MSM7xx Controllers Configuration Guide v6.4.0

Passwords
Passwords must be 6 to 16 printable ASCII characters in length with at least 4 different characters.
Passwords are case sensitive. Space characters and double quotes ( " ) cannot be used. Passwords
must also conform to the selected security policy as follows.
Follow FIPS 140-2 guidelines: When selected, implements the following requirements from the
FIPS 140-2 guidelines:
All administrator passwords must be at least six characters long.
All administrator passwords must contain at least four different characters.
For more information on these guidelines, refer to the Federal Information Processing Standards
Publication (FIPS PUB) 140-2, Security Requirements for Cryptographic Modules.
Follow PCI DSS 1.2 guidelines: When selected, implements the following requirements from
the PCI DSS 1.2 guidelines:
All administrator passwords must be at least seven characters long.
All administrator passwords must contain both numeric and alphabetic characters.
The settings under Login control must be configured as follows:
Lock access after nn login failures must be set to 6 or less.
Lock access for nn minutes must be set to 30 minutes or more.
The settings under Account inactivity logout must be configured as follows:
Timeout must be set to 15 minutes or less.
For more information on these guidelines, refer to the Payment Card Industry Data Security
Standard v1.2 document.
Manager username/password reset
Not supported on the MSM765 zl and MSM775 zl.
The Allow password reset via console port feature provides a secure way to reset the manager
login username/password on a controller to factory default values (admin/admin), without having
to reset the entire controller configuration to its factory default settings. To make use of this feature
you must be able to access the controller through its console (serial) port. See “Console ports”
(page 546).
IMPORTANT:
This feature is automatically enabled after performing a reset to factory default settings.
This feature is automatically disabled after performing a software (firmware) upgrade from
release 5.4x or earlier.
CAUTION: If you disable this feature and then forget the manager username or password, the
only way to gain access the management tool is to reset the controller to its factory default settings.
See “Resetting to factory defaults” (page 547).
Configuring management tool security
Select Controller >> Management > Management tool and configure the settings under Security.
On the MSM720
Configuring management tool security 21