Categories: CloudPCWorkspace

Microsoft Windows Azure Cloud Fails As SSL Certificate Expires

The Microsoft Windows Azure cloud suffered a a major outage, when an SSL security certificate for Azure Storage expired, breaking business applications, and Microsoft’s own Xbox Live, for twelve hours on Friday.

The company has offered a refund (as specified in service level agreements) to those affected, but has not yet explained how it allowed a certificate to expire, which is needed for secure access to data stored on the Azure cloud. The incident is an uncanny reminder of the failure caused one year ago when Windows Azure failed to take account of the extra Leap Year day in February, and has had commentators jaws dropping.

Windows Azure Cloud Of Death

“On Friday, February 22, Windows Azure Storage was affected by an expired certificate,” said Adrienne Hall, general manager, Microsoft Trustworthy Computing (pictured). “We have completed the restoration and all services are back online. For more information please go to the Service Dashboard.”

Anyone storing critical data on a cloud service should be using SSL (secure sockets layer) to access that data, and when this failed, critical applications trying to use Azure Storage failed.

Anyone storing critical data on a cloud service should be using SSL (secure sockets layer) to access that data, and when this failed, critical applications trying to use Azure Storage failed.

Discussion on the Windows Azure Forums quickly identified the problem  and produced evidence in the form of a screenshot (shown here). The most obvious temporary fix was to switch off the secure protocol HTTPS, and use HTTP, but users running real business data on their Azure cloud instances might have been reluctant to do that.

Anger quickly swelled, with commentators lambasting Microsoft for a “trivial” error. “This is quite a stupid mistake,” said analyst Clive Longbottom of QuoCirca. “All the technology was working – they just forgot to pay the bill for a certificate.”

This kind of error is very easy to make, but this does not let Microsoft off the hook, commentators said, “It does happen to private sites as well – regularly,” commented Longbottom.

Last year’s embarassing Leap Year error also hit Windows Azure’s certificates, and Microsoft did – eventually – publish a very full explanation of how the mistake was made.

Check out some more Tech Failures – try our quiz!

Peter Judge

Peter Judge has been involved with tech B2B publishing in the UK for many years, working at Ziff-Davis, ZDNet, IDG and Reed. His main interests are networking security, mobility and cloud

Recent Posts

Apple Announces Record Share Buyback, Amid iPhone Sales Decline

Investor appeasement? Apple unveils huge $110 billion share buyback program, as sales of iPhone decline…

2 hours ago

Tesla Backs Away From Gigacasting Manufacturing – Report

Tesla retreats from pioneering gigacasting manufacturing process, amid cost cutting and challenges at EV giant

19 hours ago

US Urges No AI Control Of Nuclear Weapons

No skynet please. After the US, UK and France pledge human only control of nuclear…

20 hours ago

LastPass Separates From Parent After Security Incidents

New chapter for LastPass as it becomes an independent company to focus on cybersecurity, after…

22 hours ago

US To Ban Huawei, ZTE From Certifying Wireless Kit

US FCC seeks to ban Chinese telecom firms at centre of national security concerns from…

1 day ago