How to setup SSL for IMAP/SMTP domains?

Hi,

I’m on Ubuntu 20.04 with exim4 etc. The mail server is working, but I can’t seem to get the SSL stuff going. I’ve tried using my main hostname (i.e the domain where my Hestia CP is loaded, but on normal HTTP/SSL port), and that works fine for http/https. But I can’t get it to work. So a couple of questions:

  1. How can I get SSL for domains (i.e a hosted domain), which is setup using LE just fine for the web side - so actually work for emails as well? I could have sworn there used to be an option for it - but I can’t find it

  2. How can I get SSL setup for the main server domain (i.e what I have in /etc/hostname), so that Ic an also use that for connecting?

Thanks

Andy

1.) edit mail domain, tick the ssl checkbox and generate one. then use mail.domain.tld for incoming and outgoing mails.
2.) set a proper a record for your hostname, then run v-add-letsencrypt-host

Thanks for the ridiculously fast reply :wink: When I try and set that up for the main domain (which is hosted on the “admin” account), I can’t actually add a mail domain to do that:

2.) set a proper a record for your hostname, then run v-add-letsencrypt-host

That side actually works fine already :slight_smile: (I can access https://north.xxx.com:9183 and also https://north.xxx.com both fine). The issue seems to be just when I do a SSL test

Cert Hostname DOES NOT VERIFY (mail.north.xxx.com != north.xxx.com | DNS:north.xxxcom)
		So email is encrypted but the host is not verified

I’m wondering if that has something to do with the MX record I had in the nameserver as Linode. It was set as mail.north.xxx.com). I’ve updated that so will see if that helps :slight_smile:

Thanks

Andy

Create a new user, then in there create all you need

1 Like

Ah I didn’t think about putting the mail domain under a new user… duh! (I assumed because the north.xxx.com domain was under “admin”, it would only allow a mail domain under that account)

Thanks

1 Like

I still can’t get this to work :frowning:

In /usr/local/hestia/ssl/mail I see the files correctly mail.brettinc.co.uk.key and .crt).

When trying to add in RoundCube:

So it seems to think its ok - until you go and add it:

It runs fine when I test it on https://www.checktls.com/TestReceiver:

I’m not sure what else to try :confused:

… check your settings: “Connection Security: None” can’t work…

2 Likes

Duh, me being an idiot! Must have missed that! Working now :slight_smile:

1 Like

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.