3 ms·
>Or they could just use their 'enterprise configuration management' to enforce TLS 1.2 internally... Until the PCI auditors come and start telling everyone tha
by voidlogic 9y ago
>Or they could just use their 'enterprise configuration management' to enforce TLS 1.2 internally...
Until the PCI auditors come and start telling everyone that 1.2 is obsolete because 1.3 exists...
- AaronFriel 9y agoA network setup that permits network admins to obtain plaintext account data (information the PCI spec requires be protected) would not be PCI compliant.
- voidlogic 9y agoI don't think that is true, if the access to decrypt packet captures adheres to PCI access controls why would that violate anything? So long as the decryption of a packet capture happens on host in PCI scope, the user is a PCI user and their actions are directly traceable to that single user? People who run systems in PCI need to debug their production systems too...
- AaronFriel 9y agoThese are all important caveats, but I'd suspect that many/most network devices do not have the rigorous controls to enforce all of those requirements simultaneously. I am out of my element here, though.
- voidlogic 9y agoIts not so bad, you have some dedicated debugging PCI host that you ship your packet captures too (packet capture never leaves PCI), then you checkout necessary private keys (system with keys is in PCI and only lets PCI users do this) and have a debugging session.
- ploxiln 9y agoDealing with dumb and possibly conflicting PCI requirements is between these enterprises and PCI. It's not appropriate for them to get accommodations from the IETF and various internet companies/users to help them with that.
- voidlogic 9y agoI think your POV is fine in theory, but PCI/eCommerce is once of the primary stakeholders in transport encryptions both in terms of businesses and users. So it might deserve some special consideration (if reasonable) or not :p