{"description": "To allow clients to make encrypted connections the <tt>ssl</tt>\nflag in Dovecot's configuration file needs to be set to <tt>yes</tt>.\n<br /><br />\nEdit <tt>/etc/dovecot/conf.d/10-ssl.conf</tt> and add or correct the following line:\n<pre>ssl = yes</pre>", "rationale": "SSL encrypt network traffic between the Dovecot server and its clients \nprotecting user credentials, mail as it is downloaded, and clients may use\nSSL certificates to authenticate the server, preventing another system from\nimpersonating the server.", "severity": "unknown", "references": {}, "control_references": {}, "components": [], "identifiers": {}, "ocil_clause": null, "ocil": null, "oval_external_content": null, "fixtext": "", "checktext": "", "vuldiscussion": "", "srg_requirement": "", "warnings": [], "conflicts": [], "requires": [], "policy_specific_content": {}, "platform": null, "platforms": [], "sce_metadata": {}, "inherited_platforms": [], "cpe_platform_names": [], "inherited_cpe_platform_names": [], "bash_conditional": null, "fixes": {}, "title": "Enable the SSL flag in /etc/dovecot.conf", "definition_location": "/aptdata/openscap/scap-security-guide/linux_os/guide/services/imap/configure_dovecot/dovecot_enabling_ssl/dovecot_enable_ssl/rule.yml", "template": null}