base.m4: Tweakable TLS parameters in `smtp' transport.
[exim-config] / exchange.m4
index 3e771c6..b0dab45 100644 (file)
 SECTION(global, daemon)m4_dnl
 daemon_smtp_ports = CONF_smtp_port : CONF_submission_port
 
-SECTION(global, tls)m4_dnl
-tls_certificate = CONF_sysconf_dir/server.cert
-tls_privatekey = CONF_sysconf_dir/server.key
-tls_advertise_hosts = *
-tls_dhparam = CONF_ca_dir/dh-param-2048.pem
-tls_require_ciphers = ${if or {{={$received_port}{CONF_submission_port}} \
-                              {match_ip {$sender_host_address}{+trusted}}} \
-                          {CONF_good_ciphers} \
-                          {CONF_acceptable_ciphers}}
-tls_verify_certificates = CONF_ca_dir/ca.cert
-tls_verify_hosts = ${if eq{$acl_c_mode}{submission} {} {+allnets}}
-
 DIVERT(null)
 ###--------------------------------------------------------------------------
 ### Check source addresses for apparently local senders.
@@ -47,12 +35,6 @@ SECTION(acl, mail-hooks)m4_dnl
        ## Check that a submitted message's sender address is allowable.
        require  acl = mail_client_addr
 
-       ## Insist that a local client connect through TLS.
-       deny     message = Hosts within CONF_master_domain must use TLS
-               !condition = ${if eq{$acl_c_mode}{submission}}
-                hosts = +allnets
-               !encrypted = *
-
 SECTION(acl, misc)m4_dnl
 mail_client_addr:
 
@@ -74,7 +56,7 @@ mail_client_addr:
                        RCLNTLSNDR \
                        Apparently local sender, but received from remote \
                        server.\n\t\
-                       sender=$sender_address, \
+                       sender=$sender_address \
                        host=$sender_host_address
 
        ## OK.