Oops – Microsoft Certificate expired when logging on with Live ID

When signing in to a Microsoft site this evening I received a security warning from Firefox. Strange, I was convinced the site was genuine and I had not followed a spoofed phishing link to get there. How could this be?

I chose to continue using the “Add exception” button to get to the screen where I could see the certificate details. Nothing wrong with the certificate issue, path and so on, except that it expired a few hours ago at 18:26 GMT:

Expired Microsoft Certificate

This certificate is not actually for live.com that runs the logon part of the process, but profile.microsoft.com which looks after the other parts of the page which wrap round this. So, not vital but likely to cause much confusion and FUD until they get a new certificate to fix the problem.

Do you know when your certificates expire? And all your different domain names? What about other vital contracts which would stop you doing business if they expired suddenly? How do you manage all of these; is it a central business policy or does it just come down to one overworked IT Manager’s Outlook calendar?