Solved

https encryption and certificate

Posted on 2007-03-30
4
164 Views
Last Modified: 2008-02-01
On a jsp paysite, I have checked that the site using running SSL as it's https and I have checked the certificate information, is there anything else I can check security wise before makign a payment, I'm talking what I can test from the jsp site itself.
0
Comment
Question by:pma111
  • 2
  • 2
4 Comments
 
LVL 30

Expert Comment

by:Mayank S
ID: 18825731
Sounds good. Are you going to ask the user for credit card information?
0
 
LVL 3

Author Comment

by:pma111
ID: 18834765
Yeah it does pass such information, or once it goes live it will.
0
 
LVL 3

Author Comment

by:pma111
ID: 18939507
I cant really accept mayankeagle answer as a solution, I was hoping for a bit more info on what could be initially tested....
0
 
LVL 30

Accepted Solution

by:
Mayank S earned 250 total points
ID: 19047217
From a security standpoint, you look good. Make sure that you do not store the credit card number. You can store username/ password in an encrypted format (use one-way hashing for the password). Also make sure you use some clustering/ fault tolerant architecture to ensure your system is highly available. There isn't really much info in your question, so I'm not sure what server you are using. Here is a guide on Tomcat clustering:

http://tomcat.apache.org/tomcat-5.5-doc/cluster-howto.html
0

Featured Post

Master Your Team's Linux and Cloud Stack

Come see why top tech companies like Mailchimp and Media Temple use Linux Academy to build their employee training programs.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Apache server configuration 7 85
how to exclude a file using regex 5 118
Is it possible to "sandbox" html content within a JSP? 4 101
java operators 3 116
An article on effective troubleshooting
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question