Skype for Business Server Access Edge not starting after 15th Jan? Quovadis.........
An interesting start to the week.
On the 15th of January 2021, Quovadis/Digicert revoked an intermediate certificate without any apparent notification.
As 'luck' would have it some patching happened shortly after and the server rebooted. The services would not come up.
After some checking of new software deployments (security/management), validating patching, restoring VMs from backup it was discovered that changing the system clock back to the 14th Jan let the services start. With such a specific cut-off date/time and the service event logs (not always pointing in the right direction!) it pointed a finger at certificate revokcation. We knew the public certs weren't due to expire for 6 months and the dates on the intermediate and root cert were all fine.
Some google-fu found that we were not alone
AusCERT statement “QuoVadis Global SSL ICA G3” issue impacting multiple customers
QuoVadis Intermediate Revoke Update | Jisc community
Even though we double-checked the certificate and even downloaded and re-applied the certificate, the certificate chain supplied was still the original package and didn't include the updated/re-issued intermediate certificate.
Downloading and applying the intermediate certificate itself http://trust.quovadisglobal.com/qvsslg3.crt fixed the issue immediately.
Also remember you may need to patch your gateways too if you have public certs (ie Teams Direct Routing).
The issue only appeared once the services were restarted so it may continue to raise its head for a wee while.
Comments
Post a Comment