Certificate

Don't miss a thing. Post your questions and discussion about other uncategorized NAS features here.

Certificate

Postby bugyou2 » Tue Mar 13, 2012 11:46 pm

What is a certificate for? Can I use Qnap https without certificate?
bugyou2
Know my way around
 
Posts: 113
Joined: Wed Dec 28, 2011 10:01 pm
NAS Model: Not Selected

Re: Certificate

Postby schumaku » Wed Mar 14, 2012 4:41 am

bugyou2 wrote:What is a certificate for?
Far to much to explaian in a few words - start here: http://en.wikipedia.org/wiki/Secure_Soc ... escription

bugyou2 wrote:Can I use Qnap https without certificate?
Without? No. With the default certificate (and private key): Yes ... however pleae understand the private key is well known and distributed with all QNAP NAS firmware. So in therory - anybody able to capture the SSL/TLS data stream from a client to the NAS, would be able to decode it.
User avatar
schumaku
Guru
 
Posts: 22317
Joined: Mon Jan 21, 2008 4:41 pm
Location: Kloten (Zurich), Switzerland -- Skype: schumaku
NAS Model: TS-x79 Pro

Re: Certificate

Postby bugyou2 » Thu Mar 15, 2012 12:27 am

schumaku wrote:
bugyou2 wrote:What is a certificate for?
Far to much to explaian in a few words - start here: http://en.wikipedia.org/wiki/Secure_Soc ... escription

bugyou2 wrote:Can I use Qnap https without certificate?
Without? No. With the default certificate (and private key): Yes ... however pleae understand the private key is well known and distributed with all QNAP NAS firmware. So in therory - anybody able to capture the SSL/TLS data stream from a client to the NAS, would be able to decode it.


Thank you! But how come I get this from firefox and then when I click on I understand the risks -> add exception -> confirm security exception I can get thru my Qnap. Does it really work this way with the default certificate you were talking about?
You do not have the required permissions to view the files attached to this post.
bugyou2
Know my way around
 
Posts: 113
Joined: Wed Dec 28, 2011 10:01 pm
NAS Model: Not Selected

Re: Certificate

Postby schumaku » Thu Mar 15, 2012 7:03 pm

bugyou2 wrote: Does it really work this way with the default certificate you were talking about?
Yes. Once you have a fixed hostname (rep. a fully qualified one), I sugest you are start to look-out for a free or commecrial security cetificate.
User avatar
schumaku
Guru
 
Posts: 22317
Joined: Mon Jan 21, 2008 4:41 pm
Location: Kloten (Zurich), Switzerland -- Skype: schumaku
NAS Model: TS-x79 Pro

Re: Certificate

Postby tmt » Thu Mar 15, 2012 8:39 pm

Actually, the cause of this isn't the hostname, it's the chain of trust. Because of the way the default NAS certificate is self-signed, it doesn't have a CA (certifying authority). And because there's no CA, there is no way for the browser to trust it.

It is possible to create a self-signed cert that does have a CA, and then such a CA cert could be stored by the browser and it wouldn't squawk. But that's a bit of a challenge to set up, so unless you want to turn off this warning altogether, I agree the safest and best approach is to obtain a proper cert.
SS-439, Ubuntu Server 12.04.2 LTS, EXT4, RAID10, 4xHitachi 5K1000
TS-112, 3.7.3 20120801, EXT4, 1xHitachi 7K1000
tmt
Been there, done that
 
Posts: 977
Joined: Mon Nov 16, 2009 11:02 am
NAS Model: SS-439 Pro

Re: Certificate

Postby bugyou2 » Thu Mar 15, 2012 11:53 pm

Thanks for the replies. But is it still ok to access Qnap https without a certificate?
bugyou2
Know my way around
 
Posts: 113
Joined: Wed Dec 28, 2011 10:01 pm
NAS Model: Not Selected

Re: Certificate

Postby tmt » Fri Mar 16, 2012 2:49 am

Sure, as long as you're aware that the encryption you obtain from the default QNAP certificate is not completely private. However, it would still take a rather sophisticated attacker to exploit this.

Depending on how concerned you are about this, and how technical you may be, there's a QNAP wiki page describing how to generate your own certificate. It's still self-signed, and therefore not universally trusted by browsers, but it does generate a new non-shared private key of your chosen length. The wiki is here: http://wiki.qnap.com/wiki/Use_OpenSSL_t ... connection
SS-439, Ubuntu Server 12.04.2 LTS, EXT4, RAID10, 4xHitachi 5K1000
TS-112, 3.7.3 20120801, EXT4, 1xHitachi 7K1000
tmt
Been there, done that
 
Posts: 977
Joined: Mon Nov 16, 2009 11:02 am
NAS Model: SS-439 Pro


Return to Miscellaneous

Who is online

Users browsing this forum: No registered users and 3 guests