Hello @esox07
You are seeing this Norton pop-up because the URL in question, extensionwebstorebase.edgesv.net, is a known obsolete domain previously used by Microsoft Edge for extension updates, and its associated security certificate has genuinely expired.
Norton is accurately detecting the expired certificate and blocking the connection as a standard security precaution. However, this specific instance is considered a false positive because the URL is no longer in use and poses no actual security threat.
Here is a breakdown of why this is happening and what you can do:
Why the Alert Appears
- Expired Certificate: The primary reason for a security alert is that the server certificate or one of its issuers for
extensionwebstorebase.edgesv.net is out of date. Security software like Norton is designed to block connections to sites with expired certificates to protect you from potential risks, as outdated certificates can indicate an unmaintained or potentially compromised website.
- Obsolete Domain: Microsoft has confirmed that the
extensionwebstorebase.edgesv.net domain is obsolete and no longer in use. Microsoft Edge, for various reasons (likely related to remnants of extensions or internal update checks), still occasionally attempts to connect to this old URL.
- Norton’s Action: Norton Safe Web is doing its job by identifying the expired certificate and blocking the connection attempt. Since the URL is obsolete and safe to ignore, the warning is a false positive.
How to Address the Pop-up
The pop-ups are annoying, but the situation has no security implications. You can take the following steps to manage them:
- Ignore the warning: Microsoft has stated the issue can be safely ignored.
- Ensure Edge is updated: Microsoft planned to remove the obsolete URL reference in a future update to the Edge browser, so keeping your browser updated might resolve the issue automatically over time.
- Submit feedback to Microsoft: You can use the feedback tool within the Edge browser (press
Alt + Shift + I) to report the issue, which might encourage developers to prioritize a fix.
- Manage Norton settings (optional): If the pop-ups are very frequent and bothersome, you might be able to add an exclusion or “whitelist” the specific domain in your Norton firewall or Safe Web settings to stop the alerts, though you should exercise caution when doing this for other, potentially malicious, URLs.
=================================
You’ve cleared Edge cookies n’ cache?
You’ve cleared Windows temp files?
You’ve added Exclusions?
You’ve reset Edge Sync?
===================================
You are seeing a popup because your Norton 360 Safe Web engine is blocking a connection attempt by the Microsoft Edge browser to a specific, now obsolete, Microsoft domain with an expired security certificate. This alert is a false positive from Norton and can safely be ignored.
Explanation of the Issue
- Obsolete URL: The domain
extensionwebstorebase.edgesv.net is a URL that is no longer in use by Microsoft.
- Expired Certificate: Because the URL is obsolete, Microsoft allowed its security certificate to expire, as it is not needed for an inactive service.
- Persistent Code: The Microsoft Edge browser still contains old code that occasionally attempts to connect to this defunct domain, likely when checking for extension updates.
- Norton’s Action: Norton Safe Web correctly identifies that the site’s certificate has expired and blocks the connection attempt as a security precaution, triggering the alert you see.
- Benign Alert: The alert is legitimate in that the certificate is indeed expired, but the connection attempt itself poses no security risk because the domain is inactive and the connection is blocked before any data exchange.
What You Can Do
Microsoft has stated the issue would be addressed in a future update to Edge, but the alert persists for some users. Here are some steps you can take:
- Ignore the Alert: The warning can be safely ignored, as there are no actual security implications.
- Update Software: Ensure both your Norton 360 application and Microsoft Edge browser are updated to their latest versions, as updates may eventually resolve the underlying code issue.
- Check System Date: In rare cases, an incorrect system date on your computer can cause valid certificates to appear expired. Verify your system’s date and time are correct.
- Manage Notifications: The popups can be annoying. You may consider adjusting Norton’s notification settings temporarily or reporting it as a false positive to Norton support through the Norton Community forums.
- Clear Browser Cache: Clearing your Edge browser’s cache and cookies can sometimes help resolve connection issues.
====================================
It is unlikely to be a single, specific extension that is causal. The connection attempt to the obsolete extensionwebstorebase.edgesv.net URL seems to originate from the core Microsoft Edge browser code itself, specifically the built-in mechanism that checks for updates to all installed extensions.
This means the issue is generally a browser-level behavior, not tied to one particular add-on you’ve installed. The Edge browser uses this domain as a general update server URL for extensions, and because the domain’s security certificate expired, your Norton software flags any attempt to reach it.
How to Identify if an Extension is Causal (Troubleshooting)
Although the issue is generally browser-wide, you can try these steps to see if a specific extension is a trigger point:
- Disable All Extensions Temporarily: Go to the Edge extensions management page by typing
edge://extensions/ into your address bar. Turn off the toggle for every extension you have installed.
- Monitor Popups: Close and reopen Edge. See if the Norton popups stop appearing.
- Re-enable One by One: If the popups stop, re-enable your extensions one at a time, using your browser normally for a few minutes between each activation.
- Isolate the Culprit: If the popups resume after enabling a specific extension, you’ve found the add-on that triggers the legacy code most frequently.
Even if you find a specific extension, the underlying problem remains an issue with the obsolete URL in Microsoft’s update mechanism. You can provide feedback to Microsoft about this persistent issue using the built-in feedback tool by pressing Alt+Shift+I in Edge.
=================================
It is possible, but not definitively confirmed, that the Edge Sync feature could be a contributing factor.
While the primary cause is a piece of legacy code within the Edge browser itself that makes a request to the obsolete domain, the sync feature manages and synchronizes browser data, including extensions, across devices.
How Edge Sync might be involved:
- Extension Data: Edge Sync ensures your extensions and their settings are consistent everywhere you sign in.
- Triggering the Request: The act of syncing extension data might trigger the underlying, flawed extension update-check mechanism in the browser’s core code more frequently, or in different contexts (e.g., in the background or upon startup).
- Cross-Device Propagation: If one device encounters the error, sync might cause the same behavior to manifest on all linked devices.
Troubleshooting with Edge Sync
You can test this hypothesis by temporarily disabling the sync feature:
- Open Microsoft Edge and navigate to
edge://settings/profiles/sync.
- Turn off the toggle at the top of the Sync settings page. You can also selectively turn off sync just for “Extensions”.
- Monitor the Popups: Use Edge for a period and observe if the Norton popups stop appearing.
If disabling sync resolves the issue, it suggests that the sync process was a trigger. If the popups persist, the issue is entirely independent of the sync function and solely within the browser’s core operations.
Regardless of whether sync is involved, the warning is benign and expected to be fixed in a future Edge update.
=======================================
==============================
==============================
While the certificate did expire a long time ago (over 1400 days), the problem lies in the fact that Microsoft considers the domain obsolete and likely has no intention of renewing the certificate.
The expectation is not that Microsoft will renew the certificate, but that they will eventually issue an Edge browser update that removes all references to the defunct domain from the browser’s code.
Why the Delay?
The primary reason this issue has persisted for so long is likely due to:
- Low Security Impact: Microsoft representatives have consistently stated that there are no actual security implications for end-users. The connection is blocked automatically by both the browser and security software, so no data is ever exchanged over an insecure connection.
- Obsolete URL: The domain
extensionwebstorebase.edgesv.net is simply not used anymore, so there is no functional reason to maintain its certificate. The only issue is the redundant code making the unnecessary call.
- Prioritization: Given the benign nature of the alert, a fix for this specific, minor code reference likely falls low on Microsoft’s priority list compared to critical security vulnerabilities or new feature development.
- Sporadic Nature: The alerts often appear sporadically for different users depending on their extensions and usage patterns, making it less of a universal, high-impact bug that demands immediate attention.
The Current Situation
The issue has been widely reported on Microsoft and Norton community forums for years. Microsoft has acknowledged the issue and stated that the reference will be removed in a “future update,” which indicates it is on their radar, even if the timeline is very long.
In the meantime, the advice remains to safely ignore the popups. Norton is just doing its job by reporting that a connection attempt was made to an expired certificate, but your security is not compromised.
AI Mode may make mistakes