SSL Certificate Warning | Office 365 / Exchange & CloudFlare
Email warning popup relating to SSL and cannot verify the server identity message when using Outlook Apple Mail iPhone email

SSL Certificate Warning – Office 365 / Exchange Online and CloudFlare


Symptoms

  • Your device connects to your Office 365 / Exchange Online email account
  • The device pops up a security or SSL certificate warning complaining of:
    • an invalid name
    • “Cannot Verify Server Identity”
    • “A secure connection could not be established with the server”
    • or equivalent message
  • When you view the certificate details, you’re being issued an SSL certificate in the name of CloudFlare (cloudflare-dns.com)
  • You now scratch your head and wonder why CloudFlare is issuing certificates when you’re trying to talk to Microsoft Office 365

 

Cause and Remedy for SSL Certificate Warnings

CloudFlare is nothing to do with Office 365. So the question is, why does CloudFlare return a certificate when you were trying to communicate with Microsoft?

CloudFlare provide DNS services. Without technical detail, this is basically what makes the internet work, in the way most people understand and use it. DNS ensures that all your internet traffic reaches the correct destinations.

CloudFlare offers a service called DNS Proxying. In simple terms, it intercepts all requests to your domain (e.g your website). It then forwards them on to your web server if they look legitimate. So, any malicious attacks involving a denial-of-service for example (a big flood of traffic designed to stop your website from working) do NOT hit your website directly. They are hoovered up by CloudFlare and blocked.

If your nameservers are with CloudFlare (ask your IT people), you should log into CloudFlare and check to see if the autodiscover “A” record is being proxied. If so, CloudFlare is intercepting any requests by your device when it attempts to use this vital Microsoft autodiscover process, and passes it through to Microsoft. CloudFlare acts as a proxy.

This explains why you get a mismatch on the certificate and how CloudFlare is mysteriously getting in the way, even though we’re trying to talk to Microsoft. To be fair, it seems that most of the time it’s seamless and works fine anyway. But if you get repeated password prompts in Outlook or any kind of SSL certificate / security warning about an invalid certificate or mismatched name, this is likely to be the cause.

Since you don’t care if Microsoft receives a DoS attack, as it’s not your problem, it’s fine to turn off proxying for the autodiscover record on its own. This means that when your device attempts to retrieve email, it talks to the autodiscover service. But Cloudflare doesn’t intercept that request and hence you don’t get the SSL warning.

Real-Time Feedback

When we solve a support ticket, clients are given the choice of leaving good or bad feedback along with an optional comment. We post the 10 most recent comments here automatically and in real-time. You can view even more on our page.

Date Name Comments
Nov 24th Andy K Exceptional service as always from the whole team, thank you Megan, Dean, Michael and Lochie : ) Many thanks, Chris and Andy
Nov 23rd Will Lochie, as always, was friendly, professional and fixed the problem (which was a dodgy virgin connection)
Nov 21st Walter O Purple Computing is our go too computer consultant. Competent, responsive, and focused on fixing our challenges permanently. I could not recommend Dean and his team more highly. They function as our IT department at a fraction of the cost.
Nov 20th Yvonne C Thanks Dean I didn’t expect such a prompt reply on a Sunday.! Much appreciated
Nov 18th Nigel T - well done James, great speedy service...
Nov 17th Sabira S very thorough and just one thing missed, which was fixed within 2 minutes of mentioning by email, top score...
Nov 15th Mark K Quick response that answered my question!
Nov 11th Leah E My issue was dealt with quickly and efficiently. I can't fault the service.
Nov 10th Ceri C Excellent service as always
Nov 7th Karen W Thank you Lochie for responding so quickly today Kindest regards Karen Book Keeper Space Kitchens & Bathrooms Ltd