[exim-cvs] Testsuite: split out OpenSSL TLS1.3 resume tests

Startseite
Nachricht löschen
Nachricht beantworten
Autor: Exim Git Commits Mailing List
Datum:  
To: exim-cvs
Betreff: [exim-cvs] Testsuite: split out OpenSSL TLS1.3 resume tests
Gitweb: https://git.exim.org/exim.git/commitdiff/927a335fbd3d51e29a216efd034b61f0a169f6aa
Commit:     927a335fbd3d51e29a216efd034b61f0a169f6aa
Parent:     360dccf0892b75ebbfcd5363c1c70a35f80ad337
Author:     Jeremy Harris <jgh146exb@???>
AuthorDate: Sat Jun 19 19:11:43 2021 +0100
Committer:  Jeremy Harris <jgh146exb@???>
CommitDate: Sat Jun 19 19:18:07 2021 +0100


    Testsuite: split out OpenSSL TLS1.3 resume tests


    Older library versions do not support 1.3 so a separate numbered
    testcase is needed
---
 test/confs/5892                                    |   4 +
 test/confs/5893                                    |   4 +
 test/confs/{5892 => 5894}                          |   5 +-
 test/confs/{5893 => 5895}                          |   5 +-
 test/log/5892                                      | 141 ------------------
 test/log/5893                                      | 155 --------------------
 test/log/5894                                      | 143 +++++++++++++++++++
 test/log/5895                                      | 157 +++++++++++++++++++++
 test/scripts/5892-Resume-OpenSSL/5892              |  31 +---
 test/scripts/5893-Resume-OpenSSL-OCSP/5893         |  31 +---
 test/scripts/5894-Resume-OpenSSL-TLS1.3/5894       |  28 ++++
 test/scripts/5894-Resume-OpenSSL-TLS1.3/REQUIRES   |   4 +
 test/scripts/5895-Resume-OpenSSL-TLS1.3-OCSP/5895  |  28 ++++
 .../5895-Resume-OpenSSL-TLS1.3-OCSP/REQUIRES       |   5 +
 test/stderr/5892                                   |   2 -
 test/stderr/5893                                   |   2 -
 test/stderr/{5892 => 5894}                         |   2 -
 test/stderr/{5892 => 5895}                         |   2 -
 test/stdout/5892                                   |   2 -
 test/stdout/5893                                   |   2 -
 test/{stderr/5892 => stdout/5894}                  |   2 -
 test/{stderr/5892 => stdout/5895}                  |   2 -
 22 files changed, 379 insertions(+), 378 deletions(-)


diff --git a/test/confs/5892 b/test/confs/5892
index 4e6883f..a773846 100644
--- a/test/confs/5892
+++ b/test/confs/5892
@@ -15,7 +15,11 @@ acl_smtp_helo = check_helo
acl_smtp_rcpt = check_recipient
log_selector = +received_recipients +tls_resumption +tls_peerdn

+.ifdef _OPT_OPENSSL_NO_TLSV1_3_X
openssl_options = +no_sslv2 +no_sslv3 +single_dh_use OPTION
+.else
+openssl_options = +no_sslv2 +no_sslv3 +single_dh_use
+.endif
tls_advertise_hosts = *

# Set certificate only if server
diff --git a/test/confs/5893 b/test/confs/5893
index 74b61b7..a7f73a9 100644
--- a/test/confs/5893
+++ b/test/confs/5893
@@ -15,7 +15,11 @@ acl_smtp_helo = check_helo
acl_smtp_rcpt = check_recipient
log_selector = +received_recipients +tls_resumption +tls_peerdn

+.ifdef _OPT_OPENSSL_NO_TLSV1_3_X
openssl_options = +no_sslv2 +no_sslv3 +single_dh_use OPTION
+.else
+openssl_options = +no_sslv2 +no_sslv3 +single_dh_use
+.endif
tls_advertise_hosts = *

# Set certificate only if server
diff --git a/test/confs/5892 b/test/confs/5894
similarity index 96%
copy from test/confs/5892
copy to test/confs/5894
index 4e6883f..da34717 100644
--- a/test/confs/5892
+++ b/test/confs/5894
@@ -1,7 +1,6 @@
-# Exim test configuration 5892
+# Exim test configuration 5894

SERVER =
-OPTION =

.include DIR/aux-var/tls_conf_prefix

@@ -15,7 +14,7 @@ acl_smtp_helo = check_helo
acl_smtp_rcpt = check_recipient
log_selector = +received_recipients +tls_resumption +tls_peerdn

-openssl_options = +no_sslv2 +no_sslv3 +single_dh_use OPTION
+openssl_options = +no_sslv2 +no_sslv3 +single_dh_use
tls_advertise_hosts = *

# Set certificate only if server
diff --git a/test/confs/5893 b/test/confs/5895
similarity index 96%
copy from test/confs/5893
copy to test/confs/5895
index 74b61b7..d279b1e 100644
--- a/test/confs/5893
+++ b/test/confs/5895
@@ -1,7 +1,6 @@
-# Exim test configuration 5893
+# Exim test configuration 5895

SERVER =
-OPTION =

.include DIR/aux-var/tls_conf_prefix

@@ -15,7 +14,7 @@ acl_smtp_helo = check_helo
acl_smtp_rcpt = check_recipient
log_selector = +received_recipients +tls_resumption +tls_peerdn

-openssl_options = +no_sslv2 +no_sslv3 +single_dh_use OPTION
+openssl_options = +no_sslv2 +no_sslv3 +single_dh_use
tls_advertise_hosts = *

 # Set certificate only if server
diff --git a/test/log/5892 b/test/log/5892
index 61450a7..b3d395f 100644
--- a/test/log/5892
+++ b/test/log/5892
@@ -88,75 +88,6 @@
 1999-03-02 09:44:33 10HmbM-0005vi-00 bits    256
 1999-03-02 09:44:33 10HmbM-0005vi-00 => noverify_resume@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=no DN="/CN=server1.example.com" C="250 OK id=10HmbN-0005vi-00"
 1999-03-02 09:44:33 10HmbM-0005vi-00 Completed
-1999-03-02 09:44:33 10HmbO-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for getticket@???
-1999-03-02 09:44:33 10HmbO-0005vi-00 tls_out_resumption client requested new ticket, server provided
-1999-03-02 09:44:33 10HmbO-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbO-0005vi-00 peer cert subject    CN=server1.example.com
-1999-03-02 09:44:33 10HmbO-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbO-0005vi-00 peer dn    /CN=server1.example.com
-1999-03-02 09:44:33 10HmbO-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 10HmbO-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbO-0005vi-00 => getticket@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbP-0005vi-00"
-1999-03-02 09:44:33 10HmbO-0005vi-00 Completed
-1999-03-02 09:44:33 10HmbQ-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for resume@??? abcd@??? xyz@???
-1999-03-02 09:44:33 10HmbQ-0005vi-00 tls_out_resumption session resumed
-1999-03-02 09:44:33 10HmbQ-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbQ-0005vi-00 peer cert subject    CN=server1.example.com
-1999-03-02 09:44:33 10HmbQ-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbQ-0005vi-00 peer dn    /CN=server1.example.com
-1999-03-02 09:44:33 10HmbQ-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 10HmbQ-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbQ-0005vi-00 tls_out_resumption not requested or offered
-1999-03-02 09:44:33 10HmbQ-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbQ-0005vi-00 peer cert subject    CN=server1.example.com
-1999-03-02 09:44:33 10HmbQ-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbQ-0005vi-00 peer dn    /CN=server1.example.com
-1999-03-02 09:44:33 10HmbQ-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 10HmbQ-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbQ-0005vi-00 => resume@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbR-0005vi-00"
-1999-03-02 09:44:33 10HmbQ-0005vi-00 -> xyz@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbR-0005vi-00"
-1999-03-02 09:44:33 10HmbQ-0005vi-00 => abcd@??? R=client T=send_to_server2 H=ip4.ip4.ip4.ip4 [ip4.ip4.ip4.ip4] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbS-0005vi-00"
-1999-03-02 09:44:33 10HmbQ-0005vi-00 Completed
-1999-03-02 09:44:33 10HmbT-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for renewal@???
-1999-03-02 09:44:33 10HmbT-0005vi-00 tls_out_resumption session resumed, also new ticket
-1999-03-02 09:44:33 10HmbT-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbT-0005vi-00 peer cert subject    CN=server1.example.com
-1999-03-02 09:44:33 10HmbT-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbT-0005vi-00 peer dn    /CN=server1.example.com
-1999-03-02 09:44:33 10HmbT-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 10HmbT-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbT-0005vi-00 => renewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbU-0005vi-00"
-1999-03-02 09:44:33 10HmbT-0005vi-00 Completed
-1999-03-02 09:44:33 10HmbV-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for postrenewal@???
-1999-03-02 09:44:33 10HmbV-0005vi-00 tls_out_resumption session resumed
-1999-03-02 09:44:33 10HmbV-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbV-0005vi-00 peer cert subject    CN=server1.example.com
-1999-03-02 09:44:33 10HmbV-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbV-0005vi-00 peer dn    /CN=server1.example.com
-1999-03-02 09:44:33 10HmbV-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 10HmbV-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbV-0005vi-00 => postrenewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbW-0005vi-00"
-1999-03-02 09:44:33 10HmbV-0005vi-00 Completed
-1999-03-02 09:44:33 10HmbX-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for timeout@???
-1999-03-02 09:44:33 10HmbX-0005vi-00 tls_out_resumption session resumed, also new ticket
-1999-03-02 09:44:33 10HmbX-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbX-0005vi-00 peer cert subject    CN=server1.example.com
-1999-03-02 09:44:33 10HmbX-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbX-0005vi-00 peer dn    /CN=server1.example.com
-1999-03-02 09:44:33 10HmbX-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 10HmbX-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbX-0005vi-00 => timeout@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbY-0005vi-00"
-1999-03-02 09:44:33 10HmbX-0005vi-00 Completed
-1999-03-02 09:44:33 10HmbZ-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for notreq@???
-1999-03-02 09:44:33 10HmbZ-0005vi-00 tls_out_resumption not requested or offered
-1999-03-02 09:44:33 10HmbZ-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbZ-0005vi-00 peer cert subject    CN=server1.example.com
-1999-03-02 09:44:33 10HmbZ-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbZ-0005vi-00 peer dn    /CN=server1.example.com
-1999-03-02 09:44:33 10HmbZ-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 10HmbZ-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbZ-0005vi-00 => notreq@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmcA-0005vi-00"
-1999-03-02 09:44:33 10HmbZ-0005vi-00 Completed


 ******** SERVER ********
 1999-03-02 09:44:33 exim x.yz daemon started: pid=pppp, no queue runs, listening for SMTP on port PORT_D
@@ -251,75 +182,3 @@
 1999-03-02 09:44:33 10HmbN-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=no S=sss id=E10HmbM-0005vi-00@??? for noverify_resume@???
 1999-03-02 09:44:33 10HmbN-0005vi-00 => :blackhole: <noverify_resume@???> R=server
 1999-03-02 09:44:33 10HmbN-0005vi-00 Completed
-1999-03-02 09:44:33 exim x.yz daemon started: pid=pppp, no queue runs, listening for SMTP on port PORT_D
-1999-03-02 09:44:33 tls_in_resumption    client requested new ticket, server provided
-1999-03-02 09:44:33 our cert subject    CN=server1.example.com
-1999-03-02 09:44:33 peer cert subject    
-1999-03-02 09:44:33 peer cert verified    0
-1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 bits    256
-1999-03-02 09:44:33 10HmbP-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmbO-0005vi-00@??? for getticket@???
-1999-03-02 09:44:33 10HmbP-0005vi-00 => :blackhole: <getticket@???> R=server
-1999-03-02 09:44:33 10HmbP-0005vi-00 Completed
-1999-03-02 09:44:33 tls_in_resumption    session resumed
-1999-03-02 09:44:33 our cert subject    CN=server1.example.com
-1999-03-02 09:44:33 peer cert subject    
-1999-03-02 09:44:33 peer cert verified    0
-1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 bits    256
-1999-03-02 09:44:33 10HmbR-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=no S=sss id=E10HmbQ-0005vi-00@??? for resume@??? xyz@???
-1999-03-02 09:44:33 10HmbR-0005vi-00 => :blackhole: <xyz@???> R=server
-1999-03-02 09:44:33 10HmbR-0005vi-00 => :blackhole: <resume@???> R=server
-1999-03-02 09:44:33 10HmbR-0005vi-00 Completed
-1999-03-02 09:44:33 tls_in_resumption    not requested or offered
-1999-03-02 09:44:33 our cert subject    CN=server1.example.com
-1999-03-02 09:44:33 peer cert subject    
-1999-03-02 09:44:33 peer cert verified    0
-1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 bits    256
-1999-03-02 09:44:33 10HmbS-0005vi-00 <= CALLER@??? H=the.local.host.name (myhost.test.ex) [ip4.ip4.ip4.ip4] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmbQ-0005vi-00@??? for abcd@???
-1999-03-02 09:44:33 10HmbS-0005vi-00 => :blackhole: <abcd@???> R=server
-1999-03-02 09:44:33 10HmbS-0005vi-00 Completed
-1999-03-02 09:44:33 tls_in_resumption    session resumed, also new ticket
-1999-03-02 09:44:33 our cert subject    CN=server1.example.com
-1999-03-02 09:44:33 peer cert subject    
-1999-03-02 09:44:33 peer cert verified    0
-1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 bits    256
-1999-03-02 09:44:33 10HmbU-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=no S=sss id=E10HmbT-0005vi-00@??? for renewal@???
-1999-03-02 09:44:33 10HmbU-0005vi-00 => :blackhole: <renewal@???> R=server
-1999-03-02 09:44:33 10HmbU-0005vi-00 Completed
-1999-03-02 09:44:33 tls_in_resumption    session resumed
-1999-03-02 09:44:33 our cert subject    CN=server1.example.com
-1999-03-02 09:44:33 peer cert subject    
-1999-03-02 09:44:33 peer cert verified    0
-1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 bits    256
-1999-03-02 09:44:33 10HmbW-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=no S=sss id=E10HmbV-0005vi-00@??? for postrenewal@???
-1999-03-02 09:44:33 10HmbW-0005vi-00 => :blackhole: <postrenewal@???> R=server
-1999-03-02 09:44:33 10HmbW-0005vi-00 Completed
-1999-03-02 09:44:33 tls_in_resumption    session resumed, also new ticket
-1999-03-02 09:44:33 our cert subject    CN=server1.example.com
-1999-03-02 09:44:33 peer cert subject    
-1999-03-02 09:44:33 peer cert verified    0
-1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 bits    256
-1999-03-02 09:44:33 10HmbY-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=no S=sss id=E10HmbX-0005vi-00@??? for timeout@???
-1999-03-02 09:44:33 10HmbY-0005vi-00 => :blackhole: <timeout@???> R=server
-1999-03-02 09:44:33 10HmbY-0005vi-00 Completed
-1999-03-02 09:44:33 tls_in_resumption    client requested new ticket, server provided
-1999-03-02 09:44:33 our cert subject    CN=server1.example.com
-1999-03-02 09:44:33 peer cert subject    
-1999-03-02 09:44:33 peer cert verified    0
-1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 bits    256
-1999-03-02 09:44:33 10HmcA-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmbZ-0005vi-00@??? for notreq@???
-1999-03-02 09:44:33 10HmcA-0005vi-00 => :blackhole: <notreq@???> R=server
-1999-03-02 09:44:33 10HmcA-0005vi-00 Completed
diff --git a/test/log/5893 b/test/log/5893
index 6b04057..8c535f7 100644
--- a/test/log/5893
+++ b/test/log/5893
@@ -97,82 +97,6 @@
 1999-03-02 09:44:33 10HmbM-0005vi-00 bits    256
 1999-03-02 09:44:33 10HmbM-0005vi-00 => noverify_resume@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=no DN="/CN=server1.example.com" C="250 OK id=10HmbN-0005vi-00"
 1999-03-02 09:44:33 10HmbM-0005vi-00 Completed
-1999-03-02 09:44:33 10HmbO-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for getticket@???
-1999-03-02 09:44:33 10HmbO-0005vi-00 tls_out_resumption client requested new ticket, server provided
-1999-03-02 09:44:33 10HmbO-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbO-0005vi-00 peer cert subject    CN=server1.example.com
-1999-03-02 09:44:33 10HmbO-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbO-0005vi-00 peer dn    /CN=server1.example.com
-1999-03-02 09:44:33 10HmbO-0005vi-00 ocsp    4
-1999-03-02 09:44:33 10HmbO-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 10HmbO-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbO-0005vi-00 => getticket@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbP-0005vi-00"
-1999-03-02 09:44:33 10HmbO-0005vi-00 Completed
-1999-03-02 09:44:33 10HmbQ-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for resume@??? abcd@??? xyz@???
-1999-03-02 09:44:33 10HmbQ-0005vi-00 tls_out_resumption session resumed
-1999-03-02 09:44:33 10HmbQ-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbQ-0005vi-00 peer cert subject    CN=server1.example.com
-1999-03-02 09:44:33 10HmbQ-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbQ-0005vi-00 peer dn    /CN=server1.example.com
-1999-03-02 09:44:33 10HmbQ-0005vi-00 ocsp    4
-1999-03-02 09:44:33 10HmbQ-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 10HmbQ-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbQ-0005vi-00 tls_out_resumption not requested or offered
-1999-03-02 09:44:33 10HmbQ-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbQ-0005vi-00 peer cert subject    CN=server1.example.com
-1999-03-02 09:44:33 10HmbQ-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbQ-0005vi-00 peer dn    /CN=server1.example.com
-1999-03-02 09:44:33 10HmbQ-0005vi-00 ocsp    4
-1999-03-02 09:44:33 10HmbQ-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 10HmbQ-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbQ-0005vi-00 => resume@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbR-0005vi-00"
-1999-03-02 09:44:33 10HmbQ-0005vi-00 -> xyz@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbR-0005vi-00"
-1999-03-02 09:44:33 10HmbQ-0005vi-00 => abcd@??? R=client T=send_to_server2 H=ip4.ip4.ip4.ip4 [ip4.ip4.ip4.ip4] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbS-0005vi-00"
-1999-03-02 09:44:33 10HmbQ-0005vi-00 Completed
-1999-03-02 09:44:33 10HmbT-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for renewal@???
-1999-03-02 09:44:33 10HmbT-0005vi-00 tls_out_resumption session resumed, also new ticket
-1999-03-02 09:44:33 10HmbT-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbT-0005vi-00 peer cert subject    CN=server1.example.com
-1999-03-02 09:44:33 10HmbT-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbT-0005vi-00 peer dn    /CN=server1.example.com
-1999-03-02 09:44:33 10HmbT-0005vi-00 ocsp    4
-1999-03-02 09:44:33 10HmbT-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 10HmbT-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbT-0005vi-00 => renewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbU-0005vi-00"
-1999-03-02 09:44:33 10HmbT-0005vi-00 Completed
-1999-03-02 09:44:33 10HmbV-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for postrenewal@???
-1999-03-02 09:44:33 10HmbV-0005vi-00 tls_out_resumption session resumed
-1999-03-02 09:44:33 10HmbV-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbV-0005vi-00 peer cert subject    CN=server1.example.com
-1999-03-02 09:44:33 10HmbV-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbV-0005vi-00 peer dn    /CN=server1.example.com
-1999-03-02 09:44:33 10HmbV-0005vi-00 ocsp    4
-1999-03-02 09:44:33 10HmbV-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 10HmbV-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbV-0005vi-00 => postrenewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbW-0005vi-00"
-1999-03-02 09:44:33 10HmbV-0005vi-00 Completed
-1999-03-02 09:44:33 10HmbX-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for timeout@???
-1999-03-02 09:44:33 10HmbX-0005vi-00 tls_out_resumption session resumed, also new ticket
-1999-03-02 09:44:33 10HmbX-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbX-0005vi-00 peer cert subject    CN=server1.example.com
-1999-03-02 09:44:33 10HmbX-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbX-0005vi-00 peer dn    /CN=server1.example.com
-1999-03-02 09:44:33 10HmbX-0005vi-00 ocsp    4
-1999-03-02 09:44:33 10HmbX-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 10HmbX-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbX-0005vi-00 => timeout@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbY-0005vi-00"
-1999-03-02 09:44:33 10HmbX-0005vi-00 Completed
-1999-03-02 09:44:33 10HmbZ-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for notreq@???
-1999-03-02 09:44:33 10HmbZ-0005vi-00 tls_out_resumption not requested or offered
-1999-03-02 09:44:33 10HmbZ-0005vi-00 our cert subject    
-1999-03-02 09:44:33 10HmbZ-0005vi-00 peer cert subject    CN=server1.example.com
-1999-03-02 09:44:33 10HmbZ-0005vi-00 peer cert verified    1
-1999-03-02 09:44:33 10HmbZ-0005vi-00 peer dn    /CN=server1.example.com
-1999-03-02 09:44:33 10HmbZ-0005vi-00 ocsp    4
-1999-03-02 09:44:33 10HmbZ-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 10HmbZ-0005vi-00 bits    256
-1999-03-02 09:44:33 10HmbZ-0005vi-00 => notreq@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmcA-0005vi-00"
-1999-03-02 09:44:33 10HmbZ-0005vi-00 Completed


 ******** SERVER ********
 1999-03-02 09:44:33 exim x.yz daemon started: pid=pppp, no queue runs, listening for SMTP on port PORT_D
@@ -276,82 +200,3 @@
 1999-03-02 09:44:33 10HmbN-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=no S=sss id=E10HmbM-0005vi-00@??? for noverify_resume@???
 1999-03-02 09:44:33 10HmbN-0005vi-00 => :blackhole: <noverify_resume@???> R=server
 1999-03-02 09:44:33 10HmbN-0005vi-00 Completed
-1999-03-02 09:44:33 exim x.yz daemon started: pid=pppp, no queue runs, listening for SMTP on port PORT_D
-1999-03-02 09:44:33 tls_in_resumption    client requested new ticket, server provided
-1999-03-02 09:44:33 our cert subject    CN=server1.example.com
-1999-03-02 09:44:33 peer cert subject    
-1999-03-02 09:44:33 peer cert verified    0
-1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    4
-1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 bits    256
-1999-03-02 09:44:33 10HmbP-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmbO-0005vi-00@??? for getticket@???
-1999-03-02 09:44:33 10HmbP-0005vi-00 => :blackhole: <getticket@???> R=server
-1999-03-02 09:44:33 10HmbP-0005vi-00 Completed
-1999-03-02 09:44:33 tls_in_resumption    session resumed
-1999-03-02 09:44:33 our cert subject    CN=server1.example.com
-1999-03-02 09:44:33 peer cert subject    
-1999-03-02 09:44:33 peer cert verified    0
-1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    0
-1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 bits    256
-1999-03-02 09:44:33 10HmbR-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=no S=sss id=E10HmbQ-0005vi-00@??? for resume@??? xyz@???
-1999-03-02 09:44:33 10HmbR-0005vi-00 => :blackhole: <xyz@???> R=server
-1999-03-02 09:44:33 10HmbR-0005vi-00 => :blackhole: <resume@???> R=server
-1999-03-02 09:44:33 10HmbR-0005vi-00 Completed
-1999-03-02 09:44:33 tls_in_resumption    not requested or offered
-1999-03-02 09:44:33 our cert subject    CN=server1.example.com
-1999-03-02 09:44:33 peer cert subject    
-1999-03-02 09:44:33 peer cert verified    0
-1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    4
-1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 bits    256
-1999-03-02 09:44:33 10HmbS-0005vi-00 <= CALLER@??? H=the.local.host.name (myhost.test.ex) [ip4.ip4.ip4.ip4] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmbQ-0005vi-00@??? for abcd@???
-1999-03-02 09:44:33 10HmbS-0005vi-00 => :blackhole: <abcd@???> R=server
-1999-03-02 09:44:33 10HmbS-0005vi-00 Completed
-1999-03-02 09:44:33 tls_in_resumption    session resumed, also new ticket
-1999-03-02 09:44:33 our cert subject    CN=server1.example.com
-1999-03-02 09:44:33 peer cert subject    
-1999-03-02 09:44:33 peer cert verified    0
-1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    0
-1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 bits    256
-1999-03-02 09:44:33 10HmbU-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=no S=sss id=E10HmbT-0005vi-00@??? for renewal@???
-1999-03-02 09:44:33 10HmbU-0005vi-00 => :blackhole: <renewal@???> R=server
-1999-03-02 09:44:33 10HmbU-0005vi-00 Completed
-1999-03-02 09:44:33 tls_in_resumption    session resumed
-1999-03-02 09:44:33 our cert subject    CN=server1.example.com
-1999-03-02 09:44:33 peer cert subject    
-1999-03-02 09:44:33 peer cert verified    0
-1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    0
-1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 bits    256
-1999-03-02 09:44:33 10HmbW-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=no S=sss id=E10HmbV-0005vi-00@??? for postrenewal@???
-1999-03-02 09:44:33 10HmbW-0005vi-00 => :blackhole: <postrenewal@???> R=server
-1999-03-02 09:44:33 10HmbW-0005vi-00 Completed
-1999-03-02 09:44:33 tls_in_resumption    session resumed, also new ticket
-1999-03-02 09:44:33 our cert subject    CN=server1.example.com
-1999-03-02 09:44:33 peer cert subject    
-1999-03-02 09:44:33 peer cert verified    0
-1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    0
-1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 bits    256
-1999-03-02 09:44:33 10HmbY-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=no S=sss id=E10HmbX-0005vi-00@??? for timeout@???
-1999-03-02 09:44:33 10HmbY-0005vi-00 => :blackhole: <timeout@???> R=server
-1999-03-02 09:44:33 10HmbY-0005vi-00 Completed
-1999-03-02 09:44:33 tls_in_resumption    client requested new ticket, server provided
-1999-03-02 09:44:33 our cert subject    CN=server1.example.com
-1999-03-02 09:44:33 peer cert subject    
-1999-03-02 09:44:33 peer cert verified    0
-1999-03-02 09:44:33 peer dn    
-1999-03-02 09:44:33 ocsp    4
-1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
-1999-03-02 09:44:33 bits    256
-1999-03-02 09:44:33 10HmcA-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmbZ-0005vi-00@??? for notreq@???
-1999-03-02 09:44:33 10HmcA-0005vi-00 => :blackhole: <notreq@???> R=server
-1999-03-02 09:44:33 10HmcA-0005vi-00 Completed
diff --git a/test/log/5894 b/test/log/5894
new file mode 100644
index 0000000..429c345
--- /dev/null
+++ b/test/log/5894
@@ -0,0 +1,143 @@
+1999-03-02 09:44:33 10HmaX-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for getticket@???
+1999-03-02 09:44:33 10HmaX-0005vi-00 tls_out_resumption client requested new ticket, server provided
+1999-03-02 09:44:33 10HmaX-0005vi-00 our cert subject    
+1999-03-02 09:44:33 10HmaX-0005vi-00 peer cert subject    CN=server1.example.com
+1999-03-02 09:44:33 10HmaX-0005vi-00 peer cert verified    1
+1999-03-02 09:44:33 10HmaX-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmaX-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 10HmaX-0005vi-00 bits    256
+1999-03-02 09:44:33 10HmaX-0005vi-00 => getticket@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmaY-0005vi-00"
+1999-03-02 09:44:33 10HmaX-0005vi-00 Completed
+1999-03-02 09:44:33 10HmaZ-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for resume@??? abcd@??? xyz@???
+1999-03-02 09:44:33 10HmaZ-0005vi-00 tls_out_resumption session resumed
+1999-03-02 09:44:33 10HmaZ-0005vi-00 our cert subject    
+1999-03-02 09:44:33 10HmaZ-0005vi-00 peer cert subject    CN=server1.example.com
+1999-03-02 09:44:33 10HmaZ-0005vi-00 peer cert verified    1
+1999-03-02 09:44:33 10HmaZ-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmaZ-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 10HmaZ-0005vi-00 bits    256
+1999-03-02 09:44:33 10HmaZ-0005vi-00 tls_out_resumption not requested or offered
+1999-03-02 09:44:33 10HmaZ-0005vi-00 our cert subject    
+1999-03-02 09:44:33 10HmaZ-0005vi-00 peer cert subject    CN=server1.example.com
+1999-03-02 09:44:33 10HmaZ-0005vi-00 peer cert verified    1
+1999-03-02 09:44:33 10HmaZ-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmaZ-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 10HmaZ-0005vi-00 bits    256
+1999-03-02 09:44:33 10HmaZ-0005vi-00 => resume@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbA-0005vi-00"
+1999-03-02 09:44:33 10HmaZ-0005vi-00 -> xyz@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbA-0005vi-00"
+1999-03-02 09:44:33 10HmaZ-0005vi-00 => abcd@??? R=client T=send_to_server2 H=ip4.ip4.ip4.ip4 [ip4.ip4.ip4.ip4] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbB-0005vi-00"
+1999-03-02 09:44:33 10HmaZ-0005vi-00 Completed
+1999-03-02 09:44:33 10HmbC-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for renewal@???
+1999-03-02 09:44:33 10HmbC-0005vi-00 tls_out_resumption session resumed, also new ticket
+1999-03-02 09:44:33 10HmbC-0005vi-00 our cert subject    
+1999-03-02 09:44:33 10HmbC-0005vi-00 peer cert subject    CN=server1.example.com
+1999-03-02 09:44:33 10HmbC-0005vi-00 peer cert verified    1
+1999-03-02 09:44:33 10HmbC-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmbC-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 10HmbC-0005vi-00 bits    256
+1999-03-02 09:44:33 10HmbC-0005vi-00 => renewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbD-0005vi-00"
+1999-03-02 09:44:33 10HmbC-0005vi-00 Completed
+1999-03-02 09:44:33 10HmbE-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for postrenewal@???
+1999-03-02 09:44:33 10HmbE-0005vi-00 tls_out_resumption session resumed
+1999-03-02 09:44:33 10HmbE-0005vi-00 our cert subject    
+1999-03-02 09:44:33 10HmbE-0005vi-00 peer cert subject    CN=server1.example.com
+1999-03-02 09:44:33 10HmbE-0005vi-00 peer cert verified    1
+1999-03-02 09:44:33 10HmbE-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmbE-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 10HmbE-0005vi-00 bits    256
+1999-03-02 09:44:33 10HmbE-0005vi-00 => postrenewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbF-0005vi-00"
+1999-03-02 09:44:33 10HmbE-0005vi-00 Completed
+1999-03-02 09:44:33 10HmbG-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for timeout@???
+1999-03-02 09:44:33 10HmbG-0005vi-00 tls_out_resumption session resumed, also new ticket
+1999-03-02 09:44:33 10HmbG-0005vi-00 our cert subject    
+1999-03-02 09:44:33 10HmbG-0005vi-00 peer cert subject    CN=server1.example.com
+1999-03-02 09:44:33 10HmbG-0005vi-00 peer cert verified    1
+1999-03-02 09:44:33 10HmbG-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmbG-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 10HmbG-0005vi-00 bits    256
+1999-03-02 09:44:33 10HmbG-0005vi-00 => timeout@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbH-0005vi-00"
+1999-03-02 09:44:33 10HmbG-0005vi-00 Completed
+1999-03-02 09:44:33 10HmbI-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for notreq@???
+1999-03-02 09:44:33 10HmbI-0005vi-00 tls_out_resumption not requested or offered
+1999-03-02 09:44:33 10HmbI-0005vi-00 our cert subject    
+1999-03-02 09:44:33 10HmbI-0005vi-00 peer cert subject    CN=server1.example.com
+1999-03-02 09:44:33 10HmbI-0005vi-00 peer cert verified    1
+1999-03-02 09:44:33 10HmbI-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmbI-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 10HmbI-0005vi-00 bits    256
+1999-03-02 09:44:33 10HmbI-0005vi-00 => notreq@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbJ-0005vi-00"
+1999-03-02 09:44:33 10HmbI-0005vi-00 Completed
+
+******** SERVER ********
+1999-03-02 09:44:33 exim x.yz daemon started: pid=pppp, no queue runs, listening for SMTP on port PORT_D
+1999-03-02 09:44:33 tls_in_resumption    client requested new ticket, server provided
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
+1999-03-02 09:44:33 peer cert subject    
+1999-03-02 09:44:33 peer cert verified    0
+1999-03-02 09:44:33 peer dn    
+1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 bits    256
+1999-03-02 09:44:33 10HmaY-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmaX-0005vi-00@??? for getticket@???
+1999-03-02 09:44:33 10HmaY-0005vi-00 => :blackhole: <getticket@???> R=server
+1999-03-02 09:44:33 10HmaY-0005vi-00 Completed
+1999-03-02 09:44:33 tls_in_resumption    session resumed
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
+1999-03-02 09:44:33 peer cert subject    
+1999-03-02 09:44:33 peer cert verified    0
+1999-03-02 09:44:33 peer dn    
+1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 bits    256
+1999-03-02 09:44:33 10HmbA-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=no S=sss id=E10HmaZ-0005vi-00@??? for resume@??? xyz@???
+1999-03-02 09:44:33 10HmbA-0005vi-00 => :blackhole: <xyz@???> R=server
+1999-03-02 09:44:33 10HmbA-0005vi-00 => :blackhole: <resume@???> R=server
+1999-03-02 09:44:33 10HmbA-0005vi-00 Completed
+1999-03-02 09:44:33 tls_in_resumption    not requested or offered
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
+1999-03-02 09:44:33 peer cert subject    
+1999-03-02 09:44:33 peer cert verified    0
+1999-03-02 09:44:33 peer dn    
+1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 bits    256
+1999-03-02 09:44:33 10HmbB-0005vi-00 <= CALLER@??? H=the.local.host.name (myhost.test.ex) [ip4.ip4.ip4.ip4] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmaZ-0005vi-00@??? for abcd@???
+1999-03-02 09:44:33 10HmbB-0005vi-00 => :blackhole: <abcd@???> R=server
+1999-03-02 09:44:33 10HmbB-0005vi-00 Completed
+1999-03-02 09:44:33 tls_in_resumption    session resumed, also new ticket
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
+1999-03-02 09:44:33 peer cert subject    
+1999-03-02 09:44:33 peer cert verified    0
+1999-03-02 09:44:33 peer dn    
+1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 bits    256
+1999-03-02 09:44:33 10HmbD-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=no S=sss id=E10HmbC-0005vi-00@??? for renewal@???
+1999-03-02 09:44:33 10HmbD-0005vi-00 => :blackhole: <renewal@???> R=server
+1999-03-02 09:44:33 10HmbD-0005vi-00 Completed
+1999-03-02 09:44:33 tls_in_resumption    session resumed
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
+1999-03-02 09:44:33 peer cert subject    
+1999-03-02 09:44:33 peer cert verified    0
+1999-03-02 09:44:33 peer dn    
+1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 bits    256
+1999-03-02 09:44:33 10HmbF-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=no S=sss id=E10HmbE-0005vi-00@??? for postrenewal@???
+1999-03-02 09:44:33 10HmbF-0005vi-00 => :blackhole: <postrenewal@???> R=server
+1999-03-02 09:44:33 10HmbF-0005vi-00 Completed
+1999-03-02 09:44:33 tls_in_resumption    session resumed, also new ticket
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
+1999-03-02 09:44:33 peer cert subject    
+1999-03-02 09:44:33 peer cert verified    0
+1999-03-02 09:44:33 peer dn    
+1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 bits    256
+1999-03-02 09:44:33 10HmbH-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=no S=sss id=E10HmbG-0005vi-00@??? for timeout@???
+1999-03-02 09:44:33 10HmbH-0005vi-00 => :blackhole: <timeout@???> R=server
+1999-03-02 09:44:33 10HmbH-0005vi-00 Completed
+1999-03-02 09:44:33 tls_in_resumption    client requested new ticket, server provided
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
+1999-03-02 09:44:33 peer cert subject    
+1999-03-02 09:44:33 peer cert verified    0
+1999-03-02 09:44:33 peer dn    
+1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 bits    256
+1999-03-02 09:44:33 10HmbJ-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmbI-0005vi-00@??? for notreq@???
+1999-03-02 09:44:33 10HmbJ-0005vi-00 => :blackhole: <notreq@???> R=server
+1999-03-02 09:44:33 10HmbJ-0005vi-00 Completed
diff --git a/test/log/5895 b/test/log/5895
new file mode 100644
index 0000000..fa15df2
--- /dev/null
+++ b/test/log/5895
@@ -0,0 +1,157 @@
+1999-03-02 09:44:33 10HmaX-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for getticket@???
+1999-03-02 09:44:33 10HmaX-0005vi-00 tls_out_resumption client requested new ticket, server provided
+1999-03-02 09:44:33 10HmaX-0005vi-00 our cert subject    
+1999-03-02 09:44:33 10HmaX-0005vi-00 peer cert subject    CN=server1.example.com
+1999-03-02 09:44:33 10HmaX-0005vi-00 peer cert verified    1
+1999-03-02 09:44:33 10HmaX-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmaX-0005vi-00 ocsp    4
+1999-03-02 09:44:33 10HmaX-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 10HmaX-0005vi-00 bits    256
+1999-03-02 09:44:33 10HmaX-0005vi-00 => getticket@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmaY-0005vi-00"
+1999-03-02 09:44:33 10HmaX-0005vi-00 Completed
+1999-03-02 09:44:33 10HmaZ-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for resume@??? abcd@??? xyz@???
+1999-03-02 09:44:33 10HmaZ-0005vi-00 tls_out_resumption session resumed
+1999-03-02 09:44:33 10HmaZ-0005vi-00 our cert subject    
+1999-03-02 09:44:33 10HmaZ-0005vi-00 peer cert subject    CN=server1.example.com
+1999-03-02 09:44:33 10HmaZ-0005vi-00 peer cert verified    1
+1999-03-02 09:44:33 10HmaZ-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmaZ-0005vi-00 ocsp    4
+1999-03-02 09:44:33 10HmaZ-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 10HmaZ-0005vi-00 bits    256
+1999-03-02 09:44:33 10HmaZ-0005vi-00 tls_out_resumption not requested or offered
+1999-03-02 09:44:33 10HmaZ-0005vi-00 our cert subject    
+1999-03-02 09:44:33 10HmaZ-0005vi-00 peer cert subject    CN=server1.example.com
+1999-03-02 09:44:33 10HmaZ-0005vi-00 peer cert verified    1
+1999-03-02 09:44:33 10HmaZ-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmaZ-0005vi-00 ocsp    4
+1999-03-02 09:44:33 10HmaZ-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 10HmaZ-0005vi-00 bits    256
+1999-03-02 09:44:33 10HmaZ-0005vi-00 => resume@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbA-0005vi-00"
+1999-03-02 09:44:33 10HmaZ-0005vi-00 -> xyz@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbA-0005vi-00"
+1999-03-02 09:44:33 10HmaZ-0005vi-00 => abcd@??? R=client T=send_to_server2 H=ip4.ip4.ip4.ip4 [ip4.ip4.ip4.ip4] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbB-0005vi-00"
+1999-03-02 09:44:33 10HmaZ-0005vi-00 Completed
+1999-03-02 09:44:33 10HmbC-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for renewal@???
+1999-03-02 09:44:33 10HmbC-0005vi-00 tls_out_resumption session resumed, also new ticket
+1999-03-02 09:44:33 10HmbC-0005vi-00 our cert subject    
+1999-03-02 09:44:33 10HmbC-0005vi-00 peer cert subject    CN=server1.example.com
+1999-03-02 09:44:33 10HmbC-0005vi-00 peer cert verified    1
+1999-03-02 09:44:33 10HmbC-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmbC-0005vi-00 ocsp    4
+1999-03-02 09:44:33 10HmbC-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 10HmbC-0005vi-00 bits    256
+1999-03-02 09:44:33 10HmbC-0005vi-00 => renewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbD-0005vi-00"
+1999-03-02 09:44:33 10HmbC-0005vi-00 Completed
+1999-03-02 09:44:33 10HmbE-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for postrenewal@???
+1999-03-02 09:44:33 10HmbE-0005vi-00 tls_out_resumption session resumed
+1999-03-02 09:44:33 10HmbE-0005vi-00 our cert subject    
+1999-03-02 09:44:33 10HmbE-0005vi-00 peer cert subject    CN=server1.example.com
+1999-03-02 09:44:33 10HmbE-0005vi-00 peer cert verified    1
+1999-03-02 09:44:33 10HmbE-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmbE-0005vi-00 ocsp    4
+1999-03-02 09:44:33 10HmbE-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 10HmbE-0005vi-00 bits    256
+1999-03-02 09:44:33 10HmbE-0005vi-00 => postrenewal@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbF-0005vi-00"
+1999-03-02 09:44:33 10HmbE-0005vi-00 Completed
+1999-03-02 09:44:33 10HmbG-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for timeout@???
+1999-03-02 09:44:33 10HmbG-0005vi-00 tls_out_resumption session resumed, also new ticket
+1999-03-02 09:44:33 10HmbG-0005vi-00 our cert subject    
+1999-03-02 09:44:33 10HmbG-0005vi-00 peer cert subject    CN=server1.example.com
+1999-03-02 09:44:33 10HmbG-0005vi-00 peer cert verified    1
+1999-03-02 09:44:33 10HmbG-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmbG-0005vi-00 ocsp    4
+1999-03-02 09:44:33 10HmbG-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 10HmbG-0005vi-00 bits    256
+1999-03-02 09:44:33 10HmbG-0005vi-00 => timeout@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbH-0005vi-00"
+1999-03-02 09:44:33 10HmbG-0005vi-00 Completed
+1999-03-02 09:44:33 10HmbI-0005vi-00 <= CALLER@??? U=CALLER P=local S=sss for notreq@???
+1999-03-02 09:44:33 10HmbI-0005vi-00 tls_out_resumption not requested or offered
+1999-03-02 09:44:33 10HmbI-0005vi-00 our cert subject    
+1999-03-02 09:44:33 10HmbI-0005vi-00 peer cert subject    CN=server1.example.com
+1999-03-02 09:44:33 10HmbI-0005vi-00 peer cert verified    1
+1999-03-02 09:44:33 10HmbI-0005vi-00 peer dn    /CN=server1.example.com
+1999-03-02 09:44:33 10HmbI-0005vi-00 ocsp    4
+1999-03-02 09:44:33 10HmbI-0005vi-00 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 10HmbI-0005vi-00 bits    256
+1999-03-02 09:44:33 10HmbI-0005vi-00 => notreq@??? R=client T=send_to_server1 H=127.0.0.1 [127.0.0.1] X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=yes DN="/CN=server1.example.com" C="250 OK id=10HmbJ-0005vi-00"
+1999-03-02 09:44:33 10HmbI-0005vi-00 Completed
+
+******** SERVER ********
+1999-03-02 09:44:33 exim x.yz daemon started: pid=pppp, no queue runs, listening for SMTP on port PORT_D
+1999-03-02 09:44:33 tls_in_resumption    client requested new ticket, server provided
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
+1999-03-02 09:44:33 peer cert subject    
+1999-03-02 09:44:33 peer cert verified    0
+1999-03-02 09:44:33 peer dn    
+1999-03-02 09:44:33 ocsp    4
+1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 bits    256
+1999-03-02 09:44:33 10HmaY-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmaX-0005vi-00@??? for getticket@???
+1999-03-02 09:44:33 10HmaY-0005vi-00 => :blackhole: <getticket@???> R=server
+1999-03-02 09:44:33 10HmaY-0005vi-00 Completed
+1999-03-02 09:44:33 tls_in_resumption    session resumed
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
+1999-03-02 09:44:33 peer cert subject    
+1999-03-02 09:44:33 peer cert verified    0
+1999-03-02 09:44:33 peer dn    
+1999-03-02 09:44:33 ocsp    0
+1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 bits    256
+1999-03-02 09:44:33 10HmbA-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=no S=sss id=E10HmaZ-0005vi-00@??? for resume@??? xyz@???
+1999-03-02 09:44:33 10HmbA-0005vi-00 => :blackhole: <xyz@???> R=server
+1999-03-02 09:44:33 10HmbA-0005vi-00 => :blackhole: <resume@???> R=server
+1999-03-02 09:44:33 10HmbA-0005vi-00 Completed
+1999-03-02 09:44:33 tls_in_resumption    not requested or offered
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
+1999-03-02 09:44:33 peer cert subject    
+1999-03-02 09:44:33 peer cert verified    0
+1999-03-02 09:44:33 peer dn    
+1999-03-02 09:44:33 ocsp    4
+1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 bits    256
+1999-03-02 09:44:33 10HmbB-0005vi-00 <= CALLER@??? H=the.local.host.name (myhost.test.ex) [ip4.ip4.ip4.ip4] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmaZ-0005vi-00@??? for abcd@???
+1999-03-02 09:44:33 10HmbB-0005vi-00 => :blackhole: <abcd@???> R=server
+1999-03-02 09:44:33 10HmbB-0005vi-00 Completed
+1999-03-02 09:44:33 tls_in_resumption    session resumed, also new ticket
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
+1999-03-02 09:44:33 peer cert subject    
+1999-03-02 09:44:33 peer cert verified    0
+1999-03-02 09:44:33 peer dn    
+1999-03-02 09:44:33 ocsp    0
+1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 bits    256
+1999-03-02 09:44:33 10HmbD-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=no S=sss id=E10HmbC-0005vi-00@??? for renewal@???
+1999-03-02 09:44:33 10HmbD-0005vi-00 => :blackhole: <renewal@???> R=server
+1999-03-02 09:44:33 10HmbD-0005vi-00 Completed
+1999-03-02 09:44:33 tls_in_resumption    session resumed
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
+1999-03-02 09:44:33 peer cert subject    
+1999-03-02 09:44:33 peer cert verified    0
+1999-03-02 09:44:33 peer dn    
+1999-03-02 09:44:33 ocsp    0
+1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 bits    256
+1999-03-02 09:44:33 10HmbF-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=no S=sss id=E10HmbE-0005vi-00@??? for postrenewal@???
+1999-03-02 09:44:33 10HmbF-0005vi-00 => :blackhole: <postrenewal@???> R=server
+1999-03-02 09:44:33 10HmbF-0005vi-00 Completed
+1999-03-02 09:44:33 tls_in_resumption    session resumed, also new ticket
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
+1999-03-02 09:44:33 peer cert subject    
+1999-03-02 09:44:33 peer cert verified    0
+1999-03-02 09:44:33 peer dn    
+1999-03-02 09:44:33 ocsp    0
+1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 bits    256
+1999-03-02 09:44:33 10HmbH-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx* CV=no S=sss id=E10HmbG-0005vi-00@??? for timeout@???
+1999-03-02 09:44:33 10HmbH-0005vi-00 => :blackhole: <timeout@???> R=server
+1999-03-02 09:44:33 10HmbH-0005vi-00 Completed
+1999-03-02 09:44:33 tls_in_resumption    client requested new ticket, server provided
+1999-03-02 09:44:33 our cert subject    CN=server1.example.com
+1999-03-02 09:44:33 peer cert subject    
+1999-03-02 09:44:33 peer cert verified    0
+1999-03-02 09:44:33 peer dn    
+1999-03-02 09:44:33 ocsp    4
+1999-03-02 09:44:33 cipher    TLS1.x:ke-RSA-AES256-SHAnnn:xxx
+1999-03-02 09:44:33 bits    256
+1999-03-02 09:44:33 10HmbJ-0005vi-00 <= CALLER@??? H=(helo.data.changed) [127.0.0.1] P=esmtps X=TLS1.x:ke-RSA-AES256-SHAnnn:xxx CV=no S=sss id=E10HmbI-0005vi-00@??? for notreq@???
+1999-03-02 09:44:33 10HmbJ-0005vi-00 => :blackhole: <notreq@???> R=server
+1999-03-02 09:44:33 10HmbJ-0005vi-00 Completed
diff --git a/test/scripts/5892-Resume-OpenSSL/5892 b/test/scripts/5892-Resume-OpenSSL/5892
index 6c04424..5a8dd3e 100644
--- a/test/scripts/5892-Resume-OpenSSL/5892
+++ b/test/scripts/5892-Resume-OpenSSL/5892
@@ -1,4 +1,4 @@
-# TLS session resumption
+# TLSv1.2 session resumption
 #
 ### TLS1.2
 exim -DSERVER=server -DOPTION=+no_tlsv1_3 -bd -oX PORT_D
@@ -32,33 +32,4 @@ exim -odf -DVALUE=resume noverify_resume@???
 Dest on this means the server cert will not verify (but try_verify will permit it)
 ****
 killdaemon
-sleep 1
-sudo rm -f DIR/spool/db/tls
-#
-#
-### TLS1.3
-exim -DSERVER=server -bd -oX PORT_D
-****
-exim -DVALUE=resume -odf getticket@???
-Test message. Contains FF: ?
-****
-exim -DVALUE=resume -odf resume@??? abcd@??? xyz@???
-Test message to two different hosts, one does not support resume
-****
-# allow time for ticket to hit renewal time
-sleep 3
-exim -DVALUE=resume -odf renewal@???
-Test message.
-****
-exim -DVALUE=resume -odf postrenewal@???
-Test message.
-****
-sleep 3
-exim -DVALUE=resume -odf timeout@???
-Test message.
-****
-exim -odf notreq@???
-Test message, not requesting resumption.
-****
-killdaemon
 no_msglog_check
diff --git a/test/scripts/5893-Resume-OpenSSL-OCSP/5893 b/test/scripts/5893-Resume-OpenSSL-OCSP/5893
index 18bce1f..a85c3ed 100644
--- a/test/scripts/5893-Resume-OpenSSL-OCSP/5893
+++ b/test/scripts/5893-Resume-OpenSSL-OCSP/5893
@@ -1,4 +1,4 @@
-# TLS session resumption with OCSP
+# TLSv1.2 session resumption with OCSP
 #
 ### TLS1.2
 exim -DSERVER=server -DOPTION=+no_tlsv1_3 -bd -oX PORT_D
@@ -32,33 +32,4 @@ exim -odf -DVALUE=resume noverify_resume@???
 Dest on this means the server cert will not verify (but try_verify will permit it)
 ****
 killdaemon
-sleep 1
-sudo rm -f DIR/spool/db/tls
-#
-#
-### TLS1.3
-exim -DSERVER=server -bd -oX PORT_D
-****
-exim -DVALUE=resume -odf getticket@???
-Test message. Contains FF: ?
-****
-exim -DVALUE=resume -odf resume@??? abcd@??? xyz@???
-Test message to two different hosts, one does not support resume
-****
-# allow time for ticket to hit renewal time
-sleep 3
-exim -DVALUE=resume -odf renewal@???
-Test message.
-****
-exim -DVALUE=resume -odf postrenewal@???
-Test message.
-****
-sleep 3
-exim -DVALUE=resume -odf timeout@???
-Test message.
-****
-exim -odf notreq@???
-Test message, not requesting resumption.
-****
-killdaemon
 no_msglog_check
diff --git a/test/scripts/5894-Resume-OpenSSL-TLS1.3/5894 b/test/scripts/5894-Resume-OpenSSL-TLS1.3/5894
new file mode 100644
index 0000000..722bc9b
--- /dev/null
+++ b/test/scripts/5894-Resume-OpenSSL-TLS1.3/5894
@@ -0,0 +1,28 @@
+# TLSv1.3 session resumption
+#
+### TLS1.3
+exim -DSERVER=server -bd -oX PORT_D
+****
+exim -DVALUE=resume -odf getticket@???
+Test message. Contains FF: ?
+****
+exim -DVALUE=resume -odf resume@??? abcd@??? xyz@???
+Test message to two different hosts, one does not support resume
+****
+# allow time for ticket to hit renewal time
+sleep 3
+exim -DVALUE=resume -odf renewal@???
+Test message.
+****
+exim -DVALUE=resume -odf postrenewal@???
+Test message.
+****
+sleep 3
+exim -DVALUE=resume -odf timeout@???
+Test message.
+****
+exim -odf notreq@???
+Test message, not requesting resumption.
+****
+killdaemon
+no_msglog_check
diff --git a/test/scripts/5894-Resume-OpenSSL-TLS1.3/REQUIRES b/test/scripts/5894-Resume-OpenSSL-TLS1.3/REQUIRES
new file mode 100644
index 0000000..6b79369
--- /dev/null
+++ b/test/scripts/5894-Resume-OpenSSL-TLS1.3/REQUIRES
@@ -0,0 +1,4 @@
+support OpenSSL
+running IPv4
+support TLS_resume
+feature _OPT_OPENSSL_NO_TLSV1_3_X
diff --git a/test/scripts/5895-Resume-OpenSSL-TLS1.3-OCSP/5895 b/test/scripts/5895-Resume-OpenSSL-TLS1.3-OCSP/5895
new file mode 100644
index 0000000..5709b4a
--- /dev/null
+++ b/test/scripts/5895-Resume-OpenSSL-TLS1.3-OCSP/5895
@@ -0,0 +1,28 @@
+# TLSv1.3 session resumption with OCSP
+#
+### TLS1.3
+exim -DSERVER=server -bd -oX PORT_D
+****
+exim -DVALUE=resume -odf getticket@???
+Test message. Contains FF: ?
+****
+exim -DVALUE=resume -odf resume@??? abcd@??? xyz@???
+Test message to two different hosts, one does not support resume
+****
+# allow time for ticket to hit renewal time
+sleep 3
+exim -DVALUE=resume -odf renewal@???
+Test message.
+****
+exim -DVALUE=resume -odf postrenewal@???
+Test message.
+****
+sleep 3
+exim -DVALUE=resume -odf timeout@???
+Test message.
+****
+exim -odf notreq@???
+Test message, not requesting resumption.
+****
+killdaemon
+no_msglog_check
diff --git a/test/scripts/5895-Resume-OpenSSL-TLS1.3-OCSP/REQUIRES b/test/scripts/5895-Resume-OpenSSL-TLS1.3-OCSP/REQUIRES
new file mode 100644
index 0000000..1ba7fa7
--- /dev/null
+++ b/test/scripts/5895-Resume-OpenSSL-TLS1.3-OCSP/REQUIRES
@@ -0,0 +1,5 @@
+support OpenSSL
+running IPv4
+support TLS_resume
+support OCSP
+feature _OPT_OPENSSL_NO_TLSV1_3_X
diff --git a/test/stderr/5892 b/test/stderr/5892
index 6b5c434..6f9aa13 100644
--- a/test/stderr/5892
+++ b/test/stderr/5892
@@ -1,6 +1,4 @@
 ### TLS1.2
-### TLS1.3


******** SERVER ********
### TLS1.2
-### TLS1.3
diff --git a/test/stderr/5893 b/test/stderr/5893
index 6b5c434..6f9aa13 100644
--- a/test/stderr/5893
+++ b/test/stderr/5893
@@ -1,6 +1,4 @@
### TLS1.2
-### TLS1.3

******** SERVER ********
### TLS1.2
-### TLS1.3
diff --git a/test/stderr/5892 b/test/stderr/5894
similarity index 68%
copy from test/stderr/5892
copy to test/stderr/5894
index 6b5c434..28e3af0 100644
--- a/test/stderr/5892
+++ b/test/stderr/5894
@@ -1,6 +1,4 @@
-### TLS1.2
### TLS1.3

******** SERVER ********
-### TLS1.2
### TLS1.3
diff --git a/test/stderr/5892 b/test/stderr/5895
similarity index 68%
copy from test/stderr/5892
copy to test/stderr/5895
index 6b5c434..28e3af0 100644
--- a/test/stderr/5892
+++ b/test/stderr/5895
@@ -1,6 +1,4 @@
-### TLS1.2
### TLS1.3

******** SERVER ********
-### TLS1.2
### TLS1.3
diff --git a/test/stdout/5892 b/test/stdout/5892
index 6b5c434..6f9aa13 100644
--- a/test/stdout/5892
+++ b/test/stdout/5892
@@ -1,6 +1,4 @@
### TLS1.2
-### TLS1.3

******** SERVER ********
### TLS1.2
-### TLS1.3
diff --git a/test/stdout/5893 b/test/stdout/5893
index 6b5c434..6f9aa13 100644
--- a/test/stdout/5893
+++ b/test/stdout/5893
@@ -1,6 +1,4 @@
### TLS1.2
-### TLS1.3

******** SERVER ********
### TLS1.2
-### TLS1.3
diff --git a/test/stderr/5892 b/test/stdout/5894
similarity index 68%
copy from test/stderr/5892
copy to test/stdout/5894
index 6b5c434..28e3af0 100644
--- a/test/stderr/5892
+++ b/test/stdout/5894
@@ -1,6 +1,4 @@
-### TLS1.2
### TLS1.3

******** SERVER ********
-### TLS1.2
### TLS1.3
diff --git a/test/stderr/5892 b/test/stdout/5895
similarity index 68%
copy from test/stderr/5892
copy to test/stdout/5895
index 6b5c434..28e3af0 100644
--- a/test/stderr/5892
+++ b/test/stdout/5895
@@ -1,6 +1,4 @@
-### TLS1.2
### TLS1.3

******** SERVER ********
-### TLS1.2
### TLS1.3