1. Go to the email where it is requested to complete the configuration process, click on the link
CA Issuers - URI:http://secure.globalsign.
openssl verify -untrusted fullchain.crt server.crt
1. Go to the email where it is requested to complete the configuration process, click on the link
root@server:/volume1/docker/
root@server:/usr/syno/etc/
total 20
drwx------ 2 root root 4096 Mar 18 16:12 dCjJGL
-rwx------ 1 root root 1904 May 11 09:38 SERVICES
drwx------ 2 root root 4096 May 18 10:20 uE4Pkn
-rw------- 1 root root 7 May 18 10:21 DEFAULT
-rw------- 1 root root 2552 May 18 10:28 INFO
root@server:/usr/syno/etc/
root@server:/usr/syno/etc/
total 52
-r-------- 1 root root 1890 Mar 18 16:12 cert.pem
-r-------- 1 root root 1801 Mar 18 16:12 chain.pem
-r-------- 1 root root 1390 Mar 18 16:12 ECC-cert.pem
-r-------- 1 root root 1566 Mar 18 16:12 ECC-chain.pem
-r-------- 1 root root 2958 Mar 18 16:12 ECC-fullchain.pem
-r-------- 1 root root 241 Mar 18 16:12 ECC-privkey.pem
-r-------- 1 root root 3693 Mar 18 16:12 fullchain.pem
-r-------- 1 root root 1704 Mar 18 16:12 privkey.pem
-r-------- 1 root root 262 Mar 18 16:12 renew.json
-r-------- 1 root root 1890 Mar 18 16:12 RSA-cert.pem
-r-------- 1 root root 1801 Mar 18 16:12 RSA-chain.pem
-r-------- 1 root root 3693 Mar 18 16:12 RSA-fullchain.pem
-r-------- 1 root root 1704 Mar 18 16:12 RSA-privkey.pem
root@server:/usr/syno/etc/
DNS:*.domain.com, DNS:domain.com
root@server:/usr/syno/etc/
> -in cert.pem \
> -inkey privkey.pem \
> -certfile chain.pem \
> -out unifi.p12 \
> -name unifi \
> ls -lrt^C
root@server:/usr/syno/etc/
total 60
-r-------- 1 root root 1890 Mar 18 16:12 cert.pem
-r-------- 1 root root 1801 Mar 18 16:12 chain.pem
-r-------- 1 root root 1390 Mar 18 16:12 ECC-cert.pem
-r-------- 1 root root 1566 Mar 18 16:12 ECC-chain.pem
-r-------- 1 root root 2958 Mar 18 16:12 ECC-fullchain.pem
-r-------- 1 root root 241 Mar 18 16:12 ECC-privkey.pem
-r-------- 1 root root 3693 Mar 18 16:12 fullchain.pem
-r-------- 1 root root 1704 Mar 18 16:12 privkey.pem
-r-------- 1 root root 262 Mar 18 16:12 renew.json
-r-------- 1 root root 1890 Mar 18 16:12 RSA-cert.pem
-r-------- 1 root root 1801 Mar 18 16:12 RSA-chain.pem
-r-------- 1 root root 3693 Mar 18 16:12 RSA-fullchain.pem
-r-------- 1 root root 1704 Mar 18 16:12 RSA-privkey.pem
-rw------- 1 root root 4344 May 18 22:01 unifi.p12
root@server:/usr/syno/etc/
root@server:/volume1/docker/
total 228
drwxr-xr-x+ 3 admin users 4096 Mar 6 15:53 backup
drwxr-xr-x+ 4 admin users 40960 May 18 22:01 db
-rwxr-xr-x+ 1 root root 35879 May 18 09:41 firmware.json
-rwxr-xr-x+ 1 admin users 6502 May 11 09:39 keystore
-rwxr-xr-x+ 1 admin users 2742 Aug 28 2023 keystore-2023-08-28.bak
-rwxr-xr-x+ 1 root root 6502 May 18 21:57 keystore-2026-05-18.bak
-rwxr-xr-x+ 1 admin users 1424 May 18 21:40 model_lifecycles.json
-rwxr-xr-x+ 1 admin users 0 Oct 17 2023 system_env
-rwxr-xr-x+ 1 root root 1394 May 11 09:40 system.properties
-rwxr-xr-x+ 1 root root 1394 May 11 09:40 system.properties.bk
-rwxr-xr-x+ 1 root root 110245 May 15 17:41 uidb.json
-rw------- 1 root root 4344 May 18 22:01 unifi.p12
root@server:/volume1/docker/
> -srckeystore /unifi/data/unifi.p12 \
> -srcstoretype PKCS12 \
> -srcstorepass aircontrolenterprise \
> -destkeystore /unifi/data/keystore \
> -deststoretype JKS \
> -deststorepass aircontrolenterprise \
> -alias unifi
Importing keystore /unifi/data/unifi.p12 to /unifi/data/keystore...
Existing entry alias unifi exists, overwrite? [no]: yes
root@server:/volume1/docker/
root@server:/usr/syno/etc/
> -inkey privkey.pem \
> -in cert.pem \
> -certfile chain.pem \
> -certpbe AES-256-CBC \
> -keypbe AES-256-CBC \
> -macalg SHA256
Enter Export Password:
Verifying - Enter Export Password:
# Generated by iptables-save v1.6.0 on Sun Feb 18 13:27:56 2018 *nat :PREROUTING ACCEPT [485:82476] :INPUT ACCEPT [24:2229] :OUTPUT ACCEPT [192:15907] :POSTROUTING ACCEPT [192:15907] -A POSTROUTING -s 10.8.0.0/24 -o eth0 -m comment --comment "Allow OpenVPN routing from source 10.8.0.0 to eth0" -j MASQUERADE COMMIT # Completed on Sun Feb 18 13:27:56 2018 # Generated by iptables-save v1.6.0 on Sun Feb 18 13:27:56 2018 *filter :INPUT DROP [67:11459] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [687:299583] :f2b-openvpn - [0:0] :f2b-sshd - [0:0] -A INPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -m comment --comment "Block null packets" -j DROP -A INPUT -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -m comment --comment "Block a syn-flood attack" -j DROP -A INPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -m comment --comment "Block Xmas packets" -j DROP # localhost -A INPUT -i lo -m comment --comment "Allow localhost traffic" -j ACCEPT -A INPUT -i lo -p tcp -m tcp --dport 4711:4720 -m comment --comment "TODO" -j ACCEPT # Established connections -A INPUT -m state --state RELATED,ESTABLISHED -m comment --comment "Allow all established inbound connections" -j ACCEPT # DNS server -A INPUT -p udp -m udp --dport 53 -m comment --comment "Allow DNS to this host from anywhere" -j ACCEPT -A INPUT -p tcp -m tcp --dport 53 -m comment --comment "Allow DNS to this host from anywhere" -j ACCEPT # OpenVPN server -A INPUT -p tcp -m multiport --dports 1194 -m comment --comment "Allow OpenVPN to this host from anywhere" -j f2b-openvpn # SSH server -A INPUT -p tcp -m multiport --dports 22 -m comment --comment "Allow SSH to this host from anywhere" -j f2b-sshd -A INPUT -p icmp -m icmp --icmp-type 8 -m comment --comment "Allow ping to this host from anywhere" -j ACCEPT # HTTP server -A INPUT -p tcp -m tcp --dport 80 -m comment --comment "Allow HTTP to this host from anywhere" -j ACCEPT # SSLH multiplexer -A INPUT -p tcp -m tcp --dport 443 -m comment --comment "Allow HTTPS to this host from anywhere" -j ACCEPT # SSH server -A INPUT -p tcp -m tcp --dport 22 -m comment --comment "Allow SSH to this host from anywhere" -j ACCEPT # Samba server -A INPUT -p tcp -m multiport --dports 139,445 -m comment --comment "Allow Samba to this host from anywhere" -j ACCEPT -A INPUT -p udp -m multiport --dports 137,138 -m comment --comment "Allow Samba to this host from anywhere" -j ACCEPT # Transmission server -A INPUT -p tcp -m tcp --dport 9091 -m comment --comment "Allow Transmission to this host from anywhere" -j ACCEPT # Reject rules -A INPUT -m comment --comment "Reject all other inboud traffic, unless specified" -j REJECT --reject-with icmp-port-unreachable -A FORWARD -m comment --comment "Reject all other inboud traffic, unless specified" -j REJECT --reject-with icmp-port-unreachable -A f2b-openvpn -j RETURN -A f2b-sshd -j RETURN COMMIT # Completed on Sun Feb 18 13:27:56 2018
# SSH server -A INPUT -s 192.168.1.0/24 -p tcp -m tcp --dport 22 -m comment --comment "Allow SSH to this host from anywhere" -j ACCEPT
sudo -i
cd /etc/iptables/
cp -rp rules.v4 rules.v4.ori
vi rules.v4
iptables -L
iptables-restore < /etc/rules.v4
iptables -L
vi /etc/network/if-pre-up.d/iptables
/sbin/iptables-restore < /etc/iptables.up.rules
chmod +x /etc/network/if-pre-up.d/iptables
iptables-save > /etc/iptables/rules.v4
root@server:/# netstat -an | grep 30000 tcp 0 0 192.168.0.5:30000 0.0.0.0:* LISTEN
root@server:/# netstat -an | grep 443 tcp 0 0 0.0.0.0:443 0.0.0.0:* LISTEN tcp6 0 0 :::443 :::* LISTEN
2017-01-10T19:04:33+01:00 server synoservicecfg: service_restart.c:21 synoservice: restart [nginx] ... 2017-01-10T19:04:34+01:00 server synoservicecfg: service_restart.c:52 synoservice: finish restart [nginx].12. Verify that HTTPS is only listening onto localhost (127.0.0.1)
root@server:/usr/syno/share/nginx# netstat -an | grep 443 tcp 0 0 127.0.0.1:443 0.0.0.0:* LISTEN tcp6 0 0 :::443 :::* LISTEN
root@server:/usr/syno/share/nginx# netstat -an | grep 443 tcp 0 0 192.168.0.5:443 0.0.0.0:* LISTEN tcp 0 0 127.0.0.1:443 0.0.0.0:* LISTEN tcp6 0 0 :::443 :::* LISTEN
root@raspi1:~# netstat -an | grep LISTEN tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTENAs you can see, there is nothing running on port 443 (HTTPS) yet, so we'll need to enable the HTTPS configuration for Apache.
root@raspi1:~# ls -l /etc/apache2/mods-enabled/*ssl* root@raspi1:~#
root@raspi1:~# cd /etc/apache2/mods-enabled/ root@raspi1:~# ln -s ../mods-available/ssl.conf ssl.conf root@raspi1:~# ln -s ../mods-available/ssl.load ssl.load
root@raspi1:~# cd /etc/apache2/sites-enabled/ root@raspi1:~# ln -s ../sites-available/default-ssl 000-default-ssl
DocumentRoot /var/www <Directory /> Options FollowSymLinks #Changed None to All on 18/11/2016 AllowOverride All </Directory> <Directory /var/www/> Options Indexes FollowSymLinks MultiViews #Changed None to All on 18/11/2016 AllowOverride All Order allow,deny allow from all </Directory>
root@raspi1:~# /etc/init.d/apache2 restart