IdExchange 1.9.1

Unlocking a credential with PCA - Operator Assisted

Required Permissions: CredentialManager + CMS Issuer role

Important: The card must be locked before inserting into PCA.

image2018-1-11_9-1-19.png

If a card holder locks out their card or needs to change their PIN they can follow these steps to update their card.


Required CMS Configurations



In the CMS User Portal configuration, the Online unlock method must be set to Assisted Only.

image2021-7-23_10-25-1.png

In the security settings, the My Digital Id Card security must be set to LDAP Password

image2018-2-8_16-1-46.png



Steps

Step Number

Procedure

Example

1

Authenticate to PCA with an operator possessing the CredentialManager permissions.


2

Click the "Unlock/Update Credential" Button.

image2018-1-11_9-8-59.png

3

When asked, insert the locked credential into a reader.

image2018-1-11_9-9-14.png

4

The credential will be read and analyzed.

image2018-1-11_9-9-29.png

5

If the card is active the prompt for changing the PIN will appear.

active.PNG

6

Verify the user information and press "Confirm".

image2018-1-11_9-5-36.png

7

Confirm the identity verification.

m5.PNG

8

Instruct the user to create a new PIN.

image2018-1-11_9-10-23.png

9

Instruct the user to confirm the new PIN.

image2018-1-11_9-10-44.png

10

The credential will be unlocked.

image2018-1-11_9-11-14.png

11

The system will indicate when the unlock process is complete. Remove the credential.

image2018-1-11_9-13-15.png



Viewing the user's credential unlock history 

To view the history of the user follow these steps:

Step Number

Procedure

Example

1

Access the IDMS portal and click "manage" under "PIV".

Search for the user.

Identify the user and click "manage".

m1.PNG

2

Once the user is accessed, click the "history" tab.

Here you can view the user history.

Note the "unlock" is recorded and shown in the history of the user.

m2.PNG

3

Alternative way is to go to the IDMS portal and under "Reports" and click "User History".

Search for the desired user and click "Retrieve History".

m3.PNG

4

Here is the full history of the user.

Note the "unlock" is recorded and shown in the history of the user.

m4.PNG