Certificate authority recommendations for QNAP home NAS?

Questions about SNMP, Power, System, Logs, disk, & RAID.
Post Reply
User avatar
glenintenn
Getting the hang of things
Posts: 64
Joined: Sat Dec 01, 2018 9:48 am

Certificate authority recommendations for QNAP home NAS?

Post by glenintenn »

just wondered if anyone has any strong feelings about which certificate authority to use for a QNAP home NAS? With the QLocker advisory floating around, it just makes sense to force HTTPS which in turn means that i need to get a cert.

It seems rather dumb (et. al. pointless?) to just Google around and find the first free cert provider and use one of theirs. I don't need Fort Knox but I do need dead bolts on the doors.

thoughts?
GiT
QNAP TS-231P2-4G
QTS 5.0.1.2276
User avatar
dolbyman
Guru
Posts: 35210
Joined: Sat Feb 12, 2011 2:11 am
Location: Vancouver BC , Canada

Re: Certificate authority recommendations for QNAP home NAS?

Post by dolbyman »

https will provide exactly no protection against those attacks..so unclear why it would matter
User avatar
jaysona
Been there, done that
Posts: 854
Joined: Tue Dec 02, 2008 11:26 am
Location: Somewhere in the Great White North

Re: Certificate authority recommendations for QNAP home NAS?

Post by jaysona »

glenintenn wrote: Fri Apr 23, 2021 10:23 pm just wondered if anyone has any strong feelings about which certificate authority to use for a QNAP home NAS? With the QLocker advisory floating around, it just makes sense to force HTTPS which in turn means that i need to get a cert.

It seems rather dumb (et. al. pointless?) to just Google around and find the first free cert provider and use one of theirs. I don't need Fort Knox but I do need dead bolts on the doors.

thoughts?
Using a TLS certificate and HTTPS will secure the communication session between the web browser (your computer in this case) and the web server (NAS in this case). A TLS certificate will not protect the NAS from being attacked by malware, the malware will just try to connect to the NAS using port 443 instead of port 8080, but it will still be able to connect to the NAS.

At the end of the day, making a NAS accessible from the Internet either via port 443 or port 8080 will result in an eventually comprised NAS.

Apparently, this can not be stated often enough........

viewtopic.php?f=45&t=160849&start=45#p786872
RAID is not a Back-up!

H/W: QNAP TVS-871 (i7-4790. 16GB) (Plex server) / TVS-EC1080 (32Gig ECC) - VM host & seedbox
H/W: Asustor AS6604T (8GB) / Asustor AS7010T (16GB) (media storage)
H/W: TS-219 Pro / TS-509 Pro
O/S: Slackware 14.2 / MS Windows 7-64 (x5)
Router1: Asus RT-AC86U - Asuswrt-Merlin - 386.7_2
Router2: Asus RT-AC68U - Asuswrt-Merlin - 386.7_2
Router3: Linksys WRT1900AC - DD-WRT v3.0-r46816 std
Router4: Asus RT-AC66U - FreshTomato v2021.10.15

Misc: Popcorn Hour A-110/WN-100, Pinnacle Show Center 250HD, Roku SoundBridge Radio (all retired)
Ditched QNAP units: TS-269 Pro / TS-253 Pro (8GB) / TS-509 Pro / TS-569 Pro / TS-853 Pro (8GB)
TS-670 Pro x2 (i7-3770s 16GB) / TS-870 Pro (i7-3770 16GB) / TVS-871 (i7-4790s 16GB)
User avatar
glenintenn
Getting the hang of things
Posts: 64
Joined: Sat Dec 01, 2018 9:48 am

Re: Certificate authority recommendations for QNAP home NAS?

Post by glenintenn »

OK. In my newb reading the QNAP bulletin https://www.qnap.com/en/how-to/faq/arti ... s-security, mentions changing ports and my simple mind was thinking one port was better than two and if I was going to have one port it would be https and have a proper certificate on it...

Probably too much ZDNet reading?
GiT
QNAP TS-231P2-4G
QTS 5.0.1.2276
User avatar
glenintenn
Getting the hang of things
Posts: 64
Joined: Sat Dec 01, 2018 9:48 am

Re: Certificate authority recommendations for QNAP home NAS?

Post by glenintenn »

My system is not exposed on the internet. This was just thinking about minimal hardening (which I've not done). The bulletin pinned on this forum mentioned this as one bullet (it also indicates not using port 443). To the points above, it's not directly related... it's just a best practice overall.
GiT
QNAP TS-231P2-4G
QTS 5.0.1.2276
User avatar
dolbyman
Guru
Posts: 35210
Joined: Sat Feb 12, 2011 2:11 am
Location: Vancouver BC , Canada

Re: Certificate authority recommendations for QNAP home NAS?

Post by dolbyman »

https in your private LAN is a hassle just because you need to work with FQDN for them to be valid, NASNAME or IPadress will result in warnings
User avatar
jaysona
Been there, done that
Posts: 854
Joined: Tue Dec 02, 2008 11:26 am
Location: Somewhere in the Great White North

Re: Certificate authority recommendations for QNAP home NAS?

Post by jaysona »

glenintenn wrote: Fri Apr 23, 2021 10:49 pm OK. In my newb reading the QNAP bulletin https://www.qnap.com/en/how-to/faq/arti ... s-security, mentions changing ports and my simple mind was thinking one port was better than two and if I was going to have one port it would be https and have a proper certificate on it...

Probably too much ZDNet reading?
*ugh* That is a never ending battle and apparent losing battle. No security person (worth the salt in their hash) will ever advise the practice of Security by Obscurity, because once the obscurity is removed, there is no security. Changing port numbers just looks good optically, but in reality it provides a minor delay in having the NAS discovered on-line.

More than two years ago, just for shiggles, I decided to place one of my NASes on-line and I rotated the ports being used, I used ports such as 32982, 47651, 61478, etc and in all cases the NAS was discovered by some bot within a matter of weeks to a few months. With the proliferation of 10 and 100 gigabit VPSes available for rent by the minute, Internet address space scanning today is stupidly simple, ridiculously fast and cheap to perform.

There's no such thing as too much reading - ZDNet or otherwise, but you do need to step back, process what you have read, give it some deeper thought and consideration, instead of just taking everything at face value.
RAID is not a Back-up!

H/W: QNAP TVS-871 (i7-4790. 16GB) (Plex server) / TVS-EC1080 (32Gig ECC) - VM host & seedbox
H/W: Asustor AS6604T (8GB) / Asustor AS7010T (16GB) (media storage)
H/W: TS-219 Pro / TS-509 Pro
O/S: Slackware 14.2 / MS Windows 7-64 (x5)
Router1: Asus RT-AC86U - Asuswrt-Merlin - 386.7_2
Router2: Asus RT-AC68U - Asuswrt-Merlin - 386.7_2
Router3: Linksys WRT1900AC - DD-WRT v3.0-r46816 std
Router4: Asus RT-AC66U - FreshTomato v2021.10.15

Misc: Popcorn Hour A-110/WN-100, Pinnacle Show Center 250HD, Roku SoundBridge Radio (all retired)
Ditched QNAP units: TS-269 Pro / TS-253 Pro (8GB) / TS-509 Pro / TS-569 Pro / TS-853 Pro (8GB)
TS-670 Pro x2 (i7-3770s 16GB) / TS-870 Pro (i7-3770 16GB) / TVS-871 (i7-4790s 16GB)
User avatar
glenintenn
Getting the hang of things
Posts: 64
Joined: Sat Dec 01, 2018 9:48 am

Re: Certificate authority recommendations for QNAP home NAS?

Post by glenintenn »

jaysona wrote: Fri Apr 23, 2021 11:18 pm
More than two years ago, just for shiggles, I decided to place one of my NASes on-line and I rotated the ports being used, I used ports such as 32982, 47651, 61478, etc and in all cases the NAS was discovered by some bot within a matter of weeks to a few months. With the proliferation of 10 and 100 gigabit VPSes available for rent by the minute, Internet address space scanning today is stupidly simple, ridiculously fast and cheap to perform.

There's no such thing as too much reading - ZDNet or otherwise, but you do need to step back, process what you have read, give it some deeper thought and consideration, instead of just taking everything at face value.
Fair point about reading but until real results like you posted are known, it's not always evident what is journalistic overreach to sell eyeballs on e-mags and what is actually true.
GiT
QNAP TS-231P2-4G
QTS 5.0.1.2276
Post Reply

Return to “System & Disk Volume Management”