Dovecot not offering TLSv1.2 after a few minutes

Markus Wienhöfer markus at wienhoefer.de
Mon Nov 14 16:14:18 UTC 2022


I have a very strange problem with one of our Dovecot servers (2.2.33.2) on Ubuntu 18.04.

The current configuration allows for TLSv1 to TLSv1.3 connections. I can verify those using testssl.sh, the tests will succeed (although correctly mentioning, that TLSv1 and TLSv1.1 should be disabled). Running the tests again after about 5 minutes, the results are different. TLSv1.2 now shows "not offered and downgraded to a weaker protocol".

Has anybody experienced a similar problem before?

Best regards
Markus
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://dovecot.org/pipermail/dovecot/attachments/20221114/ba1fc9c6/attachment.htm>


More information about the dovecot mailing list