Separate tls key/cert options for imap, submission and smtp

This commit is contained in:
Julian Rother 2025-01-29 17:23:04 +01:00
parent dd44c7ba8c
commit 9a33043197
Signed by: julian
GPG key ID: C19B924C0CD13341
4 changed files with 14 additions and 8 deletions

View file

@ -3,8 +3,8 @@ protocols = imap sieve
mail_plugins = $mail_plugins quota
ssl = required
ssl_cert = <{{ mailserver.tls_cert }}
ssl_key = <{{ mailserver.tls_key }}
ssl_cert = <{{ mailserver.imap_tls_cert }}
ssl_key = <{{ mailserver.imap_tls_key }}
ssl_dh = </etc/ssl/dh-4096.pem
ssl_min_protocol = TLSv1.2
ssl_cipher_list = ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384