X-Cart: shopping cart software

X-Cart forums (https://forum.x-cart.com/index.php)
-   News and Announcements (https://forum.x-cart.com/forumdisplay.php?f=28)
-   -   X-Payments 1.0 beta testing (https://forum.x-cart.com/showthread.php?t=52833)

geckoday 03-31-2010 06:02 PM

Re: X-Payments 1.0 beta testing
 
Quote:

Originally Posted by Steel
Hello Ralph,

I have a couple questions for you. Do you know if the following 4.3 (and 4.2?) features are required to be compliant, and if so, will these requirements still be necessary with off-site processing? If so, and Qualiteam (or a 3rd party) does not plan on developing these features for prior versions, then we need to get on with 4.3 and/or other options.

PCI DSS compliance options
  • Number of failed login attempts after which a user account must be suspended: The number of login attempts that a user is allowed to make using an incorrect password before X-Cart automatically suspends their account. For compliance with PCI Data Security Standard, set this value to 6.
  • Lockout duration in minutes (Leave empty if you do not want to automatically re-enable automatically suspended users): The time period for which a user must remain suspended after having been automatically suspended by the system after a number of failed login attempts. For compliance with PCI Data Security Standard, set this value to 30 minutes or leave the field empty.
  • Number of days of inactivity after which an administrator account must be suspended (Set to 0 or leave empty if you do not wish to suspend unused administrator accounts): The number of days that an administrator account may remain inactive before getting automatically suspended by X-Cart. For compliance with PCI Data Security Standard, set this value to 90 days.
  • Use password strength check: This option allows you to enable password strength check for passwords created by the users of your store. If this option is enabled, every time a user creates a new password for their account, X-Cart will perform a check to ensure that this password contains both numeric and alphabetic symbols and is no less than 7 symbols in length. If this option is disabled, no such check will be performed. For compliance with PCI Data Security Standard, enable this option.
  • Number of days after which non-customer users must be requested to change their password: The number of days since the user's most recent login after which X-Cart must request the user to change their password. This setting is relevant only for non-customer users (administrators, providers). For compliance with PCI Data Security Standard, set this value to 90 days.
  • Do not allow a user to submit a new password that is the same as any of the last four passwords they have used: This option helps you ensure that users who are requested to change their password will change their password to something new (not a password they have already used). For compliance with PCI Data Security Standard, enable this option.
http://help.qtmsoft.com/index.php?title=X-Cart:Security_Options

Thanks


None of the above is required if you are using a gateway hosted payment page. In fact, nothing in X-Cart makes any difference if you are using a hosted payment page because X-Cart will not store, process or transmit card numbers. In this case you really don't care about X-Payments either.

None of the above is needed for PCI-DSS compliance if you are using a background payment method, are not storing credit card numbers and are eligible for SAQ C (most likely of the first two are true but read the SAQ). You will need X-Payments though to comply with the VISA PA-DSS mandate.

If you store card numbers the above is a requirement for PCI-DSS compliance. But with the PA-DSS mandate coming you'll have to switch to X-Payments anyway and X-Payments includes the above separately from X-Cart. So if you integrate X-Payments with a pre-4.3 version of X-Cart (or Carrie supplies a retrofit) you don't need the above in X-Cart since X-Payments is the payment application and it includes that stuff.

jillsybte 03-31-2010 06:48 PM

Re: X-Payments 1.0 beta testing
 
What is the status of the 4.3 branch regarding the Visa mandate coming in July?
I'm under the impression that no 4.x versions currently comply with the mandate and won't without the successful creation and inclusion of X-Payments. Am I misunderstanding this? It's possible I could upgrade my store to 4.3.x by July. Will that help me at all in regard to this issue?

Jayk 03-31-2010 07:09 PM

Re: X-Payments 1.0 beta testing
 
Quote:

Originally Posted by jillsybte
What is the status of the 4.3 branch regarding the Visa mandate coming in July?
I'm under the impression that no 4.x versions currently comply with the mandate and won't without the successful creation and inclusion of X-Payments. Am I misunderstanding this? It's possible I could upgrade my store to 4.3.x by July. Will that help me at all in regard to this issue?


4.3 will need X-Payments to be compliant if transmitting or storing CC data, but at least QT is making X-Payments for 4.3. Anyone using a prior version to 4.3 is apparently out of luck at this point.

Jason

BCSE 03-31-2010 07:18 PM

Re: X-Payments 1.0 beta testing
 
Quote:

Originally Posted by Jayk
4.3 will need X-Payments to be compliant if transmitting or storing CC data, but at least QT is making X-Payments for 4.3. Anyone using a prior version to 4.3 is apparently out of luck at this point.

Jason


We plan to make the connector compatible with 4.1.x and 4.2.x as we do not plan to upgrade to 4.3.x yet and we have many customized clients that just can't upgrade at this point in time. Especially with the economy.

We're currently testing things now to make a full assessment, but we plan to make it easy for all our clients to come up to the standard in July if they want to continue to use background payment methods.

Carrie

Jayk 03-31-2010 07:26 PM

Re: X-Payments 1.0 beta testing
 
Quote:

Originally Posted by BCSE
We plan to make the connector compatible with 4.1.x and 4.2.x as we do not plan to upgrade to 4.3.x yet and we have many customized clients that just can't upgrade at this point in time. Especially with the economy.

We're currently testing things now to make a full assessment, but we plan to make it easy for all our clients to come up to the standard in July if they want to continue to use background payment methods.

Carrie


That's good to hear. We've been torn on whether to upgrade to 4.3 from 4.1.12 and there's at least one mod we need that's not ported past 4.2.x yet.

Thanks Carrie.

Jason

MercuryMindsSupport 04-01-2010 01:14 AM

Re: X-Payments 1.0 beta testing
 
Please add us to the list.

rrf 04-01-2010 08:25 AM

Re: X-Payments 1.0 beta testing
 
To all beta testers of X-Payments: thank you for your feedback!

I just want to sum up the most important issues raised by now.
The top 3 obstacles that limit the number of customers that can benefit for X-Payments are:


1. There is no official planned version of X-Payments for X-Cart versions earlier than 4.3
2. X-Cart store owners would love the border between X-Cart and X-Payments to be as seamless for end user as possible. Buyers should not feel that they are leaving the web site.
3. X-Payments requires PHP version 5.3.0 and above. Some of the web hosting service providers still have older versions of PHP, which are not supported by X-Payments.


Another concern is not about X-Payments itself but rather about Qualiteam's ability to deliver this solution in a timely manner.


I will address all of these problems / concerns one by one, to make sure that we are on a way to actually solve them, instead of grouping them into shapeless blob. My answers will appear in this thread.

If there are any issues that are not on my list, please start a separate thread on each issue, in "Payment Issues" forum (
http://forum.x-cart.com/forumdisplay.php?f=25 )

rrf 04-01-2010 08:52 AM

Re: X-Payments 1.0 beta testing
 
Addressing these concerns requires involvement from the software engineers behind X-Payments. It's well past the office hours here now, so I'll get back to you in 24 hours.

hyper1 04-01-2010 10:16 AM

Re: X-Payments 1.0 beta testing
 
To clarify, it is not that we would love for our customers to not feel they left our site (I will leave x-cart in a second when my customers feel they left my site), it is that we cannot afford to have our customers leave our site. We use the checkout and invoice page for several elements of our analytics and marketing reports. I just want to make sure you do not misunderstand my requirements for my passions.

Also, statements like "official planned version" are part of the challenge we face with the X-cart team's communication style. Forget whether it is official or not. The question is

Will you release a version of x-payment for carts prior to 4.3, and if so, what versions will be supported?

Finally, I would prefer my software provider not get confused with the important role they play in my store. It is to design and upgrade software to the latest industry standards and the level of innovation that allows me to achieve a level of success that I deem appropriate. I am with the host I have today because previous hosts were unable to meet our expectations. I should also state I am with X-Cart for the same reason, please do not let me down.

jillsybte 04-01-2010 04:25 PM

Re: X-Payments 1.0 beta testing
 
1 Attachment(s)
Has anyone heard of CRE Secure? I found it while I was looking around for possible solutions to our upcoming PCI/PA-DSS problems: http://www.cresecure.com/pages.php?CDpath=6_28.

They make a module for X-Cart (http://www.cresecure.com/pages.php?CDpath=5_8) 4.0 to 4.3 and it looks like its fairly simple to install (I attached the manual).

They actually host the CC transaction process, but through their "HTML Cloning" technology the customers don't know they're leaving your site. The main drawback appears to be an extra fee involved: up to $20/month plus a little more if you have over 250 transactions. You keep your current merchant account and link it to CRE Secure.

Anyway, I haven't had a chance to look through the info thoroughly yet. I just wanted to see if anyone has heard of it and/or offer it as a possible solution to those in the same boat as I am.


All times are GMT -8. The time now is 03:08 PM.

Powered by vBulletin Version 3.5.4
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.