Use TLS by default on callouts/cutthroughs
[users/jgh/exim.git] / test / confs / 5840
index cd9e8b9c38e08420f4e952e379f8c2754cc8b7ae..4f468a3843c9c6e4178ab81e20a3084f0146e346 100644 (file)
@@ -13,7 +13,11 @@ gecos_name = CALLER_NAME
 
 # ----- Main settings -----
 
+.ifndef OPT
 acl_smtp_rcpt = accept
+.else
+acl_smtp_rcpt = accept verify = recipient/callout
+.endif
 
 log_selector =  +received_recipients +tls_peerdn +tls_certificate_verified
 
@@ -64,9 +68,6 @@ send_to_server:
 
   hosts_try_dane =     *
   hosts_require_dane = !thishost.test.ex
-  hosts_request_ocsp = ${if or { {= {4}{$tls_out_tlsa_usage}} \
-                                {= {0}{$tls_out_tlsa_usage}} } \
-                        {*}{}}
   tls_verify_cert_hostnames = ${if eq {OPT}{no_certname} {}{*}}
   tls_try_verify_hosts = thishost.test.ex
   tls_verify_certificates = CDIR2/ca_chain.pem