{"slug":"object-storage-migration","title":"Object Storage Migration Troubleshooting","description":"Troubleshooting guide for NAS, backup, and sync tools after the DanubeData Object Storage backend migration from MinIO to Ceph.","section":"Features","url":"https://docs.danubedata.ro/object-storage-migration","markdown_url":"https://docs.danubedata.ro/object-storage-migration.md","breadcrumbs":[{"title":"Features","slug":null},{"title":"Storage","slug":"storage-overview"},{"title":"Migration Troubleshooting","slug":"object-storage-migration"}],"headings":[{"level":1,"title":"Object Storage Migration Troubleshooting","id":"object-storage-migration-troubleshooting"},{"level":2,"title":"Quick Navigation","id":"quick-navigation"},{"level":2,"title":"What Changed","id":"what-changed"},{"level":3,"title":"Key Differences","id":"key-differences"},{"level":2,"title":"Common Issues","id":"common-issues"},{"level":3,"title":"SSL/TLS Certificate Errors","id":"ssltls-certificate-errors"},{"level":3,"title":"\"Access Denied\" After Migration","id":"access-denied-after-migration"},{"level":3,"title":"\"Bucket Not Found\" or \"NoSuchBucket\"","id":"bucket-not-found-or-nosuchbucket"},{"level":3,"title":"Slow Uploads or Timeouts","id":"slow-uploads-or-timeouts"},{"level":2,"title":"TrueNAS","id":"truenas"},{"level":3,"title":"Reconfiguring Cloud Credentials","id":"reconfiguring-cloud-credentials"},{"level":3,"title":"Troubleshooting Cloud Sync Tasks","id":"troubleshooting-cloud-sync-tasks"},{"level":2,"title":"Proxmox Backup Server","id":"proxmox-backup-server"},{"level":3,"title":"Proxmox VE (S3 via Storage Configuration)","id":"proxmox-ve-s3-via-storage-configuration"},{"level":3,"title":"Using rclone on Proxmox","id":"using-rclone-on-proxmox"},{"level":2,"title":"Synology","id":"synology"},{"level":3,"title":"Hyper Backup","id":"hyper-backup"},{"level":3,"title":"Cloud Sync","id":"cloud-sync"},{"level":2,"title":"QNAP","id":"qnap"},{"level":3,"title":"Reconfiguring HBS 3","id":"reconfiguring-hbs-3"},{"level":3,"title":"Troubleshooting","id":"troubleshooting"},{"level":2,"title":"Veeam","id":"veeam"},{"level":3,"title":"Reconfiguring the S3 Repository","id":"reconfiguring-the-s3-repository"},{"level":3,"title":"Troubleshooting","id":"troubleshooting"},{"level":2,"title":"Duplicati","id":"duplicati"},{"level":3,"title":"Reconfiguring Duplicati","id":"reconfiguring-duplicati"},{"level":3,"title":"Troubleshooting","id":"troubleshooting"},{"level":2,"title":"rclone","id":"rclone"},{"level":3,"title":"Configuration","id":"configuration"},{"level":3,"title":"Verify","id":"verify"},{"level":3,"title":"Troubleshooting","id":"troubleshooting"},{"level":2,"title":"Restic","id":"restic"},{"level":3,"title":"Configuration","id":"configuration"},{"level":3,"title":"Migrating an Existing Repository","id":"migrating-an-existing-repository"},{"level":3,"title":"Troubleshooting","id":"troubleshooting"},{"level":2,"title":"s3cmd","id":"s3cmd"},{"level":3,"title":"Configuration","id":"configuration"},{"level":3,"title":"Troubleshooting","id":"troubleshooting"},{"level":2,"title":"AWS CLI","id":"aws-cli"},{"level":3,"title":"Configuration","id":"configuration"},{"level":3,"title":"Troubleshooting","id":"troubleshooting"},{"level":2,"title":"MinIO Client (mc)","id":"minio-client-mc"},{"level":3,"title":"Configuration","id":"configuration"},{"level":3,"title":"Troubleshooting","id":"troubleshooting"},{"level":2,"title":"Cyberduck","id":"cyberduck"},{"level":3,"title":"Configuration","id":"configuration"},{"level":3,"title":"Troubleshooting","id":"troubleshooting"},{"level":2,"title":"MSP360 (CloudBerry) Backup","id":"msp360-cloudberry-backup"},{"level":3,"title":"Reconfiguring the S3 Account","id":"reconfiguring-the-s3-account"},{"level":3,"title":"Troubleshooting","id":"troubleshooting"},{"level":2,"title":"Acronis Cyber Protect","id":"acronis-cyber-protect"},{"level":3,"title":"Reconfiguring S3 Storage","id":"reconfiguring-s3-storage"},{"level":3,"title":"Troubleshooting","id":"troubleshooting"},{"level":2,"title":"Arq Backup","id":"arq-backup"},{"level":3,"title":"Configuration","id":"configuration"},{"level":3,"title":"Troubleshooting","id":"troubleshooting"},{"level":2,"title":"Kopia","id":"kopia"},{"level":3,"title":"Configuration","id":"configuration"},{"level":3,"title":"Migrating an Existing Repository","id":"migrating-an-existing-repository"},{"level":3,"title":"Troubleshooting","id":"troubleshooting"},{"level":2,"title":"Unraid","id":"unraid"},{"level":3,"title":"rclone (via User Scripts or CLI)","id":"rclone-via-user-scripts-or-cli"},{"level":3,"title":"Duplicati on Unraid","id":"duplicati-on-unraid"},{"level":3,"title":"CA Certificate Plugin","id":"ca-certificate-plugin"},{"level":2,"title":"Asustor","id":"asustor"},{"level":3,"title":"Reconfiguring DataSync Center","id":"reconfiguring-datasync-center"},{"level":3,"title":"Troubleshooting","id":"troubleshooting"},{"level":2,"title":"TerraMaster","id":"terramaster"},{"level":3,"title":"Reconfiguring TFM Backup","id":"reconfiguring-tfm-backup"},{"level":3,"title":"Troubleshooting","id":"troubleshooting"},{"level":2,"title":"General Checklist","id":"general-checklist"}],"format":"markdown","word_count":3881,"content":"# Object Storage Migration Troubleshooting\n\nTroubleshooting guide for NAS, backup, and sync tools after the DanubeData Object Storage backend migration from MinIO to Ceph.\n\n## Quick Navigation\n\n| NAS / Appliances | Backup Software | CLI / Sync Tools |\n|------------------|-----------------|------------------|\n| [TrueNAS](#truenas) | [Veeam](#veeam) | [rclone](#rclone) |\n| [Synology](#synology) | [Duplicati](#duplicati) | [Restic](#restic) |\n| [QNAP](#qnap) | [MSP360 (CloudBerry)](#msp360-cloudberry-backup) | [s3cmd](#s3cmd) |\n| [Unraid](#unraid) | [Acronis Cyber Protect](#acronis-cyber-protect) | [AWS CLI](#aws-cli) |\n| [Asustor](#asustor) | [Arq Backup](#arq-backup) | [MinIO Client (mc)](#minio-client-mc) |\n| [TerraMaster](#terramaster) | [Kopia](#kopia) | [Cyberduck](#cyberduck) |\n| [Proxmox](#proxmox-backup-server) | | |\n\nNot listed? See the [General Checklist](#general-checklist) at the bottom.\n\n---\n\n## What Changed\n\nDanubeData Object Storage has migrated from MinIO to Ceph RGW. The S3 API remains fully compatible, but some tools may require minor configuration adjustments. Your endpoint, access keys, and bucket names remain the same.\n\n### Key Differences\n\n| Area | Before (MinIO) | After (Ceph RGW) |\n|------|----------------|-------------------|\n| **URL Style** | Path-style and virtual-hosted | Path-style and virtual-hosted |\n| **Signature** | AWS Signature v4 | AWS Signature v4 or v2 |\n| **Multipart Threshold** | 5 GB max part | 5 GB max part |\n| **SSL Certificate** | Same domain | Same domain, new certificate chain |\n\n> **Note**: Both AWS Signature v4 and Signature v2 are supported. Prefer v4, which is the stronger scheme, unless your client cannot sign correctly with it — see [S3 Signature Requirements](object-storage-signature-requirements).\n\n## Common Issues\n\n### SSL/TLS Certificate Errors\n\nAfter migration, some clients cache the old TLS certificate. Symptoms include `SSL certificate problem`, `certificate verify failed`, or `CERTIFICATE_VERIFY_FAILED`.\n\n**Fix:**\n\n```bash\n# Clear the system CA cache (Linux)\nsudo update-ca-certificates\n\n# Clear the system CA cache (macOS)\nsudo security delete-certificate -Z <old-cert-hash>\n\n# Or simply restart the application/service to pick up the new certificate\n```\n\nFor appliances (NAS devices), restart the backup service or reboot the device to refresh the certificate store.\n\n### \"Access Denied\" After Migration\n\nIf your credentials were working before but now return `403 Access Denied`:\n\n1. Verify your access key and secret key are correct (re-enter them in your tool)\n2. Ensure you are using **AWS Signature v4** (not v2)\n3. Set the region to `fsn1` if your tool requires a region\n4. Confirm the endpoint is `https://s3.danubedata.ro`\n\n### \"Bucket Not Found\" or \"NoSuchBucket\"\n\nBucket names have not changed, but some tools cache bucket metadata. Clear the tool's cache or re-enter the bucket name manually.\n\n### Slow Uploads or Timeouts\n\nCeph RGW may handle multipart uploads slightly differently. If you experience timeouts:\n\n- Increase the multipart chunk size (e.g., from 5 MB to 64 MB)\n- Increase the connection timeout in your client\n- Reduce the number of parallel upload threads if the tool allows it\n\n---\n\n## TrueNAS\n\nTrueNAS uses **Cloud Sync Tasks** to back up to S3-compatible storage.\n\n### Reconfiguring Cloud Credentials\n\n1. Go to **Credentials > Cloud Credentials**\n2. Edit your DanubeData credential (or create a new one)\n3. Set:\n   - **Provider**: Amazon S3\n   - **Access Key ID**: your access key\n   - **Secret Access Key**: your secret key\n   - **Endpoint URL**: `https://s3.danubedata.ro`\n4. Under **Advanced Settings**:\n   - **Region**: leave empty or set to `fsn1`\n   - Leave **Use Signature v2** unchecked (v4 is preferred; v2 also works)\n5. Click **Verify Credential** to test the connection\n6. Save\n\n### Troubleshooting Cloud Sync Tasks\n\n**\"InvalidArgument\" or \"AuthorizationHeaderMalformed\"**\n- Try toggling **Use Signature v2** — both signature versions are supported\n\n**\"Connection timed out\"**\n- Verify the endpoint URL includes `https://` (not `http://`)\n- Check that TrueNAS can resolve `s3.danubedata.ro` (try `ping s3.danubedata.ro` from the TrueNAS shell)\n\n**\"SSL: CERTIFICATE_VERIFY_FAILED\"**\n- Go to **System > General > GUI > SSL** and update the CA certificates, or reboot TrueNAS to refresh the certificate store\n\n**Cloud Sync stuck at 0%**\n- Delete and recreate the Cloud Sync task with fresh credentials\n- Check the task log at **Tasks > Cloud Sync Tasks > View Logs**\n\n---\n\n## Proxmox Backup Server\n\nProxmox Backup Server (PBS) supports S3 storage via **datastore** backends or by using **rclone** for offsite copies.\n\n### Proxmox VE (S3 via Storage Configuration)\n\nProxmox VE does not natively support S3 as a backup target. If you are using a script or wrapper to push backups to S3:\n\n1. Update your script's S3 configuration to use AWS Signature v4\n2. Ensure the endpoint is `https://s3.danubedata.ro`\n3. Test with a manual upload:\n\n```bash\n# From the Proxmox host\ns3cmd --host=s3.danubedata.ro --host-bucket=\"%(bucket)s.s3.danubedata.ro\" \\\n  --access_key=YOUR_KEY --secret_key=YOUR_SECRET \\\n  --signature-v2=False \\\n  put /tmp/testfile s3://your-bucket/testfile\n```\n\n### Using rclone on Proxmox\n\nIf you use rclone to sync Proxmox backups to DanubeData:\n\n```bash\n# Update your rclone config (~/.config/rclone/rclone.conf)\n[danubedata]\ntype = s3\nprovider = Other\naccess_key_id = YOUR_ACCESS_KEY\nsecret_access_key = YOUR_SECRET_KEY\nendpoint = https://s3.danubedata.ro\nregion = fsn1\n```\n\nVerify the connection:\n\n```bash\nrclone ls danubedata:your-bucket\n```\n\nSee the [rclone section](#rclone) below for more troubleshooting.\n\n---\n\n## Synology\n\nSynology NAS supports S3 storage via **Hyper Backup** and **Cloud Sync**.\n\n### Hyper Backup\n\nHyper Backup needs **Signature Version 2** against DanubeData Object Storage, and a task's signature\nversion cannot be edited after the task is created. Full setup instructions, and how to move an\nexisting task without re-uploading your data, are on the dedicated page:\n**[Synology Hyper Backup](synology-hyper-backup)**.\n\n### Cloud Sync\n\n1. Open **Cloud Sync**\n2. Edit your existing connection\n3. Set:\n   - **S3 Server**: Custom\n   - **Server Address**: `https://s3.danubedata.ro`\n   - **Signature Version**: **V4**\n4. Re-enter your credentials\n5. Click **Test Connection** before saving\n\nIf uploads fail with `403 AccessDenied` while downloads still work, see [S3 Signature Requirements](object-storage-signature-requirements) — some clients need **V2**.\n\n**\"Connection failed\" in Cloud Sync**\n- Older DSM versions may not support the new certificate chain. Update DSM, or manually import DanubeData's CA certificate via **Control Panel > Security > Certificates**\n\n---\n\n## QNAP\n\nQNAP uses **Hybrid Backup Sync (HBS 3)** for S3 cloud backups.\n\n### Reconfiguring HBS 3\n\n1. Open **HBS 3 (Hybrid Backup Sync)**\n2. Go to **Storage Spaces** in the left sidebar\n3. Edit your existing S3-compatible storage space (or create a new one)\n4. Configure:\n   - **Server Address**: `s3.danubedata.ro`\n   - **Port**: `443`\n   - **Access Key**: your access key\n   - **Secret Key**: your secret key\n   - **Use SSL**: Enabled\n   - **Signature Version**: **V4**\n5. Click **Test** to verify the connection\n6. Select your bucket and save\n\n### Troubleshooting\n\n**\"Connection failed\" or \"Unable to list buckets\"**\n- Ensure **Signature Version** is set to **V4**\n- If uploads fail with `403 AccessDenied` while downloads still work, see [S3 Signature Requirements](object-storage-signature-requirements) — some clients need **V2**\n- Ensure **Use SSL** is enabled\n- Verify the server address is exactly `s3.danubedata.ro` (no `https://` prefix, no trailing slash)\n\n**\"Access Denied\" on backup job**\n- Re-enter the secret key (some QNAP firmware versions mask and re-encode the key incorrectly after edits)\n- Create a fresh storage space rather than editing the existing one\n\n**Backup jobs failing intermittently**\n- Increase the **Timeout** value in the backup job's advanced settings\n- Reduce the **Concurrent Connections** to 2-4\n\n---\n\n## Veeam\n\nVeeam Backup & Replication supports S3-compatible storage as an **Object Storage Repository**.\n\n### Reconfiguring the S3 Repository\n\n1. Open **Veeam Backup & Replication Console**\n2. Go to **Backup Infrastructure > Backup Repositories**\n3. Edit your S3-compatible repository\n4. On the **Account** step:\n   - Re-enter your **Access Key** and **Secret Key**\n   - Ensure the **Service Point** is `https://s3.danubedata.ro`\n   - Set **Region** to `fsn1` (or `us-east-1` if `fsn1` is not accepted)\n5. On the **Bucket** step, re-select your bucket\n6. Finish the wizard\n\n### Troubleshooting\n\n**\"Failed to connect to the endpoint\"**\n- Veeam requires the endpoint with `https://` prefix\n- Ensure port 443 is not blocked by your firewall\n\n**\"The request signature we calculated does not match\"**\n- Re-enter both the access key and secret key (copy-paste to avoid typos)\n- Ensure no proxy is modifying request headers\n\n**\"The specified bucket does not exist\"**\n- Click **Browse** to refresh the bucket list rather than typing the name manually\n\n**Backup jobs failing with \"Internal Server Error\"**\n- Check if the backup is using very small block sizes. Increase the block size in the backup job settings\n- Ensure Veeam is up to date (minimum v12 recommended for best S3 compatibility)\n\n---\n\n## Duplicati\n\nDuplicati supports S3-compatible storage as a backup destination.\n\n### Reconfiguring Duplicati\n\n1. Open **Duplicati Web UI**\n2. Edit your backup configuration\n3. Under **Storage Type**, select **S3 Compatible**\n4. Configure:\n   - **Server**: Custom URL\n   - **Custom URL**: `s3.danubedata.ro`\n   - **Bucket Name**: your bucket name\n   - **AWS Access ID**: your access key\n   - **AWS Access Key**: your secret key\n   - **Region**: `fsn1`\n5. Under **Advanced Options**, ensure:\n   - `--s3-ext-signatureversion=4` is set\n6. Click **Test Connection**\n\n### Troubleshooting\n\n**\"AuthorizationHeaderMalformed\"**\n- Add the advanced option: `--s3-ext-signatureversion=4`\n\n**\"SSL certificate problem\"**\n- On the machine running Duplicati, update the CA certificates:\n  ```bash\n  # Linux\n  sudo update-ca-certificates\n\n  # Windows\n  certutil -generateSSTFromWU roots.sst\n  ```\n- Or add the advanced option `--accept-any-ssl-certificate=true` (not recommended for production)\n\n**\"A socket operation was attempted to an unreachable network\"**\n- Verify DNS resolution: `nslookup s3.danubedata.ro`\n- Verify HTTPS connectivity: `curl -I https://s3.danubedata.ro`\n\n---\n\n## rclone\n\nrclone is widely used for syncing data to S3-compatible storage.\n\n### Configuration\n\nUpdate your rclone remote in `~/.config/rclone/rclone.conf`:\n\n```ini\n[danubedata]\ntype = s3\nprovider = Other\naccess_key_id = YOUR_ACCESS_KEY\nsecret_access_key = YOUR_SECRET_KEY\nendpoint = https://s3.danubedata.ro\nregion = fsn1\nacl = private\n```\n\nOr reconfigure interactively:\n\n```bash\nrclone config update danubedata \\\n  type=s3 \\\n  provider=Other \\\n  access_key_id=YOUR_ACCESS_KEY \\\n  secret_access_key=YOUR_SECRET_KEY \\\n  endpoint=https://s3.danubedata.ro \\\n  region=fsn1\n```\n\n### Verify\n\n```bash\n# List buckets\nrclone lsd danubedata:\n\n# List objects in a bucket\nrclone ls danubedata:your-bucket\n\n# Test upload\necho \"test\" | rclone rcat danubedata:your-bucket/migration-test.txt\nrclone delete danubedata:your-bucket/migration-test.txt\n```\n\n### Troubleshooting\n\n**\"AccessDenied\" or \"SignatureDoesNotMatch\"**\n- Ensure `provider = Other` (not `Minio`). Some rclone versions send MinIO-specific headers when provider is set to `Minio`\n- Remove any `force_path_style` setting (it defaults to `true` for provider `Other`)\n\n**\"NoSuchBucket\" when bucket exists**\n- Set `region = fsn1` explicitly in the config\n\n**Slow transfers**\n- Increase chunk size: add `chunk_size = 64M` to the remote config\n- Increase transfer concurrency: `rclone copy --transfers 8 --s3-upload-concurrency 4 ...`\n\n**\"Checksum mismatch\" errors**\n- Add `--s3-disable-checksum` to your rclone command\n- Or add `disable_checksum = true` to the remote config\n\n---\n\n## Restic\n\nRestic supports S3-compatible storage as a backup repository.\n\n### Configuration\n\nSet the environment variables:\n\n```bash\nexport AWS_ACCESS_KEY_ID=YOUR_ACCESS_KEY\nexport AWS_SECRET_ACCESS_KEY=YOUR_SECRET_KEY\nexport RESTIC_REPOSITORY=s3:https://s3.danubedata.ro/your-bucket\n```\n\nOr specify them inline:\n\n```bash\nrestic -r s3:https://s3.danubedata.ro/your-bucket snapshots\n```\n\n### Migrating an Existing Repository\n\nIf you had a Restic repository on the old backend, it should continue to work without changes. Verify:\n\n```bash\n# Check repository integrity\nrestic -r s3:https://s3.danubedata.ro/your-bucket check\n\n# List snapshots\nrestic -r s3:https://s3.danubedata.ro/your-bucket snapshots\n```\n\n### Troubleshooting\n\n**\"client.PutObject: Access Denied\"**\n- Re-export your credentials and ensure they are correct\n- Ensure the bucket exists and your access key has write permissions\n\n**\"TLS handshake timeout\"**\n- Check your network connectivity to `s3.danubedata.ro`\n- If running behind a corporate proxy, configure `HTTP_PROXY` / `HTTPS_PROXY` environment variables\n\n**\"repository master key and target key mismatch\"**\n- This means the repository data was partially migrated or corrupted. Run `restic check` and if it reports errors, restore from an alternate backup\n\n**Slow backup performance**\n- Increase the connection limit: `restic -o s3.connections=10 backup ...`\n\n---\n\n## s3cmd\n\ns3cmd is a popular command-line tool for S3.\n\n### Configuration\n\nUpdate `~/.s3cfg`:\n\n```ini\n[default]\naccess_key = YOUR_ACCESS_KEY\nsecret_key = YOUR_SECRET_KEY\nhost_base = s3.danubedata.ro\nhost_bucket = %(bucket)s.s3.danubedata.ro\nuse_https = True\nsignature_v2 = False\n```\n\nOr reconfigure:\n\n```bash\ns3cmd --configure \\\n  --host=s3.danubedata.ro \\\n  --host-bucket=\"%(bucket)s.s3.danubedata.ro\" \\\n  --access_key=YOUR_KEY \\\n  --secret_key=YOUR_SECRET\n```\n\n### Troubleshooting\n\n**\"S3 error: 403 (SignatureDoesNotMatch)\"**\n- Ensure `signature_v2 = False` in `~/.s3cfg`\n\n**\"S3 error: 404 (NoSuchBucket)\"**\n- Check that `host_bucket` is set correctly. If virtual-hosted style fails, try path-style by setting `host_bucket =` (empty value)\n\n---\n\n## AWS CLI\n\nThe AWS CLI (`aws s3` / `aws s3api`) works with any S3-compatible endpoint.\n\n### Configuration\n\n```bash\naws configure --profile danubedata\n# Access Key ID: YOUR_ACCESS_KEY\n# Secret Access Key: YOUR_SECRET_KEY\n# Default region: fsn1\n# Default output format: json\n```\n\nUse the `--endpoint-url` flag for all commands:\n\n```bash\n# List buckets\naws --profile danubedata --endpoint-url https://s3.danubedata.ro s3 ls\n\n# List objects\naws --profile danubedata --endpoint-url https://s3.danubedata.ro s3 ls s3://your-bucket\n\n# Upload a file\naws --profile danubedata --endpoint-url https://s3.danubedata.ro s3 cp /tmp/testfile s3://your-bucket/testfile\n```\n\nTo avoid passing `--endpoint-url` every time, set it in `~/.aws/config`:\n\n```ini\n[profile danubedata]\nregion = fsn1\nendpoint_url = https://s3.danubedata.ro\ns3 =\n  signature_version = s3v4\n```\n\n### Troubleshooting\n\n**\"An error occurred (SignatureDoesNotMatch)\"**\n- Ensure signature version is v4. Add to your profile in `~/.aws/config`:\n  ```ini\n  s3 =\n    signature_version = s3v4\n  ```\n\n**\"Could not connect to the endpoint URL\"**\n- Verify you are passing `--endpoint-url https://s3.danubedata.ro` (not the default AWS endpoint)\n- If using `endpoint_url` in config, ensure you are on AWS CLI v2 (v1 does not support `endpoint_url` in config)\n\n**\"An error occurred (NoSuchBucket)\"**\n- Set `region = fsn1` in your profile or pass `--region fsn1`\n\n---\n\n## MinIO Client (mc)\n\nIf you were using the MinIO Client (`mc`) with the old backend, it will continue to work with Ceph RGW.\n\n### Configuration\n\n```bash\n# Update your existing alias\nmc alias set danubedata https://s3.danubedata.ro YOUR_ACCESS_KEY YOUR_SECRET_KEY\n\n# Verify\nmc ls danubedata\n```\n\n### Troubleshooting\n\n**\"Unable to validate credentials\"**\n- Remove and re-create the alias:\n  ```bash\n  mc alias remove danubedata\n  mc alias set danubedata https://s3.danubedata.ro YOUR_ACCESS_KEY YOUR_SECRET_KEY\n  ```\n\n**\"S3 API Requests must be made to API port\"**\n- Ensure the endpoint includes `https://` and does not include a port number (port 443 is implied)\n\n**Admin commands (`mc admin`) no longer work**\n- `mc admin` commands are MinIO-specific and do not work with Ceph RGW. Use the DanubeData dashboard or S3 API for bucket management\n\n---\n\n## Cyberduck\n\nCyberduck is a graphical file transfer client for macOS and Windows with S3 support.\n\n### Configuration\n\n1. Open **Cyberduck**\n2. Click **Open Connection** (or edit an existing bookmark)\n3. Select **Amazon S3** from the dropdown\n4. Configure:\n   - **Server**: `s3.danubedata.ro`\n   - **Port**: `443`\n   - **Access Key ID**: your access key\n   - **Secret Access Key**: your secret key\n5. Click **Connect**\n\n### Troubleshooting\n\n**\"Login failed\" or \"403 Forbidden\"**\n- Go to **Preferences > S3** and ensure **Signature Version** is set to **AWS4-HMAC-SHA256 (Signature Version 4)**\n- Delete the saved password from macOS Keychain or Windows Credential Manager and re-enter it\n\n**Bucket listing is empty**\n- Cyberduck uses `us-east-1` as the default region. Edit the bookmark and set the **Region** field to `fsn1`\n- Alternatively, type the bucket name directly in the **Path** field: `/your-bucket`\n\n**\"Connection timed out\"**\n- Verify that the protocol is HTTPS (not HTTP) and the port is 443\n- Check if a local firewall or proxy is blocking the connection\n\n---\n\n## MSP360 (CloudBerry) Backup\n\nMSP360 (formerly CloudBerry) Backup supports S3-compatible storage for file, image, and database backups.\n\n### Reconfiguring the S3 Account\n\n1. Open **MSP360 Backup**\n2. Go to **Backup Storage** (or **Storage Accounts**)\n3. Edit your existing S3-compatible account (or add a new one)\n4. Configure:\n   - **S3 Compatible**: selected\n   - **Service Point**: `s3.danubedata.ro`\n   - **Access Key**: your access key\n   - **Secret Key**: your secret key\n   - **Use SSL**: Enabled\n   - **Signature Version**: **4**\n   - **Bucket**: select your bucket\n5. Click **Test Connection**\n6. Save\n\n### Troubleshooting\n\n**\"The request signature we calculated does not match the signature you provided\"**\n- Edit the storage account and ensure **Signature Version** is set to **4**\n\n**\"SSL/TLS secure channel could not be established\"**\n- Update your OS to get the latest CA certificates\n- On Windows: run Windows Update. On macOS: update macOS via System Preferences\n\n**Backup plan fails with \"Access Denied\" but test connection works**\n- The backup plan may be running under a different Windows user account (e.g., SYSTEM) that has different credentials stored. Re-enter the storage account credentials in the MSP360 service context\n\n**\"The specified bucket does not exist\"**\n- Clear the local bucket cache: go to **Tools > Options > Cache** and click **Clear Cache**, then re-select the bucket\n\n---\n\n## Acronis Cyber Protect\n\nAcronis supports S3-compatible storage as a backup destination for cloud and local backup plans.\n\n### Reconfiguring S3 Storage\n\n1. Open the **Acronis Management Console** (or **Cyber Protect Console**)\n2. Go to **Settings > Backup Storage**\n3. Edit your S3-compatible storage location\n4. Update:\n   - **Service URL**: `https://s3.danubedata.ro`\n   - **Access Key**: your access key\n   - **Secret Key**: your secret key\n   - **Bucket**: re-select your bucket\n   - **Region**: `fsn1`\n5. Click **Test Connection**\n6. Save\n\n### Troubleshooting\n\n**\"Failed to initialize the storage\"**\n- Acronis may cache connection metadata. Remove the storage location and add it again from scratch\n- Ensure the URL includes `https://`\n\n**\"The storage is unavailable\"**\n- Verify that the Acronis agent service has network access to `s3.danubedata.ro` on port 443\n- If the agent runs on a server behind a proxy, configure the proxy in Acronis agent settings\n\n**Backup fails with \"Part upload error\"**\n- Reduce the **Multipart Upload Size** in the storage's advanced settings (e.g., from 128 MB to 64 MB)\n- Increase the **Connection Timeout** value\n\n**Existing backups show as \"corrupted\" after migration**\n- Run **Validate Backup** on the affected backup set. If Acronis reports the archive as valid, the error is a stale cache — clear the agent cache and retry\n\n---\n\n## Arq Backup\n\nArq Backup (macOS and Windows) supports S3-compatible storage for encrypted backups.\n\n### Configuration\n\n1. Open **Arq Backup**\n2. Go to **Destinations**\n3. Edit your existing destination (or add a new one)\n4. Select **S3-Compatible** as the type\n5. Configure:\n   - **Server URL**: `https://s3.danubedata.ro`\n   - **Access Key ID**: your access key\n   - **Secret Access Key**: your secret key\n   - **Region**: `fsn1`\n   - **Path Style**: Enabled\n6. Select your bucket\n7. Save\n\n### Troubleshooting\n\n**\"Unable to list buckets\"**\n- Enable **Path Style** access in the destination settings\n- Set the region to `fsn1` (Arq may default to `us-east-1`)\n\n**\"Authentication error\" on existing backup set**\n- Edit the destination, re-enter the secret key, and click **Test**\n- If the error persists, check that no other Arq instance is writing to the same bucket concurrently\n\n**Backup verification fails**\n- Run **Verify Backup Data** from the **Backups** menu. Arq stores its own index files in the bucket — if any were in transit during migration, a verify-and-repair cycle will fix them\n\n---\n\n## Kopia\n\nKopia is a modern backup tool with native S3-compatible storage support.\n\n### Configuration\n\n```bash\n# Connect to an existing repository\nkopia repository connect s3 \\\n  --bucket=your-bucket \\\n  --access-key=YOUR_ACCESS_KEY \\\n  --secret-access-key=YOUR_SECRET_KEY \\\n  --endpoint=s3.danubedata.ro \\\n  --region=fsn1\n\n# Or create a new repository\nkopia repository create s3 \\\n  --bucket=your-bucket \\\n  --access-key=YOUR_ACCESS_KEY \\\n  --secret-access-key=YOUR_SECRET_KEY \\\n  --endpoint=s3.danubedata.ro \\\n  --region=fsn1\n```\n\n### Migrating an Existing Repository\n\nIf you had a Kopia repository on the old backend:\n\n```bash\n# Reconnect to the repository\nkopia repository connect s3 \\\n  --bucket=your-bucket \\\n  --access-key=YOUR_ACCESS_KEY \\\n  --secret-access-key=YOUR_SECRET_KEY \\\n  --endpoint=s3.danubedata.ro \\\n  --region=fsn1\n\n# Verify repository integrity\nkopia repository validate-provider\n\n# List snapshots\nkopia snapshot list\n```\n\n### Troubleshooting\n\n**\"unable to open repository\"**\n- Ensure the endpoint does not include a trailing slash\n- Re-enter the access key and secret key\n\n**\"repository not initialized in the provided storage\"**\n- This means Kopia cannot find its metadata files. Verify the bucket name and prefix path are correct\n\n**\"invalid credentials\"**\n- Kopia caches credentials locally. Run `kopia repository disconnect` and then reconnect with fresh credentials\n\n---\n\n## Unraid\n\nUnraid supports S3 backup via community plugins, most commonly **Appdata Backup** with rclone or **Duplicati** as a Docker container.\n\n### rclone (via User Scripts or CLI)\n\nIf you use rclone on Unraid to sync shares or appdata to S3:\n\n1. SSH into your Unraid server\n2. Update the rclone config:\n\n```bash\nrclone config update danubedata \\\n  type=s3 \\\n  provider=Other \\\n  access_key_id=YOUR_ACCESS_KEY \\\n  secret_access_key=YOUR_SECRET_KEY \\\n  endpoint=https://s3.danubedata.ro \\\n  region=fsn1\n```\n\n3. Verify: `rclone lsd danubedata:`\n\nSee the [rclone section](#rclone) for more troubleshooting.\n\n### Duplicati on Unraid\n\nIf you run Duplicati as a Docker container on Unraid, follow the [Duplicati section](#duplicati) above. One Unraid-specific note:\n\n**Certificate errors inside the Duplicati container**\n- The container has its own CA store. Update the container image to the latest version, or mount the host's CA certificates:\n  ```\n  /etc/ssl/certs:/etc/ssl/certs:ro\n  ```\n\n### CA Certificate Plugin\n\nIf any S3 tool on Unraid reports certificate errors, install the **CA User Scripts** or **NerdTools** plugin from Community Applications to update the system CA bundle.\n\n---\n\n## Asustor\n\nAsustor NAS uses **DataSync Center** and **Backup Plan** for S3 cloud backups.\n\n### Reconfiguring DataSync Center\n\n1. Open **DataSync Center** from ADM\n2. Go to **Cloud Backup** and edit your existing S3 task\n3. Select **S3 Compatible** as the cloud service\n4. Configure:\n   - **Server**: `s3.danubedata.ro`\n   - **Port**: `443`\n   - **SSL**: Enabled\n   - **Access Key**: your access key\n   - **Secret Key**: your secret key\n   - **Signature Version**: **V4**\n5. Select your bucket\n6. Click **Test Connection**\n7. Save\n\n### Troubleshooting\n\n**\"Connection failed\"**\n- Ensure the server field does not include `https://` (DataSync Center adds it when SSL is enabled)\n- Ensure **Signature Version** is set to **V4**\n- If uploads fail with `403 AccessDenied` while downloads still work, see [S3 Signature Requirements](object-storage-signature-requirements) — some clients need **V2**\n\n**\"Failed to authenticate\"**\n- Re-enter both keys. Asustor may store credentials in an encrypted format that is invalidated after firmware updates\n- Update ADM to the latest version\n\n**Backup jobs stuck or not starting**\n- Restart the DataSync Center service: go to **Services > DataSync Center** and toggle it off and on\n- Check the ADM system log at **Access Control > Logs** for detailed error messages\n\n---\n\n## TerraMaster\n\nTerraMaster NAS uses **TFM Backup** and **CloudSync** for S3 cloud backups.\n\n### Reconfiguring TFM Backup\n\n1. Open **TFM Backup** from the TOS desktop\n2. Edit your existing cloud backup task\n3. Select **S3 Compatible** as the destination\n4. Configure:\n   - **Server Address**: `s3.danubedata.ro`\n   - **Port**: `443`\n   - **Use SSL/TLS**: Enabled\n   - **Access Key**: your access key\n   - **Secret Key**: your secret key\n   - **Bucket**: select your bucket\n5. Save and run a test backup\n\n### Troubleshooting\n\n**\"Connection error\" or \"Unable to connect to server\"**\n- Verify the server address has no `https://` prefix and no trailing slash\n- Ensure **Use SSL/TLS** is enabled\n- Update TOS to the latest version for certificate chain compatibility\n\n**\"Authentication failed\"**\n- Delete the existing cloud backup destination and create a new one with fresh credentials\n- TerraMaster firmware prior to TOS 5.1 may have issues with AWS Signature v4 — update firmware first\n\n**Backup appears to complete but no files are uploaded**\n- Check the bucket in the DanubeData dashboard to confirm files arrived\n- Some TOS versions create an empty task when the connection test passes but the actual upload path is misconfigured. Re-enter the bucket name manually instead of selecting from the dropdown\n\n---\n\n## General Checklist\n\nIf your tool is not listed above, follow this general checklist:\n\n1. **Endpoint**: `https://s3.danubedata.ro`\n2. **Region**: `fsn1` (or leave empty if the tool does not require it; use `us-east-1` as a fallback if `fsn1` is rejected)\n3. **Signature Version**: AWS Signature **v4** (not v2)\n4. **SSL/TLS**: Enabled (port 443)\n5. **Access Key & Secret Key**: Re-enter them (do not copy from cached config)\n6. **Path Style**: Use path-style URLs if your tool supports it (`https://s3.danubedata.ro/bucket`)\n7. **Test**: Upload a small test file before running a full backup\n\nIf you continue to experience issues after following these steps, contact support at **support@danubedata.ro** with:\n- The tool name and version\n- The exact error message\n- Your bucket name (not your secret key)\n\n---\n\n**Questions?** Contact support at support@danubedata.ro\n","prev":{"title":"S3 API Supported Actions","slug":"object-storage-supported-actions","url":"https://docs.danubedata.ro/object-storage-supported-actions","markdown_url":"https://docs.danubedata.ro/object-storage-supported-actions.md","json_url":"https://docs.danubedata.ro/object-storage-supported-actions.json"},"next":{"title":"S3 Signature Requirements","slug":"object-storage-signature-requirements","url":"https://docs.danubedata.ro/object-storage-signature-requirements","markdown_url":"https://docs.danubedata.ro/object-storage-signature-requirements.md","json_url":"https://docs.danubedata.ro/object-storage-signature-requirements.json"},"index_url":"https://docs.danubedata.ro/index.json"}