Certificate problem with Microsoft Outlook.com
For some reason, I started receiving the attached message today. The other two images are what is shown inside View. I guess this happens when Thunderbird downloads new email. I have no idea what this means or how to resolve it.
I am running macOS 10.14.6 on a 2012 MacBook Air and am on Thunderbird 60.9.1. I've been using Thunderbird and Outlook for many years without any problems. Oddly, my wife received this same message on her 2014 MacBook Air using Apple Mail, so my guess is that this is an Outlook problem, but I thought I should check here first.
Any help would be much appreciated.
Asịsa ahọpụtara
Hi xtouqh. This morning, the problem was gone. I put all of my Avast settings back as they originally were and haven't seen the problem all day. I guess Microsoft had a problem.
Thanks for the confirmation, xtouqh. And, thanks to sfhowes and the folks at DigiCert.
Gụọ azịza a na nghọta 👍 0All Replies (12)
Do you have Avast intercepting certificates? That is probably the source of the error. Disable SSL scanning and see if it helps:
sfhowes said
Do you have Avast intercepting certificates? That is probably the source of the error. Disable SSL scanning and see if it helps: https://support.postbox-inc.com/hc/en-us/articles/204602300-Invalid-Security-Certificate-Error-when-using-AVAST
Thanks for the reply, sfhowes. Well, the story gets better. A few days ago, I removed my Sophos virus protection and replaced it with Avast because I wanted protection I could turn off when need be and this is easier to do in Avast. So, after I sent the post you replied to, I unistalled Avast and went back to Sophos, but it's still doing it. The only difference is that the Common Name is now DigiCert Cloud Services CA-1. So, it isn't Avast.
I have no idea how to disable SSL scanning but in looking it up it says that you are effectively turning off the virus protection. This sounds like a scary experiment. The problem with this whole thing is that the warning is very scary with no solution provided. I really don't know what to do.
There are plenty of references if you Google Sophos SSL scanning, and advice for adding exclusions. I don't think this in any way reduces protection, as the real-time background scan of email is still in place. It just limits the interference of Sophos in secure connections to mail servers, a process that is best controlled by TB. It's generally recommended anyway to exclude TB from email scanning:
sfhowes said
There are plenty of references if you Google Sophos SSL scanning, and advice for adding exclusions. I don't think this in any way reduces protection, as the real-time background scan of email is still in place. It just limits the interference of Sophos in secure connections to mail servers, a process that is best controlled by TB. It's generally recommended anyway to exclude TB from email scanning: http://kb.mozillazine.org/Antivirus_software
I tried searching on that but couldn't really find anything that made sense to me. I went into the Sophos online settings and couldn't find any place to set anything remotely related to email scanning. So, I uninstalled Sophos, reloaded Avast, and am trying a few things in its email settings. I turned off "Scan Decure Connections" and added "pop-mail.outlook.com:995" to the scan exceptions list. If this appears to be flailing on my part, that's because it is. The warning window hasn't appeared in a little while, but I've had that happen before.
Computers are wonderful things when they work, but are an inscrutable s*** show for regular people when this kind of problem pops up.
I thank you for your help, sfhowes. I'm going to use this for a day or so to make sure it doesn't reappear and will let you know if this has solved the problem.
I wrote a reply but it was dumped. So, long story short; I couldn't find anything I could make sense of in the search you suggested. Reinstalled Avast and made some changes in its email settings that I think are what you are talking about. So, we'll see. So far, the window hasn't popped up, but I've had that happen before. So, I'll let you know how it turns out. Thanks for your help, sfhowes.
Well, the window appeared even with the changes I made in Avast. So, I went into Avast and turned off the entire email shield . . . and the popup window still appeared.
In desperation, I sent an email to DigiCert and to my amazement, just received a reply. It says: "In this case that warning means that the OS can't verify the legitimacy of the certificate for the server connection. I'd recommend reaching out to Apple Support to assist."
I'll contact Apple, but I know they aren't going to do squat for me. Any other ideas, sfhowes?
If you were on Windows I would suggest you avoid the nonsense of these antivirus programs and just use Windows Security, but, not being a mac user, I can't offer a similar recommendation. Perhaps other mac users on the forum can suggest a security app that works without interfering with TB.
If you stick with Avast, consider disabling SSL scanning:
I received the following message from DigiCert overnight:
"Unfortunately, we are not really sure how this happened. I believe it just started yesterday and we received multiple reports for the similar issue. Those were all linked to outlook.com domain names, and only happened to Apple devices (Mac, iPhone, iPad, etc.). Checking certificate installation with tools doesn't display any error, and the same issue is not found with Window computers. So the only suggestion we can provide at the moment is checking with Apple's support team."
So, it isn't just me.
I received the following message from DigiCert overnight:
Unfortunately, we are not really sure how this happened. I believe it just started yesterday and we received multiple reports for the similar issue. Those were all linked to outlook.com domain names, and only happened to Apple devices (Mac, iPhone, iPad, etc.). Checking certificate installation with tools doesn't display any error, and the same issue is not found with Window computers. So the only suggestion we can provide at the moment is checking with Apple's support team.
So, it isn't just me.
I received the following reply from DigiCert:
"Unfortunately, we are not really sure how this happened. I believe it just started yesterday and we received multiple reports for the similar issue. Those were all linked to outlook.com domain names, and only happened to Apple devices (Mac, iPhone, iPad, etc.). Checking certificate installation with tools doesn't display any error, and the same issue is not found with Window computers. So the only suggestion we can provide at the moment is checking with Apple's support team."
So it isn't just happening to me.
FWIW, despite what the reply from DigiCert says, I was getting this all day yesterday on Windows 10 + Thunderbird 78.4.0 + IMAP to office365.com servers, today the issue has disappeared by itself.
Asịsa Ahọpụtara
Hi xtouqh. This morning, the problem was gone. I put all of my Avast settings back as they originally were and haven't seen the problem all day. I guess Microsoft had a problem.
Thanks for the confirmation, xtouqh. And, thanks to sfhowes and the folks at DigiCert.