> Hello,
> My mail system is build with postfix, dovecot and roundcube.
> In first time users can view and "manage" their mail only on the webmail.
> So this one (webmail) use IMAP (no tls/ssl at all) authentication to give access to users maildir. This connection is made on the 'loopback' interface and use PLAIN method.
> This works fine (configuration below without ssl parameters).
> That's normal. But client(network) is considered by dovecot as secure, so won't the auth possible without certificate ?
> Can't we make two auth policy to make secure (client crt require) for public IP/client and less "secure" (without crt client) for local process (postfix) and local newtwork( for roundcube ?
> I see section "auth default { ... }" and is used by ... default ! But can we make an other one to make this two particular authentication on the same "instance" ?

If I understood well, you're looking for the config option like
login_trusted_networks (as available in 1.2.11, I don't know since when).

