Still Not Secure in Chrome
-
Hi
We migrated to HTTPs in November - but we still aren't showing as Secure.
I thought it was due to there being an Insecure SHA-1 script in the SSlL Certificate, so am waiting to get this fixed.
We had a few http links outstanding so they have been updated, but we're still getting the issue.
Does anyone have an idea of what it could be? https://www.key.co.uk/en/key/
-
I'm surprised to say... that SSL certificate you have is very poor quality and has a number of pretty significant security issues, in addition to the SHA-1 encryption.]
To answer your specific question, there's nothing you or your devs can do about the SHA-1 encryption problem, as that problem exists on one of the certificates in the chain that is owned and controlled by Thawte (the cert issuer or "Certificate Authority"), not your own certificate. It is up to them to fix it.
As you can see from the cert security scan, there are a number of other issues with the certificate that are unacceptable. Especially in a paid certificate. [Edited for clarity - some of those warnings are likely server-specific, meaning the server is being allowed to communicate with certificate in less than optimal ways]
https://www.ssllabs.com/ssltest/analyze.html?d=www.key.co.ukIt's unlikely that the encryption problem is whats giving the "not secure" warning on the site at the moment (although it will become a major issue later in February) so you'll need to keep looking for resources called over HTTP if you're still getting warnings.
When I had a quick look at the home page, I didn't see any more warnings, as it appears you've fixed the image call that Andrew mentioned. You can use Chrome or Firefox Dev Tools to inspect any pages that are not secure to be shown exactly what element is causing the failure. It often comes down to hardcoded images like those in CSS/background images etc, or hardcoded scripts. For example, your Quotations page is calling a script from Microsoft to validate the form, but it's failing as it's called over HTTP.
Knowing this, you'd want to check any other pages using such form validation. A thorough Screaming Frog crawl to look for any other wayward HTTP calls can also help dig our the remaining random culprits.
Hope that helps?
Paul
Sidenote: Your certificate authority is Thawte, which is connected with Symantec. Which has done such a bad job of securing their certificates that Chrome and other browsers no longer trust them and are in the near future are going to be officially distrusted and ignored. Symantec has in fact given up their Certificate Authority status and is transferring their business to a new company which does have a trusted infrastructure for issuing certificates. So you're going to need to deal with a new certificate in the not too distant future anyway.
Given the poor security of your existing cert, and the upcoming issues, if it were me, I'd be asking for a refund of my current cert, and replacing it with one from a more reliable issuer. I know that can mean a lot of extra work, but as these existing problematic certs go through the distrust process over the next 8 months, sites that haven't dealt with the issue are going to break.
It's possible that Thawte will build out a reliable process for migrating. At the very least, you need to have a strong conversation with your issuer about how to insure you are getting the security and long-term reliability you've paid for. Sorry to be the bearer of bad news that is a much bigger issue. You can read up about it more here:
https://security.googleblog.com/2017/09/chromes-plan-to-distrust-symantec.html -
Thank you.
Also, does anyone know if we need to rekey the SHA-1 signature algorithm, what we rekey it with or should my dev team know this?
-
I also got this report from https://www.whynopadlock.com
Soft FailureAn image with an insecure url of "http://www.key.co.uk/img/W/KEY/F7/IC/F7-112H204-1-LX.jpg" was loaded on line: 1 of https://www.key.co.uk/en/key.
Errors that are reported on line 1 are generally not part of the source code. This error may be caused by an external javascript file which is writing to the page, however we are unable to reliably detect these scripts in our automated test.
Please contact us using the "Need Help?" link below if you need assistance with resolving this error.
Browse Questions
Explore more categories
-
Moz Tools
Chat with the community about the Moz tools.
-
SEO Tactics
Discuss the SEO process with fellow marketers
-
Community
Discuss industry events, jobs, and news!
-
Digital Marketing
Chat about tactics outside of SEO
-
Research & Trends
Dive into research and trends in the search industry.
-
Support
Connect on product support and feature requests.
Related Questions
-
Old competitor site but GMB listing no more, are links still valuable?
One of my clients has come into the possession of a competitor's website. They sat on it for a while (other things going on) and because the company ceased trading the GMB listing seems to have been removed by Google and the leads have dropped off since this loss. The links are OK, so am considering 301 redirects, if the links still pass any value.
Intermediate & Advanced SEO | | GrouchyKids
Linking Domains 98
Domain Authority 23
Spam Score 2 % Are the links likely to still pass value? Also in terms of updating the WHOIS info what's the best approach?0 -
.co.uk to .com domain move Dec 26th, still 40% down - do I risk moving back? (desperate)
Hi All, I'm desperate for a bit of advice. I run www.tyrereviews.com which has been my project since 2006, and after LOTS of hard work over 15 years held 1000's of P1 positions in the SERPs. I recently moved from the original .co.uk to .com to aid with future internationalising plans. I was very careful not to change ANYTHING else, just 301 from the UK to the .com and updated everything in webmaster consoles. My background is development and I spent weeks triple researching everything to make sure I followed all the google best practices, as this is my life's work and primary income source. From a tech point of view the change went perfectly, but sadly google quickly started deranking the new domain, and now two months on it seems to have stabilised at around 40% down on traffic year on year and mostly dropped from the UK region. This is mostly from medium to long tail keywords. One such example is "Michelin Primacy 4" in google UK, old webmaster tools is showing my average position this time last year as 1.4 and now I'm 12.4! The .com site is geo targeted to the UK by both webmaster tools and href lang tags. So, my question is, so I keep waiting, or do I give up andrisk the switch back to the uk domain before it's too late? Thanks in advance.
Intermediate & Advanced SEO | | TyreReviews0 -
Redirect 301 still works?
Hi, yesterday a friend said that 301 redirects does not transfer your page rank or domain autorithy anymore. I could'nt find anything in internet saying it, but I decided to ask you guys, since I think you are very reliable. so, 301 redirects wroks for transfer page rank, and i can create better domains and transfer everything, or this strategy is gone forever now?
Intermediate & Advanced SEO | | chablau0 -
Robots.txt Disallowed Pages and Still Indexed
Alright, I am pretty sure I know the answer is "Nothing more I can do here." but I just wanted to double check. It relates to the robots.txt file and that pesky "A description for this result is not available because of this site's robots.txt". Typically people want the URL indexed and the normal Meta Description to be displayed but I don't want the link there at all. I purposefully am trying to robots that stuff outta there.
Intermediate & Advanced SEO | | DRSearchEngOpt
My question is, has anybody tried to get a page taken out of the Index and had this happen; URL still there but pesky robots.txt message for meta description? Were you able to get the URL to no longer show up or did you just live with this? Thanks folks, you are always great!0 -
Changing domain names but still ranking as old one
Hi there, I have a client who changed domain names back in November 2015 but is still coming up in search engines with their old domain name not their new one. For example, I search for my clients name, let's call them Example B. So I search for "Example B" and within the search results they come up top and the title tag is correct as it says something along the lines of "Welcome to Example B". However the URL underneath is actually their old name which is Example A. When you click on the link, it redirects over to the new name so thats fine, but it's just annoying that Example A is still appearing when it should be Example B now. I don't think they have a new Webmaster Tools account setup for their new domain (I need to check still), but they do still have their old one setup. Is there something I can do within Webmaster Tools to tell it that Example A is now gone and to start indexing and referring to them as Example B? What else should I do to make sure their new name is coming up not their old one anymore?
Intermediate & Advanced SEO | | Virginia-Girtz1 -
Link building - still effective ?
Hi, I know 70-80% of the links on Google have no-follow keyword. What I need to know is if link building by using guest posting and a combination of no-follow links through social media is still effective ? What would you suggest in terms of link building. I have read all the articles on moz and everything, but I need a personal touch on this matter. Thanks,
Intermediate & Advanced SEO | | kiraftw
Andrei0 -
How could I create this? Would it be a chrome extension?
I do a lot of checking for duplicate content on sites. I use chrome and generally I highlight a phrase, do right click and then "Search Google for...". However, I would like to have a quick shortcut where I can search Google for a phrase that is enclosed in quotes. Is there a chrome extension for this? If not, can I build one? Thanks.
Intermediate & Advanced SEO | | MarieHaynes0 -
Do Nofollows still work for Sculpting?
Before answering this, let me explain my goals. I know that Google made a change a couple years ago that discounts the amount of Page Rank passed to dofollow links when there is a nofollow link present on the page. My goal is to keep the most page rank possible on my home page and pass a specified amount of Page Rank to 7 out of 10 of the pages linked to from my home page. I realize that creating 3 of the outgoing links as no follow links is not going to increase the Page Rank being sent to the other 7 pages. My question is will my home page be able to retain the Page Rank that would have been used by the three nofollow links or is that Page Rank value just lost when I implement a nofollow?
Intermediate & Advanced SEO | | MyNet0