IdExchange 1.9.1

Unlocking a credential with PCA

Required Permissions: CredentialManager + CMS Issuer role

image2018-1-11_9-1-19.png

If a card holder locks out their card or needs to change their PIN they can follow these steps to update their card.


Required CMS Configurations

  1. In the Configuration\User Portal configurations, the Online unlock method must be set to Both Self and Assisted The automatic update operations must unable PIN Unlock and Card Lock/Unlock

    image-20250403-161928.png
  2. In the security settings, the PIN / Initial Password Display must be set to Disguised

    image-20250403-162019.png
  3. In the security settings section, the User Portal must be set to LDAP Password

    image-20250403-162115.png


Steps

Procedure

Example

1

Authenticate to PCA with an operator possessing the CredentialManager permissions.


2

Click the "Unlock/Update Credential" Button.

image2018-1-11_9-8-59.png

3

When asked, insert the locked credential into a reader.

image2018-1-11_9-9-14.png

4

The credential will be read and analyzed.

image2018-1-11_9-9-29.png

5

If the card is active the prompt for changing the PIN will appear.

active.PNG

6

Verify the user information and press "Confirm".

image2018-1-11_9-5-36.png

7

Confirm the identity verification.

m5.PNG

8

Instruct the user to create a new PIN.

image2018-1-11_9-10-23.png

9

Instruct the user to confirm the new PIN.

image2018-1-11_9-10-44.png

10

The credential will be unlocked.

image2018-1-11_9-11-14.png

11

The system will indicate when the unlock process is complete. Remove the credential.

image2018-1-11_9-13-15.png



Viewing the user's credential unlock history 

To view the history of the user follow these steps:

Step Number

Procedure

Example

1

Access the IDMS portal and click "manage" under "PIV".

Search for the user.

Identify the user and click "manage".

m1.PNG

2

Once the user is accessed, click the "history" tab.

Here you can view the user history.

Note the "unlock" is recorded and shown in the history of the user.

m2.PNG

3

Alternative way is to go to the IDMS portal and under "Reports" and click "User History".

Search for the desired user and click "Retrieve History".

m3.PNG

4

Here is the full history of the user.

Note the "unlock" is recorded and shown in the history of the user.

m4.PNG