From e051a6fb4427e9d0e0a6197fe5c11e432814d3ee Mon Sep 17 00:00:00 2001 From: link2xt Date: Sat, 9 Nov 2024 03:54:15 +0000 Subject: [PATCH] Require TLS 1.3 on client-facing ports I tested with -tls1_2 option of openssl s_client that TLS 1.2 connections are no longer possible on any ports except port 25. Port 25 requires at least TLS 1.2 for encrypted connections. --- cmdeploy/src/cmdeploy/dovecot/dovecot.conf.j2 | 2 +- cmdeploy/src/cmdeploy/postfix/master.cf.j2 | 2 ++ 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/cmdeploy/src/cmdeploy/dovecot/dovecot.conf.j2 b/cmdeploy/src/cmdeploy/dovecot/dovecot.conf.j2 index 1390e4db..d6e9e878 100644 --- a/cmdeploy/src/cmdeploy/dovecot/dovecot.conf.j2 +++ b/cmdeploy/src/cmdeploy/dovecot/dovecot.conf.j2 @@ -209,7 +209,7 @@ ssl = required ssl_cert = =TLSv1.3 -o smtpd_sasl_auth_enable=yes -o smtpd_sasl_type=dovecot -o smtpd_sasl_path=private/auth @@ -36,6 +37,7 @@ smtps inet n - y - 5000 smtpd -o syslog_name=postfix/smtps -o smtpd_tls_wrappermode=yes -o smtpd_tls_security_level=encrypt + -o smtpd_tls_mandatory_protocols=>=TLSv1.3 -o smtpd_sasl_auth_enable=yes -o smtpd_sasl_type=dovecot -o smtpd_sasl_path=private/auth