Deleted cert by mistake, can’t create new one

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: vpn.ecoarome.com

I ran this command: n/a

It produced this output: n/a

My web server is (include version): n/a

The operating system my web server runs on is (include version): n/a

My hosting provider, if applicable, is: n/a

I can login to a root shell on my machine (yes or no, or I don’t know): yes

I’m using a control panel to manage my site (no, or provide the name and version of the control panel): DSM 6.2.2

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you’re using Certbot): n/a

Hello.

I have a Synology NAS (ds218+) and had a working LE certificate on in for vpn.ecoarome.com

While trying to figure out how to add another sub domain to the certificate (ds218plus.ecoarome.com) I made a big mistake, and deleted it from my NAS

Now when I try to make a new certificate from my NAS control panel (DSM 6.2.2) of course it sais the domain name is already in use.

I have limited experience with connecting through SSH, but no clue about certbot whatsoever.

Ideally, I’d like to remove the cert from LE database without waiting 2 month for expiration, but if that’s not possible, at least I’d need help to add the cert back to my NAS and if possible add the second domain name to it.

Thank you.

DSM 6.2.2 is the latest for that unit and it should just work with LetsEncrypt.
I do see that it now has self-signed synology cert: SSL Labs test
And I also noticed that the FQDN “ds218plus.ecoarome.com” does NOT resolve to an IP - which may be part of the renewal problem.

  • yes, ds218plus.ecoarome.com does not resolve right now, because i deactivaded it’s dns while i am trying to fix the original problem. i will turn it on again at a later point, mostly because we haven’t 100% decided yet if we want to use that secondary name or another
  • yes, right now vpn.ecoarome.com (the main one) is using the default self signed one, because like i explained earlier, i removed the LE one and i can’t just leave the NAS without an active cert at all.

so, can you provide any help how to “reinstall” our active LE cert?

hm, maybe it was just a timed error. i tried again now and it worked.

thanks for your help :slight_smile:

1 Like

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.