For the complete documentation index, see llms.txt. This page is also available as Markdown.

Verifone Commander

The Verifone Commander™ is a high-powered server that increases the capacity and functionality of Verifone’s ethernet capable Point of Sale (POS) workstations.

The Verifone Commander™ is a high-powered server that increases the capacity and functionality of Verifone’s ethernet capable Point of Sale (POS) workstations by extending the processing and communications bandwidth for managing peripherals.

Future needs are designed into the hardware to provide support for additional serial ports and CPU boards along with additional fan and/or power connection that may be needed as a result. Use of these expansion capabilities will be determined by Verifone. System peripherals, such as fuel dispensers, dispenser card readers (DCRs), and car wash controllers connect directly to the Verifone Commander.

In addition to Configuration Client, Verifone Commander also has other site management software: Report Navigator, Transaction Manager and Verifone Commander Console. Report Navigator is used to view reporting data for the store. Reporting information such as the close day report can be configured to include a multitude of report options. Transaction Manager allows for site transaction logs and data to be accessed from the Verifone Commander or archived locally. Verifone Commander Console enables multiple store reporting data to be consolidated into one place for easy visibility to monitor and track sales trends.

The Verifone Commander contains a built in V950, referred to as the V950SC.

When a router is installed in this configuration, it can be configured so that the Verifone Commander’s V950SC can:

  • Receive software upgrades remotely using Verifone’s Remote Software Download feature.

  • Connect with the Verifone Helpdesk for remote troubleshooting and diagnostics.

Verifone C-Site Management

Verifone C-Site Management is a web application that enables Petroleum Merchants and Major Oil administrators to maintain a centralized point for site data, monitor sites remotely, and provides a convenient platform for synchronous oversight and configuration.

Verifone C-Site Management does not require a technician to visit each location to make changes and updates. Updates can be done selectively or all at once from the web application.

To create an account for Verifone C-Site Management, navigate to the following URL and select ‘Sign Up for Free’. https://petromop.verifone.cloud/home

Refer to the Verifone C-Site Management User Guide for more information.

Configuration Client

The Verifone Commander can receive configuration changes using Configuration Client. Configuration client is a web-based utility that allows store personnel, Verifone Authorized Service Contractors, and Verifone Helpdesk to modify site information. To utilize Configuration Client you must be using a supported web browser.

The supported Web Browsers are:

  • Chrome versions 60 or higher

  • Firefox versions 53 or higher

  • Internet Explorer versions 8 or higher

Key in the URL https://192.168.31.11/ConfigClient.html into the Web Browser and press [Enter].

Enter Username and Password.

Click Login.

Minimum Age Requirement

From Verifone Release 57.01, when a user changes their password in configuration client, they must wait at least a day before they can change the password again. This is to help prevent users from recycling through their old passwords. If this control is not implemented, users can change passwords repeatedly and then reuse an old password even though password-history (last 4) is configured, defeating the history control. If the user forgot their password within a day, they can use the forgot password feature one time.

This process does not impact the helpdesk or secure users from being able to reset a password for a user.

What Changed

Starting with Base057.01.00, the Commander enforces a 24-hour minimum age between password changes. After you change your password, you must wait 24 hours before you can change it again.

This is a PCI compliance requirement. Without a minimum age, users could cycle through passwords quickly to get back to a previously used password, bypassing the password-history protection that prevents reuse.

How It Works — By Scenario

Changing Your Own Password

When you change your password through the Commander Config Client, the 24-hour clock starts immediately.

If you try to change your password again before 24 hours have passed, the system will block the request and display a message explaining the wait.

Forgot Your Newly Created Password?

If you forget the password you just created, you can use the Forgot Password option (which asks your security challenge questions) to set a new password. This is allowed once within a 24-hour period.

After using Forgot Password, the 24-hour clock resets from that point.

You cannot use Forgot Password a second time within the same 24-hour window. If you need further help, contact your manager or helpdesk.

Admin or Helpdesk Resets Your Password

When a manager or helpdesk agent resets a user's password, the 24-hour rule does not apply.

The user receives a temporary password and must create a new one at their next login. This first-login change is always permitted, regardless of any timing restriction.

This applies whether or not the Force Change on Next Login option is enabled — any admin-reset password requires a change at first login.

Back Office (PDK) Partners

Third-party Back Office systems that use the Commander change password command are subject to the same 24-hour rule.

If a PDK partner attempts to change a user's password within 24 hours of the last change, the command will return an error.

Fresh Installation — First Login

On a fresh Commander installation, when the manager logs in for the first time and changes the default password, this change is exempt from the 24-hour rule.

Quick Reference — When Is the 24-Hour Wait Applied?

Scenario
24-Hour Wait?

User changes their own password (Config Client)

Yes

User tries to change password again within 24 hours

Blocked

User uses Forgot Password (challenge questions) — first use

Allowed once

User tries Forgot Password a second time within 24 hours

Blocked

Admin / Helpdesk resets a user's password

Exempt

User changes temp password at first login after admin reset

Exempt

PDK (Back Office partner) uses change password command

Yes

Fresh install — manager changes default password at first login

Exempt

Frequently Asked Questions

Why was this change made?

PCI compliance guidelines require that password controls prevent users from quickly cycling through passwords to reuse an old one. A 24-hour minimum age enforces this by giving the password-history protection time to take effect.

What does the system show if I try to change my password too soon?

The system will block the change and display a message explaining that a minimum password age is in effect and you must wait. No change will be made to your password.

I just set my password but mistyped it. Now I can't log in. What do I do?

Use the Forgot Password option on the login screen. Answer your security challenge questions and you will be able to set a new password. This one-time exception exists specifically for this scenario.

If my manager resets my password, do I have to wait 24 hours before I can create my own?

No. When your password is reset by a manager or helpdesk agent, you will be required to create a new password at your next login. This first-login change is always permitted and is not subject to the 24-hour wait.

Does the 24-hour rule apply to our Back Office system?

Yes. If your Back Office (PDK) system uses the Commander change password command, it is subject to the same 24-hour minimum age. If a password change is attempted within 24 hours, the system will return an error. Contact your Back Office vendor if you see unexpected errors related to password changes.

One-Time Password (OTP) Prompt

From release 47 and higher, there is an additional prompt for a one-time password (OTP) implemented into Configuration Client. As part of PCI/DSS v3.2 Requirement 8.3.1, this incorporates a multi-factor authentication for all non-console access into the Cardholder Data Environment (CDE) for personnel with administrative access.

Menus that have this prompt include:

  • Security > Manage Users (Includes Roles)

  • Initial Setup

  • Date & Time

  • Local Area Network Config

  • VHQ Configuration

  • Payment Controller > POS Configuration

  • EPS Configuration > EPS Global Configuration

  • Full Service Attendant Configuration

  • InComm Configuration

  • LINQ3 Lottery Configuration

  • Payware Fleet and Loyalty Configuration

  • PCATS Loyalty Configuration

  • Proprietary Fleet Configuration

  • Punch Card Loyalty Configuration

  • Network Configuration (network references the name of the network installed, such as Buypass)

  • Loyalty Card Configuration

While the preceding is the list of functions In Base 47 that include the OTP prompt within Configuration Client, it may be expanded to other areas and new features in future releases.

Clicking on Guidelines to generate an OTP (see image above) will display the 3 different ways to obtain the OTP.

The OTP is 4 digits in length. When generated using any of the 3 methods above, it will appear on the 7- Segment status display of the Verifone Commander (displaying 2 numbers at a time; the period indicates the first set of numbers). If generated from the POS/register, it will also display on the POS screen.

The OTP is directly tied to the user’s Configuration Client login session. If the OTP is generated and correctly entered, the OTP will be active until the user logs out or the Configuration Client session times out for inactivity (15 minutes). The OTP does not require re-entry after it has been saved for the session, meaning the user can go between menus that require entry, without being prompted.

The OTP requirement applies to backing up and restoring files to the Verifone Commander using SMS Import/Export. Files that require an OTP may not be restored to the Verifone Commander, and an error message (“One Time Password Required”) appears when attempting to do so. Clicking OK on the error prompt allows the rest of the import or export to proceed. Clicking Abort aborts the remainder of the import or export. In newer versions of SMS Import/Export, items that require OTP are removed from the backup and restore list.

Last updated

Was this helpful?