If it's plain HTTP, serve it as such. The browser message is not misleading in any way. The site uses an untrusted certificate, and there's danger in that. Just don't put self-signed certs on internet-facing pages. It offers literally no benefit, but causes a reasonable amount of harm.