Results 1 to 6 of 6
  1. #1
    Join Date
    Jun 2008
    Posts
    627
    Plugin Contributions
    0

    Default Question about SSL score "B"

    Hi

    A week or so ago I received an email alerting me to this thread

    PayPal upgrading SSL Certificates in 2015

    http://www.zen-cart.com/showthread.p...icates-in-2015

    Since I don't have permission to reply to that thread I thought I would ask my question here.

    I went to the link provided to test my sites ssl and it received a B. I provided the results link to my host. I also provided the above link to the original thread and asked what could be done to get my sites ssl score up to an A.

    This is the response I received from support

    " I do see that it is receiving a B, however, there is not any information included in the report to determine a direct fix. If ZenCart has information on this that they can provide to you, we would be more than happy to assist further, however, content and design work is not normally within our scope of support, and as the SSL is functioning, this does not appear to be an issue directly related to the server."

    I don't think this has anything to do with content or design. I checked Apache and OpenSSL versions and they appear to be ok:

    Apache: 2.2.29
    OpenSSL:1.0.1e-fips

    I am ready to respond to support and point out the link to paypals pdf file with advise for hosts. Is there anything else I should tell them?

  2. #2
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: Question about SSL score "B"

    First, my apologies for implying in that post that you "must have an A score for PayPal to work". That's an incorrect interpretation of what I meant to convey. I'll update the article.

    Receiving a B score, or any other score at https://www.ssllabs.com/ssltest/ has nothing to do with PayPal or Zen Cart. It's strictly a server-side configuration of your webserver and your domain's vhost within that server.

    An "A" score isn't necessarily required, but anything less than an A could mean customers may occasionally encounter issues using your site in SSL mode. Again though, that's a server thing, and not specific to PayPal or Zen Cart.

    Telling your hosting company to look at anything from PayPal or Zen Cart will not help them fix their optimal configuration of your server with respect to SSL.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  3. #3
    Join Date
    Aug 2009
    Location
    Longs, SC
    Posts
    626
    Plugin Contributions
    2

    Default Re: Question about SSL score "B"

    I received the same score for my client's sites. In all cases the cause of the drop to a B was This server accepts the RC4 cipher, which is weak. Grade capped to B. The solution is for the hosting company to disable the RC4 cipher. Unfortunately in a shared hosting environment they may not be willing to do that. I doubt that just having the RC4 cipher enabled will cause Paypal to stop working.

  4. #4
    Join Date
    Mar 2004
    Posts
    16,042
    Plugin Contributions
    5

    Default Re: Question about SSL score "B"

    Quote Originally Posted by badarac View Post
    I doubt that just having the RC4 cipher enabled will cause Paypal to stop working.
    Since the presence of RC4 ciphers are causing PCI compliance failure it might just stop paypal from working, Not sure just something to think about
    Zen cart PCI compliant Hosting

  5. #5
    Join Date
    Jun 2008
    Posts
    627
    Plugin Contributions
    0

    Default Re: Question about SSL score "B"

    DrByte, I didn't take it that an A was required so no problem, but I figured why not shoot for an A if possible.

    Thanks badarac, I'll pass that info along and see what they have to say.

    Merlinpa1969, if that turns out to be the case, I imagine they will have to deal with it then.


    thanks all for your input

  6. #6
    Join Date
    Jun 2008
    Posts
    627
    Plugin Contributions
    0

    Default Re: Question about SSL score "B"

    Quote Originally Posted by badarac View Post
    I received the same score for my client's sites. In all cases the cause of the drop to a B was This server accepts the RC4 cipher, which is weak. Grade capped to B. The solution is for the hosting company to disable the RC4 cipher. Unfortunately in a shared hosting environment they may not be willing to do that. I doubt that just having the RC4 cipher enabled will cause Paypal to stop working.
    just wanted to come back and say that I passed on your comment to my host. I am on shared hosting and they did disable the RC4 cipher so my site is now getting an A. Thanks

 

 

Similar Threads

  1. v150 I have a question about this "payment fee" on my invoices!!
    By Darion in forum General Questions
    Replies: 2
    Last Post: 29 Sep 2012, 11:26 PM
  2. v150 Is there a mod to "ask a question about an item"?
    By sergiojg in forum General Questions
    Replies: 8
    Last Post: 9 Aug 2012, 11:23 PM
  3. quick "How Did You Hear About Us" question
    By AdamN in forum All Other Contributions/Addons
    Replies: 0
    Last Post: 28 Jul 2008, 07:11 PM
  4. For images, does "base" = "small"? And a question about alternates.
    By molywerks in forum Templates, Stylesheets, Page Layout
    Replies: 5
    Last Post: 29 Feb 2008, 02:49 PM
  5. Question about "sales message goes here" plus
    By techwizard in forum Installing on a Windows Server
    Replies: 2
    Last Post: 25 Nov 2006, 12:30 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR