In ASL Ver 3.202 in SMTP-Proxy-Mode a certificate
(/var/chroot-smtp/etc/exim.cert)is generated.
This certificate changes at every reboot and also with other reasons in the meantime.
To establish encrypted connections to ASL, this certificate has to be imported into the other peer in the area of trusted certificates.
The regenerations of the certificate require a continual re-importation into peers. - no reasonable work is possible.