mirror of
https://github.com/Mailu/Mailu.git
synced 2024-12-14 10:53:30 +02:00
a3d8daa585
Ensure that RC4 and SSLv3 is not used. This is based off mailinabox project settings, while not the most ideal settings this improves the configuration from what it is currently.
62 lines
1.5 KiB
CFEngine3
62 lines
1.5 KiB
CFEngine3
###############
|
|
# General
|
|
###############
|
|
|
|
# Main domain and hostname
|
|
mydomain = {{ DOMAIN }}
|
|
myhostname = {{ HOSTNAME }}
|
|
myorigin = $mydomain
|
|
# Relayed networks
|
|
mynetworks = 127.0.0.1/32 [::1]/128 {{ RELAYNETS }}
|
|
# Empty alias list to override the configuration variable and disable NIS
|
|
alias_maps = hash:/etc/aliases
|
|
# SQLite configuration
|
|
sql = sqlite:${config_directory}/
|
|
# Only accept virtual emails
|
|
mydestination =
|
|
# Relayhost if any is configured
|
|
relayhost = {{ RELAYHOST }}
|
|
|
|
###############
|
|
# TLS
|
|
###############
|
|
smtpd_use_tls = yes
|
|
smtpd_tls_cert_file=/certs/cert.pem
|
|
smtpd_tls_key_file=/certs/key.pem
|
|
smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache
|
|
smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache
|
|
smtp_tls_security_level = may
|
|
smtpd_tls_protocols=!SSLv2,!SSLv3
|
|
smtpd_tls_ciphers=medium
|
|
smtpd_tls_exclude_ciphers=aNULL,RC4
|
|
|
|
|
|
###############
|
|
# SASL
|
|
###############
|
|
smtpd_sasl_local_domain = $myhostname
|
|
smtpd_sasl_type = dovecot
|
|
smtpd_sasl_path = inet:imap:2102
|
|
smtpd_sasl_auth_enable = yes
|
|
smtpd_sasl_security_options = noanonymous
|
|
|
|
###############
|
|
# Virtual
|
|
###############
|
|
virtual_mailbox_domains = ${sql}sqlite-virtual_mailbox_domains.cf
|
|
virtual_alias_maps = ${sql}sqlite-virtual_alias_maps.cf
|
|
virtual_transport = lmtp:inet:imap:2525
|
|
lmtp_host_lookup = native
|
|
|
|
###############
|
|
# Milter
|
|
###############
|
|
smtpd_milters = inet:milter:9900
|
|
milter_protocol = 6
|
|
milter_mail_macros = i {mail_addr} {client_addr} {client_name} {auth_authen}
|
|
milter_default_action = tempfail
|
|
|
|
###############
|
|
# Extra Settings
|
|
###############
|