Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

What is FICAM

FICAM is the acronym for Federal Identity, Credential, and Access Management, an architectural roadmap and implementation guide designed to help U.S. federal government agencies improve their services' security, cost, and interoperability. FICAM addresses the intersection of digital identities, secure credentials, and access control into one comprehensive management approach. It also supports the integration of physical access control with enterprise identity and access systems and enables information sharing across systems and agencies with common access controls and policies.

...

  • The FED Unlimited Edition of Velocity must be updated to the version 3(v3.6 SP2 or later release), and you must obtain a license for the Velocity Certificate Checking Service (version 3v3.6.5.108 or later)

  • Each controller running in FICAM mode must include a SNIB3 communications expansion board (with SNIB3 firmware version 2v2.01.0005 or later) and an RS-485 Readers Expansion Board (RREB), or have the equivalent functionality built onto the mainboard

  • M2, M8, Mx, Mx-1, or Mx-1-ME controllers (CCM firmware version 7v7.5.63 or later)

  • To enroll PIV, PIV-I, or TWIC cards into Velocity, you also need a smart card reader with contacts (such as Identiv's SPR332 v2.0 Secure Class 2 PIN pad reader)

  • New FICAM-capable RS-485 card readers (such as Identiv’s uTrust TS Government readers, Veridt’s Stealth Bio, or Stealth Dual readers) are required

  • FICAM uses larger data structures that require more memory per credential, you should consider adding a memory expansion board to each controller running in FICAM mode or the user can switch to SNIB3 DB mode for extra user capacity

Info

For more information about Identiv’s FICAM Solution, see

...

:

...

https://www.identiv.com/products/physical-access/hirsch-government-ficam-solution

Info

For most customers, Identiv’s FICAM solution enables you to upgrade an existing Velocity system, instead of having to purchase and install a new physical access control system.

...

  1. Contact Identiv to purchase the VCCS

  2. Obtain the installation file for the VCCS from Identiv, and copy it to your Velocity Server

  3. Locate the installation file (such as VelocityCertService_3.8.5.29.exe), then right-click on it and choose the “Run as administratorcommand from the pop-up menu

  4. While running the VCCS setup, a dialog appears displaying the ValidationSystemID as shown. Please make a note of this ID.

...

  1. Right-click on the icon for Velocity’s Service Control Manager (in the Windows tray), and choose Settings.

  2. In the resulting Velocity Settings dialog:

    1. Click on the Velocity Cert Check Service entry in the left-hand pane.

    2. On the resulting Velocity Cert Check Service Settings page, click on the Configure button.

  3. On the General page of the resulting Velocity Cert Check Service Configuration dialog, copy the value in the System ID field to the Windows Clipboard, then paste it into an email message.
    For details about “Enforce FICAM Strict Compliance” checkbox, refer the Velocity help pages under Home - > FICAM Solution - > Configuring and Managing the Velocity Cert Check Service - > Velocity Cert Check Service Configuration dialog –> > General page

    Image RemovedImage Added
  4. Right-click on the icon for Velocity’s Service Control Manager (in the Windows tray), and choose Velocity License Manager.

  5. On the resulting Velocity License Manager window, copy the value of the Velocity Server ID field (on the top line) to the Windows Clipboard, then paste it into the email message.

  6. Compose your email message so that:

    1. It is addressed to vlas@identiv.com

    2. It has a Subject such as “License Request for Velocity Cert Check Service

    3. The Body includes both the System ID value and the Server ID values

  7. Send the email message

...

  1. Right-click on the icon for Velocity’s Service Control Manager (in the Windows tray), and choose Velocity License Manager.

  2. Copy the license key (which is a large block of letters and numbers) in the email message from Identiv to the Windows Clipboard. On the Velocity License Manager window, paste the license key into the Add / Renew License field, then click the Add / Renew button.

...

  1. Click on the menu button in the upper left corner of Velocity’s main window.

  2. Click on the Preferences button at the bottom of the drop-down menu.

  3. On the General tab of the resulting Velocity Preferences dialog, check the Enable the FICAM Mode checkbox.

    For more details about FICAM Degraded Mode Timeout, refer the Velocity help pages under Home - > FICAM Solution - > Enabling FICAM Mode and Specifying the FICAM Degraded Mode Timeout setting.

    Image RemovedImage Added
  4. Restart the Velocity client and all Velocity Services for the configuration to apply.

Creating the User Defined Fields for PIV Smart Card Readers

...

  1. From the Enrollment Manager’s menu bar, choose the Tools > User Defined Fields… command.

  2. On the User Defined Fields page of the resulting User Defined Setup dialog, create the user-defined fields needed for the data of a PIV card, with the Caption and Type specified.

    Image RemovedImage Added

    Image RemovedImage Added

  3. When you are finished creating the user-defined fields, click the OK button.

  4. From the Enrollment Manager’s menu bar, choose the Tools > Preferences command.

  5. On the General page of the resulting Preferences dialog, click on the drop-down list in the UDF Name Parsing section and select the user-defined field you created earlier for the Full Name, then click the OK button.  (This text data will be parsed into separate First Name, Middle Name, and Last Name fields.)

    Image RemovedImage Added
  6. Click the OK button on the message dialog informing you that these changes will not take effect until after the Enrollment Manager has been restarted, then close and reopen the Enrollment Manager.

Creating a Credential Template for PIV and PIV-I Smart Cards

...

  1. In Velocity’s main window, expand the System Tree (in the left pane of the Administration module) to display the Velocity Configuration > Credential Templates folder, and click on that folder.

  2. In the right pane of the Administration module, double-click the Add New Template item.

  3. In the New Credential Template Properties dialog, specify the appropriate values on the General page.

    Image RemovedImage Added
    1. In the Description field, type a unique descriptive name for this new credential template

    2. From the Badge Template drop-down list, select (None) because you will not be creating new printed badges

    3. From the IDF drop-down list, select an entry that includes Card

    4. From the card Type drop-down list, select 200-bit FASCN

    5. Click on the UDF… button (on the right of the Data field)

  4. On the Concatenate FASCN UDFs dialog, select the corresponding numeric UDF (previously defined in Creating the User-Defined Fields for a PIV Card) from each drop-down list, then click OK.

  5. For creating a credential template for PIV-I smart cards, follow steps 1 till 3. In the Concatenate FASCN UDFs dialog, for UDF field selection on Agency Code, select 'UUID' from the drop-down for PIV-I card.
    Unlike the PIV cards, the PIV-I cards accept only one UUID value.

    Image RemovedImage Added

Setting up the Door Properties

...

  1. Velocity supplies a default reader name, such as Reader 01.

  2. From the Disable reader above this level drop-down, select the threat level for the door.
    Note: Threat level is a numeric value assigned to each card reader for access to be granted. If the card threat level is greater than or equal to both the reader's and the system's threat level, access is granted. If the card threat level is less than either, access is denied. Changing the system's threat level can act to either grant or deny access to all the doors in the facility. The greater the number, the greater the threat level.

  3. Choose the appropriate RS-485 reader model from the Reader Type drop-down.

  4. The exact value for this OSDP Address field depends on the reader's manufacturer, and whether the reader is used for entry or exit. For example,

    • an Identiv reader's address should be set to 0 when it is the door’s entry reader, and set to 1 when it is the door’s optional exit reader

    • a Veridt reader's address should be set to 1 when it is the door’s entry reader, and set to 2 when it is the door’s optional exit reader

  5. The Update Reader Firmware... button appears only when the RS-485 Interface value is selected for the Reader Interface option and the selected Reader Type is one of the available TS readers by Identiv.

FICAM-Related Options on the Card Reader Setup

...

  1. Select the appropriate Custom Card Codes from the drop-down to remap the data. Only those card data maps previously defined for this system appear in this drop-down list.

  2. For FICAM, select Hex Pass-Through (NP) option in MATCH Algorithm (any bits).

  3. Check Enable Keypad only if the reader includes a keypad for entering PIN codes.

  4. For FICAM, select PIV-I/PIV-C, 32 Hex Digit UUID option in Fixed bit length cards .

  5. For FICAM, select either 200 bits in, 32 digits out or 128 bits in, 32 digits out in PIV Card (FASCN handling).

  6. Click OK. The , the Reader configurations gets downloaded to the controller.

  7. Reopen the Door Properties window.

  8. If secure OSDP reader type is used, then Goto Entry Reader - > Card Reader Setup tab and click the Initiate Secure OSDP Connection button as shown.

    Image RemovedImage Added
  9. The reader restarts and comes back online. Click , click OK.
    The reader firmware version is available in the General tab.

...

  1. Open the Microsoft Management Console (MMC) by clicking Start - > Run -> type mmc and hit [press Enter].

  2. In the Console window, choose File - > Add/Remove Snap-in..

  3. Under Available snap-ins, select Certificates and click Add then click OK.

  4. Select Computer Account and click Next.

    Image RemovedImage Added
  5. Click Local computer: (the computer this console is running on) and Finish.

    Image RemovedImage Added
  6. On the resulting Console window, select Certificates (Local Computer) - > Certificates - > More Actions - > All Tasks - > Import..

    Image RemovedImage Added
  7. In the Certificate Import Wizard window, click Next to continue to import the certificate.

    Image RemovedImage Added
  8. Select Browse to import the certificate and click Next.

    Image RemovedImage Added
  9. After choosing the Security type files. Click Next to proceed to Completing the Certificate Import Wizard window and click Finish as shown.

    Image RemovedImage Added
  10. The successful certificate import wizard window appears. Click , click OK to close the wizard.

For detailed instructions on how to configure the Windows system to trust the Federal Common Policy CA G2 (FCPCA G2) certificate, refer How to configure Windows System to trust the FCPCA G2 Certificate.

...

  1. From the Enrollment Manager’s menu bar, choose the Tools > Device Configuration… command.

  2. On the Device Configuration dialog, select PIV Reader tab.

    Image RemovedImage Added
    1. Make sure that the Enable PIV reader(s) option is checked.

    2. Make sure that the Default Card Type is set to FIPS 201 Contact.

    3. Click the Map UDF Fields… button.

  3. On the Map UDF Fields window:

    1. Select the Auto Map button to automatically map between like-named data objects on a PIV card and the corresponding user-defined fields that you created earlier in the UDF setup dialog previous.

    2. To manually map fields, click on an entry in the Document Field list, and drag it onto the corresponding entry in the UDF Field list.

    3. After you have finished specifying all of the mappings, click the Apply button, and then click the Close button.

  4. Back on the Device Configuration dialog, click the OK button.

  5. Click the OK button on the message dialog informing you that these changes will not take effect until after the Enrollment Manager has been restarted, then close and reopen the Enrollment Manager.

Enrolling a FICAM Credential

  1. Insert a PIV card into the Smart Card Reader.

  2. In the Enrollment Manager, click on the Add Person item in the left pane.

    Image RemovedImage Added
  3. At the bottom of the Personal Information pane on the right, click the Scan button.

  4. On the PIV Reader page of the resulting Verify Scanner Data dialog, verify that the Type is set to FIPS 201 Contact, and then click the Read Card button.

  5. On the resulting Card PIN dialog, type the PIN for this card and then click OK.

  6. After the card’s data has been read, click the Validate Certificates button.

  7. You may optionally click the View buttons to view the security certificates.

  8. Click the Accept button to close the Verify Scanner Data dialog.

  9. Back in the Enrollment Manager, click the Apply button (in the lower right corner of the Personal Information pane).

  10. Click on the Add New Credential from Template item, choose an appropriate credential template from the resulting Select Credential Template dialog, and click OK.

  11. In the resulting credential properties dialog, verify that the FASCN field is populated, and click OK.

  12. Download this new credential to your controllers.

  13. Remove the PIV card from your enrollment reader, and test the card at an appropriate door reader, to verify that everything is working properly.