22.2 Device Security page (Security Settings)
Setting |
|
Default value |
No |
Description |
Whether the holder’s security phrase is used when unlocking a card. |
Further information |
See the Self-service PIN reset authentication section in the Operator's Guide. |
Setting |
|
Default value |
No |
Description |
Updates the PIV 9E Key, if it is supported by the device. The card symmetric 9E key is diversified from the 9B Master Key, and is changed to the customer master key during card issuance, and using the factory master key when the card is erased. Set this option to Yes to update the PIV 9E key on supported devices during issuance and erasure. Set this option to No to prevent any attempt to update the PIV 9E key on issuance or erasure. |
Further information |
|
Setting |
|
Default value |
1 |
Description |
The number of security phrases the user is required to provide when an operator asks them; for example, during the Authenticate Person or Unlock Credential workflows. |
Further information |
See section 3.3.1, Setting the number of security phrases required to authenticate. |
Setting |
|
Default value |
2 |
Description |
The number of security phrases to enroll for a user in the Change Security Phrases or Change My Security Phrases workflows. |
Further information |
See section 3.3.1, Setting the number of security phrases required to authenticate. |
Setting |
|
Default value |
Challenge |
Description |
Challenge – a dialogue between the holder and the helpdesk, passing challenges and responses to identify the holder and the device. Witness – another holder must witness the request. None – offline unlocking not possible. |
Further information |
Used for Giesecke & Devrient cards. |
Setting |
|
Default value |
Random |
Description |
Random – Generate a random SOPIN and set it on the card to be initialized (higher security). Factory – Leave the default SOPIN on the card (low security). |
Further information |
|
Setting |
|
Default value |
12549856 |
Description |
Default PIN for canceled cards. If you are using on-device PIN policies, you must set the transport PIN to match the PIN policy in the card properties file. |
Further information |
|
Note: You can also set the requirements for customer GlobalPlatform and PIV 9B keys for each device type supported by your system. If the option is set to Yes, and the card supports the feature, MyID requires the customer key to be configured before issuing devices of this type.
If you change any of the options on this screen away from the default, your system will be potentially insecure, and MyID will display an appropriate warning when logging in to MyID or when issuing a smart card that would be affected. See section 20.3, System security for more information.
The Securing Devices section in the System Security Checklist document contains important information on securing your system.