The security certificate has expired or is not yet valid

%3CLINGO-SUB%20id%3D%22lingo-sub-177489%22%20slang%3D%22en-US%22%3EThe%20security%20certificate%20has%20expired%20or%20is%20not%20yet%20valid%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-177489%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Guys%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20am%20trying%20to%20connect%20my%20office365%20account%20to%20my%20Desktop%20Outlook%202016%20application%20and%20i%20am%20getting%20the%20following%20message%20%22The%20security%20certificate%20has%20expired%20or%20is%20not%20yet%20valid%22%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20was%20searching%20for%20this%20issue%20but%20i%20didn't%20find%20any%20solution.%3C%2FP%3E%0A%3CP%3EDoes%20anyone%20know%20what%20to%20do%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThank%20you!!%3C%2FP%3E%0A%3CP%3EStavros%3C%2FP%3E%0A%3CP%3E%3CIMG%20src%3D%22file%3A%2F%2F%2FC%3A%5CUsers%5Cbuggy%5CAppData%5CLocal%5CTemp%5CSNAGHTML5100f64a.PNG%22%20width%3D%22353%22%20height%3D%22246%22%20border%3D%220%22%20%2F%3E%3CIMG%20src%3D%22file%3A%2F%2F%2FC%3A%5CUsers%5Cbuggy%5CAppData%5CLocal%5CTemp%5CSNAGHTML5100f64a.PNG%22%20width%3D%22353%22%20height%3D%22246%22%20border%3D%220%22%20%2F%3E%3CIMG%20src%3D%22file%3A%2F%2F%2FC%3A%5CUsers%5Cbuggy%5CAppData%5CLocal%5CTemp%5CSNAGHTML51011ea3.PNG%22%20width%3D%22353%22%20height%3D%22246%22%20border%3D%220%22%20%2F%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-177489%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-299479%22%20slang%3D%22en-US%22%3ERe%3A%20The%20security%20certificate%20has%20expired%20or%20is%20not%20yet%20valid%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-299479%22%20slang%3D%22en-US%22%3EWell%2C%20in%20our%20case%20all%20was%20done%20by%20hosting%20provider%2C%20so%20I%20can't%20tell%20exactly%20how%20to%20do%20this.%20But%20when%20installing%20certificate%20you%20have%20to%20include%20intermediate%20certificate%20in%20a%20combined%20file.%20Thia%20will%20fix%20the%20Extra%20download%20entry%2C%20though%20I'm%20not%20sure%20it%20will%20fix%20your%20issue.%20I'm%20just%20guessing%20it%20might%20be%20related.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-299448%22%20slang%3D%22en-US%22%3ERe%3A%20The%20security%20certificate%20has%20expired%20or%20is%20not%20yet%20valid%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-299448%22%20slang%3D%22en-US%22%3E%3CP%3Ehi%20friend%2C%20i%20do%20it%20and%20it%20show%20this%20to%20me%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPath%20%231%3A%20Trusted%3C%2FP%3E%3CP%3E1%20Sent%20by%20server%20%3CA%20href%3D%22http%3A%2F%2Fwww.mydomain.com%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ewww.mydomain.com%3C%2FA%3E%3C%2FP%3E%3CP%3E2%20Sent%20by%20server%20GlobeSSL%20DV%20Certification%20Authority%202%3C%2FP%3E%3CP%3E3%20In%20trust%20store%20USERTrust%20RSA%20Certification%20Authority%20Self-signed%3C%2FP%3E%3CP%3EPath%20%232%3A%20Trusted%3C%2FP%3E%3CP%3E1%20Sent%20by%20server%20%3CA%20href%3D%22http%3A%2F%2Fwww.mydomain.com%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ewww.mydomain.com%3C%2FA%3E%3C%2FP%3E%3CP%3E2%20Sent%20by%20server%20GlobeSSL%20DV%20Certification%20Authority%202%3C%2FP%3E%3CP%3E3%20Extra%20download%20USERTrust%20RSA%20Certification%20Authority%3C%2FP%3E%3CP%3E4%20In%20trust%20store%20AddTrust%20External%20CA%20Root%20Self-signed%3CBR%20%2F%3EWeak%20or%20insecure%20signature%2C%20but%20no%20impact%20on%20root%20certificate%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EI%20managenment%20my%20web%20site%2C%20what%20i%20need%20to%20do%3F%3CBR%20%2F%3E%3CBR%20%2F%3EThanks!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-299438%22%20slang%3D%22en-US%22%3ERe%3A%20The%20security%20certificate%20has%20expired%20or%20is%20not%20yet%20valid%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-299438%22%20slang%3D%22en-US%22%3E%3CP%3EYou%20can%20check%20your%20domain%20here%20%3CA%20href%3D%22https%3A%2F%2Fwww.ssllabs.com%2Fssltest%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.ssllabs.com%2Fssltest%3C%2FA%3E%20it%20might%20give%20you%20an%20error%20that%20full%20chain%20of%20certificate%20is%20not%20installed%20(under%20Certification%20Path%20-%20press%20Click%20here%20to%20expand).%20It%20should%20say%20Sent%20by%20server%20in%20first%20two%20steps.%20If%20one%20of%20the%20steps%20is%20Additional%20download%2C%20then%20it%20is%20an%20issue.%20In%20that%20case%20you%20or%20your%20hosting%20provider%20have%20to%20install%20the%20certificate%20properly%20by%20combining%20full%20chain.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20had%20similar%20issue%20where%20mobile%20Skype%20app%20was%20complaining%20about%20bad%20certificate%20(though%20our%20page%20was%20showing%20green%20lock%20in%20browsers).%20I%20guess%20mobile%20apps%20can't%20get%20full%20chain%20on%20their%20own%20and%20expect%20it%20from%20a%20domain.%20Installing%20full%20chain%20fixed%20problem%20for%20us.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-299413%22%20slang%3D%22en-US%22%3ERe%3A%20The%20security%20certificate%20has%20expired%20or%20is%20not%20yet%20valid%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-299413%22%20slang%3D%22en-US%22%3E%3CP%3ENop%20i%20didn't%20find%20any%20solution.%20I%20just%20have%20the%20users%20to%20click%20a%20yes%20and%20all%20are%20sync%20normaly%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-298869%22%20slang%3D%22en-US%22%3ERe%3A%20The%20security%20certificate%20has%20expired%20or%20is%20not%20yet%20valid%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-298869%22%20slang%3D%22en-US%22%3EDo%20you%20solved%20it%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-177572%22%20slang%3D%22en-US%22%3ERe%3A%20The%20security%20certificate%20has%20expired%20or%20is%20not%20yet%20valid%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-177572%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Nuno%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20really%20appreciate%20your%20help.%20I%20will%20talk%20first%20with%20Hostgator%20to%20check%20if%20they%20can%20help%20and%20i%20will%20update%20again%20the%20post.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThank%20you%20in%20advance.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-177566%22%20slang%3D%22en-US%22%3ERe%3A%20The%20security%20certificate%20has%20expired%20or%20is%20not%20yet%20valid%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-177566%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Stravos%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20your%20autodiscover%20record%20point%20to%20that%20provider%20and%20is%20your%20architecture%2C%20you%20will%20need%20to%20talk%20with%20them%20and%20correct%20the%20certificate.%20If%20you%20can%20describe%20here%20more%20detail%20on%20your%20architecture%20and%20the%20full%20result%20of%20autodiscover%20test%20(Without%20sensitive%20information)%20we%20could%20help%20more.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-177564%22%20slang%3D%22en-US%22%3ERe%3A%20The%20security%20certificate%20has%20expired%20or%20is%20not%20yet%20valid%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-177564%22%20slang%3D%22en-US%22%3ESo%20do%20i%20have%20to%20talk%20with%20hostgator%20or%20is%20something%20that%20i%20can%20do%3F%20i%20am%20a%20little%20bit%20confused.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-177562%22%20slang%3D%22en-US%22%3ERe%3A%20The%20security%20certificate%20has%20expired%20or%20is%20not%20yet%20valid%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-177562%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Stavros%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThat's%20the%20cause%2C%20and%20keep%20post%20here%20how%20the%20cause%20is%20based%20on%20what%20you%20found%20on%20test%20autodiscover.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-177558%22%20slang%3D%22en-US%22%3ERe%3A%20The%20security%20certificate%20has%20expired%20or%20is%20not%20yet%20valid%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-177558%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Nuno%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20messages%20are%20%3A%3C%2FP%3E%0A%3CP%3EThe%20Microsoft%20Connectivity%20Analyzer%20is%20attempting%20to%20build%20certificate%20chains%20for%20certificate%20CN%3Dmydomain.com%2C%20OU%3DPositiveSSL%2C%20OU%3DHosted%20by%20Hostgator.com%20LLC%2C%20OU%3DDomain%20Control%20Validated.%3C%2FP%3E%0A%3CP%3EA%20certificate%20chain%20couldn't%20be%20constructed%20for%20the%20certificate.%3CBR%20%2F%3E%3CBR%20%2F%3Eand%20second%3CBR%20%2F%3ETesting%20TCP%20port%20443%20on%20host%20autodiscover.mydomain.com%20to%20ensure%20it's%20listening%20and%20open.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20specified%20port%20is%20either%20blocked%2C%20not%20listening%2C%20or%20not%20producing%20the%20expected%20response.%3CBR%20%2F%3E%3CBR%20%2F%3EThank%20you%20for%20your%20help%3C%2FP%3E%0A%3CP%3E%3CLI-WRAPPER%3E%3C%2FLI-WRAPPER%3E%3C%2FP%3E%0A%3CP%3E%3CLI-WRAPPER%3E%3C%2FLI-WRAPPER%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-177555%22%20slang%3D%22en-US%22%3ERe%3A%20The%20security%20certificate%20has%20expired%20or%20is%20not%20yet%20valid%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-177555%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Stavros%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ECan%20you%20test%20the%20Autodiscover%20test%20to%20see%20the%20problem%20%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22http%3A%2F%2Faka.ms%2Frca%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttp%3A%2F%2Faka.ms%2Frca%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-177553%22%20slang%3D%22en-US%22%3ERe%3A%20The%20security%20certificate%20has%20expired%20or%20is%20not%20yet%20valid%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-177553%22%20slang%3D%22en-US%22%3E%3CP%3Esubject%3C%2FP%3E%0A%3CP%3ECN%20%3D%20mydomainname.com%3CBR%20%2F%3EOU%20%3D%20PositiveSSL%3CBR%20%2F%3EOU%20%3D%20Hosted%20by%20Hostgator.com%20LLC%3CBR%20%2F%3EOU%20%3D%20Domain%20Control%20Validated%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-177551%22%20slang%3D%22en-US%22%3ERe%3A%20The%20security%20certificate%20has%20expired%20or%20is%20not%20yet%20valid%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-177551%22%20slang%3D%22en-US%22%3E%3CP%3EWhen%20you%20click%20the%26nbsp%3B%3CSTRONG%3EView%20Certificate%3C%2FSTRONG%3E%20button%20in%20the%20warning%2C%20what%20is%20the%20subject%20name%20that%20is%20displayed%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-177548%22%20slang%3D%22en-US%22%3ERe%3A%20The%20security%20certificate%20has%20expired%20or%20is%20not%20yet%20valid%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-177548%22%20slang%3D%22en-US%22%3E%3CP%3EThank%20you%20Christopher%20for%20your%20answer.%3C%2FP%3E%0A%3CP%3EThe%20only%20connectivity%20that%20office%20365%20has%20is%20with%20my%20hosting.%3C%2FP%3E%0A%3CP%3EI%20checked%20again%20my%20DNS%20functions%20and%20i%20believe%20that%20are%20correct.%3C%2FP%3E%0A%3CP%3EThe%20autodiscover%20should%20be%20%3CSPAN%20class%3D%22value-entry%22%3Eautodiscover.outlook.com%3C%2FSPAN%3E%20if%20i%20am%20right.%3C%2FP%3E%0A%3CP%3EAm%20i%20missing%20something%20here%3F%20%3A)%3C%2Fimg%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThank%20you%20again%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-177498%22%20slang%3D%22en-US%22%3ERe%3A%20The%20security%20certificate%20has%20expired%20or%20is%20not%20yet%20valid%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-177498%22%20slang%3D%22en-US%22%3E%3CP%3EThis%20looks%20like%20it%20could%20be%20a%20result%20of%20being%20in%20hybrid%20where%20the%20certificate%20being%20presented%20by%20your%20on-premises%20server(s)%20for%20autodiscover%20may%20not%20be%20valid.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hi Guys,

 

I am trying to connect my office365 account to my Desktop Outlook 2016 application and i am getting the following message "The security certificate has expired or is not yet valid"

 

I was searching for this issue but i didn't find any solution.

Does anyone know what to do?

 

Thank you!!

Stavros

15 Replies
Highlighted

This looks like it could be a result of being in hybrid where the certificate being presented by your on-premises server(s) for autodiscover may not be valid.

Highlighted

Thank you Christopher for your answer.

The only connectivity that office 365 has is with my hosting.

I checked again my DNS functions and i believe that are correct.

The autodiscover should be autodiscover.outlook.com if i am right.

Am i missing something here? :)

 

Thank you again

Highlighted

When you click the View Certificate button in the warning, what is the subject name that is displayed?

Highlighted

subject

CN = mydomainname.com
OU = PositiveSSL
OU = Hosted by Hostgator.com LLC
OU = Domain Control Validated

Highlighted

Hi Stavros,

 

Can you test the Autodiscover test to see the problem ?

 

http://aka.ms/rca

Highlighted

Hi Nuno,

 

The messages are :

The Microsoft Connectivity Analyzer is attempting to build certificate chains for certificate CN=mydomain.com, OU=PositiveSSL, OU=Hosted by Hostgator.com LLC, OU=Domain Control Validated.

A certificate chain couldn't be constructed for the certificate.

and second
Testing TCP port 443 on host autodiscover.mydomain.com to ensure it's listening and open.

 

The specified port is either blocked, not listening, or not producing the expected response.

Thank you for your help

Highlighted

Hi Stavros,

 

That's the cause, and keep post here how the cause is based on what you found on test autodiscover.

Highlighted
So do i have to talk with hostgator or is something that i can do? i am a little bit confused.
Highlighted

Hi Stravos,

 

If your autodiscover record point to that provider and is your architecture, you will need to talk with them and correct the certificate. If you can describe here more detail on your architecture and the full result of autodiscover test (Without sensitive information) we could help more.

Highlighted

Hi Nuno,

 

I really appreciate your help. I will talk first with Hostgator to check if they can help and i will update again the post.

 

Thank you in advance.

Highlighted
Highlighted

Nop i didn't find any solution. I just have the users to click a yes and all are sync normaly

Highlighted

You can check your domain here https://www.ssllabs.com/ssltest it might give you an error that full chain of certificate is not installed (under Certification Path - press Click here to expand). It should say Sent by server in first two steps. If one of the steps is Additional download, then it is an issue. In that case you or your hosting provider have to install the certificate properly by combining full chain.

 

We had similar issue where mobile Skype app was complaining about bad certificate (though our page was showing green lock in browsers). I guess mobile apps can't get full chain on their own and expect it from a domain. Installing full chain fixed problem for us.

Highlighted

hi friend, i do it and it show this to me

 

Path #1: Trusted

1 Sent by server www.mydomain.com

2 Sent by server GlobeSSL DV Certification Authority 2

3 In trust store USERTrust RSA Certification Authority Self-signed

Path #2: Trusted

1 Sent by server www.mydomain.com

2 Sent by server GlobeSSL DV Certification Authority 2

3 Extra download USERTrust RSA Certification Authority

4 In trust store AddTrust External CA Root Self-signed
Weak or insecure signature, but no impact on root certificate


I managenment my web site, what i need to do?

Thanks!

Highlighted
Well, in our case all was done by hosting provider, so I can't tell exactly how to do this. But when installing certificate you have to include intermediate certificate in a combined file. Thia will fix the Extra download entry, though I'm not sure it will fix your issue. I'm just guessing it might be related.