latest stable versions: v150827 (changelog)

Old Forums (READ-ONLY): The community now lives at WP Sharks™. If you have an s2Member® Pro question, please use our new Support System.

About: hakata

Sorry, I've not written a description yet. I'll get to it soon!


Topics I'm Subscribed To


Topics I've Started


My Latest Replies (From Various Topics)

Viewing 13 replies - 1 through 13 (of 13 total)
Author Replies
Author Replies
Posted: Wednesday May 22nd, 2013 at 10:05 pm #50408
hakata
Username: hakata

Thanks for this. I will see what I can do. So, basically I would just need a very barebones copy of my wordpress installation on the secure subdomain with just the secure checkout pages and the script to update the main installation with the username, name, email, subscription type, etc. Is that right? Is there a way to use the Paypal IPN to handle some of this?

Posted: Wednesday May 22nd, 2013 at 9:51 pm #50405
hakata
Username: hakata

Thanks so much.

Posted: Friday May 10th, 2013 at 4:56 pm #49711
hakata
Username: hakata

Just a quick update on my PCI compliance adventures. Hope this is helpful for others:

1) Hostgator has been extremely helpful with getting everything set up, addressing PCI compliance issues on the server, etc. This is the most cost-effective PCI hosting solution I have found so far. I’ll update if I experience problems in the future, but so far so good.

2) We tried Trust Guard as our scanning vendor, but it took over three days for them to start a scan. In fact, I canceled the service after 3 days, since the scan had not yet run. I was imagining a nightmare scenario where I would have to wait a week or more for every scan, which could translate into months if there were problems/false positives to address. After my issues with Trust Guard, I contacted Trustwave. I couldn’t find a free trial or a cancellation policy, so I contacted their support prior to purchase. Support seemed friendly but would not answer questions about cancellation/free trial. In the end, I tried McAfee, which I thought would be expensive. Turns out there is a 90-day free trial and the cost of just the PCI scanning service is actually quite reasonable. We are still in the trial, so I have not yet paid for the service. I will update if things change. So far, I have been able to run scans on demand. Scans start immediately. They can also be scheduled for future dates and times. Support is friendly and quick. So far, I am very happy with their service.

Posted: Tuesday Apr 30th, 2013 at 7:27 pm #48828
hakata
Username: hakata

Thanks so much for the response. Please also extend my thanks to Jason. The knowledge base article was quite extensive and quite helpful. I am glad to see that I am not the only one who spent his weekend thinking about PCI compliance. I am off to get quotes from Hostgator and Firehost. It is helpful to have the recommendations and to finally have a single, clearly-written explanation of what is required.

As an additional suggestion, it might be worth considering future integration with a service like recur.ly which, as I understand it, could eliminate the need for PCI-compliant hosting.

You guys are the best. I have been pleasantly surprised with the level of integration that S2Member provides and the level of support you offer. Keep up the good work…and thanks again.

Posted: Monday Apr 29th, 2013 at 5:40 pm #48670
hakata
Username: hakata

I know this is a complicated question. For now, could you confirm the following:

1) Does S2Member’s integration with Authorize.net utilize the Direct Post Method?
http://developer.authorize.net/api/howitworks/dpm/

If so, just switching the payment gateway seems to be the easiest (and cheapest) solution.

Posted: Saturday Apr 27th, 2013 at 2:41 pm #48587
hakata
Username: hakata

Thanks, Cristian. I have done a bit more research on this. PCI compliance seems to be the elephant in the room — at least in for small businesses that want to outsource hosting of ecommerce sites.

I found this discussion to be helpful:
http://www.sitepoint.com/forums/showthread.php?807314-Rackspace-Customers-cannot-host-shopping-carts-on-the-cloud

Rackspace CloudSites doesn’t allow the PCI scans.
Godaddy doesn’t either. They are pushing you to their shopping cart or to dedicated hardware: http://support.godaddy.com/groups/web-hosting/forum/topic/pci-compliance/ (The link is a bit old, but I think the situation is still the same.)

I went to FireHost and tried to configure a PCI compliant hosting option on their website, but that resulted in a solution that costs more that $800/month.

Also, regarding Paypal Advanced, on the service main page, the rollover for “Simplify PCI Compliance” says, “With this solution, the only remaining requirements are a greatly simplified Security Self-Assessment Questionnaire (SAQ) and Quarterly Security Scans.” — This does not simplify things at all.

Currently, I am waiting for a quote from Rackspace for a PCI compliant solution. I expect this will be expensive.

I can only assume that most small businesses hosting ecommerce sites are just ignoring this issue, which is causing the major hosts to ignore this issue as well, or push the “honest” small businesses toward expensive solutions.

I did have one small stroke of luck — it appears that Amazon Web Services is PCI Compliant, which means that theoretically, I could host WordPress on EC2 and successfully pass the scans…I think.

Posted: Friday Apr 12th, 2013 at 6:08 pm #47333
hakata
Username: hakata

This is very helpful. I will try moving the files to the main directory and also contact the host. If/when I am able to resolve this, I will post back here.

Thanks so much for your help.

Posted: Friday Apr 12th, 2013 at 4:57 pm #47327
hakata
Username: hakata

Thanks so much. I will leave access enabled until you are finished.

Posted: Friday Apr 12th, 2013 at 3:18 am #47269
hakata
Username: hakata

I’ve tested just about everything I can think of, and the only thing left is the host. I will try a new host and see if the problem goes away. Are you still interested in taking a look, or should I disable credentials? Have you had other problems with the login widget and Rackspace Cloud Sites?

Posted: Thursday Apr 11th, 2013 at 5:32 pm #47230
hakata
Username: hakata

I was reviewing the notes above and thought that “time out” might be a bit unclear. The actual error in Chrome is “Error 324 (net::ERR_EMPTY_RESPONSE): The server closed the connection without sending any data.” Similar error in Safari and Firefox.

We have paused development due to this issue, so any help you can provide would be appreciated.

Posted: Wednesday Apr 10th, 2013 at 7:42 pm #47137
hakata
Username: hakata

Just sent credentials. Please let me know when you have finished so I can disable. Thanks.

Posted: Wednesday Apr 10th, 2013 at 3:20 pm #47109
hakata
Username: hakata

This problem is persisting. Any other suggestions? Anyone else experiencing this?

Posted: Wednesday Apr 10th, 2013 at 3:04 am #47032
hakata
Username: hakata

Thanks for getting back to me. I ran the server scanner earlier today before I contacted support at my host. Everything looked ok except for this:

In order to run s2Member®, your installation of PHP needs one of the following…
• Either the cURL extension for remote communication via PHP (plus the OpenSSL extension for PHP).
• Or, set: allow_url_fopen = on in your php.ini file (and enable the OpenSSL extension for PHP).

The host confirmed that both cURL and allow_url_fopen were enabled.

Viewing 13 replies - 1 through 13 (of 13 total)

Old Forums (READ-ONLY): The community now lives at WP Sharks™. If you have an s2Member® Pro question, please use our new Support System.

Contacting s2Member: Please use our Support Center for bug reports, pre-sale questions & technical assistance.