Exchange 2019 Mitigation service error 1008

Dmitry Horushin 61 Reputation points
2022-06-10T09:57:22.21+00:00

Hi,
I regularly receive error 1008
Exception encountered while fetching mitigations : System.Exception: This XML is not deemed safe to consume since Response xml's signing cert is invalid or not from microsoft

The issue started June 9.

Any suggestions?

King regards,
Dmitry

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,355 questions
{count} votes

Accepted answer
  1. Andy David - MVP 142.2K Reputation points MVP
    2022-06-13T14:48:25.207+00:00
    0 comments No comments

4 additional answers

Sort by: Most helpful
  1. Luis Rodriguez 6,191 Reputation points Microsoft Employee
    2022-06-10T11:24:19.17+00:00

    Hello @Dmitry Horushin

    Welcome to Microsoft Q&A Platform,

    Please refer to the thread below as it's related to the same scenario:

    https://learn.microsoft.com/en-us/answers/questions/577935/mitigation-service-cert-xml-tls-error.html

    I hope this helps!

    ----------

    Please don’t forget to "Accept the answer" and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.

    0 comments No comments

  2. Joyce Shen - MSFT 16,641 Reputation points
    2022-06-13T02:07:25.277+00:00

    Hi @Luis Rodriguez

    Yes, Event 1008 with the same source will be logged for any errors that are encountered, such as when the EM service cannot reach the OCS(Office Config Service).

    Ensure that your Exchange servers can communicate with the Internet to validate the certificate chain.

    simulate the behaviour of the EEMS by getting the test page with a browser (https://officeclient.microsoft.com/getexchangemitigations). For those of you not being familiar - look at the schema links in the XML document as well as the certificate of the URL and check all the certificate chaining, revocation lists URLs and so on.
    For the IPs compare the blocked IPs with the following networks and allow them:
    https://www.microsoft.com/en-us/download/details.aspx?id=53602
    https://www.gstatic.com/ipranges/goog.json
    https://github.com/SecOps-Institute/Akamai-ASN-and-IPs-List/blob/master/akamai_ip_cidr_blocks.lst


    If an Answer is helpful, please click "Accept Answer" and upvote it.

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  3. Dmitry Horushin 61 Reputation points
    2022-06-13T14:36:56.26+00:00

    Hi,
    Thank you for your answers and questions.

    1) Error 1008 appears every hour on all Exchange servers.
    2) There is no problems to connect to https://officeclient.microsoft.com/getexchangemitigations
    Browsers on all servers return the same answer. I think that it's something wrong with the signature as it's described on the reference of @nak

    Best regards,
    Dmitry

    0 comments No comments

  4. Dmitry Horushin 61 Reputation points
    2022-06-14T05:44:58.923+00:00

    Hi, Andy.
    Thank you for providing details.
    Now the issue is resolved.
    Have a nice day!
    Dmitry

    0 comments No comments