What action can you take?
Review your custom content and ensure that it’s served through a secure HTTPS host. HTTPS uses encryption of data in-transit (TLS) to prevent attacks such as man-in-middle. The method of configuring HTTPS may change based on the service you are using. Please use the service-specific links above for additional guidance on configuring HTTPS.
Can I use a workaround until I configure HTTPS?
We recommend configuring HTTPS on all pages. While you are configuring HTTPS, the following interim workarounds will help you to overcome mixed content-related errors.
To enable the Google Chrome mixed content flag within Chrome, click the padlock icon in the URL bar → Click Site Settings → Find the Insecure Content dropdown. Then use the dropdown list to change Block (default) to Allow. Note that Google hasn’t announced how long this functionality remains available.
Note: We do not recommend this approach unless you have business-critical needs and strongly recommend configuring HTTPS as soon as possible.
Q: What is mixed content?
A: Web pages are rendered by browsers based on two protocols – HTTP and HTTPS. A website that follows the HTTPS protocol is far safer than one that uses HTTP. HTTPS-enabled sites are encrypted, thus ensuring authentication, data integrity, secrecy. However, there are websites that load both HTTPS and HTTP content on the same page and this is called Mixed Content. Most sites that face mixed content issues have external resources such as images, videos, style sheets, scripts loaded via the HTTP domain. Even though the initial request is sent as HTTPS, once the mixed content is rendered in the Google Chrome browser, it shows the site as insecure as there are chances that the HTTP resources may harm the users.
Q: What is the timeline for the change?
A: The planned Google Chrome rollout begins with a browser warning and then advances to blocking mixed content downloads. Here is the Google Chrome rollout schedule for your reference.
| Type of content | File examples | Browser warning | Blocking |
|---|---|---|---|
| Executables | exe, apk | Chrome 84 (Aug) | Chrome 85 (Sep) |
| Archives | zip, iso | Chrome 85 (Sep) | Chrome 86 (Oct) |
| Documents | pdf, docx | Chrome 86 (Oct) | Chrome 87 (Nov) |
| Multimedia | png, mp3 | Chrome 87 (Nov) | Chrome 89 (Jan '21) |
Q: What is impacted?
A:
Q: What is NOT impacted?
A:
000390796

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.