LINUXOR.SK ... open source notes ...

Email - Roundcube config.inc.php, webmail

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

Email Solution · Config document · referenced from Webmail

note<ROUNDCUBE_DES_KEY> and <ROUNDCUBE_DB_PASSWORD> are placeholders for secrets; <ORGANISATION> and <TIMEZONE> replace a name and a city. A real des_key has to be 24 random characters, unique to the installation.

The local configuration of Roundcube: the login domain, the IMAP server, the SMTP server, the database and the plugins. Everything not set here comes from defaults.inc.php of the package. The licence header and the stock comment above each option are left out; the section banners and every active line are as built.

ItemValue
Path on the server/etc/roundcubemail/config.inc.php
Shown hereDC2-A-VCMSX002
Ownerapache:apache, set with chown in the install notes
SoftwareRoundcube (roundcubemail) from EPEL for RHEL 7; the archive does not record the version
Activated withnothing; PHP reads the file on every request

The file

php
<?php

$config = array();

// ----------------------------------
// SYSTEM
// ----------------------------------

$config['username_domain'] = 'ad-dc2.example.net';

$config['username_domain_forced'] = true;

$config['product_name'] = '<ORGANISATION> Webmail - DC2';

$config['des_key'] = '<ROUNDCUBE_DES_KEY>';

$config['session_storage'] = 'php';

// ----------------------------------
// LOGGING/DEBUGGING
// ----------------------------------

$config['debug_level'] = 1;

$config['log_driver'] = 'syslog';

$config['syslog_facility']= LOG_MAIL;

$config['syslog_id'] = 'roundcube';

// ----------------------------------
// USER PREFERENCES
// ----------------------------------

$config['language'] = 'en_US';

$config['timezone'] = '<TIMEZONE>';

$config['skin'] = 'larry';

$config['create_default_folders'] = true;

$config['protect_default_folders'] = true;

// ----------------------------------
// SQL DATABASE
// ----------------------------------

$config['db_dsnw'] = 'mysql://roundcube:<ROUNDCUBE_DB_PASSWORD>@localhost/roundcube';

// ----------------------------------
// IMAP
// ----------------------------------

$config['default_host'] = '127.0.0.1';

$config['default_port'] = 143;

// ----------------------------------
// SMTP
// ----------------------------------

$config['smtp_server'] = 'ssl://127.0.0.1';

$config['smtp_port'] = 465;

$config['smtp_user'] = '%u';

$config['smtp_pass'] = '%p';

// ----------------------------------
// PLUGINS
// ----------------------------------

$config['plugins'] = array(
    'archive',
    'zipdownload',
);

Against the install notes

The install notes create this file with cp /etc/roundcubemail/defaults.inc.php /etc/roundcubemail/config.inc.php and then list the answers given to the web installer. The archived file is neither: it is a short file in the layout of config.inc.php.sample with 22 options. Where the two disagree, the file is what ran.

OptionInstall notes (installer answers)Archived file
default_hostlocalhost127.0.0.1
username_domain_forcednot mentionedtrue
session_storagenot mentionedphp
timezonenot mentionedset
create_default_folders, protect_default_foldersnot mentionedtrue
pluginsarchivearchive, zipdownload
db_prefixrc_not set
temp_dir, log_dir/var/lib/roundcubemail/, /var/log/roundcubemail/not set
ip_check, enable_spellcheck, identities_levelanswerednot set
sent_mbox, trash_mbox, drafts_mbox, junk_mboxSent, Trash, Trash, Junknot set
mail_pagesize, prefer_html, htmleditor, draft_autosave, mdn_requestsanswerednot set

drafts_mbox: Trash in the notes looks like a slip of the pen; since the option is not in the file, the default of the package applied.

Checked against Roundcube 1.7.4

As builtToday
Roundcube from EPEL 71.7.4 and the LTS release 1.6.19, both of 2026-09-06. EPEL 9 has 1.5.15, EPEL 10 has 1.6.19
default_host, default_portRenamed in 1.6: imap_host, with the port inside the value, for example localhost:143
smtp_server, smtp_portRenamed in 1.6: smtp_host; the equivalent of the as-built pair is ssl://127.0.0.1:465
smtp_user = '%u', smtp_pass = '%p'Unchanged; these are the defaults since 1.4
debug_levelRemoved in 1.4
skin = 'larry'The default skin is elastic; Larry left the core in 1.6
des_keySame name, still 24 characters for the default cipher_method, which is still DES-EDE3-CBC; the documentation calls AES-256-CBC the better choice
session_storage = 'php'Still valid; the default is db
plugins: archive, zipdownloadBoth still shipped
PHP 51.7 requires PHP 8.1 or later
Document root at the application directory1.7 makes the public_html/ directory the mandatory document root

One thing would not survive a move as it is: current PHP verifies the peer certificate and its name on TLS streams by default, and Roundcube connects to ssl://127.0.0.1, while the certificate is issued to the host name. Whether that fails was not tested; smtp_conn_options is the option that carries the TLS settings. Roundcube publishes security fixes about monthly, so the version of a distribution repository deserves a look before it is trusted.

← solutionz