Beginning in Access It! v6.2, support has been added to run an Auxiliary Authentication Module (AAM) within the EP/LP-4502 Controllers. This engine may be used for the purpose of doing extended authentication against credentials. This is very useful in properly authenticating Personal Identity Verification (PIV) and similar credentials related to FICAM.
Support for the AAM is only available within the EP-4502 and LP-4502.
Only 16 readers can be supported by a single EP-4502 using the AAM.
The following components are required to complete the integration.
- Access It! min s/w v6.2.0.1
- HID pivClass Workstation (tested with s/w v1.4.2.0)
- HID pivClass PACS Service Administration (tested with s/w v1.4.2.0)
- One of the following controllers:
- EP-4502 min f/w 1.257
- LP-4502 min f/w 1.257
- EP/LP pivCLASS firmware add-on min f/w 5.4.126
- HID pivCLASS reader configured for half-duplex OSDP communication
The HID pivCLASS software is a separate application from the Access It!. The HID pivCLASS workstation is used to enroll credentials into the Access It! Universal.NET database and the pivCLASS PACS Service Administration is used to communicate to the EP/LP-4502's AAM. Prior to configuring the EP/LP controller, the HID pivCLASS service administration must be pre-programmed to accept a connection from the EP/LP's MAC address.
pivCLASS firmware add-on
The Panel Utility is required to download the necessary firmware file. To obtain the firmware required for the pivCLASS firmware add-on contact Access It! Technical Support.
- On the EP/LP-4502 set S1 - Configuration DIP Switch DIP 2 ON
- Apply power to the EP/LP-4502 controller
- Manually configure a computer to 192.168.0.100
- Using a crossover cable, connect computer to the on-board NIC of the EP/LP-4502
- Open the Panel Utility (Start | Programs | Access It! Universal.NET | Client Utilities)
- Click the Attach button
- Select model EP/LP-4502 96MB
- Select Comm Type TCP/IP
- Select Address 0
- Enter IP Address 192.168.0.251
- Select TCP Port 3001
- Click OK
Once connected, the lower right icon will report Online - Select Download SCP Firmware
- Navigate to the pivCLASS firmware add-on file
- Click Open
- Wait 90 seconds for firmware download to complete
- Click Detach
- Power down EP/LP-4502
EP Web Browser
- On the EP/LP-4502 set S1 - Configuration DIP Switch DIP 2 ON
- On the EP/LP-4502 set S1 - Configuration DIP Switch DIPs 1, 3 & 4 OFF
- Apply power to the EP/LP-4502 controller
- Manually configure a computer to 192.168.0.100
- Using a crossover cable, connect computer to the on-board NIC of the EP/LP-4502
- Open a web browser and navigate to 192.168.0.251
- On the EP/LP-4502 set S1 - Configuration DIP Switch DIP 1 ON
- Click Click Here to Login
- Click Continue to this website (not recommended).
- Enter a Username of admin
- Enter a Password of password
- Click Network from the left hand menu
- Under the section Interface 1, select Use Static IP configuration:
- IP Address: <Set accordingly>
- Subnet Mask: <Set accordingly>
- Default Gateway: <Set accordingly>
- Click Accept
- Click Host Comm from the left hand menu
- Within the Data Security drop list, select TLS if Available
- Click Accept
- Click Auto-Save from the left hand menu
- Set the Card Database Size accordingly
- Click the pivCLASS Embedded Auth from the left hand menu
- Enter the IP Address of the machine hosting the HID pivCLASS PACS Service
- Enter port number used by the HID pivCLASS PACS Service
Default port used is 10200 - Select (check) the Encrypt Communication using TLS/SSL if needed by the HID pivCLASS PACS Service
- Click Test Communication to verify settings
- Click Apply Setting from the left hand menu
- Click Apply, Reboot button
- Wait 60 seconds for EP/LP controller to reboot
- Remove power from the EP/LP controller
- Set all S1 - Configuration DIP Switch DIPs OFF
- Apply power to the EP/LP controller
Access It! Universal.NET
- Within Access It!, create a new IP Server Channel
- Within Access It!, create a new EP/LP-4502 with the specified amount of memory from the web configuration
- Select the Aux authentication module type of pivCLASS Embedded Auth (HID)
- Configure the Comm tab to use the new Channel and the IP address added within the the web configuration
- Click OK
- Click Save
- Within Access It!, edit a reader installed under the EP/LP-4502
- Within the Reader Settings tab select the Reader type of OSDP
- Within the Reader Settings tab select the default Authentication check to be used
- Click Save
Aside from a the default mode configured within the reader settings tab, the Authentication checks can also be set through Tasks or by sending a direct command to the reader.
Beginning with Access It! v7.0 the ability to use custom assurance profiles has been added. To add a new format, the database table ReaderAssuranceProfiles must be added to using the ProfileID from the pivClass server.