Mde 5523e
Mde 5523e
                             MDE-5523E
Computer Programs and Documentation
                            All Gilbarco Inc. and/or Veeder-Root Company computer programs (including software on diskettes and within memory chips) and documentation are copyrighted by, and shall
                            remain the property of, Gilbarco Inc. and/or Veeder-Root Company. Such computer programs and documents may also contain trade secret information. The duplication, disclosure,
                            modification, or unauthorized use of computer programs or documentation is strictly prohibited, unless otherwise licensed by Gilbarco Inc. and/or Veeder-Root Company.
Approvals
Gilbarco is an ISO 9001:2008 registered company.
Underwriters Laboratories (UL):                                                     California Air Resources Board (CARB):
UL File#         Products listed with UL                                            Executive Order #           Product
                 All Gilbarco pumps and dispensers that bear                        G-70-52-AM                  Balance Vapor Recovery
MH1941
                 the UL listing mark.                                               G-70-150-AE                 VaporVac
MH8467           Transac System 1000 and PAM 1000
E105106          Dell DHM Minitower
E165027          G-SITE and Passport Systems
                                                ftr y
               Meter - C Series                 PA024NC10                                   G-SITE Distribution Box         PA0306
02-025
               Meter - C Series                 PA024TC10                                   G-SITE Keyboard                 PA0304
                                                                           02-037
02-029         CRIND                            —                                           G-SITE Mini Tower               PA0301
               TS-1000 Console                  —                                           G-SITE Monitor                  PA0303
               TS-1000 Controller
                                             ra a
                                                PA0241                                      G-SITE Printer (Citizen)        PA0308
02-030         Distribution Box                 PA0242                     02-038           C+ Meter                        T19976
               Meter - EC Series                PA024EC10                  02-039           Passport                        PA0324
                                            D in
               VaporVac Kits                    CV                         02-040           Ecometer                        T20453
                                                                           05-001           Titan                           KXXY Series
                                          lim
Trademarks
All product names, logos, and brands are the property of their respective owners and are for identification purposes
only. Use of these names, logos, and brands does not imply endorsement.
Table of Contents
1 – Introduction                                                                                                                                                        1-1
1.1 Purpose . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .   1-1
1.2 PA-DSS vs. PCI DSS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .              1-1
1.3 Related Documents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .           1-1
1.4 Abbreviations and Acronyms. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .                 1-2
1.5 Common Terms. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .           1-4
1.6 Supported Hardware . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .            1-4
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022                                                           Page i
Table of Contents
Page ii                   MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
                                                                                                                                           Table of Contents
Index Index-1
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022                                                  Page iii
Table of Contents
Page iv             MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
1.1 Purpose                                                                                                         Introduction
1 – Introduction
1.1 Purpose
                      This manual provides the required information to install and operate the Passport™ Enhanced
                      Dispenser Hub (EDH) in compliance with the Payment Application Data Security Standard
                      (PA-DSS) version 3.2.
                      Failure to comply with the information provided in this manual can place the merchant in
                      violation of PA-DSS and possibly Payment Card Industry Data Security Standard (PCI DSS)
                      compliance.
                      PCI DSS is a series of requirements that apply to the entire payment environment at a
                      merchant location. PA-DSS covers only a portion of that environment. It does not cover all
                      aspects of PCI DSS. It is the responsibility of the merchant to ensure that the overall payment
                      environment is operated and maintained in a manner compliant with PCI DSS.
                      For more information on specific requirements of PCI DSS or PA-DSS, refer to the PCI
                      Security Standards Council website: www.pcisecuritystandards.org.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022                   Page 1-1
Introduction                                                                        1.4 Abbreviations and Acronyms
Page 1-2       MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
1.4 Abbreviations and Acronyms                                                                             Introduction
                      Term         Description
                      NFS          Network File System
                      NTFS         New Technology File System
                      PA-DSS       Payment Application Data Security Standard
                      PCA          Program Compatibility Assistant
                      PCI DSS      Payment Card Industry Data Security Standard
                      PnP          Plug and Play
                      PNRP         Peer Name Resolution Protocol
                      POS          Point of Sale
                      PSS          Platform Support Service
                      QoS          Quality-of-Service
                      qWave        Quality Windows® Audio Video Experience
                      RD           Remote Desktop
                      RDCS         Remote Desktop Configuration service
                      RIP          Routing Information Protocol
                      RPC          Remote Procedure Call
                      RSA          Rivest Shamir Adleman
                      SAM          Security Accounts Manager
                      SENS         System Event Notification Service
                      SFTP         Secure File Transfer Protocol
                      SMI          Security Manager Interface
                      SNMP         Simple Network Management Protocol
                      SSDP         Simple Services Discovery Protocol
                      SSTP         Secure Socket Tunneling Protocol
                      SZR          Secure Zone Router
                      TAPI         Telephony API
                      TCP/IP       Transmission Control Protocol/Internet Protocol
                      TLS          Transport Layer Security
                      TPM          Trusted Platform Module
                      UPnP         Universal PnP
                      URL          Uniform Resource Locator
                      VPN          Virtual Private Network
                      WIA          Windows Image Acquisition
                      WinRM        Windows Remote Management
                      WMI          Windows Management Instrumentation
                      WPAD         Web Proxy Auto-Discovery
                      WPF          Windows Presentation Foundation
                      WS-D         Web Services - Discovery
                      WSCSVC       Windows Security Center Service
                      WUA          Windows Update Agent
                      XML          EXtensible Markup Language
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022       Page 1-3
Introduction                                                                                              1.5 Common Terms
Page 1-4       MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
2.1 Overview                                                                                               System Security
2 – System Security
2.1 Overview
                      The Security Manager application was created to enable overall management of security on
                      the EDH. The merchant uses this application to manage access to the EDH as well as
                      additional merchant-owned portions of the system’s security.
                      Note: Security Manager provides access to sensitive information and must be used only by the
                            merchant. The Username and Password are confidential information that only the
                            merchant may possess. The ASC should not have access to this information. The
                            merchant must enter the username and password and print the Security Manager
                            Report as part of setup.
                      Username: Admin
                      Password: Admin
                      Before the system can be used to process payment transactions, it will force changing of the
                      password to a strong password of this account. Further, selection of a strong password for the
                      Admin account and all user accounts is enforced and maintained once system security is
                      enabled.
                      It is the responsibility of the Merchant to assign the Admin password to a single individual, per
                      PCI DSS requirements, as group or shared passwords are not allowed. For Merchants with
                      more than one administrator, additional admin level users can be added as required.
Additional details on use of the Administrative User account are provided later in this manual.
                      For more information on these two methods, refer to “2.3.1 Accessing Security Manager via
                      System Maintenance” on page 2-2 and “2.3.2 Accessing Security Manager via Support
                      Console” on page 2-3.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022          Page 2-1
System Security                                                                      2.3 Security Manager Login Process
                  1 Press the Ctrl, Alt, and P keys on the Passport keyboard simultaneously. The System
                     Maintenance login screen opens.
3 Enter Passport in the Password field. The System Maintenance toolbar appears.
Page 2-2           MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
2.3 Security Manager Login Process                                                                         System Security
                  4 Navigate to EDHub > Security Mgr > Manager. The Security Manager Login window
                      opens.
                  1 To access Support Console at the MWS, select the Help key in the upper right corner of the
                      screen. To access Support Console at the CWS, at stores running Passport V20.03 or earlier,
                      navigate to More > More > Tools, and then select Support. At stores running Passport
                      V20.04 or later, select the Telephone icon at the top of the CWS screen. 
                      The Support Console screen opens.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022          Page 2-3
System Security                                                                      2.3 Security Manager Login Process
                     Note: Security Manager logs each attempt to log into Security Manager (including
                           unsuccessful attempts) into the security audit log.
                     While connecting to the EDH, the key in the middle of the Security Manager Login window
                     displays Please wait - Connecting to EDH. The user must wait until the key name changes to
                     Login before entering details in the User Name and Password fields.
Page 2-4           MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
2.4 Using Security Manager                                                                                 System Security
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022          Page 2-5
System Security                                                                              2.4 Using Security Manager
(i) (ii)
Page 2-6          MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
2.4 Using Security Manager                                                                                 System Security
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022          Page 2-7
System Security                                                                              2.4 Using Security Manager
Page 2-8          MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
3.1 User Management                                                                           User Names and Passwords
(i) (ii)
                      Four basic functions are provided for managing User Names and Passwords. All functions are
                      available to users with Administrator access. Only the Change Current User Password
                      function is available to non-Administrator users. If a User Name with user-level access selects
                      any of the other functions, the following error message displays, in red letters, centered
                      between the bottom row of keys and the Exit key:
Selecting the Exit key returns the user to the main Security Manager window.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022      Page 3-1
User Names and Passwords                                                                        3.1 User Management
               1 From the Security Manager main window, select User Management. The User Management
                 window opens.
Note: The Add User function can be accessed only by an Administrator-level user.
2 From the User Management window, click Add User. The Add User window opens.
Page 3-2       MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
3.1 User Management                                                                             User Names and Passwords
                  4 Select the Administrative User check box if the user is to be assigned as an Administrator. An
                      Administrator-level user has access to all Security Manager functions.
                      Notes: 1) User Name is an alphanumeric field with minimum of seven and maximum of 20
                                characters.
                            2) The Administrative User check box is cleared by default.
                  3 Select Add User. The initial password is the value keyed in the User Name field and must be
                      changed by the new user the first time the new user logs into Security Manager. This can be
                      done by selecting the Change Current User Password function.
                                        IMPORTANT INFORMATION
                       • A User Name cannot be added if it already exists. If an attempt is made to add an
                         already existing User Name, Security Manager displays the error message: 
                         “Error - User Name Already Exists.”
                       • Users can be added only when the system is secure (security-enabled). If an attempt
                         is made to add a user before the system is secure, Security Manager displays the error
                         message: “Error - It is required that the system be Hardened (Security Enabled)
                         in order to add more users.”
                       • Security Manager logs an entry in the Security Audit Log when a User Name is added.
                         The log entry includes the following information:
                          - User Name that added the new user
                          - User Name added and notation if Administrative User was selected
                          - Date/Time
                          - Terminal at which the new user was added
                       • A unique User Name must be assigned to each user. Group User Names are not
                         permitted under PCI DSS.
                       • For more information on managing User accounts, refer to “3.2 User Name and
                         Password Best Practices” on page 3-9.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022          Page 3-3
User Names and Passwords                                                                        3.1 User Management
               1 From the Security Manager main window, select User Management. The User Management
                 window opens.
2 From the User Management window, select Remove User. The Remove User window opens.
Page 3-4       MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
3.1 User Management                                                                           User Names and Passwords
                                        IMPORTANT INFORMATION
                       • Security Manager logs an entry to the Security Audit Log when a User Name is removed. 
                         The log entry includes the following information:
                          - User Name that removed the user
                          - User Name removed
                          - Date/Time
                          - Terminal at which the user was removed
                       • A User Name cannot be removed if it does not exist. If an attempt is made to remove a User Name
                         that does not exist, Security Manager displays the error message: “Error - User Name Does Not
                         Exist.”
                       • The merchant must manage User Name removals in accordance with PCI DSS.
                       • For more information on managing User accounts, refer to “3.2 User Name and Password Best
                         Practices” on page 3-9.
                  1 From the Security Manager main window, select User Management. The User Management
                      window opens.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022          Page 3-5
User Names and Passwords                                                                         3.1 User Management
2 From the User Management window, select Reset User. The Reset User window opens.
               4 Select Reset User. Security Manager resets the user’s password to the User Name. The user
                  must select the Change Current User Password function at the next Security Manager login.
                                    IMPORTANT INFORMATION
                   • Security Manager adds an entry to the Security Audit Log when a User Name is reset.
                     The log entry includes the following information:
                      - User Name that reset the user
                      - User Name reset
                      - Date/Time
                      - Terminal at which the user was reset
                   • The Admin user is protected and cannot be reset.
                   • A User Name password cannot be reset if the User Name does not exist. If an attempt
                     is made to reset the password of a User Name that does not exist, Security Manager
                     displays the error message: “Error - User Name Does Not Exist.”
                   • The merchant must manage User Name removals in accordance with PCI DSS.
                   • For more information on managing User accounts, refer to “3.2 User Name and
                     Password Best Practices” on page 3-9.
Page 3-6       MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
3.1 User Management                                                                           User Names and Passwords
                      To change the password of the user currently logged onto Security Manager, proceed as
                      follows:
                  1 From the Security Manager main window, select User Management. The User Management
                      window opens.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022      Page 3-7
User Names and Passwords                                                                         3.1 User Management
               2 From the User Management window, select Change Current User Password. The Change
                  Password window opens.
               3 Enter the new password in the Enter New Password field. Security Manager masks each user
                  keystroke with *.
               4 Enter the new password again in the Re-Enter Password field. Security Manager masks each
                  user keystroke with *.
                                   IMPORTANT INFORMATION
                  • The values the user keys in the Enter New Password and Re-Enter Password fields
                    must match. If they do not, Security Manager displays the error message: 
                    “Error - Passwords do not match.”
                  • The new password must not match any of the previous four passwords for that user. If
                    the new password does match one of the previous four passwords, Security Manager
                    displays the error: “Error: Changing user password failed. Most likely this is
                    because the new password matched the current password or the last one used.”
                  • The new password must be at least seven characters in length and contain at least one
                    digit. Security Manager accepts special characters, as well.
                  • Security Manager adds an entry to the Security Audit Log when a user’s password is
                    changed. The log entry includes the following information:
                     - User Name that changed the password
                     - Date/Time
                     - Terminal at which the password was changed
                  • The merchant must manage passwords in accordance with PCI DSS.
                  • For more information on managing User accounts, refer to “3.2 User Name and
                    Password Best Practices” on page 3-9.
Page 3-8       MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
3.2 User Name and Password Best Practices                                                                 User Names and Passwords
                      Entry of six consecutive invalid passwords will result in the user account being locked for 30
                      minutes. After the 30-minute lockout period, the user may attempt to login again.
                      These requirements apply to Security Manager and other devices connected to the merchant
                      network, including the Passport MWS/Server, BOS, Loyalty systems, etc. Failure to maintain
                      compliant settings for User Names and Passwords may result in PCI DSS non-compliance.
                                                                         Requirement
                      Assign all users a unique User Name before allowing them access to the system.
                      For authentication purposes, use either a unique Password/Passphrase or two-factor authentication (such as
                      token or smart card).
                      Control addition, deletion, and modification of User Names and Passwords.
                      Verify user identity before performing a password reset.
                      Set first-time passwords to a unique value and require them to be changed after the first use.
                      Immediately revoke access for a terminated user.
                      Remove or disable inactive user accounts at least every 90 days.
                      Communicate password procedures and policies to all users who have access to cardholder data.
                      Do not use group, shared, or generic accounts and passwords.
                      Change user passwords at least every 90 days.
                      Require a minimum password length of at least seven characters.
                      Use passwords containing both numeric and alphabetic characters.
                      Do not allow an individual to submit a new password that is the same as any of the last four previously used
                      passwords.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022                         Page 3-9
User Names and Passwords                                                 3.2 User Name and Password Best Practices
Page 3-10       MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
4.1 Overview                                                                                  Reports and Data Retention
4.1 Overview
                      According to PCI DSS requirements, all reports that display or print unmasked customer
                      account number information must be secured properly both on the EDH and in paper form
                      after printing. Customer account information is stored and secured in encrypted form in a
                      database on the EDH. The EDH provides the ability to generate Secure Reports for the
                      merchant to use for transaction reconciliation. The merchant can configure the amount of time
                      this data is retained.
This section provides information on how to retrieve and print Secure Reports.
                                        IMPORTANT INFORMATION
                       The default Secure Report Password during installation is PDFPassword. During
                       installation of the EDH, the merchant must select a new Secure Report Password.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022        Page 4-1
Reports and Data Retention                                                                 4.2 Secure Report Password
                1 From the Security Manager main window, select System Management > Set System
                    Passwords. The System Passwords Menu window opens.
                    Note: Only an Administrator-level user can access Secure Report Password.
                                                                                             (ii)
                                            (i)
                2 Select Change Secure Report Password. The Change Secure Report Password window
                    opens.
                3 Enter the new password in the Enter New Password field. Security Manager masks each user
                    keystroke with *.
Page 4-2         MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
4.2 Secure Report Password                                                                     Reports and Data Retention
                  4 Enter the new password again in the Re-Enter Password field. Security Manager masks each
                      user keystroke with *.
                  5 Select Change Password. Security Manager validates the new password and returns to the
                      System Management screen.
                                        IMPORTANT INFORMATION
                       • The values that user enters in the Enter New Password and Re-Enter Password
                         fields must match. If they do not, Security Manager displays the error message: 
                         “Error - Passwords do not match.”
                       • The new password must be at least seven characters in length and contain at least one
                         digit. Security Manager accepts special characters, as well.
                       • Security Manager adds an entry to the Security Audit Log when a user’s password is
                         changed. The log entry includes the following information:
                          - User Name that changed the password, along with indication if the user is an
                            Administrator-level user
                          - Date/Time
                          - Terminal at which the password was changed
                       • The merchant must manage passwords in accordance with PCI DSS.
                       • For more information on managing user accounts, refer to “3.2 User Name and
                         Password Best Practices” on page 3-9.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022         Page 4-3
Reports and Data Retention                                                                 4.2 Secure Report Password
                    The requirements for each payment network are different; therefore, the list of network reports
                    approved to print vary by payment network. Refer to the relevant Network Addendum for a
                    description of specific secure reports supported by Passport.
                1 From the MWS main menu, navigate to Reports > Network. The Network Reports window
                    opens.
                    Note: Passport displays secure reports in the Network Reports menu list, denoted by
                          “(Secure)” appended to the report name.
                2 Select the secure report and click Select displayed in the right side bar of the Network Reports
                    window. The Period Selection screen opens.
                3 Select the reporting period and click either Print Preview or Print. The Password entry dialog
                    box opens with a prompt to enter a Document Open Password.
                    Figure 4-4: Password Entry Prompt
Page 4-4         MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
4.3 Data Retention                                                                               Reports and Data Retention
                  5 Click OK to view or print the report or click Cancel to terminate the process and remove the
                      Password entry dialog box.
                                        IMPORTANT INFORMATION
                       Security Manager allows the user up to three attempts to enter the correct password.
                       If the user enters the correct password, the report displays (Print Preview key
                       selected) or prints (Print key selected); otherwise, Security Manager denies access
                       to the report. For more information on Passport Reports, refer to the relevant Network
                       Addendum.
                      These requirements apply to data retained on the EDH database and printed on secure reports.
                      After the merchant determines the necessary data retention period, the period may be
                      configured on the Passport MWS.
                      Note: Some payment networks mandate specific data retention periods, which are not
                            configurable by the merchant. For more information on configuring retention periods,
                            refer to the relevant Network Addendum.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022           Page 4-5
Reports and Data Retention                                                                            4.3 Data Retention
Page 4-6         MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
5.1 Overview                                                                                     Remote Access to the EDH
5.1 Overview
                      PCI DSS has specific requirements for remote access into the merchant’s network
                      environment. This section describes the general requirements along with the specific
                      requirements for accessing the EDH.
                                        IMPORTANT INFORMATION
                       • If the nature of the support activity requires that the merchant provide the
                         PassportTech or PassportServices password information over the phone, confirm
                         that a support call was initiated from the merchant to Gilbarco. This password
                         information must never be given over the phone if the call originated from
                         somewhere other than the merchant.
                       • If the password information is provided, System Security must be rolled to ensure
                         new passwords are generated. Refer to the Roll Security option detailed in “7.3.3
                         System Security” on page 7-5.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022         Page 5-1
Remote Access to the EDH                                                      5.2 Enabling Remote Access to the EDH
                                    IMPORTANT INFORMATION
                   Direct remote access to the EDH from outside the merchant network is not supported and, if
                   configured, could violate the merchant’s PCI DSS compliance.
                  Remote access to the EDH is enabled through Security Manager by using System
                  Maintenance or Support Console. For information on accessing Security Manager, refer to 
                  “2-System Security” on page 2-1.
               1 From the Security Manager main window, select Remote Support. The Security Manager
                  Remote Support window opens.
Page 5-2        MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
5.2 Enabling Remote Access to the EDH                                                          Remote Access to the EDH
                  2 Enter text describing the reason for enabling Remote Support into the text box below the
                      Status field and then select Enable Remote Support. A warning message is displayed.
                                        IMPORTANT INFORMATION
                       • To prevent unauthorized access to the EDH, the merchant must know the person requesting a
                         temporary password for remote access and why remote access is necessary before creating a
                         temporary support account.
                       • Security Manager logs an entry in the Security Audit Log each time Remote Support is enabled or
                         disabled.
                       • In the event a user forgets to disable Remote Support, Security Manager automatically disables
                         Remote Support after being enabled for more than 24 hours.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022           Page 5-3
Remote Access to the EDH                                                     5.3 Disabling Remote Access to the EDH
               4 To create a Temporary Support Account, select Create Temp Support Acct. Security
                  Manager generates and displays a temporary password in the Password field. Technical
                  support uses this password to access the EDH remotely for dial-in support.
1 Log into Security Manager. Refer to “2.3 Security Manager Login Process” on page 2-1.
                  3 Select Disable Remote Support. When Security Manager disables Remote Support, the
                      Status field changes to Disabled.
                      Note: This function must be accessed only when instructed by a Gilbarco Call Center or
                            Technical Support agent.
                  1 At sites running Passport V20.03 or earlier, from the CWS idle screen, navigate to More >
                      More > Tools and select Support.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022       Page 5-5
Remote Access to the EDH                                                  5.4 Enabling Remote Support from the CWS
                  At sites running Passport V20.04 or later, select the Telephone icon at the top of the CWS
                  screen.
                  The Support Console screen opens with Remote Support Disabled displayed at the bottom.
                  Figure 5-8: Support Console - Remote Support Disabled
Page 5-6        MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
5.4 Enabling Remote Support from the CWS                                                       Remote Access to the EDH
                  2 Select Enable Support. When remote support is enabled, the Enable Support key changes to
                      “Extend Support” to allow the site to extend the amount of time that remote support will be
                      enabled, and the Disable Support key turns red indicating the Passport system is ready for
                      remote access. Gilbarco Call Center or Technical Support personnel may access the Passport
                      system (see Figure 5-9 and Figure 5-10).
Figure 5-10: Support Console - Remote Support Enabled - Secure Zone Router (SZR)
                  3 When the Gilbarco Call Center or Technical Support agent completes the work, select Disable
                      Support and then select Exit.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022       Page 5-7
Remote Access to the EDH                                                             5.5 Extend Secure Remote Access
                                    IMPORTANT INFORMATION
                    When configured, the PCI DSS requirement to enable/disable remote support as
                    required is no longer enforced by the Passport system and must be handled as part of
                    the broader Merchant network controls.
1 From the MWS main screen, select Set Up > Store > Store Options.
4 Restart the MWS/CWS to make Extend Secure Remote Access configuration active.
                   Note: When Passport is configured to Extend Secure Remote Access for Helpdesk at all
                         times and Enable Enhanced Remote Support Passwords is not selected:
                         1) Selecting Enable Support at sites using a non-Acumera Managed Network Service
                            Provider (MNSP) is not required.
                         2) For Gilbarco access to Acumera sites, selecting Enable Support is required to 
                            build the remote access tunnel.
                   This section describes how to configure Passport to use the enhanced remote support
                   passwords and how a Gilbarco Call Center or Technical Support agent interacts with personnel
                   at the store.
Page 5-8        MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
5.6 Enhanced Remote Support Passwords                                                              Remote Access to the EDH
                  1 From the MWS main screen, navigate to Set Up > Store > Store Options. The Store Options
                      configuration screen opens.
                  3 In the Remote Access Password Options, select Enable Enhanced Remote Support
                      Passwords. Passport automatically enables the Alpha Numeric radio button. The following
                      table contains the Remote Access Password Options fields and their descriptions:
                      Field                              Description
                      Enable Enhanced Remote Support     Checkbox; when checked, Passport generates strong unique passwords
                      Passwords                          for remote access to the Passport system.
                      Alpha Numeric                      When enabled, Passport generates Remote Support passwords
                                                         containing letters and numbers. Accessible only after Enable Enhanced
                                                         Remote Support Passwords field is enabled. Default when Enable
                                                         Enhanced Remote Support Passwords field is enabled. This setting
                                                         causes Passport to generate an 8-character strong alpha numeric remote
                                                         support password.
                      Alpha Numeric with Symbols         When enabled, Passport generates Remote Support passwords
                                                         containing letters, numbers, and symbols. Symbols set includes the
                                                         following:
                                                         !@#$%^&
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022                 Page 5-9
Remote Access to the EDH                                                    5.6 Enhanced Remote Support Passwords
                  The Support Console screen contains a Remote Support section. By default, remote support is
                  disabled.
Page 5-10        MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
5.6 Enhanced Remote Support Passwords                                                          Remote Access to the EDH
                      If Enable Enhanced Remote Support Passwords is set, when the Passport user selects
                      Enable Support, the Support Console screen opens with remote support in enhanced mode.
                      The content of the Support Console screen depends upon the configuration saved in the 
                      MWS > Set Up > Store > Store Options > Password tab.
                      Figure 5-13 and Figure 5-14 illustrate the Support Console screen contents if the Alpha
                      Numeric option is set.
Figure 5-14: Enhanced Remote Support - Alpha Numeric Mode with SZR
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022       Page 5-11
Remote Access to the EDH                                                    5.6 Enhanced Remote Support Passwords
                  In Alpha Numeric and Alpha Numeric with Symbols modes, the Support Console screen
                  displays the 8-character support password, the amount of time that remote support will remain
                  enabled, as well as the Make New Password and Display As Words keys. The Make New
                  Password key allows the Passport user to generate a different remote support password, which
                  may be helpful if the user and the Gilbarco Call Center or Technical Support agent are having
                  difficulty communicating the current remote support password. The Display As Words key
                  causes the remote support password to be displayed in words that the Passport user can read to
                  the Gilbarco Call Center or Technical Support agent, making it easier to communicate the
                  remote support password.
Figure 5-15 and Figure 5-16 illustrate the remote support password displayed as words.
Figure 5-15: Enhanced Remote Support Password Displayed as Words (Alpha Numeric)
                  Figure 5-16: Enhanced Remote Support Password Displayed as Words (Alpha Numeric
                               with Symbols)
Page 5-12        MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
5.6 Enhanced Remote Support Passwords                                                          Remote Access to the EDH
                      If Enable Enhanced Remote Support Passwords is not set, when the Passport user selects
                      Remote Sup., the password screen does not appear on the System Maintenance bar and the
                      bar indicates standard mode is running.
                      Figure 5-18 illustrates a detail of the System Maintenance bar when the Passport user selects
                      the Remote Sup. option with Enable Enhanced Remote Support Passwords set and
                      configured for Alpha Numeric with Symbols.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022       Page 5-13
Remote Access to the EDH                                                    5.6 Enhanced Remote Support Passwords
Page 5-14        MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
6.1 Overview                                                                                               Software Updates
6 – Software Updates
6.1 Overview
                      The EDH software can be updated onsite or remotely through a network connection. All
                      updates to the EDH are provided from within the merchant network, either through the
                      Passport MWS/Server or over a secured connection provided by the merchant.
                      Software updates are applied locally by the Passport MWS/Server and do not require remote
                      access to the EDH. The Automated Software Upgrade (ASU) functionality provided in the
                      EDH is responsible for handling software updates from the Passport MWS/Server, validating
                      the software, and performing the installation.
                      Note: All remote connections to the merchant network and Passport system must be secured
                            as per guidelines specified in “5-Remote Access to the EDH” on page 5-1.
                      Merchants with service agreements are notified by Gilbarco when software updates are
                      released. If a service agreement is not in place, Merchants can contact their Gilbarco
                      Distributor or Service Contractor for information on the latest updates.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022            Page 6-1
Software Updates                                                          6.4 Accessing and Verifying Software Updates
Page 6-2           MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
7.1 Overview                                                                                   Managing System Security
7.1 Overview
                      In addition to the features mentioned in other sections, the EDH supports a number of specific
                      security functions and requirements. This section describes each of them in detail.
                  1 Log into Security Manager (for more information, refer to “2.3 Security Manager Login
                      Process” on page 2-1).
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022        Page 7-1
Managing System Security                                                             7.3 System Management Options
                  PCI defines the following two criteria in which a forced key rotation would be required:
                   • The integrity of the key is weakened
                   • Key compromise is known or suspected
                                    IMPORTANT INFORMATION
                   • The EDH automatically rolls the KEK every 180 days.
                   • The EDH automatically rolls the DEK every 30 days.
Page 7-2        MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
7.3 System Management Options                                                                  Managing System Security
                        !   CAUTION
                       The iButton must be installed correctly in the EDH for the Key Management and
                       Password Restoration processes to occur. If the iButton is removed, damaged, or
                       incorrectly installed, these critical processes fail.
                      From the System Management window, select Key Management. The Manage Keys window
                      opens.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022        Page 7-3
Managing System Security                                                             7.3 System Management Options
               1 From the Manage Keys window, select Restore Key Storage Device Password. 
                  The Restore Key Storage Device Password window opens.
               2 From the merchant’s Security Manager Report, locate the Key Storage Device Password and
                  enter it in the Enter the Key Storage Device password field.
               3 Select Restore Password. While the EDH is restoring the Key Storage Device Password, the
                  Restore Key Storage Device window turns gray and all option or function keys are
                  inaccessible.
When the process is complete, all option or function keys are accessible.
                  Merchants utilizing cryptographic keys in other systems, must manage those keys in
                  compliance with PCI requirements, including the following:
                    • Restrict access to keys to the fewest number of custodians necessary
                    • Store keys securely in the fewest possible locations and forms
Page 7-4        MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
7.3 System Management Options                                                                  Managing System Security
                      Note: Various terms are used interchangeably for enabling System Security, such as activating
                            or hardening. This manual uses enabling.
                      Enabling System Security is a process performed to initiate all security features of the EDH.
                      When System Security is enabled, the EDH defaults to a PA-DSS compliant mode and allows
                      network transactions to be performed.
                      Before System Security can be enabled, the merchant must perform the following tasks:
                       • Change the default Security Manager Administrator Password
                       • Change the default Secure Report Password
1 Log into Security Manager using a valid User Name and Password.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022        Page 7-5
Managing System Security                                                               7.3 System Management Options
                  • When the cashier selects the corresponding dispenser number of the CRIND in error, and
                    selects the Diag key, the Diag screen displays the message “Sale Denied: system Security
                    not enabled.” in the CRIND field. Selecting the Clear Errors key deletes the error.
                  Per PCI DSS requirements, disabling System Security renders all cryptographic material
                  irretrievable.
                    !   CAUTION
                   • Disabling System Security could result in lost transactions, and must be performed with
                     a Gilbarco ASC onsite to save financial and diagnostic data and properly deactivate
                     security.
                   • Disabling System Security must only be used when decommissioning the hardware.
                     The system is unusable and will require reimaging.
2 Perform a Passport Store Close (MWS > Period Close > Store Close).
Page 7-6        MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
7.3 System Management Options                                                                  Managing System Security
1 Log into Security Manager using a valid User Name and Password.
3 Select System Security. The System Security window opens with the Status: Enabled.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022        Page 7-7
Managing System Security                                                             7.3 System Management Options
                  The Disable System Security process completes. The message “Deactivation Complete. OK”
                  is displayed.
                                    IMPORTANT INFORMATION
                   The ASC must not retain or have access to the Security Manager Report. The report can
                   be printed only from the MWS.
Page 7-8        MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
7.3 System Management Options                                                                  Managing System Security
                  1 One of the authorized officers must log into Security Manager and navigate to 
                      System Management > Security Manager Report. The Security Manager Report window
                      opens.
                  2 One of the authorized officers selects Officer 1. Half of the report prints automatically on the
                      Passport report printer.
                  3 The other authorized officer must log into Security Manager and navigate to 
                      System Management > Security Manager Report. The Security Manager Report window
                      opens.
4 The other authorized officer selects Officer 2. The second half of the report prints.
                      Changes to the following Administrator-level settings cause Security Manager to prompt the
                      user to print the Security Manager Report:
                        • Changing the User Name Admin password
                        • Manually rolling KEK
                        • Restoring the Key Storage Device Password
                        • Enabling System Security
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022        Page 7-9
Managing System Security                                                              7.3 System Management Options
                  When the user selects the Exit key from the Security Manager main window, the
                  Configuration has changed window prompts the user to print the Security Manager Report.
                  The user may take one of two actions:
                   • Select Yes to continue to print the Security Manager Report.
                   • Select No to exit Security Manager.
                  The Security Manager Report must be stored in a secure location and only accessed by
                  individuals authorized by the Merchant.
Page 7-10        MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
7.3 System Management Options                                                                  Managing System Security
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022       Page 7-11
Managing System Security                                                              7.3 System Management Options
(i) (ii)
(iii)
                  The normal operating mode is for the system to provide for automatic time synchronization.
                  Manual synchronization should be performed only if the system time was changed incorrectly
                  and needs to be adjusted. The current time on the EDH and the current time on the Passport
                  server are displayed along with a status line indicating the current state. The Sync Time To
                  EDH and Sync Time From EDH buttons are available for selection only if there is a difference
                  in the Date, Time, or Time Zone.
Page 7-12        MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
7.3 System Management Options                                                                  Managing System Security
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022       Page 7-13
Managing System Security                                                              7.3 System Management Options
(i) (ii)
Page 7-14        MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
7.3 System Management Options                                                                   Managing System Security
(i) (ii)
                      Selecting either Test Primary Host or Test Secondary Host will transmit the prior day’s audit
                      log to the selected host (Primary or Secondary). Figure 7-17 shows examples of a successful
                      and a failed test.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022        Page 7-15
Managing System Security                                                                           7.3 System Management Options
                  By default, hot fixes apply silently in the background between midnight and 4:00 A.M. on any
                  day of the week. If a reboot is required, the hot fix application pauses and waits for the
                  machine in question to be restarted, usually by the weekly watchdog process, before
                  continuing. The Hot Fix Configuration window allows the merchant to override these default
                  actions.
                  Field                           Description
                  Allow Hot Fixes to be applied   When selected, hot fixes will be applied in the background during the
                  in background                   configured time periods. When not selected, hot fixes will be applied as part of
                                                  the next Passport software package installation, thereby extending the
                                                  software package installation time. Field is selected by default.
                                                  Note: Gilbarco recommends that hot fixes be allowed to apply in the background.
                  Hot Fix Installation Days       Day(s) on which installation of hot fixes may occur. All days are selected by
                                                  default.
                  Hot Fix Installation Time       Time span in which installation of hot fixes may occur. Default settings are Start
                  Span                            time of 00:00:00 (midnight) and End time of 04:00:00.
                  Allow Full Control              If selected, the hot fix installation process will have full control to trigger any
                                                  required reboots. If not selected, the hot fix application process will pause if a
                                                  reboot is required and wait for the machine in question to be restarted, typically
                                                  by the weekly watchdog process. Field is not selected by default.
                                                  Note: Gilbarco recommends that Allow Full Control be selected only at sites that do
                                                        not trade 24 hours per day as it could interrupt trade.
                  Full Control Time Span Start,   Time period in which any reboot required by the hot fix installation process may
                  End times                       occur, when Allow Full Control is selected.
Page 7-16        MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
7.4 BIN Range Trapping                                                                            Managing System Security
                      Following are the card types on which BIN range trapping and decline occur:
                      Card Type                 Prefixes                           Account # Length
                      American Express          34, 37                                   15
                      Discover Card             6011, 622126-622925, 644-649, 65         16
                      JCB   ®                   3528-3589                                16
                      MasterCard                51-55                                    16
                      Visa                      4                                        16
                      Diners Club International® 36                                      14
                      The Security Audit Log can be accessed in the following four ways:
                       • The merchant can print the Security Audit Log for the current or previous day from the
                         EDHub menu within System Maintenance.
                       • The merchant can print an audit log for any of the previous 90 days from the EDH
                         dashboard.
                       • Audit logs from the last seven days are available in the Passport MWS/Server
                         XMLGateway directory for remote collection of logs.
                       • If configured, audit logs are pushed remotely to the configured server at the chosen time of
                         day.
                                         IMPORTANT INFORMATION
                       PCI DSS requires that the merchant review logs daily and maintain one year of audit data.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022           Page 7-17
Managing System Security                                                                            7.5 Security Audit Log
                  The Security Audit Log for the current and previous calendar day is available through Security
                  Manager in System Maintenance. To print the Security Audit Log, proceed as follows:
               1 From the MWS main screen, press the Ctrl, Alt, and P keys on the Passport keyboard
                  simultaneously. The System Maintenance Login window opens.
5 Select EDHub.
               7 To print current or today’s audit log, select Curr. Log. To print the previous day’s audit log,
                  select Prev. Log. The report prints automatically on the Passport MWS report printer.
                                     IMPORTANT INFORMATION
                   The audit log can only be printed from the MWS.
                                     IMPORTANT INFORMATION
                   Failure to retain required audit log data will result in non-compliance with PCI DSS.
Page 7-18        MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
7.6 Secure Data Storage Management                                                             Managing System Security
                      In situations where all secure data must be deleted, such as decommission, Merchants must
                      follow the instructions provided in “7.3.3.3 Disabling System Security” on page 7-6.
                      In the event the system is non-operational, the following information can be used to ensure all
                      secure data is removed from the system.
The iButton must be physically destroyed in order to remove the stored data.
                      Data in the embedded database can be removed either by physical destruction of the EDH hard
                      drive, or by using a secure delete tool to manually delete the database from the hard drive.
                      In general, the EDH handles the secure deletion of data automatically; however, in cases
                      where a manual secure deletion of data is required, Gilbarco provides instructions to the ASC
                      on how to use the Secure Delete Tool for the specific case in question.
                      The Secure Delete Tool is called sdelete. It is a command line utility that supports a number of
                      options. In a given use, it allows for the secure deletion of one or more files and directories. It
                      can also be used to cleanse free space on a logical disk. Sdelete accepts wild card characters as
                      part of the directory or file specifier.
                      where:
                      -c                        Zero free space (good for virtual disk optimization)
                      -p passes                 Specifies number of overwite passes
                      -s                        Recurse subdirectories
                      -z                        Cleanse free space
                                        IMPORTANT INFORMATION
                       The merchant must not use the Secure Delete Tool without the assistance of the ASC or
                       Gilbarco support personnel. For more information on the Secure Delete Tool, refer to MDE-4834
                       Passport V8.02+ System Recovery Guide.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022          Page 7-19
Managing System Security                                                                  7.7 Access to Clear Text PAN
                  Passport supports clear text PAN only as part of the Secure Report function. For information
                  on how to access and manage Secure Reports, refer to “Reports and Data Retention” on
                  page 4-1.
                  In all other cases where PAN is displayed or printed, such as manual entry, receipts, and
                  standard reports, a masked PAN is used.
                  EDH Secure Reports may contain unmasked cardholder data. Merchants using EDH Secure
                  Reports on other systems must be compliant with the PCI DSS controls listed in this section.
Page 7-20        MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
7.9 Replacing Hardware                                                                           Managing System Security
                                        IMPORTANT INFORMATION
                       Secure removal of cardholder data stored in previous installations of payment applications as
                       well as decommissioned EDH hardware is required for PCI DSS Compliance.
                      There are three EDH hardware replacement situations in which sensitive data must be
                      considered:
                        • Replacing the EDH hard drives
                        • Replacing the EDH compact flash card
                        • Replacing the entire EDH device
                      When replacing the hard drive or the compact flash card, the replaced device must be
                      destroyed physically before leaving the merchant location to ensure no sensitive data is
                      accessible.
                      When replacing the entire EDH device, the merchant must disable system security using the
                      Security Manager System Security function (refer to “7.3.3 System Security” on page 7-5).
                      Disabling security ensures no sensitive data remain on the EDH device. Migration and 
                      re-encryption of cardholder data from previous versions of Passport to the EDH is not
                      supported.
7.10 Troubleshooting
                      The EDH can log diagnostic information for troubleshooting purposes. Although none of the
                      Passport Logs contain unmasked cardholder data, PCI DSS guidelines require the following
                      actions to be taken when troubleshooting issues at a merchant location, when sensitive data is
                      going to be gathered.
                        • Logging must be enabled only for the period of time needed to gather the information.
                        • Logging must be disabled once data is gathered.
                        • Logging that was enabled and might contains sensitive data must be securely deleted when
                          it is no longer required.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022               Page 7-21
Managing System Security                                                                          7.10 Troubleshooting
Page 7-22        MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
                                                                                           Network Time Synchronization
                      The Passport EDH is capable of synchronizing the date and time of the system with a network
                      time server should it be required for Merchant PCI DSS compliance.
                                        IMPORTANT INFORMATION
                       Many payment network applications synchronize the date and time of the EDH to the
                       payment host. Prior to making changes, the merchant must confirm with the payment
                       network that enabling time synchronization will not disrupt transaction flow.
1 Create a Temporary Support Account and log in to the EDH using Remote Desktop.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022        Page 8-1
Network Time Synchronization
3 Select the Internet Time tab and from the Internet Time tab click Change settings.
                4 The Internet Time Settings screen opens. Select the Synchronize with an Internet time
                   server check box.
                5 Enter your time server information in the Server box or select one of the system provided time
                   servers from the drop-down list.
                7 After the synchronization is complete, select OK until you have exited out of Date and Time
                   settings.
                   In addition to the provided steps, the router must be modified to permit the EDH to access the
                   time server. For sites using an Acumera Secure Zone Router, dial 1-800-743-7501, and select
                   Option 3 and then Option 1 to have the SZR updated by Acumera. Otherwise contact the
                   MNSP for the site to have the change applied.
Page 8-2         MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
9.1 Audit Log Structure                                                                               Audit Log Definition
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022          Page 9-1
Audit Log Definition                                                                              9.1 Audit Log Structure
Page 9-2          MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
9.2 Audit Log Examples                                                                                Audit Log Definition
                      PCI DSS requirements define the actions which require log entries and the data elements
                      required to be logged for each of the actions.
                      The following audit log examples and the corresponding table entries provide information on
                      how to identify key elements from the audit log output.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022          Page 9-3
Audit Log Definition                                                                             9.2 Audit Log Examples
Page 9-4          MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
9.2 Audit Log Examples                                                                                Audit Log Definition
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022          Page 9-5
Audit Log Definition                                                                             9.2 Audit Log Examples
Page 9-6          MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
                                                                                       Supported Hardware and Software
                      The Passport PA-DSS certification was performed using Gilbarco hardware and software in
                      conjunction with supported indoor PIN Pad hardware. Failure to use approved hardware and
                      software may invalidate the Passport system’s PA-DSS compliance and can impact the
                      merchant’s overall PCI DSS compliance.
                      The following table lists the hardware and software that are valid for use in a PA-DSS certified
                      Passport installation.
                      Note: Only hardware and software relevant to PA-DSS certification is listed. Any hardware
                            and software not in scope for PA-DSS certification, such as Back Office PC are not
                            included.
                      Device                                 Application Version
                      Passport EDH                            •    11.23.01.01
                                                              •    11.23.02.01
                                                              •    11.23.04.01
                                                              •    11.23.06.01
                                                              •    11.23.07.01
                      Passport MWS/CWS                        •    20.01.23.XX
                                                              •    20.02.23.XX
                                                              •    20.04.23.XX
                                                              •    21.02.23.XX
                                                              •    21.03.23.XX
                      The merchant is responsible for ensuring that only payment terminals approved under their
                      PCI DSS certification are deployed as part of the Passport install.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022      Page 10-1
Supported Hardware and Software
Page 10-2       MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
11.1 Versioning Methodology                                                             Software Versioning Methodology
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022       Page 11-1
Software Versioning Methodology                                                          11.2 PA-DSS Version Mapping
Page 11-2       MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
12.1 Wireless Technologies                                                                               Prohibited Interfaces
12 – Prohibited Interfaces
                                        IMPORTANT INFORMATION
                       The merchant or ASC must not install the EDH in a wireless environment.
                       A merchant who chooses to install a wireless environment must install and configure a
                       secure firewall to isolate cardholder data per PCI DSS requirements. The merchant must
                       also change all wireless default encryption keys, passwords and Simple Network
                       Management Protocol (SNMP) community strings upon installation and any time anyone
                       with knowledge of the keys or passwords leaves the company or changes positions.
                       Merchants using wireless networks are advised to follow industry best practices [for
                       example, Institute of Electrical and Electronics Engineers (IEEE) 802.11.i] to provide
                       strong encryption for authentication and transmission.
                      The EDH does not support a direct Internet connection. Implementing the EDH with a direct
                      connection to the Internet violates the product’s PA-DSS compliance and the merchant’s 
                      PCI-DSS compliance.
                                        IMPORTANT INFORMATION
                       The merchant or ASC must not install the EDH with a direct Internet connection.
                       A merchant who chooses to support direct Internet connectivity at the location must
                       secure the connection by firewall and configure according to PCI DSS requirements.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022             Page 12-1
Prohibited Interfaces                                                      12.3 Transmission of Data over Public Networks
                                         IMPORTANT INFORMATION
                        The merchant or ASC must not install the EDH in an environment where sensitive data is
                        transmitted directly from the EDH over a public network. If a merchant chooses to
                        transmit sensitive data over a public network, the use of secure encryption transmission
                        technology, that is IP security (IPsec), VPN, or Transport Layer Security (TLS), is
                        required.
                        A merchant who supports public network connections must refer to PCI DSS requirements 
                        for information to properly transmit data over public networks.
                                         IMPORTANT INFORMATION
                        PCI DSS requirements prohibit transmission of unencrypted cardholder data using 
                        email or other end-user messaging technologies.
Page 12-2        MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
                                                                                    Network Communication Requirements
                      The following tables detail the services and ports used by the EDH to communicate across
                      network zones.
                      Protocol                   Port(s)              Description
                      Automated Software Update 5802                  Used to update software on the EDH.
                      Gilbarco File Transfer     5810                 Used to transfer logs and reports from the EDH to the
                      Service                                         Manager Workstation.
                      Gripps                     7000/7001            Primary interface between the EDH and Manager
                                                                      Workstation for communications.
                      Microsoft Proprietary      49152                Diagnostic interfaces used to support shutdown, as well as,
                                                 49153                task and event viewing.
                                                 49154
                                                 49155
                      Fiserv Payment Interface   Customer and         Primary protocol used for transaction processing to the
                                                 Implementation       payment processor
                                                 Dependent
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022                 Page 13-1
Network Communication Requirements
Page 13-2      MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
                                                                                                                             System Services
14 – System Services
                      The following table details the System Services utilized on the Passport EDH. All services are
                      system managed and do not require any user configuration or maintenance.
                      Service                 Description
                       ActiveX Installer      Provides User Account Control validation for the installation of ActiveX controls from the
                       (AxInstSV)             Internet and enables management of ActiveX control installation based on Group Policy
                                              settings. This service is started on demand and if disabled the installation of ActiveX controls
                                              will behave according to default browser settings.
                       Adaptive               Monitors ambient light sensors to detect changes in ambient light and adjust the display
                       Brightness             brightness. If this service is stopped or disabled, the display brightness will not adapt to
                                              lighting conditions.
                       Application            Processes application compatibility cache requests for applications as they are launched.
                       Experience
                       Application Identity   Determines and verifies the identity of an application. Disabling this service will prevent
                                              AppLocker from being enforced.
                       Application            Facilitates the running of interactive applications with additional administrative privileges. If
                       Information            this service is stopped, users will be unable to launch applications with the additional
                                              administrative privileges they may require to perform desired user tasks.
                       Application Layer      Provides support for third-party protocol plug-ins for Internet Connection Sharing (ICS).
                       Gateway Service
                       Application            Processes installation, removal, and enumeration requests for software deployed through
                       Management             Group Policy. If the service is disabled, users will be unable to install, remove, or enumerate
                                              software deployed through Group Policy. If this service is disabled, any services that explicitly
                                              depend on it will fail to start.
                       ASU                    (Gilbarco) Automated Software Upgrade
                       ASP.NET State          Provides support for out-of-process session states for ASP.NET. If this service is stopped, 
                       Service                out-of-process requests will not be processed. If this service is disabled, any services that
                                              explicitly depend on it will fail to start.
                       Background             Transfers files in the background using idle network bandwidth. If the service is disabled,
                       Intelligent Transfer   then any applications that depend on BITS, such as Windows Update or MSN® Explorer, will
                       Service (BITS)         be unable to automatically download programs and other information.
                       Base Filtering         The Base Filtering Engine (BFE) is a service that manages firewall and IPsec policies and
                       Engine                 implements user mode filtering. Stopping or disabling the BFE service will significantly
                                              reduce the security of the system. It will also result in unpredictable behavior in IPsec
                                              management and firewall applications.
                       Bit9 Agent             Monitors system activity to keep your computer safe from unwanted and potentially malicious
                                              software.
                       BitLocker Drive        BitLocker Drive Encryption Service (BDESVC) hosts the BitLocker Drive Encryption service.
                       Encryption Service     BitLocker Drive Encryption provides secure startup for the operating system, as well as full
                                              volume encryption for OS, fixed or removable volumes. This service allows BitLocker to
                                              prompt users for various actions related to their volumes when mounted, and unlocks
                                              volumes automatically without user interaction. Additionally, it stores recovery information to
                                              Active Directory, if available, and, if necessary, ensures the most recent recovery certificates
                                              are used. Stopping or disabling the service would prevent users from leveraging this
                                              functionality.
                       Block Level            The WBENGINE service is used by Windows Backup to perform backup and recovery
                       Backup Engine          operations. If this service is stopped by a user, it may cause the currently running backup or
                       Service                recovery operation to fail. Disabling this service may disable backup and recovery operations
                                              using Windows Backup on this computer.
                       Bluetooth® Support     The Bluetooth service supports discovery and association of remote Bluetooth devices.
                       Service                Stopping or disabling this service may cause already installed Bluetooth devices to fail to
                                              operate properly and prevent new devices from being discovered or associated.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022                               Page 14-1
System Services
                     Service              Description
                     BranchCache          This service caches network content from peers on the local subnet.
                     Certificate          Copies user certificates and root certificates from smart cards into the current user's
                     Propagation          certificate store, detects when a smart card is inserted into a smart card reader, installs the
                                          smart card Plug and Play (PnP) minidriver if needed.
                     Client for NFS       Enables this computer to access files on Network File System (NFS) shares.
                     CNG Key Isolation    The CNG key isolation service is hosted in the Local Security Authority (LSA) process. The
                                          service provides key process isolation to private keys and associated cryptographic
                                          operations as required by the Common Criteria. The service stores and uses long-lived keys
                                          in a secure process complying with Common Criteria requirements.
                     COM+ Event           Supports System Event Notification Service (SENS), which provides automatic distribution of
                     System               events to subscribing Component Object Model (COM) components. If the service is
                                          stopped, SENS will close and will not be able to provide logon and logoff notifications. If this
                                          service is disabled, any services that explicitly depend on it will fail to start.
                     COM+ System          Manages the configuration and tracking of COM+-based components. If the service is
                     Application          stopped, most COM+-based components will not function properly. If this service is disabled,
                                          any services that explicitly depend on it will fail to start.
                     Computer Browser     Maintains an updated list of computers on the network and supplies this list to computers
                                          designated as browsers. If this service is stopped, this list will not be updated or maintained.
                                          If this service is disabled, any services that explicitly depend on it will fail to start.
                     Credential           Provides secure storage and retrieval of credentials to users, applications, and security
                     Manager              service packages.
                     Cryptographic        Provides four management services: Catalog Database Service, which confirms the
                     Services             signatures of Windows files and allows new programs to be installed; Protected Root
                                          Service, which adds and removes Trusted Root Certification Authority certificates from this
                                          computer; Automatic Root Certificate Update Service, which retrieves root certificates from
                                          Windows Update and enable scenarios such as TLS; and Key Service, which helps enroll
                                          this computer for certificates. If this service is stopped, these management services will not
                                          function properly. If this service is disabled, any services that explicitly depend on it will fail to
                                          start.
                     DCOM Server          The DCOMLAUNCH service launches COM and Distributed COM (DCOM) servers in
                     Process Launcher     response to object activation requests. If this service is stopped or disabled, programs using
                                          COM or DCOM will not function properly. It is strongly recommended that you have the
                                          DCOMLAUNCH service running.
                     Desktop Window       Provides Desktop Window Manager startup and maintenance services.
                     Manager Session
                     Manager
                     Dynamic Host         Registers and updates IP addresses and Domain Name System (DNS) records for this
                     Configuration        computer. If this service is stopped, this computer will not receive dynamic IP addresses and
                     Protocol (DHCP)      DNS updates. If this service is disabled, any services that explicitly depend on it will fail to
                     Client               start.
                     Diagnostic Policy    The Diagnostic Policy Service enables problem detection, troubleshooting and resolution for
                     Service              Windows components. If this service is stopped, diagnostics will no longer function.
                     Diagnostic Service   The Diagnostic Service Host is used by the Diagnostic Policy Service to host diagnostics that
                     Host                 need to run in a Local Service context. If this service is stopped, any diagnostics that depend
                                          on it will no longer function.
                     Diagnostic System    The Diagnostic System Host is used by the Diagnostic Policy Service to host diagnostics that
                     Host                 need to run in a Local System context. If this service is stopped, any diagnostics that depend
                                          on it will no longer function.
                     Dialog Box Filter    Prevents dialogs and windows from blocking or interfering with the primary user interface.
                     Disk Defragmenter    Provides Disk Defragmentation Capabilities.
                     Distributed Link     Maintains links between New Technology File System (NTFS) files within a computer or
                     Tracking Client      across computers in a network.
                     Distributed          Coordinates transactions that span multiple resource managers, such as databases,
                     Transaction          message queues, and file systems. If this service is stopped, these transactions will fail. If
                     Coordinator          this service is disabled, any services that explicitly depend on it will fail to start.
Page 14-2         MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
                                                                                                                             System Services
                      Service                Description
                       DNS Client            The DNS Client service (dnscache) caches DNS names and registers the full computer
                                             name for this computer. If the service is stopped, DNS names will continue to be resolved.
                                             However, the results of DNS name queries will not be cached and the computer's name will
                                             not be registered. If the service is disabled, any services that explicitly depend on it will fail to
                                             start.
                       EDH                   (Gilbarco) Starts the Gripps service and NGCrind, monitors the Gripps service and Fuel
                                             Subsystems, and Stop Gripps and Fuel when Stopped. Also ensures System Recovery and
                                             the EdhSQLStartMonitor has run at start.
                       Encrypting File       Provides the core file encryption technology used to store encrypted files on NTFS file
                       System (EFS)          system volumes. If this service is stopped or disabled, applications will be unable to access
                                             encrypted files.
                       EventLogMonitor       (Gilbarco) Event Log Monitor writes Windows Events to a text file included in Audit Logging.
                       Extensible            The Extensible Authentication Protocol (EAP) service provides network authentication in
                       Authentication        such scenarios as 802.1x wired and wireless, VPN, and Network Access Protection (NAP).
                       Protocol              EAP also provides Application Programming Interfaces (APIs) that are used by network
                                             access clients, including wireless and VPN clients, during the authentication process. If you
                                             disable this service, this computer is prevented from accessing networks that require EAP
                                             authentication.
                       Fiserv/First Data     Provides notifications for AutoPlay hardware events.
                       Hardware
                       Detection
                       Function Discovery    The FDPHOST service hosts the Function Discovery (FD) network discovery providers.
                       Provider Host         These FD providers supply network discovery services for the Simple Services Discovery
                                             Protocol (SSDP) and Web Services - Discovery (WS-D) protocol. Stopping or disabling the
                                             FDPHOST service will disable network discovery for these protocols when using FD. When
                                             this service is unavailable, network services using FD and relying on these discovery
                                             protocols will be unable to find network devices or resources.
                       Function Discovery    Publishes this computer and resources attached to this computer so they can be discovered
                       Resource              over the network. If this service is stopped, network resources will no longer be published
                       Publication           and they will not be discovered by other computers on the network.
                       GDSSVC                Gilbarco Deployment Service used for Deployment and Diagnostics.
                       GIAFramework          (Gilbarco) GIA Publish/Subscribe Framework
                       Gilbarco Secure       (Gilbarco) Manager of iButton Encryption Services
                       CF Card Manager
                       GilbarcoScheduler     (Gilbarco) System Task/Job Scheduler
                       Gripps                (Gilbarco) Generic Retail Payment Processor System.
                       Group Policy Client   The service is responsible for applying settings configured by administrators for the computer
                                             and users through the Group Policy component. If the service is stopped or disabled, the
                                             settings will not be applied and applications and components will not be manageable through
                                             Group Policy. Any components or applications that depend on the Group Policy component
                                             might not be functional if the service is stopped or disabled.
                       GVR Diag              Gilbarco Diagnostics Service
                       GVRFTS                Gilbarco File Transfer Service
                       Health Key and        Provides X.509 certificate and key management services for the NAPAgent. Enforcement
                       Certificate           technologies that use X.509 certificates may not function properly without this service.
                       Management
                       HomeGroup             Makes local computer changes associated with configuration and maintenance of the
                       Listener              homegroup-joined computer. If this service is stopped or disabled, your computer will not
                                             work properly in a homegroup and your homegroup might not work properly. It is
                                             recommended that you keep this service running.
                       HomeGroup             Performs networking tasks associated with configuration and maintenance of homegroups. If
                       Provider              this service is stopped or disabled, your computer will be unable to detect other homegroups
                                             and your homegroup might not work properly. It is recommended that you keep this service
                                             running.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022                                Page 14-3
System Services
                     Service              Description
                     Human Interface      Enables generic input access to Human Interface Devices (HID), which activates and
                     Device Access        maintains the use of predefined hot buttons on keyboards, remote controls, and other
                                          multimedia devices. If this service is stopped, hot buttons controlled by this service will no
                                          longer function. If this service is disabled, any services that explicitly depend on it will fail to
                                          start.
                     IKE and AuthIP       The IKEEXT service hosts the Internet Key Exchange (IKE) and Authenticated Internet
                     IPsec Keying         Protocol (AuthIP) keying modules. These keying modules are used for authentication and
                     Modules              key exchange in IPsec. Stopping or disabling the IKEEXT service will disable IKE and AuthIP
                                          key exchange with peer computers. IPsec is typically configured to use IKE or AuthIP;
                                          therefore, stopping or disabling the IKEEXT service might result in an IPsec failure and might
                                          compromise the security of the system. It is strongly recommended that you have the
                                          IKEEXT service running.
                     Indexing Service     Indexes contents and properties of files on local and remote computers; provides rapid
                                          access to files through flexible querying language.
                     Interactive          Enables user notification of user input for interactive services, which enables access to
                     Services Detection   dialogs created by interactive services when they appear. If this service is stopped,
                                          notifications of new interactive service dialogs will no longer function and there might not be
                                          access to interactive service dialogs. If this service is disabled, both notifications of and
                                          access to new interactive service dialogs will no longer function.
                     Internet             Provides network address translation, addressing, name resolution and/or intrusion
                     Connection           prevention services for a home or small office network.
                     Sharing
                     IP Helper            Provides tunnel connectivity using IPv6 transition technologies (6to4, ISATAP, Port Proxy,
                                          and Teredo), and Internet Protocol-Secure Hypertext Transfer Protocol (IP-HTTPS). If this
                                          service is stopped, the computer will not have the enhanced connectivity benefits that these
                                          technologies offer.
                     IPsec Policy Agent   Internet Protocol security (IPsec) supports network-level peer authentication, data origin
                                          authentication, data integrity, data confidentiality (encryption), and replay protection. This
                                          service enforces IPsec policies created through the IP Security Policies snap-in or the
                                          command-line tool “netsh ipsec”. If you stop this service, you may experience network
                                          connectivity issues if your policy requires that connections use IPsec. Also, remote
                                          management of Windows Firewall is not available when this service is stopped.
                     Keyboard Filter      Controls keystroke filtering and mapping.
                     KtmRm for            Coordinates transactions between the Microsoft Distributed Transaction Coordinator
                     Distributed          (MSDTC) and the Kernel Transaction Manager (KTM). If it is not needed, it is recommended
                     Transaction          that this service remain stopped. If it is needed, both MSDTC and KTM will start this service
                     Coordinator          automatically. If this service is disabled, any MSDTC transaction interacting with a Kernel
                                          Resource Manager will fail and any services that explicitly depend on it will fail to start.
                     Link-Layer           Creates a Network Map, consisting of PC and device topology (connectivity) information, and
                     Topology             metadata describing each PC and device. If this service is disabled, the Network Map will not
                     Discovery Mapper     function properly.
                     LPD Service          Enables client computers to print to the Line Printer Daemon (LPD) service on this server
                                          using TCP/IP and the Line Printer Remote (LPR) protocol.
                     Microsoft .NET       Microsoft .NET Framework NGEN
                     Framework NGEN
                     v2.0.50727_X86
                     Microsoft .NET       Microsoft .NET Framework NGEN
                     Framework NGEN
                     v4.0.30319_X86
                     Microsoft iSCSI      Manages Internet Small Computer System Interface (iSCSI) sessions from this computer to
                     Initiator Service    remote iSCSI target devices. If this service is stopped, this computer will not be able to log in
                                          or access iSCSI targets. If this service is disabled, any services that explicitly depend on it
                                          will fail to start.
                     Microsoft Software   Manages software-based volume shadow copies taken by the Volume Shadow Copy
                     Shadow Copy          service. If this service is stopped, software-based volume shadow copies cannot be
                     Provider             managed. If this service is disabled, any services that explicitly depend on it will fail to start.
Page 14-4         MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
                                                                                                                               System Services
                      Service                Description
                       Multimedia Class      Enables relative prioritization of work based on system-wide task priorities. This is intended
                       Scheduler             mainly for multimedia applications. If this service is stopped, individual tasks resort to their
                                             default priority.
                       Net.Msmq Listener     Receives activation requests over the net.msmq and msmq.formatname protocols and
                       Adapter               passes them to the Windows Process Activation Service.
                       Net.Pipe Listener     Receives activation requests over the net.pipe protocol and passes them to the Windows
                       Adapter               Process Activation Service.
                       Net.Tcp Listener      Receives activation requests over the net.tcp protocol and passes them to the Windows
                       Adapter               Process Activation Service.
                       Net.Tcp Port          Provides ability to share TCP ports over the net.tcp protocol.
                       Sharing Service
                       Netlogon              Maintains a secure channel between this computer and the domain controller for
                                             authenticating users and services. If this service is stopped, the computer may not
                                             authenticate users and services and the domain controller cannot register DNS records. If
                                             this service is disabled, any services that explicitly depend on it will fail to start.
                       Network Access        The NAP agent service collects and manages health information for client computers on a
                       Protection Agent      network. Information collected by NAP agent is used to make sure that the client computer
                                             has the required software and settings. If a client computer is not compliant with health policy,
                                             it can be provided with restricted network access until its configuration is updated. Depending
                                             on the configuration of health policy, client computers might be automatically updated so that
                                             users quickly regain full network access without having to manually update their computer.
                       Network               Manages objects in the Network and Dial-Up Connections folder, in which you can view both
                       Connections           local area network and remote connections.
                       Network List          Identifies the networks to which the computer has connected, collects and stores properties
                       Service               for these networks, and notifies applications when these properties change.
                       Network Location      Collects and stores configuration information for the network and notifies programs when this
                       Awareness             information is modified. If this service is stopped, configuration information might be
                                             unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
                       Network Store         This service delivers network notifications (e.g. interface addition/deleting, etc.) to user mode
                       Interface Service     clients. Stopping this service will cause loss of network connectivity. If this service is
                                             disabled, any other services that explicitly depend on this service will fail to start.
                       Offline Files         The Offline Files service performs maintenance activities on the Offline Files cache,
                                             responds to user logon and logoff events, implements the internals of the public API, and
                                             dispatches interesting events to those interested in Offline Files activities and changes in
                                             cache state.
                       Peer Name             Enables serverless peer name resolution over the Internet using the Peer Name Resolution
                       Resolution Protocol   Protocol (PNRP). If disabled, some peer-to-peer and collaborative applications, such as
                                             Remote Assistance, may not function.
                       Peer Networking       Enables multi-party communication using Peer-to-Peer Grouping. If disabled, some
                       Grouping              applications, such as HomeGroup, may not function.
                       Peer Networking       Provides identity services for the PNRP and Peer-to-Peer Grouping services. If disabled, the
                       Identity Manager      PNRP and Peer-to-Peer Grouping services may not function, and some applications, such as
                                             HomeGroup and Remote Assistance, may not function correctly.
                       Performance Logs      Performance Logs and Alerts Collects performance data from local or remote computers
                       & Alerts              based on preconfigured schedule parameters, then writes the data to a log or triggers an
                                             alert. If this service is stopped, performance information will not be collected. If this service is
                                             disabled, any services that explicitly depend on it will fail to start.
                       Plug and Play         Enables a computer to recognize and adapt to hardware changes with little or no user input.
                                             Stopping or disabling this service will result in system instability.
                       PnP-X IP Bus          The PnP-X bus enumerator service manages the virtual network bus. It discovers network
                       Enumerator            connected devices using the SSDP/WS discovery protocols and gives them presence in PnP.
                                             If this service is stopped or disabled, presence of Network Computing Device (NCD) devices
                                             will not be maintained in PnP. All pnpx based scenarios will stop functioning.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022                                 Page 14-5
System Services
                     Service              Description
                     PNRP Machine         This service publishes a machine name using the PNRP. Configuration is managed via the
                     Name Publication     netsh context ‘p2p pnrp peer’.
                     Service
                     Portable Device      Enforces group policy for removable mass-storage devices. Enables applications such as
                     Enumerator           Windows Media Player and Image Import Wizard to transfer and synchronize content using
                     Service              removable mass-storage devices.
                     Power                Manages power policy and power policy notification delivery.
                     Print Spooler        Loads files to memory for later printing.
                     Problem Reports      This service provides support for viewing, sending and deletion of system-level problem
                     and Solutions        reports for the Problem Reports and Solutions control panel.
                     Control Panel
                     Support
                     Program              This service provides support for the Program Compatibility Assistant (PCA). PCA monitors
                     Compatibility        programs installed and run by the user and detects known compatibility problems. If this
                     Assistant Service    service is stopped, PCA will not function properly.
                     Protected Storage    Provides protected storage for sensitive data, such as passwords, to prevent access by
                                          unauthorized services, processes, or users.
                     Quality Windows      Quality Windows Audio Video Experience (qWave) is a networking platform for Audio Video
                     Audio Video          (AV) streaming applications on IP home networks. qWave enhances AV streaming
                     Experience           performance and reliability by ensuring network Quality-of-Service (QoS) for AV applications.
                                          It provides mechanisms for admission control, run time monitoring and enforcement,
                                          application feedback, and traffic prioritization.
                     Remote Access        Creates a connection to a remote network whenever a program references a remote DNS or
                     Auto Connection      NetBIOS name or address.
                     Manager
                     Remote Access        Manages dial-up and VPN connections from this computer to the Internet or other remote
                     Connection           networks. If this service is disabled, any services that explicitly depend on it will fail to start.
                     Manager
                     Remote Desktop       Remote Desktop Configuration service (RDCS) is responsible for all Remote Desktop
                     Configuration        Services and Remote Desktop (RD) related configuration and session maintenance activities
                                          that require SYSTEM context. These include per-session temporary folders, RD themes, and
                                          RD certificates.
                     Remote Desktop       Allows users to connect interactively to a remote computer. Remote Desktop and Remote
                     Services             Desktop Session Host Server depend on this service. To prevent remote use of this
                                          computer, clear the check boxes on the Remote tab of the System properties control panel
                                          item.
                     Remote Desktop       Allows the redirection of Printers/Drives/Ports for RDP connections.
                     Services
                     UserMode Port
                     Redirector
                     Remote Procedure     The RPCSS service is the Service Control Manager for COM and DCOM servers. It performs
                     Call (RPC)           object activations requests, object exporter resolutions and distributed garbage collection for
                                          COM and DCOM servers. If this service is stopped or disabled, programs using COM or
                                          DCOM will not function properly. It is strongly recommended that you have the RPCSS
                                          service running.
                     Remote Procedure     In Windows 2003 and earlier versions of Windows, the RPC Locator service manages the
                     Call (RPC) Locator   RPC name service database. In Windows Vista™ and later versions of Windows, this service
                                          does not provide any functionality and is present for application compatibility.
                     Remote Registry      Enables remote users to modify registry settings on this computer. If this service is stopped,
                                          the registry can be modified only by users on this computer. If this service is disabled, any
                                          services that explicitly depend on it will fail to start.
                     RIP Listener         Listens for route updates sent by routers that use the Routing Information Protocol version 1
                                          (RIPv1).
                     Routing and          Offers routing services to businesses in local area and wide area network environments.
                     Remote Access
Page 14-6         MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
                                                                                                                         System Services
                      Service               Description
                       RPC Endpoint         Resolves RPC interfaces identifiers to transport endpoints. If this service is stopped or
                       Mapper               disabled, programs using RPC services will not function properly.
                       Secondary Logon      Enables starting processes under alternate credentials. If this service is stopped, this type of
                                            logon access will be unavailable. If this service is disabled, any services that explicitly
                                            depend on it will fail to start.
                       Secure Socket        Provides support for the Secure Socket Tunneling Protocol (SSTP) to connect to remote
                       Tunneling Protocol   computers using VPN. If this service is disabled, users will not be able to use SSTP to
                       Service              access remote servers.
                       Security Accounts    The startup of this service signals other services that the Security Accounts Manager (SAM)
                       Manager              is ready to accept requests. Disabling this service will prevent other services in the system
                                            from being notified when the SAM is ready, which may in turn cause those services to fail to
                                            start correctly. This service should not be disabled.
                       Security Center      The Windows Security Center Service (WSCSVC) monitors and reports security health
                                            settings on the computer. The health settings include firewall (on/off), antivirus (on/off/out of
                                            date), antispyware (on/off/out of date), Windows Update (automatically/manually download
                                            and install updates), User Account Control (on/off), and Internet settings (recommended/not
                                            recommended). The service provides COM APIs for independent software vendors to
                                            register and record the state of their products to the Security Center service. The Action
                                            Center (AC) User Interface (UI) uses the service to provide systray alerts and a graphical
                                            view of the security health states in the AC control panel. NAP uses the service to report the
                                            security health states of clients to the NAP Network Policy Server to make network
                                            quarantine decisions. The service also has a public API that allows external consumers to
                                            programmatically retrieve the aggregated security health state of the system.
                       Server               Supports file, print, and named-pipe sharing over the network for this computer. If this service
                                            is stopped, these functions will be unavailable. If this service is disabled, any services that
                                            explicitly depend on it will fail to start.
                       Simple TCP/IP        Supports the following TCP/IP services: Character Generator, Daytime, Discard, Echo, and
                       Services             Quote of the Day.
                       Smart Card           Manages access to smart cards read by this computer. If this service is stopped, this
                                            computer will be unable to read smart cards. If this service is disabled, any services that
                                            explicitly depend on it will fail to start.
                       Smart Card           Allows the system to be configured to lock the user desktop upon smart card removal.
                       Removal Policy
                       SMIService           (Gilbarco) Secure Management Interface
                       SNMP Service         Enables Simple Network Management Protocol (SNMP) requests to be processed by this
                                            computer. If this service is stopped, the computer will be unable to process SNMP requests.
                                            If this service is disabled, any services that explicitly depend on it will fail to start.
                       SNMP Trap            Receives trap messages generated by local or remote SNMP agents and forwards the
                                            messages to SNMP management programs running on this computer. If this service is
                                            stopped, SNMP-based programs on this computer will not receive SNMP trap messages. If
                                            this service is disabled, any services that explicitly depend on it will fail to start.
                       Software             Enables the download, installation and enforcement of digital licenses for Windows and
                       Protection           Windows applications. If the service is disabled, the operating system and licensed
                                            applications may run in a notification mode. It is strongly recommended that you not disable
                                            the Software Protection service.
                       SPP Notification     Provides Software Licensing activation and notification.
                       Service
                       SQL Active           Enables integration with Active Directories.
                       Directory Helper
                       Service
                       SQL Server           Provides storage, processing and controlled access of data, and rapid transaction
                       (MSSQLSERVER)        processing.
                       SQL Server Agent     Executes jobs, monitors Structured Query language (SQL) Server, fires alerts, and allows
                       (MSSQLSERVER)        automation of some administrative tasks.
                       SQL Server           Provides SQL Server connection information to client computers.
                       Browser
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022                            Page 14-7
System Services
                     Service                Description
                     SQL Server VSS         Provides the interface to backup/restore Microsoft SQL server through the Windows Volume
                     Writer                 Shadow Copy Service (VSS) infrastructure.
                     SSDP Discovery         Discovers networked devices and services that use the SSDP discovery protocol, such as
                                            UPnP devices. Also announces SSDP devices and services running on the local computer. If
                                            this service is stopped, SSDP-based devices will not be discovered. If this service is
                                            disabled, any services that explicitly depend on it will fail to start.
                     StartProcSvc           (Gilbarco) Startup Processor for ASU Services.
                     Superfetch             Maintains and improves system performance over time.
                     SyslogServer           SYSLOG server which saves log entries to an SQL database.
                     SysRecoverySvc         Starts the System Recovery application and exits on completion.
                     System Event           Monitors system events and notifies subscribers to COM+ Event System of these events.
                     Notification Service
                     Task Scheduler         Enables a user to configure and schedule automated tasks on this computer. The service
                                            also hosts multiple Windows system-critical tasks. If this service is stopped or disabled, these
                                            tasks will not be run at their scheduled times. If this service is disabled, any services that
                                            explicitly depend on it will fail to start.
                     TCP/IP NetBIOS         Provides support for the NetBIOS over TCP/IP (NetBT) service and NetBIOS name
                     Helper                 resolution for clients on the network, therefore enabling users to share files, print, and log on
                                            to the network. If this service is stopped, these functions might be unavailable. If this service
                                            is disabled, any services that explicitly depend on it will fail to start.
                     Telephony              Provides Telephony API (TAPI) support for programs that control telephony devices on the
                                            local computer and, through the LAN, on servers that are also running the service.
                     Telnet                 Enables a remote user to log on to this computer and run programs, and supports various
                                            TCP/IP Telnet clients, including UNIX-based and Windows-based computers. If this service
                                            is stopped, remote user access to programs might be unavailable. If this service is disabled,
                                            any services that explicitly depend on it will fail to start.
                     Themes                 Provides user experience theme management.
                     Thread Ordering        Provides ordered execution for a group of threads within a specific period of time.
                     Server
                     TPM Base               Enables access to the Trusted Platform Module (TPM), which provides hardware-based
                     Services               cryptographic services to system components and applications. If this service is stopped or
                                            disabled, applications will be unable to use keys protected by the TPM.
                     UPnP Device Host       Allows Universal PnP (UPnP) devices to be hosted on this computer. If this service is
                                            stopped, any hosted UPnP devices will stop functioning and no additional hosted devices
                                            can be added. If this service is disabled, any services that explicitly depend on it will fail to
                                            start.
                     User Profile           This service is responsible for loading and unloading user profiles. If this service is stopped
                     Service                or disabled, users will no longer be able to successfully logon or logoff, applications may
                                            have problems getting to users’ data, and components registered to receive profile event
                                            notifications will not receive them.
                     Virtual Disk           Provides management services for disks, volumes, file systems, and storage arrays.
                     Volume Shadow          Manages and implements Volume Shadow Copies used for backup and other purposes. If
                     Copy                   this service is stopped, shadow copies will be unavailable for backup and the backup may
                                            fail. If this service is disabled, any services that explicitly depend on it will fail to start.
                     WebClient              Enables Windows-based programs to create, access, and modify Internet-based files. If this
                                            service is stopped, these functions will not be available. If this service is disabled, any
                                            services that explicitly depend on it will fail to start.
                     Windows Audio          Manages audio for Windows-based programs. If this service is stopped, audio devices and
                                            effects will not function properly. If this service is disabled, any services that explicitly depend
                                            on it will fail to start.
                     Windows Audio          Manages audio devices for the Windows Audio service. If this service is stopped, audio
                     Endpoint Builder       devices and effects will not function properly. If this service is disabled, any services that
                                            explicitly depend on it will fail to start.
                     Windows Backup         Provides Windows Backup and Restore capabilities.
Page 14-8         MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
                                                                                                                          System Services
                      Service               Description
                       Windows Biometric    The Windows biometric service gives client applications the ability to capture, compare,
                       Service              manipulate, and store biometric data without gaining direct access to any biometric hardware
                                            or samples. The service is hosted in a privileged SVCHOST process.
                       Windows              Securely enables the creation, management, and disclosure of digital identities.
                       CardSpace
                       Windows Color        The WcsPlugInService service hosts third-party Windows Color System color device model
                       System               and gamut map model plug-in modules. These plug-in modules are vendor-specific
                                            extensions to the Windows Color System baseline color device and gamut map models.
                                            Stopping or disabling the WcsPlugInService service will disable this extensibility feature, and
                                            the Windows Color System will use its baseline model processing rather than the vendor's
                                            desired processing. This might result in inaccurate color rendering.
                       Windows Defender     Protection against spyware and potentially unwanted software.
                       Windows Driver       Manages user-mode driver host processes.
                       Foundation - 
                       User-mode Driver
                       Framework
                       Windows Error        Allows errors to be reported when programs stop working or responding and allows existing
                       Reporting Service    solutions to be delivered. Also allows logs to be generated for diagnostic and repair services.
                                            If this service is stopped, error reporting might not work correctly and results of diagnostic
                                            services and repairs might not be displayed.
                       Windows Event        This service manages persistent subscriptions to events from remote sources that support
                       Collector            WS-Management protocol. This includes Windows Vista event logs, hardware and 
                                            IPMI-enabled event sources. The service stores forwarded events in a local Event Log. If this
                                            service is stopped or disabled event subscriptions cannot be created and forwarded events
                                            cannot be accepted.
                       Windows Event        This service manages events and event logs. It supports logging events, querying events,
                       Log                  subscribing to events, archiving event logs, and managing event metadata. It can display
                                            events in both XML and plain text format. Stopping this service may compromise security and
                                            reliability of the system.
                       Windows Firewall     Windows Firewall helps protect your computer by preventing unauthorized users from
                                            gaining access to your computer through the Internet or a network.
                       Windows Font         Optimizes performance of applications by caching commonly used font data. Applications will
                       Cache Service        start this service if it is not already running. It can be disabled, though doing so will degrade
                                            application performance.
                       Windows Image        Provides image acquisition services for scanners and cameras.
                       Acquisition (WIA)
                       Windows Installer    Adds, modifies, and removes applications provided as a Windows Installer (*.msi) package. If
                                            this service is disabled, any services that explicitly depend on it will fail to start.
                       Windows Licensing    This service monitors the Windows software license state.
                       Monitoring Service
                       Windows              Provides a common interface and object model to access management information about
                       Management           operating system, devices, applications and services. If this service is stopped, most
                       Instrumentation      Windows-based software will not function properly. If this service is disabled, any services
                                            that explicitly depend on it will fail to start.
                       Windows Media        Shares Windows Media Player libraries to other networked players and media devices using
                       Player Network       UPnP.
                       Sharing Service
                       Windows Modules      Enables installation, modification, and removal of Windows updates and optional
                       Installer            components. If this service is disabled, install or uninstall of Windows updates might fail for
                                            this computer.
                       Windows              Optimizes performance of Windows Presentation Foundation (WPF) applications by caching
                       Presentation         commonly used font data. WPF applications will start this service if it is not already running. It
                       Foundation Font      can be disabled, though doing so will degrade the performance of WPF applications.
                       Cache 3.0.0.0
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022                            Page 14-9
System Services
                    Service            Description
                     Windows Remote     Windows Remote Management (WinRM) service implements the WS-Management protocol
                     Management        for remote management. WS-Management is a standard web services protocol used for
                     (WS-Management)    remote software and hardware management. The WinRM service listens on the network for
                                        WS-Management requests and processes them. The WinRM Service needs to be configured
                                        with a listener using winrm.cmd command line tool or through Group Policy in order for it to
                                        listen over the network. The WinRM service provides access to Windows Management
                                        Instrumentation (WMI) data and enables event collection. Event collection and subscription
                                        to events require that the service is running. WinRM messages use Hypertext Transfer
                                        Protocol (HTTP) and HTTPS as transports. The WinRM service does not depend on IIS but
                                        is preconfigured to share a port with IIS on the same machine. The WinRM service reserves
                                        the /wsman URL prefix. To prevent conflicts with IIS, administrators should ensure that any
                                        websites hosted on IIS do not use the /wsman URL prefix.
                     Windows Time       Maintains date and time synchronization on all clients and servers in the network. If this
                                        service is stopped, date and time synchronization will be unavailable. If this service is
                                        disabled, any services that explicitly depend on it will fail to start.
                     Windows Update     Enables the detection, download, and installation of updates for Windows and other
                                        programs. If this service is disabled, users of this computer will not be able to use Windows
                                        Update or its automatic updating feature, and programs will not be able to use the Windows
                                        Update Agent (WUA) API.
                     WinHTTP           WinHTTP implements the client HTTP stack and provides developers with a Win32 API and
                     Web Proxy         COM Automation component for sending HTTP requests and receiving responses. In
                     Auto-Discovery     addition, WinHTTP provides support for auto-discovering a proxy configuration via its
                     Service            implementation of the Web Proxy Auto-Discovery (WPAD) protocol.
                     WMI Performance    Provides performance library information from WMI providers to clients on the network. This
                     Adapter            service only runs when Performance Data Helper is activated.
                     Workstation        Creates and maintains client network connections to remote servers using the SMB protocol.
                                        If this service is stopped, these connections will be unavailable. If this service is disabled, any
                                        services that explicitly depend on it will fail to start.
Page 14-10        MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022
                                                                                                                    Index
Index
A                                         Loyalty systems 3-9                       T
accessible 7-3                                                                      Technical Support 5-7
account lockout 5-1                       M                                         terminate the process 4-5
administrator access 3-1                  merchant network 3-1, 6-1                 two-factor authentication 5-1
alphanumeric field 3-3
appended 4-4
                                          N                                         U
Authorized Service Contractor 1-4
                                          non-network tender 7-6                    unauthorized access 5-3
                                          non-sales transactions 1-4                update 3-7
B                                                                                   User Management 2-7
best practices 3-1                                                                  user-level access 3-1
black box 1-4                             O
                                          onsite updates 6-1
                                                                                    V
C                                                                                   validate 2-5
cardholder data 1-1                       P                                         validates 4-3
Change Password 3-8                       PA-DSS compliance 1-4                     vendor access 5-1
characters 4-3                            Passport Audit logs 9-3                   Virtual Private Network 5-1
compliance 1-1                            Payment Application Data Security
compliant mode 7-5                        Standard 1-1
consecutive invalid passwords 3-9         payment network 4-4
create 3-5                                Period Selection 4-4
                                          Platform Support Service 2-4
                                          procedure 2-6
D
data retention 4-5
data retention period 4-5                 R
data storage 4-5                          regulatory purposes 4-5
default accounts 3-9                      relevant network addendum 4-4
devices 3-9                               Remote Support 2-7
Document Open Password 4-4                removals 3-5
                                          requirements 1-1
                                          Reset User 3-6
E                                         retention period 4-5
End of File Separator 9-1                 retrieve 4-1
Enhanced Dispenser Hub 1-1                router logs 9-2
F                                         S
File Header 9-1                           Section Separator 9-1
financial data 7-6                        secure authentication 3-9
format 7-10                               secure delete process 9-2
fueling position 7-6                      Secure Report Password 4-1
                                          Security Audit Log 3-5
I                                         Security Manager 2-1
identify 9-3                              Security Manager Interface 2-4
IMPORTANT 7-3, 7-6                        Security Manager Report 2-1
IP/MAC addresses 5-1                      security-enabled 3-3
                                          storage volume 4-5
                                          support 2-3
K                                         Support Console 2-3
keystroke 3-8                             System Maintenance 2-2
                                          System Maintenance login 2-2
L                                         System Management 2-7
lockout period 3-9
log entry 3-5
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022            Index-1
© 2022 Gilbarco Inc.
7300 West Friendly Avenue • Post Office Box 22087
Greensboro, North Carolina 27420
Phone (336) 547-5000 • http://www.gilbarco.com • Printed in the U.S.A.
MDE-5523E Passport EDH (Fiserv®/First Data™) V11.23.01.* Implementation Guide for PA-DSS V3.2 · May 2022