My SellerDeck Account | Newsletter | Free Trial

Community and Knowledge Base

  #1  
Old 17-Dec-2014, 09:58 AM
pmsupport's Avatar
pmsupport pmsupport is offline
Registered User
Join Date: Mar 2007
Full Name: Paul Murphy
Posts: 244
Thanks: 2
Thanked 35 Times in 28 Posts
SellerDeck Payments: SSLv3 Support and POODLE

Hi all,

You may already have heard about a security issue known as SSLv3 POODLE. The issue affects servers and clients that use the SSL protocol to encrypt sensitive information in transit. However, SSLv3 is a legacy protocol which has been superseded for some time by TLS1.0.

From 15 January 2015 the SellerDeck Payments platform will no longer accept connections using SSLv3. Instead SellerDeck Payments will use TLS. Therefore you must be using a hosting server which supports TLS1.0 or better in order to continue using SellerDeck Payments. Your hosting server will need to have Crypt::SSLeay and NET::SSL installed in order to support TLS.

I am using SellerDeck Payments and SellerDeck hosting. Will customers be able to checkout correctly on my site after 15 January 2015?

Yes. If you are using SellerDeck hosting, no action is required.

I am using SellerDeck Payments with non-SellerDeck hosting. Will customers be able to checkout correctly on my site after 15 January 2015?

If you are using non-SellerDeck hosting, you will need to check that your hosting server has Crypt::SSLeay and NET::SSL installed. You can check if these modules are installed using the “Website Analysis” tool built into SellerDeck:

1. In SellerDeck, go to 'Help | Troubleshooting | Website Analysis'.
2. Under “Perl Modules”, you can see what Perl modules are installed and the version installed.
3. Look for the Perl modules Crypt::SSLeay and NET::SSL.

If the modules are not installed on your server, you will need to contact your hosting company to arrange for them to be installed.

If the hosting company does not agree to install the Perl modules, the only alternative is to change hosting provider.

Please note, after 15 January 2015, Internet Explorer 6 and below will no longer be supported. That means in order to take MOTO payments within the SellerDeck software, you will need to have Internet Explorer 7 or above installed. Also, shoppers will not be able to checkout on the site with Internet Explorer 6 and below.
__________________
Paul Murphy
Operations Manager - SellerDeck
Reply With Quote
  #2  
Old 09-Jan-2015, 08:12 AM
orcahouse orcahouse is offline
Registered User
Join Date: Oct 2005
Full Name: Tom Riddell
Posts: 92
Thanks: 12
Thanked 8 Times in 5 Posts
My hosting company has told me I can install the modules through my control panel. This is straightforward BUT there are several versions of both modules. Can you be more specific with the module versions.
__________________
www.silvermoonbeads.com - Gemstones, Pearls, Hill Tribe sterling silver, Swarovski and Findings.
Reply With Quote
  #3  
Old 09-Jan-2015, 10:42 AM
fergusw's Avatar
fergusw fergusw is offline
Registered User
Join Date: Mar 2004
Full Name: Fergus Weir
Posts: 1,583
Thanks: 75
Thanked 110 Times in 90 Posts
For reference, your hosting company should be implementing the list of modules (including the SSL ones here) as listed here:
http://community.sellerdeck.com/showthread.php?t=44812
Reply With Quote
The Following User Says Thank You to fergusw For This Useful Post:
orcahouse (09-Jan-2015)
  #4  
Old 09-Jan-2015, 11:10 AM
maroni35 maroni35 is offline
Registered User
Join Date: Jul 2003
Full Name: D Sewell
Posts: 107
Thanks: 9
Thanked 2 Times in 2 Posts
I am sorry but this is getting very very confusing.

Is this the same alert that you sent out in November which was very unclear, and is in post http://community.sellerdeck.com/showthread.php?t=55590

This suggested that we did not need to do anything if it is currently working.

Quote"
Sorry this is confusing, I'll put my hand up as I reviewed the email with others today before it went out.

Mike has distilled the essential elements from it correctly.

Firstly this is not about any 'SSL' certificate you may use on your web site (well not directly).

This is all about encryption between two points, the two points that may be a concern to you are your web server and your PSP(s).

You may have received a letter from your merchant bank helpfully telling you they will no longer support SSLv3, unhelpfully they didn't mention that you are highly unlikely to actually connect to them directly, you do it via a PSP.

If you're already using PayPal and it works, you're good
If you're already using SellerDeck Payments and it works, You're good"

well we are using Sellerdeck Payments it is working but I don't have the modules mentioned installed. So am I good???

Could you please number your alerts or something so that I know if I have dealt with the issue. Can you please clarify with a categorical answer.

Such as ignoring our previous alerts that suggested if things were working now you are fine if you do not have the two modules installed than there is no way this will work from the 15th January
__________________
David Sewell
The Cotton Patch
http://www.cottonpatch.co.uk
http://www.rotarycuttershop.co.uk
Reply With Quote
  #5  
Old 09-Jan-2015, 12:26 PM
maroni35 maroni35 is offline
Registered User
Join Date: Jul 2003
Full Name: D Sewell
Posts: 107
Thanks: 9
Thanked 2 Times in 2 Posts
Also big thank you to Fergus for pointing out the previous post on how to find the modules to install, but they don't actually link to anything anymore. You can find the Crypt one if you search on the general site it links to but not sure if this correct one to use.

Could we have something definite from Sellerdeck on which modules they would recommend and where to get them from?
__________________
David Sewell
The Cotton Patch
http://www.cottonpatch.co.uk
http://www.rotarycuttershop.co.uk
Reply With Quote
  #6  
Old 09-Jan-2015, 01:23 PM
orcahouse orcahouse is offline
Registered User
Join Date: Oct 2005
Full Name: Tom Riddell
Posts: 92
Thanks: 12
Thanked 8 Times in 5 Posts
Thanks Fergusw. My hosts & I are happy with the generic modules to install but it's the specific version we're stuck on. Failing Sellerdeck responding, maybe you could post the full version number of these modules that you have installed. Thanks again.
__________________
www.silvermoonbeads.com - Gemstones, Pearls, Hill Tribe sterling silver, Swarovski and Findings.
Reply With Quote
  #7  
Old 11-Jan-2015, 03:34 PM
pmsupport's Avatar
pmsupport pmsupport is offline
Registered User
Join Date: Mar 2007
Full Name: Paul Murphy
Posts: 244
Thanks: 2
Thanked 35 Times in 28 Posts
Hi all,

Thanks for your feedback.

We have now updated our knowledge base article to include version information and updated links:

http://community.sellerdeck.com/show...347#post289347

Thanks
__________________
Paul Murphy
Operations Manager - SellerDeck
Reply With Quote
The Following User Says Thank You to pmsupport For This Useful Post:
peblaco (11-Jan-2015)
  #8  
Old 15-Jan-2015, 11:44 AM
pmsupport's Avatar
pmsupport pmsupport is offline
Registered User
Join Date: Mar 2007
Full Name: Paul Murphy
Posts: 244
Thanks: 2
Thanked 35 Times in 28 Posts
SSLv3 update - No further action required

Hi all,

This is just an update to reassure merchants that if you have SellerDeck Payments and everything is working ok, there is no further action to be taken. SSLv3 is now fully disabled. Your SellerDeck Payments service continues as normal.

Please ignore the original post regarding the deadline on 15 January 2015. There was a miscommunication between SellerDeck and our provider.

Thanks
__________________
Paul Murphy
Operations Manager - SellerDeck
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On



All times are GMT. The time now is 05:40 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2017, Jelsoft Enterprises Ltd.