Yes. Problem was that I'am using serts only in local_name sections
local_name {
ssl_cert = </etc/letsencrypt/live/
ssl_key = </etc/letsencrypt/live/
I am using multi domain mail server with one IP.
Refer to Wiki has been closed
With client TLS SNI (Server Name Indication) support
!!!!but dovecot also need default sert&key.!!!
so I just repeat this 2 line at in the start of config.
# SSL settings
# SSL/TLS support: yes, no, required. <doc/wiki/SSL.txt>
ssl = yes
ssl_cert = </etc/letsencrypt/live/
ssl_key = </etc/letsencrypt/live/
# PEM encoded X.509 SSL/TLS certificate and private key. They're opened before
# dropping root privileges, so keep the key file unreadable by anyone but
# root. Included doc/ can be used to easily generate self-signed
# certificate, just make sure to update the domains in dovecot-openssl.cnf
local_name {
ssl_cert = </etc/letsencrypt/live/
ssl_key = </etc/letsencrypt/live/
Maybe somebody help this