<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/xsl" href="../assets/xml/rss.xsl" media="all"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>chris' random ramblings (Posts about synology)</title><link>https://atlee.ca/</link><description></description><atom:link href="https://atlee.ca/categories/synology.xml" rel="self" type="application/rss+xml"></atom:link><language>en</language><lastBuildDate>Mon, 28 Sep 2026 02:27:17 GMT</lastBuildDate><generator>Nikola (getnikola.com)</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><item><title>How to fix Let's Encrypt / acme.sh renewal on Synology</title><link>https://atlee.ca/posts/synology-acme-renewal/</link><dc:creator>chris</dc:creator><description>&lt;p&gt;I use a &lt;a href="https://letsencrypt.org/"&gt;Let's Encrypt&lt;/a&gt; certificate so &lt;a href="https://www.synology.com/en-us/dsm/feature/photos"&gt;Synology Photos&lt;/a&gt; can connect to my NAS over HTTPS without a certificate warning. I renew it with &lt;a href="https://github.com/acmesh-official/acme.sh"&gt;&lt;code&gt;acme.sh&lt;/code&gt;&lt;/a&gt; using a DNS challenge.&lt;/p&gt;
&lt;p&gt;When the certificate expired, Photos stopped syncing and renewal failed with:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code literal-block"&gt;curl: (60) SSL certificate problem: certificate has expired
&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;The error made it look like &lt;code&gt;acme.sh&lt;/code&gt; didn't trust a certificate authority. The actual problem was that the &lt;a href="https://www.rfc-editor.org/rfc/rfc8484"&gt;DNS-over-HTTPS (DoH)&lt;/a&gt; request was reaching my NAS instead of Cloudflare.&lt;/p&gt;
&lt;h3 id="finding-the-wrong-certificate"&gt;Finding the wrong certificate&lt;/h3&gt;
&lt;p&gt;During DNS validation, the renewal script queried &lt;code&gt;cloudflare-dns.com&lt;/code&gt; and &lt;code&gt;dns.google&lt;/code&gt; over DNS-over-HTTPS. I checked the certificate returned for Cloudflare:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code literal-block"&gt;openssl&lt;span class="w"&gt; &lt;/span&gt;s_client&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="se"&gt;\&lt;/span&gt;
&lt;span class="w"&gt;  &lt;/span&gt;-connect&lt;span class="w"&gt; &lt;/span&gt;cloudflare-dns.com:443&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="se"&gt;\&lt;/span&gt;
&lt;span class="w"&gt;  &lt;/span&gt;-servername&lt;span class="w"&gt; &lt;/span&gt;cloudflare-dns.com&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="se"&gt;\&lt;/span&gt;
&lt;span class="w"&gt;  &lt;/span&gt;-showcerts&lt;span class="w"&gt; &lt;/span&gt;&amp;lt;/dev/null&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="m"&gt;2&lt;/span&gt;&amp;gt;/dev/null&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;|&lt;/span&gt;
openssl&lt;span class="w"&gt; &lt;/span&gt;x509&lt;span class="w"&gt; &lt;/span&gt;-noout&lt;span class="w"&gt; &lt;/span&gt;-subject&lt;span class="w"&gt; &lt;/span&gt;-issuer&lt;span class="w"&gt; &lt;/span&gt;-dates
&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;The subject was my NAS's hostname. A local lookup showed that &lt;code&gt;cloudflare-dns.com&lt;/code&gt; resolved to &lt;code&gt;0.0.0.0&lt;/code&gt; and &lt;code&gt;::&lt;/code&gt;:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code literal-block"&gt;nslookup&lt;span class="w"&gt; &lt;/span&gt;cloudflare-dns.com
&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;My router uses a NextDNS profile with &lt;strong&gt;Block Bypass Methods&lt;/strong&gt; enabled. It was blocking the DNS-over-HTTPS providers and returning those addresses. The connection went back to the NAS, which presented its expired certificate. That's why &lt;code&gt;curl&lt;/code&gt; complained about an expired certificate while &lt;code&gt;acme.sh&lt;/code&gt; was trying to contact Cloudflare.&lt;/p&gt;
&lt;p&gt;I checked the same name using Cloudflare's resolver directly:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code literal-block"&gt;nslookup&lt;span class="w"&gt; &lt;/span&gt;cloudflare-dns.com&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="m"&gt;1&lt;/span&gt;.1.1.1
&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;That returned the expected address. I added &lt;code&gt;cloudflare-dns.com&lt;/code&gt; and &lt;code&gt;dns.google&lt;/code&gt; to the NextDNS allowlist.&lt;/p&gt;
&lt;h3 id="clearing-the-failed-challenge-and-renewing"&gt;Clearing the failed challenge and renewing&lt;/h3&gt;
&lt;p&gt;The first attempt had created the ACME DNS TXT record before it failed. After allowing the DNS-over-HTTPS providers, the next attempt stopped with Cloudflare error 81058 because that TXT record already existed. I deleted the stale &lt;code&gt;_acme-challenge&lt;/code&gt; record from Cloudflare, checked that it was gone, and ran the renewal again. I also upgraded &lt;code&gt;acme.sh&lt;/code&gt; from 3.0.9 to 3.1.5. The script deployed the new certificate into DSM with &lt;code&gt;sudo&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;The fix for this error was the NextDNS allowlist. The certificate subject gave away the real problem: I was seeing my NAS's certificate in a connection that should have gone to Cloudflare.&lt;/p&gt;
&lt;h3 id="separately-adding-ca-roots-to-dsm"&gt;Separately: adding CA roots to DSM&lt;/h3&gt;
&lt;p&gt;I also updated DSM's CA roots, but that was separate maintenance, not the fix above. On DSM 7, custom root certificates go in this directory as &lt;code&gt;.crt&lt;/code&gt; files:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code literal-block"&gt;/usr/syno/etc/security-profile/ca-bundle-profile/ca-certificates/
&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;With SSH enabled, I copied the current ISRG Root X1 and X2 certificates from &lt;a href="https://letsencrypt.org/certificates/"&gt;Let's Encrypt&lt;/a&gt; into that directory and rebuilt DSM's trust bundle:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code literal-block"&gt;sudo&lt;span class="w"&gt; &lt;/span&gt;mkdir&lt;span class="w"&gt; &lt;/span&gt;-p&lt;span class="w"&gt; &lt;/span&gt;/usr/syno/etc/security-profile/ca-bundle-profile/ca-certificates
sudo&lt;span class="w"&gt; &lt;/span&gt;cp&lt;span class="w"&gt; &lt;/span&gt;isrgrootx1.pem&lt;span class="w"&gt; &lt;/span&gt;/usr/syno/etc/security-profile/ca-bundle-profile/ca-certificates/isrg-root-x1.crt
sudo&lt;span class="w"&gt; &lt;/span&gt;cp&lt;span class="w"&gt; &lt;/span&gt;isrg-root-x2.pem&lt;span class="w"&gt; &lt;/span&gt;/usr/syno/etc/security-profile/ca-bundle-profile/ca-certificates/isrg-root-x2.crt
sudo&lt;span class="w"&gt; &lt;/span&gt;chmod&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="m"&gt;644&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;/usr/syno/etc/security-profile/ca-bundle-profile/ca-certificates/*.crt
sudo&lt;span class="w"&gt; &lt;/span&gt;/usr/syno/bin/update-ca-certificates.sh
&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;This updates roots DSM uses to verify certificates from other services. It doesn't change the certificate DSM presents to Photos clients; that is managed under &lt;strong&gt;Control Panel → Security → Certificate&lt;/strong&gt;. Synology's &lt;a href="https://kb.synology.com/en-us/DSM/help/DSM/AdminCenter/connection_certificate"&gt;certificate guide&lt;/a&gt; covers that separate step.&lt;/p&gt;</description><category>linux</category><category>networking</category><category>synology</category><guid>https://atlee.ca/posts/synology-acme-renewal/</guid><pubDate>Sun, 27 Sep 2026 04:00:00 GMT</pubDate></item></channel></rss>