diff options
author | Jeremy Harris <jgh146exb@wizmail.org> | 2014-05-06 14:44:21 +0100 |
---|---|---|
committer | Jeremy Harris <jgh146exb@wizmail.org> | 2014-05-06 22:40:45 +0100 |
commit | 4466248715466b6f251454283642b74de65e9d9a (patch) | |
tree | 487f21c1e0aa2c02c8d6ce5a21aa83b1f258ddaa /test/confs/5651 | |
parent | 65867078f62db450bd8f91100600f6de559e7590 (diff) |
OCSP observability: variables $tls_{in,out}_ocsp
and smtp transport option hosts_request_ocsp
Diffstat (limited to 'test/confs/5651')
-rw-r--r-- | test/confs/5651 | 29 |
1 files changed, 25 insertions, 4 deletions
diff --git a/test/confs/5651 b/test/confs/5651 index e38043f3e..4a1989f43 100644 --- a/test/confs/5651 +++ b/test/confs/5651 @@ -18,6 +18,8 @@ gecos_name = CALLER_NAME domainlist local_domains = test.ex : *.test.ex acl_smtp_rcpt = check_recipient +acl_smtp_data = check_data + log_selector = +tls_peerdn remote_max_parallel = 1 @@ -44,6 +46,11 @@ check_recipient: accept domains = +local_domains deny message = relay not permitted +check_data: + warn condition = ${if def:h_X-TLS-out:} + logwrite = client claims: $h_X-TLS-out: + accept + # ----- Routers ----- @@ -54,8 +61,9 @@ client: condition = ${if eq {SERVER}{server}{no}{yes}} retry_use_local_part transport = send_to_server${if eq{$local_part}{nostaple}{1} \ - {${if eq{$local_part}{smtps} {3}{2}}} \ - } + {${if eq{$local_part}{norequire} {2} \ + {${if eq{$local_part}{smtps} {4}{3}}} \ + }}} server: driver = redirect @@ -81,11 +89,22 @@ send_to_server1: port = PORT_D tls_verify_certificates = DIR/aux-fixed/exim-ca/example.com/CA/CA.pem hosts_require_tls = * -# note no ocsp here + hosts_request_ocsp = : + headers_add = X-TLS-out: OCSP status $tls_out_ocsp send_to_server2: driver = smtp allow_localhost + hosts = HOSTIPV4 + port = PORT_D + tls_verify_certificates = DIR/aux-fixed/exim-ca/example.com/CA/CA.pem + hosts_require_tls = * +# note no ocsp mention here + headers_add = X-TLS-out: OCSP status $tls_out_ocsp + +send_to_server3: + driver = smtp + allow_localhost hosts = 127.0.0.1 port = PORT_D helo_data = helo.data.changed @@ -93,8 +112,9 @@ send_to_server2: tls_verify_certificates = DIR/aux-fixed/exim-ca/example.com/CA/CA.pem hosts_require_tls = * hosts_require_ocsp = * + headers_add = X-TLS-out: OCSP status $tls_out_ocsp -send_to_server3: +send_to_server4: driver = smtp allow_localhost hosts = 127.0.0.1 @@ -105,6 +125,7 @@ send_to_server3: protocol = smtps hosts_require_tls = * hosts_require_ocsp = * + headers_add = X-TLS-out: OCSP status $tls_out_ocsp # ----- Retry ----- |