![ZAZO TsmWeb TSM500i User Manual Download Page 31](http://html1.mh-extra.com/html/zazo/tsmweb-tsm500i/tsmweb-tsm500i_user-manual_3200836031.webp)
TSM500i and TsmWeb User Guide (PCI HSM v3) (PR-D2-1037 Rev 1.1)
| Page 31
Zazoo Limited, Co. No 9265606 | Directors: Dr S C P Belamant (French),
Mr H G Kotze, Mr P M Belamant | Company Secretary: Ms C W van Straaten
www.zazooltd.com
3.4
Reset CSPs, clear all passwords, and set passwords
This operation should NOT be used to set initial passwords - for that use 'Authenticate HSM & Set
Initial Passwords' (see section 2.8).
This operation should only be used when ALL passwords have been forgotten.
This operation will result in the erasure of ALL CSPs and ALL passwords.
To proceed, the customer must send a signed letter to the Manufacturer requesting the reset
certificate. The letter must include the names and email addresses of the two crypto officers that
will set their passwords simultaneously and take control of the HSM after all secrets have been
erased.
Requirements:
Logged into TSM-WEB and the KCED connected to the TSM500i.
This service can only be performed if the module is in the
Loader state
Both crypto officers must have received their
Reset Password Token
, one for each Cryptographic
Officer, sent individually to the email addresses specified on the signed letter. The tokens may only be
used once
where-after they will not function.
Both crypto officers must be present during this command.
Whenever the KCED is connected to the HSM, the Cryptographic Officers must inspect the HSM, the
externally connected device, and the inter-connecting cable for any signs of tampering or insertion
of a bugging device.
Process:
Click on “Clear CSPs and Reset Passwords” tab on the
TSM Operators
page.
Set “Officer 1 Name” and “Officer 2 Name” fields.
Copy both tokens into their respective boxes and click on
CLEAR CSPS & RESET PASSWORDS
.
The first Crypto Officer must look at the
KCED screen
that should show a message for Operator #1 to
enter a new password.
The password must be entered via the KCED keypad
.
A password must be at least 7 digits in length, using digits in the range 0 to 9.
The KCED will prompt the first Crypto Officer to verify the password (enter it a second time).
Once the password has been verified it is stored in the TSM500i.
Make a record of the password and keep it locked in a safe when not in use.
The
second Crypto Officer
(identified as Operator #2 by the TSM500i) will be prompted to set their
password in the same way.
The crypto officers must keep a record of their passwords in a safe place and
ENSURE THAT THEY FULLY UNDERSTAND THE CONSEQUENCES OF LOSING THEIR PASSWORDS!
If all crypto officers forget their passwords, there is NO way to reset the HSM passwords without
ERASING ALL CSPs.