Closed Bug 877763 Opened 11 years ago Closed 11 years ago

https://www.kohls.com/ may not work properly because of mixed content blocking

Categories

(Tech Evangelism Graveyard :: English US, defect)

defect
Not set
minor

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: mwobensmith, Unassigned)

References

()

Details

(Keywords: verifyme, Whiteboard: [mcb-chrome30+][mcb-ie])

Mixed content blocking is a feature that prevents insecure elements on secure pages from loading. In Firefox 23, this feature will default to blocking "active" insecure content, which may break some web sites. 

More information on Firefox's Mixed Content Blocker is below: 
http://blog.mozilla.org/tanvi/2013/04/10/mixed-content-blocking-enabled-in-firefox-23/

The security feature is currently causing errors the HTTPS version of www.kohls.com. It also appears to be functioning incorrectly in IE10.

https://www.kohls.com/ should render and function like http://www.kohls.com/, but it doesn't because some HTTP resource(s) are not loaded.  Here is a list of the active, HTTP resources that were blocked: 

Blocked loading mixed active content "http://www.facebook.com/plugins/likebox.php?href=http%3A%2F%2Fwww.facebook.com%2Fkohls&width=315&colorscheme=light&connections=5&border_color=%23A5A9AC&stream=false&header=false&height=185" @ https://www.kohls.com/:3122
When trying to browser https://kohls.com and add items to your shopping cart, the customer reviews section is missing because of mixed content (http) loads.
Whiteboard: [mcb-chrome29+][mcb-ie]
I emailed the Kohl's webmaster pointing them to this bug.
Whiteboard: [mcb-chrome29+][mcb-ie] → [mcb-chrome30+][mcb-ie]
https://kohls.com has an invalid cert:

kohls.com uses an invalid security certificate. The certificate is only valid for *.test.edgekey.net (Error code: ssl_error_bad_cert_domain)

And https://www.kohls.com redirects me to http://kohls.com.

I think we can close this bug.  Adding verifyme keyword so that this is verified.
Status: NEW → RESOLVED
Closed: 11 years ago
Keywords: verifyme
Resolution: --- → FIXED
Product: Tech Evangelism → Tech Evangelism Graveyard
You need to log in before you can comment on or make changes to this bug.