04/02/2018
Important security update for TLS 1.2 - The TLS deadline is fast approaching! Failure to act could result in processing interruptions.
As with most card processors, Heartland/Global will be standardizing all payment servers and processors to require a minimum of TLS 1.2 for all connections, as well as limiting to a set of approved Cipher suites. All security mechanisms prior to TLS 1.2, such as TLS 1.1 and SSL, will be disabled and no longer connect to our payment URLs. This will allow us to align with the industry to provide maximum security to our merchants. This conversion will happen on or around May 31, 2018.
There are several components to a system that determine whether a site will be able to negotiate a TLS 1.2 connection, so it will be important to look at all factors in determining what steps need to be made to prepare for this change. The operating system, version of .NET, and the POS version all play a part, as well as potential Windows registry settings.
In order to continue to process credit cards via Heartland after May 31, 2018, all merchants must be on compliant systems. If upgrading to a compliant configuration is not possible, an out-of-scope solution such as PAX S300 can be leveraged.
Point of Sales systems that are not updated to support TLS v1.2 by May 31st, 2018 will be unable to process transactions.
Our company has put together resources to assist customers and dealers for this change.