{"id":2414,"date":"2015-09-16T02:52:55","date_gmt":"2015-09-16T06:52:55","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=1865"},"modified":"2017-03-27T04:28:39","modified_gmt":"2017-03-27T08:28:39","slug":"urgent-notice-regarding-sha-256-compliance-for-paypal-com","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/urgent-notice-regarding-sha-256-compliance-for-paypal-com\/","title":{"rendered":"Urgent Notice Regarding SHA-256 Compliance for Paypal.com"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2015\/09\/paypal-security.jpg\" alt=\"paypal SHA-256 Update\" width=\"478\" height=\"250\" class=\"aligncenter size-full wp-image-1913\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2015\/09\/paypal-security.jpg 478w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2015\/09\/paypal-security-300x157.jpg 300w\" sizes=\"auto, (max-width: 478px) 100vw, 478px\" \/><br \/>\n<strong><em>Urgent Action Needed! Paypal.com Change Impacting IPN<\/em><\/strong><br \/>\n<strong>1.<\/strong> Do you use Instant Payment Notification (IPN)?<br \/>\n<strong>2.<\/strong> If, so you must be running a SHA-256 SSL compliant server as soon as possible!<br \/>\n<strong>3.<\/strong> Contact the person or the company who hosts your IPNs to ensure they are SHA-256 Compliant<\/p>\n<p>Paypal.com is one of the most popular payment gateways in the world. As a payment processor, it is PayPal\u2019s duty to ensure the highest level of security for their merchants, developers, and consumers. In accordance with this duty, PayPal is making upgrades to the SSL certificates on all their web and API endpoints.<\/p>\n<p>If you are using Paypal.com for instant payment notification (IPN) and have a non SHA-256 compliant server or OS, you will need to upgrade to a SHA-256 compliant server \/ OS configuration.<\/p>\n<p>If your IPN listener\/validator is hosted by a partner, shopping cart or third-party hosting, please reach out to them and confirm that they have taken the necessary steps to ensure ongoing connectivity. Refer to online resources, such as those listed below, for details on compatible configurations, then contact your website technical team for development support.<\/p>\n<p><strong>Why is PayPal making these changes?<\/strong><\/p>\n<p>The industry is phasing out the now old and insecure SHA-1 Hashing Algorithm in favor of its successor SHA-2. This change is taking effect across the entire Internet \u2013 spearheaded by Google, Mozilla, Microsoft, and the CA\/B Forum.<br \/>\nSince Google Chrome is deprecating support for SHA-1 by the end of 2015, and all support for SHA-1 will be deprecated by the end of 2016, you will need to act soon to implement these changes.<\/p>\n<p><strong>During the upgrade, ensure that all SSL certificates meet the following standards:<\/strong><\/p>\n<div class=\"imgesulis\">\n<ul>\n<li>Discontinue support for secure connections that require validation with the Symantec G2 Root Certificate; only validate with the <strong><a href=\"https:\/\/www.thesslstore.com\/symantec.aspx\" target=\"_blank\">Symantec G5 Root Certificate<\/a><\/strong>.<\/li>\n<li>That the server certificate and intermediate certificates use SHA-256 signatures<\/li>\n<\/ul>\n<\/div>\n<p><strong>SHA2 supported Browser and Server List for Symantec, GeoTrust, Thawte &#038; RapidSSL Certificates:<\/strong><\/p>\n<p><strong>Operating Systems\/Other \u2013 support SHA-256<\/strong><\/p>\n<div class=\"imgesulis\">\n<ul>\n<li>Android 2.3+<\/li>\n<li>Apple iOS 3.0+<\/li>\n<li>Apple OS X 10.5+<\/li>\n<li>Blackberry 5.0+<\/li>\n<li>ChromeOS<\/li>\n<li>Windows 7<\/li>\n<li>Windows Outlook 2003+ running on Service Pack 3 (partial), complete on Windows Vista<\/li>\n<li>Windows Phone 7+<\/li>\n<li>Windows Vista<\/li>\n<li>Windows XP SP3+ (patched)<\/li>\n<\/ul>\n<\/div>\n<p><strong>Browsers \u2013 support SHA-256<\/strong><\/p>\n<p><body><\/p>\n<div class=\"imgesulis\">\n<ul>\n<li>Adobe Acrobat\/Reader 7<\/li>\n<li>Blackberry 5+<\/li>\n<li>Chrome 26+<\/li>\n<li>Chrome under Linux<\/li>\n<li>Chrome under Mac from Mac OS X 10.5<\/li>\n<li>Chrome under Windows Vista and higher<\/li>\n<li>Firefox 1.5+<\/li>\n<li>Internet Explorer 7+ and higher<\/li>\n<li>Internet Explorer 7+ under Vista<\/li>\n<li>Internet Explorer 6+ under Windows XP SP3 (patched)<\/li>\n<li>Java 1.4.2+ based products<\/li>\n<li>Konqueror 3.5.6+<\/li>\n<li>Mozilla 1.4+<\/li>\n<li>Mozilla products based on NSS 3.8+ (since April 2003)<\/li>\n<li>Netscape 7.1+<\/li>\n<li>Opera 9.0+<\/li>\n<li>Products based on OpenSSL 0.9.8o+<\/li>\n<li>Safari from Mac OS X 10.5+<\/li>\n<li>Windows Phone 7+<\/li>\n<\/ul>\n<\/div>\n<p><strong>Servers \u2013 support SHA-256<\/strong><\/p>\n<div class=\"imgesulis\">\n<ul>\n<li>Apache server and OpenSSL 0.9.8o+<\/li>\n<li>Apache 2.0.63+ , OpenSSL 1.1.x<\/li>\n<li>OpenSSL based servers &#8211; OpenSSL 0.9.8o+<\/li>\n<li>Windows Server 2003+ with patch 938397<\/li>\n<li>Windows Server 2003+ or XP client with patch 968730<\/li>\n<li>Windows Server 2008+<\/li>\n<li>Java based servers &#8211; 1.4.2+<\/li>\n<li>Cisco ACE module software version A4(1.0)<\/li>\n<\/ul>\n<\/div>\n<p><strong>Citrix Receiver models<\/strong><\/p>\n<div class=\"imgesulis\">\n<ul>\n<li>Oracle Mac 11.8.2<\/li>\n<li>Windows 4.1 (std)<\/li>\n<li>Windows 3.4 (ent)<\/li>\n<li>Windows 8\/RT (1.4)<\/li>\n<li>Windows Phone 8 (1.1)<\/li>\n<li>WebLogic v10.3.1+ see bug8422724<\/li>\n<li>Oracle Wallet Manager 11.2.0.3+<\/li>\n<li>IBM HTTP Server 8.5 (with Lotus Domino  9+)<\/li>\n<li>Juniper Secure Access &#8211; SA 6.4R5, 6.5R3, and 7.0R1 and later releases.<\/li>\n<li>WebSphere application Server v8.0.0.4<\/li>\n<\/ul>\n<\/div>\n<p><strong>Servers which reportedly DO NOT support SHA-256 in their entirety<\/strong><\/p>\n<div class=\"imgesulis\">\n<ul>\n<li>Juniper SBR<\/li>\n<li>IBM Domino<\/li>\n<li>Citrix Receiver models \u2013 see URL*<\/li>\n<li>Linux 13.0<\/li>\n<li>IOS 5.8.3<\/li>\n<li>Android 3.4.13<\/li>\n<li>HTML 5 1.2<\/li>\n<li>Playbook 1.0<\/li>\n<li>Blackberry 2.2 \/ BlackBerry 1.0 Tech Preview<\/li>\n<li>Cisco ACE module software versions A2 and A3<\/li>\n<\/ul>\n<\/div>\n<p><strong>Some Important FAQs for Upgrading to SHA-2 SSL?<\/strong><\/p>\n<p><strong>Q. What is the SHA-256 rollout schedule?<\/strong><br \/>\nTo avoid service interruption, your clients must support SHA-256 per the schedule above.<\/br><br \/>\n<strong>Q. Can I update BOTH the G5 root and SHA-256 certificate at the same time?<\/strong><br \/>\nYes. First, confirm that the G5 Root Certificate is in your keystore. If not, then download and add it. Next, update your SSL certificate to process SHA-256 certificates.<\/br><br \/>\n<strong>Q. How do I check my existing SSL Certificate is SHA-1 or SHA-2 Support?<\/strong><br \/>\nYou can easily check the by visiting the <strong><a href=\"https:\/\/shachecker.com\/\" target=\"_blank\">SHA Checker Tool<\/a><\/strong><\/br><br \/>\n<strong>Q. What is the status of the PayPal Sandbox used for integration testing?<\/strong><br \/>\nPayPal Sandbox endpoints have been upgraded to accept secure connections signed by the G5 Root Certificate and the SHA-256 algorithm, so merchants can begin testing their integration.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Urgent Action Needed! Paypal.com Change Impacting IPN 1. Do you use Instant Payment Notification (IPN)? 2. If, so you must be running a SHA-256 SSL compliant server as soon as&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[25],"tags":[],"class_list":["post-2414","post","type-post","status-publish","format-standard","hentry","category-ssl-certificates","post-without-tags"],"views":7903,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/2414","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=2414"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/2414\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=2414"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=2414"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=2414"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}