<feed xmlns='http://www.w3.org/2005/Atom'>
<title>fripost-ansible/roles/IMAP-proxy/files/etc/stunnel, branch master</title>
<subtitle>Fripost ansible scripts</subtitle>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/'/>
<entry>
<title>Remove the IMAP caching proxy.</title>
<updated>2016-05-28T12:17:19+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2016-05-28T11:52:48+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=0084cd71699b4ad55c2912647f93afa32bbf7671'/>
<id>0084cd71699b4ad55c2912647f93afa32bbf7671</id>
<content type='text'>
Dovecot imapc requires two authentication rounds to the IMAP backend for
each connection.  It seems suboptimal that Roundcube keeps connecting to
the IMAP server for each new connection, but benchmarks shows little
advantage in caching the IMAP sessions with imapproxy:

  http://www.dovecot.org/list/dovecot/2012-February/133544.html
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Dovecot imapc requires two authentication rounds to the IMAP backend for
each connection.  It seems suboptimal that Roundcube keeps connecting to
the IMAP server for each new connection, but benchmarks shows little
advantage in caching the IMAP sessions with imapproxy:

  http://www.dovecot.org/list/dovecot/2012-February/133544.html
</pre>
</div>
</content>
</entry>
<entry>
<title>Use systemd unit files for stunnel4.</title>
<updated>2016-05-12T09:33:55+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2016-05-11T16:07:09+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=90d498034b891123350785a134402172de477f4f'/>
<id>90d498034b891123350785a134402172de477f4f</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>stunnel: disable compression.</title>
<updated>2015-10-27T15:26:24+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2015-10-27T15:26:24+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=c2b9d04ecef5babc028728d4426aab9237b5ce86'/>
<id>c2b9d04ecef5babc028728d4426aab9237b5ce86</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>stunnel: use GCM ciphers only; use SSL options rather than ciphers to disable protocols.</title>
<updated>2015-10-27T15:13:40+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2015-10-27T15:13:40+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=04bd46f2b238c052fe98a538c3601da131ccc343'/>
<id>04bd46f2b238c052fe98a538c3601da131ccc343</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Rename imap.conf → roundcube.conf</title>
<updated>2015-06-07T00:54:24+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2015-06-04T16:57:34+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=e8514e6a5ed5677c52cceb6c526c33d9bb235355'/>
<id>e8514e6a5ed5677c52cceb6c526c33d9bb235355</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>stunnel.conf → imap.conf</title>
<updated>2015-06-07T00:54:09+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2015-06-01T16:42:43+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=2b308feeeaf36017e4255c2685b7a5609b290957'/>
<id>2b308feeeaf36017e4255c2685b7a5609b290957</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Upgrade the webmail configuration from Wheezy to Jessie.</title>
<updated>2015-06-07T00:53:54+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2015-05-31T02:02:00+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=b29601e313e8d35ec7edee343c82ca71ed6a3a12'/>
<id>b29601e313e8d35ec7edee343c82ca71ed6a3a12</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Disable Nagle's algorithm (and SSLv3) in stunnel.</title>
<updated>2015-06-07T00:52:29+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2014-07-04T21:04:17+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=379a4b157c50645bdc7bb134b245bdd6e4938061'/>
<id>379a4b157c50645bdc7bb134b245bdd6e4938061</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Use stunnel to secure the connection from the IMAP proxy to the IMAP server.</title>
<updated>2015-06-07T00:52:15+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2014-07-02T15:54:24+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=7a5cc5032b036f110a19b899cfc264065b473ed1'/>
<id>7a5cc5032b036f110a19b899cfc264065b473ed1</id>
<content type='text'>
The reason is that we don't want to rely on CAs to verify the
certificate of our server.  Dovecot currently doesn't offer a way to
match said cert against a local copy or known fingerprint.  stunnel
does.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The reason is that we don't want to rely on CAs to verify the
certificate of our server.  Dovecot currently doesn't offer a way to
match said cert against a local copy or known fingerprint.  stunnel
does.
</pre>
</div>
</content>
</entry>
</feed>
