payShield 10K Installation and User Guide
©Thales Group
Page 235
All Rights Reserved
Example 1:
Settings affecting PCI HSM compliance do not all have compliant values
Online>
QS
<Return>
PIN length: 04
Encrypted PIN length: 05
Echo: OFF
Atalla ZMK variant support: OFF
Transaction key support: NONE
User storage key length: SINGLE
Display general information on payShield Manager Landing Page:
NO
Default LMK identifier: 00
Management LMK identifier: 00
Select clear PINs: NO
Enable ZMK translate command: NO
Enable X9.17 for import: NO
Enable X9.17 for export: NO
Solicitation batch size: 1024
ZMK length: DOUBLE
Decimalization tables: ENCRYPTED
Decimalization table checks: ENABLED
PIN encryption algorithm: A
Press "Enter" to view additional security settings...
<Return>
Authorized state required when importing DES key under RSA key:
YES
Minimum HMAC length in bytes: 10
Enable PKCS#11 import and export for HMAC keys: NO
Enable ANSI X9.17 import and export for HMAC keys: NO
Enable ZEK/TEK encryption of ASCII data or Binary data or None:
NONE
Restrict key check values to 6 hex chars: YES
Enable multiple authorized activities: YES
Allow persistent authorized activities: NO
Enable variable length PIN offset: NO
Enable weak PIN checking: NO
Enable PIN block Format 34 as output format for PIN
translations to ZPK: NO
Enable translation of account number for LMK encrypted PINs: NO
Use HSM clock for date/time validation: YES
Additional padding to disguise key length: NO
Key export and import in trusted format only: YES
Protect MULTOS cipher data checksums: YES
Enable Key Scheme Tag 'X' (X9.17) for storing keys under LMK:
NO
Enable use of Tokens in PIN Translation: NO
Enable use of Tokens in PIN Verification: NO
Allow Error light to be extinguished when viewing Error Log: NO
Ensure LMK Identifier in command corresponds with host port: NO
Ignore LMK ID in Key Block Header: NO
Enable import and export of RSA Private keys: NO
NOTE: The following settings are not all PCI HSM compliant.
Prevent single-DES keys masquerading as double or triple-length
keys: YES
Single-DES: DISABLED