Re: Payflow Pro functions
| From: | John Donagher | Date: | Tue, 28 Nov 2000 22:35:29 +0000 |
| Subject: | Re: Payflow Pro functions | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-27754@lists.php.net to get a copy of this message | ||
Javier-
Yes, this is possible, but the basic idea that we've been trying to convey to Verisign is that
their SDK cripples certain types of implementations. In particular, anyone incorporating their SDK
into an SSL-enabled application will be forced to do some kludgy, unideal workaround. This
shouldn't be the case for customers paying $1k a month to use their service. Unfortunately,
since they seem to ignore everyone who's contacted them to complain, they don't see it
this way. :(
As far as workarounds go, this is probably the best there is.
John
On Tue, 28 Nov 2000, Javier Muniz wrote:
> After a short discussion with Lars Wilson, I've been asked to post the
> following here... it occured to me while reading the manual's user
> contributed notes, and I have yet to test it (probably will sometime
> next month)
>
> You could run two instances of apache side-by-side, one compiled with
> SSL+PHP4, the other compiled with PHP4+PayfloPro SDK. The
> PayFlowPro-enabled instance should listen only on lo0 as to prevent
> attacks from the outside world (to snoop on lo0 you should need root, in
> which case the server is already compromised). The SSL+PHP4 instance
> could then make http sub-requests to the PayFlowPro-enabled server,
> which would do the actual processing.
> For extra cleanliness, the PayFlowPro-enabled server could respond in
> XML.
> I have not looked into all of the security implications of such an
> implementation, and welcome comments.
>
>
--
John Donagher
Application Engineer
Intacct Corp. - Powerful Accounting on the Web
408-395-0989
720 University Ave.
Los Gatos CA 95032
www.intacct.com
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.0.1 (GNU/Linux)
Comment: For info see http://www.gnupg.org
mQGiBDnCZ1oRBACFgkFCV6p3dWic1qm1FLhip5beIyzZSt+ccTDYQQdPZA/t5H+k
PZ7ZFBIUrXz/oEqwQwlEKlg8JQqg7hgtcL+xrIJ0BInLeSJG4lvvB551g59Thr7/
OsdxNVxKci775+K+GkdAz4xcULMuB+QE7t665Ri46EAS8ALos5UG6DGmhwCguD0v
1cxwy/KlKr+oi4sWM9caueED/RmjiSD3vmBZQt6PMisVe1AmkEf6cJoemduCSJxu
0eMz/LIeu+CqfpuJH2N/dZ3hRj9xMSHF4l71wKqV99zhm58kDGwG1u3yVzULPDqz
0yL+8nunlkoOUyn3zOnh3Zmz4POFVMZQ5oian3QkLllUwly5JCi5tWULxZ2vOkb0
zzjuA/4jigNxYV4NAyCl+wAbnyzk9/Iz8EHv4/0Ex8ytlcMtvBJKa9HjJxlyIl74
yOILHk3+GSAdM0b3ZmbavpoCpebinOMBhqEVBwCI4VUIAqf86gx+2dKBGxfKPnU4
Xxvqs/BOl/EbeJjyd4uieYndGRaWg+kYXqZ7SxrlFN24fohnd7QgSm9obiBEb25h
Z2hlciA8am9obkB3ZWJtZXRhLmNvbT6IVgQTEQIAFgUCOcJnWgQLCgQDAxUDAgMW
AgECF4AACgkQIt6tVu6+jd3SHwCgjssFktMXf8NjE9JBR+sJ2gDIsW8An0CFNdFd
dU+DJYC6ogYP9AsVfM27uQENBDnCZ2MQBAD8E0qe1gBKjtoRmyiyORtwhOz/2XZE
mqiZN2NouAUWRRZd4dHggFAA1jUsp2MVIZZQyY9ajNVy3Oaxj5kYz8LR5GItxxcD
jC8RFXKM40ZfTJeR7fH6eJa689w+le71Tt4ALyN4xcjSWuksr8795AhHFjonDi8D
rgGIq6GtWvi/KwADBgQAmeBbcjPzhqR2M8TdvEyNfVTQSSp/RNoTjNNWpHui8V0p
kiQ49tbsqeMjXGToGgMugfmrX77JidXyuVjgYjT9xUdaaA25qKAR75M9izDliT7Y
h5L+QZTAw0/5X9go7XK3WI3LYfFrp4TP0veXgSWxDqccqsRzWKW7IoXsliTCbVqI
RgQYEQIABgUCOcJnYwAKCRAi3q1W7r6N3YIcAKCkJMTPLu6tOPnXPl2s3xmnSawy
BACeOx83WlBhVScYWo+BUzntJ6ks4T0=
=OkJU
-----END PGP PUBLIC KEY BLOCK-----