Here is my current SSL related configuration
[root@ired nginx]# grep -r ssl /etc/dovecot/dovecot.conf /etc/nginx/templates/ssl.tmpl
/etc/dovecot/dovecot.conf:ssl_protocols = !SSLv2 !SSLv3
/etc/dovecot/dovecot.conf:ssl = required
/etc/dovecot/dovecot.conf:verbose_ssl = no
/etc/dovecot/dovecot.conf:ssl_ca = </etc/pki/tls/certs/iRedMail.crt
/etc/dovecot/dovecot.conf:ssl_cert = </etc/pki/tls/certs/iRedMail.crt
/etc/dovecot/dovecot.conf:ssl_key = </etc/pki/tls/private/iRedMail.key
/etc/dovecot/dovecot.conf:ssl_cipher_list = ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+3DES:!aNULL:!MD5
/etc/dovecot/dovecot.conf:ssl_prefer_server_ciphers = yes
/etc/dovecot/dovecot.conf:# With disable_plaintext_auth=yes AND ssl=required, STARTTLS is mandatory.
/etc/dovecot/dovecot.conf:# Set disable_plaintext_auth=no AND ssl=yes to allow plain password transmitted
/etc/dovecot/dovecot.conf: # ssl = yes
/etc/dovecot/dovecot.conf: # ssl = yes
/etc/nginx/templates/ssl.tmpl:ssl on;
/etc/nginx/templates/ssl.tmpl:ssl_protocols TLSv1.2;
/etc/nginx/templates/ssl.tmpl:ssl_ciphers ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+3DES:!aNULL:!MD5;
/etc/nginx/templates/ssl.tmpl:ssl_prefer_server_ciphers on;
/etc/nginx/templates/ssl.tmpl:ssl_dhparam /etc/pki/tls/dh2048_param.pem;
/etc/nginx/templates/ssl.tmpl:# To use your own ssl cert (e.g. LetsEncrypt), please create symbol link to
/etc/nginx/templates/ssl.tmpl:# ssl cert/key used below, so that we can manage this config file with Ansible.
/etc/nginx/templates/ssl.tmpl:ssl_certificate /etc/pki/tls/certs/iRedMail.crt;
/etc/nginx/templates/ssl.tmpl:ssl_certificate_key /etc/pki/tls/private/iRedMail.key;
And the files (links)
[root@ired nginx]# ls -l /etc/pki/tls/certs/iRedMail.crt /etc/pki/tls/certs/iRedMail.crt /etc/pki/tls/private/iRedMail.key /etc/pki/tls/certs/iRedMail.crt /etc/pki/tls/private/iRedMail.key
lrwxrwxrwx 1 root root 49 Dec 30 10:55 /etc/pki/tls/certs/iRedMail.crt -> /etc/letsencrypt/live/ired.X.com/fullchain.pem
lrwxrwxrwx 1 root root 49 Dec 30 10:55 /etc/pki/tls/certs/iRedMail.crt -> /etc/letsencrypt/live/ired.X.com/fullchain.pem
lrwxrwxrwx 1 root root 49 Dec 30 10:55 /etc/pki/tls/certs/iRedMail.crt -> /etc/letsencrypt/live/ired.X.com/fullchain.pem
lrwxrwxrwx 1 root root 47 Dec 25 17:59 /etc/pki/tls/private/iRedMail.key -> /etc/letsencrypt/live/ired.X.com/privkey.pem
lrwxrwxrwx 1 root root 47 Dec 25 17:59 /etc/pki/tls/private/iRedMail.key -> /etc/letsencrypt/live/ired.X.com/privkey.pem