LE certificate chaos

Currently reading
LE certificate chaos

Telos

Subscriber
3,173
1,025
NAS
DS418play, DS213j, DS3623xs+, DSM 7.3.3-25847
I've been troubleshooting recent caldav sync issues between the NAS and Thuderbird and my "smarts" landed me in a mess.

I happened to notice that on my Win10 laptop, there was no apparent cert for the NAS. First, I attempted to download the LE cert from the NAS, thinking I could import it into Windows. However, the download is apparently only for the Synology NAS as the cert file extensions weren't recognized by Windows cert import.

So I tried another approach... I logged onto the NAS via my Synology DDNS using a browser. From the browser "view site information" padlock, I opened and downloaded the cert and it came in a format that Windows cert import could use.

I imported the downloaded cert into Windows using all the basic defaults and it located itself in an "Other" tab. So I figured how smart I am.

I rebooted the PC, opened the browser and attempted to log in, BUT... the browser informed me that my cert was odd and there was a 3rd party compromise suspected, and the browser would not give me the login screen (using the DDNS). I tried an alternate DDNS with the same result.

Next, I removed the cert I imported, rebooted... and the same issue. No access.

I just now reimaged my machine back 24 hours, and all is well. When I enter the DDNS I'm taken immediately to the DSM log in.

What did I do wrong? I'm flummoxed.
 

fredbert

Moderator
NAS Support
Subscriber
4,311
1,727
NAS
DS1520+, DS218+, DS215j
Router
  1. RT2600ac
  2. MR2200ac
  3. RT6600ax
  4. WRX560
Operating system
  1. macOS
Mobile operating system
  1. iOS
Is that a tea tray or a tray bake? ;)

@Telos If you have a LE certificate then you shouldn't need to install any certificate on the PC. If the LE certificate doesn't list the domain or subject alternate name of the URL that you used to connect then you can add an exception for that specific connection on that browser ... it's the same that happens when an unsigned cert is used for and URL by all browsers.

If you have an unsigned certificate then you could install the server certificate and say it's trusted, but this is something I haven't done for 19 years so memory is hazy.
 

Telos

Subscriber
3,173
1,025
NAS
DS418play, DS213j, DS3623xs+, DSM 7.3.3-25847
Just so I'm not offering a wrong solution, wanna be sure. What are you traying to do here exactly?
@Telos If you have a LE certificate then you shouldn't need to install any certificate on the PC. If the LE certificate doesn't list the domain or subject alternate name of the URL that you used to connect then you can add an exception for that specific connection on that browser ... it's the same that happens when an unsigned cert is used for and URL by all browsers.

When I sync Thuderbird CalDAV calendars (with my DDNS links) I occasionally get a popup about a certificate issue. The "View" certificate button doesn't open anything, and the "Allow" button is grayed out.

So I figured I would manually load the LE cert into Thunderbird to keep this from happening. As I wrote... this backfired and only made everything worse.

FWIW I also get a message to the effect that 'calendar "name here" is not presently available' when opening Thunderbird. Last night I rolled back the default calendar addon "Lightning" and these messages have stopped (temporarily?). I couldn't find any discussion of this on the Mozilla forums, so I started tweaking my Windows cert repository.
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Similar threads

  • Question
The whole world agrees that https is the right and secure way to access web applications. The question is...
Replies
1
Views
501
If a answer is still needed! You should import the cloudflare orgin server RSA PEM see doc. Origin CA...
Replies
1
Views
1,385
Replies
2
Views
1,374
Tremendous stuff thank you fredbert.
Replies
4
Views
1,258
  • Question
@WST16 - you found my boundaries 😉, I don’t use the 7.
Replies
8
Views
1,143
Thanks @fredbert - that makes sense to me since I have another cert from R3 for the mentioned connection...
Replies
8
Views
1,209
Good to hear. I guess I'll know more when expiration hits.
Replies
3
Views
4,070

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!

Top