Coming SHA-256: Do I need to update my IPN listener that does not use a secure URL?

Currently, I use only payment buttons, and I got the IPN php script from https://github.com/paypal/ipn-code-samples dated November 10, 2014.

My script just goes to www.paypal.com without encryption.

Is encryption mandatory?

+4
source share
3 answers

Your IPN listener will be responsible for receiving PayPal callbacks and sending them to PayPal for verification. In this case, the connection between your server and the PayPal endpoint will require SHA-2 encryption.

, , / , , SHA-2.

PayPal , , -

+3

, SHA-2 (SHA-256). SSL SHA-2 .

Chrome SHA-1 2015 , PayPal SHA-1 2016 .

shaaa..

+1

PayPal SHA2 (SHA-256). ( Live), , .

https://developer.paypal.com/developer/ipnSimulator/

If the test passes, it means that your server may be dealing with SHA-2 and you no longer need to renew the certificate. If this fails, contact your server vendor to help you renew your SSL certificate.

0
source

Source: https://habr.com/ru/post/1607244/


All Articles