<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: PCI DSS Requirement 4.1: Protecting Cardholder Data with SSL and TLS</title>
	<atom:link href="http://www.pcidssguru.com/pci-dss/ssl_tls_pci_dss/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pcidssguru.com/encryption/ssl_tls_pci_dss/</link>
	<description>Practical Implementation Guidance on the Payment Card Industry Data Security Standard</description>
	<lastBuildDate>Tue, 31 Jan 2012 16:19:53 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Raider</title>
		<link>http://www.pcidssguru.com/encryption/ssl_tls_pci_dss/comment-page-1/#comment-8779</link>
		<dc:creator>Raider</dc:creator>
		<pubDate>Tue, 01 Nov 2011 08:33:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=7#comment-8779</guid>
		<description>Hi all,

Does anyone know how the issued SSL certificate must be stored according to PCI DSS? Do requirements 3.5, 3.6 apply to SSL certificates?</description>
		<content:encoded><![CDATA[<p>Hi all,</p>
<p>Does anyone know how the issued SSL certificate must be stored according to PCI DSS? Do requirements 3.5, 3.6 apply to SSL certificates?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Igor</title>
		<link>http://www.pcidssguru.com/encryption/ssl_tls_pci_dss/comment-page-1/#comment-8508</link>
		<dc:creator>Igor</dc:creator>
		<pubDate>Wed, 26 Oct 2011 08:12:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=7#comment-8508</guid>
		<description>Hi all,

again question regarding GPRS POS. If we use separate private APN and our traffic is encrypted from provider router towards bank internal network, is there need for SSL? 
So, traffic is not encrypted end-to-end with IPSec, but from providers first router. Also, GPRS isn&#039;t going clear over the air, it is also encrypted with some provider based algorithm, unfortunately not secure anymore (http://en.wikipedia.org/wiki/A5/1)</description>
		<content:encoded><![CDATA[<p>Hi all,</p>
<p>again question regarding GPRS POS. If we use separate private APN and our traffic is encrypted from provider router towards bank internal network, is there need for SSL?<br />
So, traffic is not encrypted end-to-end with IPSec, but from providers first router. Also, GPRS isn&#8217;t going clear over the air, it is also encrypted with some provider based algorithm, unfortunately not secure anymore (<a href="http://en.wikipedia.org/wiki/A5/1" rel="nofollow">http://en.wikipedia.org/wiki/A5/1</a>)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vsevolod Kolchinsky</title>
		<link>http://www.pcidssguru.com/encryption/ssl_tls_pci_dss/comment-page-1/#comment-8250</link>
		<dc:creator>Vsevolod Kolchinsky</dc:creator>
		<pubDate>Fri, 21 Oct 2011 09:16:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=7#comment-8250</guid>
		<description>IPSEC with appropriate key management procedure obviously enough to safeguard data</description>
		<content:encoded><![CDATA[<p>IPSEC with appropriate key management procedure obviously enough to safeguard data</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marinko</title>
		<link>http://www.pcidssguru.com/encryption/ssl_tls_pci_dss/comment-page-1/#comment-8162</link>
		<dc:creator>Marinko</dc:creator>
		<pubDate>Wed, 19 Oct 2011 06:01:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=7#comment-8162</guid>
		<description>Hi.

I have one question about GPRS. Is it enought to use Internet protocol security (IPSEC) to safeguard sensitive cardholder data or I sould use something more (like SSL)?
I &#039;m ussing GPRS APN to send data.</description>
		<content:encoded><![CDATA[<p>Hi.</p>
<p>I have one question about GPRS. Is it enought to use Internet protocol security (IPSEC) to safeguard sensitive cardholder data or I sould use something more (like SSL)?<br />
I &#8216;m ussing GPRS APN to send data.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Big John</title>
		<link>http://www.pcidssguru.com/encryption/ssl_tls_pci_dss/comment-page-1/#comment-8136</link>
		<dc:creator>Big John</dc:creator>
		<pubDate>Tue, 18 Oct 2011 15:55:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=7#comment-8136</guid>
		<description>The mobile network providers encrypt data while in transit over their networks (3G). Does anybody know if this enctyption is addequate in addressing PCI requirements?</description>
		<content:encoded><![CDATA[<p>The mobile network providers encrypt data while in transit over their networks (3G). Does anybody know if this enctyption is addequate in addressing PCI requirements?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Simon</title>
		<link>http://www.pcidssguru.com/encryption/ssl_tls_pci_dss/comment-page-1/#comment-6654</link>
		<dc:creator>Simon</dc:creator>
		<pubDate>Sat, 17 Sep 2011 09:43:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=7#comment-6654</guid>
		<description>I onle have a GSM terminal to process my transactions, therefore what will I need to be compliant?</description>
		<content:encoded><![CDATA[<p>I onle have a GSM terminal to process my transactions, therefore what will I need to be compliant?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SgtShultz</title>
		<link>http://www.pcidssguru.com/encryption/ssl_tls_pci_dss/comment-page-1/#comment-1114</link>
		<dc:creator>SgtShultz</dc:creator>
		<pubDate>Thu, 10 Jun 2010 16:46:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=7#comment-1114</guid>
		<description>My understanding of MPLS is that PCI still considers this a private network. However I have been told that this may change in v1.3!</description>
		<content:encoded><![CDATA[<p>My understanding of MPLS is that PCI still considers this a private network. However I have been told that this may change in v1.3!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joaquim</title>
		<link>http://www.pcidssguru.com/encryption/ssl_tls_pci_dss/comment-page-1/#comment-724</link>
		<dc:creator>Joaquim</dc:creator>
		<pubDate>Wed, 26 Aug 2009 09:37:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=7#comment-724</guid>
		<description>As per PCIDSS standards, do MPLS and Lease Lines come into the &quot;OPEN&quot; network?</description>
		<content:encoded><![CDATA[<p>As per PCIDSS standards, do MPLS and Lease Lines come into the &#8220;OPEN&#8221; network?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://www.pcidssguru.com/encryption/ssl_tls_pci_dss/comment-page-1/#comment-99</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Sat, 10 Jan 2009 22:45:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=7#comment-99</guid>
		<description>I&#039;ve never worked with a merchant using GPRS APNs, but I believe it would still meet the definition of a public network.  You&#039;re transmitting data over the air, so it needs to be encrypted.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve never worked with a merchant using GPRS APNs, but I believe it would still meet the definition of a public network.  You&#8217;re transmitting data over the air, so it needs to be encrypted.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrew</title>
		<link>http://www.pcidssguru.com/encryption/ssl_tls_pci_dss/comment-page-1/#comment-43</link>
		<dc:creator>Andrew</dc:creator>
		<pubDate>Fri, 03 Oct 2008 09:19:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=7#comment-43</guid>
		<description>Hi,
i have some doubts about this sentence:
“Examples of open, public networks that are in scope of the PCI DSS (...) and general packet radio service (GPRS)”

What if we use our GPRS APN to send data, so nobody else can connect to this APN. It&#039;s still public network?</description>
		<content:encoded><![CDATA[<p>Hi,<br />
i have some doubts about this sentence:<br />
“Examples of open, public networks that are in scope of the PCI DSS (&#8230;) and general packet radio service (GPRS)”</p>
<p>What if we use our GPRS APN to send data, so nobody else can connect to this APN. It&#8217;s still public network?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

