"HTTPS security is compromised" message is shown in Console when a HTTPS page is loaded in iframe

May 5, 2014
Steps to reproduce

URL = http://srvr-clw/bugs/67132/


Repro Steps:

  1. Download the attached file “iframe.html” to your local machine.
  2. Open it in IE.
  3. Press F12 to open "F12 Developer Tools". Switch to Network panel and enable traffic capturing.
  4. Refresh the webpage (iframe.html)
  5. Go to the Developer Tools -> Console, and you will see an error message: “SEC7111: HTTPS security is compromised by https://en.wikipedia.org/wiki/Main_Page File: iframe.html”
  6. But if you check the traffic capturing result, you will see that all resources (js, css, img) are loaded via HTTPS.

Expected Results:

The error message “SEC7111 …” should not be shown because all resources are loaded in HTTPS.

Actual Results:


