# Effective July 2018, Google’s Chrome browser will mark non-HTTPS sites as ‘not secure’

**URL:** <https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597>\
**Category:** RapidWeaver Classic\
**Created:** [February 11, 2018, 11:34am UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597 "2018-02-11T11:34:05Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![teefers](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/teefers/32/8173_2.png) [@teefers](https://forums.realmacsoftware.com/u/teefers)\
**Post date:** [February 11, 2018, 11:34am UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/1 "2018-02-11T11:34:05Z")

</div>

If you’re not using SSL on your site(s) yet you’re running out of time.  
It looks like with the release of chrome 68 scheduled for July release sites accessed as HTTP, not HTTPS will be marked as **not secure** right in the address bar. Now you get that message only if you’re accepting users input.  
This message will affect your bounce rate.

> **[A secure web is here to stay](https://blog.chromium.org/2018/02/a-secure-web-is-here-to-stay.html)**
>
> For the past several years, we’ve moved toward a more secure web by strongly advocating that sites adopt HTTPS encryption. And within the la...

---

<div class="post-metadata">

**Author:** ![Rovertek](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/rovertek/32/223_2.png) [@Rovertek](https://forums.realmacsoftware.com/u/Rovertek)\
**Post date:** [February 11, 2018, 4:01pm UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/2 "2018-02-11T16:01:42Z")

</div>

I can’t imagine why would anybody **not** switch to HTTPS. Especially, when [SSL/TLS certificates](https://letsencrypt.org) are free and they renew automatically. One-time effort that anybody can accomplish will give peace of mind forever (or until next improvement in Internet security)…

---

<div class="post-metadata">

**Author:** ![bruce](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/bruce/32/23155_2.png) [@bruce](https://forums.realmacsoftware.com/u/bruce)\
**Post date:** [February 11, 2018, 5:11pm UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/3 "2018-02-11T17:11:55Z")

</div>

Please help and explain how we make our sites HTTPS. Thanks.

---

<div class="post-metadata">

**Author:** ![Rovertek](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/rovertek/32/223_2.png) [@Rovertek](https://forums.realmacsoftware.com/u/Rovertek)\
**Post date:** [February 11, 2018, 5:21pm UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/4 "2018-02-11T17:21:06Z")

</div>

Many hosts provide a free SSL/TLS certificate obtained from Let’s Encrypt. So, first go to your cPanel and look for Let’s Encrypt SSL:

 ![45%20PM](https://europe1.discourse-cdn.com/flex005/uploads/realmacsoftware1/original/2X/f/f62671b8b5c9b2cc5975404b09c06538633adc05.png)

This will lead you through the whole process.

If that is not an option in your case, click the link I provided in my previous post. That will also explain the whole process. Additionally, they have a very good forum where all intricacies are addressed by professionals from Let’s Encrypt, if necessary.

---

<div class="post-metadata">

**Author:** ![bruce](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/bruce/32/23155_2.png) [@bruce](https://forums.realmacsoftware.com/u/bruce)\
**Post date:** [February 11, 2018, 6:42pm UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/5 "2018-02-11T18:42:48Z")

</div>

Looks like my host has WordPress FREE SSL. I will test that and see how it goes. Thanks.

---

<div class="post-metadata">

**Author:** ![Bazza](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/bazza/32/2104_2.png) [@Bazza](https://forums.realmacsoftware.com/u/Bazza)\
**Post date:** [February 11, 2018, 7:12pm UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/6 "2018-02-11T19:12:55Z")

</div>

Are you with Bluehost by any chance Bruce?

---

<div class="post-metadata">

**Author:** ![bruce](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/bruce/32/23155_2.png) [@bruce](https://forums.realmacsoftware.com/u/bruce)\
**Post date:** [February 11, 2018, 7:53pm UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/7 "2018-02-11T19:53:53Z")

</div>

Yes. Do you have any suggestions?

---

<div class="post-metadata">

**Author:** ![bruce](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/bruce/32/23155_2.png) [@bruce](https://forums.realmacsoftware.com/u/bruce)\
**Post date:** [February 14, 2018, 1:51am UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/8 "2018-02-14T01:51:35Z")

</div>

I ordered the free SSL. It says it’s installing. Is there something I need to do to my RW project file, like change the web address?

---

<div class="post-metadata">

**Author:** ![richardnicholls](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/richardnicholls/32/995_2.png) [@richardnicholls](https://forums.realmacsoftware.com/u/richardnicholls)\
**Post date:** [February 14, 2018, 8:23am UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/9 "2018-02-14T08:23:21Z")

</div>

Cloudfare, [https://www.cloudflare.com](https://www.cloudflare.com), offer free SSL certs.  
I set 2 sites up yesterday in 2 minutes, all I needed to do was change the DNS address with my hosting provider and job’s-a-good-un.  
Their free level is perfectly adequate for most sites I’d say.  
Richard

---

<div class="post-metadata">

**Author:** ![mark](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/mark/32/145_2.png) [@mark](https://forums.realmacsoftware.com/u/mark)\
**Post date:** [February 14, 2018, 10:00am UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/10 "2018-02-14T10:00:14Z")

</div>

Hi Richard

Have you experienced any publishing issues when using Cloudflare SSL?

After turning on Cloudflare SSL I can’t publish and I get the error “Operation was aborted by an application callback.”

As yet I’m not sure if its related, I’ve turned off SSL and, as yet, I still can’t publish.

Changing the names servers to Cloudflare appeared to work OK, I could still publish, but when I switched on SSL publishing immediately failed and turning off SSL hasn’t fixed it yet.

Regards

Mark

---

<div class="post-metadata">

**Author:** ![webdeer](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/webdeer/32/5299_2.png) [@webdeer](https://forums.realmacsoftware.com/u/webdeer)\
**Post date:** [February 14, 2018, 10:27am UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/11 "2018-02-14T10:27:57Z")

</div>

Unfortunately some hosts don’t support Lets Encrypt unless you have a dedicated IP address - Clook for example. I have inherited 2 sites with Lets Encrypt SSL domain names, and both did not auto renew this year causing the customers to panic and blame me. I found it impossible to resolve using the available Lets Encrypt support and my host kindly resolved the auto renew even though t was nothing to do with them. They later explained that that is one of the reasons they don’t offer Lets Encrypt.

---

<div class="post-metadata">

**Author:** ![richardnicholls](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/richardnicholls/32/995_2.png) [@richardnicholls](https://forums.realmacsoftware.com/u/richardnicholls)\
**Post date:** [February 14, 2018, 11:25am UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/12 "2018-02-14T11:25:03Z")

</div>

Just tested it and it’s fine.  
I am using SFTP rather than FTP though, not sure if that makes a difference.  
Richard

---

<div class="post-metadata">

**Author:** ![teefers](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/teefers/32/8173_2.png) [@teefers](https://forums.realmacsoftware.com/u/teefers)\
**Post date:** [February 14, 2018, 11:27am UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/13 "2018-02-14T11:27:24Z")

</div>

> [@webdeer](#):
>
> They later explained that that is one of the reasons they don’t offer Lets Encrypt.

You don’t have to have a static (dedicated) IP address to use _Lets Encrypt_ or use the auto renew process. Very very few shared hosted websites have a static IP address, in fact, most of the shared hosting companies don’t even offer that as an option until you upgrade to a VPS plan.  
I’ve had auto-renewal of Let’s Encrypt certificates lots of times on different host companies without a static IP and have had no problems.  
Now I wouldn’t set up the let’s Encrypt myself as your client appears to have done, as they probably don’t have and shouldn’t have the level of admin access needed to setup correctly, but there are thousands of hosting companies that have set it up as a simple cPannel option. From what I’ve been told by a friend who has been working as a Unix admin since the mid 80’s is it shouldn’t take more than an hour to set up.  
Most of the hosting companies that don’t offer this service are doing this to increase sales of private certificates or upgrades in hosting plans. The reality is the service from lets Encrypt doesn’t cost them a penny.  
It’s up to everyone who chooses a hosting company to accept these excuses or choose a different company to host with.

---

<div class="post-metadata">

**Author:** ![teefers](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/teefers/32/8173_2.png) [@teefers](https://forums.realmacsoftware.com/u/teefers)\
**Post date:** [February 14, 2018, 11:48am UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/14 "2018-02-14T11:48:25Z")

</div>

Did you try connecting with an IP address (for ftp) or are you using a server name?

Might want to have a look at this article:  
[https://support.cloudflare.com/hc/en-us/articles/200169346-Using-FTP-with-CloudFlare-](https://support.cloudflare.com/hc/en-us/articles/200169346-Using-FTP-with-CloudFlare-)

---

<div class="post-metadata">

**Author:** ![webdeer](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/webdeer/32/5299_2.png) [@webdeer](https://forums.realmacsoftware.com/u/webdeer)\
**Post date:** [February 14, 2018, 12:27pm UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/15 "2018-02-14T12:27:50Z")

</div>

For sure you don’t need a fixed IP, but in Clooks case, they only offer Lets Encrypt setup IF you have a fixed IP. Or maybe they don’t because their blurb is a bit vague on it now.

No doubt this is all a marketing thing to drive you to their paid for SSL.

However, I would never use Lets Encrypt because of the renew issues I had with them which far outweighed the small cost of a 36 monthsSSL basic certificate with someone like Comodo.

---

<div class="post-metadata">

**Author:** ![Bazza](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/bazza/32/2104_2.png) [@Bazza](https://forums.realmacsoftware.com/u/Bazza)\
**Post date:** [February 14, 2018, 12:49pm UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/16 "2018-02-14T12:49:22Z")

</div>

HI Bruce, I went with Veerotech and so far so good!

Regards

Barrie

---

<div class="post-metadata">

**Author:** ![teefers](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/teefers/32/8173_2.png) [@teefers](https://forums.realmacsoftware.com/u/teefers)\
**Post date:** [February 14, 2018, 1:06pm UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/17 "2018-02-14T13:06:31Z")

</div>

If you want, to pay for them there are lots of options, many come with an insurance bond covering losses if the encryption fails.  
Most RapidWeaver users don’t want to pay for things like this.  
Let’s Encrypt certificates only have a 90-day expiry date, so they do have to be renewed more often than the paid plans. However, most good hosting companies now have that setup for automatic renewal and don’t have any issues with it. DreamHost auto renew process takes place with 30 days left on the certificate.  
Just to let folks know, I’ve had issues with paid certificates getting renewed as well. It might only happen every one to three years, but they still expire.  
My main point here is there’s no reason for a hosting company not to offer free certificates other than trying to sell you something that should be free.  
For most small websites a free certificate from Let’s Encrypt is more than what you’ll need, and implemented correctly by the host company should be trouble free. I’ve had a few of them for years and never had a problem with renewal.

---

<div class="post-metadata">

**Author:** ![mark](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/mark/32/145_2.png) [@mark](https://forums.realmacsoftware.com/u/mark)\
**Post date:** [February 14, 2018, 1:41pm UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/18 "2018-02-14T13:41:37Z")

</div>

Thanks Richard, I left it for a while and came back to it and it’s working fine now, and I’m using standard FTP. I still don’t know if it’s something with Cloudflare or just a ‘glitch’ in Rapidweaver publishing.

Regards  
Mark

---

<div class="post-metadata">

**Author:** ![mark](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/mark/32/145_2.png) [@mark](https://forums.realmacsoftware.com/u/mark)\
**Post date:** [February 14, 2018, 1:42pm UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/19 "2018-02-14T13:42:51Z")

</div>

Thanks Doug, I’ll take a look. I’m just ftp-ing using the server name.  
Regards  
Mark

---

<div class="post-metadata">

**Author:** ![bruce](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/bruce/32/23155_2.png) [@bruce](https://forums.realmacsoftware.com/u/bruce)\
**Post date:** [February 14, 2018, 1:43pm UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/20 "2018-02-14T13:43:33Z")

</div>

I have the free SSL from Bluehost installed, now I need to know is there any change I need to make to my RW project (site) and then publish it again? I can see the padlock, but I can also get to my site using http:// without the “s.”

[Next page](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597.md?page=2)
