slightly off topic:
i wonder why google (or mozilla) do not add something like a "less secure" root CA service where everybody can get a ssl cert for free (after showing control over the domain).
this would degrade the annoying message to a simple warning and probably make lots of hobbyist websites use only ssl.
(if you have to choose between annoy your user or just using plain http i guess many choose the later.)