Zen Cart Logo
Forums / Built-in Shipping and Payment Modules / PayPal SHA-256 Security Update Sept 2015

PayPal SHA-256 Security Update Sept 2015

Views: 15,300

Results 1 to 20 of 27
11 Sep 2015, 12:59 AM
#1
malaperth avatar

malaperth

New Zenner

Join Date:
Dec 2013
Location:
Maine
Posts:
77
Plugin Contributions:
0

PayPal SHA-256 Security Update Sept 2015

I received this email and read all it offered and I apologize for my ignorance, but I have no idea what it means as far as changes to the server (I am running 1.5.1 with, at the moment, the original PayPal, not the Express). This is the email:

As we have previously communicated to you, PayPal is upgrading the certificate for https://www.paypal.com to SHA-256. This endpoint is also used by merchants using the Instant Payment Notification (IPN) product.

This upgrade is scheduled for 9/30/2015; however, we may need to change this date on short notice to you to align to the industry security standard.

You’re receiving this notification because you’ve been identified as a merchant who has used IPN endpoints within the past year. If you have not made the necessary changes, we urge you to do so right away to avoid a disruption of your service!
Because these changes are technical in nature, we advise that you consult with your individuals responsible for your PayPal integration. They will be able to identify what, if any, changes are needed. Please share this email and the hyperlinks below with your technical contact for evaluation.

Testing in the Sandbox is one of the best ways to make sure your integration works. Sandbox endpoints have been upgraded to accept secure connections by the SHA-256 Certificates.

Full technical details can be found in our Merchant Security System Upgrade Guide. In addition, our 2015-2016 SSL Certificate Change microsite contains a schedule of our service upgrade plan.

I can't be the only one that's gotten this email so it seems I'm just the only one ignorant enough to not know what it means as far as server changes on the old 1.5.1 version of Zen Cart. Would anyone be so kind as to educate me as to what I need to do?

Mal

11 Sep 2015, 2:44 AM
#2
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: PayPal SHA-256 Security Update Sept 2015

PayPal first started talking about this back in March, and I posted the following in response to that: PayPal upgrading SSL Certificates in 2015

In short, Zen Cart itself is not affected at all by these changes.

Nevertheless you may want to take this opportunity to get your hosting company to ensure they've got their server up-to-date. I posted some guidance in the above article for you to reference.

14 Sep 2015, 9:12 AM
#3
cscotty avatar

cscotty

New Zenner

Join Date:
Nov 2014
Location:
United Kingdom
Posts:
38
Plugin Contributions:
0

Re: PayPal SHA-256 Security Update Sept 2015

DrByte:

PayPal first started talking about this back in March, and I posted the following in response to that: PayPal upgrading SSL Certificates in 2015

In short, Zen Cart itself is not affected at all by these changes.

Nevertheless you may want to take this opportunity to get your hosting company to ensure they've got their server up-to-date. I posted some guidance in the above article for you to reference.

Appending to this thread as it is relevant.

DrByte: the link at 2(a) for advice to your hosting company in the post you refer to above doesn't work. Seems it's some kind of privileged area.

I am completly stuck on this security update. I switched to the sandbox and it fails with error:
10002
Security error
Security header is not valid

I have done as the post suggested i.e point out the issues to the hosting company. They have improved the grading up to "C" but no joy. I would need to moved to different server to upgrade to TLS 1.2 and improve things further. Do you that is required to make this work? Honestly, I have no idea what to say to them to help and they don't seem to know either.

It's the blind leading the clueless, I'm afraid:) I'd really appreciate some idea on how to progress this. Thank you.

14 Sep 2015, 1:58 PM
#4
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: PayPal SHA-256 Security Update Sept 2015

CScotty:

Appending to this thread as it is relevant.

DrByte: the link at 2(a) for advice to your hosting company in the post you refer to above doesn't work. Seems it's some kind of privileged area.Evidently PayPal changed the URLs to their articles. I've updated the post with them:
https://www.paypal-knowledge.com/infocenter/index?page=content&id=FAQ1766
https://www.paypal-knowledge.com/resources/sites/PAYPAL/content/live/FAQ/1000/FAQ1766/en_US/2015%20Merchant%20Security%20System%20Upgrade%20Guide%20%28U.S.%20English%29.pdf

CScotty:

I am completly stuck on this security update. I switched to the sandbox and it fails with error:
10002
Security error
Security header is not validThat's a result of using "production" credentials on the sandbox, or vice versa. The sandbox requires a different set of User/Signature/Password credentials.

CScotty:

I have done as the post suggested i.e point out the issues to the hosting company. They have improved the grading up to "C" but no joy.That's a good start. Hopefully eventually they'll take the time to dig deep enough to fix the other reported issues, as that will benefit all their customers and improve them as a host.

In the meantime, I can't speak for anyone but I suspect this PayPal change won't adversely affect you.

One test that might help is to use the latest curltester.php and see what results it gives back for the sandbox. The tester doesn't actually use any credentials to login so it's not a complete test, but it does confirm that an initial "handshake" sort of connection can be made, and I believe the connection will fail if the SHA certs are wrong.
To use: Upload the curltester file to /extras/curltester.php on your own server, and then use your browser to visit that page, ie: http://your_site.com/extras/curltester.php
(To obtain the latest curltester.php file, simply right-click the link above and choose "save as" and store it on your PC. Then upload it to your server using FTP.)

14 Sep 2015, 2:59 PM
#5
cscotty avatar

cscotty

New Zenner

Join Date:
Nov 2014
Location:
United Kingdom
Posts:
38
Plugin Contributions:
0

Re: PayPal SHA-256 Security Update Sept 2015

Hi DrByte,

Thanks for updating the link and your input on the credentials. That was indeed the problem.

The sandbox credentials, so I thought, were incredibly hard to locate on the PayPal site so for the benefit of others here is how to do it as on 14th Sept 2015.

Log on at https://developer.paypal.com/
Click on Dashboard (along the top)
Click on "Account" under Sandbox on the left
Click the account name for which you wish to view the credentials
Click on "Profile". After a few secs a drop down box will appear. When it does select the "API Credentials" Tab.

18 Sep 2015, 11:24 PM
#6
honrheart avatar

honrheart

Zen Follower

Join Date:
Jul 2008
Posts:
139
Plugin Contributions:
0

Re: PayPal SHA-256 Security Update Sept 2015

DrByte:

PayPal first started talking about this back in March, and I posted the following in response to that: PayPal upgrading SSL Certificates in 2015

In short, Zen Cart itself is not affected at all by these changes.

Nevertheless you may want to take this opportunity to get your hosting company to ensure they've got their server up-to-date. I posted some guidance in the above article for you to reference.

I'm curious ... how will this affect stores that do not have SSL enabled and use paypal express (rather than the standard paypal). For example several stores use hostgator which uses a shared SSL certificate but when setting zen SSL is not enabled. When we contacted HostGator we were told shared SSL would not work and we needed to purchase a private SSL (or upgrade to business) but not sure that's true since we have SSL disabled on our stores. Just trying to be proactive and honestly I don't want to instruct people to purchase an SSL or upgrade if it is not needed.

19 Sep 2015, 7:34 PM
#7
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: PayPal SHA-256 Security Update Sept 2015

The server's ability to communicate securely to external services is not something "you" can fix. That's up to your hosting company. This is not handled by your domain's SSL certificate. It's handled by configuring the server to properly use OpenSSL (or equiv) to have the CURL services use secure TLS communication to talk to the likes of PayPal or other payment gateways securely. Again, it has nothing to do with whether your store is set up to use SSL when customers interact with it via their browser.

19 Sep 2015, 11:34 PM
#8
honrheart avatar

honrheart

Zen Follower

Join Date:
Jul 2008
Posts:
139
Plugin Contributions:
0

Re: PayPal SHA-256 Security Update Sept 2015

This is why I'm confused ... I initially received this reply from HostGator:

Hello, Thank you for contacting HostGator. We have been receiving a number of questions regarding this change by PayPal. The deprecation of SHA-1 has been occurring for some time and we have updated our servers accordingly. The most common issue we have encountered with this change is with customers that have older SSL certificates installed for their domains. In these cases, we are able to reissue these to the new SHA-256 algorithm. Our server's are updated properly for Apache and OpenSSL. You do not currently have a SSL certificate installed for your domain, so that aspect would not apply. If you do encounter any issues with interacting between your site and PayPal, please let us know and we would be more than happy to investigate further. Best Regards, Jordan B. Customer Service Manager

Then the following day I received an update to the ticket:

Unfortunately the Shared SSL does not supply the level of security that PayPal requires to support their new configuration. You will need to order a private SSL at https://hostgator.com/ssl and we will install it.

I'm just trying to find out how best to advise these store owners so they experience little or no downtime. How would YOU suggest to proceed Dr Byte? I take it to mean they DO need to either purchase the SSL or upgrade their acct to the business package which includes the private ssl & dedicated IP but I want to make sure I'm not just reading their responses wrong.

21 Sep 2015, 2:36 PM
#9
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: PayPal SHA-256 Security Update Sept 2015

Again, there are TWO aspects to SSL:

a) SSL certificates for the domain/URL, which is used by browsers. Those might need updating/re-issuing, if old-style certificates are currently in use.

b) SSL configuration in the back end for Apache/OpenSSL/CURL/PHP/etc.

The post you quoted above says that "A" will be needed for any sites that have old certificates, or for sites formerly using Shared certificates. It also says that they believe they've taken care of all the stuff needed for "B".

21 Sep 2015, 3:03 PM
#10
honrheart avatar

honrheart

Zen Follower

Join Date:
Jul 2008
Posts:
139
Plugin Contributions:
0

Re: PayPal SHA-256 Security Update Sept 2015

DrByte:

Again, there are TWO aspects to SSL:

a) SSL certificates for the domain/URL, which is used by browsers. Those might need updating/re-issuing, if old-style certificates are currently in use.

b) SSL configuration in the back end for Apache/OpenSSL/CURL/PHP/etc.

The post you quoted above says that "A" will be needed for any sites that have old certificates, or for sites formerly using Shared certificates. It also says that they believe they've taken care of all the stuff needed for "B".

So for those that do not have SSL enabled on there store there isn't anything they need to do? Is that correct? If they do they may need to have their certificates re-issued if it's an older one.

I just want to give everyone correct info which is why I'm trying to clarify it for them.

21 Sep 2015, 3:11 PM
#11
honrheart avatar

honrheart

Zen Follower

Join Date:
Jul 2008
Posts:
139
Plugin Contributions:
0

Re: PayPal SHA-256 Security Update Sept 2015

I just saw where you said if they used shared certificates so then are you saying they WILL need the private SSL as HostGator mentioned in their second response?

21 Sep 2015, 6:06 PM
#12
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: PayPal SHA-256 Security Update Sept 2015

honrheart:

I just saw where you said if they used shared certificates so then are you saying they WILL need the private SSL as HostGator mentioned in their second response?
That is how I read what hostgator is saying to you about hostgator accounts, yes.

22 Sep 2015, 4:50 PM
#13
honrheart avatar

honrheart

Zen Follower

Join Date:
Jul 2008
Posts:
139
Plugin Contributions:
0

Re: PayPal SHA-256 Security Update Sept 2015

DrByte:

That is how I read what hostgator is saying to you about hostgator accounts, yes.

Ok here's the latest and this makes it sound as if the SSL is more of a benefit than a requirement. Most of the store owners I know have SSL turned off:

My question to them:

One final question before I decide how to proceed. Does it matter either way if we do not have SSL enabled on our stores? We use Zen Cart and you are given the option to enable the SSL or not. Most of the stores in my industry have it set to false and I was wondering if that makes any difference whether or not we would need the private SSL or not. I don't want to tell people they MUST have it if it's not necessary. I know a previous update said you would be ready for the Apache/OpenSSL part of Paypal's new changes but if we have SSL turned off in our stores why do we need to purchase a PrivateSSL certificate?

Their Reply:

It is true that you do not need an SSL installed to run an online store. Not having one installed increases the risk of client personal information (account log in or credit card/PayPal account details) being stolen as there is no secure login or cart checkout without an SSL. So installing an SSL is a security service to protect client information as well as a safety perception for your clients (they see the https in the address or the SSL site seal and feel more secure in their transactions on your site - which is a reality and not just a perception) that will bring more sales over not having an SSL. So installing an SSL is more of a benefit in these regards. I hope this helps.


I know having a SSL is a great benefit but what these store owners want to know is if it's a requirement for their stores to run with paypal's new changes. HostGator is ready for the Apache/OpenSSL but it appears as if the privateSSL is only requirement if customers have SSL enabled, if not then it's just a suggestion but their stores will run fine without. Is that how you see it?

23 Sep 2015, 1:57 PM
#14
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: PayPal SHA-256 Security Update Sept 2015

honrheart:

I know having a SSL is a great benefit but what these store owners want to know is if it's a requirement for their stores to run with paypal's new changes.
Sigh.

No, having a private SSL certificate on your domain is NOT a requirement for a Zen Cart store to operate with PayPal Express Checkout, including the Summer/Fall 2015 SHA-256 changes PayPal is making.

But a storeowner who is serious about customer engagement and customers feeling comfortable shopping there and that the storeowner actually cares about their security will happily install a private dedicated SSL certificate to their store. The annual cost of a private SSL certificate is so low nowadays that there's very little justification to not do it.

18 Dec 2015, 8:13 PM
#15
amperial avatar

amperial

New Zenner

Join Date:
Dec 2013
Posts:
2
Plugin Contributions:
0

Re: PayPal SHA-256 Security Update Sept 2015

A new letter from PayPal today:

The following are technical changes that may require some upgrades to your system. Please share this information with your development team or hosting provider.

Now
Test Sandbox endpoints and tlstest.paypal.com are live.

New SFTP IP addresses are live.

Sandbox is issuing API Credential Certificates with new standard (2048-bit, SHA-256).

Jan 14, 2016
After this date, Sandbox API endpoints only support new standard (HTTP/1.1, TLS 1.2 and SHA-256 certificates).

This includes https://www.sandbox.paypal.com only accepting HTTPS for IPN Postbacks.

Jan 31, 2016
Production starts issuing API Credential Certificates with new standard (2048-bit, SHA-256).

Feb 29, 2016
Test Sandbox endpoints will be removed.

Mar 17, 2016
New SFTP IP addresses add to DNS for reports.paypal.com.

Apr 14, 2016
Old SFTP IP addresses removed from DNS for reports.paypal.com.

May 12, 2016
Old SFTP IP addresses stop working.

Jun 17, 2016
After this date, Production API endpoints will start moving to the new standard (HTTP/1.1, TLS 1.2 and SHA-256 certificates)

Sep 30, 2016
IPN postbacks to https://www.paypal.com only allow HTTPS

Jan 1, 2018
All Certificate API Credentials must have been upgraded to the new standard.

18 Dec 2015, 8:35 PM
#16
ajeh avatar

ajeh

Oba-san

Join Date:
Sep 2003
Location:
Ohio
Posts:
62,757
Plugin Contributions:
1

Re: PayPal SHA-256 Security Update Sept 2015

There will be only a couple VERY MINOR changes needed to Zen Cart (and will be included in v1.5.5) ... but you WILL need to work with your hosting company to ensure your server is capable of the modern TLS 1.2 security communications requirements.

21 Dec 2015, 11:38 PM
#17
buildingblocks avatar

buildingblocks

Totally Zenned

Join Date:
Jun 2008
Posts:
629
Plugin Contributions:
0

Re: PayPal SHA-256 Security Update Sept 2015

Ajeh:

There will be only a couple VERY MINOR changes needed to Zen Cart (and will be included in v1.5.5) ... but you WILL need to work with your hosting company to ensure your server is capable of the modern TLS 1.2 security communications requirements.

will these changes be available as patches for existing carts?

23 Dec 2015, 4:07 PM
#18
wilt avatar

wilt

Oji-san

Join Date:
Jun 2003
Location:
Newcastle UK
Posts:
1,883
Plugin Contributions:
3

Re: PayPal SHA-256 Security Update Sept 2015

Hi,

That is the intention. :)

buildingblocks:

will these changes be available as patches for existing carts?

24 Dec 2015, 1:47 AM
#19
buildingblocks avatar

buildingblocks

Totally Zenned

Join Date:
Jun 2008
Posts:
629
Plugin Contributions:
0

Re: PayPal SHA-256 Security Update Sept 2015

:) Thanks

wilt:

Hi,

That is the intention. :)

24 Dec 2015, 3:06 AM
#20
kobra avatar

kobra

Black Belt

Join Date:
Aug 2005
Location:
Arizona
Posts:
31,500
Plugin Contributions:
4

Re: PayPal SHA-256 Security Update Sept 2015

will these changes be available as patches for existing carts?
I am pretty certain that this depends upon what version of ZenCart you are using
Refer to the support doc here
https://www.zen-cart.com/showthread.php?72868-Zen-Cart-Software-Support-Life-Cycle