<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Production Certificate Upgrades begin May 26, 2015 in Integration and Testing</title>
    <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50904#M26313</link>
    <description>&lt;P&gt;Windows Server 2012 R2 Standard&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our client dropped the ball and didn't tell us about this until the day after it was implemented. Their payments have been broken for 48 hours and this is now critical:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Searching by SHA hash in the cert store on the server, I found 2/5 of the required certs already installed -- the Entrust certs still needed to be installed:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Entrust:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Entrust.net Secure Server Certification Authority 99A6 9BE6 1AFE 886B 4D2B 8200 7CB8 54FC 317E 1539&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Not installed&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Entrust.net Certification Authority (2048) 5030 0609 1D97 D4F5 AE39 F7CB E792 7D7D 652D 3431&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Not installed&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Entrust Root Certification Authority B31E B1B7 40E3 6C84 02DA DC37 D44D F5D4 6749 52F9&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Not installed&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;CyberTrust:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Baltimore CyberTrust Root D4DE 20D0 5E66 FC53 FE1A 5088 2C78 DB28 52CA E474&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Installed present in both&amp;nbsp;Trusted Root Certification Authorities and Third-Party Root Certification Authorities&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Both expire 2025&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;GeoTrust:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;GeoTrust Global CA DE28 F4A4 FFE5 B92F A3C5 03D1 A349 A7F9 962A 8212&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Installed &lt;SPAN&gt;present in both&amp;nbsp;&lt;/SPAN&gt;Trusted Root Certification Authorities and Third-Party Root Certification Authorities&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Both expire 2022&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;_______&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I DLed and installed all 3 Entrust certs and have tried installing them into both the Intermediate Cert Auth store as well as the Third Party Root Cert Store via the cert util in MMC. Payments still broken per the client and the certs are not showing up in the cert chain via SSLChecker.com or the DigiCert chain check util.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I then moved to focus on the suggested chain certs which may be needed "if explicitly requested by your developer."&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;Verizon Akamai SureServer CA G14-SHA2 Baltimore CyberTrust Root 6AD2 B04E 2196 E48B F685 7528 90E8 11CD 2ED6 0606&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Entrust Certification Authority – L1K Entrust Inc CCA2 7D33 C735 A7D0 6D1F ECAD 980E 498D A681 C963&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Entrust Root Certification Authority – G2 Entrust Inc 8CF4 27FD 790C 3AD1 6606 8DE8 1E57 EFBB 9322 72D4&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;GeoTrust SSL CA - G4 GeoTrust Global CA, GeoTrust Inc DE28 F4A4 FFE5 B92F A3C5 03D1 A349 A7F9 962A 8212&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The final chain cert, GeoTrust SSL CA is already installed in Third Party Root Cert store in MMC and is therefore also present in Trusted Root Cert store. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I've located the other 3 certs just googling them (Verizon, Entrust L1K, and Entrust Root G2) and installed them into the&amp;nbsp;Third Party Root store. They still did not&amp;nbsp;show&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;up in the cert chains. I removed them from that store and installed them in the Intermediate Cert Auth store. Still not showing up in the chain via Digicert or SSLChecker.com. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Ran IISRESET.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Still not showing up in the chains via Digicert or SSLChecker.com.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What in the world needs to be done to get these certs configured correctly? This is awful and urgent.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 29 May 2015 17:50:07 GMT</pubDate>
    <dc:creator>certparty</dc:creator>
    <dc:date>2015-05-29T17:50:07Z</dc:date>
    <item>
      <title>Production Certificate Upgrades begin May 26, 2015</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50438#M25886</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Authorize.Net will upgrade and replace Production certificates for API services starting May 26, 2015. Technical details are provided for solutions connecting to Authorize.Net APIs that may need updates.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;To see the full announcement, please see this &lt;A href="https://community.developer.cybersource.com/t5/The-Authorize-Net-Developer-Blog/Production-Certificate-Upgrades-begin-May-26-2015/ba-p/50430" target="_self"&gt;blog post&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2015 20:05:54 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50438#M25886</guid>
      <dc:creator>RichardH</dc:creator>
      <dc:date>2015-04-24T20:05:54Z</dc:date>
    </item>
    <item>
      <title>Re: Production Certificate Upgrades begin May 26, 2015</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50445#M25892</link>
      <description>&lt;P&gt;Our lower environment stopped working when calling apitest.authorize.net.&amp;nbsp; While investigating I was informed that the Sandbox Environment moved to Dyanmic IP addresses.&amp;nbsp; ( 23.x.x.x)&amp;nbsp; My server is behind a firewall and the Secuirty Team is not comfortable approving PCI requests to any destination on the public net.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have plans to move Production Environment to use Dynamic IP addresses as well?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you, Dave51&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2015 20:01:34 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50445#M25892</guid>
      <dc:creator>Dave51</dc:creator>
      <dc:date>2015-04-27T20:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: Production Certificate Upgrades begin May 26, 2015</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50446#M25893</link>
      <description>&lt;P&gt;&lt;A href="http://community.developer.authorize.net/t5/The-Authorize-Net-Developer-Blog/Authorize-Net-Begins-Infrastructure-and-SHA-2-Certificate/ba-p/49615" target="_blank"&gt;http://community.developer.authorize.net/t5/The-Authorize-Net-Developer-Blog/Authorize-Net-Begins-Infrastructure-and-SHA-2-Certificate/ba-p/49615&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Yup it will go into production too.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2015 20:04:14 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50446#M25893</guid>
      <dc:creator>RaynorC1emen7</dc:creator>
      <dc:date>2015-04-27T20:04:14Z</dc:date>
    </item>
    <item>
      <title>Re: Production Certificate Upgrades begin May 26, 2015</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50447#M25894</link>
      <description>&lt;P&gt;Richard,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In &lt;A href="https://community.developer.cybersource.com/t5/The-Authorize-Net-Developer-Blog/Production-Certificate-Upgrades-begin-May-26-2015/ba-p/50430" target="_self"&gt;this post&lt;/A&gt;, you mentioned we need &lt;STRONG&gt;3&lt;/STRONG&gt; certs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, you only mention &lt;STRONG&gt;one&lt;/STRONG&gt;&amp;nbsp;cert in&amp;nbsp;&lt;A href="https://community.developer.cybersource.com/t5/The-Authorize-Net-Developer-Blog/Authorize-Net-Begins-Infrastructure-and-SHA-2-Certificate/ba-p/49615" target="_self"&gt;this other post&lt;/A&gt;&amp;nbsp;(&lt;SPAN&gt;Root 2 - GeoTrust Global CA).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;We tested transactions with the test/sandbox API and it works on our production servers (becuase we have&amp;nbsp;&lt;SPAN&gt;Root 2 - GeoTrust Global CA installed). Is there anything else we will need?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2015 21:06:34 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50447#M25894</guid>
      <dc:creator>kotowick</dc:creator>
      <dc:date>2015-04-27T21:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: Production Certificate Upgrades begin May 26, 2015</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50460#M25907</link>
      <description>&lt;P&gt;We recommend everyone install all four certificates mentioned in our &lt;A href="https://community.developer.cybersource.com/t5/The-Authorize-Net-Developer-Blog/Production-Certificate-Upgrades-begin-May-26-2015/ba-p/50430" target="_self"&gt;blog post&lt;/A&gt;, for minimal disruption, whether in Sandbox or Production:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN style="line-height: 16px;"&gt;Verizon Akamai SureServer CA G14-SHA2&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="line-height: 16px;"&gt;Entrust Certification Authority – L1K&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="line-height: 16px;"&gt;Entrust Root Certification Authority – G2&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="line-height: 16px;"&gt;GeoTrust SSL CA - G4&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN style="line-height: 16px;"&gt;Richard&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 17:09:30 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50460#M25907</guid>
      <dc:creator>RichardH</dc:creator>
      <dc:date>2015-04-28T17:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: Production Certificate Upgrades begin May 26, 2015</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50461#M25908</link>
      <description>&lt;P&gt;I have just confirmed with my Network team that the firewall solution we use only allows IP.&amp;nbsp; I can't create a rule by domain or URL.&amp;nbsp;Do you have a white paper that&amp;nbsp;I can bring to my internal teams ( Network and Security) to find a work around before Dynamic IP is actived in Produciton?&lt;/P&gt;&lt;P&gt;Thank you, Dave51&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 17:26:18 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50461#M25908</guid>
      <dc:creator>Dave51</dc:creator>
      <dc:date>2015-04-28T17:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: Production Certificate Upgrades begin May 26, 2015</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50464#M25911</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/18272"&gt;@Dave51&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A good reference is &lt;A href="http://blog.algosec.com/2014/09/avoid-traps-need-know-pci-requirement-1-part-3.html" target="_self"&gt;this article by Matthew Pascucci of Algosec&lt;/A&gt;.&amp;nbsp; In it he emphasizes using a DMZ on the perimeter to control inbound traffic (PCI 1.3.1) and controlling access between your internal systems and the DMZ to control unauthorized outbound traffic to the internet (PCI 1.3.5).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Richard&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 20:36:08 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50464#M25911</guid>
      <dc:creator>RichardH</dc:creator>
      <dc:date>2015-04-28T20:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: Production Certificate Upgrades begin May 26, 2015</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50470#M25917</link>
      <description>&lt;P&gt;RichardH,&lt;/P&gt;&lt;P&gt;&amp;nbsp;Appreciate the article. My server does sit in a DMZ zone between two firewalls. Will need to have a chat with my Network team.&lt;/P&gt;&lt;P&gt;Thank you, Dave51&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2015 12:19:02 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50470#M25917</guid>
      <dc:creator>Dave51</dc:creator>
      <dc:date>2015-04-29T12:19:02Z</dc:date>
    </item>
    <item>
      <title>Re: Production Certificate Upgrades begin May 26, 2015</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50494#M25934</link>
      <description>&lt;P&gt;Update: My Security Team has some concerns on this statement in the article. " Direct connections via IP address are strongly discouraged and will soon be disallowed."&amp;nbsp;&amp;nbsp; They site these reason for their concern and are asking why this direction was chosen.&lt;/P&gt;&lt;P&gt;* Changing to dynamic IP range without any identification of potential scope poses a significant security risk to our data as we cannot acertain with significant reliability our data is going to the correct destination.&lt;/P&gt;&lt;P&gt;* Authorization based on DNS lookup is insecure as these are easily spoofed.&lt;/P&gt;&lt;P&gt;* Is Authorize.net performing any ingress filtering from their customers?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you, Dave51&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2015 14:54:51 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50494#M25934</guid>
      <dc:creator>Dave51</dc:creator>
      <dc:date>2015-04-30T14:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: Production Certificate Upgrades begin May 26, 2015</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50495#M25935</link>
      <description>&lt;P&gt;Is there any change for TLS support ? specifically, will TLS 1.0 still be supported ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2015 14:57:43 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50495#M25935</guid>
      <dc:creator>Christophe</dc:creator>
      <dc:date>2015-04-30T14:57:43Z</dc:date>
    </item>
    <item>
      <title>Re: Production Certificate Upgrades begin May 26, 2015</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50497#M25937</link>
      <description>&lt;P&gt;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/13401"&gt;@Christophe&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We're not removing TLS 1.0 at this time, but merchants are always encouraged to support the strongest protocols possible which is currently TLS 1.2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Richard&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2015 15:25:18 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50497#M25937</guid>
      <dc:creator>RichardH</dc:creator>
      <dc:date>2015-04-30T15:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: Production Certificate Upgrades begin May 26, 2015</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50498#M25938</link>
      <description>&lt;P&gt;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/18272"&gt;@Dave51&lt;/a&gt;, can't you spoof IP addresses as well? In which case, direct IP address connections don't automatically provide more security, and in fact can defeat security since you have to disable TLS domain verification to connect.&lt;BR /&gt;&lt;BR /&gt;We don't whitelist merchant IP connections. We do expect merchants to connect to our API endpoints by domain name and fully utilize TLS to secure the connection, however.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2015 15:46:46 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50498#M25938</guid>
      <dc:creator>Lilith</dc:creator>
      <dc:date>2015-04-30T15:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: Production Certificate Upgrades begin May 26, 2015</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50590#M26023</link>
      <description>&lt;P&gt;I just tested with test.authorize.net instead of secure.authorize.net and had no problems. Using Java 7 but didn't install any of the new certificates. Is test.authorize.net already enforcing&amp;nbsp;SHA-2 or do I have to create a sandbox account?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 May 2015 18:45:01 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50590#M26023</guid>
      <dc:creator>tpeierls</dc:creator>
      <dc:date>2015-05-07T18:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: Production Certificate Upgrades begin May 26, 2015</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50654#M26072</link>
      <description>&lt;P&gt;My company has some security limitations regarding dynamic IPs and domain connections, &lt;SPAN&gt;does anybody know when this&amp;nbsp;i&lt;/SPAN&gt;&lt;SPAN&gt;nfrastruc&lt;/SPAN&gt;&lt;SPAN&gt;ture update is going to be implemented on production environment?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2015 14:06:37 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50654#M26072</guid>
      <dc:creator>flinacio</dc:creator>
      <dc:date>2015-05-14T14:06:37Z</dc:date>
    </item>
    <item>
      <title>Re: Production Certificate Upgrades begin May 26, 2015</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50663#M26081</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/18342"&gt;@flinacio&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are still waiting for the schedule for production. &amp;nbsp;We will publish the information here as soon as possible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Richard&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2015 19:59:01 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50663#M26081</guid>
      <dc:creator>RichardH</dc:creator>
      <dc:date>2015-05-14T19:59:01Z</dc:date>
    </item>
    <item>
      <title>Re: Production Certificate Upgrades begin May 26, 2015</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50664#M26082</link>
      <description>&lt;P&gt;This Just In!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our production release will occur around the first part of August. &amp;nbsp;More details will be available in the next week or two and will be posted here in the community as well as through email to merchants, partners and developers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Richard&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2015 20:38:32 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50664#M26082</guid>
      <dc:creator>RichardH</dc:creator>
      <dc:date>2015-05-14T20:38:32Z</dc:date>
    </item>
    <item>
      <title>Re: Production Certificate Upgrades begin May 26, 2015</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50666#M26083</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will you please explain how can I know if I need to do anything about this? What are the use cases where I would need to do something?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a website with a secure certificate installed that connects to Authorize.net. Is this a use case where I would need to check and or do something?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please be specific as I'm new to ssl. Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 15 May 2015 00:02:47 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50666#M26083</guid>
      <dc:creator>Msimpson</dc:creator>
      <dc:date>2015-05-15T00:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: Production Certificate Upgrades begin May 26, 2015</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50673#M26089</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We use the simple SIM (XML based) method to POST transactions to Authorize.net.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do these certificate changes affect us or people like us?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this specific only to people using AIM?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 15 May 2015 15:17:38 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50673#M26089</guid>
      <dc:creator>icarroll</dc:creator>
      <dc:date>2015-05-15T15:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: Production Certificate Upgrades begin May 26, 2015</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50674#M26090</link>
      <description>&lt;P&gt;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/18349"&gt;@Msimpson&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The upgrades applies to all API endpoints your application may be using with HTTPS at Authorize.Net.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/18351"&gt;@icarroll&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The impact for SIM is low since it is browser-driven and they already support these changes. &amp;nbsp;If your implementation also connects using the Authorize.Net API (AIM), you will of course need to support these changes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Richard&lt;/P&gt;</description>
      <pubDate>Fri, 15 May 2015 15:34:52 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50674#M26090</guid>
      <dc:creator>RichardH</dc:creator>
      <dc:date>2015-05-15T15:34:52Z</dc:date>
    </item>
    <item>
      <title>Re: Production Certificate Upgrades begin May 26, 2015</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50675#M26091</link>
      <description>&lt;P&gt;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/18313"&gt;@tpeierls&lt;/a&gt;&amp;nbsp;Sorry for not responding sooner.&lt;BR /&gt;&lt;BR /&gt;SHA-2 is a hash used to sign certificates (among other things) so it's not a matter of whether we're enforcing it, but whether your software will be able to use SHA-2 to validate our certificate's signature. SHA-2 has been around for over a decade at this point, so really we're concerned about legacy software here.&lt;BR /&gt;&lt;BR /&gt;The certs on test.authorize.net and the rest of our Sandbox environment are currently signed using SHA-2. If your software can connect to test.authorize.net right now, you should be good on that front.&lt;BR /&gt;&lt;BR /&gt;In August there will be other certificates your software will need to validate, also signed using SHA-2. And test.authorize.net should have that in place as well.&lt;/P&gt;</description>
      <pubDate>Fri, 15 May 2015 15:43:16 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Production-Certificate-Upgrades-begin-May-26-2015/m-p/50675#M26091</guid>
      <dc:creator>Lilith</dc:creator>
      <dc:date>2015-05-15T15:43:16Z</dc:date>
    </item>
  </channel>
</rss>

