05-21-2019 05:23 PM
We have a Scada System that sends out email alerts when there is an alert generated in the system. This Scada System is segregated on its own Vlan with an ACL allowing SMTP traffic so it can send out the alert email. In the ACL, I specified all the IPs from Microsoft of their smtp.office365.com, and I allowed DNS traffic so It can resolve the smtp.office365.com to one of those IPs allowed through. It works fine for about a month and then all of a sudden we get an error saying “Failed to send email message The remote certificate is invalid according to the validation procedure”. Once I take down the ACL and allow full communication, it works fine. What other traffic do I need to allow through the ACL so it can validate the certificate for Office 365, anyone else come across something like this before?
05-21-2019 11:44 PM
first a remark, I guess this is the wrong community for your post, this is Cisco routing, not office
but here some things you can check
"I specified all the IPs from Microsoft of their smtp.office365.com"
1) did you check for any changes?
Microsoft specifies some ranges, but can add /remove IP's at any time!
2) maybe the root-certificate list on the Scada system needs update?
with outdated root/intermediate certificates the remote certificate cannot be validated.
05-22-2019 07:45 AM
05-22-2019 08:01 AM
check for time synchonization
05-22-2019 09:10 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide