TBANK Security Intellinx System V0.6 20160523
TBANK Security Intellinx System V0.6 20160523
TBANK Security Intellinx System V0.6 20160523
for TBANK
TABLE OF CONTENTS
VERSION CONTROL......................................................................................1
INTRODUCTION............................................................................................2
INTELLINX SYSTEM CONFIGURATIONS ENCRYPTION....................................3
FIRST
ENCRYPTION TO THE
DATA CHANNELS....................................................22
LIST OF FIGURES
Figure 1: First time password 1..................................................4
Figure 2: First time password 2..................................................4
Figure 3: First time password 3..................................................5
Figure 4: First time password 4..................................................5
Figure 5: First time password 5..................................................6
Figure 6: First time password 6..................................................7
Figure 7: First time password 7..................................................8
Figure 8: Authentication setup 1................................................9
Figure 9: Authentication setup 2..............................................10
Figure 10: Authentication setup 3............................................10
Figure 11: Authentication setup 5............................................11
Figure 12: Authentication setup 6............................................12
Figure 13: Authentication setup 7............................................13
Figure 14: Authentication setup 8............................................13
Figure 15: Setup the encryption and sign are explain 1...........14
Figure 16: Setup the encryption and sign are explain 2...........15
Figure 17: Setup the encryption and sign are explain 3...........15
Figure 18: Setup the encryption and sign are explain 4...........15
Figure 19: Setup the encryption and sign are explain 5...........17
Figure 20: No keyset apply is not allow to Activate Service.....18
Figure 21: Setup the encryption and sign are explain 6...........19
Figure 22: Setup the encryption and sign are explain 7...........20
Figure 23: Setup the encryption and sign are explain 8...........20
Figure 24: Setup the encryption and sign are explain 9...........21
Figure 25: DC encrypt 1...........................................................22
Figure 26: DC encrypt 2...........................................................22
Figure 27: Generating master key for the database password 1
................................................................................................ 23
ii
iv
Version Control
Versi
on
Date
0.1
Aug
2015
0.2
0.3
0.4
0.5
Author\Editor
26, Thonthep K.
Purpose of update
Initial Draft
Udorn D.
Aug 27,
2015
Thonthep K.
Aug 28,
2015
Thonthep K.
Sep 4,
2015
Thonthep K.
Apr 8, 2016
Thonthep K.
0.6
May 23,
2016
Thonthep K.
Introduction
There are several related ways to implement Intellinx System with the strong
security enforces. In order to run the system, the most important information for
the organization needed to be applied in the many ways of secured methodology.
Information security is the infrastructure to make Intellinx system secure. The
following security setup and configuration in Intellinx TBANK fraud system has
been implemented.
This document lists are prepared for TBANK configuration installed for the
ATM Fraud production environment.
(Rule
3. Click OK again.
3.2The system configuration key files for encryption are located in this
path:
D:\Intellinx\Server\servers\itxsvc_dc_atm\security\keysets
File name: sys_conf_key.xml
The Authentication server has a choice for the Apache Directory Service ,
Open Ldap, Microsoft Active Directory etc. To provide the user authentication
security binding to the Intellinx system.
The procedure to setup the encryption and sign are explain below:
Intellinx provide a utility for generate the encryption key that conform to
the standard algorithms. To generate the file called utility Key Set by running the
command by the following step.
1) Run "D:\Intellinx\Server\tools\KeysetUtil.bat"
The installation directory on production is D:\Intellinx\Server
2) Choose 1: Generate a new keyset
"D:\Intellinx\Server\servers\itxsvc_ss_CDS_2348\security\keysets\current_key_set"
"D:\Intellinx\Server\servers\itxsvc_ss_CDS_2348\keysets\5352F216-D27F-3C730690C8D25E35D114"
"D:\Intellinx\Server\servers\itxsvc_ss_HP_2358\security\keysets\current_key_set"
"D:\Intellinx\Server\servers\itxsvc_ss_HP_2358\keysets\5352F216-D27F-3C730690C8D25E35D114"
"D:\Intellinx513\Server\servers\HPapp_2468\security\keysets\current_key_set"
"D:\Intellinx513\Server\servers\HPapp_2468\keysets\5352F216-D27F-3C730690C8D25E35D114"
"E:\Intellinx5\Server\servers\itxsvc_atm_sit_2448\security\keysets\current_key_set
"
"E:\Intellinx5\Server\servers\itxsvc_atm_sit_2448\security\keysets\5352F216D27F-3C73-0690C8D25E35D114"
"E:\Intellinx5\Server\servers\itxsvc_cdshp_sit_2668\security\keysets\current_key_s
et"
"E:\Intellinx5\Server\servers\itxsvc_cdshp_sit_2668\security\keysets\5352F216D27F-3C73-0690C8D25E35D114"
"E:\Intellinx5\Server\servers\itxsvc_re_2648\security\keysets\current_key_set"
"E:\Intellinx5\Server\servers\itxsvc_re_2648\security\keysets\5352F216-D27F3C73-0690C8D25E35D114"
"E:\Intellinx5\Server\servers\itxsvc_re_job_2658\security\keysets\current_key_set"
"E:\Intellinx5\Server\servers\itxsvc_re_job_2658\security\keysets\5352F216-D27F3C73-0690C8D25E35D114"
"E:\Intellinx5\Server\servers\itxsvc_atm_uat_2549\security\keysets\current_key_se
t"
"E:\Intellinx5\Server\servers\itxsvc_atm_uat_2549\security\keysets\5352F216D27F-3C73-0690C8D25E35D114"
"E:\Intellinx5\Server\servers\itxsvc_cdshp_uat_2778\security\keysets\current_key_
set"
6) Open the Enterprise Manager and then double click on the server for
example itxsvc_dc_atm you will get to the Server Configuration, click
on the Encryption tab.
2
1
8) Click OK
Under the Recording tab click on the Encrypt recording and Sign
recording check boxes and then click OK for apply then restart the
DataChannel.
All DataChannel has been applied to this keyset and enable the encryption
data that finally writing down to the BackLog Database. Sessions data are
3. After that, press Enter and it will show that master key file generated
successfully as follows.
3. After that, press Enter and it will show that master key file generated
successfully as follows. The password shown in No.1 will be used up
next.
6. Copy the master key encryption file .masterkey under this path
D:\Intellinx\IC\InvestigationCenter\Appserver\conf\
The keystore file will be create after put the enter the password.
25/08/2015 02:57 PM
1,264 keystore.jks
3. Click OK
After applying the parameters for the encrytion Web Replay service then
restart the server service. The service will be applied to the itxsvc_bl on the
ATM production server.
In order need to be remove comment begin <!-- and end --> then add
new lines and put the parameter as follow:
1. keystoreFile = "D:\Intellinx\Security\keystore.jks
2. keystorePass = "xxxxxx"
3. keyAlias = "itx_key"
Export certification
1. Click on Certificate Error and select View certificates
3. Click Next
7. Click Finish
Import certification
1. Click Start > type certmgr.msc
certmgr.msc that showed up
in
search
panel
and
select
3. Click Next
5. Select certificate file (in this case its the same file from previous
chapter)
7. Select Place all certifications in the following store and click Browse
11.Certificate store path should have Local Computer in the end and
click Next