| ||||||||||
Shopping cart software Solutions for online shops and malls | ||||||||||
|
X-Cart Home | FAQ | Forum rules | Calendar | User manuals | Login |
Upcoming X-Cart v 4.4.6 (now renamed to 4.5.0) & PCI-DSS requirements | ||||
|
|
Thread Tools |
#101
|
|||||||
|
|||||||
Which Integration Method To Choose?
Hi all. I'm somewhat confused, then, as to which integration method to use between XC 4.4.6 and eProcessing Network, who processes our payments. Here is a list of their 5 available integration methods. Can anyone tell me please? http://www.eprocessingnetwork.com/Utilities.html
D
__________________
X-Cart v4.7.5 reBOOT |
|||||||
#102
|
|||||||
|
|||||||
Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements
You would have to use the Database Engine method.
__________________
Padraic Ryan Ryan Design Studio Professional E-Commerce Development |
|||||||
#103
|
|||||||
|
|||||||
Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements
I don't know where you are getting your info from, but Authorize.net Aim is still PCI excepted. This is on the SAQ. and requires a different level of scanning when using it. ( Which I just passed )
__________________
x-cart 4.4 |
|||||||
#104
|
|||||||||
|
|||||||||
Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements
Quote:
The only judgement that really matters is that of the compliance officer at the merchant's bank. So far, in my small sample, the compliance officer has approved the use of the DPM method, and allowed for filling out of SAQ-A. I would advise having a discussion with them, with an email trail, before you choose to implement it over x-payments. Quote:
I agree that the 10 store functionality of x-payments is not very useful. However - according to QT, you do have the ability to brand the checkout page for each store: http://forum.x-cart.com/showpost.php?p=310504&postcount=2 @nickff Quote:
I think this is a risky position for you to take with your clients. It could be in the fine print somewhere of something they have received. It could become an issue if there is ever an instance of fraud, then the bank would try to put all the burden on the merchant. I know of several who believe this is a low risk, and choose not to do anything yet while they wait for clear guidance from their banks. It is ultimately the merchant's decision - I just try and make sure they have all the information they need to decide. ---
__________________
X-CART (4.1.9,12/4.2.2-3/4.3.1-2/4.4.1-5)-Gold (CDSEO, Altered-Cart On Sale, BCSE Preorder Backorder, QuickOrder, X-Payments, BCSE DPM Module) |
|||||||||
#105
|
|||||||
|
|||||||
Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements
I just got off the phone with Authorize.net, Nation wide credit card solutions and Control Scan ( the Company that scans my website for PCI ) none of them have heard of this. They all have said this sounds like a sales ploy. You would think Authorize.net would here about this way before Xcart would.
__________________
x-cart 4.4 |
|||||||
#106
|
|||||||
|
|||||||
Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements
None of them have heard of PA-DSS compliance? I highly doubt that. What exactly did you ask them?
__________________
Padraic Ryan Ryan Design Studio Professional E-Commerce Development |
|||||||
#107
|
|||||||
|
|||||||
Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements
I asked them if Authorize.net aim was no longer going to be accepted as being PCI compliant. I also asked them if they have heard of a move not to allow a customer to input their credit card info on a website. That they would be directed to a credit card payment gateway instead and then be allowed to input their credit card info. Such as Authorize.net Sim to be able to be PCI compliant. They all said no they have not heard of such a thing. They all stated as long as you have a SSL installed that you would be fine under PCi guide lines. I know from past experience that the Authorize.net SIm is not very reliable. It will kick out the customer at times sending them back to the website. Authorize.net even suggests using their Aim version instead because of this.
__________________
x-cart 4.4 |
|||||||
#108
|
|||||||||
|
|||||||||
Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements
Quote:
Please provide the following information regarding the payment applications your organization uses: Payment Application in Use | Version Number | Last Validated according to PABP/PA-DSS https://www.pcisecuritystandards.org/security_standards/documents.php?category=saqs Step 1 to determine if you are compliant is to figure out which SAQ applies to you, most merchants that accept credit cards on their site qualify for SAQ-C If you call authorize.net back, ask them "Do I need to use a PA-DSS validated payment application?"
__________________
Mike White - Now Accepting new clients and projects! Work with the best, get a US based development team for just $125 an hour. Call 1-502-773-6454, email mike at babymonkeystudios.com, or skype b8bym0nkey XcartGuru X-cart Tutorials | X-cart 5 Tutorials Check out the responsive template for X-cart. |
|||||||||
#109
|
|||||||
|
|||||||
Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements
Dumb question: Why is X-Payments PCI Compliant if you supposedly don't leave your website to process the payment?
__________________
Aaron Running version: 4.5.5 |
|||||||
#110
|
|||||||||
|
|||||||||
Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements
Because X-payments has been validated by the pci council to meet the requirements of PA-DSS. For you to be pci compliant and accept cards directly on your site, you must use a PA-DSS validated payment application.
__________________
Mike White - Now Accepting new clients and projects! Work with the best, get a US based development team for just $125 an hour. Call 1-502-773-6454, email mike at babymonkeystudios.com, or skype b8bym0nkey XcartGuru X-cart Tutorials | X-cart 5 Tutorials Check out the responsive template for X-cart. |
|||||||||
|
|||
X-Cart forums © 2001-2020
|