This one has been resolved but not solved. Set var $live_site to https and the security warning is no longer displaying. However, now my entire site is https instead of just the login and registration. I really don't want the entire site https but would rather have that than getting warnings and errors and potential for unsecure password posting and registration.
It appears that whatever is calling
www.mysite.com/components/com_comprofiler/js/cb12.min.js
?... is not recogizing the settings in the cb_login module.