From August 19th 2020, SECTIGO issues SSL certificates with a maximum lifetime of 398 days (13 months) as specified by CA/Browser consortium. SSL certificates with a longer lifetime must be re-issued annually (free of charge). You'll receive reminders via e-mail. SSL certificates issued before August 19th 2020 remain valid until their planned expiry date. Code Signing & S/MIME certificates are not affected and remain valid until their planned expiry date.

Can i obtain a SSL certificate for a server with dynamic IP / DNS / DynDNS address? What about synology.me, myqnapcloud.com, dyndns.org subdomains?

Yes, it is possible to obtain a SSL certificate for dynamic IP based servers. For mail authentication you need a proper "MX" DNS entry. Please choose "HTTP" type authentication during CSR placement for servers with <subdomain>.synology.me, <subdomain>.dyndns.org or <subdomain>.myqnapcloud.com domain, as authentication emails won't be processed by synology.me. If you are running your synology disk station with your own domain, you can of course also use email validation.

Synology CAA DNS records are allowing us to issue PositiveSSL and RapidSSL certificates for the following domains:

YourDomain.synology.com
YourDomain.synology.me
YourDomain.myds.com
YourDomain.myds.de

You can NOT obtain SSL from us for the following domains:

YourDomain.dsmynas.com
YourDomain.myds.me
YourDomain.dyndns.org

Unfortunately, the CAs had recently been uncooperative on issuing SSL certificates for dyndns.org subdomains. We therefore cannot recommend customers to order a SSL for such domains. Other dynamic DNS providers have not been affected so far.

In general:

Dynamic DNS with your own domain => Email validation:
For validating your SSL certificate via Email you need a valid MX entry for your domain or at least a valid email forwarder with your domain registrar. Allowed Emails are admin@, administrator@webmaster@root@, postmaster@. For validating .com/.net/.org you can also choose the email address from the WHOIS entry of your domain. Please be aware that this option is not available for some domain suffixes (e.g. .de, .at). The certificate authority will send an email with validation link that you will have to approve. Without approval the SSL cannot be issued!

Dynamic DNS subdomain (synlology.me, myqnapclud.com) => HTTP validation:
For servers on <subdomain>.synology.me, <subdomain>.myqnapcloud.com or <subdomain>.dyndns.org etc. please choose "HTTP" validation while placing your CSR. In this case the email validation won't be possible because emails sent to qnap, synology etc. won't ever be forwarded to you. - Of course you can use email validation if your synology diskstation is running on your own domain and can receive validation emails on root@, administrator@, ... 


Please find further details regarding SSL installation in the Synology knowledgebase


Was this answer helpful?

 Print this Article

Also Read

SSL request and installation under Synology DiskStation NAS

If you want to obtain a SSL certificate for your Synology diskstation, we recommend to NOT use...

ErrorCode:-9009|Message:Vendor returns error:ErrorField:CSR|ErrorMessageThe common name in the CSR does not match the site's domain name

This error may occur when you are re-issuing a certificate and are using a different COMMON NAME...

Microsoft IIS: multi-domain SSL on a single IP. Setting up host headers for IIS with SAN

How to configure SSL host headers in Microsoft IIS...

How to export an existing SSL certificate from Windows IIS and reuse it on Linux (convert .PFX to .KEY and .CRT)

1) In Windows, right click on the SSL certificate and export to .PFX 2) On Linux, convert the...

How to obtain a SSL certificate? How does e-mail authentication work?

After ordering a SSL certificate with InterSSL, you have to place a CSR (Certificate Signing...