Synology DSM can automatically renew Let's Encrypt certificates before they expire. They are valid for 90 days, and port 80 must be open on both the NAS and the router for renewal to work. [11]
To issue or renew the certificate, ensure that:
- The primary domain and every subject alternative name point to the public IP address of the Synology NAS. [1]
- If using Synology DDNS, its status is activated.
- The Synology DDNS hostname has not been changed. [1]
- You are not importing a certificate transferred from another device. Certificates exported from another device cannot be renewed after being imported; obtain a new Let's Encrypt certificate on the current NAS instead. [1]
If renewal still fails, check that port 80 is reachable from the Internet and verify all certificate domain names resolve to the NAS’s public IP. A changed web-server backend has also been reported as a possible cause in a community case, although this is not confirmed as a general Synology requirement. [4]
For VPN-related problems after renewal, update the VPN package and re-export the OpenVPN configuration when required; Synology has documented certificate-chain issues that can prevent clients from connecting. [10]