.IR hostname ]
.RB [ \-user
.IR username ]
-.RB [ \-sasl ]
+.RB [ \-sasl " | " \-nosasl ]
.RB [ \-saslmech
.IR mechanism ]
.RB [ \-initialtls ]
.RB [ \-notls ]
+.RB [ \-certverify " | " \-nocertverify ]
.RB [ \-authservice
.IR service ]
.RB [ \-snoop ]
switch. The
.B \-notls
switch will disable all attempts to negotiate TLS.
+.PP
+When using TLS the default is to verify the remote certificate and SubjectName
+against the local trusted certificate store. This can be controlled by
+the
+.B \-certverify
+and
+.B \-nocertverify
+switches. See your OpenSSL documentation for more information on certificate
+verification.
.SH FILES
.fc ^ ~
.nf