A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2016-5951
https://bugzilla.suse.com/show_bug.cgi?id=984639
https://bugzilla.redhat.com/show_bug.cgi?id=1346055
http://lists.opensuse.org/opensuse-updates/2016-11/msg00096.html