X-Cart: shopping cart software

X-Cart forums (https://forum.x-cart.com/index.php)
-   News and Announcements (https://forum.x-cart.com/forumdisplay.php?f=28)
-   -   X-Cart and PCI DSS / PA-DSS compliance (https://forum.x-cart.com/showthread.php?t=46073)

bigredseo 03-09-2009 01:11 PM

Re: X-Cart and PCI-DSS / PA-DSS compliance
 
Thanks for the clear up on that Ralph. It'll be interesting to see how things turn out over the next few months. Any of the PCI Compliant software that we are running currently is all encoded once the merchant stuff takes over, which is why I assumed that things would need to be encoded also.

We'll wait and see what transpires here with X-Cart.

ozchris 03-19-2009 06:31 PM

Re: X-Cart and PCI-DSS / PA-DSS compliance
 
sooo, how does this match up to the thread on 4.3 http://forum.x-cart.com/showthread.php?t=45398 where it lists the payment processors that will not be supported by 4.3?

is that approach now obsolete? replaced by the new payment module?

we were using vaultx - aka globalpoint aka paycorp, in Australia, for all our xcarts and credit card processing.

does that mean we can grab the existing code from 4.1.8 for vaultx and somehow link it to the new payment module?

or is it something that xcart can be asked to do?

exsecror 03-20-2009 03:05 AM

Re: X-Cart and PCI-DSS / PA-DSS compliance
 
Quote:

Originally Posted by ozchris
sooo, how does this match up to the thread on 4.3 http://forum.x-cart.com/showthread.php?t=45398 where it lists the payment processors that will not be supported by 4.3?

is that approach now obsolete? replaced by the new payment module?

we were using vaultx - aka globalpoint aka paycorp, in Australia, for all our xcarts and credit card processing.

does that mean we can grab the existing code from 4.1.8 for vaultx and somehow link it to the new payment module?

or is it something that xcart can be asked to do?


This doesn't affect payment gateways per-se, just x-cart's core cc processing logic.

JWait 03-20-2009 07:56 AM

Re: X-Cart and PCI-DSS / PA-DSS compliance
 
Is there a list of payment gateways that will be supported by v5.0 anywhere? I've looked but can't find any.

JazzyJeff 03-20-2009 06:02 PM

Re: X-Cart and PCI-DSS / PA-DSS compliance
 
Quote:

Originally Posted by JWait
Is there a list of payment gateways that will be supported by v5.0 anywhere? I've looked but can't find any.


I think Qualiteam is still making that decision.

JWait 03-21-2009 04:44 AM

Re: X-Cart and PCI-DSS / PA-DSS compliance
 
I realize they can't have a "final" list of what payment processors will be supported, but as it stands right now, there are none. I would just like to know if there are any that will definitely be supported so I can make a decision as to what processor to go with now and not have to change later.

cotc2001 04-01-2009 03:40 AM

Re: X-Cart and PCI-DSS / PA-DSS compliance
 
Just out of interest what is going to happen with older versions of x-cart i.e 4.0.x branch? is it going to be a case of if we want to be complaint then we will have no option but to upgrade (at a huge cost in the thousands because of all modifications) or is there going to be some way to have x-cart do customisations to make older branches compliant??

balinor 04-01-2009 04:26 AM

Re: X-Cart and PCI-DSS / PA-DSS compliance
 
No, the message at the top of the thread says it will be a payment module compatible with 4.0.x. This is what we were pushing for, and it seems they will be accommodating us instead of making everyone upgrade to v5.

cotc2001 04-01-2009 06:16 AM

Re: X-Cart and PCI-DSS / PA-DSS compliance
 
Quote:

1. We release X-Cart 4.3
2. We develop a payment module for X-Cart 4.3 and X-Cart 5.0 and verify it by a PA-QSA; probably, the source code of the module will be encrypted with Zend/ionCube
3. X-Cart users disable its credit card processing functions (so, X-Cart becomes not a subject for PCI-DSS) and install the PA-DSS verified payment module that handles all the credit card stuff; we will distribute the module among existing X-Cart users for free
4. The payment module will be implemented in such a way that allows its use with X-Cart 4.1.x and 4.2.x (with moderate customization of X-Cart source code).
5. Third-parties developing integration modules for payment gateways, not supported by the verified payment module out of the box, will have to complete a PA-DSS audit themselves (that costs dozens of thousands USD annually) if the chosen gateway integration method is a subject for PCI-DSS rules.
I couldn't see a mention of 4.0.x , only 4.1 onwards

balinor 04-01-2009 06:24 AM

Re: X-Cart and PCI-DSS / PA-DSS compliance
 
Perhaps they could clarify, I was under the impression it would be for 4.0 as well.


All times are GMT -8. The time now is 09:23 PM.

Powered by vBulletin Version 3.5.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.