When I had the error this morning, I see the below in my CAPI2 log. It lead me to checking the issuing CAs to see if I trusted them and I noticed I didn't have either of the intermediate CAs for DigiCert Cloud Services CA-1. I think I've seen it issued by both the new and old intermediate CA... Always the same root CA, and I have yet to find any certs that are listed as expired in the crl.
The list of CAs MS apparently uses is here, and I should have them installed already? https://learn.microsoft.com/en-us/microsoft-365/compliance/encryption-office-365-certificate-chains?view=o365-worldwide
I'm trying the two for the DigiCert Cloud Services CA-1 and will see what happens. I realize this doesn't match up with any revoked cert error, but I figured it doesn't hurt to try. I also see it's lsass, but again, figured it can't hurt to try.
I also find it strange that the 4 instances we have had this morning, 3 of the times it was after the person was away from the PC for a bit, and once was when it came out of hibernation this AM.
<CertVerifyCertificateChainPolicy>
<Policy type="CERT_CHAIN_POLICY_MICROSOFT_ROOT" constant="7" />
<Certificate fileRef="F7DA87B0B58B2A2EEC386EC7A60AB14D5A60A499.cer" subjectName="outlook.com" />
<CertificateChain chainRef="{3BD14261-79CD-4F1C-9F04-D87B6752C13D}" />
<Flags value="20000" MICROSOFT_ROOT_CERT_CHAIN_POLICY_CHECK_APPLICATION_ROOT_FLAG="true" />
<Status chainIndex="0" elementIndex="2" />
<EventAuxInfo ProcessName="lsass.exe" />
<CorrelationAuxInfo TaskId="{5E002671-EFDF-4383-808F-B28A1CF1B431}" SeqNumber="1" />
<Result value="800B0109">A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.</Result>
</CertVerifyCertificateChainPolicy>