- 1.0.1 doesn't tell anything without the letter behind it. Latest is version 1.0.1u.
- that still doesn't tell anything since most Linux distributions backport important security fixes
- then of course your hoster needs to make correct https configurations which corresponds to latest security standards, or to at least what Paypal expects.
- encrypting the form's hidden fields doesn't bring any additional security, only a tiny bit of privacy as it doesn't expose account id or email until payment is completed, so you could try to disable it.
- but I believe that most probable cause is your hoster's openssl settings for https that are not secure and thus do not correspond to paypal's new minimal requirements.