|
|
70765b |
diff -up dovecot-2.2.18/doc/example-config/conf.d/10-mail.conf.default-settings dovecot-2.2.18/doc/example-config/conf.d/10-mail.conf
|
|
|
70765b |
--- dovecot-2.2.18/doc/example-config/conf.d/10-mail.conf.default-settings 2014-06-02 13:50:10.000000000 +0200
|
|
|
70765b |
+++ dovecot-2.2.18/doc/example-config/conf.d/10-mail.conf 2015-08-24 17:09:03.866648631 +0200
|
|
|
70765b |
@@ -165,7 +165,7 @@ namespace inbox {
|
|
|
70765b |
# to make sure that users can't log in as daemons or other system users.
|
|
|
70765b |
# Note that denying root logins is hardcoded to dovecot binary and can't
|
|
|
70765b |
# be done even if first_valid_uid is set to 0.
|
|
|
70765b |
-#first_valid_uid = 500
|
|
|
70765b |
+first_valid_uid = 1000
|
|
|
70765b |
#last_valid_uid = 0
|
|
|
70765b |
|
|
|
70765b |
# Valid GID range for users, defaults to non-root/wheel. Users having
|
|
|
70765b |
@@ -283,6 +283,7 @@ namespace inbox {
|
|
|
70765b |
# them simultaneously.
|
|
|
70765b |
#mbox_read_locks = fcntl
|
|
|
70765b |
#mbox_write_locks = dotlock fcntl
|
|
|
70765b |
+mbox_write_locks = fcntl
|
|
|
70765b |
|
|
|
70765b |
# Maximum time to wait for lock (all of them) before aborting.
|
|
|
70765b |
#mbox_lock_timeout = 5 mins
|
|
|
70765b |
diff -up dovecot-2.2.18/doc/example-config/conf.d/10-ssl.conf.default-settings dovecot-2.2.18/doc/example-config/conf.d/10-ssl.conf
|
|
|
70765b |
--- dovecot-2.2.18/doc/example-config/conf.d/10-ssl.conf.default-settings 2014-10-03 16:36:00.000000000 +0200
|
|
|
70765b |
+++ dovecot-2.2.18/doc/example-config/conf.d/10-ssl.conf 2015-08-24 17:10:49.536071649 +0200
|
|
|
70765b |
@@ -3,7 +3,9 @@
|
|
|
70765b |
##
|
|
|
70765b |
|
|
|
70765b |
# SSL/TLS support: yes, no, required. <doc/wiki/SSL.txt>
|
|
|
70765b |
-#ssl = yes
|
|
|
70765b |
+# disable plain pop3 and imap, allowed are only pop3+TLS, pop3s, imap+TLS and imaps
|
|
|
70765b |
+# plain imap and pop3 are still allowed for local connections
|
|
|
70765b |
+ssl = required
|
|
|
70765b |
|
|
|
70765b |
# PEM encoded X.509 SSL/TLS certificate and private key. They're opened before
|
|
|
70765b |
# dropping root privileges, so keep the key file unreadable by anyone but
|
|
|
70765b |
@@ -50,6 +52,7 @@ ssl_key =
|
|
|
70765b |
|
|
|
70765b |
# SSL ciphers to use
|
|
|
70765b |
#ssl_cipher_list = ALL:!LOW:!SSLv2:!EXP:!aNULL
|
|
|
70765b |
+ssl_cipher_list = PROFILE=SYSTEM
|
|
|
70765b |
|
|
|
70765b |
# Prefer the server's order of ciphers over client's.
|
|
|
70765b |
#ssl_prefer_server_ciphers = no
|