PayPal SSL cert update

22 views
Skip to first unread message

Paul Kim

unread,
Sep 26, 2009, 10:27:58 AM9/26/09
to potion...@googlegroups.com
I was a bit surprised to wake up this morning with a ton of
PotionStore errors: "certificate verify failed"

After some poking around, I came across this: https://ppmts.custhelp.com/cgi-bin/ppdts.cfg/php/enduser/popup_adp.php?p_faqid=800&p_created=1244653674

In short, PayPal renewed their certs and it requires an update to your
root certs. If you follow the instructions, it should lead you to
downloading this file: https://cms.paypal.com/cms_content/US/en_US/files/developer/PP_PHP_SOAP_SDK.tar.gz

After unpacking, grab lib/PayPal/cert/api_cert_chain.crt and stick it
in the certs directory of your PotionStore install.

Did a couple tests and that seems to fix it.

Did I miss some announcement about this anywhere? Is there some way to
mitigate this type of problem in the future?

paul

Paul Kim

unread,
Sep 26, 2009, 10:55:21 AM9/26/09
to potion...@googlegroups.com
Minor correction:

Put the new cert file in your config/certs directory (there should be
a version of the file already there so that should be a clue that it's
the right place).


John McLaughlin

unread,
Sep 26, 2009, 11:39:03 AM9/26/09
to Potion Store Discussions
Hey Paul,


Thanks so much -- Last night I started getting emails about failed
orders (it was very late, I was tired and I figured it was a one up
problem) -- Woke up this morning to tons of errors -- Found this post,
followed the instructions and it's all good now

Again, thanks so much.

-John

Chad Sellers

unread,
Sep 26, 2009, 11:39:36 AM9/26/09
to potion...@googlegroups.com

Wow, thanks for catching that. I didn't see any sort of announcement
about this either.

Thanks,
Chad

Chad Sellers
Useful Fruit Software
http://www.usefulfruit.com/

Paul Kim

unread,
Sep 26, 2009, 11:49:07 AM9/26/09
to potion...@googlegroups.com
It seems that PayPal has a live status blog: http://www.paypaldeveloper.com/t5/Live-Site-Status/bg-p/mts_updates
(thanks to Daniel Jalkut for pointing it out to me)

It did mention this a few days ago: http://developer.paypal-portal.com/t5/Live-Site-Status/SSL-Certificate-renewal-for-API-endpoints/ba-p/154667

So, it might be a good idea to subscribe to the RSS feed for this type
of thing.

Andy, I assume you'll update the cert in the repo?

paul

Andy Kim

unread,
Sep 26, 2009, 6:28:42 PM9/26/09
to potion...@googlegroups.com
Hey Paul,

Thanks for catching this and making my life easier this morning. I'm
surprised that they made this move without emailing any of us.

The certificate has been updated at the GitHub project.

- Andy Kim
Reply all
Reply to author
Forward
0 new messages