Jump to content

Google Lets SMTP Certificate Expire


Reefa

Recommended Posts

Whoops! It appears as though Google on Saturday let a digital certificate expire that was used to secure its smtp.google.com domain, the domain used by Gmail and Google Apps users to send outgoing email.

The issue appears to stem from Google Internet Certificate Authority G2 which has become invalid. Google Internet Authority G2 issues digital certificates for Google web sites and properties, indicating that the issue will likely stem beyond the SMTP certificate and affect other Google services levering SSL.

Users took to Twitter on Saturday to vent as many recieved security warnings from email clients such as Microsoft Outlook when attempts were made to connect securely to smtp.google.com.

"This Certificate has an Invalid Issuer," was one message seen by SecurityWeek in Microsoft Outlook for Mac as of Saturday morning.

Root-Certificate-Not-Trusted.png

According to Google, Google Internet Authority G2 is operated in accordance with the latest version of the CA/Browser Forum Baseline Requirements and is signed by the GeoTrust Global CA.

"We're aware of a problem with Gmail affecting a majority of users. The affected users are able to access Gmail, but are seeing error messages and/or other unexpected behavior," Google posted to its Gmail status page Saturday afternoon.

At 3:46PM, Google posted another update to say the issue has been resolved, but without any explaination of what happened.

"The problem with Gmail should be resolved. We apologize for the inconvenience and thank you for your patience and continued support. Please rest assured that system reliability is a top priority at Google, and we are making continuous improvements to make our systems better," the update said.

A check by online service SSL Shopper earlier on Saturday showed one of the root or intermediate certificates expired on April 4, 2015, more specifically the second certificate in the chain as detailed below. The certificate in question has since been renewed and is now set to expire on Dec. 31, 2016.

smtp.google.com_chain-expired.jpg

Google did not immediately respond to a request for comment.

Google-SMTP-Expired-Certificate.jpg

securityweek.com

Link to comment
Share on other sites


  • Views 1.1k
  • Created
  • Last Reply

Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...