fix permissions for doveadm
[ansible.git] / roles / email / tasks / dovecot.yml
index aa59821b216685d42f803982587f70241c469acc..5d8ef0c38f051744879021508f2a84d821d24f02 100644 (file)
@@ -22,7 +22,7 @@
   template:
     dest: /etc/dovecot/{{ item }}
     src: templates/dovecot/{{ item }}
-    mode: u=rw,g=r,o=
+    mode: u=rw,g=r,o=r # changepw needs read access
     group: dovecot
   loop:
   - conf.d/10-auth.conf
   - conf.d/20-lmtp.conf
   - conf.d/90-quota.conf
   - conf.d/auth-sql.conf.ext
+- name: configure dovecot secrets
+  notify: dovecot
+  template:
+    dest: /etc/dovecot/{{ item }}
+    src: templates/dovecot/{{ item }}
+    mode: u=rw,g=r,o=
+    group: dovecot
+  loop:
   - dovecot-sql.conf.ext
 - name: install quota notification script
   template:
 - name: create newmail dir
   file: path=/root/newmail state=directory
 - name: install newmail script
-  copy:
+  template:
     dest: /root/newmail/newmail
-    src: files/newmail/newmail
+    src: templates/newmail/newmail
     mode: u=rwx,g=rx,o=rx
-- name: install newmail templates
-  copy:
-    dest: /root/newmail/templates.py
-    src: files/newmail/templates.py
+- name: install newmail config
+  template:
+    dest: /root/newmail/{{ item }}
+    src: templates/newmail/{{ item }}
+  loop:
+  - templates.py
+  - settings.py
 - name: install changepw script
   when: postfix.dovecot.changepw_cgi is defined
   template: