Internet Explorer 7 has SSL problems: "This page contains both secure and non-secure items"
Reproduction steps:
1. Start Internet Explorer 7
2. Go to Tools > Internet Options...
3. Delete all cached items
4. Open https://staging.akoha.com/
Expected result:
Page loads without errors
Actual result:
"This page contains both secure and non-secure items"
1. Start Internet Explorer 7
2. Go to Tools > Internet Options...
3. Delete all cached items
4. Open https://staging.akoha.com/
Expected result:
Page loads without errors
Actual result:
"This page contains both secure and non-secure items"
1
person has this problem
I have this problem, too!
Tell me when someone solves it.
The more people who report this problem, the more it gets noticed.
The more people who report this problem, the more it gets noticed.
The company thinks this is not a problem.
-
Inappropriate?Okay, we're looking into this now.
-
Inappropriate?I'm noticing that you don't have your certificates properly installed on that server. Have you installed the intermediate chain file that GoDaddy gives you with the SSL certificates?
My test pages show that no security warnings are thrown... I don't know how the browser will behave when one of the certificates as an untrusted CA.
Does the following URL generate security warnings for you? https://getsatisfaction.com/akoha/fee... -
That URL you provided does not generate security warnings.
Interestingly enough, the "Go Daddy Class 2 Certification Authority" is a default Trusted Root CA shipped with IE 7. Surely this wouldn't be the problem? -
I got security warning about your certificate's CA in IE6,7,8 and Chrome. -
Inappropriate?I've made sure all of the intermediate certificates are installed on staging.akoha.com.
I don't get an error in Google Chrome or IE8, but I still get a "This page contains both secure and non-secure items" error in IE6 and IE7.
None of these browsers provide really useful or complete debugging information, so I've turned to the openssl command-line utility for more information:
openssl s_client -connect staging.akoha.com:443 -CAfile /usr/share/curl/curl-ca-bundle.crt
CONNECTED(00000003)
depth=3 /L=ValiCert Validation Network/O=ValiCert, Inc./OU=ValiCert Class 2 Policy Validation Authority/CN=http://www.valicert.com//emailAddress=info@valicert.com
verify return:1
depth=2 /C=US/O=The Go Daddy Group, Inc./OU=Go Daddy Class 2 Certification Authority
verify return:1
depth=1 /C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./OU=http://certificates.godaddy.com/repository/CN=Go Daddy Secure Certification Authority/serialNumber=07969287
verify return:1
depth=0 /O=*.akoha.com/CN=*.akoha.com/OU=Domain Control Validated
verify return:1
---
Certificate chain
0 s:/O=*.akoha.com/CN=*.akoha.com/OU=Domain Control Validated
i:/C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./OU=http://certificates.godaddy.com/repository/CN=Go Daddy Secure Certification Authority/serialNumber=07969287
1 s:/C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./OU=http://certificates.godaddy.com/repository/CN=Go Daddy Secure Certification Authority/serialNumber=07969287
i:/C=US/O=The Go Daddy Group, Inc./OU=Go Daddy Class 2 Certification Authority
2 s:/C=US/O=The Go Daddy Group, Inc./OU=Go Daddy Class 2 Certification Authority
i:/L=ValiCert Validation Network/O=ValiCert, Inc./OU=ValiCert Class 2 Policy Validation Authority/CN=http://www.valicert.com//emailAddress=info@valicert.com
3 s:/L=ValiCert Validation Network/O=ValiCert, Inc./OU=ValiCert Class 2 Policy Validation Authority/CN=http://www.valicert.com//emailAddress=info@valicert.com
i:/L=ValiCert Validation Network/O=ValiCert, Inc./OU=ValiCert Class 2 Policy Validation Authority/CN=http://www.valicert.com//emailAddress=info@valicert.com
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIEyTCCA7GgAwIBAgIEAODK+TANBgkqhkiG9w0BAQUFADCByjELMAkGA1UEBhMC
VVMxEDAOBgNVBAgTB0FyaXpvbmExEzARBgNVBAcTClNjb3R0c2RhbGUxGjAYBgNV
BAoTEUdvRGFkZHkuY29tLCBJbmMuMTMwMQYDVQQLEypodHRwOi8vY2VydGlmaWNh
dGVzLmdvZGFkZHkuY29tL3JlcG9zaXRvcnkxMDAuBgNVBAMTJ0dvIERhZGR5IFNl
Y3VyZSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTERMA8GA1UEBRMIMDc5NjkyODcw
HhcNMDgxMTA1MTcxMTI4WhcNMDkxMTA1MTcxMTI4WjBPMRQwEgYDVQQKEwsqLmFr
b2hhLmNvbTEUMBIGA1UEAxMLKi5ha29oYS5jb20xITAfBgNVBAsTGERvbWFpbiBD
b250cm9sIFZhbGlkYXRlZDCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA06ov
JFM14ZiRj+R53iMIwhm9gwyaTs6NzBMpSRv9uOT0RE/paVjlYejA/haUKJWjPgfZ
ePaiGjdIEm/rK5KXAym6Nsp6SSFjLME+3Xwckf6OtnppANzc04m/SYIxtCh9E96z
Q6txJpn6soHQXreNOYxhlQa6VVIE+VqTcUo7Vv8CAwEAAaOCAbMwggGvMA8GA1Ud
EwEB/wQFMAMBAQAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMA4GA1Ud
DwEB/wQEAwIFoDAyBgNVHR8EKzApMCegJaAjhiFodHRwOi8vY3JsLmdvZGFkZHku
Y29tL2dkczEtMC5jcmwwUwYDVR0gBEwwSjBIBgtghkgBhv1tAQcXATA5MDcGCCsG
AQUFBwIBFitodHRwOi8vY2VydGlmaWNhdGVzLmdvZGFkZHkuY29tL3JlcG9zaXRv
cnkvMIGABggrBgEFBQcBAQR0MHIwJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmdv
ZGFkZHkuY29tLzBKBggrBgEFBQcwAoY+aHR0cDovL2NlcnRpZmljYXRlcy5nb2Rh
ZGR5LmNvbS9yZXBvc2l0b3J5L2dkX2ludGVybWVkaWF0ZS5jcnQwHwYDVR0jBBgw
FoAU/axhMpNsRdbi7oVfmrrndplozOcwIQYDVR0RBBowGIILKi5ha29oYS5jb22C
CWFrb2hhLmNvbTAdBgNVHQ4EFgQUvr9g1SRrsLJ0t8LaVtas5gcH2jUwDQYJKoZI
hvcNAQEFBQADggEBABbSjYCIN+lDWVv6/5FzNdNNbLz0s2qWNQzXwDm67YVuID+b
49GDHyD5JZDOQ5fvSS58NJAcYJFWWnpe7fZMaY8o3QXSVhXggAM5TUsCJggy5n06
lJShg6iBFcgP9Klu0ObPpQTjxS2/oqzp7zlYv0ce5F9KDsuDUD2WzqAkduI4g3UG
1QYI64I/yrJx7tw2qB2wWTSo/e9Q/2HKpnKs6bwZ4hu/auP3zfF4O/+3ZPDMZvdz
CCsfkKapSJSv6LIYnqPErWANny/3kEE11ed6ByO/WfGWrq6vkd4VotveP4ol12iY
zN5n89mqZBjWpUfM4L2l4jHwOVfmTwHkX0PkYOE=
-----END CERTIFICATE-----
subject=/O=*.akoha.com/CN=*.akoha.com/OU=Domain Control Validated
issuer=/C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./OU=http://certificates.godaddy.com/repository/CN=Go Daddy Secure Certification Authority/serialNumber=07969287
---
No client certificate CA names sent
---
SSL handshake has read 4676 bytes and written 322 bytes
---
New, TLSv1/SSLv3, Cipher is AES256-SHA
Server public key is 1024 bit
Compression: NONE
Expansion: NONE
SSL-Session:
Protocol : TLSv1
Cipher : AES256-SHA
Session-ID: 9F23C4EED8C3E30D3EC64B8B114C53F5218B6191BAE284D761D743BDB1F2CAC1
Session-ID-ctx:
Master-Key: 8548E2A6B90649798DF9998A84932625E25BB7DC5F0A8E878EE4B1F67C927C3DCFE6CBC57A50112340C81F35EF56A3F8
Key-Arg : None
Start Time: 1244223518
Timeout : 300 (sec)
Verify return code: 0 (ok)
---
The most important line in there is the last on: Verify return code: 0 (ok).
I don't understand why only IE6 and IE7 complain...
I’m nonplussed
-
Inappropriate?Alright, looking at your guy's source your aren't using the latest embed statements or javascripts.
Since it looks like you guys have hacked up the embed statement, you'll need to rework your setup to use the new embed statements.
-Scott
1 person says
this solves the problem
-
Thanks, that did it. Sadly, it was not obvious that we needed to upgrade.
Loading Profile...



EMPLOYEE
