Home Forums OS X Server and Client Discussion Mail Cipher Strength on Port 993

Viewing 2 posts - 1 through 2 (of 2 total)
  • Author
    Posts
  • #379556
    Waragainstsleep
    Participant

    Morning all,

    have a customer who ran a security scan on his servers via a 3rd party service. It produced a report and has flagged up an issue with the SSl cipher strength on port 993.

    Here is the line in question:

    “The remote service supports the use of weak SSL ciphers. Description : The remote host supports the use of SSL ciphers that offer either weak encryption or no encryption at all.”

    The server in question is a Mac Mini Server running 10.6 Server using built in Mail service. It is set to require a certificate in order to read POP or IMAP mail. I have found various references to cipher strength for smtp and lmtp in postconfig, I found a couple of likely looking config files that turned out to be empty. Can anyone tell me if and how I can check and change the strength of the cipher being used for secure IMAP please?

    Many thanks.

    #379574
    Waragainstsleep
    Participant

    For anyone who cares its a case of modifying the “ssl_cipher_list =” line in /etc/dovecot/dovecot.conf.

Viewing 2 posts - 1 through 2 (of 2 total)
  • You must be logged in to reply to this topic.

Comments are closed