Re: Dovecot stops responding when I update SSL certificate
6 Mar
2016
6 Mar
'16
4:45 a.m.
HotSlots Webmaster <webmaster@hotslots132.com> writes:
When you start dovecot, does CPU load of dovecot/ssl-params roof to 100%? It's possible it's generating ephemeral DH keys. In a previous post to this list, I note that the run time to generate these keys can vary wildly, and gets worse with longer keys. Sometimes you get lucky, and you'll generate then quickly, sometimes it takes a long while (minutes).
http://dovecot.org/pipermail/dovecot/2015-November/102447.html
Try running
openssl dhparam -noout 2048
to see how it varies for you. If what I suspect is true, you can try using shorter keys. A followup post suggest a way you can precompute the key
Joseph Tam <jtam.home@gmail.com>
3452
Age (days ago)
3452
Last active (days ago)
2 comments
3 participants
participants (3)
-
A. Schulze
-
aki.tuomi@dovecot.fi
-
Joseph Tam