No https...Why??

Status
Not open for further replies.

MagnusEunson

Bearded Super Villain
ECF Veteran
Verified Member
Apr 30, 2011
4,448
4,789
Behind you
What browser are you using? When I connect I get a valid TLS 1.0 cert from the GeoTrust DV SSL CA ... it's possible your browser needs an updated CA list but regular updates of IE, Firefox, or Chrome would do that for you. And that's a long-standing CA so I'd be surprised if you don't have it.

There are other more broken / nefarious options but those are stretching it for this post. -Magnus
 

Jason365

Super Member
ECF Veteran
Aug 18, 2009
388
0
ATX
I am using Chrome 11.0.696.71. and this is what its saying..

The site uses SSL, but Google Chrome has detected either high-risk insecure content on the page or problems with the site’s certificate. Don’t enter sensitive information on this page. Invalid certificate or other serious https issues could indicate that someone is attempting to tamper with your connection to the site.

So I dunno.. I will clear my cache and such to see if it help with the certificate. But it did this from 2 different computers. So I dont think thats it.
 

MagnusEunson

Bearded Super Villain
ECF Veteran
Verified Member
Apr 30, 2011
4,448
4,789
Behind you
Hrmm. In what point of the checkout process does this happen for you? Chrome is updated well and I'm using Chrome right now without this same problem. Can you copy the URL for me? Send it via PM.. Even if it has tokens for your order w/o cookies on my end I won't see the order. Just want to connect to that server, see what TLS cert it sends over, and if what other servers content comes from on whatever page you're on so I can try to see if I can figure it out. Long shot from here because it might just redirect me elsewhere but I can try. -Magnus
 

hoogie76

Unregistered Supplier
ECF Veteran
Aug 1, 2009
2,955
659
Charlotte, NC
if you type in https for the checkout page what happens? Have you tried another browser?

My chrome shows this up top:
secure.jpg

Thanks, hoog
 
Last edited:

Paddrino

Super Member
ECF Veteran
Verified Member
May 21, 2011
422
173
Austin, TX
www.youtube.com
It could be that only part of the site is encrypted. It could be some image or add insertion that is not encrypted. The certificate is valid up until 2012 by GeoTrust.

Edit: There are a few "add ons" on the page that are transmitted via http instead of https. That is probably why you are getting the warning. That doesn't mean that the page is insecure. It just means that parts of the page are not encrypted. You may have your security settings set really high which is triggering the warning.
 
Last edited:

MagnusEunson

Bearded Super Villain
ECF Veteran
Verified Member
Apr 30, 2011
4,448
4,789
Behind you
IF you use a different browser and the behavior changes, then it's localized to Chrome and perhaps a simple reinstall will fix it. If the other browser has similar HTTPS warnings then the first culprit is your Windows certificate storage (which Chrome doesn't trust by default but can cause problems like this). Is the other browser also shows this problem then we've got both local compromise and unsavory ISP options to consider.

Could go through about a dozen options in ten minutes at the console but this way is tough. Hrmm.

It's probably something simple though, the paranoid options don't fit this sort of thing. You'd see it all over the place.

And, just to elimiate a whole CA storage problem in Chrome... any problems with https://www.google.com ? -Magnus
 

MagnusEunson

Bearded Super Villain
ECF Veteran
Verified Member
Apr 30, 2011
4,448
4,789
Behind you
Edit: There are a few "add ons" on the page that are transmitted via http instead of https. That is probably why you are getting the warning. That doesn't mean that the page is insecure. It just means that parts of the page are not encrypted. You may have your security settings set really high which is triggering the warning.

He says ~all~ pages though. And I went through the whole process and not all the pages had mixed content.

If he selects the lock icon and pastes the certificate material at least we could very it matches. Even a forged one will fail the chain check. -Magnus
 
Status
Not open for further replies.

Users who are viewing this thread