Todo: DH-Parameter einbinden
Wie in ssl oder dehydrated beschrieben Server-Zertifikat bauen
cd /etc/ssl cp /root/server-ssl/servercert.pem certs/ cp /root/server-ssl/serverkey.pem private/ cp /home/ca/ca.*/cacert.pem certs/
chmod 640 private/serverkey.pem #chgrp ssl private/serverkey.pem
ausführlich: https://ssl-config.mozilla.org/#server=dovecot&config=intermediate
vereinfacht:
ssl = required ssl_cert = </etc/ssl/certs/servercert.pem ssl_key = </etc/ssl/private/serverkey.pem
doveconf ssl_cert doveconf ssl_key systemctl reload dovecot.service
curl -v --ssl-reqd --url imaps://server.example.com:993 --user user1@server.example.com
nc server.example.com 143
..
* OK [CAPABILITY IMAP4rev1 LITERAL+ SASL-IR LOGIN-REFERRALS ID ENABLE IDLE STARTTLS AUTH=PLAIN] Dovecot ready.
testssl server.example.com:993 testssl --starttls=imap server.example.com:143
openssl s_client -starttls imap -CAfile /etc/ssl/certs/cacert.pem -connect server.example.com:143