Using classic Outlook for Windows in business environments
We've seen this intermittently in Ontario.
Certificate Serial number is 0f12dc8955821d6d936bcf34e50f60c5
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hi
The pictures below started popping up on our PCs. and the PC was using not part of any domain. I tried to follow the link below but the IE was inaccessible. https://answers.microsoft.com/en-us/outlook_com/forum/all/outlookoffice365com-security-certificate-has-been/743bdb2b-06ce-4206-923e-bdb7041528bd
Using classic Outlook for Windows in business environments
We've seen this intermittently in Ontario.
Certificate Serial number is 0f12dc8955821d6d936bcf34e50f60c5
Anyone got any official notification from Microsoft that this is being looked at? It's way to random for way to many users to be a local issue or something that we need to user workarounds to fix.
This is also hitting two completely separate tenants in Canada east coast which we manage. Random users, at work, at home, vpn connected, direct ISP connected, desktop,laptop, mobile, Windows, Mac, does not make a difference. So this certainly looks like a Microsoft side issue. At first it was very sporadically reported but now several users are reporting it since it has increased in frequency this past week.
More info
ON, Canada
Thumbprint = f7da87b0b58b2a2eec386ec7a60ab14d5a60a499
Serial = 0f12dc8955821d6d936bcf34e50f60c5
CRL & OCSP report
https://certificate.revocationcheck.com/d841795beb73bb7c9e78a3713e3af6e1a506e86a00b95235a0e45304acc6b69f/outlook.com
Correct me if I'm wrong but the report states that it is not revoked.
CRL information does say "Revocation information is updated at least once every twelve months "
CERTUIL OUTPUT
C:\temp>certutil -verify -urlfetch testoulook.crt.cer
Issuer:
CN=DigiCert Cloud Services CA-1
O=DigiCert Inc
C=US
Name Hash(sha1): 48b6a9e21293b3c020b12ace4e73649a3c67dc9b
Name Hash(md5): 15b99a482264ff73f2a208ddbefd9e98
Subject:
CN=outlook.com
O=Microsoft Corporation
L=Redmond
S=Washington
C=US
Name Hash(sha1): 830674a4478dcff5ece46d1b71e1ebe193d47d67
Name Hash(md5): f32ab5d9094e4f0bed302ed125cc82cd
Cert Serial Number: 0f12dc8955821d6d936bcf34e50f60c5
dwFlags = CA_VERIFY_FLAGS_CONSOLE_TRACE (0x20000000)
dwFlags = CA_VERIFY_FLAGS_DUMP_CHAIN (0x40000000)
ChainFlags = CERT_CHAIN_REVOCATION_CHECK_CHAIN_EXCLUDE_ROOT (0x40000000)
HCCE_LOCAL_MACHINE
CERT_CHAIN_POLICY_BASE
--------
CERT_CHAIN_CONTEXT --------
ChainContext.dwInfoStatus = CERT_TRUST_HAS_PREFERRED_ISSUER (0x100)
ChainContext.dwRevocationFreshnessTime: 19 Hours, 8 Minutes, 53 Seconds
SimpleChain.dwInfoStatus = CERT_TRUST_HAS_PREFERRED_ISSUER (0x100)
SimpleChain.dwRevocationFreshnessTime: 19 Hours, 8 Minutes, 53 Seconds
CertContext[0][0]: dwInfoStatus=102 dwErrorStatus=0
Issuer: CN=DigiCert Cloud Services CA-1, O=DigiCert Inc, C=US
NotBefore: 7/25/2022 8:00 PM
NotAfter: 7/25/2023 7:59 PM
Subject: CN=outlook.com, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Serial: 0f12dc8955821d6d936bcf34e50f60c5
SubjectAltName: DNS Name=.clo.footprintdns.com, DNS Name=.hotmail.com, DNS Name=.internal.outlook.com, DNS Name=.live.com, DNS Name=.nrb.footprintdns.com, DNS Name=.office.com, DNS Name=.office365.com, DNS Name=.outlook.com, DNS Name=*.outlook.office365.com, DNS Name=attachment.outlook.live.net, DNS Name=attachment.outlook.office.net, DNS Name=attachment.outlook.officeppe.net, DNS Name=attachments.office.net, DNS Name=attachments-sdf.office.net, DNS Name=ccs.login.microsoftonline.com, DNS Name=ccs-sdf.login.microsoftonline.com, DNS Name=hotmail.com, DNS Name=mail.services.live.com, DNS Name=office365.com, DNS Name=outlook.com, DNS Name=outlook.office.com, DNS Name=substrate.office.com, DNS Name=substrate-sdf.office.com
Cert: f7da87b0b58b2a2eec386ec7a60ab14d5a60a499
Element.dwInfoStatus = CERT_TRUST_HAS_KEY_MATCH_ISSUER (0x2)
Element.dwInfoStatus = CERT_TRUST_HAS_PREFERRED_ISSUER (0x100)
---------------- Certificate AIA ----------------
Verified "Certificate (0)" Time: 0 81b68d6cd2f221f8f534e677523bb236bba1dc56
[0.0] http://cacerts.digicert.com/DigiCertCloudServicesCA-1.crt
---------------- Certificate CDP ----------------
Verified "Base CRL (0a52)" Time: 0 a0f47f61e4f0b841cf49dffb063c3dc82325119d
[0.0] http://crl3.digicert.com/DigiCertCloudServicesCA-1-g1.crl
Verified "Base CRL (0a52)" Time: 0 a0f47f61e4f0b841cf49dffb063c3dc82325119d
[1.0] http://crl4.digicert.com/DigiCertCloudServicesCA-1-g1.crl
---------------- Base CRL CDP ----------------
No URLs "None" Time: 0 (null)
---------------- Certificate OCSP ----------------
Verified "OCSP" Time: 0 266ca90d4cf7f2c17376696ecdd431ba9794d485
[0.0] http://ocspx.digicert.com
--------------------------------
CRL (null):
Issuer: CN=DigiCert Cloud Services CA-1, O=DigiCert Inc, C=US
ThisUpdate: 11/2/2022 12:15 AM
NextUpdate: 11/8/2022 11:30 PM
CRL: 8913134d940671fe8638e88bd349fd55f791724c
Issuance[0] = 2.23.140.1.2.2
Application[0] = 1.3.6.1.5.5.7.3.2 Client Authentication
Application[1] = 1.3.6.1.5.5.7.3.1 Server Authentication
CertContext[0][1]: dwInfoStatus=102 dwErrorStatus=0
Issuer: CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US
NotBefore: 8/4/2015 8:00 AM
NotAfter: 8/4/2030 8:00 AM
Subject: CN=DigiCert Cloud Services CA-1, O=DigiCert Inc, C=US
Serial: 019ec1c6bd3f597bb20c3338e551d877
Cert: 81b68d6cd2f221f8f534e677523bb236bba1dc56
Element.dwInfoStatus = CERT_TRUST_HAS_KEY_MATCH_ISSUER (0x2)
Element.dwInfoStatus = CERT_TRUST_HAS_PREFERRED_ISSUER (0x100)
---------------- Certificate AIA ----------------
No URLs "None" Time: 0 (null)
---------------- Certificate CDP ----------------
Verified "Base CRL (0288)" Time: 0 b57e588e3371a7fee13eaa737aefdf4e126dcf51
[0.0] http://crl4.digicert.com/DigiCertGlobalRootCA.crl
Verified "Base CRL (0288)" Time: 0 b57e588e3371a7fee13eaa737aefdf4e126dcf51
[1.0] http://crl3.digicert.com/DigiCertGlobalRootCA.crl
---------------- Base CRL CDP ----------------
No URLs "None" Time: 0 (null)
---------------- Certificate OCSP ----------------
Verified "OCSP" Time: 0 80d02a82ed91c45c253ac7f02d0e860f7dad676e
[0.0] http://ocsp.digicert.com
--------------------------------
CRL (null):
Issuer: CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US
ThisUpdate: 11/1/2022 3:10 PM
NextUpdate: 11/8/2022 3:10 PM
CRL: 29770badf567892431ebfbc24697ed9b9317281c
Application[0] = 1.3.6.1.5.5.7.3.2 Client Authentication
Application[1] = 1.3.6.1.5.5.7.3.3 Code Signing
Application[2] = 1.3.6.1.5.5.7.3.4 Secure Email
Application[3] = 1.3.6.1.5.5.7.3.1 Server Authentication
Application[4] = 1.3.6.1.5.5.7.3.8 Time Stamping
CertContext[0][2]: dwInfoStatus=10a dwErrorStatus=0
Issuer: CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US
NotBefore: 11/9/2006 8:00 PM
NotAfter: 11/9/2031 8:00 PM
Subject: CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US
Serial: 083be056904246b1a1756ac95991c74a
Cert: a8985d3a65e5e5c4b2d7d66d40c6dd2fb19c5436
Element.dwInfoStatus = CERT_TRUST_HAS_KEY_MATCH_ISSUER (0x2)
Element.dwInfoStatus = CERT_TRUST_IS_SELF_SIGNED (0x8)
Element.dwInfoStatus = CERT_TRUST_HAS_PREFERRED_ISSUER (0x100)
---------------- Certificate AIA ----------------
No URLs "None" Time: 0 (null)
---------------- Certificate CDP ----------------
No URLs "None" Time: 0 (null)
---------------- Certificate OCSP ----------------
No URLs "None" Time: 0 (null)
--------------------------------
Application[0] = 1.3.6.1.5.5.7.3.2 Client Authentication
Application[1] = 1.3.6.1.5.5.7.3.3 Code Signing
Application[2] = 1.3.6.1.5.5.7.3.4 Secure Email
Application[3] = 1.3.6.1.5.5.7.3.1 Server Authentication
Application[4] = 1.3.6.1.5.5.7.3.8 Time Stamping
EV[0] = 2.16.840.1.114412.2.1
EV[1] = 2.23.140.1.3
Exclude leaf cert:
Chain: a8f25e97a4ef94994351f1a0b09068320cd7f732
Full chain:
Chain: 72d2e243f0cc9ff042e9d321fd51a4fdb6c2d364
------------------------------------
Verified Issuance Policies:
2.23.140.1.2.2
Verified Application Policies:
1.3.6.1.5.5.7.3.2 Client Authentication
1.3.6.1.5.5.7.3.1 Server Authentication
Cert is an End Entity certificate
Leaf certificate revocation check passed
CertUtil: -verify command completed successfully.
So its is not revoked, but outlook is stating otherwise.
Morning,
I am new to this forum but wanted everyone's opinion. I have a small number of users that are experiencing this issue. So, I check the serial number from the issued DigiCert cert and cross-referenced the data with the website "https://certificate.revocationcheck.com/outlook.com". I noticed the serial number is different from the website and the issue cert. I wonder if this could be the cause for some of my users.