Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
syno:dsm7inst [2026/08/22 19:42] – [KMIP for key management] Bernard Condrausyno:dsm7inst [2026/08/22 19:44] (current) – [KMIP for key management] Bernard Condrau
Line 8: Line 8:
 ===== KMIP for key management ===== ===== KMIP for key management =====
   * Follow the guide to install [[https://kb.synology.com/en-global/DSM/help/DSM/AdminCenter/connection_security_kmip?version=7|KMIP]] on a Synology NAS server and client   * Follow the guide to install [[https://kb.synology.com/en-global/DSM/help/DSM/AdminCenter/connection_security_kmip?version=7|KMIP]] on a Synology NAS server and client
-  * What this guide does not mention is how to generate working certificates for DSM 7.4 and later, which hardened the certificate requirements. You will generate matching certificates from an official Synology script, which will be installed alongside the default certificates, and are valid for 10 years.+  * What this guide does not mention is how to generate working certificates for DSM 7.4 and later, which hardened the certificate requirements. You will generate matching certificates from an official Synology script, which will be installed alongside the default certificates, and are valid for 10 years. These certificates also work for Synology clients, when added to a [[deb13:kmip_server_pykmip|KMIP Server (PyKMIP)]] not hosted on a synology NAS.
     - The default, out-of-the-box self-signed Synology certificate will fail on DSM 7.4     - The default, out-of-the-box self-signed Synology certificate will fail on DSM 7.4
     - Login to your NAS on the command line with SSH and elevate to root     - Login to your NAS on the command line with SSH and elevate to root