summaryrefslogtreecommitdiffstats
path: root/roles/IMAP-proxy/files/etc/stunnel
Commit message (Collapse)AuthorAgeFiles
* Remove the IMAP caching proxy.Guilhem Moulin2016-05-281
| | | | | | | | | Dovecot imapc requires two authentication rounds to the IMAP backend for each connection. It seems suboptimal that Roundcube keeps connecting to the IMAP server for each new connection, but benchmarks shows little advantage in caching the IMAP sessions with imapproxy: http://www.dovecot.org/list/dovecot/2012-February/133544.html
* Use systemd unit files for stunnel4.Guilhem Moulin2016-05-121
|
* stunnel: disable compression.Guilhem Moulin2015-10-271
|
* stunnel: use GCM ciphers only; use SSL options rather than ciphers to ↵Guilhem Moulin2015-10-271
| | | | disable protocols.
* Rename imap.conf → roundcube.confGuilhem Moulin2015-06-071
|
* stunnel.conf → imap.confGuilhem Moulin2015-06-071
|
* Upgrade the webmail configuration from Wheezy to Jessie.Guilhem Moulin2015-06-071
|
* Disable Nagle's algorithm (and SSLv3) in stunnel.Guilhem Moulin2015-06-071
|
* Use stunnel to secure the connection from the IMAP proxy to the IMAP server.Guilhem Moulin2015-06-071
The reason is that we don't want to rely on CAs to verify the certificate of our server. Dovecot currently doesn't offer a way to match said cert against a local copy or known fingerprint. stunnel does.