Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
syno:dsm7inst [2026/09/02 15:46] – [Setup rescue login] Bernard Condrausyno:dsm7inst [2026/10/01 12:47] (current) – [Check MailPlus Server connectivity] Bernard Condrau
Line 11: Line 11:
   * How to setup a [[deb13:kmip_server_pykmip|KMIP Server (PyKMIP)]] on Debian 13   * How to setup a [[deb13:kmip_server_pykmip|KMIP Server (PyKMIP)]] on Debian 13
  
- +===== Encrypted shared folders ===== 
- +  * On a NAS where encrypting the entire ''/volume1'' is not necessary or not advisable (no sensitive data, or performance concerns) you can encrypt single shared folders. 
- +  * To avoid data in encrypted shared folders get into the wrong hands follow my guide [[deb9:encrypted|Encrypted partitions/folders with auto-mount]]. <color red>This guide is outdated, but principles still apply. I will update the guide in due time.</color>
  
  
Line 22: Line 21:
   * The encryption keys will be stored in the Encryption Key Vault of the NAS, the keys will be automatically applied on boot of the system. This protects against theft or change of hard disks, but not against theft of the entire NAS. To protect against theft of the NAS you need to move the Encryption Key Vault to an external device running a KMIP server, which is supported by Synology. How to setup the KMIP server on a Synology NAS is described in [[dsm7kmip|KMIP for key management]].   * The encryption keys will be stored in the Encryption Key Vault of the NAS, the keys will be automatically applied on boot of the system. This protects against theft or change of hard disks, but not against theft of the entire NAS. To protect against theft of the NAS you need to move the Encryption Key Vault to an external device running a KMIP server, which is supported by Synology. How to setup the KMIP server on a Synology NAS is described in [[dsm7kmip|KMIP for key management]].
   * If you do not have another Synology NAS on another location, or you do not want to use your other NAS on another location as the KMIP server, you can install a working KMIP server on a linux machine. How this is done is described in [[deb13:kmip_server_pykmip|KMIP Server (PyKMIP)]].   * If you do not have another Synology NAS on another location, or you do not want to use your other NAS on another location as the KMIP server, you can install a working KMIP server on a linux machine. How this is done is described in [[deb13:kmip_server_pykmip|KMIP Server (PyKMIP)]].
-  * You need to take precautions in case you get locked out from your DSM because the Encrypted Key Vault is not accessible. Synology let's you login with SSH when password login is enabled even if the homes directory is not accessible (if it resides on the non-accessible encrypted volume). However, enabling password login is a security risk which I want to avoid, so I developed a method to handle this case in [[dsm7rescue|Rescue an encrypted volume]] .+  * You need to take precautions in case you get locked out from your DSM because the Encrypted Key Vault is not accessible. Synology let's you login with SSH when password login is enabled even if the homes directory is not accessible (e.g. if it resides on the non-accessible encrypted volume). However, enabling password login is a security risk which I want to avoid, so I developed a method to handle this case in [[dsm7rescue|Rescue an encrypted volume]] .
  
 ===== Migrate MailPlus Server to new NAS ===== ===== Migrate MailPlus Server to new NAS =====
Line 79: Line 78:
  
 exit 0</code> exit 0</code>
 +  - Check basic TCP connectivity:<code>telnet [smtp_host] [port] (e.g., telnet smtp.gmail.com 587)</code>
 +  - Check certificate assignment in Synology DSM<code>openssl s_client -connect mail.yourdomain.tld:465 -showcerts
 +openssl s_client -connect mail.yourdomain.tld:993 -showcerts
 +openssl s_client -connect mail.yourdomain.tld:587 -starttls smtp -showcerts</code>
 +  - If the //verify return code: 0// is not 0 but 1 or another number, your DSM most likely does not serve the intermediate certifiate. In this case you need to do the following:
 +    - Go to **Control Panel --> Security --> Certificate --> Settings** and assign Synology's default certificate to //MailPlus-Server-dovcot// and //MailPlus-Server-postfix//. Click **OK** and wait 30 seconds, then set the certifiates back to your Letsencrypt certificate and hit **OK**.
 +    - Go to **Control Panel --> Security --> Advanced --> Custom Settings** and set //MailPlus-Server-dovcot// and //MailPlus-Server-postfix// to //Intermediate compatibility//.
 +    - Stop and restart //Synology MailPlus Server// and //Synology MailPlus (Client)//.
 +  - You can also enter ''cat /var/packages/MailPlus-Server/target/etc/main.cf | grep .pem'' and check whether ''fullchain.pem'' is referenced.
 +  - Re-check the certificate assignment.
 +  - Open **MailPlus Server** and go to **Mail Delivery --> General**. //Enable SMTP authentication// and disable external postmaster in //External Postmaster//.
 +  - Disable //SMTP-SSL/TLS (port 465)// in **Synology MailPlus Server --> Service**
 +
 +===== Check MailPlus Server connectivity =====
 +  * Use the following command from an external source and from within your LAN:<code>openssl s_client -starttls smtp -connect smtp.example.com:587</code>
 +  * If external access works, but LAN access does not, then you have likely run into DNS/hairpin NAT issues. You best solve this by adding your mail host to the host overrides table. In [[pfsense:pfsense|pfSense firewall]] this is at //Services --> DNS Resolver --> General Settings//, scroll down to the bottom of the page.
 +  * You can check this by accessing your SMTP Server from within your LAN by IP address instead of the mail domain name.
 +  * Another good tool to check SMTP accessability is [[https://github.com/keny-studio/terminal-c/blob/main/Swaks%20-%20SMTP%20Testing%20tool.md|swaks]]:<code>sudo apt update
 +sudo apt install swaks
 +swaks --to recipient@example.com \
 +      --from sender@example.com \
 +      --server smtp.example.com \
 +      --port 587 \
 +      --tls \
 +      --auth LOGIN \
 +      --auth-user your_username \
 +      --auth-password your_password</code>
 +  * Make sure your web server who uses your SMTP Server will not get blocked by DSM or MailPlus Server. Go to //MailPlus Server --> Mail Delivery --> Security --> Block/Allow List// and //Control Panel --> Security --> Protection//, check //Block List// and add the web server's IP address to the //Allow List//.
 +
 +===== Developer Guide =====
 +  * [[https://help.synology.com/developer-guide/|Package Developer Guide]]
 +  * [[https://github.com/vletroye/SynoPackages|GitHub SynoPackages]]
 ==== Links ==== ==== Links ====
   * [[https://kb.synology.com/en-id/DSM/tutorial/How_to_migrate_MailPlus_to_another_NAS|How do I migrate MailPlus to another Synology NAS?]]   * [[https://kb.synology.com/en-id/DSM/tutorial/How_to_migrate_MailPlus_to_another_NAS|How do I migrate MailPlus to another Synology NAS?]]