Your certificate on the on-prem send connector isnt set right or it cant be checked by Exchange Online or you have network issues on-prem
The easiest solution is to probably re-run the Hybrid Wizard and make sure a valid, third part certificate is chosen for the send connector between on-prem and hybrid,
If you do it manually, be sure to use a the correct, 3rd party cert:
$cert = Get-ExchangeCertificate -Thumbprint <Thumbprint>
$tlscertificatename = "<i>$($cert.Issuer)<s>$($cert.Subject)"
Set-ReceiveConnector "EX2016SRV1\HybridRecConnector" -TlsCertificateName $tlscertificatename
Set-SendConnector -Identity “Send Connector Name” -TLSCertificateName $tlscertificatename
If this has already been done, here are some other possibilities:
https://answers.microsoft.com/en-us/msoffice/forum/all/revocationoffline-error-in-one-of-the-hub-servers/a6256f84-f771-4f3b-a38f-c1d9336b5372