OpenSSL: better handling of $tls_{in,out}_certificate_verified under resumption
[users/heiko/exim.git] / test / confs / 4060
index dcc0ec2e726f44ebab8d157d2c452017f8459656..1916770731335d8a07f43f5efd6cc9a794691375 100644 (file)
@@ -23,9 +23,15 @@ chunking_advertise_hosts = OPT
 tls_advertise_hosts = *
 tls_certificate = ${if eq {SERVER}{server}{DIR/aux-fixed/cert1}fail}
 
+.ifdef _HAVE_DMARC
+dmarc_tld_file =
+.endif
+
 # Avoid ECDHE key-exchange so that we can wireshark-decode (not TLS1.3)
 .ifdef _HAVE_GNUTLS
 tls_require_ciphers = NORMAL:-KX-ALL:+RSA
+.else
+tls_require_ciphers = DEFAULT:!kECDHE
 .endif
 
 pipelining_connect_advertise_hosts = *