Email - Dovecot 10-ssl.conf
Email Solution · Config document · referenced from Dovecot authentication
noteThe certificate and key paths name a server of the other site. They are without effect while
ssl = no and must not be taken as the place where the certificates of these servers are; those are under /etc/pki/tls, see TLS and certificates.The TLS settings of Dovecot's own listeners. TLS is switched off: the only network listener in use is IMAP for the webmail on the same host, and the SASL socket for Postfix is a UNIX socket. Stock comments are left out.
| Item | Value |
|---|---|
| Path on the server | /etc/dovecot/conf.d/10-ssl.conf |
| Shown here | DC2-A-VCMSX001 |
| Also on | DC2-B-VCMSX001 and DC2-A-VCMSX002, with the two certificate lines commented out |
| Software | Dovecot 2.2 from the RHEL 7 repository; the exact package release is not recorded |
The file
# TLS off for the Dovecot listeners. The first marker is the earlier state. # CFG-OFF -> ssl = required # CFG-ON -> ssl = no ssl = no # Left over from the first internal server of site 1, built in 2017-2018: # its name and a 4096-bit key. The install notes of the site 2 servers # create no such files, and with "ssl = no" Dovecot does not open them. ssl_cert = </etc/pki/dovecot/certs/dc1-a-vcmsx001-4096.cer ssl_key = </etc/pki/dovecot/private/dc1-a-vcmsx001-4096.key
Differences between the hosts
| Host | Line | Value |
|---|---|---|
DC2-A-VCMSX001 | ssl_cert, ssl_key | active, as shown |
DC2-B-VCMSX001 | ssl_cert, ssl_key | commented out (# ssl_cert = …, # ssl_key = …), same paths |
DC2-A-VCMSX002 | ssl_cert, ssl_key | commented out, same paths |
On DC2-A-VCMSX001 there is also a 10-ssl.conf.rpmnew from a later package update. The stock file in it has ssl = required and the distribution's self-signed /etc/pki/dovecot/certs/dovecot.pem, so both the ssl = no and the certificate paths are local changes.
Checked against Dovecot 2.4.5
| As built | Today |
|---|---|
ssl = no | still valid; the values are yes (default), no and required |
ssl_cert = <file, ssl_key = <file | renamed ssl_server_cert_file and ssl_server_key_file |
ssl_protocols (stock comment) | replaced in 2.3 by ssl_min_protocol, whose default in 2.4 is TLSv1.2 |
CentOS Stream 9 and 10, the upstream of RHEL 9 and 10, still carry Dovecot 2.3, so on RHEL the step from 2.2 to 2.3 comes first and the 2.4 syntax applies with upstream packages only.