The upgrade from Stretch to Buster for the most part went well. I did however break something on email. Thunderbird tells me:
Thunderbird wrote:The IMAP server mail.elsmussols.net does not support the selected authentication method.
My T'Bird settings pre-upgrade (which worked):
Connecttion security: STARTTLS
Authentication method: Normal password
Port: 143
Stretch to Buster involved moving from dovecot 2.2 to 2.3 and I got the following emails from apt:
dovecot (1:2.3.2-1) unstable; urgency=medium
Upgrading to the 2.3 series may require manual configuration changes.
Some settings have been removed, while others have had their defaults
changed. Please see
/usr/share/doc/dovecot-core/wiki/Upgrading.2.3.txt.gz
or the online version at
https://wiki2.dovecot.org/Upgrading/2.3
for more information and review your configuration accordingly.
-- Apollon Oikonomopoulos <apoikos@debian.org> Sat, 24 Mar 2018 00:34:07 +0200
dovecot (1:2.2.31-1) unstable; urgency=medium
TLS is now enabled by default, using the ssl-cert-snakeoil certificate
provided by the ssl-cert package. Upgrades from older versions will be
prompted to accept the new configuration and enable TLS. If you have already
configured TLS yourself, you'll most probably want to keep your settings
intact.
See /usr/share/doc/dovecot-core/README.Debian for more information on the
certificate's default location and how to install your own certificates.
-- Apollon Oikonomopoulos <apoikos@debian.org> Sun, 25 Jun 2017 01:09:28 +0300
On the server I am getting the following errors in
/var/log/mail.err
:
Aug 13 12:21:20 pendle dovecot: imap-login: Error: Failed to initialize SSL server context: Can't load DH parameters: error:1408518A:SSL routines:ssl3_ctx_ctrl:dh key too small: user=<>, rip=XX, lip=XX
So I am lost. I know that this means I have to adjust some DH config to make a bigger key but I am have mangled my head on how to untangle all the various settings in all the various dovecot config files.
Comments please. I can do this but just need a few weeds clearing out of the way first. I have said this before "Email makes my head hurt".