Browse Source

Disable SSL ticket support in dovecot

Because tickets are normally only generated on service start, we should disable it to provide better PFS.
Thomas Bella 6 years ago
parent
commit
3983b3d393
1 changed files with 1 additions and 1 deletions
  1. 1 1
      data/conf/dovecot/dovecot.conf

+ 1 - 1
data/conf/dovecot/dovecot.conf

@@ -34,7 +34,7 @@ ssl_prefer_server_ciphers = yes
 ssl_cipher_list = ALL:!ADH:!LOW:!SSLv2:!SSLv3:!EXP:!aNULL:!eNULL:!3DES:!MD5:!PSK:!DSS:!RC4:!SEED:!IDEA:+HIGH:+MEDIUM
 
 # Default in Dovecot 2.3
-ssl_options = no_compression
+ssl_options = no_compression no_ticket
 
 # New in Dovecot 2.3
 ssl_dh=</etc/ssl/mail/dhparams.pem