| 1 | ### -*-m4-*- |
| 2 | ### |
| 3 | ### Basic configuration settings for distorted.org.uk Exim configuration |
| 4 | ### |
| 5 | ### (c) 2012 Mark Wooding |
| 6 | ### |
| 7 | |
| 8 | ###----- Licensing notice --------------------------------------------------- |
| 9 | ### |
| 10 | ### This program is free software; you can redistribute it and/or modify |
| 11 | ### it under the terms of the GNU General Public License as published by |
| 12 | ### the Free Software Foundation; either version 2 of the License, or |
| 13 | ### (at your option) any later version. |
| 14 | ### |
| 15 | ### This program is distributed in the hope that it will be useful, |
| 16 | ### but WITHOUT ANY WARRANTY; without even the implied warranty of |
| 17 | ### MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
| 18 | ### GNU General Public License for more details. |
| 19 | ### |
| 20 | ### You should have received a copy of the GNU General Public License |
| 21 | ### along with this program; if not, write to the Free Software Foundation, |
| 22 | ### Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA. |
| 23 | |
| 24 | ## Master domain name. |
| 25 | DEFCONF(master_domain, distorted.org.uk) |
| 26 | |
| 27 | ## The smarthost for satellite hosts. |
| 28 | DEFCONF(smarthost, mail.distorted.org.uk) |
| 29 | |
| 30 | ## The user who runs verification filters. |
| 31 | DEFCONF(filter_user, Debian-exim) |
| 32 | |
| 33 | ## Administrative groups. |
| 34 | DEFCONF(admin_groups, root : adm) |
| 35 | |
| 36 | ## Where the spam filter is. |
| 37 | DEFCONF(spamd_address, 172.29.199.179) |
| 38 | DEFCONF(spamd_port, 783) |
| 39 | |
| 40 | ## Default spam limit for incoming mail (multiplied by ten). |
| 41 | DEFCONF(spam_max, 50) |
| 42 | |
| 43 | ## Userv stuff for debugging. |
| 44 | DEFCONF(userv_opts, ) |
| 45 | |
| 46 | ## Which interfaces to listen on. Exim checks for the literal string `::0' |
| 47 | ## when setting things up: don't use `::', or we'll be tripped up by Linux's |
| 48 | ## demented non-`IPV6_V6ONLY' behaviour. |
| 49 | DEFCONF(interfaces, m4_ifelse(MODE, satellite, 127.0.0.1 ; ::1, |
| 50 | 0.0.0.0 ; ::0)) |
| 51 | |
| 52 | ## Main and submission port numbers. (This is sometimes tweaked for |
| 53 | ## testing.) |
| 54 | DEFCONF(smtp_port, 25) |
| 55 | DEFCONF(submission_port, 587) |
| 56 | |
| 57 | ## Locations of other configuration files. |
| 58 | DEFCONF(sysconf_dir, /etc/mail) |
| 59 | DEFCONF(userconf_dir, $home/.mail) |
| 60 | DEFCONF(alias_file, /etc/aliases) |
| 61 | DEFCONF(ca_dir, /etc/ca) |
| 62 | |
| 63 | ## User address suffix handling. |
| 64 | DEFCONF(user_suffix_list, +* : -*) |
| 65 | DEFCONF(user_extaddr_regexp, $acl_c_user([-+@]|\$)) |
| 66 | DEFCONF(user_extaddr_fixup, ${sg {$local_part_suffix}{^[-+]}{}}) |
| 67 | |
| 68 | ## Other hosts allowed to relay mail through us. |
| 69 | DEFCONF(relay_clients, +trusted) |
| 70 | |
| 71 | ## TLS-related settings. We're assuming GNUTLS here, rather than OpenSSL. |
| 72 | ## For local connections we are very strict. For random clients, we try |
| 73 | ## fairly hard to encourage any kind of crypto on the grounds that probably |
| 74 | ## nobody can verify our certificate anyway. |
| 75 | DEFCONF(good_ciphers, NONE<::>m4_dnl |
| 76 | :+VERS-TLS1.2:+VERS-TLS1.1:+VERS-TLS1.0<::>m4_dnl |
| 77 | :+DHE-RSA:+DHE-DSS<::>m4_dnl |
| 78 | :+AES-256-CBC:+AES-128-CBC<::>m4_dnl |
| 79 | :+SHA256:+SHA384:+SHA512:+SHA1<::>m4_dnl |
| 80 | :+SIGN-RSA-SHA512:+SIGN-RSA-SHA384:+SIGN-RSA-SHA256:+SIGN-DSA-SHA256<::>m4_dnl |
| 81 | :+CTYPE-X.509<::>m4_dnl |
| 82 | :+COMP-NULL<::>m4_dnl |
| 83 | ) |
| 84 | DEFCONF(acceptable_ciphers, NORMAL<::>m4_dnl |
| 85 | :-MD5<::>m4_dnl |
| 86 | ) |
| 87 | |
| 88 | ###----- That's all, folks -------------------------------------------------- |