class mail::tls::hardened inherits mail::tls {
# Hardened config
postfix::config { "smtpd_tls_ciphers": value => 'high' }
- postfix::config { "smtp_tls_protocols": value => '!SSLv2, SSLv3, TLSv1' }
+ postfix::config { "smtp_tls_protocols": value => '!SSLv2, !SSLv3' }
+ postfix::config { "smtp_tls_mandatory_protocols" value => '!SSLv2, !SSLv3' }
postfix::config { "smtp_tls_note_starttls_offer": value => 'yes' }
postfix::config { "smtpd_tls_received_header": value => 'yes' }
- postfix::config { "smtpd_tls_mandatory_protocols": value => 'TLSv1' }
+ postfix::config { "smtpd_tls_protocols": value => '!SSLv2, !SSLv3' }
+ postfix::config { "smtpd_tls_mandatory_protocols": value => '!SSLv2, !SSLv3' }
postfix::config { "smtpd_tls_session_cache_database": value => 'btree:${data_directory}/smtpd_scache' }
postfix::config { "smtp_tls_session_cache_database": value => 'btree:${data_directory}/smtp_scache' }