summaryrefslogtreecommitdiff
path: root/dovecot/conf.d/10-master.conf
blob: aed5df8b2de85490a485d64adfeff449c06aa2ad (plain)
  1. #default_process_limit = 100
  2. #default_client_limit = 1000
  3. # Default VSZ (virtual memory size) limit for service processes. This is mainly
  4. # intended to catch and kill processes that leak memory before they eat up
  5. # everything.
  6. #default_vsz_limit = 256M
  7. # Login user is internally used by login processes. This is the most untrusted
  8. # user in Dovecot system. It shouldn't have access to anything at all.
  9. #default_login_user = dovenull
  10. # Internal user is used by unprivileged processes. It should be separate from
  11. # login user, so that login processes can't disturb other processes.
  12. #default_internal_user = dovecot
  13. service imap-login {
  14. inet_listener imap {
  15. #port = 143
  16. }
  17. inet_listener imaps {
  18. #port = 993
  19. #ssl = yes
  20. }
  21. # Number of connections to handle before starting a new process. Typically
  22. # the only useful values are 0 (unlimited) or 1. 1 is more secure, but 0
  23. # is faster. <doc/wiki/LoginProcess.txt>
  24. #service_count = 1
  25. # Number of processes to always keep waiting for more connections.
  26. #process_min_avail = 0
  27. # If you set service_count=0, you probably need to grow this.
  28. #vsz_limit = $default_vsz_limit
  29. }
  30. service pop3-login {
  31. inet_listener pop3 {
  32. #port = 110
  33. }
  34. inet_listener pop3s {
  35. #port = 995
  36. #ssl = yes
  37. }
  38. }
  39. service lmtp {
  40. unix_listener lmtp {
  41. #mode = 0666
  42. }
  43. unix_listener /var/spool/postfix/private/dovecot-lmtp {
  44. group = postfix
  45. mode = 0600
  46. user = postfix
  47. }
  48. # Create inet listener only if you can't use the above UNIX socket
  49. #inet_listener lmtp {
  50. # Avoid making LMTP visible for the entire internet
  51. #address =
  52. #port =
  53. #}
  54. }
  55. service imap {
  56. # Most of the memory goes to mmap()ing files. You may need to increase this
  57. # limit if you have huge mailboxes.
  58. #vsz_limit = $default_vsz_limit
  59. # Max. number of IMAP processes (connections)
  60. #process_limit = 1024
  61. }
  62. service pop3 {
  63. # Max. number of POP3 processes (connections)
  64. #process_limit = 1024
  65. }
  66. service auth {
  67. # auth_socket_path points to this userdb socket by default. It's typically
  68. # used by dovecot-lda, doveadm, possibly imap process, etc. Users that have
  69. # full permissions to this socket are able to get a list of all usernames and
  70. # get the results of everyone's userdb lookups.
  71. #
  72. # The default 0666 mode allows anyone to connect to the socket, but the
  73. # userdb lookups will succeed only if the userdb returns an "uid" field that
  74. # matches the caller process's UID. Also if caller's uid or gid matches the
  75. # socket's uid or gid the lookup succeeds. Anything else causes a failure.
  76. #
  77. # To give the caller full permissions to lookup all users, set the mode to
  78. # something else than 0666 and Dovecot lets the kernel enforce the
  79. # permissions (e.g. 0777 allows everyone full permissions).
  80. unix_listener auth-userdb {
  81. mode = 0660
  82. user = dovecot
  83. group = mail
  84. }
  85. # Postfix smtp-auth
  86. unix_listener /var/spool/postfix/private/auth {
  87. mode = 0600
  88. user = postfix
  89. group = postfix
  90. }
  91. # unix_listener /var/run/ejabberd/auth {
  92. # mode = 0660
  93. # user = ejabberd
  94. # group = ejabberd
  95. # }
  96. # Auth process is run as this user.
  97. #user = $default_internal_user
  98. }
  99. service auth-worker {
  100. # Auth worker process is run as root by default, so that it can access
  101. # /etc/shadow. If this isn't necessary, the user should be changed to
  102. # $default_internal_user.
  103. #user = root
  104. }
  105. service dict {
  106. # If dict proxy is used, mail processes should have access to its socket.
  107. # For example: mode=0660, group=vmail and global mail_access_groups=vmail
  108. unix_listener dict {
  109. #mode = 0600
  110. #user =
  111. #group =
  112. }
  113. }