[exim-cvs] OpenSSL: fix tls_out_ocsp under resumption

Inizio della pagina
Delete this message
Reply to this message
Autore: Exim Git Commits Mailing List
Data:  
To: exim-cvs
Oggetto: [exim-cvs] OpenSSL: fix tls_out_ocsp under resumption
Gitweb: https://git.exim.org/exim.git/commitdiff/c82de233a9bf264bb0db7ae72b2aa6da62ade2f0
Commit:     c82de233a9bf264bb0db7ae72b2aa6da62ade2f0
Parent:     f4e62a871680af98f14beb5f21dbe3b85c5c35ff
Author:     Jeremy Harris <jgh146exb@???>
AuthorDate: Tue May 7 22:17:28 2019 +0100
Committer:  Jeremy Harris <jgh146exb@???>
CommitDate: Tue May 7 22:45:51 2019 +0100


    OpenSSL: fix tls_out_ocsp under resumption
---
 src/src/dbstuff.h     |   3 +-
 src/src/tls-openssl.c |  24 ++++---
 test/confs/5890       |  14 ++--
 test/confs/5891       |  14 ++--
 test/log/5890         | 136 ++++++++++++++++++-------------------
 test/log/5891         | 182 +++++++++++++++++++++++++-------------------------
 6 files changed, 192 insertions(+), 181 deletions(-)


diff --git a/src/src/dbstuff.h b/src/src/dbstuff.h
index 227de39..58154d7 100644
--- a/src/src/dbstuff.h
+++ b/src/src/dbstuff.h
@@ -807,7 +807,8 @@ typedef struct {
typedef struct {
time_t time_stamp;
/*************/
- uschar verify_override;
+ uschar verify_override:1;
+ uschar ocsp:3;
uschar session[1];
} dbdata_tls_session;

diff --git a/src/src/tls-openssl.c b/src/src/tls-openssl.c
index 39e7fc8..4cf9863 100644
--- a/src/src/tls-openssl.c
+++ b/src/src/tls-openssl.c
@@ -1715,17 +1715,17 @@ if(!p)
return cbinfo->u_ocsp.client.verify_required ? 0 : 1;
}

-if(!(rsp = d2i_OCSP_RESPONSE(NULL, &p, len)))
- {
-  tls_out.ocsp = OCSP_FAILED;
+if (!(rsp = d2i_OCSP_RESPONSE(NULL, &p, len)))
+  {
+  tls_out.ocsp = OCSP_FAILED;    /*XXX should use tlsp-> to permit concurrent outbound */
   if (LOGGING(tls_cipher))
     log_write(0, LOG_MAIN, "Received TLS cert status response, parse error");
   else
     DEBUG(D_tls) debug_printf(" parse error\n");
   return 0;
- }
+  }


-if(!(bs = OCSP_response_get1_basic(rsp)))
+if (!(bs = OCSP_response_get1_basic(rsp)))
   {
   tls_out.ocsp = OCSP_FAILED;
   if (LOGGING(tls_cipher))
@@ -2759,6 +2759,7 @@ if (tlsp->host_resumable)
     DEBUG(D_tls) debug_printf("good session\n");
     tlsp->resumption |= RESUME_CLIENT_SUGGESTED;
     tlsp->verify_override = dt->verify_override;
+    tlsp->ocsp = dt->ocsp;
     }
       }
     else
@@ -2795,6 +2796,7 @@ if (SSL_SESSION_is_resumable(ss))     /* 1.1.1 */
   tlsp->resumption |= RESUME_SERVER_TICKET;    /* server gave us a ticket */


   dt->verify_override = tlsp->verify_override;
+  dt->ocsp = tlsp->ocsp;
   (void) i2d_SSL_SESSION(ss, &s);        /* s gets bumped to end */


if ((dbm_file = dbfn_open(US"tls", O_RDWR, &dbblock, FALSE, FALSE)))
@@ -3024,12 +3026,6 @@ if (!(exim_client_ctx->ssl = SSL_new(exim_client_ctx->ctx)))
}
SSL_set_session_id_context(exim_client_ctx->ssl, sid_ctx, Ustrlen(sid_ctx));

-#ifdef EXPERIMENTAL_TLS_RESUME
-if (!tls_client_ssl_resume_prehandshake(exim_client_ctx->ssl, tlsp, host,
-      errstr))
-  return FALSE;
-#endif
-
 SSL_set_fd(exim_client_ctx->ssl, cctx->sock);
 SSL_set_connect_state(exim_client_ctx->ssl);


@@ -3089,6 +3085,12 @@ if (request_ocsp)
}
#endif

+#ifdef EXPERIMENTAL_TLS_RESUME
+if (!tls_client_ssl_resume_prehandshake(exim_client_ctx->ssl, tlsp, host,
+      errstr))
+  return FALSE;
+#endif
+
 #ifndef DISABLE_EVENT
 client_static_cbinfo->event_action = tb ? tb->event_action : NULL;
 #endif
diff --git a/test/confs/5890 b/test/confs/5890
index a836802..f1aa9a2 100644
--- a/test/confs/5890
+++ b/test/confs/5890
@@ -19,7 +19,11 @@ tls_advertise_hosts = *


# Set certificate only if server

-tls_certificate = ${if eq {SERVER}{server}{DIR/aux-fixed/cert1}fail}
+CDIR=DIR/aux-fixed/exim-ca/example.com
+
+tls_certificate = CDIR/server1.example.com/server1.example.com.chain.pem
+tls_privatekey = CDIR/server1.example.com/server1.example.com.unlocked.key
+tls_ocsp_file = CDIR/server1.example.com/server1.example.com.ocsp.good.resp

 tls_require_ciphers = OPTION
 tls_resumption_hosts = 127.0.0.1
@@ -86,7 +90,7 @@ send_to_server1:
 .else
   tls_resumption_hosts =    :
 .endif
-  tls_verify_certificates =    DIR/aux-fixed/cert1
+  tls_verify_certificates =    CDIR/CA/CA.pem
   tls_verify_cert_hostnames =    ${if match {$local_part}{^noverify} {*}{:}}
   tls_try_verify_hosts =    *
   event_action =        ${acl {log_resumption}}
@@ -96,9 +100,9 @@ send_to_server2:
   allow_localhost
   hosts = HOSTIPV4
   port = PORT_D
-  tls_verify_certificates = DIR/aux-fixed/cert1
-  tls_verify_cert_hostnames = :
-  event_action =    ${acl {log_resumption}}
+  tls_verify_certificates =    CDIR/CA/CA.pem
+  tls_verify_cert_hostnames =    :
+  event_action =        ${acl {log_resumption}}



# ----- Retry -----
diff --git a/test/confs/5891 b/test/confs/5891
index 165921d..190ce25 100644
--- a/test/confs/5891
+++ b/test/confs/5891
@@ -20,7 +20,11 @@ tls_advertise_hosts = *

# Set certificate only if server

-tls_certificate = ${if eq {SERVER}{server}{DIR/aux-fixed/cert1}fail}
+CDIR=DIR/aux-fixed/exim-ca/example.com
+
+tls_certificate = CDIR/server1.example.com/server1.example.com.chain.pem
+tls_privatekey = CDIR/server1.example.com/server1.example.com.unlocked.key
+tls_ocsp_file = CDIR/server1.example.com/server1.example.com.ocsp.good.resp

tls_resumption_hosts = 127.0.0.1

@@ -86,7 +90,7 @@ send_to_server1:
 .else
   tls_resumption_hosts =    :
 .endif
-  tls_verify_certificates =    DIR/aux-fixed/cert1
+  tls_verify_certificates =    CDIR/CA/CA.pem
   tls_verify_cert_hostnames =    ${if match {$local_part}{^noverify} {*}{:}}
   tls_try_verify_hosts =    *
   event_action =        ${acl {log_resumption}}
@@ -96,9 +100,9 @@ send_to_server2:
   allow_localhost
   hosts = HOSTIPV4
   port = PORT_D
-  tls_verify_certificates = DIR/aux-fixed/cert1
-  tls_verify_cert_hostnames = :
-  event_action =    ${acl {log_resumption}}
+  tls_verify_certificates =    CDIR/CA/CA.pem
+  tls_verify_cert_hostnames =    :
+  event_action =        ${acl {log_resumption}}



 # ----- Retry -----
diff --git a/test/log/5890 b/test/log/5890
index b8a4d44..17ae494 100644
--- a/test/log/5890
+++ b/test/log/5890
@@ -1,186 +1,186 @@
 1999-03-02 09:44:33 10HmaX-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for getticket@???
 1999-03-02 09:44:33 10HmaX-0005vi-00 tls_out_resumption client requested new ticket, server provided
 1999-03-02 09:44:33 10HmaX-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmaX-0005vi-00 peer cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmaX-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmaX-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmaX-0005vi-00 peer dn    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmaX-0005vi-00 peer dn    CN=server1.example.com
 1999-03-02 09:44:33 10HmaX-0005vi-00 ocsp    1
 1999-03-02 09:44:33 10HmaX-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmaX-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmaX-0005vi-00 => getticket@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock" C="250 OK id=10HmaY-0005vi-00"
+1999-03-02 09:44:33 10HmaX-0005vi-00 => getticket@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="CN=server1.example.com" C="250 OK id=10HmaY-0005vi-00"
 1999-03-02 09:44:33 10HmaX-0005vi-00 Completed
 1999-03-02 09:44:33 10HmaZ-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for resume@??? abcd@??? xyz@???
 1999-03-02 09:44:33 10HmaZ-0005vi-00 tls_out_resumption session resumed
 1999-03-02 09:44:33 10HmaZ-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmaZ-0005vi-00 peer cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmaZ-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmaZ-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmaZ-0005vi-00 peer dn    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmaZ-0005vi-00 peer dn    CN=server1.example.com
 1999-03-02 09:44:33 10HmaZ-0005vi-00 ocsp    1
 1999-03-02 09:44:33 10HmaZ-0005vi-00 cipher    TLS1.x:ke--AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmaZ-0005vi-00 bits    256
 1999-03-02 09:44:33 10HmaZ-0005vi-00 tls_out_resumption not requested or offered
 1999-03-02 09:44:33 10HmaZ-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmaZ-0005vi-00 peer cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmaZ-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmaZ-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmaZ-0005vi-00 peer dn    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmaZ-0005vi-00 peer dn    CN=server1.example.com
 1999-03-02 09:44:33 10HmaZ-0005vi-00 ocsp    1
 1999-03-02 09:44:33 10HmaZ-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmaZ-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmaZ-0005vi-00 => resume@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke--AES256-SHAnnn:xxx* CV=yes DN="C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock" C="250 OK id=10HmbA-0005vi-00"
-1999-03-02 09:44:33 10HmaZ-0005vi-00 -> xyz@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke--AES256-SHAnnn:xxx* CV=yes DN="C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock" C="250 OK id=10HmbA-0005vi-00"
-1999-03-02 09:44:33 10HmaZ-0005vi-00 => abcd@??? R=client T=send_to_server2 H=ip4.ip4.ip4.ip4 [ip4.ip4.ip4.ip4] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock" C="250 OK id=10HmbB-0005vi-00"
+1999-03-02 09:44:33 10HmaZ-0005vi-00 => resume@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke--AES256-SHAnnn:xxx* CV=yes DN="CN=server1.example.com" C="250 OK id=10HmbA-0005vi-00"
+1999-03-02 09:44:33 10HmaZ-0005vi-00 -> xyz@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke--AES256-SHAnnn:xxx* CV=yes DN="CN=server1.example.com" C="250 OK id=10HmbA-0005vi-00"
+1999-03-02 09:44:33 10HmaZ-0005vi-00 => abcd@??? R=client T=send_to_server2 H=ip4.ip4.ip4.ip4 [ip4.ip4.ip4.ip4] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="CN=server1.example.com" C="250 OK id=10HmbB-0005vi-00"
 1999-03-02 09:44:33 10HmaZ-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbC-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for renewal@???
 1999-03-02 09:44:33 10HmbC-0005vi-00 tls_out_resumption session resumed
 1999-03-02 09:44:33 10HmbC-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbC-0005vi-00 peer cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbC-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbC-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbC-0005vi-00 peer dn    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbC-0005vi-00 peer dn    CN=server1.example.com
 1999-03-02 09:44:33 10HmbC-0005vi-00 ocsp    1
 1999-03-02 09:44:33 10HmbC-0005vi-00 cipher    TLS1.x:ke--AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbC-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbC-0005vi-00 => renewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke--AES256-SHAnnn:xxx* CV=yes DN="C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock" C="250 OK id=10HmbD-0005vi-00"
+1999-03-02 09:44:33 10HmbC-0005vi-00 => renewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke--AES256-SHAnnn:xxx* CV=yes DN="CN=server1.example.com" C="250 OK id=10HmbD-0005vi-00"
 1999-03-02 09:44:33 10HmbC-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbE-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for postrenewal@???
 1999-03-02 09:44:33 10HmbE-0005vi-00 tls_out_resumption session resumed
 1999-03-02 09:44:33 10HmbE-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbE-0005vi-00 peer cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbE-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbE-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbE-0005vi-00 peer dn    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbE-0005vi-00 peer dn    CN=server1.example.com
 1999-03-02 09:44:33 10HmbE-0005vi-00 ocsp    1
 1999-03-02 09:44:33 10HmbE-0005vi-00 cipher    TLS1.x:ke--AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbE-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbE-0005vi-00 => postrenewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke--AES256-SHAnnn:xxx* CV=yes DN="C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock" C="250 OK id=10HmbF-0005vi-00"
+1999-03-02 09:44:33 10HmbE-0005vi-00 => postrenewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke--AES256-SHAnnn:xxx* CV=yes DN="CN=server1.example.com" C="250 OK id=10HmbF-0005vi-00"
 1999-03-02 09:44:33 10HmbE-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbG-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for timeout@???
 1999-03-02 09:44:33 10HmbG-0005vi-00 tls_out_resumption client offered session, server only provided new ticket
 1999-03-02 09:44:33 10HmbG-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbG-0005vi-00 peer cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbG-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbG-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbG-0005vi-00 peer dn    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbG-0005vi-00 peer dn    CN=server1.example.com
 1999-03-02 09:44:33 10HmbG-0005vi-00 ocsp    1
 1999-03-02 09:44:33 10HmbG-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbG-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbG-0005vi-00 => timeout@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock" C="250 OK id=10HmbH-0005vi-00"
+1999-03-02 09:44:33 10HmbG-0005vi-00 => timeout@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="CN=server1.example.com" C="250 OK id=10HmbH-0005vi-00"
 1999-03-02 09:44:33 10HmbG-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbI-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for notreq@???
 1999-03-02 09:44:33 10HmbI-0005vi-00 tls_out_resumption no client request
 1999-03-02 09:44:33 10HmbI-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbI-0005vi-00 peer cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbI-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbI-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbI-0005vi-00 peer dn    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbI-0005vi-00 peer dn    CN=server1.example.com
 1999-03-02 09:44:33 10HmbI-0005vi-00 ocsp    1
 1999-03-02 09:44:33 10HmbI-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbI-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbI-0005vi-00 => notreq@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock" C="250 OK id=10HmbJ-0005vi-00"
+1999-03-02 09:44:33 10HmbI-0005vi-00 => notreq@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="CN=server1.example.com" C="250 OK id=10HmbJ-0005vi-00"
 1999-03-02 09:44:33 10HmbI-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbK-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for noverify_getticket@???
 1999-03-02 09:44:33 10HmbK-0005vi-00 tls_out_resumption client requested new ticket, server provided
 1999-03-02 09:44:33 10HmbK-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbK-0005vi-00 peer cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbK-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbK-0005vi-00 peer cert verified    0
-1999-03-02 09:44:33 10HmbK-0005vi-00 peer dn    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbK-0005vi-00 peer dn    CN=server1.example.com
 1999-03-02 09:44:33 10HmbK-0005vi-00 ocsp    1
 1999-03-02 09:44:33 10HmbK-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbK-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbK-0005vi-00 => noverify_getticket@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no DN="C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock" C="250 OK id=10HmbL-0005vi-00"
+1999-03-02 09:44:33 10HmbK-0005vi-00 => noverify_getticket@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no DN="CN=server1.example.com" C="250 OK id=10HmbL-0005vi-00"
 1999-03-02 09:44:33 10HmbK-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbM-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for noverify_resume@???
 1999-03-02 09:44:33 10HmbM-0005vi-00 tls_out_resumption session resumed
 1999-03-02 09:44:33 10HmbM-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbM-0005vi-00 peer cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbM-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbM-0005vi-00 peer cert verified    0
-1999-03-02 09:44:33 10HmbM-0005vi-00 peer dn    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbM-0005vi-00 peer dn    CN=server1.example.com
 1999-03-02 09:44:33 10HmbM-0005vi-00 ocsp    1
 1999-03-02 09:44:33 10HmbM-0005vi-00 cipher    TLS1.x:ke--AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbM-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbM-0005vi-00 => noverify_resume@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke--AES256-SHAnnn:xxx* CV=no DN="C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock" C="250 OK id=10HmbN-0005vi-00"
+1999-03-02 09:44:33 10HmbM-0005vi-00 => noverify_resume@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke--AES256-SHAnnn:xxx* CV=no DN="CN=server1.example.com" C="250 OK id=10HmbN-0005vi-00"
 1999-03-02 09:44:33 10HmbM-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbO-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for getticket@???
 1999-03-02 09:44:33 10HmbO-0005vi-00 tls_out_resumption client requested new ticket, server provided
 1999-03-02 09:44:33 10HmbO-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbO-0005vi-00 peer cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbO-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbO-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbO-0005vi-00 peer dn    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbO-0005vi-00 peer dn    CN=server1.example.com
 1999-03-02 09:44:33 10HmbO-0005vi-00 ocsp    1
 1999-03-02 09:44:33 10HmbO-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbO-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbO-0005vi-00 => getticket@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock" C="250 OK id=10HmbP-0005vi-00"
+1999-03-02 09:44:33 10HmbO-0005vi-00 => getticket@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="CN=server1.example.com" C="250 OK id=10HmbP-0005vi-00"
 1999-03-02 09:44:33 10HmbO-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbQ-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for resume@??? abcd@??? xyz@???
 1999-03-02 09:44:33 10HmbQ-0005vi-00 tls_out_resumption session resumed, also new ticket
 1999-03-02 09:44:33 10HmbQ-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbQ-0005vi-00 peer cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbQ-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbQ-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbQ-0005vi-00 peer dn    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbQ-0005vi-00 peer dn    CN=server1.example.com
 1999-03-02 09:44:33 10HmbQ-0005vi-00 ocsp    1
 1999-03-02 09:44:33 10HmbQ-0005vi-00 cipher    TLS1.x:ke-PSK-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbQ-0005vi-00 bits    256
 1999-03-02 09:44:33 10HmbQ-0005vi-00 tls_out_resumption not requested or offered
 1999-03-02 09:44:33 10HmbQ-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbQ-0005vi-00 peer cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbQ-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbQ-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbQ-0005vi-00 peer dn    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbQ-0005vi-00 peer dn    CN=server1.example.com
 1999-03-02 09:44:33 10HmbQ-0005vi-00 ocsp    1
 1999-03-02 09:44:33 10HmbQ-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbQ-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbQ-0005vi-00 => resume@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-PSK-AES256-SHAnnn:xxx* CV=yes DN="C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock" C="250 OK id=10HmbR-0005vi-00"
-1999-03-02 09:44:33 10HmbQ-0005vi-00 -> xyz@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-PSK-AES256-SHAnnn:xxx* CV=yes DN="C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock" C="250 OK id=10HmbR-0005vi-00"
-1999-03-02 09:44:33 10HmbQ-0005vi-00 => abcd@??? R=client T=send_to_server2 H=ip4.ip4.ip4.ip4 [ip4.ip4.ip4.ip4] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock" C="250 OK id=10HmbS-0005vi-00"
+1999-03-02 09:44:33 10HmbQ-0005vi-00 => resume@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-PSK-AES256-SHAnnn:xxx* CV=yes DN="CN=server1.example.com" C="250 OK id=10HmbR-0005vi-00"
+1999-03-02 09:44:33 10HmbQ-0005vi-00 -> xyz@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-PSK-AES256-SHAnnn:xxx* CV=yes DN="CN=server1.example.com" C="250 OK id=10HmbR-0005vi-00"
+1999-03-02 09:44:33 10HmbQ-0005vi-00 => abcd@??? R=client T=send_to_server2 H=ip4.ip4.ip4.ip4 [ip4.ip4.ip4.ip4] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="CN=server1.example.com" C="250 OK id=10HmbS-0005vi-00"
 1999-03-02 09:44:33 10HmbQ-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbT-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for renewal@???
 1999-03-02 09:44:33 10HmbT-0005vi-00 tls_out_resumption session resumed, also new ticket
 1999-03-02 09:44:33 10HmbT-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbT-0005vi-00 peer cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbT-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbT-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbT-0005vi-00 peer dn    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbT-0005vi-00 peer dn    CN=server1.example.com
 1999-03-02 09:44:33 10HmbT-0005vi-00 ocsp    1
 1999-03-02 09:44:33 10HmbT-0005vi-00 cipher    TLS1.x:ke-PSK-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbT-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbT-0005vi-00 => renewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-PSK-AES256-SHAnnn:xxx* CV=yes DN="C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock" C="250 OK id=10HmbU-0005vi-00"
+1999-03-02 09:44:33 10HmbT-0005vi-00 => renewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-PSK-AES256-SHAnnn:xxx* CV=yes DN="CN=server1.example.com" C="250 OK id=10HmbU-0005vi-00"
 1999-03-02 09:44:33 10HmbT-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbV-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for postrenewal@???
 1999-03-02 09:44:33 10HmbV-0005vi-00 tls_out_resumption session resumed, also new ticket
 1999-03-02 09:44:33 10HmbV-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbV-0005vi-00 peer cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbV-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbV-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbV-0005vi-00 peer dn    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbV-0005vi-00 peer dn    CN=server1.example.com
 1999-03-02 09:44:33 10HmbV-0005vi-00 ocsp    1
 1999-03-02 09:44:33 10HmbV-0005vi-00 cipher    TLS1.x:ke-PSK-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbV-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbV-0005vi-00 => postrenewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-PSK-AES256-SHAnnn:xxx* CV=yes DN="C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock" C="250 OK id=10HmbW-0005vi-00"
+1999-03-02 09:44:33 10HmbV-0005vi-00 => postrenewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-PSK-AES256-SHAnnn:xxx* CV=yes DN="CN=server1.example.com" C="250 OK id=10HmbW-0005vi-00"
 1999-03-02 09:44:33 10HmbV-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbX-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for timeout@???
 1999-03-02 09:44:33 10HmbX-0005vi-00 tls_out_resumption client offered session, server only provided new ticket
 1999-03-02 09:44:33 10HmbX-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbX-0005vi-00 peer cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbX-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbX-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbX-0005vi-00 peer dn    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbX-0005vi-00 peer dn    CN=server1.example.com
 1999-03-02 09:44:33 10HmbX-0005vi-00 ocsp    1
 1999-03-02 09:44:33 10HmbX-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbX-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbX-0005vi-00 => timeout@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock" C="250 OK id=10HmbY-0005vi-00"
+1999-03-02 09:44:33 10HmbX-0005vi-00 => timeout@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="CN=server1.example.com" C="250 OK id=10HmbY-0005vi-00"
 1999-03-02 09:44:33 10HmbX-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbZ-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for notreq@???
 1999-03-02 09:44:33 10HmbZ-0005vi-00 tls_out_resumption no client request
 1999-03-02 09:44:33 10HmbZ-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbZ-0005vi-00 peer cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbZ-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbZ-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbZ-0005vi-00 peer dn    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 10HmbZ-0005vi-00 peer dn    CN=server1.example.com
 1999-03-02 09:44:33 10HmbZ-0005vi-00 ocsp    1
 1999-03-02 09:44:33 10HmbZ-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbZ-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbZ-0005vi-00 => notreq@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock" C="250 OK id=10HmcA-0005vi-00"
+1999-03-02 09:44:33 10HmbZ-0005vi-00 => notreq@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="CN=server1.example.com" C="250 OK id=10HmcA-0005vi-00"
 1999-03-02 09:44:33 10HmbZ-0005vi-00 Completed


 ******** SERVER ********
 1999-03-02 09:44:33 exim x.yz daemon started: pid=pppp, no queue runs, listening for SMTP on port PORT_D
 1999-03-02 09:44:33 tls_in_resumption    client requested new ticket, server provided
-1999-03-02 09:44:33 our cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    0
+1999-03-02 09:44:33 ocsp    2
 1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 bits    256
 1999-03-02 09:44:33 10HmaY-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmaX-0005vi-00@??? for getticket@???
@@ -199,11 +199,11 @@
 1999-03-02 09:44:33 10HmbA-0005vi-00 => :blackhole: <resume@???> R=server
 1999-03-02 09:44:33 10HmbA-0005vi-00 Completed
 1999-03-02 09:44:33 tls_in_resumption    not requested or offered
-1999-03-02 09:44:33 our cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    0
+1999-03-02 09:44:33 ocsp    2
 1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 bits    256
 1999-03-02 09:44:33 10HmbB-0005vi-00 <= CALLER@??? H=the.local.host.name (myhost.test.ex) [ip4.ip4.ip4.ip4] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmaZ-0005vi-00@??? for abcd@???
@@ -232,33 +232,33 @@
 1999-03-02 09:44:33 10HmbF-0005vi-00 => :blackhole: <postrenewal@???> R=server
 1999-03-02 09:44:33 10HmbF-0005vi-00 Completed
 1999-03-02 09:44:33 tls_in_resumption    client offered session, server only provided new ticket
-1999-03-02 09:44:33 our cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    0
+1999-03-02 09:44:33 ocsp    2
 1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 bits    256
 1999-03-02 09:44:33 10HmbH-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmbG-0005vi-00@??? for timeout@???
 1999-03-02 09:44:33 10HmbH-0005vi-00 => :blackhole: <timeout@???> R=server
 1999-03-02 09:44:33 10HmbH-0005vi-00 Completed
 1999-03-02 09:44:33 tls_in_resumption    client requested new ticket, server provided
-1999-03-02 09:44:33 our cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    0
+1999-03-02 09:44:33 ocsp    2
 1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 bits    256
 1999-03-02 09:44:33 10HmbJ-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmbI-0005vi-00@??? for notreq@???
 1999-03-02 09:44:33 10HmbJ-0005vi-00 => :blackhole: <notreq@???> R=server
 1999-03-02 09:44:33 10HmbJ-0005vi-00 Completed
 1999-03-02 09:44:33 tls_in_resumption    client requested new ticket, server provided
-1999-03-02 09:44:33 our cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    0
+1999-03-02 09:44:33 ocsp    2
 1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 bits    256
 1999-03-02 09:44:33 10HmbL-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmbK-0005vi-00@??? for noverify_getticket@???
@@ -277,11 +277,11 @@
 1999-03-02 09:44:33 10HmbN-0005vi-00 Completed
 1999-03-02 09:44:33 exim x.yz daemon started: pid=pppp, no queue runs, listening for SMTP on port PORT_D
 1999-03-02 09:44:33 tls_in_resumption    client requested new ticket, server provided
-1999-03-02 09:44:33 our cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    0
+1999-03-02 09:44:33 ocsp    2
 1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 bits    256
 1999-03-02 09:44:33 10HmbP-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmbO-0005vi-00@??? for getticket@???
@@ -300,11 +300,11 @@
 1999-03-02 09:44:33 10HmbR-0005vi-00 => :blackhole: <resume@???> R=server
 1999-03-02 09:44:33 10HmbR-0005vi-00 Completed
 1999-03-02 09:44:33 tls_in_resumption    not requested or offered
-1999-03-02 09:44:33 our cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    0
+1999-03-02 09:44:33 ocsp    2
 1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 bits    256
 1999-03-02 09:44:33 10HmbS-0005vi-00 <= CALLER@??? H=the.local.host.name (myhost.test.ex) [ip4.ip4.ip4.ip4] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmbQ-0005vi-00@??? for abcd@???
@@ -333,22 +333,22 @@
 1999-03-02 09:44:33 10HmbW-0005vi-00 => :blackhole: <postrenewal@???> R=server
 1999-03-02 09:44:33 10HmbW-0005vi-00 Completed
 1999-03-02 09:44:33 tls_in_resumption    client requested new ticket, server provided
-1999-03-02 09:44:33 our cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    0
+1999-03-02 09:44:33 ocsp    2
 1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 bits    256
 1999-03-02 09:44:33 10HmbY-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmbX-0005vi-00@??? for timeout@???
 1999-03-02 09:44:33 10HmbY-0005vi-00 => :blackhole: <timeout@???> R=server
 1999-03-02 09:44:33 10HmbY-0005vi-00 Completed
 1999-03-02 09:44:33 tls_in_resumption    client requested new ticket, server provided
-1999-03-02 09:44:33 our cert subject    C=UK,O=The Exim Maintainers,OU=Test Suite,CN=Phil Pennock
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    0
+1999-03-02 09:44:33 ocsp    2
 1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 bits    256
 1999-03-02 09:44:33 10HmcA-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmbZ-0005vi-00@??? for notreq@???
diff --git a/test/log/5891 b/test/log/5891
index 986525d..6b04057 100644
--- a/test/log/5891
+++ b/test/log/5891
@@ -1,194 +1,194 @@
 1999-03-02 09:44:33 10HmaX-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for getticket@???
 1999-03-02 09:44:33 10HmaX-0005vi-00 tls_out_resumption client requested new ticket, server provided
 1999-03-02 09:44:33 10HmaX-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmaX-0005vi-00 peer cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 10HmaX-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmaX-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmaX-0005vi-00 peer dn    /C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock
-1999-03-02 09:44:33 10HmaX-0005vi-00 ocsp    1
+1999-03-02 09:44:33 10HmaX-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmaX-0005vi-00 ocsp    4
 1999-03-02 09:44:33 10HmaX-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmaX-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmaX-0005vi-00 => getticket@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock" C="250 OK id=10HmaY-0005vi-00"
+1999-03-02 09:44:33 10HmaX-0005vi-00 => getticket@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmaY-0005vi-00"
 1999-03-02 09:44:33 10HmaX-0005vi-00 Completed
 1999-03-02 09:44:33 10HmaZ-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for resume@??? abcd@??? xyz@???
 1999-03-02 09:44:33 10HmaZ-0005vi-00 tls_out_resumption session resumed
 1999-03-02 09:44:33 10HmaZ-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmaZ-0005vi-00 peer cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 10HmaZ-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmaZ-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmaZ-0005vi-00 peer dn    /C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock
-1999-03-02 09:44:33 10HmaZ-0005vi-00 ocsp    1
+1999-03-02 09:44:33 10HmaZ-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmaZ-0005vi-00 ocsp    4
 1999-03-02 09:44:33 10HmaZ-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmaZ-0005vi-00 bits    256
 1999-03-02 09:44:33 10HmaZ-0005vi-00 tls_out_resumption not requested or offered
 1999-03-02 09:44:33 10HmaZ-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmaZ-0005vi-00 peer cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 10HmaZ-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmaZ-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmaZ-0005vi-00 peer dn    /C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock
-1999-03-02 09:44:33 10HmaZ-0005vi-00 ocsp    1
+1999-03-02 09:44:33 10HmaZ-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmaZ-0005vi-00 ocsp    4
 1999-03-02 09:44:33 10HmaZ-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmaZ-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmaZ-0005vi-00 => resume@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock" C="250 OK id=10HmbA-0005vi-00"
-1999-03-02 09:44:33 10HmaZ-0005vi-00 -> xyz@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock" C="250 OK id=10HmbA-0005vi-00"
-1999-03-02 09:44:33 10HmaZ-0005vi-00 => abcd@??? R=client T=send_to_server2 H=ip4.ip4.ip4.ip4 [ip4.ip4.ip4.ip4] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock" C="250 OK id=10HmbB-0005vi-00"
+1999-03-02 09:44:33 10HmaZ-0005vi-00 => resume@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbA-0005vi-00"
+1999-03-02 09:44:33 10HmaZ-0005vi-00 -> xyz@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbA-0005vi-00"
+1999-03-02 09:44:33 10HmaZ-0005vi-00 => abcd@??? R=client T=send_to_server2 H=ip4.ip4.ip4.ip4 [ip4.ip4.ip4.ip4] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbB-0005vi-00"
 1999-03-02 09:44:33 10HmaZ-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbC-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for renewal@???
 1999-03-02 09:44:33 10HmbC-0005vi-00 tls_out_resumption session resumed
 1999-03-02 09:44:33 10HmbC-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbC-0005vi-00 peer cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 10HmbC-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbC-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbC-0005vi-00 peer dn    /C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock
-1999-03-02 09:44:33 10HmbC-0005vi-00 ocsp    1
+1999-03-02 09:44:33 10HmbC-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmbC-0005vi-00 ocsp    4
 1999-03-02 09:44:33 10HmbC-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbC-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbC-0005vi-00 => renewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock" C="250 OK id=10HmbD-0005vi-00"
+1999-03-02 09:44:33 10HmbC-0005vi-00 => renewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbD-0005vi-00"
 1999-03-02 09:44:33 10HmbC-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbE-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for postrenewal@???
 1999-03-02 09:44:33 10HmbE-0005vi-00 tls_out_resumption session resumed
 1999-03-02 09:44:33 10HmbE-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbE-0005vi-00 peer cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 10HmbE-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbE-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbE-0005vi-00 peer dn    /C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock
-1999-03-02 09:44:33 10HmbE-0005vi-00 ocsp    1
+1999-03-02 09:44:33 10HmbE-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmbE-0005vi-00 ocsp    4
 1999-03-02 09:44:33 10HmbE-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbE-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbE-0005vi-00 => postrenewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock" C="250 OK id=10HmbF-0005vi-00"
+1999-03-02 09:44:33 10HmbE-0005vi-00 => postrenewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbF-0005vi-00"
 1999-03-02 09:44:33 10HmbE-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbG-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for timeout@???
 1999-03-02 09:44:33 10HmbG-0005vi-00 tls_out_resumption client requested new ticket, server provided
 1999-03-02 09:44:33 10HmbG-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbG-0005vi-00 peer cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 10HmbG-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbG-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbG-0005vi-00 peer dn    /C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock
-1999-03-02 09:44:33 10HmbG-0005vi-00 ocsp    1
+1999-03-02 09:44:33 10HmbG-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmbG-0005vi-00 ocsp    4
 1999-03-02 09:44:33 10HmbG-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbG-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbG-0005vi-00 => timeout@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock" C="250 OK id=10HmbH-0005vi-00"
+1999-03-02 09:44:33 10HmbG-0005vi-00 => timeout@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbH-0005vi-00"
 1999-03-02 09:44:33 10HmbG-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbI-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for notreq@???
 1999-03-02 09:44:33 10HmbI-0005vi-00 tls_out_resumption not requested or offered
 1999-03-02 09:44:33 10HmbI-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbI-0005vi-00 peer cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 10HmbI-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbI-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbI-0005vi-00 peer dn    /C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock
-1999-03-02 09:44:33 10HmbI-0005vi-00 ocsp    1
+1999-03-02 09:44:33 10HmbI-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmbI-0005vi-00 ocsp    4
 1999-03-02 09:44:33 10HmbI-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbI-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbI-0005vi-00 => notreq@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock" C="250 OK id=10HmbJ-0005vi-00"
+1999-03-02 09:44:33 10HmbI-0005vi-00 => notreq@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbJ-0005vi-00"
 1999-03-02 09:44:33 10HmbI-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbK-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for noverify_getticket@???
-1999-03-02 09:44:33 10HmbK-0005vi-00 [127.0.0.1] SSL verify error: certificate name mismatch: DN="/C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock" H="127.0.0.1"
+1999-03-02 09:44:33 10HmbK-0005vi-00 [127.0.0.1] SSL verify error: certificate name mismatch: DN="/CN=server1.example.com" H="127.0.0.1"
 1999-03-02 09:44:33 10HmbK-0005vi-00 tls_out_resumption client requested new ticket, server provided
 1999-03-02 09:44:33 10HmbK-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbK-0005vi-00 peer cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 10HmbK-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbK-0005vi-00 peer cert verified    0
-1999-03-02 09:44:33 10HmbK-0005vi-00 peer dn    /C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock
-1999-03-02 09:44:33 10HmbK-0005vi-00 ocsp    1
+1999-03-02 09:44:33 10HmbK-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmbK-0005vi-00 ocsp    4
 1999-03-02 09:44:33 10HmbK-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbK-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbK-0005vi-00 => noverify_getticket@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no DN="/C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock" C="250 OK id=10HmbL-0005vi-00"
+1999-03-02 09:44:33 10HmbK-0005vi-00 => noverify_getticket@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no DN="/CN=server1.example.com" C="250 OK id=10HmbL-0005vi-00"
 1999-03-02 09:44:33 10HmbK-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbM-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for noverify_resume@???
 1999-03-02 09:44:33 10HmbM-0005vi-00 tls_out_resumption session resumed
 1999-03-02 09:44:33 10HmbM-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbM-0005vi-00 peer cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 10HmbM-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbM-0005vi-00 peer cert verified    0
-1999-03-02 09:44:33 10HmbM-0005vi-00 peer dn    /C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock
-1999-03-02 09:44:33 10HmbM-0005vi-00 ocsp    1
+1999-03-02 09:44:33 10HmbM-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmbM-0005vi-00 ocsp    4
 1999-03-02 09:44:33 10HmbM-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbM-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbM-0005vi-00 => noverify_resume@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=no DN="/C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock" C="250 OK id=10HmbN-0005vi-00"
+1999-03-02 09:44:33 10HmbM-0005vi-00 => noverify_resume@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=no DN="/CN=server1.example.com" C="250 OK id=10HmbN-0005vi-00"
 1999-03-02 09:44:33 10HmbM-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbO-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for getticket@???
 1999-03-02 09:44:33 10HmbO-0005vi-00 tls_out_resumption client requested new ticket, server provided
 1999-03-02 09:44:33 10HmbO-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbO-0005vi-00 peer cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 10HmbO-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbO-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbO-0005vi-00 peer dn    /C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock
-1999-03-02 09:44:33 10HmbO-0005vi-00 ocsp    1
+1999-03-02 09:44:33 10HmbO-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmbO-0005vi-00 ocsp    4
 1999-03-02 09:44:33 10HmbO-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbO-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbO-0005vi-00 => getticket@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock" C="250 OK id=10HmbP-0005vi-00"
+1999-03-02 09:44:33 10HmbO-0005vi-00 => getticket@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbP-0005vi-00"
 1999-03-02 09:44:33 10HmbO-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbQ-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for resume@??? abcd@??? xyz@???
 1999-03-02 09:44:33 10HmbQ-0005vi-00 tls_out_resumption session resumed
 1999-03-02 09:44:33 10HmbQ-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbQ-0005vi-00 peer cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 10HmbQ-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbQ-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbQ-0005vi-00 peer dn    /C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock
-1999-03-02 09:44:33 10HmbQ-0005vi-00 ocsp    1
+1999-03-02 09:44:33 10HmbQ-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmbQ-0005vi-00 ocsp    4
 1999-03-02 09:44:33 10HmbQ-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbQ-0005vi-00 bits    256
 1999-03-02 09:44:33 10HmbQ-0005vi-00 tls_out_resumption not requested or offered
 1999-03-02 09:44:33 10HmbQ-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbQ-0005vi-00 peer cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 10HmbQ-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbQ-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbQ-0005vi-00 peer dn    /C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock
-1999-03-02 09:44:33 10HmbQ-0005vi-00 ocsp    1
+1999-03-02 09:44:33 10HmbQ-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmbQ-0005vi-00 ocsp    4
 1999-03-02 09:44:33 10HmbQ-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbQ-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbQ-0005vi-00 => resume@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock" C="250 OK id=10HmbR-0005vi-00"
-1999-03-02 09:44:33 10HmbQ-0005vi-00 -> xyz@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock" C="250 OK id=10HmbR-0005vi-00"
-1999-03-02 09:44:33 10HmbQ-0005vi-00 => abcd@??? R=client T=send_to_server2 H=ip4.ip4.ip4.ip4 [ip4.ip4.ip4.ip4] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock" C="250 OK id=10HmbS-0005vi-00"
+1999-03-02 09:44:33 10HmbQ-0005vi-00 => resume@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbR-0005vi-00"
+1999-03-02 09:44:33 10HmbQ-0005vi-00 -> xyz@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbR-0005vi-00"
+1999-03-02 09:44:33 10HmbQ-0005vi-00 => abcd@??? R=client T=send_to_server2 H=ip4.ip4.ip4.ip4 [ip4.ip4.ip4.ip4] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbS-0005vi-00"
 1999-03-02 09:44:33 10HmbQ-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbT-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for renewal@???
 1999-03-02 09:44:33 10HmbT-0005vi-00 tls_out_resumption session resumed, also new ticket
 1999-03-02 09:44:33 10HmbT-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbT-0005vi-00 peer cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 10HmbT-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbT-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbT-0005vi-00 peer dn    /C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock
-1999-03-02 09:44:33 10HmbT-0005vi-00 ocsp    1
+1999-03-02 09:44:33 10HmbT-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmbT-0005vi-00 ocsp    4
 1999-03-02 09:44:33 10HmbT-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbT-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbT-0005vi-00 => renewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock" C="250 OK id=10HmbU-0005vi-00"
+1999-03-02 09:44:33 10HmbT-0005vi-00 => renewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbU-0005vi-00"
 1999-03-02 09:44:33 10HmbT-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbV-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for postrenewal@???
 1999-03-02 09:44:33 10HmbV-0005vi-00 tls_out_resumption session resumed
 1999-03-02 09:44:33 10HmbV-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbV-0005vi-00 peer cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 10HmbV-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbV-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbV-0005vi-00 peer dn    /C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock
-1999-03-02 09:44:33 10HmbV-0005vi-00 ocsp    1
+1999-03-02 09:44:33 10HmbV-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmbV-0005vi-00 ocsp    4
 1999-03-02 09:44:33 10HmbV-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbV-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbV-0005vi-00 => postrenewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock" C="250 OK id=10HmbW-0005vi-00"
+1999-03-02 09:44:33 10HmbV-0005vi-00 => postrenewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbW-0005vi-00"
 1999-03-02 09:44:33 10HmbV-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbX-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for timeout@???
 1999-03-02 09:44:33 10HmbX-0005vi-00 tls_out_resumption session resumed, also new ticket
 1999-03-02 09:44:33 10HmbX-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbX-0005vi-00 peer cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 10HmbX-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbX-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbX-0005vi-00 peer dn    /C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock
-1999-03-02 09:44:33 10HmbX-0005vi-00 ocsp    1
+1999-03-02 09:44:33 10HmbX-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmbX-0005vi-00 ocsp    4
 1999-03-02 09:44:33 10HmbX-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbX-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbX-0005vi-00 => timeout@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock" C="250 OK id=10HmbY-0005vi-00"
+1999-03-02 09:44:33 10HmbX-0005vi-00 => timeout@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbY-0005vi-00"
 1999-03-02 09:44:33 10HmbX-0005vi-00 Completed
 1999-03-02 09:44:33 10HmbZ-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for notreq@???
 1999-03-02 09:44:33 10HmbZ-0005vi-00 tls_out_resumption not requested or offered
 1999-03-02 09:44:33 10HmbZ-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbZ-0005vi-00 peer cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 10HmbZ-0005vi-00 peer cert subject    CN=server1.example.com
 1999-03-02 09:44:33 10HmbZ-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbZ-0005vi-00 peer dn    /C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock
-1999-03-02 09:44:33 10HmbZ-0005vi-00 ocsp    1
+1999-03-02 09:44:33 10HmbZ-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmbZ-0005vi-00 ocsp    4
 1999-03-02 09:44:33 10HmbZ-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 10HmbZ-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbZ-0005vi-00 => notreq@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/C=UK/O=The Exim Maintainers/OU=Test Suite/CN=Phil Pennock" C="250 OK id=10HmcA-0005vi-00"
+1999-03-02 09:44:33 10HmbZ-0005vi-00 => notreq@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmcA-0005vi-00"
 1999-03-02 09:44:33 10HmbZ-0005vi-00 Completed


 ******** SERVER ********
 1999-03-02 09:44:33 exim x.yz daemon started: pid=pppp, no queue runs, listening for SMTP on port PORT_D
 1999-03-02 09:44:33 tls_in_resumption    client requested new ticket, server provided
-1999-03-02 09:44:33 our cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    0
+1999-03-02 09:44:33 ocsp    4
 1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 bits    256
 1999-03-02 09:44:33 10HmaY-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmaX-0005vi-00@??? for getticket@???
 1999-03-02 09:44:33 10HmaY-0005vi-00 => :blackhole: <getticket@???> R=server
 1999-03-02 09:44:33 10HmaY-0005vi-00 Completed
 1999-03-02 09:44:33 tls_in_resumption    session resumed
-1999-03-02 09:44:33 our cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
@@ -200,18 +200,18 @@
 1999-03-02 09:44:33 10HmbA-0005vi-00 => :blackhole: <resume@???> R=server
 1999-03-02 09:44:33 10HmbA-0005vi-00 Completed
 1999-03-02 09:44:33 tls_in_resumption    not requested or offered
-1999-03-02 09:44:33 our cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    0
+1999-03-02 09:44:33 ocsp    4
 1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 bits    256
 1999-03-02 09:44:33 10HmbB-0005vi-00 <= CALLER@??? H=the.local.host.name (myhost.test.ex) [ip4.ip4.ip4.ip4] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmaZ-0005vi-00@??? for abcd@???
 1999-03-02 09:44:33 10HmbB-0005vi-00 => :blackhole: <abcd@???> R=server
 1999-03-02 09:44:33 10HmbB-0005vi-00 Completed
 1999-03-02 09:44:33 tls_in_resumption    session resumed, also new ticket
-1999-03-02 09:44:33 our cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
@@ -222,7 +222,7 @@
 1999-03-02 09:44:33 10HmbD-0005vi-00 => :blackhole: <renewal@???> R=server
 1999-03-02 09:44:33 10HmbD-0005vi-00 Completed
 1999-03-02 09:44:33 tls_in_resumption    session resumed, also new ticket
-1999-03-02 09:44:33 our cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
@@ -233,40 +233,40 @@
 1999-03-02 09:44:33 10HmbF-0005vi-00 => :blackhole: <postrenewal@???> R=server
 1999-03-02 09:44:33 10HmbF-0005vi-00 Completed
 1999-03-02 09:44:33 tls_in_resumption    client requested new ticket, server provided
-1999-03-02 09:44:33 our cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    0
+1999-03-02 09:44:33 ocsp    4
 1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 bits    256
 1999-03-02 09:44:33 10HmbH-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmbG-0005vi-00@??? for timeout@???
 1999-03-02 09:44:33 10HmbH-0005vi-00 => :blackhole: <timeout@???> R=server
 1999-03-02 09:44:33 10HmbH-0005vi-00 Completed
 1999-03-02 09:44:33 tls_in_resumption    no client request
-1999-03-02 09:44:33 our cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    0
+1999-03-02 09:44:33 ocsp    4
 1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 bits    256
 1999-03-02 09:44:33 10HmbJ-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmbI-0005vi-00@??? for notreq@???
 1999-03-02 09:44:33 10HmbJ-0005vi-00 => :blackhole: <notreq@???> R=server
 1999-03-02 09:44:33 10HmbJ-0005vi-00 Completed
 1999-03-02 09:44:33 tls_in_resumption    client requested new ticket, server provided
-1999-03-02 09:44:33 our cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    0
+1999-03-02 09:44:33 ocsp    4
 1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 bits    256
 1999-03-02 09:44:33 10HmbL-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmbK-0005vi-00@??? for noverify_getticket@???
 1999-03-02 09:44:33 10HmbL-0005vi-00 => :blackhole: <noverify_getticket@???> R=server
 1999-03-02 09:44:33 10HmbL-0005vi-00 Completed
 1999-03-02 09:44:33 tls_in_resumption    session resumed
-1999-03-02 09:44:33 our cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
@@ -278,18 +278,18 @@
 1999-03-02 09:44:33 10HmbN-0005vi-00 Completed
 1999-03-02 09:44:33 exim x.yz daemon started: pid=pppp, no queue runs, listening for SMTP on port PORT_D
 1999-03-02 09:44:33 tls_in_resumption    client requested new ticket, server provided
-1999-03-02 09:44:33 our cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    0
+1999-03-02 09:44:33 ocsp    4
 1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 bits    256
 1999-03-02 09:44:33 10HmbP-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmbO-0005vi-00@??? for getticket@???
 1999-03-02 09:44:33 10HmbP-0005vi-00 => :blackhole: <getticket@???> R=server
 1999-03-02 09:44:33 10HmbP-0005vi-00 Completed
 1999-03-02 09:44:33 tls_in_resumption    session resumed
-1999-03-02 09:44:33 our cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
@@ -301,18 +301,18 @@
 1999-03-02 09:44:33 10HmbR-0005vi-00 => :blackhole: <resume@???> R=server
 1999-03-02 09:44:33 10HmbR-0005vi-00 Completed
 1999-03-02 09:44:33 tls_in_resumption    not requested or offered
-1999-03-02 09:44:33 our cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    0
+1999-03-02 09:44:33 ocsp    4
 1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 bits    256
 1999-03-02 09:44:33 10HmbS-0005vi-00 <= CALLER@??? H=the.local.host.name (myhost.test.ex) [ip4.ip4.ip4.ip4] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmbQ-0005vi-00@??? for abcd@???
 1999-03-02 09:44:33 10HmbS-0005vi-00 => :blackhole: <abcd@???> R=server
 1999-03-02 09:44:33 10HmbS-0005vi-00 Completed
 1999-03-02 09:44:33 tls_in_resumption    session resumed, also new ticket
-1999-03-02 09:44:33 our cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
@@ -323,7 +323,7 @@
 1999-03-02 09:44:33 10HmbU-0005vi-00 => :blackhole: <renewal@???> R=server
 1999-03-02 09:44:33 10HmbU-0005vi-00 Completed
 1999-03-02 09:44:33 tls_in_resumption    session resumed
-1999-03-02 09:44:33 our cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
@@ -334,7 +334,7 @@
 1999-03-02 09:44:33 10HmbW-0005vi-00 => :blackhole: <postrenewal@???> R=server
 1999-03-02 09:44:33 10HmbW-0005vi-00 Completed
 1999-03-02 09:44:33 tls_in_resumption    session resumed, also new ticket
-1999-03-02 09:44:33 our cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
@@ -345,11 +345,11 @@
 1999-03-02 09:44:33 10HmbY-0005vi-00 => :blackhole: <timeout@???> R=server
 1999-03-02 09:44:33 10HmbY-0005vi-00 Completed
 1999-03-02 09:44:33 tls_in_resumption    client requested new ticket, server provided
-1999-03-02 09:44:33 our cert subject    CN=Phil Pennock,OU=Test Suite,O=The Exim Maintainers,C=UK
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
 1999-03-02 09:44:33 peer cert subject    
 1999-03-02 09:44:33 peer cert verified    0
 1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    0
+1999-03-02 09:44:33 ocsp    4
 1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
 1999-03-02 09:44:33 bits    256
 1999-03-02 09:44:33 10HmcA-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmbZ-0005vi-00@??? for notreq@???