Sign In
Upload
Manuals
Brands
Thales Manuals
Network Card
payShield 10K
Thales payShield 10K Manuals
Manuals and User Guides for Thales payShield 10K. We have
1
Thales payShield 10K manual available for free PDF download: Installation And User Manual
Thales payShield 10K Installation And User Manual (470 pages)
Brand:
Thales
| Category:
Network Card
| Size: 12 MB
Table of Contents
Table of Contents
3
Documentation Overview
11
Audience
11
Payshield 10K General Description
11
Introduction
11
Typical Configuration
12
Command Flow
13
Smart Cards
13
Customer Trust Authority (CTA)
14
Customer Security Domain
15
Keys
15
Encryption Mechanism
15
HSM Recovery Key
15
Local Master Keys (Lmks)
16
Multiple Lmks
16
Terminal PIN Key
17
Terminal Authentication Key
17
Terminal Master Key
17
Zone Master Key
17
Zone PIN Key
17
Terminal Encryption Key
18
PIN Verification Key
18
Card Verification Key
18
Master Session Key
18
Key Shares
18
Host Commands Supporting Multiple Lmks
19
LMK Usage in Host Commands
20
Payshield 10K License Packages
21
Description
23
Trusted Management Device (TMD)
23
Background
23
Introduction
23
Example Sequence of Steps to Set-Up and Transfer Keys
25
Backwards Compatibility and Differences
27
Payshield 9000 / Payshield 10K
27
Host Interface and Commands
27
Options for Managing Payshield 10K
28
Modifications Made to the Console Commands
28
Feature Comparison
29
Front Panel Key Lock Positions
31
Front Panel Leds
31
Front Panel
31
Rear Panel
32
Enhanced Security Features
32
Diagnostics
33
Monitoring
33
Transitioning Smart Cards
33
Transitioning Legacy Manager Smart Cards
34
User Documentation
35
Copying a Card at the Console
35
Transitioning Non-Supported Legacy HSM Smart Cards
35
Physical Description
37
Front Panel
37
Key Locks and Keys
37
Changing the HSM State Via the Key Locks
37
Smart Card Reader
38
Front Panel Leds
38
Health LED
39
Service LED
39
Air Inlets
40
Blue LED
40
Boot-Up LED Sequence
40
Tamper LED
40
Rear Panel
41
AC/DC Power Supplies
41
Swapping out the Power Supply
41
Fan Trays
42
Battery
42
Ground Lug
43
Erase Button and LED
43
USB Type a Port
43
Ethernet Ports
43
Pcie Card Interface
43
AC Power On/Off Switch
43
Installation
45
Pre-Installation Tasks
45
Mechanical and Electrical Specifications
45
Physical Characteristics
45
Power Considerations
45
Environmental Considerations
46
Battery Consideration
46
Installation Procedure
46
Introduction
51
Payshield 10K 10G Ethernet Hardware Platform Variant
51
General Notes
52
Installing 10Gb Ports
52
Rear Panel Overview
52
Power Consumption
53
Payshield Management Options
55
Preparing for Commissioning
57
Configuring Payshield 10K for Static IP (if Required)
57
Prerequisites
57
Introduction
57
Commission Using Payshield Manager
57
Install Smart Card Reader Driver
58
Check the Proxy Configuration
58
Configure DNS
58
Connect to the Network
59
Connecting to Payshield 10K, Installing Browser Extensions and Configuring Smart Card Reader
60
Connecting to Payshield 10K
60
Installing Thales Browser Extensions
61
Configure the Smart Card Reader
67
Commissioning Payshield 10K
68
Open the Commissioning Wizard Page
69
Create a New Security Domain
70
Load the Security Domain
75
Set HSM Recovery Key (HRK) Passphrases
80
Create Left and Right Remote Access Control Key Cards
81
Adding Additional Warranted Hsms to the Security Domain
86
Additional Information
87
Using Payshield Manager with Macos Catalina
87
Using Payshield Manager
91
Introduction to Payshield Manager
91
Logging into Payshield Manager
91
Status Tab
93
Summary Tab
93
Top Tab Descriptions
93
Operational Tab
94
Domain Tab
95
Configuration Tab
95
Virtual Console Tab
96
Quick Links
96
Terminate Session
96
Lower Screen Icons
96
Switching to Online or Offline State
97
Switching to Secure State
97
Payshield 10K States
97
Secure
97
Offline
97
Online
97
Time Remaining
98
Information
98
User
98
Status
99
Smart Card Operations
99
User Logout
100
Login Additional Users
100
Login/Logout of Users
100
Summary Page
101
Summary Dashboard
101
Health Dashboard
102
How to Resolve Reported Errors
102
Configuration Dashboard
105
Local Master Key
106
Status Page
107
Device Information
108
Utilization Statistics
109
Health Statistics/Diagnostics
113
Health/Stats
113
Diagnostics
114
Maintenance
115
Error Log
115
Audit Log
116
Software Info
123
Software - How to Update Software
124
License Summary - How to Update Licensing
125
Fips/Licensing
125
Installed Licenses
126
FIPS Validated Algorithms
127
Import Certificate
127
General Information
127
TLS Management
128
Secure Host Communications
128
Operational
129
Local Master Keys
130
Generate LMK - Create Trusted Officer
130
Verify an LMK Card
139
Create an Authorizing Card
139
Duplicate an LMK Card
140
Generate an LMK
140
Install an LMK from RLMK Card Set
141
Delete an Installed LMK
141
Replace an Installed LMK
142
Set the Default LMK
142
Set the Management LMK
143
Enter Authorized State
144
Install LMK from RLMK Card Set
145
Multiple Authorization Mode
145
Key Change Storage
145
Single Authorization Mode
145
Delete an Installed LMK
146
Replace an Old LMK
146
Domain
147
Payshield Security Group
148
Security Domain
149
Commission a Smart Card
149
HRK Operations
154
Copy a Domain Card
154
Create a New Security Domain
154
Decommission a Card
154
Configuration
156
Host Settings
157
Active Host Interface
157
Ethernet
158
Access Control List (ACL)
160
Tcp/Udp
161
Tls
162
Printer Settings
163
Security Settings
165
Security Parameter Descriptions
167
Management Settings
167
Management - Interface
167
Management - Timeouts
169
Appendix Contents
210
Console Commands - Listed Alphabetically
214
Configuration Commands
218
Reset to Factory Settings (RESET)
219
Upload Software and Licenses (UPLOAD)
221
Configure Commands (CONFIGCMDS)
223
Configure PIN Block Formats (CONFIGPB)
225
Configure Security (CS)
227
View Security Configuration (QS)
236
Configure Host Port (CH)
241
View Host Port Configuration (QH)
244
Host Port Access Control List (ACL) Configuration (CONFIGACL)
247
Configure Printer Port (CP)
250
View Printer Port Configuration (QP)
253
Configure Management Port (CM)
255
View Management Port Configuration (QM)
257
Configure Auxiliary Port (CA)
258
View Auxiliary Port Configuration (QA)
260
Configure Alarms (CL)
261
View Alarm Configuration (QL)
262
View/Change Instantaneous Utilization Period (UTILCFG)
263
Suspend/Resume Collection of Utilization Data (UTILENABLE)
264
Suspend/Resume Collection of Health Check Counts (HEALTHENABLE)
265
View SNMP Settings (SNMP)
266
Add an SNMP User (SNMPADD)
267
Delete an SNMP User (SNMPDEL)
268
Configure SNMP Traps (TRAP)
269
Add a New SNMP Trap (TRAPADD)
270
Delete an SNMP Trap (TRAPDEL)
271
Fraud Detection Commands
272
Configure Fraud Detection (A5)
273
Re-Enable PIN Verification (A7)
275
Diagnostic Commands
276
Diagnostic Test (DT)
277
View Software Revision Number (VR)
281
View Available Commands (GETCMDS)
283
Show Network Statistics (NETSTAT)
285
Test TCP/IP Network (PING)
287
Trace TCP/IP Route (TRACERT)
288
View/Reset Utilization Data (UTILSTATS)
290
View/Reset Health Check Counts (HEALTHSTATS)
292
Local Master Keys
293
Multiple Lmks
293
Types of Lmks
293
LMK Commands
295
Generate LMK Component(S) (GK)
296
Load LMK (LK)
299
Load 'Old' LMK into Key Change Storage (LO)
305
Load 'New' LMK into Key Change Storage (LN)
309
Verify LMK Store (V)
313
Duplicate LMK Component Sets (DC)
314
Delete LMK (DM)
315
Delete 'Old' or 'New' LMK from Key Change Storage (DO)
316
View LMK Table (VT)
317
Generate Test LMK (GT)
320
Authorization Commands
322
Operational Commands
322
Enter the Authorized State (A)
323
Cancel the Authorized State (C)
325
Authorize Activity (A)
326
Cancel Authorized Activity (C)
336
View Authorized Activities (VA)
338
Logging Commands
339
Display the Error Log (ERRLOG)
340
Clear the Error Log (CLEARERR)
342
Display the Audit Log (AUDITLOG)
343
Clear the Audit Log (CLEARAUDIT)
345
Audit Options (AUDITOPTIONS)
346
Time and Date Commands
349
Query the Time and Date (GETTIME)
351
Set Time for Automatic Self-Tests (ST)
352
Settings, Storage and Retrieval Commands
353
Save HSM Settings to a Smartcard (SS)
354
Retrieve HSM Settings from a Smartcard (RS)
355
Key Management Commands
358
Generate Key Component (GC)
359
Generate Key and Write Components to Smartcard (GS)
362
Encrypt Clear Component (EC)
366
Form Key from Components (FK)
369
Generate Key (KG)
376
Import Key (IK)
380
Export Key (KE)
384
Generate a Check Value (CK)
388
Set KMC Sequence Number (A6)
390
Payment System Commands
391
Generate a Card Verification Value (CV)
392
Generate a VISA PIN Verification Value (PV)
394
Load the Diebold Table (R)
396
Encrypt Decimalization Table (ED)
398
Translate Decimalization Table (TD)
400
Generate a MAC on an IPB (MI)
402
Smartcard Commands
403
Format an HSM Smartcard (FC)
404
Create an Authorizing Officer Smartcard (CO)
406
Verify the Contents of a Smartcard (VC)
407
Change a Smartcard PIN (NP)
408
Read Unidentifiable Smartcard Details (RC)
409
Eject a Smartcard (EJECT)
410
DES Calculator Commands
411
Single-Length Key Calculator (N)
412
Double-Length Key Calculator ($)
413
Triple-Length Key Calculator (T)
414
Payshield Manager Commands
415
Add a RACC to the Whitelist (XA)
416
Decommission the HSM (XD)
417
Remove RACC from the Whitelist (XE)
418
Commission the HSM (XH)
419
Generate Customer Trust Authority (XI)
420
Make an RACC Left or Right Key (XK)
422
Commission a Smartcard (XR)
423
Transfer Existing LMK to RLMK (XT)
424
Decommission a Smartcard (XX)
426
HSM Commissioning Status (XY)
427
Duplicate CTA Share (XZ)
428
Secure Host Communications
429
Generate Certificate Signing Request (SG)
430
Import Certificate (SI)
433
Export HSM Certificate's Chain of Trust (SE)
435
View Installed Certificate(S) (SV)
437
Delete Installed Certificate(S) (SD)
440
Generate HRK (SK)
441
Change HRK Passphrase (SP)
442
Restore HRK (SL)
443
KMD Support Commands
444
Generate KTK Components (KM)
445
Install KTK (KN)
446
View KTK Table (KT)
447
Import Key Encrypted under KTK (KK)
448
Delete KTK (KD)
449
Error Responses Excluded from Audit Log
450
Advertisement
Advertisement
Related Products
Thales Cinterion MLA31-W
Thales Cinterion MLP31-W
Thales Cinterion MV31-W sub6 USB
Thales gemalto Cinterion mPLAS9-W
Thales gemalto Cinterion mPLAS9-X
Thales gemalto Cinterion mPLS62-W
Thales gemalto Cinterion mPLS8-E
Thales gemalto Cinterion mPLS8-US
Thales mPLAS9
Thales mPLS62
Thales Categories
Network Hardware
GPS
Turntable
Server
Security System
More Thales Manuals
Login
Sign In
OR
Sign in with Facebook
Sign in with Google
Upload manual
Upload from disk
Upload from URL