Enabling SSL on a site that runs 3rd party ad network tags?

CLKeenan

Banned
Jun 24, 2006
2,506
14
0
Boston, MA
So I thought it would be a good idea to get an SSL cert and enable it for my site. No personally identifiable data is kept on the server, just username/email/password combos. However, I'd still consider it best practice to encrypt login sessions and user profile form completions (change of password)... correct me if I'm wrong.

Here lies the problem, I run advertisements on my site using 3rd party ad network tags that don't support https:// delivery so all of the browsers throw a flag saying that there are some page elements are insecure don't trust this site blah blah blah. That's almost worse than not having any message at all in my mind, even though the SSL cert is encrypting what it should because now the user is thinking something is awry.

Any thoughts on how I can fix this? Or am I SOL?

Thanks,
-Chris
 


As far as I know, non-https links are fine, looks like you have the problem with images that are non-https. Is there a way to host images locally?

I'm getting a ton of lines like this in Google Dev Tools console:

The page at https://..... ran insecure content from http://www2a.glam.com/mobile/detect.act?affiliateId=367551923.
The page at https://..... ran insecure content from http://connect.facebook.net/en_US/all.js.
The page at https://....... ran insecure content from http://www8.glam.com/js/widgets/glam_logo.js.
The page at https://....... ran insecure content from http://edge.quantserve.com/quant.js.
The page at https://www.course-notes.org/US_History ran insecure content from http://www2.glam.com/app/site/affil...=viewAdJs&affiliateId=367551923&adSize=728x90.


The first one is a mobile browser detect script from my ad network which will redirect the visitor to the mobile site if they are on a smartphone.

The second is facebook connect.

The third is quantcast script

The fourth is a leaderboard ad tag.



Another idea I had would be to try to remove all the ads from any of the pages I'd want to encrypt, like the login page and user page. Won't hurt my ad revenue too much.
 
Well, I most likely will be in the future so I want to iron out the kinks now when it doesn't matter.

Then all you have to do is only 301 redirect the pages that you need https on. No need to serve 3rd party unsecured ads on a checkout page anyway. There is no good reason to put the whole site behind https that I can think of.
 
Yup. This will be much more feasible in my new layout that I have being designer by one of WF's own. Should be ready to be launched in a week or so.