diff --git a/.etckeeper b/.etckeeper index 0873ce21..6286e4fb 100755 --- a/.etckeeper +++ b/.etckeeper @@ -566,9 +566,21 @@ maybe chmod 0600 'docker/key.json' maybe chmod 0755 'dovecot' maybe chmod 0755 'dovecot/conf.d' maybe chmod 0644 'dovecot/conf.d/10-ssl.conf' +maybe chmod 0644 'dovecot/conf.d/20-imap.conf' +maybe chmod 0644 'dovecot/conf.d/90-sieve.conf' maybe chmod 0640 'dovecot/dovecot-mysql.conf' maybe chmod 0644 'dovecot/dovecot.conf' maybe chmod 0700 'dovecot/private' +maybe chmod 0755 'dovecot/sieve' +maybe chmod 0755 'dovecot/sieve-after' +maybe chmod 0644 'dovecot/sieve-after/spam-to-folder.sieve' +maybe chmod 0644 'dovecot/sieve-after/spam-to-folder.svbin' +maybe chown 'vmail' 'dovecot/sieve/learn-ham.sieve' +maybe chgrp 'vmail' 'dovecot/sieve/learn-ham.sieve' +maybe chmod 0600 'dovecot/sieve/learn-ham.sieve' +maybe chown 'vmail' 'dovecot/sieve/learn-spam.sieve' +maybe chgrp 'vmail' 'dovecot/sieve/learn-spam.sieve' +maybe chmod 0600 'dovecot/sieve/learn-spam.sieve' maybe chmod 0644 'dovecot/ssl-params.conf' maybe chmod 0755 'dpkg' maybe chmod 0644 'dpkg/dpkg.cfg' @@ -4033,6 +4045,10 @@ maybe chmod 0644 'nginx/sites-available/.git/logs/refs/remotes/origin/master' maybe chmod 0755 'nginx/sites-available/.git/objects' maybe chmod 0755 'nginx/sites-available/.git/objects/00' maybe chmod 0444 'nginx/sites-available/.git/objects/00/75a2b6c5d3f7de00b0b50d5c80122ea160e315' +maybe chmod 0755 'nginx/sites-available/.git/objects/0b' +maybe chmod 0444 'nginx/sites-available/.git/objects/0b/d138ff086bdf035fb97ca2daf8e2d258e5d405' +maybe chmod 0755 'nginx/sites-available/.git/objects/0d' +maybe chmod 0444 'nginx/sites-available/.git/objects/0d/3430af92c666345f59329dcceff0298758dad6' maybe chmod 0755 'nginx/sites-available/.git/objects/14' maybe chmod 0444 'nginx/sites-available/.git/objects/14/3fad9bf93dc694de2c327db30b613a6aee8e26' maybe chmod 0755 'nginx/sites-available/.git/objects/1d' @@ -4070,6 +4086,8 @@ maybe chmod 0444 'nginx/sites-available/.git/objects/58/2623bcffc148e720bd7b347e maybe chmod 0444 'nginx/sites-available/.git/objects/58/cee42a9d6b9f6eb0cfa2ef02ca3c9eb86f1263' maybe chmod 0755 'nginx/sites-available/.git/objects/5c' maybe chmod 0444 'nginx/sites-available/.git/objects/5c/d97c153858a5bbf8718897a9659ba257d6d1ac' +maybe chmod 0755 'nginx/sites-available/.git/objects/5d' +maybe chmod 0444 'nginx/sites-available/.git/objects/5d/69405acdb20d204c14382e19a6c03192e69ca0' maybe chmod 0755 'nginx/sites-available/.git/objects/67' maybe chmod 0444 'nginx/sites-available/.git/objects/67/3d193d86c1d8c1dd1a64555b80b93e0e2b1134' maybe chmod 0444 'nginx/sites-available/.git/objects/67/87b4bcbf43fe978ab0024ff2c8a90047fe318f' @@ -4503,7 +4521,10 @@ maybe chmod 0644 'rspamd/local.d/dkim_signing.conf' maybe chmod 0644 'rspamd/local.d/logging.inc' maybe chmod 0644 'rspamd/local.d/milter_headers.inc' maybe chmod 0644 'rspamd/local.d/multimap.conf' +maybe chmod 0644 'rspamd/local.d/neural.conf' +maybe chmod 0644 'rspamd/local.d/neural_group.conf' maybe chmod 0644 'rspamd/local.d/options.inc' +maybe chmod 0644 'rspamd/local.d/phishing.conf' maybe chmod 0644 'rspamd/local.d/redis.conf' maybe chmod 0644 'rspamd/local.d/whitelist.sender.domain.map' maybe chmod 0644 'rspamd/local.d/worker-controller.inc' @@ -4668,17 +4689,19 @@ maybe chmod 0755 'ssl' maybe chmod 0755 'ssl/certs' maybe chmod 0644 'ssl/certs/ca-certificates.crt' maybe chmod 0644 'ssl/certs/ca.pem' -maybe chmod 0600 'ssl/certs/isrg-root-ocsp-x1.pem' -maybe chmod 0600 'ssl/certs/isrg-root-x2.pem' -maybe chmod 0600 'ssl/certs/isrgrootx1.pem' maybe chmod 0600 'ssl/certs/lets-encrypt-e1.pem' -maybe chmod 0600 'ssl/certs/lets-encrypt-r3.pem' +maybe chmod 0644 'ssl/certs/lets-encrypt-e2.pem' +maybe chmod 0644 'ssl/certs/lets-encrypt-r3-cross-signed.pem' +maybe chmod 0644 'ssl/certs/lets-encrypt-r4-cross-signed.pem' +maybe chmod 0644 'ssl/certs/lets-encrypt-r4.pem' +maybe chmod 0644 'ssl/certs/lets-encrypt-x3-cross-signed.pem' maybe chown 'caelebfi' 'ssl/certs/securesyslog.crt' maybe chgrp 'caelebfi' 'ssl/certs/securesyslog.crt' maybe chmod 0755 'ssl/certs/securesyslog.crt' maybe chmod 0644 'ssl/certs/ssl-cert-snakeoil.pem' maybe chmod 0644 'ssl/certs/sub.class1.client.ca.pem' maybe chmod 0644 'ssl/certs/sub.class1.server.ca.pem' +maybe chmod 0644 'ssl/certs/trustid-x3-root.pem' maybe chmod 0644 'ssl/openssl.cnf' maybe chgrp 'ssl-cert' 'ssl/private' maybe chmod 0710 'ssl/private' diff --git a/ca-certificates.conf b/ca-certificates.conf index 2541afb6..8ff464e6 100644 --- a/ca-certificates.conf +++ b/ca-certificates.conf @@ -56,7 +56,7 @@ mozilla/Cybertrust_Global_Root.crt mozilla/D-TRUST_Root_Class_3_CA_2_2009.crt mozilla/D-TRUST_Root_Class_3_CA_2_EV_2009.crt !mozilla/DST_ACES_CA_X6.crt -mozilla/DST_Root_CA_X3.crt +!mozilla/DST_Root_CA_X3.crt !mozilla/Deutsche_Telekom_Root_CA_2.crt mozilla/DigiCert_Assured_ID_Root_CA.crt mozilla/DigiCert_Assured_ID_Root_G2.crt @@ -188,7 +188,6 @@ mozilla/ePKI_Root_Certification_Authority.crt mozilla/Certum_Trusted_Network_CA_2.crt mozilla/Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.crt mozilla/Hellenic_Academic_and_Research_Institutions_RootCA_2015.crt -mozilla/ISRG_Root_X1.crt !mozilla/OpenTrust_Root_CA_G1.crt !mozilla/OpenTrust_Root_CA_G2.crt !mozilla/OpenTrust_Root_CA_G3.crt @@ -228,3 +227,4 @@ mozilla/Hongkong_Post_Root_CA_3.crt mozilla/OISTE_WISeKey_Global_Root_GC_CA.crt mozilla/UCA_Extended_Validation_Root.crt mozilla/UCA_Global_G2_Root.crt +mozilla/ISRG_Root_X1.crt diff --git a/dovecot/conf.d/20-imap.conf b/dovecot/conf.d/20-imap.conf new file mode 100644 index 00000000..eebc300e --- /dev/null +++ b/dovecot/conf.d/20-imap.conf @@ -0,0 +1,76 @@ +## +## IMAP specific settings +## + +# If nothing happens for this long while client is IDLEing, move the connection +# to imap-hibernate process and close the old imap process. This saves memory, +# because connections use very little memory in imap-hibernate process. The +# downside is that recreating the imap process back uses some resources. +#imap_hibernate_timeout = 0 + +# Maximum IMAP command line length. Some clients generate very long command +# lines with huge mailboxes, so you may need to raise this if you get +# "Too long argument" or "IMAP command line too large" errors often. +#imap_max_line_length = 64k + +# IMAP logout format string: +# %i - total number of bytes read from client +# %o - total number of bytes sent to client +# %{fetch_hdr_count} - Number of mails with mail header data sent to client +# %{fetch_hdr_bytes} - Number of bytes with mail header data sent to client +# %{fetch_body_count} - Number of mails with mail body data sent to client +# %{fetch_body_bytes} - Number of bytes with mail body data sent to client +# %{deleted} - Number of mails where client added \Deleted flag +# %{expunged} - Number of mails that client expunged +# %{trashed} - Number of mails that client copied/moved to the +# special_use=\Trash mailbox. +#imap_logout_format = in=%i out=%o + +# Override the IMAP CAPABILITY response. If the value begins with '+', +# add the given capabilities on top of the defaults (e.g. +XFOO XBAR). +#imap_capability = + +# How long to wait between "OK Still here" notifications when client is +# IDLEing. +#imap_idle_notify_interval = 2 mins + +# ID field names and values to send to clients. Using * as the value makes +# Dovecot use the default value. The following fields have default values +# currently: name, version, os, os-version, support-url, support-email. +#imap_id_send = + +# ID fields sent by client to log. * means everything. +#imap_id_log = + +# Workarounds for various client bugs: +# delay-newmail: +# Send EXISTS/RECENT new mail notifications only when replying to NOOP +# and CHECK commands. Some clients ignore them otherwise, for example OSX +# Mail (:]path[;