summaryrefslogtreecommitdiff
path: root/test/confs/5760
blob: e9868d109497f88506808458fae143d0417a789d (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
# Exim test configuration 5760 (dup of 5750)
# $tls_out_peercert - OpenSSL

SERVER=

exim_path = EXIM_PATH
host_lookup_order = bydns
primary_hostname = myhost.test.ex
rfc1413_query_timeout = 0s
spool_directory = DIR/spool
log_file_path = DIR/spool/log/SERVER%slog
gecos_pattern = ""
gecos_name = CALLER_NAME

# ----- Main settings -----

acl_smtp_rcpt = accept

log_selector =  +tls_peerdn

queue_only
queue_run_in_order

tls_advertise_hosts = *

tls_certificate = DIR/aux-fixed/exim-ca/example.com/server1.example.com/server1.example.com.pem
tls_privatekey = DIR/aux-fixed/exim-ca/example.com/server1.example.com/server1.example.com.unlocked.key

tls_verify_hosts = *
tls_verify_certificates = DIR/aux-fixed/exim-ca/example.com/server2.example.com/ca_chain.pem

#

begin acl
logger:
  warn   logwrite =  $acl_arg1 $tpda_delivery_local_part
  warn   logwrite =  ${if !def:tls_out_ourcert \
		{NO CLENT CERT presented} \
		{Our cert SN: ${certextract{subject}{$tls_out_ourcert}}}}
  accept condition = ${if !def:tls_out_peercert}
	 logwrite =  No Peer cert
  accept logwrite = Peer cert:
	 logwrite =  ver <${certextract {version}       {$tls_out_peercert}}>
	 logwrite =  SN  <${certextract {subject}       {$tls_out_peercert}}>
         logwrite =  IN  <${certextract {issuer}	{$tls_out_peercert}}>
         logwrite =  NB  <${certextract {notbefore}	{$tls_out_peercert}}>
         logwrite =  NA  <${certextract {notafter}	{$tls_out_peercert}}>
         logwrite =  SA  <${certextract {sig_algorithm} {$tls_out_peercert}}>
         logwrite =  SG  <${certextract {signature}	{$tls_out_peercert}}>
	 logwrite = ${certextract {subj_altname,>;}{$tls_out_peercert}{SAN <$value>}{(no SAN)}}
	 logwrite =       ${certextract {ocsp_uri}	{$tls_out_peercert} {OCU <$value>}{(no OCU)}}
	 logwrite =       ${certextract {crl_uri}	{$tls_out_peercert} {CRU <$value>}{(no CRU)}}


# ----- Routers -----

begin routers

client:
  driver = accept
  condition = ${if eq {SERVER}{server}{no}{yes}}
  retry_use_local_part
  transport = send_to_server


# ----- Transports -----

begin transports

send_to_server:
  driver = smtp
  allow_localhost
  hosts = 127.0.0.1
  port = PORT_D

  tls_certificate = DIR/aux-fixed/exim-ca/example.com/server2.example.com/server2.example.com.pem
  tls_privatekey = DIR/aux-fixed/exim-ca/example.com/server2.example.com/server2.example.com.unlocked.key

  tls_verify_certificates = DIR/aux-fixed/exim-ca/\
       ${if eq {$local_part}{good}\
{example.com/server1.example.com/ca_chain.pem}\
{example.net/server1.example.net/ca_chain.pem}}

  tpda_delivery_action =   ${acl {logger} {delivery} {$domain} }
  tpda_host_defer_action = ${acl {logger} {deferral} {$domain} }

# ----- Retry -----


begin retry

* * F,5d,10s


# End