Anyone using LetsEncrypt SSL for Dovecot and Postfix?

4 posts / 0 new
Last post
#1 Mon, 09/09/2019 - 11:58
netizen

Anyone using LetsEncrypt SSL for Dovecot and Postfix?

On a GPL server I have created a server matching the hostname of the server (obviously FQDN name). I then issued a LetsEncrypt SSL for the Apache side of things and of course all is working well. I then configured Dovecot and Postfix to use that ssl certificate (by putting the path into Dovecot & Postfix config).

This is from Dovecot: ssl_cert = </home/myserver.mydomain.com/ssl.cert ssl_key = </home/myserver.mydomain.com/ssl.key ssl_ca = /home/myserver.mydomain.com/ssl.ca

Dovecot and Postfix work well of course with the certificate. THE PROBLEM however is that when the system automatically (every 2 months) renews the Apache SSL, dovecot and postfix are not reloaded (or restarted). The result is that clients (IMAP for example) are getting connection errors because Dovecot and Postfix are actually using the expired domain and not the renewed one.

What am I doing wrong here? How can this be fixed?

Tue, 09/10/2019 - 06:46
applejack

Just restart those services after each renewal.

Tue, 09/10/2019 - 06:54
Pierrot

I am doing it but another way, i'm using on the SSL cert page the 2 or 3 buttons saying "copy to Postfix", "copy to Dovecot", ... and I do not have that problem... Maybe something get's written somewhere that restart those services when renewing ?

Tue, 09/10/2019 - 13:40 (Reply to #3)
netizen

This sounds like the solution if you have never had to restart the mail services Thank you

Topic locked