If you need to change the default SSL/TLS ciphers/ protocols Dovecot in DirectAdmin it is important to place these changes in a custom directory.

CustomBuild overrides any changes you make unless you place these changes in a custom directory so CustomBuild recognizes the changes.

Run the following command to create the custom directory and copy the ssl.conf file into it:

cd /usr/local/directadmin/custombuild
mkdir -p custom/dovecot/conf
cp configure/dovecot/conf/ssl.conf custom/dovecot/conf/ssl.conf

Change the ciphers and/or protocols as desired using a file editor such as nano or vim.

For example, if a PCI compliance provider requires TLSv1.2, then change the ssl_min_protocol line in the ssl.conf file to look like this:

ssl_min_protocol = TLSv1.2

To test the available protocols and available ciphers you can use nmap as the root user of the server as follows:

nmap localhost -p 993 --script ssl-enum-ciphers

IMPORTANT: You can run this command from outside the server too, replacing the localhost with the server hostname / IP, or a domain that resolves to the server.
 

 

If you encounter any problems in applying the above instructions please contact us. HostX offers the fastest KVM VPS servers and can offer you specialized assistance in DirectAdmin administration.

Cette réponse était-elle pertinente ? 0 Utilisateurs l'ont trouvée utile (0 Votes)