![ZAZO TsmWeb TSM500i User Manual Download Page 40](http://html1.mh-extra.com/html/zazo/tsmweb-tsm500i/tsmweb-tsm500i_user-manual_3200836040.webp)
TSM500i and TsmWeb User Guide (PCI HSM v3) (PR-D2-1037 Rev 1.1)
| Page 40
Zazoo Limited, Co. No 9265606 | Directors: Dr S C P Belamant (French),
Mr H G Kotze, Mr P M Belamant | Company Secretary: Ms C W van Straaten
www.zazooltd.com
4.10
SSL/TLS Certificate
SSL / TLS support was added to TSM-WEB from v3.21.0 onwards. When logging into TSM-WEB, the web
browser will be re-directed to the SSL-secured log-in page.
When TSM-WEB generates a certificate, it assigns it a validity period of 2 years. The TSM Page displays the TLS
certificate expiry date.
The TSM-WEB alert system is used to notify the user that the certificate is going to expire when the expiry date
reaches the notification window of 90 days remaining. Each time a session is established a warning will be
generated which can be acknowledged from within TSM-WEB.
Steps to Generate a New TLS Certificate:
A new certificate can be generated via the “System” page within TSM-WEB. There are two options available:
Click
Regenerate Certificate
to simply regenerate the server certificate used for TLS
connections.
Click
Regenerate Key & Certificate
to generate a new key-pair and certificate for the web
server to use in TLS connections.
The TLS key algorithm can be changed via the “Preferences Manager”, both RSA and EC key types are
supported. It must be noted however that EC is not supported in Internet Explorer but has been tested
successfully in both Mozilla Firefox and Google Chrome.
As a fail-safe mechanism, if a new certificate has not been generated before the current certificate expires; the
server will automatically generate a new certificate on start-up. Therefore, if a user is unable to connect to the
web server, on a secure connection, due to its certificate having expired, the TSM-WEB server needs to be
restarted. The TSM500i-NSS will need to be rebooted for this to happen.
4.11
Disabling and Enabling SSL / TLS
SSL or TLS is a PCI-DSS security requirement applicable to EFT and many other environments. This
service should NOT be disabled except as a temporary measure to resolve a specific TLS-related
problem.
4.11.1
Disable TLS from the LCD MENU
Using the LCD MAIN MENU as described in section 4.7, select the “Disable TLS” option and confirm the
operation. The TLS service is now disabled.
4.11.2
Disable or Enable TLS from TSM-WEB
TLS cannot be re-enabled via the LCD Menu. To enable or disable TLS via TSM-WEB, select “Preference
Manager” from the side menu. Edit the
tls.enabled
preference as required.
After enabling TLS from TSM-WEB, it will be necessary to power-cycle the TSM500i-NSS in order to start the
TLS service.