diff --git a/mail-server/dovecot.nix b/mail-server/dovecot.nix index 75c8b82..b29d8b6 100644 --- a/mail-server/dovecot.nix +++ b/mail-server/dovecot.nix @@ -292,7 +292,7 @@ in ssl_server_key_file = x509PrivateKeyFile; # https://ssl-config.mozilla.org/#server=dovecot&version=2.3.21&config=intermediate&openssl=3.4.1&guideline=5.7 ssl = "required"; - ssl_min_protocol = "TLSv1.2"; + ssl_min_protocol = "TLSv1"; ssl_server_prefer_ciphers = "client"; ssl_cipher_list = lib.concatStringsSep ":" [ # TLS1.3 diff --git a/mail-server/postfix.nix b/mail-server/postfix.nix index aa02d37..bd5af4a 100644 --- a/mail-server/postfix.nix +++ b/mail-server/postfix.nix @@ -392,8 +392,8 @@ in smtpd_tls_auth_only = true; # TLS versions supported for the SMTP server - smtpd_tls_protocols = ">=TLSv1.2"; - smtpd_tls_mandatory_protocols = ">=TLSv1.2"; + smtpd_tls_protocols = ">=TLSv1"; + smtpd_tls_mandatory_protocols = ">=TLSv1"; # Require ciphersuites that OpenSSL classifies as "High" smtpd_tls_ciphers = "high";