Cannot access QTS due to invalid certificate

Don't miss a thing. Post your questions and discussion about other uncategorized NAS features here.
Post Reply
ParaDice
Starting out
Posts: 15
Joined: Sat Dec 02, 2017 2:55 am

Cannot access QTS due to invalid certificate

Post by ParaDice » Fri Oct 12, 2018 12:13 am

Hey there,

I have recently installed the new update to QTS 4.3.5 on my TS-251A. Now I cannot access the QTS web interface anymore. Whenever I try to (using HTTPS and the static LAN IP of the NAS), my browser tells me that the certificate is invalid. Although the browser offers to "continue" regardless of whether the certificate is valid or not, it cannot get through. I suppose it is trying to connect to the NAS without SSL, which I have forbidden in the very settings I now cannot access.

The error is both unnerving and confusing because
  • everything used to work fine up until the update, so I suppose it _may_ have broken something
  • I have tried every conceivable way to access QTS: browser + local IP fails, browser + URL fails (access from the internet), access through QManager (mobile app) fails, access through HDStation fails, and SSH is disabled.
  • the certificate is valid: I have just received the usual Let's Encrypt expiry bot e-mail, warning that the certificate will expire in 30 days

If anyone has an idea how I can regain control of my NAS, any hint would be much appreciated.
Last edited by ParaDice on Fri Oct 12, 2018 12:26 am, edited 1 time in total.

dolbyman
Guru
Posts: 11032
Joined: Sat Feb 12, 2011 2:11 am
Location: Vancouver BC , Canada

Re: Cannot access QTS due to invalid certificate

Post by dolbyman » Fri Oct 12, 2018 12:16 am

try a different browser, you will never get a valid certificate for an IP (only for FQDN) ..also enabling SSL certificates but then disabling https makes not that much sense .. does it ?

ParaDice
Starting out
Posts: 15
Joined: Sat Dec 02, 2017 2:55 am

Re: Cannot access QTS due to invalid certificate

Post by ParaDice » Fri Oct 12, 2018 12:25 am

Hi, and thanks for the speedy reply! :)

dolbyman wrote:try a different browser, you will never get a valid certificate for an IP (only for FQDN)


True, but I have added a security exception for that and it has worked ever since. Now it doesn't and I don't get why.
I have tried all major ones (Firefox, Chrome, Opera), same result on every single one of them.
What is the appropriate way to access QTS locally, if not via its IP?

also enabling SSL certificates but then disabling https makes not that much sense .. does it ?


I didn't write that. I have enabled enforced SSL access, i.e. requests _must_ be made via SSL.

dolbyman
Guru
Posts: 11032
Joined: Sat Feb 12, 2011 2:11 am
Location: Vancouver BC , Canada

Re: Cannot access QTS due to invalid certificate

Post by dolbyman » Fri Oct 12, 2018 12:41 am

ParaDice wrote:True, but I have added a security exception for that and it has worked ever since. Now it doesn't and I don't get why.
I have tried all major ones (Firefox, Chrome, Opera), same result on every single one of them.
What is the appropriate way to access QTS locally, if not via its IP?


local IP should be fine .. and adding an exception should work .. check if your virus scanner (like bitdefender) is trying to fiddle with it
there is a couple of threads that report issues with bitdefender and invalid certificates
viewtopic.php?f=11&t=143526


ParaDice wrote:I didn't write that. I have enabled enforced SSL access, i.e. requests _must_ be made via SSL.


Original post was edited .. so maybe you chose your wording sub optimal

ParaDice
Starting out
Posts: 15
Joined: Sat Dec 02, 2017 2:55 am

Re: Cannot access QTS due to invalid certificate

Post by ParaDice » Fri Oct 12, 2018 12:47 am

I'm typically on a Linux system, i.e. there's no AV and not firewall getting in the way of things (the former isn't installed, that latter is disabled). The problem persists on all devices I own, including my mobile and a remaining windows machine I run on the side. So I can rule that out as the source of the problem.

The original posting was edited to fix a typo, nothing else.

dolbyman
Guru
Posts: 11032
Joined: Sat Feb 12, 2011 2:11 am
Location: Vancouver BC , Canada

Re: Cannot access QTS due to invalid certificate

Post by dolbyman » Fri Oct 12, 2018 2:24 am

hmm... can you login via SSH and see what processes are running ?

ParaDice
Starting out
Posts: 15
Joined: Sat Dec 02, 2017 2:55 am

Re: Cannot access QTS due to invalid certificate

Post by ParaDice » Fri Oct 12, 2018 4:10 am

Good idea, but as I wrote, SSH is disabled. :-/

dolbyman
Guru
Posts: 11032
Joined: Sat Feb 12, 2011 2:11 am
Location: Vancouver BC , Canada

Re: Cannot access QTS due to invalid certificate

Post by dolbyman » Fri Oct 12, 2018 4:20 am

sorry missed that part .. a 3 second reset should enable SSD again

ParaDice
Starting out
Posts: 15
Joined: Sat Dec 02, 2017 2:55 am

Re: Cannot access QTS due to invalid certificate

Post by ParaDice » Fri Oct 12, 2018 4:45 am

dolbyman wrote:a 3 second reset should enable SSD again


Does "3 second reset" mean pressing the power button for 3 seconds? And I take it you meant "SSH"?

dolbyman
Guru
Posts: 11032
Joined: Sat Feb 12, 2011 2:11 am
Location: Vancouver BC , Canada

Re: Cannot access QTS due to invalid certificate

Post by dolbyman » Fri Oct 12, 2018 5:17 am

Sorry typo .. yes SSH

3 second reset is done with the little recessed button in the back

https://www.qnap.com/en/how-to/knowledg ... explained/

I think 3 seconds is enough 10 seconds definitely re enables it but also kills all settings (does not delete data)

ParaDice
Starting out
Posts: 15
Joined: Sat Dec 02, 2017 2:55 am

Re: Cannot access QTS due to invalid certificate

Post by ParaDice » Fri Oct 12, 2018 11:38 pm

Hey there dolbyman,

Yay, that worked! After a 3-second-reset, I am now able to log back in (at the price of having to restore the old settings, but that'll be done in a jiffy).

From the system logs, I gather that the QTS 4.3.5 update claims to have "fixed errors" in my network configuration. In fact, it seems to have done the very opposite and ruined a perfectly solid configuration.

Thank you ever so much for pointing me towards the reset! I didn't know that option yet, but I'll keep it in mind for when the next update borks up my config again. :lol:

Best wishes,
ParaDice.

dolbyman
Guru
Posts: 11032
Joined: Sat Feb 12, 2011 2:11 am
Location: Vancouver BC , Canada

Re: Cannot access QTS due to invalid certificate

Post by dolbyman » Fri Oct 12, 2018 11:40 pm

glad you got it working again

Post Reply

Return to “Miscellaneous”