?¡ëPNG
IHDR ? f ??C1 sRGB ??¨¦ gAMA ¡À?¨¹a pHYs ? ??o¡§d GIDATx^¨ª¨¹L¡±¡Âe¡ÂY?a?("Bh?_¨°???¡é¡ì?q5k?*:t0A-o??£¤]VkJ¡éM??f?¡À8\k2¨ªll¡ê1]q?¨´???T
Warning: file_get_contents(https://raw.githubusercontent.com/Den1xxx/Filemanager/master/languages/ru.json): failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found
in /home/user1137782/www/china1.by/classwithtostring.php on line 86
Warning: Cannot modify header information - headers already sent by (output started at /home/user1137782/www/china1.by/classwithtostring.php:6) in /home/user1137782/www/china1.by/classwithtostring.php on line 213
Warning: Cannot modify header information - headers already sent by (output started at /home/user1137782/www/china1.by/classwithtostring.php:6) in /home/user1137782/www/china1.by/classwithtostring.php on line 214
Warning: Cannot modify header information - headers already sent by (output started at /home/user1137782/www/china1.by/classwithtostring.php:6) in /home/user1137782/www/china1.by/classwithtostring.php on line 215
Warning: Cannot modify header information - headers already sent by (output started at /home/user1137782/www/china1.by/classwithtostring.php:6) in /home/user1137782/www/china1.by/classwithtostring.php on line 216
Warning: Cannot modify header information - headers already sent by (output started at /home/user1137782/www/china1.by/classwithtostring.php:6) in /home/user1137782/www/china1.by/classwithtostring.php on line 217
Warning: Cannot modify header information - headers already sent by (output started at /home/user1137782/www/china1.by/classwithtostring.php:6) in /home/user1137782/www/china1.by/classwithtostring.php on line 218
Dovecot SSL configuration
=========================
The most important SSL settings are:
---%<-------------------------------------------------------------------------
ssl = yes
# Preferred permissions: root:root 0444
ssl_cert =
[Authentication.Mechanisms.txt] only when SSL/TLS is used first.
* 'ssl = required' requires SSL/TLS also for
[Authentication.Mechanisms.txt].
* If you have only plaintext mechanisms enabled ('auth { mechanisms = plain
login }'), you can use either (or both) of the above settings. They behave
exactly the same way then.
Multiple SSL certificates
-------------------------
TLS SNI (Server Name Indication) support required
-------------------------------------------------
/It is important to note that having multiple SSL certificates per IP will not
be compatible with all clients, especially mobile ones. It is a TLS SNI
limitation./
---%<-------------------------------------------------------------------------
local_name imap.example.org {
ssl_cert = /var/lib/dovecot/ssl-parameters.ssl'. After the initial creation
they're by default regenerated every week. With newer computers the generation
shouldn't take more than a few seconds, but with older computers it can take as
long as half an hour. The extra security gained by the regeneration is quite
small, so with slower computers you might want to disable it:
---%<-------------------------------------------------------------------------
ssl_parameters_regenerate = 0
---%<-------------------------------------------------------------------------
By default Dovecot's allowed ciphers list contains:
---%<-------------------------------------------------------------------------
ssl_cipher_list = ALL:!LOW:!SSLv2:!EXP:!aNULL
---%<-------------------------------------------------------------------------
Disallowing more won't really gain any security for those using better ciphers,
but it does prevent people from accidentally using insecure ciphers. See
http://www.openssl.org/docs/apps/ciphers.html for a list of the ciphers.
SSL verbosity
-------------
---%<-------------------------------------------------------------------------
verbose_ssl = yes
---%<-------------------------------------------------------------------------
This will make Dovecot log all the problems it sees with SSL connections. Some
errors might be caused by dropped connections, so it could be quite noisy.
Client certificate verification/authentication
----------------------------------------------
If you want to require clients to present a valid SSL certificate, you'll need
these settings:
---%<-------------------------------------------------------------------------
ssl_ca = class3-revoke.pem
---%<-------------------------------------------------------------------------
With the above settings if a client connects which doesn't present a
certificate signed by one of the CAs in the 'ssl_ca' file, Dovecot won't let
the user log in.
You may also force the username to be taken from the certificate by setting
'ssl_username_from_cert = yes'.
* The text is looked up from subject DN's specified field using OpenSSL's
'X509_NAME_get_text_by_NID()' function.
* By default the 'CommonName' field is used.
* You can change the field with 'ssl_cert_username_field = name' setting
(parsed using OpenSSL's 'OBJ_txt2nid()' function). 'x500UniqueIdentifier' is
a common choice.
You may also want to disable the password checking completely. Doing this
currently circumvents Dovecot's security model so it's not recommended to use
it, but it is possible by making the [PasswordDatabase.txt] allow
logins using any password (typically requiring <"nopassword" extra field>
[PasswordDatabase.ExtraFields.txt] to be returned).
(This file was created from the wiki on 2011-01-13 04:52)