Email - Roundcube config.inc.php, webmail
Email Solution · Config document · referenced from Webmail
<ROUNDCUBE_DES_KEY> and <ROUNDCUBE_DB_PASSWORD> are placeholders for secrets; <ORGANISATION> and <TIMEZONE> replace a name and a city. A real des_key has to be 24 random characters, unique to the installation.The local configuration of Roundcube: the login domain, the IMAP server, the SMTP server, the database and the plugins. Everything not set here comes from defaults.inc.php of the package. The licence header and the stock comment above each option are left out; the section banners and every active line are as built.
| Item | Value |
|---|---|
| Path on the server | /etc/roundcubemail/config.inc.php |
| Shown here | DC2-A-VCMSX002 |
| Owner | apache:apache, set with chown in the install notes |
| Software | Roundcube (roundcubemail) from EPEL for RHEL 7; the archive does not record the version |
| Activated with | nothing; PHP reads the file on every request |
The file
<?php $config = array(); // ---------------------------------- // SYSTEM // ---------------------------------- $config['username_domain'] = 'ad-dc2.example.net'; $config['username_domain_forced'] = true; $config['product_name'] = '<ORGANISATION> Webmail - DC2'; $config['des_key'] = '<ROUNDCUBE_DES_KEY>'; $config['session_storage'] = 'php'; // ---------------------------------- // LOGGING/DEBUGGING // ---------------------------------- $config['debug_level'] = 1; $config['log_driver'] = 'syslog'; $config['syslog_facility']= LOG_MAIL; $config['syslog_id'] = 'roundcube'; // ---------------------------------- // USER PREFERENCES // ---------------------------------- $config['language'] = 'en_US'; $config['timezone'] = '<TIMEZONE>'; $config['skin'] = 'larry'; $config['create_default_folders'] = true; $config['protect_default_folders'] = true; // ---------------------------------- // SQL DATABASE // ---------------------------------- $config['db_dsnw'] = 'mysql://roundcube:<ROUNDCUBE_DB_PASSWORD>@localhost/roundcube'; // ---------------------------------- // IMAP // ---------------------------------- $config['default_host'] = '127.0.0.1'; $config['default_port'] = 143; // ---------------------------------- // SMTP // ---------------------------------- $config['smtp_server'] = 'ssl://127.0.0.1'; $config['smtp_port'] = 465; $config['smtp_user'] = '%u'; $config['smtp_pass'] = '%p'; // ---------------------------------- // PLUGINS // ---------------------------------- $config['plugins'] = array( 'archive', 'zipdownload', );
Against the install notes
The install notes create this file with cp /etc/roundcubemail/defaults.inc.php /etc/roundcubemail/config.inc.php and then list the answers given to the web installer. The archived file is neither: it is a short file in the layout of config.inc.php.sample with 22 options. Where the two disagree, the file is what ran.
| Option | Install notes (installer answers) | Archived file |
|---|---|---|
default_host | localhost | 127.0.0.1 |
username_domain_forced | not mentioned | true |
session_storage | not mentioned | php |
timezone | not mentioned | set |
create_default_folders, protect_default_folders | not mentioned | true |
plugins | archive | archive, zipdownload |
db_prefix | rc_ | not set |
temp_dir, log_dir | /var/lib/roundcubemail/, /var/log/roundcubemail/ | not set |
ip_check, enable_spellcheck, identities_level | answered | not set |
sent_mbox, trash_mbox, drafts_mbox, junk_mbox | Sent, Trash, Trash, Junk | not set |
mail_pagesize, prefer_html, htmleditor, draft_autosave, mdn_requests | answered | not set |
drafts_mbox: Trash in the notes looks like a slip of the pen; since the option is not in the file, the default of the package applied.
Checked against Roundcube 1.7.4
| As built | Today |
|---|---|
| Roundcube from EPEL 7 | 1.7.4 and the LTS release 1.6.19, both of 2026-09-06. EPEL 9 has 1.5.15, EPEL 10 has 1.6.19 |
default_host, default_port | Renamed in 1.6: imap_host, with the port inside the value, for example localhost:143 |
smtp_server, smtp_port | Renamed in 1.6: smtp_host; the equivalent of the as-built pair is ssl://127.0.0.1:465 |
smtp_user = '%u', smtp_pass = '%p' | Unchanged; these are the defaults since 1.4 |
debug_level | Removed in 1.4 |
skin = 'larry' | The default skin is elastic; Larry left the core in 1.6 |
des_key | Same name, still 24 characters for the default cipher_method, which is still DES-EDE3-CBC; the documentation calls AES-256-CBC the better choice |
session_storage = 'php' | Still valid; the default is db |
plugins: archive, zipdownload | Both still shipped |
| PHP 5 | 1.7 requires PHP 8.1 or later |
| Document root at the application directory | 1.7 makes the public_html/ directory the mandatory document root |
One thing would not survive a move as it is: current PHP verifies the peer certificate and its name on TLS streams by default, and Roundcube connects to ssl://127.0.0.1, while the certificate is issued to the host name. Whether that fails was not tested; smtp_conn_options is the option that carries the TLS settings. Roundcube publishes security fixes about monthly, so the version of a distribution repository deserves a look before it is trusted.