# Effective July 2018, Google’s Chrome browser will mark non-HTTPS sites as ‘not secure’

**URL:** <https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597>\
**Category:** RapidWeaver Classic\
**Created:** [February 11, 2018, 11:34am UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597 "2018-02-11T11:34:05Z")\
**Posts on this page:** 12\
**Page:** 2

<div class="post-metadata">

**Author:** ![teefers](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/teefers/32/8173_2.png) [@teefers](https://forums.realmacsoftware.com/u/teefers)\
**Post date:** [February 14, 2018, 1:51pm UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/21 "2018-02-14T13:51:55Z")

</div>

Now you have the first step done(getting the certificate), you next step is to check for mixed content. Things like warehoused images or other resources that are referenced by a full URL that contain http and change them to https.  
Why no padlock can help with that:  
[https://www.whynopadlock.com](https://www.whynopadlock.com)  
After that’s done then you should redirect non secure requests (http) to the secure forum (https).  
There’s a ton of posts on this forum that address doing that, most often it’s done with.htaccess file.

---

<div class="post-metadata">

**Author:** ![bruce](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/bruce/32/23155_2.png) [@bruce](https://forums.realmacsoftware.com/u/bruce)\
**Post date:** [February 14, 2018, 1:59pm UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/22 "2018-02-14T13:59:32Z")

</div>

Thanks Doug. I think I know what to do now. This is some work, but I guess it’s “do only once” work, and a good move forward. I have seven sites and only one that I’m concerned about Google ranking, so changing the others is not important to me at this time.

---

<div class="post-metadata">

**Author:** ![teefers](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/teefers/32/8173_2.png) [@teefers](https://forums.realmacsoftware.com/u/teefers)\
**Post date:** [February 14, 2018, 2:48pm UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/23 "2018-02-14T14:48:52Z")

</div>

It’s good if you can to change them all. It’s not just about ranking, I would guess it won’t be long before it becomes a lot more than just a little warning in the address bar. I can see in the not to distant future a much more extreme warning, like the ones you get with a bad certificate.  
So even if it’s not important now, I would put it on your todo list.

---

<div class="post-metadata">

**Author:** ![ben](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/ben/32/28488_2.png) [@ben](https://forums.realmacsoftware.com/u/ben)\
**Post date:** [February 14, 2018, 2:52pm UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/24 "2018-02-14T14:52:02Z")

</div>

I’ve just written a blog post about this: [https://blog.realmacsoftware.com/remove-not-secure-rapidweaver-https/](https://blog.realmacsoftware.com/remove-not-secure-rapidweaver-https/)

There’s also a video on there showing you how to add your site to CloudFlare — I recommend CloudFlare for most users. It’s a free service and allows you to easily add HTTPS to your site (as well as giving you a CDN, caching, DDOS protection, and more!).

---

<div class="post-metadata">

**Author:** ![teefers](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/teefers/32/8173_2.png) [@teefers](https://forums.realmacsoftware.com/u/teefers)\
**Post date:** [February 14, 2018, 2:52pm UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/25 "2018-02-14T14:52:17Z")

</div>

Yeah, CloudFlare will block ftp. They are doing a lot more than just a certificate, preventing other attack’s.  
They block most ports to your server including ftp, so take a look at that article, it gives two options to fix this.

---

<div class="post-metadata">

**Author:** ![bruce](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/bruce/32/23155_2.png) [@bruce](https://forums.realmacsoftware.com/u/bruce)\
**Post date:** [February 14, 2018, 4:12pm UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/26 "2018-02-14T16:12:16Z")

</div>

> [@teefers](#):
>
> After that’s done then you should redirect non secure requests (http) to the secure forum (https).
> 
> There’s a ton of posts on this forum that address doing that, most often it’s done with.htaccess file.

Bluehost tells me this is automatic after 24 to 48 hours. I will wait and see.

---

<div class="post-metadata">

**Author:** ![bruce](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/bruce/32/23155_2.png) [@bruce](https://forums.realmacsoftware.com/u/bruce)\
**Post date:** [February 15, 2018, 2:34pm UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/27 "2018-02-15T14:34:22Z")

</div>

I don’t believe Bluehost is correct. I had to add a .htaccess file, and now it redirects.

---

<div class="post-metadata">

**Author:** ![RichardLW](https://avatars.discourse-cdn.com/v4/letter/r/ad7895/32.png) [@RichardLW](https://forums.realmacsoftware.com/u/RichardLW)\
**Post date:** [February 17, 2018, 9:13pm UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/28 "2018-02-17T21:13:06Z")

</div>

My host posts this notice. Does that mean it is https?

SECURE SOCKET LAYER SERVICES

At Netfirms, any file that you can access via your domain can be accessed through a Secure Socket Layer (SSL) connection as well.

To access any of your files through a SSL connection, use the following URL:  
[https://widman.netfirms.com/](https://widman.netfirms.com/)  
… where is the name of any file in your web directory.  
Files in subdirectories will work too. Just use  
[https://widman.netfirms.com/](https://widman.netfirms.com/)/  
… where is the name of any subdirectory.

---

<div class="post-metadata">

**Author:** ![teefers](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/teefers/32/8173_2.png) [@teefers](https://forums.realmacsoftware.com/u/teefers)\
**Post date:** [February 17, 2018, 11:04pm UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/29 "2018-02-17T23:04:00Z")

</div>

It would mean you have a certificate (SSL) on your domain. So you can access your site through HTTPS. You will need to check for mixed content, fix anything that is considered active mixed content. Then you should redirect all HTTP traffic to HTTPS.  
[https://www.whynopadlock.com](https://www.whynopadlock.com) Will help identify the mixed content.

---

<div class="post-metadata">

**Author:** ![Flashoser](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/flashoser/32/2051_2.png) [@Flashoser](https://forums.realmacsoftware.com/u/Flashoser)\
**Post date:** [February 20, 2018, 5:15pm UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/30 "2018-02-20T17:15:14Z")

</div>

ok, where are these certs are FREE where you can sue them on any hosting site??

---

<div class="post-metadata">

**Author:** ![Rovertek](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/rovertek/32/223_2.png) [@Rovertek](https://forums.realmacsoftware.com/u/Rovertek)\
**Post date:** [February 21, 2018, 12:01am UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/31 "2018-02-21T00:01:20Z")

</div>

Hi, Michael, if you mean _“where you can **see** them on any hosting site”_, it was explained in my previous post:

> [@Rovertek](#):
>
> Many hosts provide a free SSL/TLS certificate obtained from Let’s Encrypt. So, first go to your cPanel and look for Let’s Encrypt SSL:
> 
> **Screen Shot** 2018-02-11 at 12.18.45 PM.png1075x277 31.5 KB
> 
> This will lead you through the whole process.
> 
> If that is not an option in your case, click the link I provided in my previous post. That will also explain the whole process. Additionally, they have a very good forum where all intricacies are addressed by professionals from Let’s Encrypt, if necessary.

Some host do not provide FREE certificates. Instead, they expect to be paid for them. So, if you’re in doubt, ask your host. If they don’t have free certs, find another host.

---

<div class="post-metadata">

**Author:** ![system](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/system/32/25301_2.png) [@system](https://forums.realmacsoftware.com/u/system)\
**Post date:** [February 27, 2018, 12:01am UTC](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597/32 "2018-02-27T00:01:22Z")

</div>

This topic was automatically closed 6 days after the last reply. New replies are no longer allowed.

[Previous page](https://forums.realmacsoftware.com/t/effective-july-2018-google-s-chrome-browser-will-mark-non-https-sites-as-not-secure/18597.md?page=1)
