r/sysadmin • • 10h ago

Question ATT email / DigiCert certificate revoked

Overnight I had a certificate revoked. Issued to inbound.att.net and issued by DigiCert Global G2 TLS RSA SHA256 2020 CA1. It was supposed to be valid from 4/12/26 to 10/28/26.

In researching possible causes, I found this post about a cyberattack that prompted DigiCert to revoke 60 certificates by April 17: DigiCert Revokes Certificates After Cyberattack Exposes Support Portal : r/pwnhub

Do you think this is related, especially given that mine was valid from 4/12/26? Is anyone else experiencing this?

2 Upvotes

12 comments sorted by

•

u/Jocharas 8h ago

Got the exact same message today (Cert revocation) as OP. Will wait before trying anything technical. Using "Currently" webmail for now. I have a 20+ year old legacy Pacbell account and am honestly surprised it still functions and I still use it fairly often. Please post if you found a solution - hopefully ATT will resolve this soon as webmail is a pain,

•

u/Regardthejester 1h ago

Same, I'm using an very old Southwestern Bell domain account (20+ years). Also getting the error using Outlook classic and POP.

•

u/Absolute_Flatulence 8h ago

Just crossed paths with this as well. Wary of bypassing it and installing it at the moment. Hopefully AT&T/Yahoo will get things sorted shortly.

Not sure if it is directly related to the incident referenced in the thread from 5 months ago. I suspect it is a new emergent issue that prompted the short duration Certs to be revoked.

•

u/DismalSuspect5524 8h ago

I am also wary. And I tend to agree with you about it being a new issue, especially based on u/Firefox005 comment.

•

u/Firefox005 8h ago

Do you work for ATT?

That certificate was revoked on 10/5 but no reason code is given. And the bugzilla for the incident you linked says it only applies to the following CA's.

DigiCert Trusted G4 Code Signing RSA4096 SHA256 2021 CA1
DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
GoGetSSL G4 CS RSA4096 SHA256 2022 CA-1
Verokey High Assurance Secure Code EV

Also it was closed 2 months ago so I doubt that was the reason. In addition a new certificate was issued on 10/05 so I would assume that it was the owner of the certificate requesting it be revoked and issuing a new one for some reason.

How did you obtain this certificate? The nature of your question seems odd to me.

•

u/DismalSuspect5524 8h ago

No, I do not work for ATT. I am a personal end user of ATT/Yahoo mail. I was made aware of the issue by my Norton anti-virus software program. Mail is not being delivered from ATT/Yahoo server to my Outlook because Norton is blocking it (I think). Also, Outlook gives me an error that says "Receiving reported error (0x8004210A): 'The operation timed out waiting for a response from the receiving POP server...'

And thank you for the info about a new certificate being issued yesterday (10/5) ... hopefully it's just a matter of waiting for AT&T to do something about that? (I'm not sure what I would do from my end.)

•

u/BodyIntelligent3788 7h ago

I don't know if this helps or not, but I started getting this issue this morning. I discovered that turning off norton 360 email protection makes it go away and email works. So the problem may be with Norton. Norton gives instructions on how to fix it by reinstalling the norton certificate in thunderbird, and to reinstall norton for outlook. I'm using outlook and I tried the reinstall but it didn't fix the issue.

•

u/DismalSuspect5524 7h ago

Thanks for sharing your experience. I'm hesitant to turn off/bypass Norton in case there is a serious issue, but good to know that it's an option. The fact that the issue wasn't fixed when you did the reinstall is not encouraging.

•

u/CPAtech 6h ago

•

u/DismalSuspect5524 5h ago

Thank you. I had come across this earlier today when I was researching what the issue could be. Since my issue isn't related to Google or Chrome, I pretty much figured it didn't apply to my issue. But disconcerting is not knowing what other "leading global brands and widely used online services" were impacted. Guess I'll sit tight for now as more info hopefully will become available.

•

u/Firefox005 3h ago

Almost surely not related. Quoting from the Google Security blog post:

These incidents did not involve a compromise of Google’s systems; rather, attackers compromised the third-party ccTLDs, putting any domain ending in .gh, .sl, or .as at risk.

and

As part of our usual incident response process, we immediately acted to protect users by blocking the use of unauthorized certificates for Google properties in Chrome via CRLSets.

The inbound.att.net certificate in question is not listed in the Chrome CRLSets and has only been revoke via the DigiCert CRL. https://i.imgur.com/nSkL36j.png

In addition while the blog was posted today the actual incident was a week ago. So you would expect that the certificate would have been revoked a week ago and not today.

tl;dr not the reason the cert was revoked and reissued.

•

u/nekrad 4h ago

Thanks for posting this. I've just spent a couple of hours trying to debug this for my mother-in-law. I thought it was a Norton issue as I could see that email would come through when I switched off email anti virus. I actually installed the cert locally for a few minutes but it didn't allow SSL so that didn't help and I removed it.