Vince
Administrator
Spain
42766 Posts |
Posted - 05/13/2017 : 02:41:49
quote: Effective 12/31/2017, UPS will only accept TLS 1.1 and 1.2 security protocols. It is highly recommended that the most current version, TLS1.2, be implemented. After that date, any communication requests submitted to UPS using older protocols (TLS 1.0 or earlier) will fail.
UPS will only be accepting TLS 1.2 connections as from the end of this year. You can check your site to see if your server is TLS 1.2 compatible by entering the URL... yourstoreurl.com/vsadmin/ppconfirm.asp?ppdebug=tls yourstoreurl.com/vsadmin/ppconfirm.php?ppdebug=tls You should get a response that says "INVALID", (as that shows you connected ok, but the query was rejected.) If you get any kind of error, you may need to talk to your host about updating the server. Vince Click Here for Shopping Cart SoftwareClick Here to sign up for our newsletterClick Here for the latest updater
|
Mikelli
Ecommerce Template Guru
USA
1613 Posts Pre-sales questions only (More Details...)
|
Posted - 05/19/2017 : 20:00:59
Hi Vince, I just get a blank page. How should I interpret that?
Michael
|
Vince
Administrator
42766 Posts |
Posted - 05/20/2017 : 00:19:19
|
Mikelli
Ecommerce Template Guru
USA
1613 Posts Pre-sales questions only (More Details...)
|
Posted - 05/22/2017 : 21:32:09
No, we don't use PayPal, we have a capture card mod. We sell on line and have trucks that deliver on-site, so inventory is in many places. So we use our accounting software to process C Cards. So, what would you suggest to determine TLS 1.2 connections?
Just to add: both of those links when clicked on will time out
Michael
Edited by - Mikelli on 05/22/2017 21:34:39
|
Vince
Administrator
42766 Posts |
Posted - 05/23/2017 : 00:27:44
|
ITZAP
Ecommerce Template Guru
Australia
1018 Posts |
Posted - 05/23/2017 : 06:32:43
You can test your Server SSL Certificate for TLS 1.2 compliance, and much more, here ... Qualys SSL Labs =>>Gary
|
Mikelli
Ecommerce Template Guru
USA
1613 Posts Pre-sales questions only (More Details...)
|
Posted - 05/23/2017 : 20:30:23
Thanks Gary for the link! I get TLS 1.2 "YES" under the configuration tab !! Woo Hoo! So, we will see what unfolds next Michael
|
pschneider
Advanced Member
USA
218 Posts |
Posted - 09/22/2017 : 20:49:46
I tried the first 2 links and got a blank page on both my websites. Then I tried Gary's link and both my servers/websites passed with flying colors, and use the TLS 1.2. Thanks, Gary. I appreciate it. Paul
Paul Schneider Jr
|
xxcfdrr
Advanced Member
USA
231 Posts |
Posted - 01/05/2018 : 05:29:43
Hi guys, thanks for the help.
As I stated in another thread we are getting an error connected to the UPS shipping rates server and it seems intermittent.
We do our own hosting. I was actually in this thread months ago using the links test our server and the Qualsys Lab links reports we do support TLS 1.2. Here is the Protocols results of that test: TLS 1.3 No TLS 1.2 Yes TLS 1.1 No TLS 1.0 Yes SSL 3 No SSL 2 No
When I run the test script (yourstoreurl.com/vsadmin/ppconfirm.asp?ppdebug=tls) I get this message:
Testing URL: https://ipnpb.sandbox.paypal.com/cgi-bin/webscr Error : Error, couldn't connect to https://ipnpb.sandbox.paypal.com/cgi-bin/webscr (-2147012739). An error occurred in the secure channel support
Is the UPS error a for sure TLS problem or can it be something else as I am under the impression we are TLS 1.2 compatible.
Thanks again!
|
xxcfdrr
Advanced Member
USA
231 Posts |
Posted - 01/05/2018 : 09:02:58
So I disabled the TLS 1.0 via registry and rebooted. Then the MSSQL (2005) service would not start. I've put it back for now but need to figure out what the deal is.
|
Vince
Administrator
42766 Posts |
Posted - 01/05/2018 : 09:59:34
|
xxcfdrr
Advanced Member
USA
231 Posts |
Posted - 01/07/2018 : 19:35:41
Hi Vince. I've upgraded our MS SQL to 2008 r2 with all patches and support for TLS 1.2. Running the scan at ssllabs I get:
TLS 1.3 No TLS 1.2 Yes TLS 1.1 No TLS 1.0 No SSL 3 No SSL 2 No
When I run the test script (yourstoreurl.com/vsadmin/ppconfirm.asp?ppdebug=tls) I get this message:
Testing URL: https://ipnpb.sandbox.paypal.com/cgi-bin/webscr Error : Error, couldn't connect to https://ipnpb.sandbox.paypal.com/cgi-bin/webscr (-2147012739). An error occurred in the secure channel support
My checkout has been broken for me for a couple of days, yet I have received a few sporadic orders which is puzzling.
Any more ideas what can cause the shipping rate errors?
Thank you.
|
Vince
Administrator
42766 Posts |
Posted - 01/08/2018 : 04:29:44
|
xxcfdrr
Advanced Member
USA
231 Posts |
Posted - 01/08/2018 : 05:20:19
Using Win2008 Server r2 sp1. Upgraded to SQL 2008 r2 because we already own it. Did some more digging last night. Our UPS account works, has autopay so no problems there. Also, I'm getting this error during checkout on the actual web server and all other computers/browsers. Right now our checkout is broken and no orders are able to complete. Here is another screen shot of what is happening: Thank you.
|
xxcfdrr
Advanced Member
USA
231 Posts |
Posted - 01/08/2018 : 07:02:52
I think it's fixed now. I found some errors in the event log in system section each time I tried the checkout and received the UPS error.
A fatal error occurred while creating an SSL client credential. The internal error state is 10013.
Did a search and followed the steps here:
https://social.technet.microsoft.com/Forums/ie/en-US/aaced205-b0ec-4874-b440-8075dd74d8df/a-fatal-error-occurred-while-creating-an-ssl-client-credential-the-internal-error-state-is-10013?forum=exchangesvradmin
Seems fixed! Hope this helps someone else, permissions problems are not fun.
|
Vince
Administrator
42766 Posts |
Posted - 01/08/2018 : 10:41:21
|
Andy
ECT Moderator
95440 Posts |
Posted - 01/23/2018 : 07:33:05
A note from authorize.net As you may be aware, new PCI DSS requirements state that all payment systems must disable earlier versions of Transport Layer Security (TLS) protocols, TLS 1.0 and TLS 1.1. Authorize.Net is set to disable those protocols on February 28, 2018. To help the merchants identify if they’re using one of the older TLS protocols, Authorize.Net will temporarily disable those connections for a few hours on January 30, 2018 and then again on February 8, 2018. Andy Please feel free to review / rate our software
|
Tinsle
Advanced Member
United Kingdom
342 Posts |
Posted - 04/10/2018 : 01:46:05
Hi all,
Following up on this topic we notice there are important updates that need to be made by June 2018.
We are already setup on TLS 1.2 and we are currently looking into upgrading our HTTP protocol.
With regards to the below PayPal will "Discontinue Use of GET Method". POST HTTP is replacing the GET HTTP. Just checking that the template is currently setup for this?
https://www.paypal.com/au/webapps/mpp/merchant-security-roadmap
TLS 1.2 and HTTP/1.1 Upgrade
PayPal is upgrading the protocols used to secure all external connections made to our systems. Transport Layer Security version 1.2 (TLS 1.2) and Hypertext Transfer Protocol version 1.1 (HTTP/1.1) will become mandatory for communication with PayPal in 2017. You will need to verify that your environment supports TLS 1.2 and HTTP/1.1, and if necessary make appropriate updates. For information, click here.
Act by June, 2018* 4 IPN Verification Postback to HTTPS
If you are using PayPal’s Instant Payment Notification (IPN) service, you will need to ensure that HTTPS is used when posting the message back to PayPal for verification. HTTP postbacks will no longer be supported. For information, click here.
Act by June, 2018*
Discontinue Use of GET Method for Classic NVP/SOAP APIs
PayPal will no longer support the use of the GET HTTP request method for our classic NVP/SOAP APIs. If you currently use any of these APIs, you will need to ensure that your API requests only use the POST HTTP request method. For information, click here.
Act by June, 2018*
Regards
Kev
|
Vince
Administrator
42766 Posts |
Posted - 04/10/2018 : 01:56:22
|
Tinsle
Advanced Member
United Kingdom
342 Posts |
Posted - 04/10/2018 : 01:58:54
Thanks Vince,
Regards
Kev
|
oneeyedesigns
Starting Member
23 Posts Pre-sales questions only (More Details...)
|
Posted - 04/26/2018 : 15:40:34
Hi - I am trying to get PayPal to work on a few client sites that I have setup with the ecommerce templates software. I get a blank page testing vsadmin/ppconfirm.asp?ppdebug=tls. The host uses TLS 1.2 but I'm thinking the software is defaulting to 1.0 or 1.1. Is it possible (the host is asking this) to specify TLS 1.2 and not the others in the code?
|
|