Re: Secure Shopping PHP MySQL??
| From: | (Richard Lynch) | Date: | Wed, 06 Sep 2000 05:23:39 +0000 |
| Subject: | Re: Secure Shopping PHP MySQL?? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-15441@lists.php.net to get a copy of this message | ||
In article <01b901c01784$33e5e440$aa23eec7@ncelec.com>,
phplist@webbcite.com ("PHPlist") wrote:
> I am trying to put together a small site with a few items that can be
> ordered. I have a secure certificate (SSL/https) that will house the site.
> I can not afford to pay the pricing of PGP for the server to encrypt form
> mail. I have not been able to get GnuPG to send an encrypted email message
> to a remote Windoz PGP client to be viewed. It doesn't sound like there is
> much support for Windoz products under GnuPG.
Last I checked, gpg worked just fine under Windows, if you didn't mind
using MS-DOS to talk to it... But it's been awhile since I've tried it...
Oooh. I think you also have to dink around with newline conversion, or
make sure it doesn't happen or something. But it did work, once upon a
time.
There's definitely some threads on gpg in the old mailing list archives
and how to use it to send the e-mail.
I set up a similar system for a guy once, 'cuz he already had a kerchunker
(okay, so it's a card-swiper these days) and didn't want to pay an extra
5% to the ISP.
> Another option that I was thinking of was using PHP3 and MySQL. I would
> like the customer to order online via the secure connection and have the
> ordering information stored in a MySQL database. The customer could then go
> to a secure web page and view the order information and process the order
> manually.
>
> Is this possible? Any security concerns with doing it this way?
How secure is the MySQL database?
Unless it's
(A) running on the same box as SSL, and *NOT* available to any other box, or
(B) running on a different box, but *ONLY* available to the SSL box
you've got problems if you are going to be storing sensitive data in the
database. If you process the credit cards in real-time, and only store
the shipping info and what the client ought to be sending, that would be
okay.
> Does anyone have any other *inexpensive* solutions to e-commerce using SSL,
> PHP, MySQL?
CCNow takes like 9%, and doing it yourself through a card-swipe, unless
you have big volume, the credit card companies are gonna take 4%, so the
difference is not that big...
CyberCash (et al) may or may not be supported by your web-host, so they
may have an account you can piggy-back on for little or nothing.
I've been down the path you're on, and I gotta say that having an ISP set
up the SSL and CyberCash stuff for me and paying him 10% was way less
frustrating than futzing with gpg setup and then training the computer
illiterate to use gpg.
--
Richard Lynch | If this was worth $$$ to you, buy a CD
US Customer Support Director | from one of the artists listed here:
Zend Technologies USA | http://www.L-I-E.com/artists.htm
http://www.zend.com | (this has nothing to do with Zend,
duh!)