Zen Cart Logo
Forums / General Questions / Admin timeout: setting the length of timeout before rolling in again

Admin timeout: setting the length of timeout before rolling in again

Views: 3,088

Results 1 to 6 of 6
4 Jun 2016, 7:50 PM
#1
acmaurer avatar

acmaurer

New Zenner

Join Date:
Jan 2012
Posts:
27
Plugin Contributions:
0

Admin timeout: setting the length of timeout before rolling in again

I'm running 1.5.5.a.

The default admin timeout doesn't work for me. Putting together orders, shipping labels, etc. I'm constantly logging in over and over.

Where does the timeout length get set? I want to set it for something that works for me (not some programmer's idea of what's "reasonable")

5 Jun 2016, 1:39 AM
#2
frank18 avatar

frank18

Deceased

Join Date:
Nov 2007
Location:
Sunny Coast, Australia
Posts:
3,427
Plugin Contributions:
2

Re: Admin timeout: setting the length of timeout before rolling in again

acmaurer:

I'm running 1.5.5.a.

The default admin timeout doesn't work for me. Putting together orders, shipping labels, etc. I'm constantly logging in over and over.

Where does the timeout length get set? I want to set it for something that works for me (not some programmer's idea of what's "reasonable")

You can set this in Admin > Configuration > My Store

PA-DSS Admin Session Timeout Enforced?
PA-DSS Compliance requires that any Admin login sessions expire after 15 minutes of inactivity. **
Disabling this makes your site NON-COMPLIANT with PA-DSS rules, thus invalidating any certification.
**

5 Jun 2016, 1:41 AM
#3
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
177

Re: Admin timeout: setting the length of timeout before rolling in again

acmaurer:

I want to set it for something that works for me (not some programmer's idea of what's "reasonable")
While you're obviously frustrated, don't go blaming the programmers.

Blame the fraudsters and hackers that caused Visa/Mastercard to come up with what they view as reasonable security measures. It's they who impose them, if you wish to operate your site in a way that is compliant with their standards.

If you wish to turn off that forced-logout you can do without slagging on anyone by simply changing the setting in your Admin->Configuration->My Store menu. It's the "PA-DSS Admin Session Timeout Enforced?" setting. And then you can set how long you want it to be just below that in "Admin Session Time Out in Seconds".

7 Feb 2017, 8:51 AM
#4
leorwald avatar

leorwald

New Zenner

Join Date:
Oct 2016
Posts:
5
Plugin Contributions:
0

Re: Admin timeout: setting the length of timeout before rolling in again

I'm confused by this setting. As far as I understand zencart does not store any cardholder data (the PAN). If so, why does the admin have to timeout every 15 minutes. I understood that it only has to do so, if it is storing cc information.

TIA,
Leo

7 Feb 2017, 9:50 PM
#5
mc12345678 avatar

mc12345678

Totally Zenned

Join Date:
Jul 2012
Posts:
16,908
Plugin Contributions:
2

Re: Admin timeout: setting the length of timeout before rolling in again

leorwald:

I'm confused by this setting. As far as I understand zencart does not store any cardholder data (the PAN). If so, why does the admin have to timeout every 15 minutes. I understood that it only has to do so, if it is storing cc information.

TIA,
Leo
I performed the following search (pad-ss when timeout required) and the first link provided was to a pdf (https://www.pcisecuritystandards.org/minisite/en/docs/PA-DSS_v3.pdf) related to the topic of PAD-SS to which ZC has been certified.

Looking at the 2nd paragraph under the second main section of the introduction, > All applications that store, process, or transmit cardholder data are in scope for an entity's PCI DSS assessment, including applications that have been validated to PA-DSS.

Further, looking through the requirements provided, the area in question is identified as 3.1.11. Now my read of all this is: not complying with these and the other identified attributes means that the software can not be considered/evaluated as PA-DSS certified and if not PA-DSS certified then also not PCI-DSS compliant. As to the need to be such: well, a cardholder's name is considered one part of cardholder data, ZC does at least two of the three actions (store and process) and in some cases it does transmit it as well (ie. When submitting data to getting from a payment processor.) So, by sustaining the requirements of PA-DSS, ZC is able to maintain that certification (at least for the version which obtained it).

All that said, I am no authority on the subject, I did my own independent search and read on the topic and provided the above from that. Do as you will, I personally appreciate what has been done to obtain this certification and to provide a product that supports secure sales. If not mistaken, it remains the only eCommerce platform verified to meet this level of requirement. I may have applied that statement too broadly, but wouldn't be the first nor last time I'm wrong if so.

8 Feb 2017, 1:00 AM
#6
website_rob avatar

website_rob

Inactive

Join Date:
Oct 2006
Location:
Alberta, Canada
Posts:
4,572
Plugin Contributions:
0

Re: Admin timeout: setting the length of timeout before rolling in again

leorwald:

I'm confused by this setting. As far as I understand zencart does not store any cardholder data (the PAN). If so, why does the admin have to timeout every 15 minutes. I understood that it only has to do so, if it is storing cc information.

TIA,
Leo

It's all part of the PS/PCI security compliance. You could be in a somewhat public area and go away for a minute or two and someone could access information in the database. Although it may not have Credit Card information, it does contain a lot of private information that your Clients expect to stay private.