Dovecot IMAP With TLS Required And LMTP Delivery

Dovecot from AppStream: IMAP for your mail clients and LMTP for your MTA, Maildir in each home, TLS required before any login, a minimum TLS version checked before it lands, and every listener on loopback until you open it. The live test delivers over LMTP, reads the message over IMAPS, and sees a plaintext login from another address refused. Original role, live-tested on Rocky Linux 10.

ansibleMessaging & Streaming

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-10-03 · podman 4.9.3 · ansible 2.21.4 · how we verify

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/ansible-dovecot/badge)](https://www.iac-bazaar.com/catalog/ansible-dovecot?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Ansible role 1.0.0, live-tested on IaC Bazaar: [Dovecot IMAP With TLS Required And LMTP Delivery](https://www.iac-bazaar.com/catalog/ansible-dovecot?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```yaml
# Dovecot IMAP With TLS Required And LMTP Delivery: https://www.iac-bazaar.com/catalog/ansible-dovecot (download from your IaC Bazaar account)
```

Preview:IaC Bazaar: live-tested

Documentation

dovecot

Dovecot from AppStream: IMAP for your mail clients and LMTP for your MTA to deliver into, Maildir in each user's home, TLS required before any login, a minimum TLS version the role checks before it lands, and every listener on loopback until you open it. Original role for EL 10, live-tested with podman on Rocky Linux 10.

No download, and no version to pin. EL 10 packages dovecot, so the role installs it by name and takes what the distribution ships: a security update arrives through dnf, not through a new release of this role. What the role owns is the configuration and the proof that the service works.

The distribution's files, ours last. The role writes one file, conf.d/99-iacbazaar.conf, read after the package's own, so its settings win and the package's files stay as shipped. It is checked by doveconf inside a copy of the whole configuration before it lands (an unknown setting: exit 89, measured). Dovecot listens on 127.0.0.1 - 993 for IMAPS and 143 for IMAP with STARTTLS - and POP3 is off; the live test reads the sockets.

A value nothing checks. ssl_min_protocol = TLSv9 passed doveconf, and dovecot started with it - then every TLS handshake failed, "Unknown ssl_min_protocol setting" (measured). The role refuses anything but TLSv1.2 and TLSv1.3 before the file is written.

Loopback counts as secure. Dovecot treats a connection whose remote address equals its local one as secured, so a plaintext login from 127.0.0.1 to 127.0.0.1 is allowed whatever the settings (measured). The live test connects from 127.0.0.2: the server advertises LOGINDISABLED and refuses the login with [PRIVACYREQUIRED], then accepts it after STARTTLS.

Proven by mail. A message delivered over LMTP to the unix socket your MTA would use is found over IMAPS (TLS 1.2 or later) in a Maildir created 0700.

License

Commercial - IaC Bazaar EULA. (c) IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules

Live-tested

ansible-kafka

Apache Kafka 4 (SHA-512 pinned) on Java 21, one KRaft node on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test creates a topic, produces one message, consumes it back and reads the metadata quorum; the metadata log is formatted once as the service user and the root-owned release tree is run in place. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-gotify

Gotify on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback with its settings in an EnvironmentFile; the live test creates an application, pushes a message with its token, reads it back as the admin, and sees a wrong password and a bad token refused. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-postfix-tls

An EL host opens no submission service, so every client sends on port 25 where plaintext is accepted. This role adds 587, which refuses mail until the session is encrypted, and 465, which is TLS from the first byte. Port 25 keeps taking plaintext on purpose and the live test asserts it, because a mail exchanger that demands STARTTLS loses mail. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-mosquitto-broker

Mosquitto (MQTT) with accounts: the package starts in local-only mode with anonymous clients allowed, no persistence directory and no packet-size limit. This role writes a listener that refuses anonymous and wrong-password clients (proved live), keeps retained messages across restarts, caps packets at 1 MiB, and renders topic ACLs from a list. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-nats

nats on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then saves a context under a throwaway config home, reads it back, and runs server check connection against a dead port expecting exit 2 and CRITICAL. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-nats-server

NATS server from the upstream release (sha256-verified) as a hardened system service on loopback with JetStream under its own data directory and the configuration checked by nats-server -t before it lands. No client is installed, so the live test speaks the protocol itself: one session subscribes, publishes and reads its own message back. Original role, live-tested on Rocky Linux 10.

View module