Topic: performance vs security on 1 GB droplet
After realizing that a 512MB droplet just can't handle the load I switched over to a
1 GB droplet (+ 2GB swap)
irdmail standard install
commercial SSL certificate
greylisting disabled
Performance is good using standard settings.
I also enabled SSL stapling and I think (or want to believe) that it's even a tick faster now.
Security with standard settings is an acceptable A- (via SSLLABS test)
The test is complaining that:
- there is no Strict-Transport-Security in place
- server does not support Forward Secrecy
However, if I enable any of the two above my mailbox freezes right after I send out a single email.
My question is:
Is this happening because of low RAM or does iredmail simply not support these additional security measures?
==== Required information ====
- iRedMail version: 0.9.0.
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): MySQL
- Web server (Apache or Nginx): NGINX
- Linux/BSD distribution name and version: 14.04
- Related log if you're reporting an issue:
====
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.