|
|
||
|---|---|---|
| defaults | ||
| handlers | ||
| meta | ||
| tasks | ||
| tests | ||
| .ansible-lint | ||
| .gitignore | ||
| .yamllint | ||
| mise.toml | ||
| README.md | ||
| requirements.yml | ||
ansible_role_courier_imap
Courier IMAP settings that survive a package upgrade, on FreeBSD.
What it owns
Named keys in /usr/local/etc/courier-imap/imapd-ssl, and nothing else in that
file. It is 13 KB of upstream defaults and comments, so a template would freeze
one release's defaults into this repository and fight every upgrade. Owning
named keys corrects the upgrade on the next run instead.
| key | value | why |
|---|---|---|
SSLPIDFILE |
/var/run/imapd-ssl.pid |
imapd-ssl.rc dereferences it three times; empty starts the daemon with -pid= and it exits |
TLS_PROTOCOL |
TLSv1.2++ |
a floor, not a list; ++ also disables client-initiated renegotiation |
TLS_CIPHER_LIST |
HIGH |
the shipped default |
TLS_CERTFILE |
the wildcard certificate |
It also sets courier_imap_imapd_ssl_enable in rc.conf, which is what
actually starts the service. IMAPDSSLSTART inside the config does not, and
reads NO on a working host.
Why these keys
Both have already failed in production, on 2026-09-09.
The 5.3.2 to 6.0.5 upgrade rewrote the config and dropped SSLPIDFILE. IMAPS
was down for 33 minutes and the daemon failed with Unknown option '-pid='.
The same file carried TLS_PROTOCOL=TLS1:TLSv1.1:TLSv1.2. This version accepts
single tokens only and silently falls back to its documented default of TLSv1
on anything else, so the server had been serving a TLS 1.0 floor. Confirmed with
openssl s_client -tls1, which negotiated successfully. TLS 1.3 is negotiated
whenever the client offers it; requiring it is not expressible in 6.0.5.
What it will not do
Install courier-imap. If the config file is absent the role fails saying so. Installing a mail server as a side effect of a configuration run is not this role's decision.
Verification
After a change it flushes handlers and waits for port 993, guarded by
courier_imap_verify. Twice on the day this was written the file was correct
while nothing answered on that port.