How to fix Let's Encrypt / acme.sh renewal on Synology
I use a Let's Encrypt certificate so Synology Photos can connect to my NAS over HTTPS without a certificate warning. I renew it with acme.sh using a DNS challenge.
When the certificate expired, Photos stopped syncing and renewal failed with:
curl: (60) SSL certificate problem: certificate has expired
The error made it look like acme.sh didn't trust a certificate authority. The actual problem was that the DNS-over-HTTPS (DoH) request was reaching my NAS instead of Cloudflare.
Finding the wrong certificate
During DNS validation, the renewal script queried cloudflare-dns.com and dns.google over DNS-over-HTTPS. I checked the certificate returned for Cloudflare:
openssl s_client \ -connect cloudflare-dns.com:443 \ -servername cloudflare-dns.com \ -showcerts </dev/null 2>/dev/null | openssl x509 -noout -subject -issuer -dates
The subject was my NAS's hostname. A local lookup showed that cloudflare-dns.com resolved to 0.0.0.0 and :::
nslookup cloudflare-dns.com
My router uses a NextDNS profile with Block Bypass Methods enabled. It was blocking the DNS-over-HTTPS providers and returning those addresses. The connection went back to the NAS, which presented its expired certificate. That's why curl complained about an expired certificate while acme.sh was trying to contact Cloudflare.
I checked the same name using Cloudflare's resolver directly:
nslookup cloudflare-dns.com 1.1.1.1
That returned the expected address. I added cloudflare-dns.com and dns.google to the NextDNS allowlist.
Clearing the failed challenge and renewing
The first attempt had created the ACME DNS TXT record before it failed. After allowing the DNS-over-HTTPS providers, the next attempt stopped with Cloudflare error 81058 because that TXT record already existed. I deleted the stale _acme-challenge record from Cloudflare, checked that it was gone, and ran the renewal again. I also upgraded acme.sh from 3.0.9 to 3.1.5. The script deployed the new certificate into DSM with sudo.
The fix for this error was the NextDNS allowlist. The certificate subject gave away the real problem: I was seeing my NAS's certificate in a connection that should have gone to Cloudflare.
Separately: adding CA roots to DSM
I also updated DSM's CA roots, but that was separate maintenance, not the fix above. On DSM 7, custom root certificates go in this directory as .crt files:
/usr/syno/etc/security-profile/ca-bundle-profile/ca-certificates/
With SSH enabled, I copied the current ISRG Root X1 and X2 certificates from Let's Encrypt into that directory and rebuilt DSM's trust bundle:
sudo mkdir -p /usr/syno/etc/security-profile/ca-bundle-profile/ca-certificates sudo cp isrgrootx1.pem /usr/syno/etc/security-profile/ca-bundle-profile/ca-certificates/isrg-root-x1.crt sudo cp isrg-root-x2.pem /usr/syno/etc/security-profile/ca-bundle-profile/ca-certificates/isrg-root-x2.crt sudo chmod 644 /usr/syno/etc/security-profile/ca-bundle-profile/ca-certificates/*.crt sudo /usr/syno/bin/update-ca-certificates.sh
This updates roots DSM uses to verify certificates from other services. It doesn't change the certificate DSM presents to Photos clients; that is managed under Control Panel → Security → Certificate. Synology's certificate guide covers that separate step.
Comments