Showing posts with label ssl. Show all posts
Showing posts with label ssl. Show all posts

Saturday, March 31, 2012

There is a bug concerning SSL and ASP.Net 2.0 Menu Control

Hi all

It appears there is a bug - when using a 2 or more tier menu control in
asp.net in an SSL environment you get prompted with the:

"This page contains both secure and non-secure items blah blah"

a) has anyone else experienced?

b) if so do we know when to expect it to be fixed?

Thanks
KevMantorok wrote:
> Hi all
> It appears there is a bug - when using a 2 or more tier menu control in
> asp.net in an SSL environment you get prompted with the:
> "This page contains both secure and non-secure items blah blah"

Have you looked at the generated HTML to see if there is a mistake that
you made? I haven't used this control in an SSL environment yet so I'm
only speculating.

Good luck,

--
Sean
"Fao, Sean" <enceladus311@.yahoo.comI-WANT-NO-SPAM> wrote in message
news:ubV70OfFGHA.1288@.TK2MSFTNGP09.phx.gbl...
> Mantorok wrote:
>> Hi all
>>
>> It appears there is a bug - when using a 2 or more tier menu control in
>> asp.net in an SSL environment you get prompted with the:
>>
>> "This page contains both secure and non-secure items blah blah"
> Have you looked at the generated HTML to see if there is a mistake that
> you made? I haven't used this control in an SSL environment yet so I'm
> only speculating.

Yep I've checked, I've used relative paths in my links.

Kev
"Mantorok" <mantorok@.mantorok.com> wrote in message
news:dq0h62$nmc$1@.newsfeed.th.ifl.net...

> Yep I've checked, I've used relative paths in my links.

Do any of the links point to resources in non-SSL locations? If so, you will
get the message box by default when you access an SSL page which contains
links to non-SSL resources.
"Mark Rae" <mark@.markN-O-S-P-A-M.co.uk> wrote in message
news:Oub62lfFGHA.1676@.TK2MSFTNGP09.phx.gbl...
> "Mantorok" <mantorok@.mantorok.com> wrote in message
> news:dq0h62$nmc$1@.newsfeed.th.ifl.net...
>> Yep I've checked, I've used relative paths in my links.
> Do any of the links point to resources in non-SSL locations? If so, you
> will get the message box by default when you access an SSL page which
> contains links to non-SSL resources.

Yes there are links in the master page that link back to non-secure sites -
does that really make a difference? Sounds odd if it does.

Kev
"Mantorok" <mantorok@.mantorok.com> wrote in message
news:dq0lgl$q9r$1@.newsfeed.th.ifl.net...

> Yes there are links in the master page that link back to non-secure
> sites -

There's your problem...

> does that really make a difference?

Yes.

> Sounds odd if it does.

Perfectly logical if you think about it...
"Mark Rae" <mark@.markN-O-S-P-A-M.co.uk> wrote in message
news:eGZYZCgFGHA.1676@.TK2MSFTNGP09.phx.gbl...
> "Mantorok" <mantorok@.mantorok.com> wrote in message
> news:dq0lgl$q9r$1@.newsfeed.th.ifl.net...
>> Yes there are links in the master page that link back to non-secure
>> sites -
> There's your problem...
>> does that really make a difference?
> Yes.
>> Sounds odd if it does.
> Perfectly logical if you think about it...

Wait a minute - do you mean hyperlinks or just linking to non-secure stuff,
if you mean the latter then no, but the former - yes.

Kev
most likely you are referencing an image over http. the easiest way to find
the reference is to use firefox, and goto to the media tab on the pageinfo,
you will see the http reference.

-- bruce (sqlwork.com)

"Mantorok" <mantorok@.mantorok.com> wrote in message
news:dq0gjm$nbo$1@.newsfeed.th.ifl.net...
> Hi all
> It appears there is a bug - when using a 2 or more tier menu control in
> asp.net in an SSL environment you get prompted with the:
> "This page contains both secure and non-secure items blah blah"
> a) has anyone else experienced?
> b) if so do we know when to expect it to be fixed?
> Thanks
> Kev
"Mantorok" <mantorok@.mantorok.com> wrote in message
news:dq0nd6$rbg$1@.newsfeed.th.ifl.net...

> Wait a minute - do you mean hyperlinks or just linking to non-secure
> stuff, if you mean the latter then no, but the former - yes.

Either; both; whatever - that's the way it is...
"Mark Rae" <mark@.markN-O-S-P-A-M.co.uk> wrote in message
news:eQVWamnFGHA.3064@.TK2MSFTNGP10.phx.gbl...
> "Mantorok" <mantorok@.mantorok.com> wrote in message
> news:dq0nd6$rbg$1@.newsfeed.th.ifl.net...
>> Wait a minute - do you mean hyperlinks or just linking to non-secure
>> stuff, if you mean the latter then no, but the former - yes.
> Either; both; whatever - that's the way it is...

I don't think so - a hyperlink on a SSL site pointing to HTTP is not classed
as containing a non-secure item.

Firefox doesn't seem to give me this message, only IE...

Kev
"Bruce Barker" <brubar_nospamplease_@.safeco.com> wrote in message
news:ORHYzZiFGHA.2444@.TK2MSFTNGP11.phx.gbl...
> most likely you are referencing an image over http. the easiest way to
> find the reference is to use firefox, and goto to the media tab on the
> pageinfo, you will see the http reference.

Nope - all HTTPS - also, Firefox doesn't give me this shit - only IE
does...

Kev
Hi

Any references to non-SSL pages - including the code which is generated by
the Menu can cause the warning. I've noticed when I create a menu (I'm having
many other issues right now which I'm working through) that the page
generates LOTS of code and references a files in the head from the root
called /WebResource.axd?d=6txiuwerieurieuriu etc.

Also, any sytle sheet references would need considering too.

does this help?

There is a bug concerning SSL and ASP.Net 2.0 Menu Control

Hi all
It appears there is a bug - when using a 2 or more tier menu control in
asp.net in an SSL environment you get prompted with the:
"This page contains both secure and non-secure items blah blah"
a) has anyone else experienced?
b) if so do we know when to expect it to be fixed?
Thanks
KevMantorok wrote:
> Hi all
> It appears there is a bug - when using a 2 or more tier menu control in
> asp.net in an SSL environment you get prompted with the:
> "This page contains both secure and non-secure items blah blah"
Have you looked at the generated HTML to see if there is a mistake that
you made? I haven't used this control in an SSL environment yet so I'm
only speculating.
Good luck,
Sean
"Fao, Sean" <enceladus311@.yahoo.comI-WANT-NO-SPAM> wrote in message
news:ubV70OfFGHA.1288@.TK2MSFTNGP09.phx.gbl...
> Mantorok wrote:
> Have you looked at the generated HTML to see if there is a mistake that
> you made? I haven't used this control in an SSL environment yet so I'm
> only speculating.
Yep I've checked, I've used relative paths in my links.
Kev
"Mantorok" <mantorok@.mantorok.com> wrote in message
news:dq0h62$nmc$1@.newsfeed.th.ifl.net...

> Yep I've checked, I've used relative paths in my links.
Do any of the links point to resources in non-SSL locations? If so, you will
get the message box by default when you access an SSL page which contains
links to non-SSL resources.
"Mark Rae" <mark@.markN-O-S-P-A-M.co.uk> wrote in message
news:Oub62lfFGHA.1676@.TK2MSFTNGP09.phx.gbl...
> "Mantorok" <mantorok@.mantorok.com> wrote in message
> news:dq0h62$nmc$1@.newsfeed.th.ifl.net...
>
> Do any of the links point to resources in non-SSL locations? If so, you
> will get the message box by default when you access an SSL page which
> contains links to non-SSL resources.
Yes there are links in the master page that link back to non-secure sites -
does that really make a difference? Sounds odd if it does.
Kev
"Mantorok" <mantorok@.mantorok.com> wrote in message
news:dq0lgl$q9r$1@.newsfeed.th.ifl.net...

> Yes there are links in the master page that link back to non-secure
> sites -
There's your problem...

> does that really make a difference?
Yes.

> Sounds odd if it does.
Perfectly logical if you think about it...
"Mark Rae" <mark@.markN-O-S-P-A-M.co.uk> wrote in message
news:eGZYZCgFGHA.1676@.TK2MSFTNGP09.phx.gbl...
> "Mantorok" <mantorok@.mantorok.com> wrote in message
> news:dq0lgl$q9r$1@.newsfeed.th.ifl.net...
>
> There's your problem...
>
> Yes.
>
> Perfectly logical if you think about it...
Wait a minute - do you mean hyperlinks or just linking to non-secure stuff,
if you mean the latter then no, but the former - yes.
Kev
most likely you are referencing an image over http. the easiest way to find
the reference is to use firefox, and goto to the media tab on the pageinfo,
you will see the http reference.
-- bruce (sqlwork.com)
"Mantorok" <mantorok@.mantorok.com> wrote in message
news:dq0gjm$nbo$1@.newsfeed.th.ifl.net...
> Hi all
> It appears there is a bug - when using a 2 or more tier menu control in
> asp.net in an SSL environment you get prompted with the:
> "This page contains both secure and non-secure items blah blah"
> a) has anyone else experienced?
> b) if so do we know when to expect it to be fixed?
> Thanks
> Kev
>
"Mantorok" <mantorok@.mantorok.com> wrote in message
news:dq0nd6$rbg$1@.newsfeed.th.ifl.net...

> Wait a minute - do you mean hyperlinks or just linking to non-secure
> stuff, if you mean the latter then no, but the former - yes.
Either; both; whatever - that's the way it is...
"Mark Rae" <mark@.markN-O-S-P-A-M.co.uk> wrote in message
news:eQVWamnFGHA.3064@.TK2MSFTNGP10.phx.gbl...
> "Mantorok" <mantorok@.mantorok.com> wrote in message
> news:dq0nd6$rbg$1@.newsfeed.th.ifl.net...
>
> Either; both; whatever - that's the way it is...
I don't think so - a hyperlink on a SSL site pointing to HTTP is not classed
as containing a non-secure item.
Firefox doesn't seem to give me this message, only IE...
Kev

Saturday, March 24, 2012

This page contains both secure and non secure items.

Hi,
My ASP.NET application uses SSL on IIS6. up on visiting some pages, IE 6
shows this security alert:
This page contains both secure and non secure items.
Do you want to display non-secure items?
Regardless I answer no (or yes), everything works fine.
We don't like our users see that message because it makes them nervous
without any good reason.
How can I track why the browswer shows that flase security alert?
Thanks,
AlanHi Alan,
Are you using SmartNavigation in the page or referencing scripts that are
outside the Application?
Here's an article on the SmartNav problem:
Error Message When You Submit .aspx Page with SmartNav Under SSL
http://support.microsoft.com/defaul...kb;en-us;318320
"A.M" <nospam1@.online.nospam> wrote in message
news:upfpDoNTEHA.3608@.TK2MSFTNGP11.phx.gbl...
> Hi,
> My ASP.NET application uses SSL on IIS6. up on visiting some pages, IE 6
> shows this security alert:
> This page contains both secure and non secure items.
> Do you want to display non-secure items?
> Regardless I answer no (or yes), everything works fine.
> We don't like our users see that message because it makes them nervous
> without any good reason.
> How can I track why the browswer shows that flase security alert?
>
> Thanks,
> Alan
>
Are you using frames?
http://support.microsoft.com/defaul...b;EN-US;Q184960
"A.M" <nospam1@.online.nospam> wrote in message
news:upfpDoNTEHA.3608@.TK2MSFTNGP11.phx.gbl...
> Hi,
> My ASP.NET application uses SSL on IIS6. up on visiting some pages, IE 6
> shows this security alert:
> This page contains both secure and non secure items.
> Do you want to display non-secure items?
> Regardless I answer no (or yes), everything works fine.
> We don't like our users see that message because it makes them nervous
> without any good reason.
> How can I track why the browswer shows that flase security alert?
>
> Thanks,
> Alan
>
No, I don't
"Ken Cox [Microsoft MVP]" <BANSPAMken_cox@.sympatico.ca> wrote in message
news:%23d0KaePTEHA.3552@.TK2MSFTNGP09.phx.gbl...
> Are you using frames?
> http://support.microsoft.com/defaul...b;EN-US;Q184960
> "A.M" <nospam1@.online.nospam> wrote in message
> news:upfpDoNTEHA.3608@.TK2MSFTNGP11.phx.gbl...
>
It is not smartnavigation because the warning pops up on one specific page.
I am pasting the page source at the end of this post:
Thanks,
Alan
========================================
=============================
<!-- Template Start-->
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" >
<HTML>
<HEAD>
<title>Please Wait ...</title>
<meta name="GENERATOR" Content="Microsoft Visual Studio .NET 7.1">
<meta name="CODE_LANGUAGE" Content="C#">
<meta name="vs_defaultClientScript" content="JavaScript">
<meta name="vs_targetSchema"
content="http://schemas.microsoft.com/intellisense/ie5">
<script language="javascript">
self.focus();
function BeginPageLoad()
{
location.href = "LLViewer.aspx?rid=21";
}
</script>
</HEAD>
<body onload="BeginPageLoad()">
<form name="Form1" method="post"
action="LLWait.aspx?redirect=LLViewer.aspx%3frid%3d21" id="Form1">
<input type="hidden" name="__VIEWSTATE"
value=" dDwxNzg0NjA0NTg0Ozs+5wOOcjTIemMpowWPCjq0
XgZxlAA=" />
<P> </P>
<P> </P>
<P> </P>
<P align="center">
<object classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000"
codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.ca
b#version=6,0,29,0" width="400" height="200" VIEWASTEXT>
<param name="movie" value="/LLC/Images/PleaseWait.swf">
<param name="quality" value="high">
<embed src="http://pics.10026.com/?src=/LLC/Images/PleaseWait.swf" quality="high"
pluginspage="http://www.macromedia.com/go/getflashplayer"
type="application/x-shockwave-flash" width="400" height="200"></embed>
</object>
</P>
<P> </P>
</form>
</body>
</HTML>
<!-- Template End-->
========================================
=============================
"Ken Cox [Microsoft MVP]" <BANSPAMken_cox@.sympatico.ca> wrote in message
news:eH1BFdPTEHA.2408@.tk2msftngp13.phx.gbl...
> Hi Alan,
> Are you using SmartNavigation in the page or referencing scripts that are
> outside the Application?
> Here's an article on the SmartNav problem:
> Error Message When You Submit .aspx Page with SmartNav Under SSL
> http://support.microsoft.com/defaul...kb;en-us;318320
>
> "A.M" <nospam1@.online.nospam> wrote in message
> news:upfpDoNTEHA.3608@.TK2MSFTNGP11.phx.gbl...
>
Hi,
the error occurs because browser is fetching content both from secure and
insecure pages. Unless there isn't any clear that comes with HTTP (and uses
SSL that is HTTPS), you just need to remove the HTML snippet by snippet to
test out which part causes the problem.
Teemu Keiski
MCP, Microsoft MVP (ASP.NET), AspInsiders member
ASP.NET Forum Moderator, AspAlliance Columnist
http://blogs.aspadvice.com/joteke
"A.M" <nospam1@.online.nospam> wrote in message
news:edCLHPWTEHA.2128@.TK2MSFTNGP11.phx.gbl...
> No, I don't
> "Ken Cox [Microsoft MVP]" <BANSPAMken_cox@.sympatico.ca> wrote in messa
ge
> news:%23d0KaePTEHA.3552@.TK2MSFTNGP09.phx.gbl...
6
>

This page contains both secure and non secure items.

Hi,

My ASP.NET application uses SSL on IIS6. up on visiting some pages, IE 6
shows this security alert:

This page contains both secure and non secure items.
Do you want to display non-secure items?

Regardless I answer no (or yes), everything works fine.

We don't like our users see that message because it makes them nervous
without any good reason.

How can I track why the browswer shows that flase security alert?

Thanks,
AlanHi Alan,

Are you using SmartNavigation in the page or referencing scripts that are
outside the Application?

Here's an article on the SmartNav problem:

Error Message When You Submit .aspx Page with SmartNav Under SSL

http://support.microsoft.com/defaul...kb;en-us;318320

"A.M" <nospam1@.online.nospam> wrote in message
news:upfpDoNTEHA.3608@.TK2MSFTNGP11.phx.gbl...
> Hi,
> My ASP.NET application uses SSL on IIS6. up on visiting some pages, IE 6
> shows this security alert:
> This page contains both secure and non secure items.
> Do you want to display non-secure items?
> Regardless I answer no (or yes), everything works fine.
> We don't like our users see that message because it makes them nervous
> without any good reason.
> How can I track why the browswer shows that flase security alert?
>
> Thanks,
> Alan
Are you using frames?

http://support.microsoft.com/defaul...b;EN-US;Q184960

"A.M" <nospam1@.online.nospam> wrote in message
news:upfpDoNTEHA.3608@.TK2MSFTNGP11.phx.gbl...
> Hi,
> My ASP.NET application uses SSL on IIS6. up on visiting some pages, IE 6
> shows this security alert:
> This page contains both secure and non secure items.
> Do you want to display non-secure items?
> Regardless I answer no (or yes), everything works fine.
> We don't like our users see that message because it makes them nervous
> without any good reason.
> How can I track why the browswer shows that flase security alert?
>
> Thanks,
> Alan
No, I don't
"Ken Cox [Microsoft MVP]" <BANSPAMken_cox@.sympatico.ca> wrote in message
news:%23d0KaePTEHA.3552@.TK2MSFTNGP09.phx.gbl...
> Are you using frames?
> http://support.microsoft.com/defaul...b;EN-US;Q184960
> "A.M" <nospam1@.online.nospam> wrote in message
> news:upfpDoNTEHA.3608@.TK2MSFTNGP11.phx.gbl...
> > Hi,
> > My ASP.NET application uses SSL on IIS6. up on visiting some pages, IE 6
> > shows this security alert:
> > This page contains both secure and non secure items.
> > Do you want to display non-secure items?
> > Regardless I answer no (or yes), everything works fine.
> > We don't like our users see that message because it makes them nervous
> > without any good reason.
> > How can I track why the browswer shows that flase security alert?
> > Thanks,
> > Alan
It is not smartnavigation because the warning pops up on one specific page.
I am pasting the page source at the end of this post:

Thanks,
Alan

================================================== ===================

<!-- Template Start-->
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" >
<HTML>
<HEAD>
<title>Please Wait ...</title>
<meta name="GENERATOR" Content="Microsoft Visual Studio .NET 7.1">
<meta name="CODE_LANGUAGE" Content="C#">
<meta name="vs_defaultClientScript" content="JavaScript">
<meta name="vs_targetSchema"
content="http://schemas.microsoft.com/intellisense/ie5">
<script language="javascript">
self.focus();

function BeginPageLoad()
{
location.href = "LLViewer.aspx?rid=21";
}
</script>
</HEAD>
<body onload="BeginPageLoad()">
<form name="Form1" method="post"
action="LLWait.aspx?redirect=LLViewer.aspx%3frid%3d21" id="Form1">
<input type="hidden" name="__VIEWSTATE"
value="dDwxNzg0NjA0NTg0Ozs+5wOOcjTIemMpowWPCjq0XgZxlAA=" /
<P> </P>
<P> </P>
<P> </P>
<P align="center">
<object classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000"
codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.ca
b#version=6,0,29,0" width="400" height="200" VIEWASTEXT>
<param name="movie" value="/LLC/Images/PleaseWait.swf">
<param name="quality" value="high">
<embed src="http://pics.10026.com/?src=/LLC/Images/PleaseWait.swf" quality="high"
pluginspage="http://www.macromedia.com/go/getflashplayer"
type="application/x-shockwave-flash" width="400" height="200"></embed>
</object>
</P>
<P> </P>
</form>
</body>
</HTML>
<!-- Template End--
================================================== ===================

"Ken Cox [Microsoft MVP]" <BANSPAMken_cox@.sympatico.ca> wrote in message
news:eH1BFdPTEHA.2408@.tk2msftngp13.phx.gbl...
> Hi Alan,
> Are you using SmartNavigation in the page or referencing scripts that are
> outside the Application?
> Here's an article on the SmartNav problem:
> Error Message When You Submit .aspx Page with SmartNav Under SSL
> http://support.microsoft.com/defaul...kb;en-us;318320
>
> "A.M" <nospam1@.online.nospam> wrote in message
> news:upfpDoNTEHA.3608@.TK2MSFTNGP11.phx.gbl...
> > Hi,
> > My ASP.NET application uses SSL on IIS6. up on visiting some pages, IE 6
> > shows this security alert:
> > This page contains both secure and non secure items.
> > Do you want to display non-secure items?
> > Regardless I answer no (or yes), everything works fine.
> > We don't like our users see that message because it makes them nervous
> > without any good reason.
> > How can I track why the browswer shows that flase security alert?
> > Thanks,
> > Alan
Hi,

the error occurs because browser is fetching content both from secure and
insecure pages. Unless there isn't any clear that comes with HTTP (and uses
SSL that is HTTPS), you just need to remove the HTML snippet by snippet to
test out which part causes the problem.

--
Teemu Keiski
MCP, Microsoft MVP (ASP.NET), AspInsiders member
ASP.NET Forum Moderator, AspAlliance Columnist
http://blogs.aspadvice.com/joteke

"A.M" <nospam1@.online.nospam> wrote in message
news:edCLHPWTEHA.2128@.TK2MSFTNGP11.phx.gbl...
> No, I don't
> "Ken Cox [Microsoft MVP]" <BANSPAMken_cox@.sympatico.ca> wrote in message
> news:%23d0KaePTEHA.3552@.TK2MSFTNGP09.phx.gbl...
> > Are you using frames?
> > http://support.microsoft.com/defaul...b;EN-US;Q184960
> > "A.M" <nospam1@.online.nospam> wrote in message
> > news:upfpDoNTEHA.3608@.TK2MSFTNGP11.phx.gbl...
> > > Hi,
> > > > My ASP.NET application uses SSL on IIS6. up on visiting some pages, IE
6
> > > shows this security alert:
> > > > This page contains both secure and non secure items.
> > > Do you want to display non-secure items?
> > > > Regardless I answer no (or yes), everything works fine.
> > > > We don't like our users see that message because it makes them nervous
> > > without any good reason.
> > > > How can I track why the browswer shows that flase security alert?
> > > > > Thanks,
> > > Alan
> >