You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Dovecot IMAP服务器拒绝Thunderbird客户端授权的问题排查求助

Dovecot IMAP服务器拒绝Thunderbird客户端授权的问题排查求助

各位好,我遇到一个棘手的问题,希望能得到大家的帮助:

我在网上看过一些类似问题的解答,但都没能帮我解决这个问题。

我在服务器上直接安装了Thunderbird实例,它可以正常从服务器收取邮件。其他不在服务器上的客户端也能正常收信,而且其他Thunderbird客户端也能从其他服务器收信。

我的Debian Linux服务器上运行Dovecot作为IMAP服务器已经很多年了。大概一月初的时候,它突然不让Thunderbird客户端下载邮件了。我试过所有能想到的办法,检查了所有我知道的配置,但还是找不到问题所在。我想或许强制Thunderbird客户端刷新IMAP服务器的证书会有用,但当我尝试从系统获取证书时,Thunderbird说它无法获取。有没有人知道我该怎么继续排查?

当前Dovecot配置(doveconf -n输出)

# 2.3.19.1 (9b53102964): /etc/dovecot/dovecot.conf
# Pigeonhole version 0.5.19 (4eae2f79)
# OS: Linux 6.1.0-10-amd64 x86_64 Debian 12.1
# Hostname: RAID-Server
debug_log_path = /var/log/dovecot/mail.bug
info_log_path = /var/log/dovecot/mail.inf
log_path = /var/log/dovecot/mail.err
mail_location = mbox:~/mail:INBOX=~/mail/inbox
namespace inbox {
inbox = yes
location =
mailbox Drafts {
special_use = \Drafts
}
mailbox Junk {
special_use = \Junk
}
mailbox Sent {
special_use = \Sent
}
mailbox "Sent Messages" {
special_use = \Sent
}
mailbox Trash {
special_use = \Trash
}
prefix =
}
passdb {
driver = pam
}
protocols = " imap"
ssl_cert = </etc/dovecot/private/dovecot.pem
ssl_client_ca_dir = /etc/ssl/certs
ssl_dh = # hidden, use -P to show it
ssl_key = # hidden, use -P to show it
userdb {
driver = passwd
}
protocol imap {
mail_max_userip_connections = 50
}

OpenSSL连接测试结果(openssl s_client -connect 192.168.1.50:993 -tls1_2输出)

root@Backup:~# openssl s_client -connect 192.168.1.50:993 -tls1_2
CONNECTED(00000003)
---
Certificate chain
0 s:CN = RAID-Server.att.net
i:CN = RAID-Server.att.net
a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256
v:NotBefore: Oct 30 01:53:54 2019 GMT; NotAfter: Oct 27 01:53:54 2029 GMT
---
Server certificate
-----BEGIN CERTIFICATE-----
<removed>
-----END CERTIFICATE-----
subject=CN = RAID-Server.att.net
issuer=CN = RAID-Server.att.net
---
No client certificate CA names sent
Peer signing digest: SHA256
Peer signature type: RSA-PSS
Server Temp Key: X25519, 253 bits
---
SSL handshake has read 1388 bytes and written 281 bytes
Verification error: self-signed certificate
---
New, TLSv1.2, Cipher is ECDHE-RSA-AES256-GCM-SHA384
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
Protocol  : TLSv1.2
Cipher    : ECDHE-RSA-AES256-GCM-SHA384
Session-ID: AE20DEEF2FD8CC7F3881B59D51CBCB23B436E92DF06F87124F7E8A760010FFAB
Session-ID-ctx:
Master-Key: 2FC5D8CF5E6C8D77A9BA3FB659F026E6E83328A1BF98E9EF12736DC9B3778BD2260DBB1588CE0E731BF21479DC1D81A0
PSK identity: None
PSK identity hint: None
SRP username: None
TLS session ticket lifetime hint: 7200 (seconds)
TLS session ticket:
0000 - af bc 75 17 7e 2e 44 35-67 52 2e b4 72 7c 18 49   ..u.~.D5gR..r|.I
0010 - 5e 63 02 50 39 b7 47 d6-de 02 2b e9 ff e9 6b fa   ^c.P9.G...+...k.
0020 - 5f 27 f2 85 a0 a6 63 47-58 65 be f6 54 f7 96 1e   _'....cGXe..T...
0030 - e2 b5 d4 af c7 be 06 8b-8f 15 5e 65 55 27 46 61   ..........^eU'Fa
0040 - d7 e4 75 08 27 47 97 67-a6 37 bc 67 49 17 24 ab   ..u.'G.g.7.gI.$.
0050 - 78 6f c8 ba af 3e e6 b0-b4 f3 96 9f c3 0a e5 bc   xo...>..........
0060 - 70 30 c6 9e e2 2d 68 37-a1 68 2c dd dc b8 12 87   p0...-h7.h,.....
0070 - 9a 60 fd 1f be 25 8a 10-19 46 83 47 ea 7d 8c 16   .`...%...F.G.}..
0080 - d8 b8 18 ea 38 12 95 23-96 ac 13 82 e2 04 16 6c   ....8..#.......l
0090 - c7 77 bd 80 59 91 2d a2-28 f7 75 f7 ce 5a 7e 1f   .w..Y.-.(.u..Z~.
Start Time: 1708484596
Timeout   : 7200 (sec)
Verify return code: 18 (self-signed certificate)
Extended master secret: yes
---
* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ AUTH=PLAIN] Dovecot (Debian) ready.

备注:内容来源于stack exchange,提问作者LesRhorer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.20 07:49:29