)
## TLS certificate list.
-DEFCONF(certlist, CONF_sysconf_dir/server.certlist)
+DEFCONF(certlist,
+<:m4_ifelse(t, m4_ifelse(MODE, hub, nil, MODE, srv, nil, t),
+<:CONF_sysconf_dir/server.certlist:>,
+<:CONF_sysconf_dir/${if match_ip{$sender_host_address}{+trusted} \
+ {server}{letsencrypt}}.certlist:>):>)
## TLS-related settings. We're assuming GNUTLS here, rather than OpenSSL.
## For local connections we are very strict. For random clients, we try