-SECTION(global, tls)m4_dnl
-tls_certificate = CONF_sysconf_dir/server.cert
-tls_privatekey = CONF_sysconf_dir/server.key
-tls_advertise_hosts = *
-tls_dhparam = CONF_ca_dir/dh-param.pem
-tls_require_ciphers = ${if or {{={$received_port}{CONF_submission_port}} \
- {match_ip {$sender_host_address}{+trusted}}} \
- {CONF_good_ciphers} \
- {CONF_acceptable_ciphers}}
-tls_verify_certificates = CONF_ca_dir/ca.cert
-tls_verify_hosts = ${if eq{$acl_c_mode}{submission} {} {+allnets}}
-