lukewd Posted August 13, 2012 Share Posted August 13, 2012 I have just been granted merchant facilities by my bank and the last hurdle is that they require us to provide a PCI certificate. Could anyone please let me know what needs to be done (in terms of WHMCS only) in order to be PCI compliant? I do understand that PCI compliance is a process and that there will obviously be other aspects of my hosting environment that will determine my compliance. But I would simply like to know if there is anything with regards to WHMCS specifically that needs to be done, or that I should know about? many thanks, Luke 0 Quote Link to comment Share on other sites More sharing options...
easyhosting Posted August 13, 2012 Share Posted August 13, 2012 I have just been granted merchant facilities by my bank and the last hurdle is that they require us to provide a PCI certificate. Could anyone please let me know what needs to be done (in terms of WHMCS only) in order to be PCI compliant? I do understand that PCI compliance is a process and that there will obviously be other aspects of my hosting environment that will determine my compliance. But I would simply like to know if there is anything with regards to WHMCS specifically that needs to be done, or that I should know about? many thanks, Luke you could take a look here http://www.whmcs.com/partners/mcafee-secure/ 0 Quote Link to comment Share on other sites More sharing options...
lukewd Posted August 14, 2012 Author Share Posted August 14, 2012 Thanks, yes I have already found that, and this page as well: http://www.whmcs.com/features/pci-compliance/ However, there are several threads in the forum that suggest that WHMCS by default is not PCI compliant out of the box. It fails in the way that it sends password reset emails over insecure networks via email in plaintext. And this got me wondering whether there are other places where WHMCS falls short? And also, how do we go about fixing it so it is PCI compliant? Thanks 0 Quote Link to comment Share on other sites More sharing options...
easyhosting Posted August 14, 2012 Share Posted August 14, 2012 However, there are several threads in the forum that suggest that WHMCS by default is not PCI compliant they mean WHMCS.COM is not PCI compliant how do we go about fixing it so it is PCI compliant? once you make you own website PCI compliant this will also make your own WHMCS PCI compliant. we have a Comodo Instant SSL cert which comes with PCI Compliance, which is checked on a daily basis and is enough to satisfy our CC provider 0 Quote Link to comment Share on other sites More sharing options...
lukewd Posted August 14, 2012 Author Share Posted August 14, 2012 thanks for the clarification and for the tip on Comodo, will check them out now. 0 Quote Link to comment Share on other sites More sharing options...
openmind Posted August 14, 2012 Share Posted August 14, 2012 they mean WHMCS.COM is not PCI compliant once you make you own website PCI compliant this will also make your own WHMCS PCI compliant. we have a Comodo Instant SSL cert which comes with PCI Compliance, which is checked on a daily basis and is enough to satisfy our CC provider Not quite WHMCS has not been through a PA-DSS which some merchant providers will require as it is the software that processes/stores information. This is separate from making your own site/server PCI compliant. 0 Quote Link to comment Share on other sites More sharing options...
lukewd Posted August 14, 2012 Author Share Posted August 14, 2012 I see thanks for the clarification. 0 Quote Link to comment Share on other sites More sharing options...
VicToMeyeZR Posted August 16, 2012 Share Posted August 16, 2012 Whatever you do don't follow WHMC lead on this(recent hack events). Go to a completely different site that deals specifically with PCI compliance. 0 Quote Link to comment Share on other sites More sharing options...
openmind Posted August 16, 2012 Share Posted August 16, 2012 PCI compliance has got sod all to do with the recent WHMCS hack as that was social engineering not a compromise of the software. Don't confuse the issue. 0 Quote Link to comment Share on other sites More sharing options...
easyhosting Posted August 16, 2012 Share Posted August 16, 2012 PCI compliance has got sod all to do with the recent WHMCS hack as that was social engineering not a compromise of the software. Don't confuse the issue. Phil trouble is when you read through these forums, it seems that now the social engineering incident is getting the blame for everything. even some are blaming this on the current slow support 0 Quote Link to comment Share on other sites More sharing options...
openmind Posted August 16, 2012 Share Posted August 16, 2012 Unfortunately so... 0 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.