FAQ – Questions and Answers about eBanking
1. First things first
Is eBanking secure?
What does eBanking cost?
How can I activate eBanking for my account(s)?
2. Access system
What access options does Gallinat-Bank offer?
Which type of access procedure is suitable for me?
Which business transactions are supported by which type of procedure?
What are the prerequisites to be satisfied for the use of each respective procedure?
What transaction software is supported by Gallinat-eBanking, and what is the software recommended by Gallinat-Bank?
3. PIN (PersonalIdentifikationNumber) und TAN (TransAktionNumber)
Can I myself unblock my account, if it was locked because I entered the wrong PIN?
How can I block online access to my account?
Can I use my PIN and TANs for several accounts?
Can I use the PIN for my eBanking for HBCI PIN/TAN as well?
Can I change my PIN myself?
Where can I find the direct debit section in the online banking portal?
4. VR-Netky
What is the VR-Netkey?
What is the Alias?
Can I modify the Alias?
5. HBCI procedure (Homebanking Computer Interface)
Which version of HBCI is used by Gallinat-Bank?
What is the URI (Universal Resource Identifier » internet adress)
for HBCI?
Can I manage more than one account with one HBCI key?
What is HBCI PIN/TAN?
WHOw do I set up the HBCI access for HBCI PIN/TAN?
What is HBCI with a keystore medium?
How do I set up the HBCI access for HBCI with a keystore medium?
6. Proficash
A transfer order or direct debit has to be changed, but the job has already been created. How do I proceed?
7. Frequent error meassages
Order has been rejected because it has already been submitted today.
Limit exceeded or available balance insufficient.
8. Questions about EBICS
What are the hash values for the bank key in the EBICS pocedure?
Which details are required for the Bank Parameter Data File?
1. First things first
Is eBanking secure?
Yes. For our online banking application we use an SSL certificate with a high encryption level (AES-256, 256 bit key). This guarantees that no third party can secretly decrypt and therefore spy out your personal data. There are various possibilities for you to recognize such an attack and to protect yourself against it. Find out more here!
In order to prevent others from pretending to be you when dealing with the bank, you have to prove your identity several times: for the eBanking and HBCI TAN/PIN you need your PIN, plus an additional TAN for each transaction. For HBCI with floppy disk you authenticate yourself with your electronic signature.
Our staff will under no circumstances, neither in writing nor via e-mail nor on the phone, ask you to reveal your access details in combination with your personal PIN and/or TAN.
Please make sure to keep your PIN and TANs or your HBCI key floppy disk safe and private at all times and do not let anyone have access to these data. Treat your PIN, TAN and key disk as if they were cash. This way the procedures will remain secure.
Do you need any help regarding the topic of security specifically or would you like to report a phishing suspicion? Call our central hotline at +49 (0) 180 50 53 111 (0.12 euros per minute from the Deutsche Telekom network) from 8:00 until 24:00 o’clock every day. For technical issues please contact your advisor directly.
How much does eBanking cost?
The activation of your eBanking is free of charge.
How can I activate eBanking for my account(s)?
Please speak to your customer advisor. You will receive the necessary contract documents via mail. We activate your eBanking as soon as we have the signed contract. For the PIN/TAN procedure please additionally send back the signed acknowledgements of receipt.
2. Access system
What access options does Gallinat-Bank offer?
- PIN/TAN via internet
- HBCI PIN/TAN (HomeBanking Computer Interface)
- HBCI with keystore medium (e.g. USB stick oder floppy disk)
- EBICS (Electronic Banking Internet Communication Service)
What type of access procedure is suitable for me?
Your customer advisor knows your individual business transactions that arise in the context of payments. They will be glad to advise you on this. By observing daily practice we have discovered the following preferences:
1. PIN/TAN via Internet | Private clients with few transactions |
2. HBCI PIN/TAN | Private clients with many transactions |
3. HBCI with keystore medium | Private/Business clients with many transactions |
4. EBICS | Business clients with several users of payment transactions |
Which business transactions are supported by which type of procedure?
1. PIN/TAN via Internet | Balance query, transaction query, domestic transfer, EU standard credit transfer, collective orders with a maximum of seven items |
2. HBCI PIN/TAN | Balance query, transaction query, domestic transfer, direct debits, collective orders without item limit |
3. HBCI with keystore medium | Balance query, transaction query, domestic transfer, direct debits, collective orders without item limit |
4. EBICS | Balance query, transaction query, domestic transfer, EU standard credit transfer, direct debit, collective orders without item limit, domestic urgent order, order placed by telegraph, same-day international urgent payment in euros, daily SWIFT statements, short-term pre-booked positions, international payment transactions |
What are the prerequisites to be satisfied for each respective procedure?
1. PIN/TAN via Internet | Internet connection, current web browser (such as Internet Explorer or Mozilla Firefox) |
2. HBCI PIN/TAN | Internet connection, payment transactions software (such as StarMoney from version 7.0 ServicePack 6, Quicken from Version 2008) |
3. HBCI with keystore medium | Internet connection, where appropriate floppy disk drive or USB port, payment transactions software (such as StarMoney from version 7.0 ServicePack 6, Quicken from version 2008) |
4. EBICS | Internet connection, EBICS ready software (such as StarMoney Business from version 4.0 ServicePack 6 with EBICS-extension, Proficash, Multicash, Genocash, SFIRM32) |
What transaction software is supported by Gallinat-eBanking, and what is the software recommended by Gallinat-Bank?
In principle you can use any payment services software available on the market. The individual applications do however often vary significantly in their detailed functions and the supported standards. A recommendation is also made difficult by the fact that the user requirements tend to be very different. The following products have found the highest approval from our clients:
StarMoney
Quicken
Proficash
We are not familiar with the detailed program specification. If you require us to do so we will however be glad to procure a particular product for you.
3. PIN (Personal Identification Number) and TAN (TransAction Number)
Please note: As of 02.01.2008 you can use the iTAN procedure (indexed TAN)! As of 04.10.2011 we additionally support the procedures mobileTAN (TAN is supplied via mobile phone) and Sm@rt-TAN plus (TAN is supplied via a TAN generator).
Can I myself unblock my account if it was locked because I entered the wrong PIN?
Yes. When you next login, enter the correct PIN and add a valid TAN when prompted to do so.
If you have lost your PIN, contact us directly. We will issue you with a new PIN and TAN. This will also occur automatically after more than eight wrong PIN inputs.
Call +49 (0) 201 81 16 153 or +49 (0) 201 81 16 200, or speak to your customer advisor.
How can I block online access to my account?
Enter a wrong PIN number three times when you log in. The account will be blocked and you can unblock it again at a later date (see previous answers).
Alternatively you can block the access to your account via “Administration” and “Block online access” in the menu navigation. Please keep in mind that this block cannot be undone by yourself.
If however PIN and TAN should fall into the wrong hands, call us immediately. We can put in place a block that is independent of PIN and TAN.
Call +49 (0) 201 81 16 153 or +49 (0) 201 81 16 200, or speak to your customer advisor.
Can I use my PIN and TANs for several accounts?
Yes, additional accounts can be added to your VR-Netkey.
Can I use the PIN for my eBanking for HBCI PIN/TAN as well?
Yes, the already allocated PIN and the TANs can be used for both procedudures.
Can I change my PIN myself?
This function is only available with PIN/TAN via internet. Open up your online banking and log in using your VR-Netkey or your Alias and PIN. Proceed by clicking the tab “Administration” and then – in the left hand side navigation bar – “change PIN”. Enter your new PIN twice and confirm the change by entering a TAN.
Please note: If you log in for the first time using your initial PIN, you will automatically be prompted to change your PIN. Your new PIN can consist of up to five digits.
Attention: Customers have reported to us that a window opened in their browsers, asking them to change their PIN as it had expired and therefore was no longer valid. Your PIN does not have an expiry date and is valid as long as your contract with Gallinat-Bank AG is valid! Do not fill in the fields in this window.
Instead please contact your advisor as soon as you can or call us on +49 (0) 201 81 16 153 or +49 (0) 201 81 16 200. For your protection we will immediately block your access. Please then have your computer checked by security experts and, if necessary, remove any malware.
Where can I find the direct debit section in the online banking portal?
You can’t. The online banking service can only execute transfers. For direct debits you need special payment services software.
4. VR-Netkey
What is the VR-Netkey?
Once you have signed the contract for your eBanking, we will issue you a VR-Netkey. Unlike the PIN, the VR-Key refers to your person and not to your account, which makes it possible to flexibly shape your eBanking contract according to your specific needs.
You can for example create a personal alias when you log into the eBanking which – in combination with the PIN – allows you to access all authorized accounts that are connected to this login alias. These can be your own accounts but also other people’s accounts for which you, as holder of the Key, possess account authority. With a single Key you can simultaneously manage individual accounts, joint accounts and business accounts; it is no longer necessary to change account and log in again. The VR-Netkey is valid for any account for which you possess online account authority.
The VR-Netkey meets the latest security requirements in the area of eBanking. With the VR-Netkey you can log into your eBanking without entering your account number. It is therefore impossible to directly detect the corresponding account number.
This personal number is shown on the acknowledgement of receipt. You will receive the PIN by mail.
Please note: Since November 14, 2007, you can no longer log in using your account number.
What is the Alias?
When you log into your eBanking, you can enter your VR-Netkey instead of the account number. In order to not have to memorise an additional combination of digits, you can then assign a password (Alias) which you will use instead of the VR-Netkey.
Can I modify the Alias?
You can of course change your Alias, as often as you like, or delete it again. This function can be found in the online banking portal in the tab “Administration” under “Alias”.
5. HBCI procedure (Homebanking Computer Interface)
Which version of HBCI is used by Gallinat-Bank?
We use versions 2.2 and FinTS 3.0.
What is the URI (Universal Resource Identifier » internet address) for HBCI?
HBCI via keystore medium | hbci01.fiducia.de |
HBCI PIN/TAN |
Can I manage more than one account with a single HBCI key?
Yes. Please speak with your customer advisor.
What is HBCI PIN/TAN?
The encryption method used by HBCI has been transferred to the PIN/TAN procedure. This created a technique independent from t-Online (i.e. PIN/TAN through the old BTX), used to transfer bank data via the internet. This technique has by now been included in the HBCI-standard, and we support it as well.
How do I set up the HBCI access for HBCI PIN/TAN?
A short explanation of the process as for the example of StarMoney can be downloaded here.
What is HBCI with a keystore medium?
This is a system that uses a storage memory device to save the key with which your transactions via the internet are encrypted. For security reasons we recommend that you use your payment services program to make a backup copy immediately after you have created the keystore medium.
How do I set up the HBCI acess for HBCI with a keystore medium?
A short explanation of the process as for the example of StarMoney can be downloaded (PDF, 2,1 MB) here.
6. Questions about Proficash
A transfer order or direct debit has to be changed, but the job has already been created. How do I proceed?
Go to „Routine transactions“ and „data transmission“. Select the job containing the wrong data and click „Delete/Cancel“. Please then answer the next two questions with “Yes”.
7. Frequent error messages
“Order has been rejected because it has already been submitted today”
Newly submitted orders are checked for double submissions on the basis of the recipient’s account number, bank sort code and the amount to be transferred. For security reasons this verification cannot be bypassed.
With the PIN/TAN procedure the verification occurs on the actual execution date of the order. As a consequence, a transfer sent off on a Friday night can only be re-executed the following Tuesday as all transactions incurred during the weekend are invariably entered as carried out on Monday.
For HBCI the verification is only done for the respective calendar day.
“Limit exceeded or available balance insufficient”
First possibility: As long as you have not made any other arrangements in your eBanking contract with Gallinat-Bank, access to your account is limited to a maximum of 10,000 euros per day, with higher amounts being rejected. If you are using more than one account with a single TAN sheet or a single HBCI user ID, this maximum transfer amount applies jointly for all accounts.
Second possibility: Although cheques and direct debits are immediately credited to your account, they are not instantly available for transfers. It takes five working days after the value date for the bank’s computer to assume that no return debit will occur, upon which it will clear the amount.
Third possibility: Card payments with PIN are not immediately debited from your account, but the outstanding amount is no longer available for transfers. If this is a problem, please talk to your customer advisor about and overdraft credit.
8. Questions about EBICS
What are the hash values for the bank key in the EBICS procedure?
If you are using EBICS software version 2.4 or before, please use the following hash values:
Hash value for the authentication key
32 C9 7E C5 5B 94 10 D5 88 F7 A7 1B 3A 3C 2A 5C D0 15 DC 66
Hash value for the encryption key
71 5B 93 9F 28 52 EB 8D A2 2A 64 CB D4 C0 0C 70 6C EB 34 5E
For version EBICS 2.4 or later the following hash values apply:
Hash value for the authentication key
6D BC 60 C4 F3 99 1C C5 D6 B6 43 3E 53 C0 26 9F C8 69 89 E4 60 F5 53 00 D6 D2 DC 05 F2 FB 3F ED
Hash value for the encryption key
31 60 B7 6D 14 41 ED 4A 18 30 7E 71 F6 D3 54 40 3A A6 BF 88 22 2B 90 5D 72 0E 76 9E 7F 3C C8 A8
These hash values ensure an additional verification of the EBICS access’ authenticity that is independent from the communication channel EBICS.
Which details are required for the bank parameter data file?
Customer ID: Your customer ID, as stated in our accompanying letter.
Member ID: Your member ID, as stated in our accompanying letter.
Hostname: FIDUCIA3
URI: https://ebics.fiducia.de/apps/CS or https://ebics.fiducia.de/apps/CSProcessing
Information regarding URI: Both addresses are valid. Depending on which software product you are using, you might have both of them displayed. In this case you can select either one.
EBICS bank parameter string: A3ZCHNNNJVJ
Information regarding bank parameter string: Depending on your software product, this value might be needed for identification. Please consult the help function of your software product.
