22.2 Device Security page (Security Settings)

Setting

Ask Security Questions for Self Service Card Unlock

Default value

No

Description

Whether the holder’s security phrase is used when unlocking a card.

Further information

See the Self-service PIN reset authentication section in the Operator's Guide.

 

Setting

Manage PIV 9E key on supported devices

Default value

No

Description

Updates the PIV 9E Key, if it is supported by the device. The card symmetric 9E key is diversified from the 9B Master Key, and is changed to the customer master key during card issuance, and using the factory master key when the card is erased.

Set this option to Yes to update the PIV 9E key on supported devices during issuance and erasure. Set this option to No to prevent any attempt to update the PIV 9E key on issuance or erasure.

Further information

 

 

Setting

Number of security questions for operator authentication

Default value

1

Description

The number of security phrases the user is required to provide when an operator asks them; for example, during the Authenticate Person or Unlock Credential workflows.

Further information

See section 3.3.1, Setting the number of security phrases required to authenticate.

 

Setting

Number of security questions to register

Default value

2

Description

The number of security phrases to enroll for a user in the Change Security Phrases or Change My Security Phrases workflows.

Further information

See section 3.3.1, Setting the number of security phrases required to authenticate.

 

Setting

Offline Unlock Method

Default value

Challenge

Description

Challenge – a dialogue between the holder and the helpdesk, passing challenges and responses to identify the holder and the device.

Witness – another holder must witness the request.

None – offline unlocking not possible.

Further information

Used for Giesecke & Devrient cards.

 

Setting

Security Officer PIN Type

Default value

Random

Description

Random – Generate a random SOPIN and set it on the card to be initialized (higher security).

Factory – Leave the default SOPIN on the card (low security).

Further information

 

 

Setting

Transport PIN

Default value

12549856

Description

Default PIN for canceled cards. If you are using on-device PIN policies, you must set the transport PIN to match the PIN policy in the card properties file.

Further information

 

 

Note: You can also set the requirements for customer GlobalPlatform and PIV 9B keys for each device type supported by your system. If the option is set to Yes, and the card supports the feature, MyID requires the customer key to be configured before issuing devices of this type.

If you change any of the options on this screen away from the default, your system will be potentially insecure, and MyID will display an appropriate warning when logging in to MyID or when issuing a smart card that would be affected. See section 20.3, System security for more information.

The Securing Devices section in the System Security Checklist document contains important information on securing your system.