asanborn
Ecommerce Template Guru
USA
1404 Posts Pre-sales questions only (More Details...)
|
Posted - 06/26/2018 : 08:31:19
We need a link or script to test all of our E-commerce carts versions All of our PayPal Customers are receiving this letter which is causing Panic communications to us:
We’ve tried contacting you to inform you of an urgent security requirement that now needs your immediate attention. Starting on June 26, 2018, PayPal will be making changes that may impact your ability to accept any PayPal transactions, process credit card payments with PayPal, or access the funds in your PayPal Business account.
Action required by June 26, 2018.
Our records show that your PayPal integration uses an older encryption protocol. You must take the following actions immediately to upgrade your PayPal integration(s) to the TLS 1.2 cryptographic protocol by June 26, 2018.
1. Visit our security website to view the requirements: www.paypal.com/tls 2. If your website is hosted by a third-party, work with your web hosting company or e-commerce software provider. Otherwise, please contact your in-house web programmer or system administrator to make these updates. 3. Use our testing environment to verify that your servers support the latest security standards: https://tlstest.paypal.com. The testing environment will present a PayPal_Connection_OK message if you’ve completed the server update correctly. Note that you must test your API using your server, not your web browser.
If you fail to upgrade your integration by June 26, 2018, you may not be able to accept any PayPal transactions, process credit card payments with PayPal, or access the funds in your PayPal Business account.
If you need additional support, please contact your web hosting company, e-commerce software provider, in-house web programmer, or system administrator. You can also visit our Help Center for more detail.
PayPal Merchant Services
|
Andy
ECT Moderator
95440 Posts |
Posted - 06/26/2018 : 08:34:45
Hi We have links and suggestions available here https://www.ecommercetemplates.com/support/topic.asp?TOPIC_ID=107642 You need to check with your host that TLS1.2 is supported and you'll see we have a simple test using the ppconfirm.php in that thread as well as a link to a testing site https://www.ssllabs.com/ssltest/ Andy Please feel free to review / rate our software
|
asanborn
Ecommerce Template Guru
USA
1404 Posts Pre-sales questions only (More Details...)
|
Posted - 06/26/2018 : 09:07:31
HI Andy, I have read that thread. Two issues: 1. there are a lot of links on this page, which ones do I use for our websites. 2. I have click a lot of them and the pages in the URL just say "Loading" and nothing displays.
We do have some older versions of ECT running. What link can I use from the urlname.com/..... to test their stores?
PS: We have run ssslabs and all of our sites come back with a B rating.
|
Andy
ECT Moderator
95440 Posts |
Posted - 06/26/2018 : 09:10:57
Have you tried the entering the URL yoursite.com/vsadmin/ppconfirm.asp?ppdebug=tls In the report from ssllabs check which TLS protocols are supported, the overall rating here is less important. Andy Please feel free to review / rate our software
|
asanborn
Ecommerce Template Guru
USA
1404 Posts Pre-sales questions only (More Details...)
|
Posted - 06/26/2018 : 12:06:01
1. We have tried to run the links and they just sit there as "loading" and never get any page or content. Ran on the server: https://ipnpb.sandbox.paypal.com/cgi-bin/webscr https://ipnpb.paypal.com/cgi-bin/webscr
Only get loading, no response or error.
2. Yes, we have used sslabs and test passes for TLS1.1 and TLS 1.2
3. we also checked our firewall and nothing is block.
So because #1 above does not complete...
What are the exact links to test our sites?
|
Andy
ECT Moderator
95440 Posts |
Posted - 06/26/2018 : 12:27:05
|
asanborn
Ecommerce Template Guru
USA
1404 Posts Pre-sales questions only (More Details...)
|
Posted - 06/26/2018 : 14:44:38
Can you send me an email direct to reply to please? Thanks
|
Andy
ECT Moderator
95440 Posts |
Posted - 06/27/2018 : 00:06:05
|
Andy
ECT Moderator
95440 Posts |
Posted - 06/27/2018 : 07:45:26
I had a look at the sites you sent on and they are very old versions, between 4 and 9 years without updating so that's why our test wouldn't work. I would very strongly urge you to update those sites. There will have been security fixes and quite probably PayPal related changes too. On ssllabs all sites show support for TLS 1.1 and TLS1.2 so it may be they are connecting using the TLS1.1 protocol but that would be something your host could advise on. Andy Please feel free to review / rate our software
|
asanborn
Ecommerce Template Guru
USA
1404 Posts Pre-sales questions only (More Details...)
|
Posted - 06/27/2018 : 08:28:33
This is why I have other post asking what was the last version before ECT cut over to the CSS style sites.
What was that version number?
|
Andy
ECT Moderator
95440 Posts |
Posted - 06/27/2018 : 08:35:57
The first version to use the ectcart.css file for the cart and search pages was 6.5 but table based product / detail and category pages are all still supported (although not really recommended) - that shouldn't cause any problems though, should it? Andy Please feel free to review / rate our software
|
Tinsle
Advanced Member
United Kingdom
342 Posts |
Posted - 06/28/2018 : 05:34:00
Hi Andy,
All transactions for us are failing from today. customers have contacted us stating an error message after payment stage "SSL connection error".
We upgraded our server to TLS 1.2 and HTTP 1.1 over a year ago now with a fallback in place to TLS 1.1.
I have tried URL yoursite.com/vsadmin/ppconfirm.php?ppdebug=tls
This is showing an error message.
Please can you advise what the problem might be from the error message?
Regards
Kev
|
Andy
ECT Moderator
95440 Posts |
Posted - 06/28/2018 : 05:44:55
|
Tinsle
Advanced Member
United Kingdom
342 Posts |
Posted - 06/28/2018 : 05:47:10
Hi Andy,
The fallback is TLS 1.1 however the default is setup at the highest level as TLS 1.2?
Regards
Kev
|
Andy
ECT Moderator
95440 Posts |
Posted - 06/28/2018 : 06:14:49
|
Tinsle
Advanced Member
United Kingdom
342 Posts |
Posted - 06/28/2018 : 06:18:18
Ok thanks Andy,
We will disable both 1.0 and 1.1 and will let you know the outcome
Regards
Kev
|
Andy
ECT Moderator
95440 Posts |
Posted - 06/28/2018 : 06:25:59
|
Tinsle
Advanced Member
United Kingdom
342 Posts |
Posted - 06/28/2018 : 07:44:35
Hi Andy has there been any update to the ppconfirm.php page in the last few days?
The below email error message we are receiving seems to show a handshake cURL error between our website and PayPal?
SANDBOX: sandbox. Ecommerce Plus PayPal IPN Error: Error with cURL installation: SSL connect error
Regards
Kev
|
Andy
ECT Moderator
95440 Posts |
Posted - 06/28/2018 : 07:54:51
No, there haven't been any changes to that file for a while. The error may suggest the cURL installation on your server isn't configured to use TLS1.2. It could also be a temporary PayPal glitch which has come up a couple of times on the forum. Andy Please feel free to review / rate our software
|
Tinsle
Advanced Member
United Kingdom
342 Posts |
Posted - 06/28/2018 : 08:05:38
Hi Andy thanks for this
When you say possible paypal glitch, have others experienced a problem with paypal today also as i cannot seem to find any mention of this in the forum in the past few days?
|
Andy
ECT Moderator
95440 Posts |
Posted - 06/28/2018 : 08:24:21
No, nobody has reported any issues today and we haven't received any status alerts from PayPal. I only mentioned it because it has happened in the past when all settings appeared to be correct and the problem resolved itself. In your case my first point is more likely considering you have just made server changes. Andy Please feel free to review / rate our software
|
|