mail_sni: without secure_access_group, ensure mail can read the certificates

Version 1.57.2


Previously, only with secure_access_group enabled, would the cert/key files be chowned to diradmin:mail 640. Without that, they were 600. For apache, this is fine, but with mail_sni enabled, "exim" cannot read them correctly. So if mail_sni is enabled, the diradmin:mail 640 will still be set. Both internal DA code and the have been updated to ensure this is set.

