Difference between revisions of "Dovecot"

From ArchWiki
Jump to: navigation, search
(Update the preface)
(Create SSL certs: cleanup)
Line 9: Line 9:
 
[[pacman|Install]] the package {{Pkg|dovecot}} and {{Pkg|pam}} from the [[Official Repositories|official repositories]].
 
[[pacman|Install]] the package {{Pkg|dovecot}} and {{Pkg|pam}} from the [[Official Repositories|official repositories]].
  
==Create SSL certs==
+
==Create the server SSL certificate==
  
The {{Pkg|dovecot}} package contains a script to create your SSL certificate and key. 
+
The {{Pkg|dovecot}} package contains a script to generate the server SSL certificate.
* Before you run this script, create your settings file.
+
{{bc|
+
# cp /etc/ssl/dovecot-openssl.cnf{.sample,}
+
}}
+
* Edit your {{ic|/etc/ssl/dovecot-openssl.cnf}} according to your needs.
+
  
* Then execute the script.
+
* Copy the configuration file from the sample file: {{ic|# cp /etc/ssl/dovecot-openssl.cnf{.sample,} }}.
{{bc|
+
* Edit {{ic|/etc/ssl/dovecot-openssl.cnf}} to configure the certificate.
# /usr/lib/dovecot/mkcert.sh
+
}}
+
  
The cert/key pair is created under {{ic|/etc/ssl/certs}} and {{ic|/etc/ssl/private}}.
+
* Execute {{ic|# /usr/lib/dovecot/mkcert.sh}} to generate the certificate.
 +
 
 +
The certificate/key pair are created as {{ic|/etc/ssl/certs/dovecot.pem}} and {{ic|/etc/ssl/private/dovecot.pem}}.
  
 
==Configuration==
 
==Configuration==

Revision as of 21:51, 1 January 2013


The goal of this article is to setup dovecot, using PAM auth over SSL. It requires an SMTP server already working. You can follow the Sendmail guide to set up sendmail as your SMTP server.

Dovecot is an open source IMAP and POP3 server for Linux/UNIX-like systems, written primarily with security in mind. Developed by Timo Sirainen, Dovecot was first released in July 2002. Dovecot primarily aims to be a lightweight, fast and easy to set up open source mailserver. For more detailed information, please see the official Dovecot Wiki.

Installation

Install the package dovecot and pam from the official repositories.

Create the server SSL certificate

The dovecot package contains a script to generate the server SSL certificate.

  • Copy the configuration file from the sample file: # cp /etc/ssl/dovecot-openssl.cnf{.sample,} .
  • Edit /etc/ssl/dovecot-openssl.cnf to configure the certificate.
  • Execute # /usr/lib/dovecot/mkcert.sh to generate the certificate.

The certificate/key pair are created as /etc/ssl/certs/dovecot.pem and /etc/ssl/private/dovecot.pem.

Configuration

Tango-inaccurate.pngThe factual accuracy of this article or section is disputed.Tango-inaccurate.png

Reason: This section needs to be updated to reflect the new directory structure of the configuration files. (Discuss in Talk:Dovecot#)
  • Create the /etc/pam.d/dovecot file with the following content:
/etc/pam.d/dovecot
auth    required        pam_unix.so nullok
account required        pam_unix.so 
  • Check the correct path where you mail is stored. Normally is /var/spool/mail.
  • Edit the /etc/dovecot/dovecot.conf. Be sure you set the path of ssl_cert, ssl_key and mail_location correctly:
/etc/dovecot/dovecot.conf
listen = *
disable_plaintext_auth=yes
ssl = yes
ssl_cert = </etc/ssl/certs/server.crt
ssl_key = </etc/ssl/private/server.key

mail_access_groups=mail
mail_location = mbox:~/mail:INBOX=/var/spool/mail/%u
passdb {
  driver = pam
}
protocols = imap pop3
service auth {
  user = root
}
service imap-login {
  chroot = login
  user = dovecot
}
service pop3-login {
  chroot = login
  user = dovecot
}
userdb {
  driver = passwd
}
  • Change permissions for the mail_location directory:
chmod 0600 /var/spool/mail/*

Start the server

Start, and optionally, enable for autostart on boot, the dovecot.service daemon.

Read Daemon for more information.