Open mikysal78 opened 4 years ago
@mikysal78 Looks like this setting is available starting with dovecot 2.3.
No!
This output is wrong. The option is called ssl_dh not as printed ssh_dh.
Someone made a mistake there that still isn't fixed.
Yes, we should include DH parameters for Dovecot as well, as done for Postfix and Nginx already:
Postfix:
Nginx:
A reference to the ssl_dh
parameter is missing entirely in the Dovecot-associated installer files.
I'd suggest to add parameter generation logic to dovecot.py
, and reference this file through ssl_dh
in 10-ssl.conf.tpl
.
Log mail.err
root@mx:log # more mail.err Jan 27 00:31:53 mx dovecot: imap-login: Error: Diffie-Hellman key exchange requested, but no DH parameters provided. Set ssh_dh=</path/to/dh.pem