Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

iFrame not being displayed due to non secure items

Posted on 2014-04-01
2
Medium Priority
?
263 Views
Last Modified: 2014-04-01
Hi All,

We are having an issue with our website with iframes. Here are the particulars:

1. Our main site is hosted on one server and our database driven membership access site is on an another server using an association database called iMIS with the ISGWeb component. These services are displayed through the main site via an iframe. This has worked up until the last few months when more and more users aren't seeing the full iframe and being presented with a request to view non secure content.

2.  The main website is not secure. The membership access site is secure.

3.  Our vendor for the iMIS database suggests the solution is to install an SSL cert on the main server and have the whole site secure. I am not a complete web expert, but that seems not to be a best practice. I am open to other opinions.

4.  I have done some research and came across something related to the same origin policy. I am not a Java expert, so while I understand the fixes presented for this issue, I don't know how to implement them.

Any help or thoughts on this matter would be really appreciated. More and more users are having the issue which I suspect is due to browser upgrades.

Thanks.

Chip
0
Comment
Question by:cwemely
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 54

Accepted Solution

by:
Scott Fell,  EE MVE earned 1500 total points
ID: 39970269
There are a couple of issues you bring up.  First, you will need to have an SSL cert on the main site.  You don't have to use ssl on everypage, but there is nothing wrong with doing so.  It is common today.   If you have ready anything about being "slow" from ssl, it is not enough to know the difference and unless you are serving page views in the millions you will be fine.

The other issue you brought up is java. If it is a java applet the site is loading, then the applet needs to have it's own certificate https://www.java.com/en/download/help/java_blocked.xml.

If the site is private, you might be able to get away with just using https without the cert. You will just always get warnings.  You could do the same with a public site, but it is not worth the hassle. Spend the $50/yr and get a certificate.
0
 

Author Comment

by:cwemely
ID: 39970468
Thanks for the response. Yeah . . . I have finally come to that conclusion after some more research.

Thank you for your help.
0

Featured Post

Hire Technology Freelancers with Gigs

Work with freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely, and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Styling your websites can become very complex. Here I'll show how SASS can help you better organize, maintain and reuse your CSS code.
JavaScript has plenty of pieces of code people often just copy/paste from somewhere but never quite fully understand. Self-Executing functions are just one good example that I'll try to demystify here.
The viewer will learn how to dynamically set the form action using jQuery.
Learn how to set-up custom confirmation messages to users who complete your Wufoo form. Include inputs from fields in your form, webpage redirects, and more with Wufoo’s confirmation options.

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question