LINUXOR.SK ... open source notes ...

Email - Dovecot 10-ssl.conf

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

Email Solution · Config document · referenced from Dovecot authentication

noteThe certificate and key paths name a server of the other site. They are without effect while ssl = no and must not be taken as the place where the certificates of these servers are; those are under /etc/pki/tls, see TLS and certificates.

The TLS settings of Dovecot's own listeners. TLS is switched off: the only network listener in use is IMAP for the webmail on the same host, and the SASL socket for Postfix is a UNIX socket. Stock comments are left out.

ItemValue
Path on the server/etc/dovecot/conf.d/10-ssl.conf
Shown hereDC2-A-VCMSX001
Also onDC2-B-VCMSX001 and DC2-A-VCMSX002, with the two certificate lines commented out
SoftwareDovecot 2.2 from the RHEL 7 repository; the exact package release is not recorded

The file

ini
# TLS off for the Dovecot listeners. The first marker is the earlier state.
# CFG-OFF -> ssl = required
# CFG-ON  -> ssl = no
ssl = no

# Left over from the first internal server of site 1, built in 2017-2018:
# its name and a 4096-bit key. The install notes of the site 2 servers
# create no such files, and with "ssl = no" Dovecot does not open them.
ssl_cert = </etc/pki/dovecot/certs/dc1-a-vcmsx001-4096.cer
ssl_key = </etc/pki/dovecot/private/dc1-a-vcmsx001-4096.key

Differences between the hosts

HostLineValue
DC2-A-VCMSX001ssl_cert, ssl_keyactive, as shown
DC2-B-VCMSX001ssl_cert, ssl_keycommented out (# ssl_cert = …, # ssl_key = …), same paths
DC2-A-VCMSX002ssl_cert, ssl_keycommented out, same paths

On DC2-A-VCMSX001 there is also a 10-ssl.conf.rpmnew from a later package update. The stock file in it has ssl = required and the distribution's self-signed /etc/pki/dovecot/certs/dovecot.pem, so both the ssl = no and the certificate paths are local changes.

Checked against Dovecot 2.4.5

As builtToday
ssl = nostill valid; the values are yes (default), no and required
ssl_cert = <file, ssl_key = <filerenamed ssl_server_cert_file and ssl_server_key_file
ssl_protocols (stock comment)replaced in 2.3 by ssl_min_protocol, whose default in 2.4 is TLSv1.2

CentOS Stream 9 and 10, the upstream of RHEL 9 and 10, still carry Dovecot 2.3, so on RHEL the step from 2.2 to 2.3 comes first and the 2.4 syntax applies with upstream packages only.

← solutionz