Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

signature in coldfusion

Posted on 2009-04-06
7
Medium Priority
?
382 Views
Last Modified: 2013-12-24
I'm trying to do a connectivity test to a third party company called Pacnet (payment processing company).  They're requiring I pass to them a signature.  I'm trying to do this in coldfusion using a test page..

however, I get:

authenticationFailed
This server could not process your request because: Authentication failed due to incorrect user name, password, or signature.

My question is does the hash of the string look correct as well as the utc time?
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN">
<html>
<head>
<title>Testing Connectivity to Raven</title>
</head>
<body>
<h2>Testing Connectivity to Raven</h2>
<cfset curDate = Now()>
<cfset utcDate = DateConvert("local2utc", curDate)>
<cfoutput>
<cfset utctime="#DatePart('yyyy', utcDate)#-0#DatePart('m', utcDate)#-0#DatePart('d', utcDate)#T#DatePart('h', utcDate)#:#DatePart('n', utcDate)#:#DatePart('s', utcDate)#Z"><br />
current utc date and time: #utctime#<br /><br />
<cfset hash1 ="#Hash('artis,#utctime#', 'MD5')#">
<cfset hash2 ="#Hash('#hash1#,baseball', 'MD5')#">
</cfoutput> 
<form method="post" action="https://raven.pacnetservices.com/realtime/hello">
<input type="text" name="UserName" value="artis" size="100"><br />
<input type="text" name="Timestamp" value="<cfoutput>#utctime#</cfoutput>" size="100"><br />
<input type="text" name="Signature" value="<cfoutput>#hash2#</cfoutput>" size="100">
<br /><br />
<input type="submit" value="Get Response">
</form>
</body>
</html>

Open in new window

0
Comment
Question by:COwebmaster
  • 4
  • 3
7 Comments
 
LVL 16

Expert Comment

by:duncancumming
ID: 24079543
Seems like a convoluted method for the hash they require.  

You take a string "artis,#utctime#", then hash it.  
Then you take that hashed string, append ",baseball" to it and hash it again.  
Not sure the value of double-hashing something.  

You got a link to any Pacnet API documentation?

Anyway... another thing you can do is use <cfhttp> to post your form to their server, rather than create a normal form that you manually submit.  You probably know that, I guess you're just using a normal form to test what the values look like.  




0
 

Author Comment

by:COwebmaster
ID: 24097550
Ok, so I'm passing parameters to the server.  Now, how can I return the response?
<cfset curDate = Now()>
<cfset utcDate = DateConvert("local2utc", curDate)>
<cfoutput>
<cfset utctime="#DatePart('yyyy', utcDate)#-#DatePart('m', utcDate)#-#DatePart('d', utcDate)#T#DatePart('h', utcDate)#:#DatePart('n', utcDate)#:#DatePart('s', utcDate)#Z"><br />
current utc date/time: #utctime#<br /><br />
<cfset hash1 ="#Hash('artis,#utctime#', 'MD5')#">
<cfset hash2 ="#Hash('#hash1#,[hidden]', 'MD5')#">
</cfoutput> 
 
<cfparam name="attributes.UserName" default="artis">
<cfparam name="attributes.Amount" default="1">
<cfparam name="attributes.CurrencyCode" default="USD">
<cfparam name="attributes.Timestamp" default="<cfoutput>#utctime#</cfoutput>">
<cfparam name="attributes.Signature" default="<cfoutput>#hash2#</cfoutput>">
<cfparam name="attributes.PaymentType" default="cc_debit">
<cfparam name="attributes.PaymentRoutingNumber" default="[hidden]">
<CFPARAM NAME="attributes.CardNumber" DEFAULT="[hidden]">
<cfparam name="attributes.ExpiryDate" DEFAULT="0510">
<cfparam name="attributes.CVV" default="123">
<cfparam name="attributes.Reference" DEFAULT="12345">
 
<cfhttp url="https://raven.pacnetservices.com/realtime" method="POST">
	
	<cfhttpparam type="FORMFIELD" name="UserName" value="#attributes.UserName#">
	<cfhttpparam type="FORMFIELD" name="Amount" value="#attributes.Amount#">
	<cfhttpparam type="FORMFIELD" name="CurrencyCode" value="#attributes.CurrencyCode#">
	<cfhttpparam type="FORMFIELD" name="Timestamp" value="#attributes.Timestamp#">
	<cfhttpparam type="FORMFIELD" name="Signature" value="#attributes.Signature#">
	<cfhttpparam type="FORMFIELD" name="PaymentType" value="#attributes.PaymentType#">
	<cfhttpparam type="FORMFIELD" name="PaymentRoutingNumber" value="#attributes.PaymentRoutingNumber#">
	<cfhttpparam type="FORMFIELD" name="CardNumber" value="#attributes.CardNumber#">
	<cfhttpparam type="FORMFIELD" name="ExpiryDate" value="#attributes.ExpiryDate#">
	<cfhttpparam type="FORMFIELD" name="CVV" value="#attributes.CVV#">
	<cfhttpparam type="FORMFIELD" name="Reference" value="#attributes.Reference#">
	
</CFHTTP>

Open in new window

0
 
LVL 16

Expert Comment

by:duncancumming
ID: 24110306
#CFHTTP.FileContent#




0
Important Lessons on Recovering from Petya

In their most recent webinar, Skyport Systems explores ways to isolate and protect critical databases to keep the core of your company safe from harm.

 

Author Comment

by:COwebmaster
ID: 24111211
yea, i tried that and get nothing back, just a white screen.
0
 

Author Comment

by:COwebmaster
ID: 24111245
does this look right..


<cfset curDate = Now()>
<cfset utcDate = DateConvert("local2utc", curDate)>
<cfoutput>
<cfset utctime="#DatePart('yyyy', utcDate)#-#DatePart('m', utcDate)#-#DatePart('d', utcDate)#T#DatePart('h', utcDate)#:#DatePart('n', utcDate)#:#DatePart('s', utcDate)#Z"><br />
current utc date/time: #utctime#<br /><br />
<cfset hash1 ="#Hash('artis,#utctime#', 'MD5')#">
<cfset hash2 ="#Hash('#hash1#,[hidden]', 'MD5')#">
</cfoutput> 
 
<cfparam name="attributes.UserName" default="artis">
<cfparam name="attributes.Amount" default="1">
<cfparam name="attributes.CurrencyCode" default="USD">
<cfparam name="attributes.Timestamp" default="<cfoutput>#utctime#</cfoutput>">
<cfparam name="attributes.Signature" default="<cfoutput>#hash2#</cfoutput>">
<cfparam name="attributes.PaymentType" default="cc_debit">
<cfparam name="attributes.PaymentRoutingNumber" default="[hidden]">
<CFPARAM NAME="attributes.CardNumber" DEFAULT="[hidden]">
<cfparam name="attributes.ExpiryDate" DEFAULT="0510">
<cfparam name="attributes.CVV" default="123">
<cfparam name="attributes.Reference" DEFAULT="12345">
 
	<cfhttp url="https://raven.pacnetservices.com/realtime" method="POST">
	
	<cfhttpparam type="FORMFIELD" name="UserName" value="#attributes.UserName#">
	<cfhttpparam type="FORMFIELD" name="Amount" value="#attributes.Amount#">
	<cfhttpparam type="FORMFIELD" name="CurrencyCode" value="#attributes.CurrencyCode#">
	<cfhttpparam type="FORMFIELD" name="Timestamp" value="#attributes.Timestamp#">
	<cfhttpparam type="FORMFIELD" name="Signature" value="#attributes.Signature#">
	<cfhttpparam type="FORMFIELD" name="PaymentType" value="#attributes.PaymentType#">
	<cfhttpparam type="FORMFIELD" name="PaymentRoutingNumber" value="#attributes.PaymentRoutingNumber#">
	<cfhttpparam type="FORMFIELD" name="CardNumber" value="#attributes.CardNumber#">
	<cfhttpparam type="FORMFIELD" name="ExpiryDate" value="#attributes.ExpiryDate#">
	<cfhttpparam type="FORMFIELD" name="CVV" value="#attributes.CVV#">
	<cfhttpparam type="FORMFIELD" name="Reference" value="#attributes.Reference#">
	
</CFHTTP>

Open in new window

0
 
LVL 16

Accepted Solution

by:
duncancumming earned 2000 total points
ID: 24113860
well it seems to, but it depends what the pacnet page is expecting.  

try doing <cfdump var="#cfhttp#"> and see what the headers are.

lines like this:
<cfparam name="attributes.Timestamp" default="<cfoutput>#utctime#</cfoutput>">
you don't need the cfoutput, just do
<cfparam name="attributes.Timestamp" default="#utctime#">

I'm still confused about the requirement for double hashing.
0
 

Author Comment

by:COwebmaster
ID: 24154187
Thanks, that worked.
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A web service (http://en.wikipedia.org/wiki/Web_service) is a software related technology that facilitates machine-to-machine interaction over a network. This article helps beginners in creating and consuming a web service using the ColdFusion Ma…
If you don't have the right permissions set for your WordPress location in IIS, you won't be able to perform automatic updates. Here's how to fix the problem.
In response to a need for security and privacy, and to continue fostering an environment members can turn to for support, solutions, and education, Experts Exchange has created anonymous question capabilities. This new feature is available to our Pr…
Look below the covers at a subform control , and the form that is inside it. Explore properties and see how easy it is to aggregate, get statistics, and synchronize results for your data. A Microsoft Access subform is used to show relevant calcul…

876 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question