I have a VPS with linode, great hosting by the way.
I am confident with centos apache ect but I know nothing about PCI DSS compliance, I usually let SagePay or PayPal deal with it.
But I have a client that is interested in not having customers go off to another website and dealing with the card details on there own website.
I have looked into it and it seems I need the following(plz correct if wrong):
- Another IP address separate for the SSL certificate for the https://
- The SSL certificate, which can be self signed with linux commands
- Be PCI DSS compliant
Its the PCI DSS compliant thats confusing, reading on the website it seems that you can just fill out a form, perform penetration testing yourself and adhere to the PCI DSS standards they set. You do not actually need to pay to have your server scanned by an external company to ensure you are PCI DSS compliant you can do it all yourself?
If so great lol as I dont really want to be paying out to be PCI DSS compliant, but are there any free software scans or common security holes to check?
Physical access to the server hardware should be restricted but you don't need to control that yourself necessarily. You just need it to be adequately secured. That is why some of the big clouds can advertise the fact that they are able to offer PCI-DSS compliant hosting.
– al45tair Mar 07 '21 at 07:30