Microsoft forgot to renew their Office CDN certificate
old.reddit.com
old.reddit.com
just today i had to fix our internal certs because for the new ones someone forgot to include the intermediate cert in the chain, making it impossible to use a specific CLI tool. web browsers didn't complain, just the CLI sync tool :)
In the Dept I was in, it was expected the downstream system people would create the certs, and of course I would say 85% of them did not even know what a cert is. When renewal time came, we got blank stares when we mentioned the private cert. Or the person who created the cert left and never trained their replacement. Crazy situation.
I hope things changed since I left.
He learned through Slashdot, an online discussion group, that Microsoft had an outstanding $35 fee to Network Solutions (NSI) for the Passport.com Web address. The Passport site verifies user identification and passwords for access to Hotmail and about 25 other Microsoft services.
Chaney, 31, quickly paid the fee with his credit card, restoring service to Hotmail users.
https://www.cnet.com/tech/services-and-software/oregon-compa...
> Validity
> Not Before - Fri, 18 Aug 2023 02:17:43 GMT
> Not After - Thu, 27 Jun 2024 23:59:59 GMT
> Subject Alternative Name
> DNS Name - cdn.entity.osi.office.net
> DNS Name - cdn.entity.osi.officeppe.net
> DNS Name - cdn.uci.edog.officeapps.live.com
> DNS Name - cdn.uci.officeapps.live.com
> DNS Name - uci.cdn.office.net
> DNS Name - uci.edog.cdn.office.net
always thought that using *.domain.net for home-use was cool, because that way random people don't know what kinds of subdomains i use.
turns out they can find it out by just checking all the certs for my domain. well. the more you know.
anyways, what i liked about caddy was how easily it handles SSL-certs, for sure makes it easier to use! :) gonna have to look into how i can give a wildcard-cert to my rev-proxy.
sounds like i got myself a project for this weekend, implement a wildcard cert for my rev-proxy at home :)
EDIT: i guess the logs would still show the old certs, so my subdomains would still be exposed. huh. at least future subdomains would be hidden.
EDIT2: are there more ways for subdomains to get exposed, other than through DNS or SSL-Certs?
i got a wildcard-cert, implemented it on my proxy, everything works!
unfortunately, to be stealthy, i almost have to switch to a different domain. then request a new public IP, and switch.
I had the same horrified realization a few years ago when someone explained Certificate Transparency[1] to me.