# QNAP-NAS can´t renew existing certificate

**URL:** <https://community.letsencrypt.org/t/qnap-nas-can-t-renew-existing-certificate/211011>\
**Category:** Help\
**Created:** [January 2, 2024, 1:04pm UTC](https://community.letsencrypt.org/t/qnap-nas-can-t-renew-existing-certificate/211011 "2024-01-02T13:04:14Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![WeT-Klb](https://avatars.discourse-cdn.com/v4/letter/w/e9a140/32.png) [@WeT-Klb](https://community.letsencrypt.org/u/WeT-Klb)\
**Post date:** [January 2, 2024, 1:04pm UTC](https://community.letsencrypt.org/t/qnap-nas-can-t-renew-existing-certificate/211011/1 "2024-01-02T13:04:14Z")

</div>

My QNAP won´t let me renew my existing certificate. I am always told to check DNS or Port 80.  
When I log in by SSL i can send a **ping [www.google.com](http://www.google.com)** without any problems.  
And when accessing my NAS by **[http://externalIP:80/show-php.php](http://externalIP:80/show-php.php)** I will see the output.  
So both things should work. How can I renew my still valid certificate (until 9th of january 2024)?

My domain is: **[wet-klb.dyndns.org](http://wet-klb.dyndns.org)**

I ran this command: **Zertifikat erneuern**

It produced this output: **Authentifizierung fehlgeschlagen. Bitte prüfen Sie den DNS-Server oder schauen Sie nach, ob Port 80 funktioniert.**

My web server is (include version): **Apache built-in QNAP-NAS 5.1.4.2596**.

The operating system my web server runs on is (include version) : **QNAP-NAS TS-251 5.1.4.2596**.

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don't know): **Yes**

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): **Partwise**

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot): **---**

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [January 3, 2024, 11:47pm UTC](https://community.letsencrypt.org/t/qnap-nas-can-t-renew-existing-certificate/211011/2 "2024-01-03T23:47:17Z")

</div>

9 posts were split to a new topic: [QNAP NAS trouble renewing certificate](https://community.letsencrypt.org/t/qnap-nas-trouble-renewing-certificate/211091)

---

<div class="post-metadata">

**Author:** ![WeT-Klb](https://avatars.discourse-cdn.com/v4/letter/w/e9a140/32.png) [@WeT-Klb](https://community.letsencrypt.org/u/WeT-Klb)\
**Post date:** [January 2, 2024, 1:28pm UTC](https://community.letsencrypt.org/t/qnap-nas-can-t-renew-existing-certificate/211011/3 "2024-01-02T13:28:37Z")

</div>

Mid of december I receved an Email from [Letsencrypt.org](http://Letsencrypt.org) telling me, the certificate will expire in 19 days and I should renew it.  
But as it´s not the first time I receive a mail like this and QNAP used to renew 10 days before I was waitung for the NAS to do the job.  
I already started an issue at QNAP, too. Let's see what will come out.  
Where are you located? I am from germany.

---

<div class="post-metadata">

**Author:** ![WeT-Klb](https://avatars.discourse-cdn.com/v4/letter/w/e9a140/32.png) [@WeT-Klb](https://community.letsencrypt.org/u/WeT-Klb)\
**Post date:** [January 2, 2024, 3:26pm UTC](https://community.letsencrypt.org/t/qnap-nas-can-t-renew-existing-certificate/211011/5 "2024-01-02T15:26:34Z")

</div>

QNAP asked me to send a screenshop from "MyQnapcloud -\> SSL Zertifikat".  
I did so - but it is interesting there the certificate is valid only until 2024-01-02 while Control panek -\> security -\> SSL Zertifikat shows 2024.01.09....

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [January 2, 2024, 3:43pm UTC](https://community.letsencrypt.org/t/qnap-nas-can-t-renew-existing-certificate/211011/6 "2024-01-02T15:43:05Z")

</div>

I don't see any reason for the cert renewal to fail either.

From the public internet we can reach your domain using HTTP (port 80) used by the ACME HTTP challenge. See also Let's Debug result ([link here](https://letsdebug.net/wet-klb.dyndns.org/1755647))

> [@WeT-Klb](#):
>
> it is interesting there the certificate is valid only until 2024-01-02 while Control panek -\> security -\> SSL Zertifikat shows 2024.01.09....

The only active Let's Encrypt cert expires on Jan9. Sometimes NAS devices come with a built-in self-signed cert to use during setup. Are there any other details about that Jan2 expiring cert? See your LE certs with a tool like this [Let's Debug Toolkit](https://tools.letsdebug.net/cert-search)

Your domain is using the Jan9 expiring cert for HTTPS requests. Use a site like this SSL Checker to see ([link here](https://decoder.link/sslchecker)).

If you can get more detailed error messages for why it is failing we could maybe offer advice. But, for now your best action is to continue working with QNAP.

---

<div class="post-metadata">

**Author:** ![WeT-Klb](https://avatars.discourse-cdn.com/v4/letter/w/e9a140/32.png) [@WeT-Klb](https://community.letsencrypt.org/u/WeT-Klb)\
**Post date:** [January 2, 2024, 4:24pm UTC](https://community.letsencrypt.org/t/qnap-nas-can-t-renew-existing-certificate/211011/7 "2024-01-02T16:24:07Z")

</div>

As far as I know the 2nd of january-certificate is not the real expire day - to me it seems only the recent day is shown - so tomorrow it should be 2024-01-03 - i will proof that.  
Where can I find the LE certs to chech with that Let's Debug Toolkit?  
I am already in touch with QNAP service - let`s see what they can do.  
It seems I am not the only one haveing problem with that.

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [January 2, 2024, 4:30pm UTC](https://community.letsencrypt.org/t/qnap-nas-can-t-renew-existing-certificate/211011/8 "2024-01-02T16:30:23Z")

</div>

> [@WeT-Klb](#):
>
> Where can I find the LE certs to chech with that Let's Debug Toolkit

Enter your domain name on the screen and choose the look back.. Default is seven days but if you look back 90 days you will see all unexpired certs for that domain name

---

<div class="post-metadata">

**Author:** ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)\
**Post date:** [January 2, 2024, 11:04pm UTC](https://community.letsencrypt.org/t/qnap-nas-can-t-renew-existing-certificate/211011/9 "2024-01-02T23:04:18Z")

</div>

> [@WeT-Klb](#):
>
> [wet-klb.dyndns.org](http://wet-klb.dyndns.org)

Here [SSL Server Test: wet-klb.dyndns.org (Powered by Qualys SSL Labs)](https://www.ssllabs.com/ssltest/analyze.html?d=wet-klb.dyndns.org) shows " Chain issues **Incorrect order, Extra certs, Contains anchor**"

And similar here [Hardenize Report: wet-klb.dyndns.org](https://www.hardenize.com/report/wet-klb.dyndns.org/1704236456#www_certs)

And [https://decoder.link/sslchecker/wet-klb.dyndns.org/443](https://decoder.link/sslchecker/wet-klb.dyndns.org/443) " Chain Issues: _close_ The order of certificates is invalid or certificates cannot build certification path"

---

<div class="post-metadata">

**Author:** ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)\
**Post date:** [January 2, 2024, 11:33pm UTC](https://community.letsencrypt.org/t/qnap-nas-can-t-renew-existing-certificate/211011/10 "2024-01-02T23:33:24Z")

</div>

And here [myQNAPcloud](https://support.myqnapcloud.com/faq/_faq_q_would-qts-ssl-certificate-qpkg-renew-my-expiring-certificate-from-lets-encrypt-automatically?lang=en) states

> Yes. If you check the "auto renew" option when you apply for a Let's Encrypt SSL certificate, then the certificate will be automatically renewed when it is close to its expiry date. You can also change the auto-renewal setting of an existing certificate using the QTS SSL Certificate app  
> Auto-renewal works as follows:
> 
> 1. 30 days before a certificate expires, the QTS SSL Certificate app will try to renew the certificate.
> 2. To confirm that you still control the domain, Let's Encrypt will send a challenge request to myQNAPcloud DNS server.
> 3. If myQNAPcloud's DNS server cannot complete the challenge request, then the QTS SSL Certificate app will start other challenge methods using port 80 or 443.
> 4. The certificate will be downloaded to your device once the challenge request is complete.
> 5. The Web Server will be restarted after the new certificate is applied.
> 
> Notes: Renewing a certificate using port 443 first requires a new self-signed certificate to be generated. The web server will then be restarted, after the self-signed certificate is generated. This is normal behaviour.

Thus it seems [DNS-01 challenge](https://letsencrypt.org/docs/challenge-types/#dns-01-challenge) and will failover to [HTTP-01 challenge](https://letsencrypt.org/docs/challenge-types/#http-01-challenge) is used by QNAP.

---

<div class="post-metadata">

**Author:** ![WeT-Klb](https://avatars.discourse-cdn.com/v4/letter/w/e9a140/32.png) [@WeT-Klb](https://community.letsencrypt.org/u/WeT-Klb)\
**Post date:** [January 3, 2024, 4:12pm UTC](https://community.letsencrypt.org/t/qnap-nas-can-t-renew-existing-certificate/211011/11 "2024-01-03T16:12:02Z")

</div>

To be honest I have no idea what it means. Until now i never had to do anything manually - QNAP renewed the certificate automatically.  
What can I do now? How the "Chain issues" can appear?  
Until now I still can access my domain.

---

<div class="post-metadata">

**Author:** ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)\
**Post date:** [January 3, 2024, 9:10pm UTC](https://community.letsencrypt.org/t/qnap-nas-can-t-renew-existing-certificate/211011/13 "2024-01-03T21:10:29Z")

</div>

Perhaps the QNAP forum maybe of assistance as well [https://forum.qnap.com/](https://forum.qnap.com/)

---

<div class="post-metadata">

**Author:** ![Benna](https://avatars.discourse-cdn.com/v4/letter/b/53a042/32.png) [@Benna](https://community.letsencrypt.org/u/Benna)\
**Post date:** [January 22, 2024, 7:47am UTC](https://community.letsencrypt.org/t/qnap-nas-can-t-renew-existing-certificate/211011/14 "2024-01-22T07:47:29Z")

</div>

QNAP user here, i've the same proble: trying to renew the Let's encrypt certificate results in a message stating something about ACME server error. Please Verify te router and the QNAP device accepts incoming traffic on ports 80 and 443.

Im' not that expert, looking at the steps abouve sugested by QNAP i read this:

1. 30 days before a certificate expires, the QTS SSL Certificate app will try to renew the certificate.
2. To confirm that you still control the domain, Let's Encrypt will send a challenge request to myQNAPcloud DNS server.
3. If myQNAPcloud's DNS server cannot complete the challenge request, then the QTS SSL Certificate app will start other challenge methods using port 80 or 443.
4. The certificate will be downloaded to your device once the challenge request is complete.
5. The Web Server will be restarted after the new certificate is applied.

I think point number 2. could be the problem: i don't have ANY certificate on my myQNAPcloud page, i just have the let's encrypt certificate, so i guess the process will fail point 2 and goes directly to point 3, that also fails since the error message i get states he's unable to to accept incoming traffic on 80 or 443.  
Is this a dead loop?

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [January 22, 2024, 8:49am UTC](https://community.letsencrypt.org/t/qnap-nas-can-t-renew-existing-certificate/211011/15 "2024-01-22T08:49:12Z")

</div>

> [@Benna](#):
>
> i don't have ANY certificate on my myQNAPcloud page, i just have the let's encrypt certificate

I don't understand this part: so a Let's Encrypt certificate is not a certificate?

---

<div class="post-metadata">

**Author:** ![Benna](https://avatars.discourse-cdn.com/v4/letter/b/53a042/32.png) [@Benna](https://community.letsencrypt.org/u/Benna)\
**Post date:** [January 22, 2024, 9:25am UTC](https://community.letsencrypt.org/t/qnap-nas-can-t-renew-existing-certificate/211011/16 "2024-01-22T09:25:26Z")

</div>

Maybe QNAP checks as first instance "theire" certificate, if not present they search for an external authority.  
The problem, to me, is that when is probed let's encrypt, the result is a communication error on por 80 or 443, which is obviously a misleading information.  
Seems like, for some reason, let's encrypt cannot reach the NAS on those ports

---

<div class="post-metadata">

**Author:** ![WeT-Klb](https://avatars.discourse-cdn.com/v4/letter/w/e9a140/32.png) [@WeT-Klb](https://community.letsencrypt.org/u/WeT-Klb)\
**Post date:** [January 22, 2024, 10:57am UTC](https://community.letsencrypt.org/t/qnap-nas-can-t-renew-existing-certificate/211011/17 "2024-01-22T10:57:28Z")

</div>

I was told from QNAP to follow these steps:  
[Replacing the Server Certificate | QTS 5.0.x (qnap.com)](https://docs.qnap.com/operating-system/qts/5.0.x/en-us/replacing-the-server-certificate-8E7C1926.html)

Just make sure, you forwarded Port 443 in your router and you set web server in QNAP to port 80 (http) and 443 (https).

It worked for me - only QNAP still reports the certificate wasn't valid.

---

<div class="post-metadata">

**Author:** ![Benna](https://avatars.discourse-cdn.com/v4/letter/b/53a042/32.png) [@Benna](https://community.letsencrypt.org/u/Benna)\
**Post date:** [January 22, 2024, 11:47am UTC](https://community.letsencrypt.org/t/qnap-nas-can-t-renew-existing-certificate/211011/18 "2024-01-22T11:47:30Z")

</div>

When you say "Web Server" you mean the port number under "Control Panel --\> System --\> General settings --\> System port" ? Mine is usually set to 8080 but i changed it, just for this purpose, to 80.  
I then have 2 forward rules on my router, forwarding 443 and 80 to the internal NAS IP.  
I still keep getting error.

---

<div class="post-metadata">

**Author:** ![WeT-Klb](https://avatars.discourse-cdn.com/v4/letter/w/e9a140/32.png) [@WeT-Klb](https://community.letsencrypt.org/u/WeT-Klb)\
**Post date:** [January 22, 2024, 12:58pm UTC](https://community.letsencrypt.org/t/qnap-nas-can-t-renew-existing-certificate/211011/19 "2024-01-22T12:58:42Z")

</div>

No - not System port!  
I am talking about "Control Panel --\> System --\> Applications (last Button on the left side) --\> Webserver.

Yes - then forward the ports 80 and 443 to the same ports on your internal NAS-IP-Adress.

---

<div class="post-metadata">

**Author:** ![Benna](https://avatars.discourse-cdn.com/v4/letter/b/53a042/32.png) [@Benna](https://community.letsencrypt.org/u/Benna)\
**Post date:** [January 22, 2024, 3:52pm UTC](https://community.letsencrypt.org/t/qnap-nas-can-t-renew-existing-certificate/211011/20 "2024-01-22T15:52:06Z")

</div>

Ok, now it worked.  
What is out of my understanding is why i should enable the internal web server (which i don't use at all) in order to update an SSL certificate that i've created 3 months ago with the QNAP webserver service was offline

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [February 21, 2024, 3:52pm UTC](https://community.letsencrypt.org/t/qnap-nas-can-t-renew-existing-certificate/211011/21 "2024-02-21T15:52:30Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
