Why does my HTTPS page show "not fully secure"?
You installed a certificate, the page loads over HTTPS, yet the browser still complains. What is it objecting to? Almost always: mixed content — a secure page pulling sub-resources over plain HTTP.
Mixed content means an https:// page references http:// assets. Browsers split it into two classes with different treatment:
— Active mixed content: scripts, stylesheets, iframes, XHR/fetch. These can rewrite the entire page, so browsers block them outright. This is why "the page is broken" — your JavaScript over HTTP silently never loaded.
— Passive mixed content: images, audio, video. Historically only warned about, because they can't execute code — though modern browsers now auto-upgrade these to HTTPS where possible.
The security reasoning is concrete: a single HTTP-loaded script over an otherwise encrypted page hands a network attacker full DOM control, defeating the entire TLS session. So blocking active content isn't pedantry; it's closing the weakest link.
Two fixes worth knowing: serve every asset over HTTPS (the real fix), and add the upgrade-insecure-requests Content-Security-Policy directive, which tells the browser to rewrite http:// sub-resource URLs to https:// automatically.
Further reading: W3C Mixed Content specification; MDN's mixed-content reference.
Bottom line: one HTTP resource compromises a whole HTTPS page. Active content is blocked, passive is upgraded — serve everything over HTTPS to clear the warning.
Handshake Papers
@HandshakePapers
Why does my HTTPS page show "not fully secure"?
Этот пост опубликован в Telegram-канале Handshake Papers. Подписаться можно по ссылке: @HandshakePapers.