diff options
author | Jeremy Harris <jgh146exb@wizmail.org> | 2018-09-08 19:31:49 +0100 |
---|---|---|
committer | Jeremy Harris <jgh146exb@wizmail.org> | 2018-09-09 15:45:27 +0100 |
commit | 624f33dfeab938e907251e3cc3062aa45353384f (patch) | |
tree | 40a0ab340f82728d3460f4c0c42758b210fa056f /test/confs | |
parent | 2b8d6aff36a25e06f418aec9e90fe7668562914b (diff) |
DANE - testcase for fail under GnuTLS with TA-mode to a selfsigned server cert
Diffstat (limited to 'test/confs')
-rw-r--r-- | test/confs/5822 | 67 | ||||
-rw-r--r-- | test/confs/5842 | 64 |
2 files changed, 131 insertions, 0 deletions
diff --git a/test/confs/5822 b/test/confs/5822 new file mode 100644 index 000000000..80a8ef43b --- /dev/null +++ b/test/confs/5822 @@ -0,0 +1,67 @@ +# Exim test configuration 5822 +# DANE/GnuTLS + +SERVER= + +.include DIR/aux-var/tls_conf_prefix + +primary_hostname = myhost.test.ex + +# ----- Main settings ----- + +acl_smtp_rcpt = accept logwrite = "rcpt ACL" + +log_selector = +received_recipients +tls_peerdn +tls_certificate_verified + +queue_run_in_order + +tls_advertise_hosts = * +# needed to force generation +tls_dhparam = historic + +tls_certificate = ${if eq {SERVER}{server} {DIR/aux-fixed/cert1} fail} + +# ----- Routers ----- + +begin routers + +client: + driver = dnslookup + condition = ${if eq {SERVER}{}} + dnssec_request_domains = * + self = send + transport = send_to_server + errors_to = "" + +server: + driver = redirect + condition = ${if !eq {SERVER}{}} + data = :blackhole: + + +# ----- Transports ----- + +begin transports + +send_to_server: + driver = smtp + allow_localhost + port = PORT_D + + hosts_try_dane = * + hosts_require_dane = HOSTIPV4 + tls_verify_cert_hostnames = : + tls_try_verify_hosts = thishost.test.ex +# tls_verify_certificates = CDIR2/ca_chain.pem + + + +# ----- Retry ----- + + +begin retry + +* * F,5d,10s + + +# End diff --git a/test/confs/5842 b/test/confs/5842 new file mode 100644 index 000000000..be45e847c --- /dev/null +++ b/test/confs/5842 @@ -0,0 +1,64 @@ +# Exim test configuration 5822 +# DANE/OpenSSL + +SERVER= + +.include DIR/aux-var/tls_conf_prefix + +primary_hostname = myhost.test.ex + +# ----- Main settings ----- + +acl_smtp_rcpt = accept logwrite = "rcpt ACL" + +log_selector = +received_recipients +tls_peerdn +tls_certificate_verified + +queue_run_in_order + +tls_advertise_hosts = * + +tls_certificate = ${if eq {SERVER}{server} {DIR/aux-fixed/cert1} fail} + +# ----- Routers ----- + +begin routers + +client: + driver = dnslookup + condition = ${if eq {SERVER}{}} + dnssec_request_domains = * + self = send + transport = send_to_server + errors_to = "" + +server: + driver = redirect + data = :blackhole: + + +# ----- Transports ----- + +begin transports + +send_to_server: + driver = smtp + allow_localhost + port = PORT_D + + hosts_try_dane = * + hosts_require_dane = HOSTIPV4 + tls_verify_cert_hostnames = : + tls_try_verify_hosts = thishost.test.ex +# tls_verify_certificates = CDIR2/ca_chain.pem + + + +# ----- Retry ----- + + +begin retry + +* * F,5d,10s + + +# End |