Welcome to Centmin Mod Community
Register Now

SSL Dealing with mix content warnings in SSL - CSP upgrade-insecure-requests

Discussion in 'Domains, DNS, Email & SSL Certificates' started by eva2000, Aug 27, 2015.

  1. eva2000

    eva2000 Administrator Staff Member

    58,895
    12,490
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,122
    Local Time:
    11:25 PM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
    Came across this while watching Letsencrypt video for a way of dealing with mixed content warnings if you have deployed a https SSL web site but have some page elements still loading from http. It's an additional header for Content-Security-Policy: upgrade-insecure-requests outlined at Upgrade Insecure Requests


     
  2. eva2000

    eva2000 Administrator Staff Member

    58,895
    12,490
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,122
    Local Time:
    11:25 PM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
     
    Last edited: Oct 22, 2015
  3. eva2000

    eva2000 Administrator Staff Member

    58,895
    12,490
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,122
    Local Time:
    11:25 PM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
  4. eva2000

    eva2000 Administrator Staff Member

    58,895
    12,490
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,122
    Local Time:
    11:25 PM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+