starttls for some services only

Bjoern Jacke lists2020 at j3e.de
Mon Feb 10 15:38:31 EET 2020


Hi,

I would like to disable offering starttls to clients for certain dovecot
services.

Background is that I want to do let a load balancer do the TLS stuff
right on connect time and let dovecot only do plain imap without
offering starttls (because the clients do imaps actually). Getting rid
of the starttls feature offering works only if I set ssl = no globally
only. Setting it in the service imap-login section seems to be
impossible. If I set it globally to no though, I cannot use it in other
services where it is needed like in the manage-sieve, where clients
unfortunately only support starttls and no tls on connect.

Is there any way to configure dovecot to offer starttls for some
services and for some not or is this just not supported currently?

Thanks
Björn


More information about the dovecot mailing list