I think Man City are using Paypal Pro. Well at least the express checkout. They seem to be using website payments standard not payments direct.. maybe because of the pci issue (or should i say confusion)
I say confusion because there are so many conflicting views from Actinic, Paypal and the Paypal developers forum regarding this issue, (of Paypal pro and pci compliance), and for the life of me, I cant get to the bottom of it.
Actinic (and other posts on this forum) explicitly say the SSL pages need to be on a pci compliant server
http://community.actinic.com/showthread.php?t=45030
A Paypal merchant developer just explicitly told me on the phone the opposite, that SSL pages at checkout is all you need as long as you dont store any cc details, to be pci compliant (along with displaying the correct blurb on your site). That my server does not need to be pci compliant as it is only transmitting encrypted cc details.
The paypal developers forum has threads saying that too.
http://www.pdncommunity.com/pdn/boar...cending&page=1
http://www.pdncommunity.com/pdn/sear...sage&q=pro+pci
I would love to know the definitive answer, there is so much differing opinion.
I suspect that the server actually does need to be pci compliant.. but the wildly differing opinions are very confusing.
I say confusion because there are so many conflicting views from Actinic, Paypal and the Paypal developers forum regarding this issue, (of Paypal pro and pci compliance), and for the life of me, I cant get to the bottom of it.
Actinic (and other posts on this forum) explicitly say the SSL pages need to be on a pci compliant server
http://community.actinic.com/showthread.php?t=45030
A Paypal merchant developer just explicitly told me on the phone the opposite, that SSL pages at checkout is all you need as long as you dont store any cc details, to be pci compliant (along with displaying the correct blurb on your site). That my server does not need to be pci compliant as it is only transmitting encrypted cc details.
The paypal developers forum has threads saying that too.
http://www.pdncommunity.com/pdn/boar...cending&page=1
http://www.pdncommunity.com/pdn/sear...sage&q=pro+pci
I would love to know the definitive answer, there is so much differing opinion.
I suspect that the server actually does need to be pci compliant.. but the wildly differing opinions are very confusing.
Comment