summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorJeremy Harris <jgh146exb@wizmail.org>2020-05-19 01:28:29 +0100
committerJeremy Harris <jgh146exb@wizmail.org>2020-05-19 01:28:29 +0100
commit4bd2a7f8dd85114f85e33e9e21158d6a3c127687 (patch)
treebd90d32c2298f35697697f7a44ec0f35b8bd6026
parent3db72f4b639a64cacf152e4f7718a18581426b10 (diff)
better guards
-rw-r--r--src/src/configure.default6
1 files changed, 5 insertions, 1 deletions
diff --git a/src/src/configure.default b/src/src/configure.default
index 7d54e11eb..733a37615 100644
--- a/src/src/configure.default
+++ b/src/src/configure.default
@@ -176,7 +176,9 @@ tls_require_ciphers = ECDSA:RSA:!COMPLEMENTOFDEFAULT
# Don't offer resumption to (most) MUAs, who we don't want to reuse
# tickets. Once the TLS extension for vended ticket numbers comes
# though, re-examine since resumption on a single-use ticket is still a benefit.
+.ifdef _HAVE_TLS_RESUME
tls_resumption_hosts = ${if inlist {$received_port}{587:465} {:}{*}}
+.endif
# In order to support roaming users who wish to send email from anywhere,
# you may want to make Exim listen on other ports as well as port 25, in
@@ -811,7 +813,7 @@ begin transports
remote_smtp:
driver = smtp
-.ifdef _HAVE_TLS
+.ifdef _HAVE_TLS_RESUME
tls_resumption_hosts = *
#endif
.ifdef _HAVE_PRDR
@@ -853,8 +855,10 @@ smarthost_smtp:
.ifdef _HAVE_GNUTLS
tls_require_ciphers = SECURE192:-VERS-SSL3.0:-VERS-TLS1.0:-VERS-TLS1.1
.endif
+.ifdef _HAVE_TLS_RESUME
tls_resumption_hosts = *
.endif
+.endif
.ifdef _HAVE_PRDR
hosts_try_prdr = *
.endif