Dovecot IMAP With TLS Required And LMTP Delivery
Dovecot from AppStream: IMAP for your mail clients and LMTP for your MTA, Maildir in each home, TLS required before any login, a minimum TLS version checked before it lands, and every listener on loopback until you open it. The live test delivers over LMTP, reads the message over IMAPS, and sees a plaintext login from another address refused. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-10-03 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-dovecot?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [Dovecot IMAP With TLS Required And LMTP Delivery](https://www.iac-bazaar.com/catalog/ansible-dovecot?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# Dovecot IMAP With TLS Required And LMTP Delivery: https://www.iac-bazaar.com/catalog/ansible-dovecot (download from your IaC Bazaar account)
```Preview:
Documentation
dovecot
Dovecot from AppStream: IMAP for your mail clients and LMTP for your MTA to deliver into, Maildir in each user's home, TLS required before any login, a minimum TLS version the role checks before it lands, and every listener on loopback until you open it. Original role for EL 10, live-tested with podman on Rocky Linux 10.
No download, and no version to pin. EL 10 packages dovecot, so the
role installs it by name and takes what the distribution ships: a security
update arrives through dnf, not through a new release of this role. What the
role owns is the configuration and the proof that the service works.
The distribution's files, ours last. The role writes one file,
conf.d/99-iacbazaar.conf, read after the package's own, so its settings win
and the package's files stay as shipped. It is checked by doveconf inside a
copy of the whole configuration before it lands (an unknown setting: exit 89,
measured). Dovecot listens on 127.0.0.1 - 993 for IMAPS and 143 for IMAP with
STARTTLS - and POP3 is off; the live test reads the sockets.
A value nothing checks. ssl_min_protocol = TLSv9 passed doveconf, and
dovecot started with it - then every TLS handshake failed, "Unknown
ssl_min_protocol setting" (measured). The role refuses anything but TLSv1.2 and
TLSv1.3 before the file is written.
Loopback counts as secure. Dovecot treats a connection whose remote address equals its local one as secured, so a plaintext login from 127.0.0.1 to 127.0.0.1 is allowed whatever the settings (measured). The live test connects from 127.0.0.2: the server advertises LOGINDISABLED and refuses the login with [PRIVACYREQUIRED], then accepts it after STARTTLS.
Proven by mail. A message delivered over LMTP to the unix socket your MTA would use is found over IMAPS (TLS 1.2 or later) in a Maildir created 0700.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-kafka
Apache Kafka 4 (SHA-512 pinned) on Java 21, one KRaft node on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test creates a topic, produces one message, consumes it back and reads the metadata quorum; the metadata log is formatted once as the service user and the root-owned release tree is run in place. Original role, live-tested on Rocky Linux 10.
ansible-gotify
Gotify on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback with its settings in an EnvironmentFile; the live test creates an application, pushes a message with its token, reads it back as the admin, and sees a wrong password and a bad token refused. Original role, live-tested on Rocky Linux 10.
ansible-postfix-tls
An EL host opens no submission service, so every client sends on port 25 where plaintext is accepted. This role adds 587, which refuses mail until the session is encrypted, and 465, which is TLS from the first byte. Port 25 keeps taking plaintext on purpose and the live test asserts it, because a mail exchanger that demands STARTTLS loses mail. Original role, live-tested on Rocky Linux 10.
ansible-mosquitto-broker
Mosquitto (MQTT) with accounts: the package starts in local-only mode with anonymous clients allowed, no persistence directory and no packet-size limit. This role writes a listener that refuses anonymous and wrong-password clients (proved live), keeps retained messages across restarts, caps packets at 1 MiB, and renders topic ACLs from a list. Original role, live-tested on Rocky Linux 10.
ansible-nats
nats on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then saves a context under a throwaway config home, reads it back, and runs server check connection against a dead port expecting exit 2 and CRITICAL. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-nats-server
NATS server from the upstream release (sha256-verified) as a hardened system service on loopback with JetStream under its own data directory and the configuration checked by nats-server -t before it lands. No client is installed, so the live test speaks the protocol itself: one session subscribes, publishes and reads its own message back. Original role, live-tested on Rocky Linux 10.