Why Synology Says "This Connection is Not Private" - (How SSL Encryption Works)

  Рет қаралды 16,540

SpaceRex

SpaceRex

Күн бұрын

You've gone through a tutorial to secure your Synology NAS, but you are still getting a message that says the webpage is not secure. In this video, I will be walking through why this message appears, if you should actually be concerned, and how to prevent it.
Hire Me! yarboroughtechnologies.com/co...
Post on the Forums! forums.spacerex.co/
Links mentioned:
Let's Encrypt: letsencrypt.org
Synology Recommendations*:
Hard drives I recommend: amzn.to/3RA3udS
Starter NAS with BTRFS: amzn.to/46hrRS7
Great all around NAS with BTRFS: amzn.to/46egNVP
More powerful NAS with BTRFS (great for larger/mid sized businesses): amzn.to/3YwRziM
#nas #synology
TOC:
00:00 Introduction
02:44 How SSL (TLS) Encryption works
09:58 Why certificate fails on Synology
11:53 How to remove "not secure" message
13:45 Option 1: QuickConnect
16:04 Option 2: Let's Encrypt
20:05 Option 3: Generate your own certificate authority
20:37 Conclusion
*These are affiliate links, which means that if you purchase a product through one of them, I will receive a small commission (at no additional cost to you). Thank you for supporting my channel!

Пікірлер: 53
@PeterHonig.
@PeterHonig. 4 ай бұрын
The nice thing about Firefox is that you can explicitly tell it to trust a site, and it will no longer bother you with a message. Not so with Chrome and Edge.
@zyghom
@zyghom 4 ай бұрын
you call it "nice" ?
@user-ek7nq4by7z
@user-ek7nq4by7z 4 ай бұрын
On the topic of security: You should make a video on setting up a VLAN on a Unifi Controller for Surveillance Station to isolate the security cameras from the rest of the network and block the cameras from accessing the internet, yet still allowing remote access to Surveillance Station. You could also cover the importance of isolating IoT devices to mitigate risk of someone accessing your NAS and other devices through weak security that some IoT devices possess.
@droneforfun5384
@droneforfun5384 4 ай бұрын
This video from Rex would be very much appreciated. I hope he got the Will to do it.
@zate251
@zate251 4 ай бұрын
Yes
@user-ek7nq4by7z
@user-ek7nq4by7z 4 ай бұрын
@@djderekrock I already have mine set up like this. He asked for suggestions on future videos and I thought it might be something that other people would benefit from as well.
@dragonjarl
@dragonjarl 4 ай бұрын
Yes this would be interesting.
@MediaWebservice
@MediaWebservice 3 ай бұрын
​@@user-ek7nq4by7zI agree, great tip 💡
@Vicvines
@Vicvines 4 ай бұрын
Will, I teach older folks about how to stay safe online, and I own a DS 923+ that I want to find a different method of accessing than just typing in the IP address. So this video knocks out 2 problems with 1 stone. Thanks!
@vardagsteknik6576
@vardagsteknik6576 4 ай бұрын
Port 80 is not necesary to use Let's Encrypt. I only use 443 for it to update to Synology and Let's Encrypt. Works great.
@niebieski8199
@niebieski8199 4 ай бұрын
bro is on fire posting new content
@SpaceRexWill
@SpaceRexWill 4 ай бұрын
haha dont get too use to it! We only do 2x a week every once in a while!
@thku1623
@thku1623 4 ай бұрын
Thanks for all of your explanations. You do it in a professional way and keep it short and simple at the same time. It's amazing. I got myself a DS220+ and find in your Synology-videos a lot of helpful answers - and also helpful questions, that I should ask myself and haven't thought about yet. 😉
@Mad_Snow
@Mad_Snow 4 ай бұрын
I just got a new NAS (had a 215j before), and I'm currently binge-watching your videos! It's amazing what you can pull off with a decent NAS :D Thanks a bunch for sharing your work for free! There's just one thing I couldn't find: how to Paperless NGX and how to set it up in the container manager. I'd love to see a video from you on that!
@twiblr
@twiblr 4 ай бұрын
This video is so good. Thank you!
@65kimmie
@65kimmie Ай бұрын
wow great explanations, and I understood! Thank you!
@zate251
@zate251 4 ай бұрын
Best content on the web.
@Duane_A
@Duane_A 2 ай бұрын
We need a LetsEncrypt tutorial for those of us who have an ISP that blocks port 80. 2 versions...one where we have access to the registrar's API and one where we do not (I think this involves a TXT DNS record, but idk). Since I do not have 20 domains with Namecheap and since I have not spent $50 in the previous 2 years, I would need to add $50 to my account before I could have access to their API (unless I can use their API sandbox to obtain a LE certificate).
@smudgetherealmc
@smudgetherealmc 4 ай бұрын
It maybe just me but I have got a LetsEncrypt certificate yet still get the '...Not Private' message when connecting my Mac via a browser - what am I doing wrong?
@droneforfun5384
@droneforfun5384 4 ай бұрын
Thank you Will. Perhaps you could talk a bit about the problems this can cause, having synology drive all of a sudden stop syncing, which is very annoying.. /from Sweden.
@TransformXRED
@TransformXRED 4 ай бұрын
That's one thing which is a bit messy. Or I didn't config things the best way. Setting up a let's encrypt certificate is super easy, and we can use a wild card too. Add that with the reverse proxies, and the synology "dyndns", accessing the nas from "outside" in https without specifying any ports, is cool. But then, accessing it locally, from the n'as ip, it's a bit of a mess (for me) for some reason. 1) we can't use physical keys like a yubikey for the 2fa (it's linked to the synology dyndns address). It's normal but I would like to be able to use my key locally too. I guess it's more complicated than that. 2. Using the synology secure sign in app on the phone doesn't work well If I'm connected on my network with wifi. I have to disable the wifi and be on the cellular network to be able to use the passwordless signing. 3. I can access locally the nas by the dyndns address I have when I use a vpn (I almost always do) because the connection to the nas comes from outside. But then I can use all the security features (2fa) very easily. The yubikey, etc. Is there a way to mix the both worlds? And have all these features available locally. Maybe by setting up a local domain name + a ssl certificate? So at least the yubikey can be used
@dbess1
@dbess1 4 ай бұрын
Please do one on Headscale and Talescale together.
@PineapplePi5634
@PineapplePi5634 4 ай бұрын
how about using ACME? i read somewhere that it uses Let's Encrypt as well but without exposing the device to the public.
@kissinuk
@kissinuk 4 ай бұрын
Is there a way of having a custom domain that resolves to the local nas with firewall configured to only allow Let's Encrypt traffic through? I.e without any other external access. This would be with a Synology router so dns server is a possibility.
@IanButterworthyyc
@IanButterworthyyc 4 ай бұрын
I tried to set up a certificate using Tailscale (which uses LetsEncrypt) , but so far not working. I think it’s a version issue as the Synology version is old. I’m using that for a remote back up and I’ve disabled the Quick Connect remote access.
@TSSC
@TSSC 4 ай бұрын
A possible 4th option (DNS forward to a DDNS)? Synology’s KZbin video “How to Configure HTTPS on Synology NAS Using Let's Encrypt” mentions setting up DDNS in DSM as an alternative to opening port 80. I don’t know much about DNS, but couldn’t a CNAME for the domain I own point to that DDNS? All feedback is welcome.
@TSSC
@TSSC 2 ай бұрын
All feedback is welcome.
@DigitalByteBard
@DigitalByteBard 4 ай бұрын
Any chance you can make a video on cloudflare tunnels?
@BobSmith-wv7zp
@BobSmith-wv7zp Ай бұрын
i cannot setup a hardware key without port forwarding which I am not inclined to do. Seems like I am adding a vulnerable variable to become more secure. Will Lets Encrypt allow me to create a hardware key because now there is a trusted authority? Thank you
@DavidM2002
@DavidM2002 4 ай бұрын
My Synology is for home use only and is set for HTTP. However, very occasionally, I connect remotely on hotel wifi using Tailscale which I believe encrypts the traffic. Am I likely to be in any danger ? I assume a travel router would add another layer of protection. This was extremely helpful; for some reason my brain could never get around what made cert's secure. Thank you.
@zyghom
@zyghom 4 ай бұрын
if you connected your NAS to Tailscale (only, no other means to connect it to internet) and you are remotely accessing it from another computer connected to THE SAME Tailscale, you are completely safe (no, not you - your NAS ;-)
@DavidM2002
@DavidM2002 4 ай бұрын
@@zyghomThank you.... my NAS thanks you...
@randomgaminginfullhd7347
@randomgaminginfullhd7347 4 ай бұрын
Hey I have a question @SpaceRex. I followed your OpenVPN tutorial. I cannot get the hostname of the NAS to be resolved thru DNS since there's no internal DNS configured inside the openvpn config file. How do I get DNS to work thru the OpenVPN? So I can get the shares via \\NAS\Share instead of \\IP\Share?
@SpaceRexWill
@SpaceRexWill 4 ай бұрын
hostnames dont work well over layer3. You can sometimes use a .local DNS server, but its hit or miss
@supernumex
@supernumex 4 ай бұрын
Is it possible to set this up with Tailscale? i.e not see the warning message if you are on the same tailscale vpn?
@SpaceRexWill
@SpaceRexWill 4 ай бұрын
So they have documentation that says you can do this, but i have never done it
@Manuparis
@Manuparis 3 ай бұрын
If I use a quickconnect instead of a domain name. Will my NAs be more or less or equally secured ?
@SpaceRexWill
@SpaceRexWill 3 ай бұрын
Quick connect without port forwarding is more secure than domain name with port forwarding If you have quick connect with port forwarding its the same as domain name with port forwarding
@Manuparis
@Manuparis 3 ай бұрын
@@SpaceRexWill thanks a lot
@hassan_ksu
@hassan_ksu 4 ай бұрын
Please do one on Tailscale.
@rhb.digital
@rhb.digital 4 ай бұрын
traefik ftw
@vviktor0
@vviktor0 Ай бұрын
Can somebody explain and help me with my problem please. I can reach my NAS by: - Local Ip - QuickConnect. But, i cant connect with DDNS. It`s says like it cannot be reached. What can be the problem? In DDNS page it says that status Normal. If somebody can help me with that i would be very grateful.
@SpaceRexWill
@SpaceRexWill Ай бұрын
This will explain it: kzbin.info/www/bejne/mJmZYqGdht94ldEsi=syOpoErafgnOz1Wn
@vviktor0
@vviktor0 Ай бұрын
@@SpaceRexWill Thank you for your feedback back, I'll try it!😊
@clivewi9103
@clivewi9103 Ай бұрын
Why can't you purchase a SSL certificate and install it on your NAS?
@SpaceRexWill
@SpaceRexWill Ай бұрын
You can!
@clivewiddus3953
@clivewiddus3953 Ай бұрын
@@SpaceRexWill If you can purchase the certificate, why not do so as a solution to the problem, which is not mentioned in the video?
@SimplifyBytes
@SimplifyBytes 4 ай бұрын
Nice video. Here is one more video where we explain Man in the Middle attack and generating self signed certificates . SSL/TLS Certificates: Essential Protection Against MITM Attacks 🛡️ | HTTPS Series 3/4 kzbin.info/www/bejne/qn6qeKCfhd54r7M
EVERY Synology Feature Explained
36:09
SpaceRex
Рет қаралды 69 М.
Best father #shorts by Secret Vlog
00:18
Secret Vlog
Рет қаралды 21 МЛН
Vivaan  Tanya once again pranked Papa 🤣😇🤣
00:10
seema lamba
Рет қаралды 36 МЛН
KINDNESS ALWAYS COME BACK
00:59
dednahype
Рет қаралды 148 МЛН
3M❤️ #thankyou #shorts
00:16
ウエスP -Mr Uekusa- Wes-P
Рет қаралды 15 МЛН
Simple Synology Settings EVERYONE should be using (Basics)
23:28
Stop Buying WD NAS Drives.
11:58
SpaceRex
Рет қаралды 390 М.
what is Synology Snapshot (and how to enable it)
17:00
Nick Talks Tech
Рет қаралды 385
Quick and Easy Local SSL Certificates for Your Homelab!
12:08
Wolfgang's Channel
Рет қаралды 711 М.
is Quick Connect Secure for Synology?
14:28
SpaceRex
Рет қаралды 48 М.
Should You Use SSDs For Your NAS?
15:22
SpaceRex
Рет қаралды 198 М.
Settings EVERY Synology NAS should have in 2024 - DSM 7.2
18:50
HTTPS, SSL, TLS & Certificate Authority Explained
43:29
Laith Academy
Рет қаралды 75 М.
7 Synology Apps YOU NEED TO USE in 2023
10:34
WunderTech
Рет қаралды 91 М.
I Built a NAS: One Year Later. EVERYTHING I Learned and the Mistakes
17:37
Jimmy Tries World
Рет қаралды 817 М.
Cheapest gaming phone? 🤭 #miniphone #smartphone #iphone #fy
0:19
Pockify™
Рет қаралды 2,2 МЛН
Хотела заскамить на Айфон!😱📱(@gertieinar)
0:21
Взрывная История
Рет қаралды 6 МЛН
Отдых для геймера? 😮‍💨 Hiper Engine B50
1:00