Hi all,
I’m pretty new but keen to learn. I have a Synology home NAS which I can access remotely. The guy who helped me set it up (I think) installed a certificate - I can see this under the Synogy control panel > Security > Certificate. I can see that it’s issued by LetsEncrypt and it has a date of 2018-1-15.
I’ve had an email saying that it’s about to expire and I need to renew it.
Also, the renewal warning e-mail could happen if you had an older certificate with slightly different name coverage. If that’s the case, then the warning might not be relevant if the changes in coverage were intentional.
I’m pretty sure that there is just the one certificate and the details I can see on the NAS suggest expiry at the same time as the email so that seems to be right.
I can see the details but I just can’t see how to renew the certificate. I’ll go away and read the article suggested and see if that helps
Thanks Juergen for the link, that was helpful. I found the but about ‘renewing’ … this says …
To renew certificates:
When your certificate is about to expire, it can be renewed using this option.
Click CSR .
Select Renew certificate and click Next .
Download the generated private key and certificate signing request.
Send the CSR to the desired certificate authority for a renewed certificate.
I have 2 certificates one from Letsencrypt and one from synology. I select the lets encrypt one then click CSR and have only 2 options:
Create a CSR and SIgn CSR - there isn’t a renew option. HOWEVER …
On the ‘Add’ dropdown tab along the top there is an option to renew - so I’ve tried that and recieved an error about port 80 needing to be open to letsencrypt so I think that’s my next area to investigate (I have changed my router since the original install so I guess I’ve some work to do)
Juergen, I’d done as you’ve suggested but I now have 3 certificates (2 from lets encrypt and one from synology). The default is currently with the old one though I imagine I can change that fairly simply. I think what I’ve done is added a new certificate without renewing the old one. I’ve not looked at opening port 80 yet.
Regarding port 80 … I have BT home router (Smart Hub), The firewall only has options for port forwarding and I’m not entirely sure what I’m doing there …
You should change the certificate, so Synology knows this is a LE-certificate Synology has created. Then the renew should work without any manual action.
What's your domain name? If you have created a new Letsencrypt certificate, your router settings are already good.