[mailserver] Disable plain imap (143)
This commit is contained in:
parent
32fc4122bd
commit
f026e3a166
4 changed files with 20 additions and 7 deletions
|
@ -1 +0,0 @@
|
||||||
tcp dport {143, 993} accept comment "Allow IMAP/IMAPS from all"
|
|
|
@ -60,6 +60,15 @@
|
||||||
group: vmail
|
group: vmail
|
||||||
recurse: true
|
recurse: true
|
||||||
|
|
||||||
|
- name: Disable plain imap inet_listener
|
||||||
|
become: true
|
||||||
|
ansible.builtin.lineinfile:
|
||||||
|
path: /etc/dovecot/conf.d/10-master.conf
|
||||||
|
regexp: '^\s*#?port = 143'
|
||||||
|
line: ' port = 0'
|
||||||
|
insertafter: ' inet_listener imap {'
|
||||||
|
notify: Reload dovecot service
|
||||||
|
|
||||||
- name: Add login to auth_mechanisms
|
- name: Add login to auth_mechanisms
|
||||||
become: true
|
become: true
|
||||||
ansible.builtin.lineinfile:
|
ansible.builtin.lineinfile:
|
||||||
|
@ -321,18 +330,18 @@
|
||||||
- spam
|
- spam
|
||||||
- ham
|
- ham
|
||||||
|
|
||||||
- name: Allow incoming IMAP/IMAPS
|
- name: Allow incoming IMAPS
|
||||||
become: true
|
become: true
|
||||||
ansible.builtin.copy:
|
ansible.builtin.template:
|
||||||
src: nftables/input.d/imap-imaps.conf
|
src: nftables/input.d/imaps.conf.j2
|
||||||
dest: /etc/nftables/input.d/imap-imaps.conf
|
dest: /etc/nftables/input.d/imaps.conf
|
||||||
mode: 0640
|
mode: 0640
|
||||||
notify: Reload nftables service
|
notify: Reload nftables service
|
||||||
|
|
||||||
- name: Allow incoming ManageSieve
|
- name: Allow incoming ManageSieve
|
||||||
become: true
|
become: true
|
||||||
ansible.builtin.copy:
|
ansible.builtin.template:
|
||||||
src: nftables/input.d/managesieve.conf
|
src: nftables/input.d/managesieve.conf.j2
|
||||||
dest: /etc/nftables/input.d/managesieve.conf
|
dest: /etc/nftables/input.d/managesieve.conf
|
||||||
mode: 0640
|
mode: 0640
|
||||||
notify: Reload nftables service
|
notify: Reload nftables service
|
||||||
|
|
|
@ -0,0 +1,3 @@
|
||||||
|
# {{ ansible_managed }}
|
||||||
|
|
||||||
|
tcp dport 993 accept comment "Allow IMAPS from all"
|
|
@ -1 +1,3 @@
|
||||||
|
# {{ ansible_managed }}
|
||||||
|
|
||||||
tcp dport 4190 accept comment "Allow ManageSieve from all"
|
tcp dport 4190 accept comment "Allow ManageSieve from all"
|
Loading…
Reference in a new issue