IdExchange 1.9.1

CMS Configuration requirements for PCA based activation

The client interacts with the credential management system for various functions including; user data retrieval, card status inquiry and request management. The following configurations must be in place for the client to work properly.

Required CMS Settings

Procedure 

1

Install the Visual C++ 2010 40219 Runtime or verify that the Visual C++ 2010 40219 Runtime is installed.

Install 64 bit and 32bit version.

Install 32bit version

image-20240514-140923.png

Install 64bit version


c++ version.PNG

2

Operator with activator permissions

The operator must also have a minimum of the CMS Issuance role with the additional permission of Help Desk, Lookup, Activate Card.



Configuration → Roles → Issuance

image2017-2-9 5:47:42.png
image2022-5-19_6-3-13.png

3

User Attribute Search

The User ID LDAP Attribute must be set to sAMAccountName

image2018-11-25_11-24-21.png

4

Photo retrieval

The CMS needs to display the photo in the search result table.


Configuration → Customization → User Attributes (from drop down menu)

*case sensitive

image2022-5-19_6-4-7.png

5

*Optional: Biometric Authentication *Only required for when performing biometric authentication with PCA.

Within the generic plugins, the

Biometric (plugin configuration) must be configured to retrieve biometrics by calling the biometric plugin.

DEVICE_INFO.plugin.client = PIV_BioMatchOnServerSample

image2017-7-25 14:36:4.png
image2022-5-19_6-4-48.png


*Verify that the PIV_BioMatchOnServerSample.input only returns the fingerprints. The quality score must be ignored because the PCA receives the quality score from the template.

*Verify the credential policy in place has the fingerprint application configured within the CMS.

image2018-6-18_13-16-28.png


Verify the CyberArmed BioAdaptor software is installed.

6

MyDigitalId Configurations

The Authentication method must be set to LDAP password

image2022-5-19_6-5-18.png


Configuration → Security Settings

7

Card Unlock Configurations

MyDigital ID must also be configured using these guidelines Unlocking a credential with PCA