RE: [PHP] Secure Shopping PHP MySQL??

From: Date: Mon, 08 May 2000 00:40:10 +0000
Subject: RE: [PHP] Secure Shopping PHP MySQL??
Groups: php.general 
Request: Send a blank email to php-general+get-15622@lists.php.net to get a copy of this message
I would also suggest using a secure program to connect to MySQL, or the whole thing is pointless. OpenSSH is a good one (www.openssh.com) -----Original Message----- From: Richard Lynch [SMTP:richard@zend.com] Sent: Tuesday, September 05, 2000 10:24 PM To: php-general@lists.php.net Subject: Re: [PHP] Secure Shopping PHP MySQL?? In article <01b901c01784$33e5e440$aa23eec7@ncelec.com>, phplist@webbcite.com ("PHPlist") wrote: > I am trying to put together a small site with a few items that can be > ordered. I have a secure certificate (SSL/https) that will house the site. > I can not afford to pay the pricing of PGP for the server to encrypt form > mail. I have not been able to get GnuPG to send an encrypted email message > to a remote Windoz PGP client to be viewed. It doesn't sound like there is > much support for Windoz products under GnuPG. Last I checked, gpg worked just fine under Windows, if you didn't mind using MS-DOS to talk to it... But it's been awhile since I've tried it... Oooh. I think you also have to dink around with newline conversion, or make sure it doesn't happen or something. But it did work, once upon a time. There's definitely some threads on gpg in the old mailing list archives and how to use it to send the e-mail. I set up a similar system for a guy once, 'cuz he already had a kerchunker (okay, so it's a card-swiper these days) and didn't want to pay an extra 5% to the ISP. > Another option that I was thinking of was using PHP3 and MySQL. I would > like the customer to order online via the secure connection and have the > ordering information stored in a MySQL database. The customer could then go > to a secure web page and view the order information and process the order > manually. > > Is this possible? Any security concerns with doing it this way? How secure is the MySQL database? Unless it's (A) running on the same box as SSL, and *NOT* available to any other box, or (B) running on a different box, but *ONLY* available to the SSL box you've got problems if you are going to be storing sensitive data in the database. If you process the credit cards in real-time, and only store the shipping info and what the client ought to be sending, that would be okay. > Does anyone have any other *inexpensive* solutions to e-commerce using SSL, > PHP, MySQL? CCNow takes like 9%, and doing it yourself through a card-swipe, unless you have big volume, the credit card companies are gonna take 4%, so the difference is not that big... CyberCash (et al) may or may not be supported by your web-host, so they may have an account you can piggy-back on for little or nothing. I've been down the path you're on, and I gotta say that having an ISP set up the SSL and CyberCash stuff for me and paying him 10% was way less frustrating than futzing with gpg setup and then training the computer illiterate to use gpg. -- Richard Lynch | If this was worth $$$ to you, buy a CD US Customer Support Director | from one of the artists listed here: Zend Technologies USA | http://www.L-I-E.com/artists.htm http://www.zend.com | (this has nothing to do with Zend, duh!) -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#15622) next »