TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Microsoft Teams outage due to expired certificate

339 pointsby stygiansonicover 5 years ago

19 comments

akerroover 5 years ago
Is anyone else redirected by this url to <a href="https:&#x2F;&#x2F;guce.advertising.com&#x2F;collectIdentifiers?sessionId=3_cc-session_3982b38b-2de1-484a-98bd-4a0b8635308c" rel="nofollow">https:&#x2F;&#x2F;guce.advertising.com&#x2F;collectIdentifiers?sessionId=3_...</a> ?<p><a href="https:&#x2F;&#x2F;gfycat.com&#x2F;fortunateyawningcopperhead" rel="nofollow">https:&#x2F;&#x2F;gfycat.com&#x2F;fortunateyawningcopperhead</a><p>My router is blocking this domain on DNS level in OpenWRT, techcrunch.com is redirecting me there, so I can&#x27;t visit this page.<p>Edit: I literally can not visit any techcrunch.com article, all of them redirect me to this doggy ads+tracking domain. It doesn&#x27;t matter if I came from google, DDG, reddit or HN.
评论 #22229669 未加载
评论 #22228539 未加载
评论 #22228315 未加载
评论 #22230956 未加载
评论 #22234104 未加载
评论 #22238119 未加载
评论 #22228192 未加载
评论 #22232371 未加载
评论 #22228339 未加载
评论 #22228502 未加载
评论 #22228312 未加载
stygiansonicover 5 years ago
A similar problem with Azure happened way back in 2013: <a href="https:&#x2F;&#x2F;www.computerworld.com&#x2F;article&#x2F;2495453&#x2F;microsoft-s-azure-service-hit-by-expired-ssl-certificate.html" rel="nofollow">https:&#x2F;&#x2F;www.computerworld.com&#x2F;article&#x2F;2495453&#x2F;microsoft-s-az...</a><p>More recently, it happened with Ericsson: <a href="https:&#x2F;&#x2F;www.theverge.com&#x2F;2018&#x2F;12&#x2F;7&#x2F;18130323&#x2F;ericsson-software-certificate-o2-softbank-uk-japan-smartphone-4g-network-outage" rel="nofollow">https:&#x2F;&#x2F;www.theverge.com&#x2F;2018&#x2F;12&#x2F;7&#x2F;18130323&#x2F;ericsson-softwar...</a><p>This article has some information about how Let&#x27;s Encrypt enabled an &quot;automated process that handles renewals&quot;: <a href="https:&#x2F;&#x2F;duo.com&#x2F;decipher&#x2F;proposal-to-make-https-certificate-expire-yearly-back-on-the-table" rel="nofollow">https:&#x2F;&#x2F;duo.com&#x2F;decipher&#x2F;proposal-to-make-https-certificate-...</a><p>I wonder if such a process should be made an industry standard? Does anyone know if there are any proposals for it?
评论 #22227565 未加载
评论 #22227681 未加载
评论 #22227551 未加载
评论 #22228213 未加载
评论 #22228629 未加载
godelmachineover 5 years ago
I am going to seize this opportunity and rant out my angst against Microsoft’s worst product till date.<p>Has anyone even felt that Teams is a heavy app that consumes a lot of time to come alive?<p>Even during calls, the quality is horrible that I don’t even want to describe the pain I go through. There’s strong distortion and voices will never be heard clearly.
评论 #22229533 未加载
评论 #22228486 未加载
评论 #22229423 未加载
评论 #22228436 未加载
评论 #22231731 未加载
评论 #22230668 未加载
评论 #22230962 未加载
novokover 5 years ago
There should be a page out there that lists Microsoft outages due to missed certificate or domain expiration. Like that hotmail one long time ago.<p>I would think at this point they would be their own major certificate authority and maybe domain registrar.
评论 #22229360 未加载
评论 #22230396 未加载
gwbas1cover 5 years ago
Another HN post mentioned that a lot of collaboration sites were down because many people are telecommuting due to the Wuhan virus.<p>I honestly thought this was why Teams was down for me.
评论 #22228375 未加载
matt_morganover 5 years ago
This has happened to me enough times to be embarrassing. It seems to happen to other people who you&#x27;d think have some sensible way to avoid it.<p>Is there a reminder service out there that specializes in your long-term expiring things? I&#x27;m not sure what would be different about it than a regular calendar, but it seems like many of us need something that makes this easier.
评论 #22227610 未加载
评论 #22227951 未加载
评论 #22227569 未加载
评论 #22228337 未加载
评论 #22227561 未加载
评论 #22227732 未加载
评论 #22228404 未加载
评论 #22227767 未加载
评论 #22228237 未加载
评论 #22227729 未加载
评论 #22229720 未加载
ChuckMcMover 5 years ago
It is an interesting side effect of the tenancy of software developers these days that any process that requires action on a &gt; 2 year interval is likely to fail, if the cycle is 5 years or more it will <i>always</i> fail.<p>The turnover insures that nobody in the department was there when the process was started&#x2F;last interacted with, and so it is off the collective organizational radar so to speak.
评论 #22229613 未加载
gjsman-1000over 5 years ago
I&#x27;m actually curious: Is there a market for a SaaS which simply keeps track of certificates and when they expire? (Perhaps even with an auto-Deploy new certificate mechanism?)
评论 #22227887 未加载
评论 #22228184 未加载
评论 #22227816 未加载
评论 #22228006 未加载
评论 #22228702 未加载
评论 #22227576 未加载
评论 #22227709 未加载
评论 #22228070 未加载
评论 #22228004 未加载
评论 #22227724 未加载
评论 #22228033 未加载
评论 #22227695 未加载
评论 #22227737 未加载
评论 #22228215 未加载
评论 #22228136 未加载
评论 #22227563 未加载
jamiesonbeckerover 5 years ago
They tweeted that it was an <i>authentication</i> certificate. I.e., probably not a regular TLS domain certificate or similar (still could be TLS client cert though), but probably more like a certificate&#x2F;key that one service used to log into another. A lot of microservice&#x2F;container&#x2F;kubernetes setups use them for all kinds of stuff, which is really a big step forward over password logins.<p>Not like it matters, but it kinda does, because those tend to be private and internally generated, and not necessarily signed by an external certificate authority.
评论 #22240302 未加载
certeraover 5 years ago
I&#x27;m going to shamelessly plug my project, Certera, here. It handles monitoring&#x2F;tracking, cert issuance and renewals and helps larger organizations manage their certificate needs more consistently.<p><a href="https:&#x2F;&#x2F;docs.certera.io" rel="nofollow">https:&#x2F;&#x2F;docs.certera.io</a>
评论 #22228997 未加载
评论 #22229811 未加载
_bxg1over 5 years ago
Amazing. A company like Microsoft could afford to hire an entire department to do nothing but make sure certificates don&#x27;t expire, but this still happens.<p>Jokes aside, I don&#x27;t understand how this problem hasn&#x27;t been solved in the general case.
评论 #22230652 未加载
评论 #22228854 未加载
ce4over 5 years ago
Does anyone know what endpoint&#x27;s certificate had expired?<p>Would be interesting what CA they used for it and if it&#x27;s a SAN certificate.<p>Edit: here&#x27;s the certificate log of the teams subdomain but I couldn&#x27;t find the one that expired today in it <a href="https:&#x2F;&#x2F;crt.sh&#x2F;?q=teams.microsoft.com" rel="nofollow">https:&#x2F;&#x2F;crt.sh&#x2F;?q=teams.microsoft.com</a>
评论 #22228127 未加载
评论 #22230682 未加载
评论 #22228790 未加载
cutlerover 5 years ago
Just listening to the number of complex shenanigans experienced sysadmins have to employ to keep up with the demands of managing HTTPS makes me wonder how on earth your average non-technical DIY static site developer has a chance in hell of keeping his site from failing modern browsers&#x27; requirements. Universal HTTPS is a bad joke.
评论 #22231639 未加载
评论 #22231666 未加载
sergiotapiaover 5 years ago
It happens - yesterday we went down for the same god damn reason. There has be a better solution.
cutlerover 5 years ago
Our HTTPS overlords have much to answer for. How many static sites, for example, really need HTTPS and the non-trivial maintenance involved in the average Apache&#x2F;Letsencrypt&#x2F;certbot setup? Talk about sledge-hammer to crack a nut. And renewals every 3 months?! Don&#x27;t get me started. Sure, the likes of Microsoft should be able to do better but isn&#x27;t there a message here? Beyond secure sites such as finance, government, logins and ecommerce the whole HTTPS certificate nonesense is a giant burden&#x2F;cost with no benefit.
评论 #22231998 未加载
chasd00over 5 years ago
when getting a site&#x2F;API on its feet, enabling https and the cert is usually the last thing to get done and an afterthought. Certs are easy to forget about but when they expire they shut.down.everything.
评论 #22231679 未加载
jlgaddisover 5 years ago
<p><pre><code> apt install ssl-cert-check</code></pre>
w0mover 5 years ago
ouch
krzatover 5 years ago
Teams is great improvement over Skype for Business, which was great improvement over Lync, but it&#x27;s still garbage. Interesting how the same company also made awesome VSCode.
评论 #22227661 未加载
评论 #22228373 未加载
评论 #22228100 未加载
评论 #22228295 未加载
评论 #22228164 未加载
评论 #22227618 未加载