4ed4ab
diff -up dovecot-2.2.10/doc/example-config/conf.d/10-mail.conf.default-settings dovecot-2.2.10/doc/example-config/conf.d/10-mail.conf
4ed4ab
--- dovecot-2.2.10/doc/example-config/conf.d/10-mail.conf.default-settings	2013-04-23 12:33:55.000000000 +0200
4ed4ab
+++ dovecot-2.2.10/doc/example-config/conf.d/10-mail.conf	2016-06-17 17:56:17.353210369 +0200
4ed4ab
@@ -165,7 +165,7 @@ namespace inbox {
4ed4ab
 # to make sure that users can't log in as daemons or other system users.
4ed4ab
 # Note that denying root logins is hardcoded to dovecot binary and can't
4ed4ab
 # be done even if first_valid_uid is set to 0.
4ed4ab
-#first_valid_uid = 500
4ed4ab
+first_valid_uid = 1000
4ed4ab
 #last_valid_uid = 0
4ed4ab
 
4ed4ab
 # Valid GID range for users, defaults to non-root/wheel. Users having
4ed4ab
@@ -286,6 +286,7 @@ namespace inbox {
4ed4ab
 # them simultaneously.
4ed4ab
 #mbox_read_locks = fcntl
4ed4ab
 #mbox_write_locks = dotlock fcntl
4ed4ab
+mbox_write_locks = fcntl
4ed4ab
 
4ed4ab
 # Maximum time to wait for lock (all of them) before aborting.
4ed4ab
 #mbox_lock_timeout = 5 mins
4ed4ab
diff -up dovecot-2.2.10/doc/example-config/conf.d/10-ssl.conf.default-settings dovecot-2.2.10/doc/example-config/conf.d/10-ssl.conf
4ed4ab
--- dovecot-2.2.10/doc/example-config/conf.d/10-ssl.conf.default-settings	2013-11-19 21:36:30.000000000 +0100
4ed4ab
+++ dovecot-2.2.10/doc/example-config/conf.d/10-ssl.conf	2016-06-17 17:54:18.749626750 +0200
4ed4ab
@@ -3,7 +3,9 @@
4ed4ab
 ##
4ed4ab
 
4ed4ab
 # SSL/TLS support: yes, no, required. <doc/wiki/SSL.txt>
4ed4ab
-#ssl = yes
4ed4ab
+# disable plain pop3 and imap, allowed are only pop3+TLS, pop3s, imap+TLS and imaps
4ed4ab
+# plain imap and pop3 are still allowed for local connections
4ed4ab
+ssl = required
4ed4ab
 
4ed4ab
 # PEM encoded X.509 SSL/TLS certificate and private key. They're opened before
4ed4ab
 # dropping root privileges, so keep the key file unreadable by anyone but