Just to follow-up with Simon's comment, you can install the SSL, configure it on the IMAP VS, then disable port 143 access from the Internet. Leave only 993 open, and it will prevent unencrypted IMAP access.
Howerver, RPC over HTTPS is definitely the way to go.