Comment by Arnt

Comment by Arnt a day ago

0 replies

Self-signed certs were a defect — people were used to just click OK and blackhats exploited that.

OP wants support for the special case where only the cert issuer trusts the cert (he has his own self-signed cert). Apple and others do support that: You make a private CA, trust that CA in the device, and then use that CA to sign certs for your IMAP server. IIRC (and this is from vague memory) you may need to configure yourself to be a company that manages employees' devices.