Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Aloha 6.7 PCI Compliance 1

Status
Not open for further replies.

neotope

IS-IT--Management
Jan 19, 2012
28
0
0
US
Does anybody have any information on the end of PCI Compliance for Aloha 6.7? Right now I have some sites still running 6.7 because of older hardware that works fine so management is trying to hold off upgrades. I am fine with this because I have some newer sites that I've migrated to 12.3 and that's keeping me busy. I just don't want to be caught holding the bag and find I'm out of compliance and need to order hardware and do upgrades quickly.
 
For the new Mastercard Bins you will need to be on at least 6.7.70 POS and 14.1.20 EDC. I believe those versions are compliant. I would recommend installing NAM if you can because I can backdoor old aloha manager in like 45 seconds.
 
Thanks for the info, I believe the 6.7 EOL for PCI compliance is Oct 2017. That's what I was wondering if it would be pushed back.
 
I just got off the phone with the president of one of the local NCR dealers. He told me, Aloha ver 6.5 and above is PCI compliant for software. However, as you can see its much more than that [URL unfurl="true"]https://res.cloudinary.com/engineering-com/image/upload/v1484249818/tips/PCI_DSS_Poster_hdsekb.pdf[/url]
I you are not doing all the steps listed you are not PCI compliant.

For EDC ver 12.3 is compliant.

Here is what is needed for hardware
pci_ov9tpo.jpg


Even upgrading to NAM its still easy to crack in less than 30 seconds with their own tool
NAM_av9hep.jpg


Facts are always better than opinions


AlohaRoss
An Aloha POS 3rd Party support Solution company.
 
AlohaRoss, thanks for the info. That's what is acceptable for new deployments I am wondering about existing deployments. If I check the pcisecuritystandards.org website it shows Aloha 6.7 being compliant through Oct 2016. My dealer said it renewed through Oct 2017 because of the delays with v15.1 deployment. They believe that 6.7 won't be a compliant version after Oct 2017 and it won't be renewed. I was wondering if anybody else had any other information.
 
You should speak to a PCI auditor. The rule had always been and I never heard it change, if you bought the system when it was validated, then you can continue to use it. If you upgrade or buy new, you need to be on the validated for new deployments. Only an auditor really is qualified to answer.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top