SyncriTab

SSL Certificates

Turn on HTTPS so that passwords, queries, and results travel between browsers and SyncriTab encrypted. HTTPS needs a certificate, and SyncriTab can create, obtain, or import one for you.

How HTTPS works in SyncriTab

A certificate proves to the browser that it's talking to your SyncriTab server and lets the two encrypt everything they exchange. It's issued for a host name, such as syncritab.example.com, and users must open SyncriTab with that name for the browser to trust it.

HTTPS is controlled from the HTTP Configuration tab of the Configuration page. See Server Configuration.

If HTTPS is turned on but no usable certificate is set up, SyncriTab creates a self-signed certificate for itself when it starts, so HTTPS always works. Browsers warn about self-signed certificates, so replace it with one of the other types for everyday use.

Choosing a certificate type

The HTTPS Certificate dialog showing the four certificate types.
Choosing how to get a certificate.
Certificate typeBest forTrusted by browsers
Automatically create a self-signed certificate Testing, or a small internal server where you can tell users to accept the warning. No. Browsers show a warning.
Obtain a certificate from Let's Encrypt Servers with a public host name. Free, and renewed automatically. Yes
Import an existing certificate You already have a certificate, for example a wildcard certificate used on other servers. Yes, if it's from a trusted authority.
Create a certificate signing request (CSR) Your organization buys certificates or runs its own certificate authority. Yes, if the authority is trusted.
Decision chart for choosing a certificate type.
Which certificate type should you use?

Before you start

  1. Choose the host name users will open, such as syncritab.example.com, and make sure it resolves to the SyncriTab server in DNS.
  2. On the HTTP Configuration tab, set TCP/IP port for HTTPS to 443, set Preferred URL to the HTTPS address, for example https://syncritab.example.com, and click Save.
  3. Allow port 443 through the server's firewall. For Let's Encrypt with web-based validation, also allow port 80 from the internet.

Creating a self-signed certificate

  1. On the HTTP Configuration tab, click Configure Certificate....
  2. In Certificate type, choose Automatically create a self-signed certificate.
  3. Enter the Host name. Use a DNS name your organization controls. If you leave the suggested name, it's based on the administrator's email domain, for example syncritab.example.com.
  4. Enter the Validity (days), from 1 to 825. The default is 365.
  5. Click Generate Certificate.

Users see a browser warning the first time they open SyncriTab. They can accept it, or your IT team can add the certificate to the trusted certificates on users' computers.

Getting a free certificate from Let's Encrypt

Let's Encrypt is a free certificate authority trusted by all major browsers. Before it issues a certificate, it checks that you control the host name, in one of two ways:

Requesting the certificate

  1. On the HTTP Configuration tab, click Configure Certificate....
  2. In Certificate type, choose Obtain a certificate from Let's Encrypt, enter the Host name, choose the Challenge type, and click Start Let's Encrypt.
  3. On the Let's Encrypt Certificate page, check the host name and choose how to validate it:
    • HTTP - SyncriTab: SyncriTab answers Let's Encrypt itself on port 80. Use this when SyncriTab listens on port 80.
    • HTTP - Another web server: another web server, such as IIS or Apache, answers on port 80 for this host name. Enter that server's Other web server root path, the folder it serves files from, so SyncriTab can place the validation file there.
    • DNS: validate with a DNS TXT record.
  4. Click Continue, read the Let's Encrypt Subscriber Agreement, and click Agree and Create Certificate.
  5. If you chose DNS, SyncriTab shows a DNS host and Value. Create a TXT record with them at your DNS provider, wait until it can be looked up publicly (this can take from a few minutes to an hour), and click Continue.
    The Let's Encrypt DNS step showing the TXT record to create.
    Adding the DNS TXT record for Let's Encrypt.
  6. SyncriTab confirms that the certificate was created. If it replaced an earlier Let's Encrypt certificate, it's already in use. If it replaced a different type of certificate, such as the self-signed one, the page asks you to restart SyncriTab to start using it. See Updating & Restarting.

Let's Encrypt limits how many certificates it issues for the same host name in a short period, so check the host name, DNS, and firewall before you start, rather than retrying repeatedly after a failure.

Renewing a Let's Encrypt certificate

Let's Encrypt certificates are valid for 90 days. SyncriTab checks every day and starts renewing about 40 days after the certificate was issued, well before it expires.

To see the certificate's status or renew it yourself, click Start Let's Encrypt again in the HTTPS Certificate dialog. The status page shows the host name, the expiration date, and the next renewal date, with a Renew now button.

The Let's Encrypt status page after a certificate was issued.
Let's Encrypt status.

Renewal emails are sent to the Administrator's address through your email server, so make sure both are set up. See Email Configuration.

Importing an existing certificate

Use this if you already have a certificate and its private key, for example one exported from IIS, Apache, or another server.

  1. Export the certificate with its private key as a PKCS#12 file (.pfx or .p12), or use a Java keystore (.jks).
  2. On the HTTP Configuration tab, click Configure Certificate... and choose Import an existing certificate.
  3. Enter the Host name, choose the Certificate file, enter the Certificate password, and choose the Keystore type: PKCS12 for .pfx and .p12 files, or JKS.
  4. Click Import Certificate.

An imported certificate isn't renewed automatically. Import a new one before it expires; the certificate summary on the HTTP Configuration tab shows the expiration date.

Getting a certificate from your certificate authority

If your organization buys certificates or runs its own certificate authority (CA), SyncriTab creates a certificate signing request (CSR) for you to send them. The private key never leaves the server.

  1. On the HTTP Configuration tab, click Configure Certificate... and choose Create a certificate signing request (CSR).
  2. Fill in the request:
    FieldWhat to enter
    Host nameThe host name users will open, such as syncritab.example.com.
    OrganizationYour company's legal name.
    Organizational unitOptional. A department, such as IT.
    CityYour city.
    State or provinceWritten out in full, such as New Jersey.
    Country codeThe two-letter code, such as US.
    RSA key size2048, 3072, or 4096 bits. 2048 is accepted everywhere; larger keys are stronger but slightly slower.
    Additional DNS namesOptional. Other names users may open, separated by commas, such as syncritab, syncritab.corp.example.com.
  3. Click Create CSR, then Download CSR.
  4. Send the CSR file to your certificate authority, following its instructions.
  5. When you receive the signed certificate, open the dialog again. Under Signed certificate and chain, choose the file (.pem, .cer, or .crt) and click Install Signed Certificate. Include the authority's intermediate certificates in the file if they sent them separately.

Like an imported certificate, it isn't renewed automatically. Create a new request before it expires.

After installing a certificate

Removing a certificate

In the certificate summary on the HTTP Configuration tab, click Remove Certificate and confirm. HTTPS may keep using the certificate until SyncriTab restarts. If HTTPS is still turned on when SyncriTab restarts, it goes back to the previous certificate if one is available, or otherwise creates a new self-signed certificate. To stop using HTTPS, also set the HTTPS port to 0.

Troubleshooting

ProblemWhat to check
The browser warns that the certificate isn't trusted. A self-signed certificate is in use. Get a trusted certificate from Let's Encrypt or your certificate authority.
The browser warns that the name doesn't match. Users are opening SyncriTab with a different name than the certificate's host name, for example an IP address. Use the host name, or add the other names to the certificate.
Let's Encrypt web-based validation fails. The host name must resolve to this server from the internet, and port 80 must be open and answered by SyncriTab or the other web server you chose.
Let's Encrypt DNS validation fails. The TXT record may not be visible yet. Wait longer, check it with an online DNS lookup tool, and try again.
HTTPS stopped working after the certificate expired. Open SyncriTab on the primary HTTP port, http://server:21786, and install a new certificate.