TSM500i and TsmWeb User Guide (PCI HSM v3) (PR-D2-1037 Rev 1.1)
| Page 30
Zazoo Limited, Co. No 9265606 | Directors: Dr S C P Belamant (French),
Mr H G Kotze, Mr P M Belamant | Company Secretary: Ms C W van Straaten
www.zazooltd.com
3.3
Reset One Password
This operation may be used to
RESET
one password. It requires a
reset certificate from the
Manufacturer
and it also requires
one officer to authenticate themselves
.
To proceed, the customer must send a signed letter to the Manufacturer requesting the reset certificate.
The letter must include the name and email address of the crypto officer that will set their password.
Requirements:
Logged into TSM-WEB and the KCED connected to the TSM500i.
This service can only be performed if the module is in the
Loader state
One Crypto Officer must have authenticated themselves, using the KCED to login.
Customer must have received the
Reset Password Token
for the Cryptographic Officer. These tokens
will only be sent to the email specified on the signed letter. The tokens may only be
used once
where-
after they will not function.
Whenever the KCED is connected to the HSM, the Cryptographic Officers must inspect the HSM, the
externally connected device, and the inter-connecting cable for any signs of tampering or insertion
of a bugging device.
Process:
Click on “Reset Password” tab on the
TSM Operators
page.
Set “Operator Name” field.
Copy the token that was received from the Manufacturer into the box and click.
The Crypto Officer must look at the
KCED screen
that should show a message for Operator to enter a
new password.
The password must be entered via the KCED keypad
.
Follow the on screen instructions on the KCED. When prompted (twice), enter the new password on
the KCED.
A password must be at least 7 digits in length, using digits in the range 0 to 9.
Make a record of your password and keep in a safe place.
ENSURE THAT YOU FULLY UNDERSTAND THE CONSEQUENCES OF LOSING YOUR PASSWORD!
If all crypto officers forget their passwords, there is NO way to reset the HSM passwords without
ERASING ALL CSPs.