Courier IMAP settings that survive a package upgrade
Find a file
2026-09-22 18:02:57 +00:00
defaults Guard the port check with its own boolean 2026-09-09 19:10:47 +00:00
handlers Courier IMAP settings that survive a package upgrade 2026-09-09 18:58:46 +00:00
meta Courier IMAP settings that survive a package upgrade 2026-09-09 18:58:46 +00:00
tasks Guard the port check with its own boolean 2026-09-09 19:10:47 +00:00
tests Courier IMAP settings that survive a package upgrade 2026-09-09 18:58:46 +00:00
.ansible-lint Courier IMAP settings that survive a package upgrade 2026-09-09 18:58:46 +00:00
.gitignore Courier IMAP settings that survive a package upgrade 2026-09-09 18:58:46 +00:00
.yamllint Courier IMAP settings that survive a package upgrade 2026-09-09 18:58:46 +00:00
mise.toml Stop the pipx virtualenvs depending on the system Python 2026-09-21 17:04:23 +00:00
README.md Guard the port check with its own boolean 2026-09-09 19:10:47 +00:00
requirements.yml Courier IMAP settings that survive a package upgrade 2026-09-09 18:58:46 +00:00

ansible_role_courier_imap

Courier IMAP settings that survive a package upgrade, on FreeBSD.

What it owns

Named keys in /usr/local/etc/courier-imap/imapd-ssl, and nothing else in that file. It is 13 KB of upstream defaults and comments, so a template would freeze one release's defaults into this repository and fight every upgrade. Owning named keys corrects the upgrade on the next run instead.

key value why
SSLPIDFILE /var/run/imapd-ssl.pid imapd-ssl.rc dereferences it three times; empty starts the daemon with -pid= and it exits
TLS_PROTOCOL TLSv1.2++ a floor, not a list; ++ also disables client-initiated renegotiation
TLS_CIPHER_LIST HIGH the shipped default
TLS_CERTFILE the wildcard certificate

It also sets courier_imap_imapd_ssl_enable in rc.conf, which is what actually starts the service. IMAPDSSLSTART inside the config does not, and reads NO on a working host.

Why these keys

Both have already failed in production, on 2026-09-09.

The 5.3.2 to 6.0.5 upgrade rewrote the config and dropped SSLPIDFILE. IMAPS was down for 33 minutes and the daemon failed with Unknown option '-pid='.

The same file carried TLS_PROTOCOL=TLS1:TLSv1.1:TLSv1.2. This version accepts single tokens only and silently falls back to its documented default of TLSv1 on anything else, so the server had been serving a TLS 1.0 floor. Confirmed with openssl s_client -tls1, which negotiated successfully. TLS 1.3 is negotiated whenever the client offers it; requiring it is not expressible in 6.0.5.

What it will not do

Install courier-imap. If the config file is absent the role fails saying so. Installing a mail server as a side effect of a configuration run is not this role's decision.

Verification

After a change it flushes handlers and waits for port 993, guarded by courier_imap_verify. Twice on the day this was written the file was correct while nothing answered on that port.