IdExchange 1.9.1

YubiKey Issuance

These instructions provide procedures for installing IDMS to issue YubiKey Devices.

Planning


Prerequisites

These tasks must be performed before the installation starts. These tasks are independent of the IdExchange install.

Grant IDMS Certificate Issuance Permissions

Create the Enrollment Agent

Certificate template for Derived PIV Authentication

Installation

Install the IDMS Application


Configuration

Microsoft Active Directory

Retrieving Custom Active Directory Attributes

Microsoft CA Connection


Create a policy for the Yubikey 





1

In the IDMS portal click "Credential Types" under "Administration" tab.

Click "Create a new credential policy".

policy51.JPG

2

Follow the format on the page.

Credential Policy Name = Give it a name

Credential Policy Key = Give it a key code

Credential Policy description = Give it a description.

Match the remaining settings with the example shown. (Picture 1)


Click "Add".

policy.JPG

(Picture 1)

3

Next to the policy that was created above click "Manage".

policy1.JPG

4

Match the configurations.

policy3.JPG policy4.JPG policy5.JPG policy6.JPG policy7.JPG

5

Click Update





Update Operator Roles 





1

In IDMS portal click "Operators" under "Administration" tab.

Next click on "mange" next to the user.

operator.JPG

2

Click on the roles to add them to the operator.


Roles required :

"Requester"

"Enrollment Officer"

"Approval Officer"

"System Manager"

"Credential Manager"

Once added, press "Update Roles"

operator1.JPG