ttremain Posted September 10, 2015 Share Posted September 10, 2015 I noticed this about a week ago. My Apache logs show that PayPal is sending the IPN, but suddenly (with no config changes) my invoices are no longer marked with a payment. 173.0.81.1 - - [10/Sep/2015:13:55:26 -0700] "POST / HTTP/1.0" 200 14911 "-" "PayPal IPN ( https://www.paypal.com/ipn )" I've checked the IPN config, as well as API signature and login. All look good. Please advise. 0 Quote Link to comment Share on other sites More sharing options...
sentq Posted September 10, 2015 Share Posted September 10, 2015 Check Gateway Log: Admin Area -> Billing -> Gateway Log, is there any issues there? 0 Quote Link to comment Share on other sites More sharing options...
elkiwigrande Posted September 10, 2015 Share Posted September 10, 2015 I got this email this afternoon from Paypal: --------------------------------------------------------------------------------------As we have previously communicated to you, PayPal is upgrading the certificate for http://www.paypal.com to SHA-256. This endpoint is also used by merchants using the Instant Payment Notification (IPN) product. This upgrade is scheduled for 9/30/2015; however, we may need to change this date on short notice to you to align to the industry security standard. You’re receiving this notification because you’ve been identified as a merchant who has used IPN endpoints within the past year. If you have not made the necessary changes, we urge you to do so right away to avoid a disruption of your service! Because these changes are technical in nature, we advise that you consult with your individuals responsible for your PayPal integration. They will be able to identify what, if any, changes are needed. Please share this email and the hyperlinks below with your technical contact for evaluation. Testing in the Sandbox is one of the best ways to make sure your integration works. Sandbox endpoints have been upgraded to accept secure connections by the SHA-256 Certificates. Full technical details can be found in our Merchant Security System Upgrade Guide. In addition, our 2015-2016 SSL Certificate Change microsite contains a schedule of our service upgrade plan. -------------------------------------------------------------------------------------- Do I need to do anything on my end to ensure continuity with Paypal? Thanks, Chris 0 Quote Link to comment Share on other sites More sharing options...
ttremain Posted September 11, 2015 Author Share Posted September 11, 2015 Check Gateway Log: Admin Area -> Billing -> Gateway Log, is there any issues there? Nothing since the 4th. But at that time, it says an Invalid Receiver Email. I have addressed that, and resent the IPN. Apache says it received the IPN, but there is nothing in the gateway log, and the invoice is still unpaid. 0 Quote Link to comment Share on other sites More sharing options...
swinghosting Posted September 11, 2015 Share Posted September 11, 2015 I'm wondering that, too. You'd think WHMCS would have a page saying something one way or the other. If they do, it's not able to be found when searching for whmcs paypal "IPN endpoints" "SHA-256" 0 Quote Link to comment Share on other sites More sharing options...
ueli.michel@web.de Posted September 11, 2015 Share Posted September 11, 2015 Hello Same here. What I have to do? I'm using WHMCS Version: 5.3.14 0 Quote Link to comment Share on other sites More sharing options...
nimonogi Posted September 11, 2015 Share Posted September 11, 2015 I've got this email today from paypal. Is there anything we need to do about this? "As we have previously communicated to you, PayPal is upgrading the certificate for http://www.paypal.com to SHA-256. This endpoint is also used by merchants using the Instant Payment Notification (IPN) product. This upgrade is scheduled for 9/30/2015; however, we may need to change this date on short notice to you to align to the industry security standard. You’re receiving this notification because you’ve been identified as a merchant who has used IPN endpoints within the past year. If you have not made the necessary changes, we urge you to do so right away to avoid a disruption of your service! Because these changes are technical in nature, we advise that you consult with your individuals responsible for your PayPal integration. They will be able to identify what, if any, changes are needed. Please share this email and the hyperlinks below with your technical contact for evaluation. Testing in the Sandbox is one of the best ways to make sure your integration works. Sandbox endpoints have been upgraded to accept secure connections by the SHA-256 Certificates. Full technical details can be found in our Merchant Security System Upgrade Guide. In addition, our 2015-2016 SSL Certificate Change microsite contains a schedule of our service upgrade plan. Thanks for your patience as we continue to improve our services." 0 Quote Link to comment Share on other sites More sharing options...
sentq Posted September 11, 2015 Share Posted September 11, 2015 under Admin Area -> Setup -> Payments -> Payment Gateways -> *PayPal* what the email address used in the configuration? make sure it is the primary email address as in PayPal account 0 Quote Link to comment Share on other sites More sharing options...
Wabun Posted September 11, 2015 Share Posted September 11, 2015 under Admin Area -> Setup -> Payments -> Payment Gateways -> *PayPal*what the email address used in the configuration? make sure it is the primary email address as in PayPal account Hi, same for me, but today I received email from PayPal that they are upgrading their certificate and that I was identified as merchant using IPN product, seems WHMcs needs to do something I think. 0 Quote Link to comment Share on other sites More sharing options...
Infopro Posted September 11, 2015 Share Posted September 11, 2015 Multiple threads on same topic merged here. 0 Quote Link to comment Share on other sites More sharing options...
ADz83 Posted September 11, 2015 Share Posted September 11, 2015 Cmon on answer from WHMCS about this? 0 Quote Link to comment Share on other sites More sharing options...
evotz Posted September 11, 2015 Share Posted September 11, 2015 How does this affect CentOS 5/RHEL 5/CloudLinux 5 vs. CentOS 6/RHEL 6/CloudLinux 6? I believe CentOS 5 uses an older openSSL version. I'm not sure if this affects anything regarding this or not. 0 Quote Link to comment Share on other sites More sharing options...
ttremain Posted September 11, 2015 Author Share Posted September 11, 2015 Multiple threads on same topic merged here. You merged two unrelated topics. Yes both had to do with PayPal, but still unrelated... - - - Updated - - - under Admin Area -> Setup -> Payments -> Payment Gateways -> *PayPal*what the email address used in the configuration? make sure it is the primary email address as in PayPal account It is. I manually marked this invoice as paid. Since this thread was messed up by someone merging an unrelated thread in, I'll open a new thread if I continue to have problems. 0 Quote Link to comment Share on other sites More sharing options...
jbw Posted September 12, 2015 Share Posted September 12, 2015 paypal now requires that all certs used be 2048 sha-2 you should check your OS and sever , see that it is SHA-2 compliant. check your SSL cert to be sure it is 2048 your cert should say this in SSL/TLS management Description 2,048 bits, created 12/24/14 9:09 AM UTC ID ( I have altered mine here ) b2fb2_fb299_3a788a9dab6a6db9868351b4b Size 2048 also if your cpanel allows for creation of smaller size than 2048 bits , I forget what that was now, but that will mean you need to upgrade cpanel and or your OS. the best way to set up whmcs is on multiple servers clustered in a master / slave config. where whmcs is housed in its own server and makes accounts on a slave IE: no hosting accounts on master just whmcs with Data base any hosting accounts are on slave , so master talks to slave but slave cannot talk to master. further if you are experiencing lots of Bruteforce attacks I have IP list for all recently know bad IPs after implementation we have had NO entrys in master and only 2 or 5 a month on slave. you may contact me here for list to add in blacklist. servers@nrwebus.com 0 Quote Link to comment Share on other sites More sharing options...
Wabun Posted September 19, 2015 Share Posted September 19, 2015 Hi, are you saying that both your server and your domain in use for WHmcs should be SHA-2 certificates and minimal 2048? 0 Quote Link to comment Share on other sites More sharing options...
Wabun Posted September 20, 2015 Share Posted September 20, 2015 (edited) Right, I bought 2 new SSL certificates one for the server and one for the domain, check their status and all looks fine, but still not getting any separated email from Paypal about the payment confirmation, although WHMcs marked the invoices as paid and I can see the transaction ID. Weirdo, perhaps something wrong with PayPal or WHMcs payment gateway??? Any one another suggestion? https://www.digicert.com/help/ Issuer = RapidSSL SHA256 CA - G3 Key Length = 2048 bit Signature algorithm = SHA256 + RSA (excellent) Secure Renegotiation: Supported And Intermediate certificate: Subject RapidSSL SHA256 CA - G3 Valid from 29/Aug/2014 to 20/May/2022 Issuer GeoTrust Global CA SSL Certificate is correctly installed Edited September 20, 2015 by Wabun Added SSL certificate. 0 Quote Link to comment Share on other sites More sharing options...
Wabun Posted September 21, 2015 Share Posted September 21, 2015 All sorted, I rang PayPal. 0 Quote Link to comment Share on other sites More sharing options...
stefan.mitu Posted September 30, 2015 Share Posted September 30, 2015 Hello, How can i verify if my ssl is ok? I've checked the certifs and it said it has fingerprints for sha-1 and sha-256. What more should i serach for? Sorry i am not that good at ssl. 0 Quote Link to comment Share on other sites More sharing options...
inthanet Posted October 4, 2015 Share Posted October 4, 2015 Check your site here https://shaaaaaaaaaaaaa.com/ 0 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.