IdExchange 1.9.1

Configuring Secure Data Export

The Secure Data Export capability allows the IDMS to securely transfer enrollment and history data to another IDMS so that the person does not need to go through the identity proofing process again. This feature can save time and costs by allow enabling organizations to securely reuse identity information that was previously collected. The IDMS implements a secure multi-phase export and import protocol protected by multi-factor authentication and strong cryptography to ensure data is securely transferred only after the appropriate approvals have been made.

Prerequisites 

The record must be exported using controls so that the export process is secured and is logged.

  1. Client certificate installed on sending IDMS

  2. Two IDMS servers on the same version:

  3. Sending IDMS must have access to CMS database

  4. User that being exported must have an active credential

  5. User CMS ID must match 

  6. User Credential Policy must match

  7. IDMS servers are able to access each other via port 443/444 (SSL) 

Installation Procedure

Sending System


Step Number

Procedure

Example

1

Generate a client certificate and install the client certificate into the local store.


2

Authenticate to IDMS portal with Admin privileges.

Press Update

image2018-9-27_8-37-19.png

3

Go to Administration, Click System Connections, Press the "Add a new CMS reporting connection" button.

image2018-9-27_8-38-47.png

4

Configure the CMS Credential Report Database

image2018-9-27_8-44-46.png

5

Authenticate to IDMS portal with Admin privileges.


Press "Features" under Administration tab.

1.PNG

6

Verify that the "Secure Data Export" feature is enabled



Press Update

2.PNG

7

Click "System Connections" under Administration tab.

system connections.PNG

8

Select "Add a new Export Data Receiving system".

add.PNG

9

Configure the IDMS server


Install the client certificate in the local users store then insert the Thumbprint under "Certificate Serial Number".


Save.

config.PNG

10

Verify the connection

If fails attempt to browse to the receiving system via a web browser (to test basic connectivity)

check.PNG




Receiving System

Add a new operator with the certificate serial number that will be used to connect to the system

Grant the new operator the role of Enrollment Officer


Steps to export data




1

Issue a credential to a user


2

Go to the  Credential and Certificate Status Report

3.PNG

3

Click the Synch Button to display the "Synchronize with CMS" transaction button.


Click the Synchronize with CMS button

5.PNG


Stage 2: User Consent




1

Have the user login to the IDMS with their smart card.


2

In the action button, click Request Export

image2018-9-26_14-9-56.png

3

Confirm the export

image2018-9-26_14-10-13.png

4

Process is complete



Stage 3: Operator Export




1

Look up the user


2

In the User Management Portal, select "Export User

image2018-9-26_14-11-19.png

3

Provide an export reason

image2018-9-26_14-11-32.png

4

Press Yes to confirm


5

Go to Event logging, verify the user was exported.

image2018-9-26_14-12-7.png