X-Cart: shopping cart software

X-Cart forums (https://forum.x-cart.com/index.php)
-   News and Announcements (https://forum.x-cart.com/forumdisplay.php?f=28)
-   -   X-Payments 1.0 beta5 announcement (https://forum.x-cart.com/showthread.php?t=53981)

Emerson 07-01-2010 05:28 PM

Re: X-Payments 1.0 beta5 announcement
 
It does not "have" to be on it's own server.
It would be best practice but I don't see why it would be required.

Duramax 6.6L 07-01-2010 05:39 PM

Re: X-Payments 1.0 beta5 announcement
 
This is a paragraph from the pdf that BSCE has in their email this month.

""PCI compliance requires that certified and non‐certified processes be run on different servers
(see SAQ‐D section 2.2.1). As a result, certified code (X‐Payments) cannot run on a machine that is also
running uncertified code (X‐Cart). X‐Payments must run on a separate server to be fully compliant.
Many companies cannot afford to have a second server that is dedicated to running software such as XPayments.
As a solution, BCS Engineering is providing X‐Payments software as a service on a PCIcompliant
system for a much lower cost than a second dedicated host. BCS Engineering’s Hosted XPayments
solution is also cheaper than a virtual host. Not all virtual hosts can be considered PCICompliant
and are not all equal. Very cheap virtual hosts can be considered, from a security standpoint,
to be equivalent to a shared hosting solution.""

I can attach the pdf if you need it.

Emerson 07-01-2010 05:53 PM

Re: X-Payments 1.0 beta5 announcement
 
conflicting info all over the place.
Please see this:
http://forum.x-cart.com/showpost.php?p=273343&postcount=62

Duramax 6.6L 07-01-2010 05:59 PM

Re: X-Payments 1.0 beta5 announcement
 
I remember reading that post before, I am just trying to sort this all out like every one else is.

balinor 07-01-2010 06:10 PM

Re: X-Payments 1.0 beta5 announcement
 
Ralph knows his stuff - if he says something is true, you are probably pretty safe to assume it is.

ambal 07-01-2010 09:53 PM

Re: X-Payments 1.0 beta5 announcement
 
Quote:

Originally Posted by balinor
Ralph knows his stuff - if he says something is true, you are probably pretty safe to assume it is.


+1 Ralph does have the knowledge!

ambal 07-01-2010 09:57 PM

Re: X-Payments 1.0 beta5 announcement
 
Quote:

Originally Posted by kulture
So basically the UK (and europe and the rest of the world) have 2 more years to play. Unless their merchant provider decides (as they are entitled to) to advance that deadline.


Some payment gateways require compliance at different deadlines. I am collecting this information for payment gateways supported by X-Payments and will have it published at http://forum.x-cart.com/showthread.php?t=54408

If you know something about deadlines set by various payment gateways don't hesitate to post that information and proof links here or PM me.

finestshops 07-01-2010 10:06 PM

Re: X-Payments 1.0 beta5 announcement
 
one client told me authorize.net customers may be getting 1 year extension. Many clients did not get anything from their payment gateways or merchant account providers about PCI.

By the way, SAQ‐D section 2.2.1 is probably applied to merchants who has to store credit card information, not just pass it for processing without saving to the database.

cflsystems 07-02-2010 03:03 AM

Re: X-Payments 1.0 beta5 announcement
 
So are we allowed to continue to use CC payments on site like nothing happened or we will get fined if not compliant? I for one never received any notice or request from the gateway or the merchant account about compliance. Tried to submit to them once and they told me "ok but we don;t need it. if we need it we'll ask you to provide it". So I guess my question is:
1. Can I still collect CC payments on site like before without being compliant until X-Payments officially is released? Or another solution is found.
2. What happens if I turn on payment gateway hosted payment page? Do I still have to file any compliance report?
3. Am I required to send any of the SAQ's even though noone asked for it?

balinor 07-02-2010 04:40 AM

Re: X-Payments 1.0 beta5 announcement
 
1. Keep going as you have - they aren't going to shut you down immediately - they have no way to prove that you aren't using a compliant cart
2. If you go to their hosted page, you can avoid the whole mess - this only applies to carts that handle CC data on site
3. I wouldn't give them anything until they ask for it


All times are GMT -8. The time now is 12:05 PM.

Powered by vBulletin Version 3.5.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.