diff options
| author | Yoshinari Takaoka | 2018-10-11 02:27:04 +0900 |
|---|---|---|
| committer | Yoshinari Takaoka | 2018-10-11 02:32:20 +0900 |
| commit | 9c5aae0eb425535621dde79717c2ce4f495a23bb (patch) | |
| tree | 42e4bd39e8d11016f7acb46be61a6030ba117c4f | |
| parent | ec5264047dfaf66c61cd0f4c9b8dd40463693722 (diff) | |
| download | courier-libs-9c5aae0eb425535621dde79717c2ce4f495a23bb.tar.bz2 | |
added comment TLS_PRIVATE_KEYFILE does not support Pass-Phrase
| -rw-r--r-- | imap/imapd-ssl.dist.in.git | 3 | ||||
| -rw-r--r-- | imap/pop3d-ssl.dist.in.git | 3 | ||||
| -rw-r--r-- | tcpd/couriertls.sgml | 2 |
3 files changed, 5 insertions, 3 deletions
diff --git a/imap/imapd-ssl.dist.in.git b/imap/imapd-ssl.dist.in.git index 5204818..17f8366 100644 --- a/imap/imapd-ssl.dist.in.git +++ b/imap/imapd-ssl.dist.in.git @@ -233,7 +233,8 @@ TLS_CERTFILE=@certsdir@/imapd.pem # # TLS_PRIVATE_KEYFILE - SSL/TLS private key for decrypting peer data. # This file must be owned by the "@mailuser@" user, and must not be world -# readable. +# readable, and must be accessible without a pass-phrase, i.e. it must not +# be encrypted. # # By default, courier generates SSL/TLS certifice including private key # and install it in TLS_CERTFILE path, so TLS_PRIVATE_KEYFILE is completely diff --git a/imap/pop3d-ssl.dist.in.git b/imap/pop3d-ssl.dist.in.git index 9611524..6b5b352 100644 --- a/imap/pop3d-ssl.dist.in.git +++ b/imap/pop3d-ssl.dist.in.git @@ -227,7 +227,8 @@ TLS_CERTFILE=@certsdir@/pop3d.pem # # TLS_PRIVATE_KEYFILE - SSL/TLS private key for decrypting peer data. # This file must be owned by the "@mailuser@" user, and must not be world -# readable. +# readable, and must be accessible without a pass-phrase, i.e. it must not +# be encrypted. # # By default, courier generates SSL/TLS certifice including private key # and install it in TLS_CERTFILE path, so TLS_PRIVATE_KEYFILE is completely diff --git a/tcpd/couriertls.sgml b/tcpd/couriertls.sgml index 0711654..c7971cc 100644 --- a/tcpd/couriertls.sgml +++ b/tcpd/couriertls.sgml @@ -241,7 +241,7 @@ for SSL/TLS clients. <para> SSL/TLS private key for decrypting client data. <envar>TLS_PRIVATE_KEY</envar> is optional because <term>TLS_CERTFILE</term> is generated including cert and private key both. -<replaceable>filename</replaceable> must not be world-readable.</para> +<replaceable>filename</replaceable> must not be world-readable, and must be accessible without a pass-phrase, i.e. it must not be encrypted.</para> </listitem> </varlistentry> |
