CA-signed: Green lockpad
Self-signed: Yellow lockpad, with question mark superimposed over it
Regular HTTP: Orange, no lockpad (insecure)
Invalid or revoked cert: Red, "stay away" displayed within <blink> tags.
The current UI that most browsers present implies that self-signed certificates are worse ("scarier") than regular HTTP, which is not true.