PayPal making big changes AGAIN.

Paypal has announced they making big changes to the criteria for accepting payments.

https://www.paypal-knowledge.com/infocenter/index?page=content&widgetview=true&id=FAQ1913&viewlocale=en_US

Come June this looks to now require an update of SSL certificates and the use of SSL for IPN post payment notification.

How ready are we for this and will all RB that accept Paypal payment need to have their own certs applied?

we are ready for these changes already:

  • We have sha256 support
  • New certificate is in the Trust chain
  • IPN POST has always used SSL

Some other minor tweaks will be added, but we are already compliant.

Thank you so much for the reply.

At present I do not use SSL (https) on my RB’s using PayPal with User manager. So at the moment I am assuming my IPN traffic from Paypal is not SSL encrypted?!
Is it therefore essential that I apply certificates and use https on my RB’s before Paypal make the changes or do you think it will be ok as it is?

Cheers