Page 3 of 3 FirstFirst 123
Results 21 to 27 of 27
  1. #21
    Join Date
    Jun 2008
    Posts
    627
    Plugin Contributions
    0

    Default Re: PayPal SHA-256 Security Update Sept 2015

    ooo, I never saw that post. Thanks. The cart is version 1.3.9. so we may be out of luck on this one.......


    Quote Originally Posted by kobra View Post
    I am pretty certain that this depends upon what version of ZenCart you are using
    Refer to the support doc here
    https://www.zen-cart.com/showthread....ort-Life-Cycle

  2. #22
    Join Date
    Jun 2008
    Posts
    627
    Plugin Contributions
    0

    Default Re: PayPal Security Update

    Paypal has been sending out these announcements again over the past couple of days and I've received several questions. I don't mean to beat this subject to death but another question please; for older carts that are using paypal express and do not have an ssl certificate installed, Will not having a patch for the minor changes you mention cause checkout to not work anymore? I'm thinking that if an ssl certificate is not in use, not having the patch will not be an issue. The issue will arise if the store owner decides to install an ssl cert. Just wanting to be certain.

    I realize keeping carts current is always preferable and that is what I recommend but I want to answer correctly on this question.

    Quote Originally Posted by Ajeh View Post
    There will be only a couple VERY MINOR changes needed to Zen Cart (and will be included in v1.5.5) ... but you WILL need to work with your hosting company to ensure your server is capable of the modern TLS 1.2 security communications requirements.

  3. #23
    Join Date
    Sep 2009
    Location
    Stuart, FL
    Posts
    12,486
    Plugin Contributions
    88

    Default Re: PayPal Security Update

    @buildingblocks, the way I read the PayPal notification, come June if a store doesn't utilize an SSL certificate, that store's not going to be able to use PayPal payment methods.

  4. #24
    Join Date
    Jul 2012
    Posts
    16,733
    Plugin Contributions
    17

    Default Re: PayPal Security Update

    Quote Originally Posted by DrByte View Post
    Sigh.

    No, having a private SSL certificate on your domain is NOT a requirement for a Zen Cart store to operate with PayPal Express Checkout, including the Summer/Fall 2015 SHA-256 changes PayPal is making.

    But a storeowner who is serious about customer engagement and customers feeling comfortable shopping there and that the storeowner actually cares about their security will happily install a private dedicated SSL certificate to their store. The annual cost of a private SSL certificate is so low nowadays that there's very little justification to not do it.
    Quote Originally Posted by lat9 View Post
    @buildingblocks, the way I read the PayPal notification, come June if a store doesn't utilize an SSL certificate, that store's not going to be able to use PayPal payment methods.
    Based on the information provided earlier/above, unless something has changed, I think it is important to identify the difference between a store having a SSL to use for customer's logging onto the store versus the server that is hosting the store and it's communication with paypal... I state this also using information posted after Drbyte's post above indicating the requirements that PayPal. Are putting on the service that is reaching out to PayPal. It doesn't appear to reference how a customer accesses the sales site.
    ZC Installation/Maintenance Support <- Site
    Contribution for contributions welcome...

  5. #25
    Join Date
    Sep 2009
    Location
    Stuart, FL
    Posts
    12,486
    Plugin Contributions
    88

    Default Re: PayPal Security Update

    I'll note that DrByte's comment was made in September of 2015, and that the communication from PayPal appears quite clear.

    From https://www.paypal-knowledge.com/inf...&locale=en_US:
    PayPal is upgrading the protocols used to secure all external connections made to our systems. Transport Layer Security version 1.2 (TLS 1.2) and Hypertext Transfer Protocol version 1.1 (HTTP/1.1) will become mandatory for communication with PayPal in 2016. You will need to verify that your environment supports TLS 1.2 and HTTP/1.1, and if necessary make appropriate updates. For information, click HERE.

    Act by June 17, 2016

  6. #26
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: PayPal Security Update

    Quote Originally Posted by buildingblocks View Post
    Paypal has been sending out these announcements again over the past couple of days and I've received several questions. I don't mean to beat this subject to death but another question please; for older carts that are using paypal express and do not have an ssl certificate installed, Will not having a patch for the minor changes you mention cause checkout to not work anymore? I'm thinking that if an ssl certificate is not in use, not having the patch will not be an issue. The issue will arise if the store owner decides to install an ssl cert. Just wanting to be certain.

    I realize keeping carts current is always preferable and that is what I recommend but I want to answer correctly on this question.
    The majority of the requirements to meet these changes PayPal is talking about (and indeed the entire payment industry) have VERY LITTLE to do with having an "SSL certificate for your domain name".
    But they DO have EVERYTHING to do with ensuring that the server's SSL/TLS capabilities for doing external communications over CURL/OpenSSL/etc to be up-to-date using modern versions and modern components.
    More about that here: https://www.zen-cart.com/entry.php?8...Back-and-Front and also in the links PayPal has been sending out. Tell your server administrator to take care of upgrading the server's TLS and HTTP infrastructure to modern standards.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  7. #27
    Join Date
    Jun 2008
    Posts
    627
    Plugin Contributions
    0

    Default Re: PayPal Security Update

    Thanks, everyone for your input.

 

 
Page 3 of 3 FirstFirst 123

Similar Threads

  1. Ajax security fix November 2015
    By brittainmark in forum Bug Reports
    Replies: 9
    Last Post: 13 May 2016, 04:50 AM
  2. Replies: 44
    Last Post: 16 Mar 2016, 04:29 PM
  3. v150 Paypal's new SHA-256 certificate
    By BryanKollar in forum PayPal Express Checkout support
    Replies: 1
    Last Post: 11 Sep 2015, 03:38 AM
  4. USPS update Sept 7
    By svetlae in forum Built-in Shipping and Payment Modules
    Replies: 2
    Last Post: 2 Sep 2014, 04:18 PM
  5. Replies: 2
    Last Post: 31 Dec 2009, 04:42 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR