Skip to content

Commit 29e299f

Browse files
author
Till Brehm
committed
Add protection against Poodle attacks in Dovecot 2 and Postfix.
1 parent 53124ed commit 29e299f

8 files changed

+12
-4
lines changed

install/tpl/debian6_dovecot2.conf.master

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,7 @@ log_timestamp = "%Y-%m-%d %H:%M:%S "
66
mail_privileged_group = vmail
77
ssl_cert = </etc/postfix/smtpd.cert
88
ssl_key = </etc/postfix/smtpd.key
9+
ssl_protocols = !SSLv2 !SSLv3
910
passdb {
1011
args = /etc/dovecot/dovecot-sql.conf
1112
driver = sql

install/tpl/debian_dovecot2.conf.master

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@ mail_privileged_group = vmail
77
postmaster_address = postmaster@example.com
88
ssl_cert = </etc/postfix/smtpd.cert
99
ssl_key = </etc/postfix/smtpd.key
10+
ssl_protocols = !SSLv2 !SSLv3
1011
passdb {
1112
args = /etc/dovecot/dovecot-sql.conf
1213
driver = sql

install/tpl/debian_postfix.conf.master

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31,4 +31,5 @@ mime_header_checks = regexp:{config_dir}/mime_header_checks
3131
nested_header_checks = regexp:{config_dir}/nested_header_checks
3232
body_checks = regexp:{config_dir}/body_checks
3333
owner_request_special = no
34-
smtp_tls_security_level = may
34+
smtp_tls_security_level = may
35+
smtpd_tls_mandatory_protocols=!SSLv2, !SSLv3

install/tpl/fedora_dovecot2.conf.master

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,7 @@ log_timestamp = "%Y-%m-%d %H:%M:%S "
66
mail_privileged_group = vmail
77
ssl_cert = </etc/postfix/smtpd.cert
88
ssl_key = </etc/postfix/smtpd.key
9+
ssl_protocols = !SSLv2 !SSLv3
910
passdb {
1011
args = /etc/dovecot-sql.conf
1112
driver = sql

install/tpl/fedora_postfix.conf.master

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,4 +28,5 @@ mime_header_checks = regexp:{config_dir}/mime_header_checks
2828
nested_header_checks = regexp:{config_dir}/nested_header_checks
2929
body_checks = regexp:{config_dir}/body_checks
3030
inet_interfaces = all
31-
smtp_tls_security_level = may
31+
smtp_tls_security_level = may
32+
smtpd_tls_mandatory_protocols=!SSLv2, !SSLv3

install/tpl/gentoo_postfix.conf.master

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,4 +28,5 @@ mime_header_checks = regexp:{config_dir}/mime_header_checks
2828
nested_header_checks = regexp:{config_dir}/nested_header_checks
2929
body_checks = regexp:{config_dir}/body_checks
3030
inet_interfaces = all
31-
smtp_tls_security_level = may
31+
smtp_tls_security_level = may
32+
smtpd_tls_mandatory_protocols=!SSLv2, !SSLv3

install/tpl/opensuse_dovecot2.conf.master

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,7 @@ log_timestamp = "%Y-%m-%d %H:%M:%S "
66
mail_privileged_group = vmail
77
ssl_cert = </etc/postfix/smtpd.cert
88
ssl_key = </etc/postfix/smtpd.key
9+
ssl_protocols = !SSLv2 !SSLv3
910
passdb {
1011
args = /etc/dovecot/dovecot-sql.conf
1112
driver = sql

install/tpl/opensuse_postfix.conf.master

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,4 +30,5 @@ mime_header_checks = regexp:{config_dir}/mime_header_checks
3030
nested_header_checks = regexp:{config_dir}/nested_header_checks
3131
body_checks = regexp:{config_dir}/body_checks
3232
inet_interfaces = all
33-
smtp_tls_security_level = may
33+
smtp_tls_security_level = may
34+
smtpd_tls_mandatory_protocols=!SSLv2, !SSLv3

0 commit comments

Comments
 (0)