Why Synology Says "This Connection is Not Private" - (How SSL Encryption Works)

  Рет қаралды 16,340

SpaceRex

SpaceRex

Күн бұрын

You've gone through a tutorial to secure your Synology NAS, but you are still getting a message that says the webpage is not secure. In this video, I will be walking through why this message appears, if you should actually be concerned, and how to prevent it.
Hire Me! yarboroughtechnologies.com/co...
Post on the Forums! forums.spacerex.co/
Links mentioned:
Let's Encrypt: letsencrypt.org
Synology Recommendations*:
Hard drives I recommend: amzn.to/3RA3udS
Starter NAS with BTRFS: amzn.to/46hrRS7
Great all around NAS with BTRFS: amzn.to/46egNVP
More powerful NAS with BTRFS (great for larger/mid sized businesses): amzn.to/3YwRziM
#nas #synology
TOC:
00:00 Introduction
02:44 How SSL (TLS) Encryption works
09:58 Why certificate fails on Synology
11:53 How to remove "not secure" message
13:45 Option 1: QuickConnect
16:04 Option 2: Let's Encrypt
20:05 Option 3: Generate your own certificate authority
20:37 Conclusion
*These are affiliate links, which means that if you purchase a product through one of them, I will receive a small commission (at no additional cost to you). Thank you for supporting my channel!

Пікірлер: 53
@user-ek7nq4by7z
@user-ek7nq4by7z 4 ай бұрын
On the topic of security: You should make a video on setting up a VLAN on a Unifi Controller for Surveillance Station to isolate the security cameras from the rest of the network and block the cameras from accessing the internet, yet still allowing remote access to Surveillance Station. You could also cover the importance of isolating IoT devices to mitigate risk of someone accessing your NAS and other devices through weak security that some IoT devices possess.
@droneforfun5384
@droneforfun5384 4 ай бұрын
This video from Rex would be very much appreciated. I hope he got the Will to do it.
@zate251
@zate251 4 ай бұрын
Yes
@user-ek7nq4by7z
@user-ek7nq4by7z 4 ай бұрын
@@djderekrock I already have mine set up like this. He asked for suggestions on future videos and I thought it might be something that other people would benefit from as well.
@dragonjarl
@dragonjarl 4 ай бұрын
Yes this would be interesting.
@MediaWebservice
@MediaWebservice 3 ай бұрын
​@@user-ek7nq4by7zI agree, great tip 💡
@Vicvines
@Vicvines 4 ай бұрын
Will, I teach older folks about how to stay safe online, and I own a DS 923+ that I want to find a different method of accessing than just typing in the IP address. So this video knocks out 2 problems with 1 stone. Thanks!
@PeterHonig.
@PeterHonig. 4 ай бұрын
The nice thing about Firefox is that you can explicitly tell it to trust a site, and it will no longer bother you with a message. Not so with Chrome and Edge.
@zyghom
@zyghom 4 ай бұрын
you call it "nice" ?
@thku1623
@thku1623 4 ай бұрын
Thanks for all of your explanations. You do it in a professional way and keep it short and simple at the same time. It's amazing. I got myself a DS220+ and find in your Synology-videos a lot of helpful answers - and also helpful questions, that I should ask myself and haven't thought about yet. 😉
@vardagsteknik6576
@vardagsteknik6576 4 ай бұрын
Port 80 is not necesary to use Let's Encrypt. I only use 443 for it to update to Synology and Let's Encrypt. Works great.
@Mad_Snow
@Mad_Snow 4 ай бұрын
I just got a new NAS (had a 215j before), and I'm currently binge-watching your videos! It's amazing what you can pull off with a decent NAS :D Thanks a bunch for sharing your work for free! There's just one thing I couldn't find: how to Paperless NGX and how to set it up in the container manager. I'd love to see a video from you on that!
@niebieski8199
@niebieski8199 4 ай бұрын
bro is on fire posting new content
@SpaceRexWill
@SpaceRexWill 4 ай бұрын
haha dont get too use to it! We only do 2x a week every once in a while!
@65kimmie
@65kimmie Ай бұрын
wow great explanations, and I understood! Thank you!
@twiblr
@twiblr 4 ай бұрын
This video is so good. Thank you!
@zate251
@zate251 4 ай бұрын
Best content on the web.
@smudgetherealmc
@smudgetherealmc 4 ай бұрын
It maybe just me but I have got a LetsEncrypt certificate yet still get the '...Not Private' message when connecting my Mac via a browser - what am I doing wrong?
@Duane_A
@Duane_A 2 ай бұрын
We need a LetsEncrypt tutorial for those of us who have an ISP that blocks port 80. 2 versions...one where we have access to the registrar's API and one where we do not (I think this involves a TXT DNS record, but idk). Since I do not have 20 domains with Namecheap and since I have not spent $50 in the previous 2 years, I would need to add $50 to my account before I could have access to their API (unless I can use their API sandbox to obtain a LE certificate).
@PineapplePi5634
@PineapplePi5634 4 ай бұрын
how about using ACME? i read somewhere that it uses Let's Encrypt as well but without exposing the device to the public.
@kissinuk
@kissinuk 4 ай бұрын
Is there a way of having a custom domain that resolves to the local nas with firewall configured to only allow Let's Encrypt traffic through? I.e without any other external access. This would be with a Synology router so dns server is a possibility.
@randomgaminginfullhd7347
@randomgaminginfullhd7347 4 ай бұрын
Hey I have a question @SpaceRex. I followed your OpenVPN tutorial. I cannot get the hostname of the NAS to be resolved thru DNS since there's no internal DNS configured inside the openvpn config file. How do I get DNS to work thru the OpenVPN? So I can get the shares via \\NAS\Share instead of \\IP\Share?
@SpaceRexWill
@SpaceRexWill 4 ай бұрын
hostnames dont work well over layer3. You can sometimes use a .local DNS server, but its hit or miss
@IanButterworthyyc
@IanButterworthyyc 4 ай бұрын
I tried to set up a certificate using Tailscale (which uses LetsEncrypt) , but so far not working. I think it’s a version issue as the Synology version is old. I’m using that for a remote back up and I’ve disabled the Quick Connect remote access.
@droneforfun5384
@droneforfun5384 4 ай бұрын
Thank you Will. Perhaps you could talk a bit about the problems this can cause, having synology drive all of a sudden stop syncing, which is very annoying.. /from Sweden.
@TSSC
@TSSC 4 ай бұрын
A possible 4th option (DNS forward to a DDNS)? Synology’s KZfaq video “How to Configure HTTPS on Synology NAS Using Let's Encrypt” mentions setting up DDNS in DSM as an alternative to opening port 80. I don’t know much about DNS, but couldn’t a CNAME for the domain I own point to that DDNS? All feedback is welcome.
@TSSC
@TSSC 2 ай бұрын
All feedback is welcome.
@BobSmith-wv7zp
@BobSmith-wv7zp Ай бұрын
i cannot setup a hardware key without port forwarding which I am not inclined to do. Seems like I am adding a vulnerable variable to become more secure. Will Lets Encrypt allow me to create a hardware key because now there is a trusted authority? Thank you
@supernumex
@supernumex 4 ай бұрын
Is it possible to set this up with Tailscale? i.e not see the warning message if you are on the same tailscale vpn?
@SpaceRexWill
@SpaceRexWill 4 ай бұрын
So they have documentation that says you can do this, but i have never done it
@TransformXRED
@TransformXRED 3 ай бұрын
That's one thing which is a bit messy. Or I didn't config things the best way. Setting up a let's encrypt certificate is super easy, and we can use a wild card too. Add that with the reverse proxies, and the synology "dyndns", accessing the nas from "outside" in https without specifying any ports, is cool. But then, accessing it locally, from the n'as ip, it's a bit of a mess (for me) for some reason. 1) we can't use physical keys like a yubikey for the 2fa (it's linked to the synology dyndns address). It's normal but I would like to be able to use my key locally too. I guess it's more complicated than that. 2. Using the synology secure sign in app on the phone doesn't work well If I'm connected on my network with wifi. I have to disable the wifi and be on the cellular network to be able to use the passwordless signing. 3. I can access locally the nas by the dyndns address I have when I use a vpn (I almost always do) because the connection to the nas comes from outside. But then I can use all the security features (2fa) very easily. The yubikey, etc. Is there a way to mix the both worlds? And have all these features available locally. Maybe by setting up a local domain name + a ssl certificate? So at least the yubikey can be used
@DigitalByteBard
@DigitalByteBard 4 ай бұрын
Any chance you can make a video on cloudflare tunnels?
@DavidM2002
@DavidM2002 4 ай бұрын
My Synology is for home use only and is set for HTTP. However, very occasionally, I connect remotely on hotel wifi using Tailscale which I believe encrypts the traffic. Am I likely to be in any danger ? I assume a travel router would add another layer of protection. This was extremely helpful; for some reason my brain could never get around what made cert's secure. Thank you.
@zyghom
@zyghom 4 ай бұрын
if you connected your NAS to Tailscale (only, no other means to connect it to internet) and you are remotely accessing it from another computer connected to THE SAME Tailscale, you are completely safe (no, not you - your NAS ;-)
@DavidM2002
@DavidM2002 4 ай бұрын
@@zyghomThank you.... my NAS thanks you...
@Manuparis
@Manuparis 3 ай бұрын
If I use a quickconnect instead of a domain name. Will my NAs be more or less or equally secured ?
@SpaceRexWill
@SpaceRexWill 3 ай бұрын
Quick connect without port forwarding is more secure than domain name with port forwarding If you have quick connect with port forwarding its the same as domain name with port forwarding
@Manuparis
@Manuparis 3 ай бұрын
@@SpaceRexWill thanks a lot
@dbess1
@dbess1 4 ай бұрын
Please do one on Headscale and Talescale together.
@vviktor0
@vviktor0 Ай бұрын
Can somebody explain and help me with my problem please. I can reach my NAS by: - Local Ip - QuickConnect. But, i cant connect with DDNS. It`s says like it cannot be reached. What can be the problem? In DDNS page it says that status Normal. If somebody can help me with that i would be very grateful.
@SpaceRexWill
@SpaceRexWill Ай бұрын
This will explain it: kzfaq.info/get/bejne/mM5mZNGYtuCpj6M.htmlsi=syOpoErafgnOz1Wn
@vviktor0
@vviktor0 Ай бұрын
@@SpaceRexWill Thank you for your feedback back, I'll try it!😊
@clivewi9103
@clivewi9103 Ай бұрын
Why can't you purchase a SSL certificate and install it on your NAS?
@SpaceRexWill
@SpaceRexWill Ай бұрын
You can!
@clivewiddus3953
@clivewiddus3953 Ай бұрын
@@SpaceRexWill If you can purchase the certificate, why not do so as a solution to the problem, which is not mentioned in the video?
@hassan_ksu
@hassan_ksu 4 ай бұрын
Please do one on Tailscale.
@rhb.digital
@rhb.digital 4 ай бұрын
traefik ftw
@SimplifyBytes
@SimplifyBytes 3 ай бұрын
Nice video. Here is one more video where we explain Man in the Middle attack and generating self signed certificates . SSL/TLS Certificates: Essential Protection Against MITM Attacks 🛡️ | HTTPS Series 3/4 kzfaq.info/get/bejne/qrN3etCatd-pqYU.html
Massive Botnet Attacking Synology - how to protect your NAS
24:42
1 or 2?🐄
00:12
Kan Andrey
Рет қаралды 47 МЛН
THEY made a RAINBOW M&M 🤩😳 LeoNata family #shorts
00:49
LeoNata Family
Рет қаралды 30 МЛН
Who has won ?? 😀 #shortvideo #lizzyisaeva
00:24
Lizzy Isaeva
Рет қаралды 10 МЛН
I Built a NAS: One Year Later. EVERYTHING I Learned and the Mistakes
17:37
Jimmy Tries World
Рет қаралды 810 М.
what is Data Scrubbing (and how to enable on Synology)
17:24
Nick Talks Tech
Рет қаралды 895
SSL/TLS Explained in 7 Minutes
7:38
Sematext
Рет қаралды 25 М.
COMPLETE BEGINNER’S GUIDE for Synology NAS - 2023 DSM 7.2
46:08
What Hard Drives Should you Buy for your Synology NAS?
21:00
SpaceRex
Рет қаралды 145 М.
My Synology NAS was ATTACKED!
8:01
WunderTech
Рет қаралды 43 М.
HTTPS, SSL, TLS & Certificate Authority Explained
43:29
Laith Academy
Рет қаралды 71 М.
STOP using Cloud Storage! Do this instead:
8:44
Liron Segev
Рет қаралды 832 М.
Quick and Easy Local SSL Certificates for Your Homelab!
12:08
Wolfgang's Channel
Рет қаралды 704 М.
Мой инст: denkiselef. Как забрать телефон через экран.
0:54
Hisense Official Flagship Store Hisense is the champion What is going on?
0:11
Special Effects Funny 44
Рет қаралды 2,8 МЛН
Хотела заскамить на Айфон!😱📱(@gertieinar)
0:21
Взрывная История
Рет қаралды 5 МЛН
ИГРОВОВЫЙ НОУТ ASUS ЗА 57 тысяч
25:33
Ремонтяш
Рет қаралды 343 М.