Setting up a StartSSL Certificate for your DS in 10 steps!

Anything regarding SSL/SSH and other security questions may go here
Forum rules
Please note the disclaimer before modifying your Synology Product.

Re: Setting up a StartSSL Certificate for your DS in 10 step

Postby vaya_putada » Mon Jul 30, 2012 10:45 am

With newer versions of DS is so simple to add a certificate to the DS.

You can do it with the wizard under "Web Station" configuration in the control panel. Is not necessary to do this procedure. I did it in the past, but now I have my certificate correctly installed without doing anything of this.

Probably you need it if you want to use the certificate for other purposes, for example VPN or others... But if you only need it for WebStation, is not necessary to do this.

Regards!
vaya_putada
Experienced
Experienced
 
Posts: 116
Joined: Sat Jan 08, 2011 5:00 pm

Re: Setting up a StartSSL Certificate for your DS in 10 step

Postby luckman212 » Thu Sep 20, 2012 5:50 pm

Hello,
I have tried to use StartSSL to create an SSL cert for my DS712, DSM4.1 final. It works from IE and Chrome but not Firefox. In Firefox I have the famous "The certificate is not trusted because no issuer chain was provided" error. I have not used the command line method, rather I imported the certificates via the DSM GUI. Is that my mistake? I think somehow the intermediate cert "sub.class1.server.ca.pem" has not installed correctly. Has anyone followed these steps with success on DSM 4.1? So many .crt, .csr, .key, .pem, .ca files my head is spinning. :roll:
DS712+, DSM 4.1-2668
User avatar
luckman212
Experienced
Experienced
 
Posts: 125
Joined: Thu May 12, 2011 3:17 am

Re: Setting up a StartSSL Certificate for your DS in 10 step

Postby luckman212 » Mon Sep 24, 2012 1:16 pm

Well I am back to report some success although I am still a bit confused. I was able to solve the Firefox intermediate CA problem by manually adding in the following lines to /usr/syno/apache/conf/extra/httpd-ssl.conf-common :
Code: Select all
SSLCertificateChainFile /usr/syno/etc/ssl/ssl.root/sub.class1.server.ca.pem
SSLCACertificateFile /usr/syno/etc/ssl/ssl.root/ca.pem

And then restarting Apache:
/usr/syno/etc/rc.d/S97apache-sys.sh restart
/usr/syno/etc/rc.d/S97apache-user.sh restart

It seems like the GUI screen within DSM under Control Panel > Web Services > HTTP > Import Certificates may be broken?
Image
Not sure where this intermediate CA gets added but I tried grep'ing through the entire /usr/syno/apache/conf/ directory looking for 'sub.class1.server.ca.pem' and didn't find it until I manually added it using the steps above. ???
DS712+, DSM 4.1-2668
User avatar
luckman212
Experienced
Experienced
 
Posts: 125
Joined: Thu May 12, 2011 3:17 am

Re: Setting up a StartSSL Certificate for your DS in 10 step

Postby luckman212 » Wed Sep 26, 2012 6:28 pm

So- Does anyone know about why the intermediate CA does not seem to work when added via the GUI?
DS712+, DSM 4.1-2668
User avatar
luckman212
Experienced
Experienced
 
Posts: 125
Joined: Thu May 12, 2011 3:17 am

Re: Setting up a StartSSL Certificate for your DS in 10 step

Postby ErikD » Mon Oct 08, 2012 7:10 pm

I installed the startSSL certificate using the GUI, including the CA certificate sub.class1.server.ca.pem from http://www.startssl.com/certs/
It's working fine. But since that time I can't use https with Ds Audio on iOS. (check IP adress from Diskstation).
DS File with https is working, so is DS Audio without https
Could there be a relation between the certificate and the disfuntioning of DS Audio https?
Is there any way to remove the certificates to test this?
DS412+, DSM 4.1-2636 final
ErikD
I'm New!
I'm New!
 
Posts: 1
Joined: Mon Oct 08, 2012 6:53 pm

Re: Setting up a StartSSL Certificate for your DS in 10 step

Postby ALBINALI » Fri Oct 19, 2012 10:27 pm

Please i need help !
which file from GUI should i keep in:
1- Privte ket
2- Certificate
3- Intermediate
??
DS 1512+
DSM 4.2-3202
User avatar
ALBINALI
Experienced
Experienced
 
Posts: 133
Joined: Sat Jul 14, 2012 10:15 pm

Re: Setting up a StartSSL Certificate for your DS in 10 step

Postby GNOE Inc. » Sat Oct 20, 2012 10:18 am

ALBINALI wrote:Please i need help !
which file from GUI should i keep in:
1- Privte ket
2- Certificate
3- Intermediate
??


- At location 'Private Key:' browse to the 'some.nopass.key'-file (made in step 4)
- At location 'Certificate:' browse to the 'ssl.crt'-file (made in step 8.8 )

Intermediate ->> - sub.class1.server.ca.pem (intermediate CA certificate)
DS 207+ FW: DSM 3.1 -1613
DS 710+ FW: DSM 4.1
DS 212+ FW: DSM 4.1

We know everything about nothing ......

Note: English is not my native language.......
User avatar
GNOE Inc.
Versed
Versed
 
Posts: 225
Joined: Sun Oct 12, 2008 8:41 pm

Re: Setting up a StartSSL Certificate for your DS in 10 step

Postby ALBINALI » Sat Oct 20, 2012 8:23 pm

GNOE Inc. wrote:
ALBINALI wrote:Please i need help !
which file from GUI should i keep in:
1- Privte ket
2- Certificate
3- Intermediate
??


- At location 'Private Key:' browse to the 'some.nopass.key'-file (made in step 4)
- At location 'Certificate:' browse to the 'ssl.crt'-file (made in step 8.8 )

Intermediate ->> - sub.class1.server.ca.pem (intermediate CA certificate)


Thank you so much for trying to help me , but is the startsll free acount work fine with this?
DS 1512+
DSM 4.2-3202
User avatar
ALBINALI
Experienced
Experienced
 
Posts: 133
Joined: Sat Jul 14, 2012 10:15 pm

Re: Setting up a StartSSL Certificate for your DS in 10 step

Postby GNOE Inc. » Sat Oct 20, 2012 8:45 pm

It's all free! :wink:
DS 207+ FW: DSM 3.1 -1613
DS 710+ FW: DSM 4.1
DS 212+ FW: DSM 4.1

We know everything about nothing ......

Note: English is not my native language.......
User avatar
GNOE Inc.
Versed
Versed
 
Posts: 225
Joined: Sun Oct 12, 2008 8:41 pm

Re: Setting up a StartSSL Certificate for your DS in 10 step

Postby ALBINALI » Sat Oct 20, 2012 8:53 pm

but as understand that thawte trial is for 30 day only !
and the startsll in one year !
sorry if it is not clear to me !
DS 1512+
DSM 4.2-3202
User avatar
ALBINALI
Experienced
Experienced
 
Posts: 133
Joined: Sat Jul 14, 2012 10:15 pm

Re: Setting up a StartSSL Certificate for your DS in 10 step

Postby GNOE Inc. » Sat Oct 20, 2012 8:59 pm

StartSSL™ Free

The StartSSL™ Free (Class 1) certificates are domain or email validated and mostly referred to as the free certificates. Because the checks are performed mostly by electronic means, they require only minimal human intervention from our side. The validations are here to make sure, that the subscriber is the owner of the domain name, resp. email account. You may find additional information on this subject in our CA policy.

The StartSSL™ Free certificates are intended for web sites which require protection of privacy and prevent eavesdropping. However information presented within these certificates, except the domain name and email address, are not verified. Should you need higher validated certification, please check out our StartSSL™ Verified (Class 2) certificates.

100% Free The StartCom Certification Authority, provides the StartSSL™ Free certificates instantly, without limitations and free of charge under the condition, that the subscriber provides his/her complete, correct personal details and accepts the Subscriber Obligations of the StartCom CA Policy. Secure your web server and mail traffic now by using the Certificate Control Panel
DS 207+ FW: DSM 3.1 -1613
DS 710+ FW: DSM 4.1
DS 212+ FW: DSM 4.1

We know everything about nothing ......

Note: English is not my native language.......
User avatar
GNOE Inc.
Versed
Versed
 
Posts: 225
Joined: Sun Oct 12, 2008 8:41 pm

Re: Setting up a StartSSL Certificate for your DS in 10 step

Postby ALBINALI » Sat Oct 20, 2012 10:50 pm

Thank you for your help seems that i need to do the steps again some thing wrong with what i do :)
DS 1512+
DSM 4.2-3202
User avatar
ALBINALI
Experienced
Experienced
 
Posts: 133
Joined: Sat Jul 14, 2012 10:15 pm

Re: Setting up a StartSSL Certificate for your DS in 10 step

Postby ALBINALI » Mon Oct 22, 2012 9:45 pm

New problem apper to me , now when i remove the https option from the DSM and try to login to my DS it is not login and when i enable it it is not login with port 5001 but it is login with port 5000 ??
so my ddns apper like this:
https://++++++.synology.me:5000
how could this be ?
now i want to remove the https option i remove all the teck from the option and it is not work :(
Image
DS 1512+
DSM 4.2-3202
User avatar
ALBINALI
Experienced
Experienced
 
Posts: 133
Joined: Sat Jul 14, 2012 10:15 pm

Re: Setting up a StartSSL Certificate for your DS in 10 step

Postby ALBINALI » Wed Oct 24, 2012 12:38 am

I don`t know what is happen i just restart the router and the http ddns work but the https it is not work hehehehehe , even if i enable it i don`t wanna enable the auto redirect to https :?
DS 1512+
DSM 4.2-3202
User avatar
ALBINALI
Experienced
Experienced
 
Posts: 133
Joined: Sat Jul 14, 2012 10:15 pm

Re: Setting up a StartSSL Certificate for your DS in 10 step

Postby ALBINALI » Sat Mar 02, 2013 5:23 pm

Hello GNOE Inc.,

Please i follow the steps is this thread
http://mikebeach.org/2012/11/13/startssl-ssl-certificate-on-synology-nas-using-subdomain/
everything was fine until i need to save the certificate in file i just copy it to a text file and after that when i copy it again from the text file it is appear this is not the right way to save a code !
Image
so please can you help me to find a way to safe this code so i can create this SSL file :cry:
DS 1512+
DSM 4.2-3202
User avatar
ALBINALI
Experienced
Experienced
 
Posts: 133
Joined: Sat Jul 14, 2012 10:15 pm

PreviousNext

Return to Security/Secured Mods

Who is online

Users browsing this forum: No registered users and 1 guest