
Connector
Synology DSM
API credential, entered client by client.
The operating system of Synology NAS appliances. Vigicap authenticates through Synology's own published login API and reads the list of APIs the NAS exposes, which names the backup applications installed on it (Hyper Backup, Active Backup for Business, Snapshot Replication). Synology's published API exposes neither the date of the last successful backup nor any restore test: this connector therefore never proposes more than level 2 on the ReCyF objective « Sauvegardes et restauration », and that ceiling comes from the vendor's API, not from the client's backups.
Beta01
What to create in the tool
The access is created in Synology DSM, not in Vigicap. Vigicap never asks for an administrator's password: it expects an API credential that you create, that you can see, and that you can revoke without us.
Where to generate it
Créez un utilisateur DSM dédié, sans droit d'administration, et désactivez la double authentification pour ce compte (l'API de connexion de Synology la refuse : codes 403/406). L'adresse demandée est celle de DSM, port 5001 en HTTPS par exemple. Le NAS doit présenter un certificat TLS valide et reconnu — le certificat auto-signé installé par défaut sera refusé par Vigicap (DSM sait obtenir un certificat Let's Encrypt : Panneau de configuration > Sécurité > Certificat).
Minimum role
Créez un utilisateur DSM dédié (Panneau de configuration > Utilisateur et groupe) sans droit d'administration et sans accès aux dossiers partagés : ce connecteur n'appelle que SYNO.API.Info et SYNO.API.Auth. La double authentification doit être désactivée sur ce seul compte de service — DSM refuse une connexion par API lorsqu'elle est exigée (codes 403 et 406).
Taken from the vendor's own role model, and checked before publication.
02
What to enter in Vigicap
The exact fields of the connection form, in the order they appear. Values marked “secret” never travel back to the browser: they are encrypted at rest and deleted on disconnection.
The form starts with the instance address, entered separately from the fields below. The public catalogue does not yet publish whether this connector needs one, or what it looks like — so this list is exact about everything else, and silent about that first field.
- Compte DSMsecret
Utilisateur DSM dédié, sans droit d'administration.
vigicap
- Mot de passesecret
Mot de passe de ce compte. La double authentification doit être désactivée sur ce compte.
03
Per-client routing
The connection is made client by client: one credential per client, entered on that client's record. Nothing is shared between two clients, and disconnecting one leaves the other untouched.
04
What it does, and what it does not do
ReCyF objectives it pre-fills
A reading feeds one objective of the ANSSI ReCyF framework. It PROPOSES it: the level only counts once a consultant has confirmed it.
- #13 Continuité et reprise d'activitéBusiness continuity and recovery
Read-only
The reads are read-only: Vigicap writes nothing into the tool while reading it.
What is read, what is kept, for how long and with which rights: the same register, connector by connector, in the data inventory.
Verification
The tool is an appliance operating system with no vendor-supported container image, so there is no throwaway instance to drive it against. This is not “not yet done”; it is a verification nobody will complete by finding an afternoon.
The trademarks and logos mentioned belong to their respective owners and identify the tools Vigicap is compatible with — see the legal notice.