Hi,
I’ve had LetsEncrypt working fine on my NAS for awhile but I’ve noticed that every time it gets renewed the next time I log on using one of Synology’s mobile apps it gives me a warning about a certificate mismatch and I have to select OK to trust it again until next time.
Is there anyway to stop this from happening?
Well, this seems to work properly for most users, so I have no idea what to suggest if you don’t want to let us look at your particular instance’s configuration.
So, the certificate might be improperly installed on your device for some reason, which is hard to confirm without seeing the specific browser error message.
Sorry about all of the effort to get to this point, but I think this is just clumsy interface in this particular app. There’s nothing wrong or invalid about the new certificate; it’s just different from the old certificate. In this case the administrator (you) has changed the certificate.
I would suggest that you ask Synology for a way to disable this specific warning in the app.
True, what @schoen writes. As a Synology user I can confirm this. I even wrote about this to Synology and they don’t seem to care.
I have worked around this by having two certificates:
Let’s Encrypt certificate for Synology web applications - DSM and Photo Station
10-years self-signed certificate for other apps (that I use mostly on mobile) - Cloud Station, File Station etc. - this certificate will last enough and I and other my Synology users are not bothered every 3 months when LE certificate is renewed.
Is this app just remembering the certificate fingerprint without validating the certificate cryptographically against a list of trusted CAs? This behavior would make sense if most certificates used with these devices were self-signed, but now that Let’s Encrypt is available and Synology has added good support for use of Let’s Encrypt certificates on NAS devices, it seems like the app could validate the certificates and not show this warning when the certificate is trusted according to the mobile device’s policy.
Well, I’ve reviewed my NAS settings and I was not correct about the mobile apps. I do have two certificates but the long-term self-signed certificate set up only for the Cloud Station app. So I didn’t have actually problem with mobile apps in general but only with Cloud Station mobile app and especially with Windows app – this is where my Synology users were constantly bothered by a warning that the certificate has changed and they had to re-apply the connection settings and accept new certificate :-/
Question for you. Did you have trouble installing your cert on your iPhone?
I’ve exported from my Synology NAS and I’m using the chain.pem file, I tried to use the cert file but it wouldn’t verify. Any insight would greatly appreciated.
Thank you.