Verifone Commander
The Verifone Commander™ is a high-powered server that increases the capacity and functionality of Verifone’s ethernet capable Point of Sale (POS) workstations.
The Verifone Commander™ is a high-powered server that increases the capacity and functionality of Verifone’s ethernet capable Point of Sale (POS) workstations by extending the processing and communications bandwidth for managing peripherals.
Future needs are designed into the hardware to provide support for additional serial ports and CPU boards along with additional fan and/or power connection that may be needed as a result. Use of these expansion capabilities will be determined by Verifone. System peripherals, such as fuel dispensers, dispenser card readers (DCRs), and car wash controllers connect directly to the Verifone Commander.
In addition to Configuration Client, Verifone Commander also has other site management software: Report Navigator, Transaction Manager and Verifone Commander Console. Report Navigator is used to view reporting data for the store. Reporting information such as the close day report can be configured to include a multitude of report options. Transaction Manager allows for site transaction logs and data to be accessed from the Verifone Commander or archived locally. Verifone Commander Console enables multiple store reporting data to be consolidated into one place for easy visibility to monitor and track sales trends.
The Verifone Commander contains a built in V950, referred to as the V950SC.
When a router is installed in this configuration, it can be configured so that the Verifone Commander’s V950SC can:
Receive software upgrades remotely using Verifone’s Remote Software Download feature.
Connect with the Verifone Helpdesk for remote troubleshooting and diagnostics.
Verifone C-Site Management
Verifone C-Site Management is a web application that enables Petroleum Merchants and Major Oil administrators to maintain a centralized point for site data, monitor sites remotely, and provides a convenient platform for synchronous oversight and configuration.
Verifone C-Site Management does not require a technician to visit each location to make changes and updates. Updates can be done selectively or all at once from the web application.
To create an account for Verifone C-Site Management, navigate to the following URL and select ‘Sign Up for Free’. https://petromop.verifone.cloud/home
Refer to the Verifone C-Site Management User Guide for more information.
Configuration Client
The Verifone Commander can receive configuration changes using Configuration Client. Configuration client is a web-based utility that allows store personnel, Verifone Authorized Service Contractors, and Verifone Helpdesk to modify site information. To utilize Configuration Client you must be using a supported web browser.
The supported Web Browsers are:
Chrome versions 60 or higher
Firefox versions 53 or higher
Internet Explorer versions 8 or higher
Key in the URL https://192.168.31.11/ConfigClient.html into the Web Browser and press [Enter].
Enter Username and Password.
Click Login.
Minimum Age Requirement
From Verifone Release 57.01, when a user changes their password in configuration client, they must wait at least a day before they can change the password again. This is to help prevent users from recycling through their old passwords. If this control is not implemented, users can change passwords repeatedly and then reuse an old password even though password-history (last 4) is configured, defeating the history control. If the user forgot their password within a day, they can use the forgot password feature one time.
This process does not impact the helpdesk or secure users from being able to reset a password for a user.
What Changed
Starting with Base057.01.00, the Commander enforces a 24-hour minimum age between password changes. After you change your password, you must wait 24 hours before you can change it again.
This is a PCI compliance requirement. Without a minimum age, users could cycle through passwords quickly to get back to a previously used password, bypassing the password-history protection that prevents reuse.
Key rule: Once you change your password, you cannot change it again for 24 hours. This applies whether you change it from the Config Client or through a Back Office (PDK) partner system.
How It Works — By Scenario
When you change your password through the Commander Config Client, the 24-hour clock starts immediately.
If you try to change your password again before 24 hours have passed, the system will block the request and display a message explaining the wait.
If you forget the password you just created, you can use the Forgot Password option (which asks your security challenge questions) to set a new password. This is allowed once within a 24-hour period.
After using Forgot Password, the 24-hour clock resets from that point.
You cannot use Forgot Password a second time within the same 24-hour window. If you need further help, contact your manager or helpdesk.
When a manager or helpdesk agent resets a user's password, the 24-hour rule does not apply.
The user receives a temporary password and must create a new one at their next login. This first-login change is always permitted, regardless of any timing restriction.
This applies whether or not the Force Change on Next Login option is enabled — any admin-reset password requires a change at first login.
Third-party Back Office systems that use the Commander change password command are subject to the same 24-hour rule.
If a PDK partner attempts to change a user's password within 24 hours of the last change, the command will return an error.
On a fresh Commander installation, when the manager logs in for the first time and changes the default password, this change is exempt from the 24-hour rule.
Quick Reference — When Is the 24-Hour Wait Applied?
User changes their own password (Config Client)
Yes
User tries to change password again within 24 hours
Blocked
User uses Forgot Password (challenge questions) — first use
Allowed once
User tries Forgot Password a second time within 24 hours
Blocked
Admin / Helpdesk resets a user's password
Exempt
User changes temp password at first login after admin reset
Exempt
PDK (Back Office partner) uses change password command
Yes
Fresh install — manager changes default password at first login
Exempt
Frequently Asked Questions
Why was this change made?
PCI compliance guidelines require that password controls prevent users from quickly cycling through passwords to reuse an old one. A 24-hour minimum age enforces this by giving the password-history protection time to take effect.
What does the system show if I try to change my password too soon?
The system will block the change and display a message explaining that a minimum password age is in effect and you must wait. No change will be made to your password.
I just set my password but mistyped it. Now I can't log in. What do I do?
Use the Forgot Password option on the login screen. Answer your security challenge questions and you will be able to set a new password. This one-time exception exists specifically for this scenario.
If my manager resets my password, do I have to wait 24 hours before I can create my own?
No. When your password is reset by a manager or helpdesk agent, you will be required to create a new password at your next login. This first-login change is always permitted and is not subject to the 24-hour wait.
Does the 24-hour rule apply to our Back Office system?
Yes. If your Back Office (PDK) system uses the Commander change password command, it is subject to the same 24-hour minimum age. If a password change is attempted within 24 hours, the system will return an error. Contact your Back Office vendor if you see unexpected errors related to password changes.
One-Time Password (OTP) Prompt
From release 47 and higher, there is an additional prompt for a one-time password (OTP) implemented into Configuration Client. As part of PCI/DSS v3.2 Requirement 8.3.1, this incorporates a multi-factor authentication for all non-console access into the Cardholder Data Environment (CDE) for personnel with administrative access.
Menus that have this prompt include:
Security > Manage Users (Includes Roles)
Initial Setup
Date & Time
Local Area Network Config
VHQ Configuration
Payment Controller > POS Configuration
EPS Configuration > EPS Global Configuration
Full Service Attendant Configuration
InComm Configuration
LINQ3 Lottery Configuration
Payware Fleet and Loyalty Configuration
PCATS Loyalty Configuration
Proprietary Fleet Configuration
Punch Card Loyalty Configuration
Network Configuration (network references the name of the network installed, such as Buypass)
Loyalty Card Configuration
While the preceding is the list of functions In Base 47 that include the OTP prompt within Configuration Client, it may be expanded to other areas and new features in future releases.
Clicking on Guidelines to generate an OTP (see image above) will display the 3 different ways to obtain the OTP.
The OTP is 4 digits in length. When generated using any of the 3 methods above, it will appear on the 7- Segment status display of the Verifone Commander (displaying 2 numbers at a time; the period indicates the first set of numbers). If generated from the POS/register, it will also display on the POS screen.
The OTP is directly tied to the user’s Configuration Client login session. If the OTP is generated and correctly entered, the OTP will be active until the user logs out or the Configuration Client session times out for inactivity (15 minutes). The OTP does not require re-entry after it has been saved for the session, meaning the user can go between menus that require entry, without being prompted.
The OTP requirement applies to backing up and restoring files to the Verifone Commander using SMS Import/Export. Files that require an OTP may not be restored to the Verifone Commander, and an error message (“One Time Password Required”) appears when attempting to do so. Clicking OK on the error prompt allows the rest of the import or export to proceed. Clicking Abort aborts the remainder of the import or export. In newer versions of SMS Import/Export, items that require OTP are removed from the backup and restore list.
Last updated
Was this helpful?
