> Maybe we *could* check if there is at least something configured for
> tls_{certificate,privatekey} and suppress the STARTTLS offer if these
> global options are missing (but continue to issue the warning.)
As a bystander here who may in the future be affected by this, I
think that this is a sensible answer to the overall problem. If Exim
knows that it can never successfully negociate TLS because nothing is
configured at all, not offering STARTTLS seems very sane and useful.
- cks