}{DIR/aux-fixed/cert1}fail}
-tls_privatekey = ${if eq {SERVER}{server}{DIR/aux-fixed/cert1}fail}
+.ifdef _HAVE_DKIM
+log_selector = +received_recipients +millisec +dkim_verbose
+.else
+log_selector = +received_recipients +millisec
+.endif
+
+.ifdef _OPT_MAIN_TLS_CERTIFICATE
+tls_certificate = DIR/aux-fixed/cert1
+.endif
 
 ALLOW
 
 
 ALLOW
 
@@ -57,7 +73,7 @@ begin routers
 to_server:
   driver = accept
   condition =  ${if !eq {SERVER}{server}}
 to_server:
   driver = accept
   condition =  ${if !eq {SERVER}{server}}
-  transport =  remote_smtp${if eq {OPT}{dkim} {_dkim}}
+  transport =  remote_smtp${if eq {SRV}{dkim} {_dkim}}
   errors_to =  ""
 
 fail_remote_domains:
   errors_to =  ""
 
 fail_remote_domains:
@@ -80,7 +96,7 @@ local_delivery:
   driver = appendfile
   delivery_date_add
   envelope_to_add
   driver = appendfile
   delivery_date_add
   envelope_to_add
-  file = DIR/test-mail/$local_part
+  file = DIR/test-mail/${bless:$local_part}
   headers_add = "X-body-linecount: $body_linecount\n\
                  X-message-linecount: $message_linecount\n\
                  X-received-count: $received_count"
   headers_add = "X-body-linecount: $body_linecount\n\
                  X-message-linecount: $message_linecount\n\
                  X-received-count: $received_count"
@@ -90,6 +106,9 @@ remote_smtp:
   driver = smtp
   hosts =      127.0.0.1
   port =       PORT_S
   driver = smtp
   hosts =      127.0.0.1
   port =       PORT_S
+  hosts_try_fastopen = :
+  tls_verify_certificates = DIR/aux-fixed/cert1
+  tls_verify_cert_hostnames =
   allow_localhost
   command_timeout = 2s
   final_timeout = 2s
   allow_localhost
   command_timeout = 2s
   final_timeout = 2s
@@ -98,11 +117,15 @@ remote_smtp_dkim:
   driver = smtp
   hosts =      127.0.0.1
   port =       PORT_S
   driver = smtp
   hosts =      127.0.0.1
   port =       PORT_S
+  hosts_try_fastopen = :
+  tls_verify_certificates = DIR/aux-fixed/cert1
+  tls_verify_cert_hostnames =
   allow_localhost
   command_timeout = 2s
   final_timeout = 2s
 
   allow_localhost
   command_timeout = 2s
   final_timeout = 2s
 
-.ifdef OPT
+.ifdef _HAVE_DKIM
+.ifdef SRV
   dkim_domain =                test.ex
   dkim_selector =      sel
   dkim_private_key =   DIR/aux-fixed/dkim/dkim.private
   dkim_domain =                test.ex
   dkim_selector =      sel
   dkim_private_key =   DIR/aux-fixed/dkim/dkim.private
@@ -110,6 +133,7 @@ remote_smtp_dkim:
   dkim_sign_headers =  LIST
 .endif
 .endif
   dkim_sign_headers =  LIST
 .endif
 .endif
+.endif
 
 # ----- Retry -----
 
 
 # ----- Retry -----