Concern for storage of payment gateway key

From: Bryon Bean (bryon_bean_at_msn.com)
Date: 07/21/04

  • Next message: Todd Knarr: "Re: Concern for storage of payment gateway key"
    Date: Wed, 21 Jul 2004 14:35:24 -0700
    
    

    Hi,

    I'm 'a lot' confused as to how I should store a payment gateway key
    (password, essentially) on a server that requires a perl script to access
    that key. The recommendations by the payment gateway are sparse at best
    (though they do recommend that the key be stored on a server other than that
    on which the script/app resides). The script is run with nobody-like
    permissions as it is a CGI script so the key must be readable by this
    nobody-like user. My confusion is this; even if the file sits encrypted on
    another server, the passphrase to decrypt the file, and the login access to
    another server must still reside in the perl script that requires the key
    information. Can someone please give me a clue about best practices (and
    maybe why) or at least point me to some documentation on the subject of
    storing documents securely that need access from un-compiled scripts (maybe
    that's a stretch!)?. TIA!

    Cheers,
    Bryon Bean
    ________________________________________
    In heaven all the interesting people are missing.
      --Friedrich Nietzsche


  • Next message: Todd Knarr: "Re: Concern for storage of payment gateway key"

    Relevant Pages

    • Re: Same Internal Server Error from last two days
      ... I am trying to run a Hello World Perl Script in Apache 2.2. ... But its constantly giving me Internal Server Error.The script ... # have to place corresponding `LoadModule' lines at this location so the ...
      (perl.beginners)
    • Re: Same Internal Server Error from last two days
      ... I am trying to run a Hello World Perl Script in Apache 2.2. ... But its constantly giving me Internal Server Error.The script Runs perfectly fine from the command prompt. ... # This is the main Apache HTTP server configuration file. ... LoadModule actions_module modules/mod_actions.so ...
      (perl.beginners)
    • Same Internal Server Error from last two days
      ... I am trying to run a Hello World Perl Script in Apache 2.2. ... But its constantly giving me Internal Server Error.The script ... # have to place corresponding `LoadModule' lines at this location so the ...
      (perl.beginners)
    • Re: Regarding a selection for mobile code/scripting language
      ... Client Side scripting, so the server can send script commands to the client. ... I decided they should be scripted and mobile code. ...
      (Vuln-Dev)
    • Re: FYI: Fetchmail saves the day!
      ... > Here is a Perl script I just wrote. ... > headers). ... The POP3 server must support the TOP command. ... I would promise to post the script in a public place after testing, ...
      (comp.os.linux.misc)