...
Contact Identiv to purchase the VCCS
Obtain the installation file for the VCCS from Identiv, and copy it to your Velocity Server
Locate the installation file (such as VelocityCertService_3.8.45.41.exe29), then right-click on it and choose the “Run as administrator” command from the pop-up menu
While running the VCCS setup, a dialog appears displaying the ValidationSystemID as shown. Please make a note of this ID.
If your Velocity system is already running the previous certificate checking service provided by Identiv’s Professional Services Group, the installer will automatically upgrade your system to use the new Velocity Cert Check Service, and your existing configuration settings will be migrated from the config.xml file into the Velocity database.
...
Right-click on the icon for Velocity’s Service Control Manager (in the Windows tray), and choose Settings.
In the resulting Velocity Settings dialog:
Click on the Velocity Cert Check Service entry in the left-hand pane.
On the resulting Velocity Cert Check Service Settings page, click on the Configure button.
On the General page of the resulting Velocity Cert Check Service Configuration dialog, copy the value in the System ID field to the Windows Clipboard, then paste it into an email message.
For details about “Enforce FICAM Strict Compliance” checkbox, refer the Velocity help pages under Home -> FICAM Solution -> Configuring and Managing the Velocity Cert Check Service -> Velocity Cert Check Service Configuration dialog –> General pageRight-click on the icon for Velocity’s Service Control Manager (in the Windows tray), and choose Velocity License Manager.
On the resulting Velocity License Manager window, copy the value of the Velocity Server ID field (on the top line) to the Windows Clipboard, then paste it into the email message.
Compose your email message so that:
It is addressed to vlas@identiv.com
It has a Subject such as “License Request for Velocity Cert Check Service“
The Body includes both the System ID value and the Server ID values
Send the email message
...
Right-click on the icon for Velocity’s Service Control Manager (in the Windows tray), and choose Velocity License Manager.
Copy the license key (which is a large block of letters and numbers) in the email message from Identiv to the Windows Clipboard. On the Velocity License Manager window, paste the license key into the Add / Renew License field, then click the Add / Renew button.
Now, the VCCS is installed and licensed on your system.
...
Click on the menu button in the upper left corner of Velocity’s main window.
Click on the Preferences button at the bottom of the drop-down menu.
On the General tab of the resulting Velocity Preferences dialog, check the Enable the FICAM Mode checkbox.
For more details about FICAM Degraded Mode Timeout, refer the Velocity help pages under Home -> FICAM Solution -> Enabling FICAM Mode and Specifying the FICAM Degraded Mode Timeout setting.Restart the Velocity client and all Velocity Services for the configuration to apply.
...
From the Enrollment Manager’s menu bar, choose the Tools > User Defined Fields… command.
On the User Defined Fields page of the resulting User Defined Setup dialog, create the user-defined fields needed for the data of a PIV card, with the Caption and Type specified.
When you are finished creating the user-defined fields, click the OK button.
From the Enrollment Manager’s menu bar, choose the Tools > Preferences command.
On the General page of the resulting Preferences dialog, click on the drop-down list in the UDF Name Parsing section and select the user-defined field you created earlier for the Full Name, then click the OK button. (This text data will be parsed into separate First Name, Middle Name, and Last Name fields.)
Click the OK button on the message dialog informing you that these changes will not take effect until after the Enrollment Manager has been restarted, then close and reopen the Enrollment Manager.
...
In Velocity’s main window, expand the System Tree (in the left pane of the Administration module) to display the Velocity Configuration > Credential Templates folder, and click on that folder.
In the right pane of the Administration module, double-click the Add New Template item.
In the New Credential Template Properties dialog, specify the appropriate values on the General page.
In the Description field, type a unique descriptive name for this new credential template
From the Badge Template drop-down list, select (None) because you will not be creating new printed badges
From the IDF drop-down list, select an entry that includes Card
From the card Type drop-down list, select 200-bit FASCN
Click on the UDF… button (on the right of the Data field)
On the Concatenate FASCN UDFs dialog, select the corresponding numeric UDF (previously defined in Creating the User-Defined Fields for a PIV Card) from each drop-down list, then click OK.
For creating a credential template for PIV-I smart cards, follow steps 1 till 3. In the Concatenate FASCN UDFs dialog, for UDF field selection on Agency Code, select 'UUID' from the drop-down for PIV-I card.
Unlike the PIV cards, the PIV-I cards accept only one UUID value.
...
Open the Microsoft Management Console (MMC) by clicking Start->Run-> type mmc and hit [Enter].
In the Console window, choose File-> Add/Remove Snap-in..
Under Available snap-ins, select Certificates and click Add then click OK.
Select Computer Account and click Next.
Click Local computer: (the computer this console is running on) and Finish.
On the resulting Console window, select Certificates (Local Computer)-> Certificates-> More Actions-> All Tasks-> Import..
In the Certificate Import Wizard window, click Next to continue to import the certificate.
Select Browse to import the certificate and click Next.
After choosing the Security type files. Click Next to proceed to Completing the Certificate Import Wizard window and click Finish as shown.
The successful certificate import wizard window appears. Click OK to close the wizard.
For detailed instructions on how to configure the Windows system to trust the Federal Common Policy CA G2 (FCPCA G2) certificate, refer How to configure Windows System to trust the FCPCA G2 Certificate.
...
From the Enrollment Manager’s menu bar, choose the Tools > Device Configuration… command.
On the Device Configuration dialog, select PIV Reader tab.
Make sure that the Enable PIV reader(s) option is checked.
Make sure that the Default Card Type is set to FIPS 201 Contact.
Click the Map UDF Fields… button.
On the Map UDF Fields window:
Select the Auto Map button to automatically map between like-named data objects on a PIV card and the corresponding user-defined fields that you created earlier in the UDF setup dialog previous.
To manually map fields, click on an entry in the Document Field list, and drag it onto the corresponding entry in the UDF Field list.
After you have finished specifying all of the mappings, click the Apply button, and then click the Close button.
Back on the Device Configuration dialog, click the OK button.
Click the OK button on the message dialog informing you that these changes will not take effect until after the Enrollment Manager has been restarted, then close and reopen the Enrollment Manager.
...
Insert a PIV card into the Smart Card Reader.
In the Enrollment Manager, click on the Add Person item in the left pane.
At the bottom of the Personal Information pane on the right, click the Scan button.
On the PIV Reader page of the resulting Verify Scanner Data dialog, verify that the Type is set to FIPS 201 Contact, and then click the Read Card button.
On the resulting Card PIN dialog, type the PIN for this card and then click OK.
After the card’s data has been read, click the Validate Certificates button.
You may optionally click the View buttons to view the security certificates.
Click the Accept button to close the Verify Scanner Data dialog.
Back in the Enrollment Manager, click the Apply button (in the lower right corner of the Personal Information pane).
Click on the Add New Credential from Template item, choose an appropriate credential template from the resulting Select Credential Template dialog, and click OK.
In the resulting credential properties dialog, verify that the FASCN field is populated, and click OK.
Download this new credential to your controllers.
Remove the PIV card from your enrollment reader, and test the card at an appropriate door reader, to verify that everything is working properly.