U

Thursday, August 17th, 2023 12:11 AM

Closed

idm.xfinity.com has revoked certificate preventing me from logging into my account, How can I get this fixed

I am not able to login to my account due to my security software detecting the revoked certificate.
Here is part of the report from SSLLabs.

SSL Report:  idm.xfinity.com  (2001:558:feed:dc:0:0:0:18)
Assessed on:  Wed, 16 Aug 2023 18:55:48 UTC |  Clear cache

Summary
Overall Rating
F
0
20
40
60
80
100
Certificate
 
Protocol Support
 
Key Exchange
 
Cipher Strength
 

Visit our  documentation page for more information, configuration guides, and books. Known issues are documented  here.
This server's certificate is not trusted, see  below for details.
Certificate #1: RSA 2048 bits (SHA256withRSA)
Server Key and Certificate #1
Subject *.identity.xfinity.com
Fingerprint SHA256: fbaae4bb73ed1078a0cbcc1fdd85bd44de7c9270b3bc0fb9e636fa615db3a90b
Pin SHA256: ccaLrMZ1T2jQh1ok0dqhUVuz0FzM1g2bPmUTBlbhzMk=
Common names *.identity.xfinity.com
Alternative names *.identity.xfinity.com activate.courtesyflex.xfinity.com care-portal-dev.xfinity.com care-portal-qa.xfinity.com care-portal-st.xfinity.com care-portal.xfinity.com courtesyflex.xfinity.com developers-st.xfinity.com developers.xfinity.com idm-dev.xfinity.com idm-qa.xfinity.com idm-st.xfinity.com idm.xfinity.com idp-dev.comcast.net idp-qa4.comcast.net idp-st.comcast.net idp.comcast.net login-dev.xfinity.com login-qa.xfinity.com login-st.xfinity.com login.comcast.net login.xfinity.com oauth-dev.xfinity.com oauth-qa.xfinity.com oauth-st.xfinity.com oauth.xfinity.com rest-dev.auth.xfinity.com rest-qa.auth.xfinity.com rest-st.auth.xfinity.com rest.auth.xfinity.com security-console-dev.aws-np.identity.xfinity.com security-console-qa.aws-np.identity.xfinity.com security-console-st.aws.identity.xfinity.com security-console.aws-np.identity.xfinity.com security-console.aws.identity.xfinity.com tve-dev.auth.xfinity.com tve-qa.auth.xfinity.com tve-st.auth.xfinity.com tve.auth.xfinity.com wifi-dev.auth.xfinity.com wifi-qa.auth.xfinity.com wifi-st.auth.xfinity.com wifi.auth.xfinity.com xdn-dev.xfinity.com xdn-qa.xfinity.com xdn-qa4.xfinity.com xdn-st.xfinity.com xdn.xfinity.com xtv-pil-dev.xfinity.com xtv-pil-qa.xfinity.com xtv-pil-st.xfinity.com xtv-pil.xfinity.com
Serial Number 008c2dd172dca7b3f46060cae1f1e034a2
Valid from Fri, 19 Aug 2022 00:00:00 UTC
Valid until Sat, 19 Aug 2023 23:59:59 UTC (expires in 2 days, 23 hours)
Key RSA 2048 bits (e 65537)
Weak key (Debian) No
Issuer COMODO RSA Organization Validation Secure Server CA
AIA: http://crt.comodoca.com/COMODORSAOrganizationValidationSecureServerCA.crt
Signature algorithm SHA256withRSA
Extended Validation No
Certificate Transparency Yes (certificate)
OCSP Must Staple No
Revocation information CRL, OCSP
CRL: http://crl.comodoca.com/COMODORSAOrganizationValidationSecureServerCA.crl
OCSP: http://ocsp.comodoca.com
Revocation status Revoked   INSECURE
DNS CAA No (more info)
Trusted No   NOT TRUSTED (Why?)
Mozilla  Apple  Android  Java  Windows 

Official Employee

 • 

819 Messages

9 months ago

@user_307ab5 I've passed this along internally to the folks that should be responsible.  I'll need them to comment before I can give further details.

New Poster

 • 

24 Messages

9 months ago

This is exactly the same problem I came here to post.  I've been getting this message for several days after entering my password to get into my email:

Secure Connection Failed

An error occurred during a connection to idm.xfinity.com. Peer’s Certificate has been revoked.

Error code: SEC_ERROR_REVOKED_CERTIFICATE

    The page you are trying to view cannot be shown because the authenticity of the received data could not be verified.
    Please contact the website owners to inform them of this problem.

I usually use Thunderbird, which can access my email.

The other oddity is if I reload the xfinity home page after getting this message, it shows me signed in and I can access my email then.  This is clearly a problem that xfinity needs to solve.

(edited)

Official Employee

 • 

819 Messages

@jiminnm​ (and others), they're aware, and they're working to resolve the issue.

Visitor

 • 

2 Messages

9 months ago

Yes, I too have been having this same issue

Your connection is not private
NET::ERR_CERT_REVOKED

idm.xfinity.com normally uses encryption to protect your information. When Vivaldi tried to connect to idm.xfinity.com this time, the website sent back unusual and incorrect credentials. This may happen when an attacker is trying to pretend to be idm.xfinity.com, or a Wi-Fi sign-in screen has interrupted the connection.

You cannot visit idm.xfinity.com right now because its certificate has been revoked. Network errors and attacks are usually temporary, so this page will probably work later.

Contributor

 • 

20 Messages

9 months ago

I am just confirming that a client and I are experiencing the same problem. Both computers in question are running Windows 11 (with the latest updates installed) and with the latest version of Mozilla Firefox (version 116.0.3). However, using Microsoft Edge allows access to Xfinity email.

Visitor

 • 

1 Message

9 months ago

Hey @XfinityAlex , any update??

Official Employee

 • 

819 Messages

@dan.gagnon​ I just checked from my browser, looks okay.  Are you still having an issue?  If so, try an icognito window perhaps. 

Official Employee

 • 

1.2K Messages

9 months ago

Hello there @user_307ab5 thanks for using our Forums to contact our Team. We are sorry to hear that you are having issues trying to access your account. What kind of browser are you using this on and have you attempted any incognito/private options?

2 Messages

@XfinityJorge​ I contacted a Comcast rep before creating this post, we tried everything you mention and more without success.

Earlier today I used ssllabs to recheck the certificates, it appears the revoked certificates have been replaced as they now valid.
My logins are currently successful.

(edited)

Official Employee

 • 

1.1K Messages

@user_307ab5 Thank you for the update and for letting us know your logins are now successful!

I am an Official Xfinity Employee.
Official Employees are from multiple teams within Xfinity: CARE, Product, Leadership.
We ask that you post publicly so people with similar questions may benefit from the conversation.
Was your question answered? Please, mark a reply as the Accepted Answer.tick
forum icon

New to the Community?

Start Here