X-Git-Url: https://www.chiark.greenend.org.uk/ucgi/~mdw/git/exim-config/blobdiff_plain/d411be33f6b1fe489a40a4566ee5b7073326075c..1dda4df9f8a4a6ff0d36ea1a7ee4648cb212e057:/config.m4 diff --git a/config.m4 b/config.m4 index 4678f20..db6b966 100644 --- a/config.m4 +++ b/config.m4 @@ -24,12 +24,23 @@ ## Master domain name. DEFCONF(master_domain, distorted.org.uk) +## List of home-system mail domain names. This can be empty if we only +## provide service for special-purpose domains. +DEFCONF(sysdomains, CONF_master_domain) + +## The magic token for local header names. +DEFCONF(header_token, Distorted) + ## The smarthost for satellite hosts. DEFCONF(smarthost, mail.distorted.org.uk) ## The user who runs verification filters. DEFCONF(filter_user, Debian-exim) +## Administrative groups. +DEFCONF(admin_groups, root : adm) +DEFCONF(trusted_groups, root : adm) + ## Where the spam filter is. DEFCONF(spamd_address, 172.29.199.179) DEFCONF(spamd_port, 783) @@ -37,6 +48,9 @@ DEFCONF(spamd_port, 783) ## Default spam limit for incoming mail (multiplied by ten). DEFCONF(spam_max, 50) +## Userv stuff for debugging. +DEFCONF(userv_opts, ) + ## Which interfaces to listen on. Exim checks for the literal string `::0' ## when setting things up: don't use `::', or we'll be tripped up by Linux's ## demented non-`IPV6_V6ONLY' behaviour. @@ -55,27 +69,50 @@ DEFCONF(alias_file, /etc/aliases) DEFCONF(ca_dir, /etc/ca) ## User address suffix handling. -DEFCONF(user_suffix_list, -* : +*) -DEFCONF(user_extaddr_regexp, $acl_c_user([-+@]|\$)) +DEFCONF(user_suffix_list, +* : -*) DEFCONF(user_extaddr_fixup, ${sg {$local_part_suffix}{^[-+]}{}}) ## Other hosts allowed to relay mail through us. -DEFCONF(relay_clients, +trusted) +DEFCONF(relay_clients, m4_dnl -:+VERS-TLS1.2:+VERS-TLS1.1<::>m4_dnl -:+DHE-RSA:+DHE-DSS<::>m4_dnl -:+AES-256-CBC:+AES-128-CBC<::>m4_dnl -:+SHA256<::>m4_dnl -:+SIGN-RSA-SHA512:+SIGN-RSA-SHA384:+SIGN-RSA-SHA256:+SIGN-DSA-SHA256<::>m4_dnl +:+VERS-TLS1.2:+VERS-TLS1.1:+VERS-TLS1.0<::>m4_dnl +:+ECDHE-RSA:+ECDHE-ECDSA:+DHE-RSA:+DHE-DSS<::>m4_dnl +:+CHACHA20-POLY1305<::>m4_dnl +:+AES-256-GCM:+AES-128-GCM:+AES-256-CBC:+AES-128-CBC<::>m4_dnl +:+AEAD:+SHA256:+SHA384:+SHA512<::>m4_dnl +:+SIGN-RSA-SHA512:+SIGN-RSA-SHA384:+SIGN-RSA-SHA256<::>m4_dnl +:+SIGN-ECDSA-SHA512:+SIGN-ECDSA-SHA384:+SIGN-ECDSA-SHA256<::>m4_dnl +:+SIGN-DSA-SHA256<::>m4_dnl +:+CURVE-X25519:+CURVE-SECP256R1:+CURVE-SECP521R1:+CURVE-SECP384R1<::>m4_dnl :+CTYPE-X.509<::>m4_dnl :+COMP-NULL<::>m4_dnl ) -DEFCONF(acceptable_ciphers, NORMAL<::>m4_dnl +DEFCONF(acceptable_ciphers, NONE<::>m4_dnl +:+VERS-TLS-ALL<::>m4_dnl +:+ECDHE-RSA:+ECDHE-ECDSA<::>m4_dnl +:+KX-ALL<::>m4_dnl +:+SIGN-ALL<::>m4_dnl +:+CTYPE-ALL<::>m4_dnl +:+CHACHA20-POLY1305<::>m4_dnl +:+AES-256-GCM:+AES-128-GCM<::>m4_dnl +:+CIPHER-ALL<::>m4_dnl +:+CURVE-X25519<::>m4_dnl +:+CURVE-ALL<::>m4_dnl +:+AEAD<::>m4_dnl +:+MAC-ALL<::>m4_dnl +:+COMP-NULL<::>m4_dnl :-MD5<::>m4_dnl )