chiark / gitweb /
distorted.lisp: Prepare for LetsEncrypt certificate on outward IMAP/SMTP.
Some SMTP TLS checking tools complain about the use of private
certificate authorities by public SMTP servers. And I must admit that,
while an SMTP server which uses an unverifiable certificate is much
better than one which doesn't try to use TLS at all, it's not as good as
it could be. So I want to use a LetsEncrypt certificate here. Prepare
for this by publishing the service public key hash in the TLSA records.