Info Why the synology.com default certificate ?

Currently reading
Info Why the synology.com default certificate ?

4,063
1,393
NAS
DS4l8play, DS202j, DS3623xs+, DSM 7.3.3-25847
So why does this cert exist? Can it safely be deleted? Is it just a placeholder since DSM requires at least one certificate?

On one machine in expires in several months. On another machine it expires in 2037. Why?

Is this cert machine specific, or could I export/import it across machines.

Thanks... this always aroused my curiosity.
 
I don't know the details of why it exists, but I know that some services depend on it when there's nothing else! eg OpenVPN), and changing to another default needs to be done right (I screwed it up and now I'm having to get support from Synology to fix my loss of remote access via VPN server)!
Seems I tried to do an 'update' to the System Default certificate, but I didnt do it right, and now it has resulted in the default certificate being deleted and I cant get the VPN to stand anymore. (Username/password Auth doesn't work using Tunnelblick client anymore. Before my faux pas it all worked fine!)
 
I think I deleted one once, nothing bad happened. Specifically SRM doesn't allow multiple certificates so the default Synology one will be overwritten if you create or add your own.

If you create your own self-signed certificate I think it has a one year life, but the default one created during initial setup goes on for years.

If the default doesn't have any services assigned to it then I think it is safe to delete. Also assign a different certificate as default.

The OpenVPN .ovpn file has certificate info embedded so that could be a source of problems if you're not just renewing, e.g., an LE cert.
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Similar threads

I am setting up a new DS224+ unit for a client. Not new to NAS drives but new to Synology. Storage pool...
Replies
0
Views
417
agree, but yet another good reminder that it is amongst good security practices to disable the default...
Replies
3
Views
908
All 3 NAS's are set that way.... FIREWALL AND NOTIFICATIONS ARE CHECKED I have in the past seen and...
Replies
2
Views
1,115
Hello guys, I am sorry for my late response, but I was travelling due to work duties. Hello Rusty, I...
Replies
4
Views
2,502
I have seen your post on Mastodon and responded, but I see no issues with using 3rd party 2fa platforms...
Replies
6
Views
5,925
If you disable your nas firewall, then it’s opened up to everything and anything, because you have no...
Replies
24
Views
5,755
  • Locked
  • Question
https://www.synoforum.com/threads/synology-nas-encryption-forensic-analysis-of-synology-nas-devices-by-elco...
Replies
1
Views
2,451

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!

Trending threads

Back
Top