Mail Server : SSL/TLS Setting2026/06/08 |
|
Configure SSL/TLS to use encrypted connections. |
|
| [1] | |
| [2] | Configure Postfix and Dovecot. |
|
root@mail:~#
vi /etc/postfix/main.cf # add to last line
smtpd_tls_security_level = may
smtpd_tls_cert_file = /etc/letsencrypt/live/mail.srv.world/fullchain.pem
smtpd_tls_key_file = /etc/letsencrypt/live/mail.srv.world/privkey.pem
smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache
root@mail:~#
vi /etc/postfix/master.cf # line 19, 20, 23 : uncomment submission inet n - y - - smtpd -o syslog_name=postfix/submission # -o smtpd_forbid_unauth_pipelining=no # -o smtpd_tls_security_level=encrypt -o smtpd_sasl_auth_enable=yes # add to last line if you like to enable smpts smtps inet n - y - - smtpd -o syslog_name=postfix/smtps -o smtpd_tls_wrappermode=yes -o smtpd_sasl_auth_enable=yes
root@mail:~#
vi /etc/dovecot/conf.d/10-ssl.conf # line 6 : change ssl = yes
# line 18,20 : change to specify your certificates ssl_server_cert_file = /etc/letsencrypt/live/mail.srv.world/fullchain.pem ssl_server_key_file = /etc/letsencrypt/live/mail.srv.world/privkey.pem
systemctl restart postfix dovecot |
| [3] | If UFW is enabled, allow services. SMTP submissions (used with STARTTLS) use [587/TCP], SMTPS uses [465/TCP], POP3S uses [995/TCP], and IMAPS uses [993/TCP]. |
|
root@mail:~# ufw allow submission root@mail:~# ufw allow submissions root@mail:~# ufw allow pop3s root@mail:~# ufw allow imaps Rule added Rule added (v6) |
| [4] | For Client's settings, ( Mozilla Thunderbird ) Open account's property and move to [Server Settings] on the left pane, then Select [STARTTLS] or [SSL/TLS] on [Connection security] field on the right pane. |
|
| [5] | Move to [Outgoing Server] on the left pane, then Select [STARTTLS] or [SSL/TLS] on [Connection security] field. Furthermore, change port to the used port. ([STARTTLS] uses [587], [SSL/TLS] uses 465.) |
|
| [6] | Verify possible to send or receive Emails normally. |
|
| Sponsored Link |
|
|