Few comments:

- OpenSSL library is required for TLS support. You can download it from:
  http://www.openssl.org

- All certificates/keys are read with privileges of "spop3d" user. Make sure
  that they are readable for this user. Keys/certificates/paramfiles
  should be in PEM format and can't be protected with passwords.

- OpenSSL 0.9.5a was used for tests, I don't know whether Solid POP3 works
  with older versions.

- Client must run "STLS" command to establish TLS connection by default.
  It's described in RFC2595. I don't know clients which support this extension,
  but there are many clients which support "pop3s" service and you probably
  want to enable it. You can enable "pop3s" service through "TLSWrap" option.
  Remember that "pop3s" service should run on port 995. You should reconfigure
  your inetd/tcpserver if you want to use it. If you want to use standalone
  version of Solid POP3, you should change POP3_PORT constant in src/const.h
  (replace value 110 with 995).

- You can specify entropy source for Pseudo Random Number Generator
  with TLSRandSource option. You SHOULD do this if your system hasn't
  an internal entropy source (/dev/[u]random device)!!! You can use
  Entropy Gathering Daemon (http://www.lothar.com/tech/crypto) for this
  purpose, but remember that EGD is resource-consuming process when
  collecting entropy. You should be very careful using EGD as a entropy
  source for a heavily-loaded POP3 server.

- Although there are 512bit and 1024bit Diffie-Hellman parameters compiled
  in the server, generating own parameters is a better idea than using these
  built in. Built in parameters are included from SKIP project.
  You can verify them as described in http://www.skip-vpn.org/spec/numbers.html
  But you really should generate your own parameters.

- You can use TLS peer authentication as a SASL EXTERNAL authentication
  mechanism. User's certificate should have user name in Common-Name field
  and TLSAskCert (or TLSRequireCert) option should be enabled. User mapping
  is disabled when EXTERNAL mechanism is used.

- There is no session reusing implemented in Solid POP3. Session manager
  may appear in next release.
