Section 2 Passwords
The FSC3000
™
(FSC) is designed to meet PA-DSS requirements for support of system access, password
control and configuration. This section provides an overview of these controls.
Password support has been designed to provide the control necessary to manage the system and let the
merchant/site owner meet their needs under PCI DSS compliance. A predefined “
Admin
” user and “
Partial
”
access user are available under a new installation (cold started system). A “
Remote
” access password is
always a requirement when entry through the internal modem or TCP/IP port is made.
IMPORTANT:
Phoenix for Windows users: there is a character limit of 10 total characters for
the Partial Access mode.
and users: there is a character limit of 15 total characters for the Partial Access mode and
Remote Aceess paswords.
Under initial configuration of a cold started FSC, the system has been designed to allow site configuration by
a
Partial
user using the default login (issue “hello” with password of “hello”). To be PCI compliant a card
swipe is not allowed at a fuel island terminal until the default passwords have been changed and the system
has been started.
NOTE:
Pump control testing can be done by issuing the “SET PUMP ON” command.
To start the system it is recommended that the installer have the site owner issue the “SET ADMIN” to modify
the default passwords for
Remote
,
Partial
and
Admin
. If necessary the site owner can then create one of
five (5) additional users for the installer to complete operational tests or provide an employee access to the
system. See below for more information on creating users.
IMPORTANT:
It is required that after the Admin password is changed the site owner should
record it and store it in a safe and secure location.
If the Admin password is lost it
cannot be retrieved from the system and a cold start will be required
.
Below are some basic guidelines for password management. Please refer to your
M030001_PA1 PA-DSS
Implementation Guide
for additional information:
1. Change Partial, Remote and user passwords every 90 days (Admin password will be forced to change
every 90-days).
2. When changing passwords, the new password should not be the same as any of the previous four (4).
3. Passwords for Admin, Partial, Remote and users should always be unique.
IMPORTANT:
If the User or Admin passwords are entered incorrectly six (6) consecutive
times, the User or Admin will be suspended for 30 minutes before another login attempt is
allowed. If the Admin is not locked out, the Admin can reset the User password with the “SET
ADMIN” command.
Doc. No.: M00-051.00 Rev.: 10
Page 17 of 181
Summary of Contents for M00-051.00 FSC3000
Page 60: ...Doc No M00 051 00 Rev 10 Page 60 of 181...
Page 63: ...Doc No M00 051 00 Rev 10 Page 63 of 181...
Page 69: ...Doc No M00 051 00 Rev 10 Page 69 of 181...
Page 99: ...Doc No M00 051 00 Rev 10 Page 99 of 181...
Page 129: ...Petrol Training Screens Doc No M00 051 00 Rev 10 Page 129 of 181...
Page 130: ...CNG Training Screens Doc No M00 051 00 Rev 10 Page 130 of 181...
Page 181: ......