Report this

What is the reason for this report?

PCI Compliance on Ecommerce Site

Posted on January 21, 2014

Hi All,

My server is ubuntu 12.04 and i am running e-commerce site. When i run PCI Compliances test on my server it will got some warning or vulnerability on server.

I have attached screenshot for that.

Can you please let me know what i have to do?

Thanks, Tejas



This textbox defaults to using Markdown to format your answer.

You can type !ref in this text area to quickly search our full set of tutorials, documentation & marketplace offerings and insert the link!

These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.

You might be better off having a 3rd party handle your payments. Someone like Stripe and Mijreh are cheap and are already PCI compliant. You don’t then have to worry about building that infrastructure.

Hello there,

I’ll also recommend letting a 3rd party handle your payments. If you decide to give it a go and handle payments on your droplet you’ll need to tweak the server configuration.

Most PCI vendors will scan the server and will ask you to close insecure ports, update security cyphers of TLS/SSL, disable plain-text authentication, update the OpenSSH version and so on.

Hope that this helps!

The developer cloud

Scale up as you grow — whether you're running one virtual machine or ten thousand.

Get started for free

Sign up and get $200 in credit for your first 60 days with DigitalOcean.*

*This promotional offer applies to new accounts only.