Results 1 to 5 of 5
  1. #1
    Join Date
    Feb 2007
    Posts
    513
    Plugin Contributions
    2

    Default Question Re: POODLE SSL Vulnerability vs if I have no SSL certificate on my store

    Hello,
    Regarding: http://www.zen-cart.com/showthread.p...yment-security
    Question: Do I need to update if my website does not have SSL installed?

    Also,
    I tested one of my websites that has SSL and I was directed to the paypal website fine, no problem.
    Question: Do I need to do the update anyway?
    Also, could there be a problem with sending the payment receipt back to my website after purchase, that I am not seeing because I did not place an order.

  2. #2
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: POODLE SSL Vulnerability and paypal CURLOPT_SSLVERSION update

    Yes, you should apply the change anyway.
    The SSL used to broker the payment transaction takes place at a different level in your server and is not related to whether you bought an SSL certificate for your store or not.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  3. #3
    Join Date
    Feb 2007
    Posts
    513
    Plugin Contributions
    2

    Default Re: Question Re: POODLE SSL Vulnerability vs if I have no SSL certificate on my store

    probably I am not using SSL version 3 because checkout seems fine? and if I am not using version 3 I do not need to update?
    I will check other websites to make sure checkout is going to paypay and that should tell me if I need to update?

  4. #4
    Join Date
    Feb 2007
    Posts
    513
    Plugin Contributions
    2

    Default Re: Question Re: POODLE SSL Vulnerability vs if I have no SSL certificate on my store

    p.s.
    I just got your message and will update anyway.

  5. #5
    Join Date
    Feb 2007
    Posts
    513
    Plugin Contributions
    2

    Default Re: Question Re: POODLE SSL Vulnerability vs if I have no SSL certificate on my store

    Also I read
    Quote Originally Posted by DrByte
    Sigh. It appears as though PayPal may have (temporarily) recanted their earlier aggressive block of all SSL3 connectivity to their live site, as connections are once again working fine (at this moment) using the original CURLOPT_SSLVERSION => 3 setting.

    But they have stated that they will remove SSLv3 entirely very soon:
    https://www.paypal-community.com/t5/...LE/ba-p/891829

 

 

Similar Threads

  1. v150 Paypal SSL 3.0 vulnerability
    By ss90 in forum PayPal Express Checkout support
    Replies: 2
    Last Post: 13 Nov 2014, 02:58 AM
  2. Securing store with a SSL Certificate
    By milelk in forum General Questions
    Replies: 14
    Last Post: 10 Jan 2011, 06:07 PM
  3. Replies: 1
    Last Post: 21 Apr 2008, 11:15 PM
  4. Viewing store through shared SSL certificate
    By kylelondonuk in forum Templates, Stylesheets, Page Layout
    Replies: 3
    Last Post: 6 Oct 2007, 08:02 PM
  5. Question about setting up a Shared SSL Certificate
    By mlm2005 in forum Basic Configuration
    Replies: 16
    Last Post: 27 Dec 2006, 12:52 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR