security certificate revoked - outlook.office365.com

John Rovel Kalaw 6 Reputation points
2022-07-27T04:28:49.213+00:00

Hi

The pictures below started popping up on our PCs. and the PC was using not part of any domain. I tried to follow the link below but the IE was inaccessible. https://answers.microsoft.com/en-us/outlook_com/forum/all/outlookoffice365com-security-certificate-has-been/743bdb2b-06ce-4206-923e-bdb7041528bd

225096-image.png

Outlook | Windows | Classic Outlook for Windows | For business
Windows for business | Windows Server | Devices and deployment | Configure application groups

49 answers

Sort by: Oldest
  1. Jacob Cavaness 11 Reputation points
    2022-11-02T15:29:07.87+00:00

    INFORMATION UPDATE:

    My coworker just got off the phone with Microsoft Support and we were told that this is a Global Issue, and that they are working to resolve it.

    For a reference I have left the case number below if you happen to call-in/chat with support.

    CASE# 33672891

    Was this answer helpful?

    2 people found this answer helpful.

  2. megs28 6 Reputation points
    2022-11-02T16:10:36.46+00:00

    When I had the error this morning, I see the below in my CAPI2 log. It lead me to checking the issuing CAs to see if I trusted them and I noticed I didn't have either of the intermediate CAs for DigiCert Cloud Services CA-1. I think I've seen it issued by both the new and old intermediate CA... Always the same root CA, and I have yet to find any certs that are listed as expired in the crl.

    The list of CAs MS apparently uses is here, and I should have them installed already? https://learn.microsoft.com/en-us/microsoft-365/compliance/encryption-office-365-certificate-chains?view=o365-worldwide

    I'm trying the two for the DigiCert Cloud Services CA-1 and will see what happens. I realize this doesn't match up with any revoked cert error, but I figured it doesn't hurt to try. I also see it's lsass, but again, figured it can't hurt to try.

    I also find it strange that the 4 instances we have had this morning, 3 of the times it was after the person was away from the PC for a bit, and once was when it came out of hibernation this AM.

    <CertVerifyCertificateChainPolicy>    
      <Policy type="CERT_CHAIN_POLICY_MICROSOFT_ROOT" constant="7" />    
      <Certificate fileRef="F7DA87B0B58B2A2EEC386EC7A60AB14D5A60A499.cer" subjectName="outlook.com" />    
      <CertificateChain chainRef="{3BD14261-79CD-4F1C-9F04-D87B6752C13D}" />    
      <Flags value="20000" MICROSOFT_ROOT_CERT_CHAIN_POLICY_CHECK_APPLICATION_ROOT_FLAG="true" />    
      <Status chainIndex="0" elementIndex="2" />    
      <EventAuxInfo ProcessName="lsass.exe" />    
      <CorrelationAuxInfo TaskId="{5E002671-EFDF-4383-808F-B28A1CF1B431}" SeqNumber="1" />    
      <Result value="800B0109">A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.</Result>    
    </CertVerifyCertificateChainPolicy>    
    

    Was this answer helpful?


  3. JB22 1 Reputation point
    2022-11-02T18:05:46.343+00:00

    Finally - Microsoft has posted an advisory [EX455084] on this issue.

    256468-image.png

    Was this answer helpful?


  4. JB22 1 Reputation point
    2022-11-02T18:24:41.063+00:00

    Within Microsoft 365 Admin Center [https://admin.microsoft.com], go to Health > Service Health. If it’s unavailable in your tenant, open a case with Microsoft and reference that advisory number and have them add it to your tenant.

    Was this answer helpful?


  5. Alex Le 1 Reputation point
    2022-11-03T11:45:55.733+00:00

    What it looks like to me is they revoked a SSL they were using globally across their 1000s of Exchange server farm. When they revoked the original SSL they have updated most of the servers w the new generated certificate and have overlooked a server or two. Hence why it’s intermittent and only happening to random users.

    If they had just one server and the ssl was revoked everyone would get the same error all the time.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.