18 - (3/3) Let's Encrypt certificate renewal on Synology test (Tutorial new method, Security)

preview_player
Показать описание
Hi guys,

As requested by a Synology community user, I have made another test of renewing the certificate without the required incoming opened ports.
Only outgoing traffic with UDP 53 (DNS) and TCP 443 (HTTPS) are necessary. Not port forwarding, no UPnP are necessary.
Please bare with me as i had this video "live". I wasn't able to perfect the content as the renewal process is limited in time and numbers.

Unfortunately i have made a small mistake while trying to intercept the HTTPS traffic. I knew it was not the correct way, but i forget.

Anyway, i tried to intercept the traffic correctly after the video, on my UTM device (proxy) but Synology will not allow to be presented with an untrusted certificate (so no MiTM attacks possible here) during the renewal process.

As it is from the USA, it couldn't initiate a connection to me as i am blocking traffic being initiated from another country than mine.
That said, the renewal works perfectly without having to allow any kind of incoming traffic.
Рекомендации по теме