I have to go figure out exactly how this works now, as I'm likely affected.
When my smtp server connects to, eg gmail's smtp server - I'd ordinarily consider my smtp server the client within the scope of that connection.
So am I supposed to present a tlsclient EKU within outbound connections and tlsserver to incoming connections?