3 ms·
Icing on the cake: Sprinkle a little Let's Encrypt in there to cover SSL. It doesn't take much to have a cron make a new cert and restart dovecot and postfix.
by twothamendment 9y ago
Icing on the cake: Sprinkle a little Let's Encrypt in there to cover SSL. It doesn't take much to have a cron make a new cert and restart dovecot and postfix.
My setup is similar, but it uses MySQL instead of LDAP.
I love being able to make aliases and even better - deleting them when I'm done with them.
- perlgod 9y agoAuthor here - I plan on switching to Let’s Encrypt once they support ECC certificates.
- zuck9 9y agoWhy do you need ECC certificates?
- perlgod 9y agoI don't need them, I just prefer them. They are arguably more secure and require much lower CPU usage.
- c0l0 9y agoAny reasonably modern x86_64 CPU can do more than 1000 RSA2048 signs (~ TLS handshakes) a second, per core. Performance considerations really aren't a good reason to not use RSA for TLS KEX.
- nirv 9y agoWhile I share your ECC preference, for today I see no reason to refuse free, reasonably secure LE support by default. ECDSA signing with LE's RSA intermediates is supported from Feb 2016, and full ECDSA cert chain will be added on July 2018[1]. [1] https://letsencrypt.org/upcoming-features/ https://letsencrypt.org/upcoming-features/
- wtetzner 9y agoI think they do support ECC certificates: https://cromwell-intl.com/open-source/google-freebsd-tls/tls-certificate.html https://cromwell-intl.com/open-source/google-freebsd-tls/tls...
- dingaling 9y ago> Sprinkle a little Let's Encrypt in there to cover SSL. Unfortunately most MTAs aren't configured to check the certificate chain, so they'll happily take any SSL cert they're handed and start chatting. MITM or downgrading is trivial. There is an IETF draft ( MTA-STS ) from 2017 that should address this.
- twothamendment 9y agoTrue and it will be nice when MTA's check the chain - but all of my mail clients do check or at least complain if it expires.