# Dovecot hardening (E2 D3). auth_failure_delay = 2s mail_max_userip_connections = 10 # --- Dovecot shared mailboxes (issue #79): info@ reads all mailboxes. --- # Canonical Dovecot 2.3 shared-mailbox scheme: acl plugin + shared namespace + # acl_shared_dict. The imap plugin list is explicit: inside a `protocol imap {}` # filter $mail_plugins expands to the filter-level value from DMS's 20-imap.conf # (which shadows the global), so a `$mail_plugins acl` line would silently drop # `acl`. Keep DMS's imap_quota to not regress quota IMAP commands. mail_plugins = " quota acl" protocol imap { mail_plugins = " quota acl imap_quota" } # Dovecot merges namespace blocks with the same identity (type+prefix); this # makes the default (maildir) "." separator explicit "/" so it matches the # shared namespace below ("All list=yes namespaces must use the same separator"). namespace inbox { separator = / } namespace { type = shared separator = / prefix = shared/%%u/ location = maildir:/var/mail/%%d/%%n:INDEXPVT=~/shared/%%u # subscriptions=yes: Roundcube's folder list is subscribed-based (LIST-EXTENDED # SUBSCRIBED / LSUB); without per-user subscriptions shared folders would be # invisible in the web UI. user-patches.sh pre-subscribes them for info@. subscriptions = yes list = children } plugin { acl = vfile # Required for the shared namespace LIST to work: tracks "who shared to whom". # /var/lib/dovecot is a symlink to /var/mail-state/lib-dovecot (persistent). acl_shared_dict = file:/var/lib/dovecot/db/shared-mailboxes.db }