This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| syno:dsm7inst [2026/09/02 15:46] – [Setup rescue login] Bernard Condrau | syno:dsm7inst [2026/10/01 12:47] (current) – [Check MailPlus Server connectivity] Bernard Condrau | ||
|---|---|---|---|
| Line 11: | Line 11: | ||
| * How to setup a [[deb13: | * How to setup a [[deb13: | ||
| - | + | ===== Encrypted shared folders ===== | |
| - | + | * On a NAS where encrypting the entire ''/ | |
| - | + | * To avoid data in encrypted shared folders get into the wrong hands follow my guide [[deb9: | |
| Line 22: | Line 21: | ||
| * The encryption keys will be stored in the Encryption Key Vault of the NAS, the keys will be automatically applied on boot of the system. This protects against theft or change of hard disks, but not against theft of the entire NAS. To protect against theft of the NAS you need to move the Encryption Key Vault to an external device running a KMIP server, which is supported by Synology. How to setup the KMIP server on a Synology NAS is described in [[dsm7kmip|KMIP for key management]]. | * The encryption keys will be stored in the Encryption Key Vault of the NAS, the keys will be automatically applied on boot of the system. This protects against theft or change of hard disks, but not against theft of the entire NAS. To protect against theft of the NAS you need to move the Encryption Key Vault to an external device running a KMIP server, which is supported by Synology. How to setup the KMIP server on a Synology NAS is described in [[dsm7kmip|KMIP for key management]]. | ||
| * If you do not have another Synology NAS on another location, or you do not want to use your other NAS on another location as the KMIP server, you can install a working KMIP server on a linux machine. How this is done is described in [[deb13: | * If you do not have another Synology NAS on another location, or you do not want to use your other NAS on another location as the KMIP server, you can install a working KMIP server on a linux machine. How this is done is described in [[deb13: | ||
| - | * You need to take precautions in case you get locked out from your DSM because the Encrypted Key Vault is not accessible. Synology let's you login with SSH when password login is enabled even if the homes directory is not accessible (if it resides on the non-accessible encrypted volume). However, enabling password login is a security risk which I want to avoid, so I developed a method to handle this case in [[dsm7rescue|Rescue an encrypted volume]] . | + | * You need to take precautions in case you get locked out from your DSM because the Encrypted Key Vault is not accessible. Synology let's you login with SSH when password login is enabled even if the homes directory is not accessible (e.g. if it resides on the non-accessible encrypted volume). However, enabling password login is a security risk which I want to avoid, so I developed a method to handle this case in [[dsm7rescue|Rescue an encrypted volume]] . |
| ===== Migrate MailPlus Server to new NAS ===== | ===== Migrate MailPlus Server to new NAS ===== | ||
| Line 79: | Line 78: | ||
| exit 0</ | exit 0</ | ||
| + | - Check basic TCP connectivity:< | ||
| + | - Check certificate assignment in Synology DSM< | ||
| + | openssl s_client -connect mail.yourdomain.tld: | ||
| + | openssl s_client -connect mail.yourdomain.tld: | ||
| + | - If the //verify return code: 0// is not 0 but 1 or another number, your DSM most likely does not serve the intermediate certifiate. In this case you need to do the following: | ||
| + | - Go to **Control Panel --> Security --> Certificate --> Settings** and assign Synology' | ||
| + | - Go to **Control Panel --> Security --> Advanced --> Custom Settings** and set // | ||
| + | - Stop and restart //Synology MailPlus Server// and //Synology MailPlus (Client)//. | ||
| + | - You can also enter '' | ||
| + | - Re-check the certificate assignment. | ||
| + | - Open **MailPlus Server** and go to **Mail Delivery --> General**. //Enable SMTP authentication// | ||
| + | - Disable // | ||
| + | |||
| + | ===== Check MailPlus Server connectivity ===== | ||
| + | * Use the following command from an external source and from within your LAN:< | ||
| + | * If external access works, but LAN access does not, then you have likely run into DNS/hairpin NAT issues. You best solve this by adding your mail host to the host overrides table. In [[pfsense: | ||
| + | * You can check this by accessing your SMTP Server from within your LAN by IP address instead of the mail domain name. | ||
| + | * Another good tool to check SMTP accessability is [[https:// | ||
| + | sudo apt install swaks | ||
| + | swaks --to recipient@example.com \ | ||
| + | --from sender@example.com \ | ||
| + | --server smtp.example.com \ | ||
| + | --port 587 \ | ||
| + | --tls \ | ||
| + | --auth LOGIN \ | ||
| + | --auth-user your_username \ | ||
| + | --auth-password your_password</ | ||
| + | * Make sure your web server who uses your SMTP Server will not get blocked by DSM or MailPlus Server. Go to //MailPlus Server --> Mail Delivery --> Security --> Block/Allow List// and //Control Panel --> Security --> Protection//, | ||
| + | |||
| + | ===== Developer Guide ===== | ||
| + | * [[https:// | ||
| + | * [[https:// | ||
| ==== Links ==== | ==== Links ==== | ||
| * [[https:// | * [[https:// | ||