• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.

Question Email Security In Pleask Chipter Suite / TLS / SSL

PeopleInside

Regular Pleskian
Hi,
I AM new on Plesk for VPS but I AM currently looking to buy a VPS with Plesk 12 Web Admin on Centos6

I AM not already using Plesk.
My question is:

I see for incoming mail postfix is the default and dovecot is the default for out coming email.
I AM using webuzo webpanel right now who use Exim as default inbox and dovecot for outbox and I can access to the exim configuration for set secure chipher suite.

In Plesk all is set by Plesk I Mean default settings of postfix and dovecot will be secure?
How to test if settings are safer?

For example if I have the domain domain.ext and my email host is mail.domain.ext well I can test on https://www.htbridge.com/ssl/ mail.domain.ext:993 (port 993)

the results of the test should have an A score that means postfix is using the best and roboust chiper suite.

In Plesk postfix will be configured for use the most secure chipters or is the user that need to configure well security settings?

Thanks
 
I am afraid that configuration of cipher suites and similar security features is not part of Plesk, but part of the operating system and needs to be carried out by the user. Plesk will make the best possible use of the components that are available on your system, but it will not replace OS vendor components.
 
I am afraid that configuration of cipher suites and similar security features is not part of Plesk, but part of the operating system and needs to be carried out by the user. Plesk will make the best possible use of the components that are available on your system, but it will not replace OS vendor components.

Hi,
thanks for the answer but I don't understand your reply.

For example I use a webpanel in my VPS under CentOS but Exim and Dovecot is installed and used by the panel not by the operative system so in my case I need SSH or goes into the panel where I can edit exim configuration and put inside the chipers.
I don't know how this is in plesk.

I see on OVH you can by a VPS and you can chose as Operative System Pleask with Plesk installed On CentOs but is not Centos who manage emails and so... as you have to set in apache for SSL best Chiper suite this maybe is needed also in postfix? What use Plesk for manage email, postfix?

Peter are you using Plesk? Are you managing email by Plesk?
mmmmm your reply is not clear to me.

In my actual case security is not part of Operative System as Chipher suite i never put into CentOs or OpenSSL but in Apache, Pure FTP, Exim, Dovecot.
With my actual control panel Apache is not set for security, Dovecot also Exim is not set for use best chipher suite... and so I have issues.
So this is why I AM asking how about Plesk.
 
Plesk uses QMail or Postfix by your choice for SMTP and Dovecot or Courier for POP3/IMAP. You can apply custom configurations to the services. I do not know what image OVH is using for their VPS. Maybe you should ask them if they have configured everything with the best cipher suites.
 
Thank you.
So you can access to the Postfix configuration and add chipersuite if is not set strongly?
I will ask maybe to OVH, thanks Peter :)
 
Back
Top