A smart credential has two types of digital IDs:
● card—Identifies the card.
● card holder—Identifies the user who owns the card.
A smart credential sets the digital ID types, if required.
When you create a smart credential, that smart credential definition will have values for the digital ID configurations that it will use. If the smart credential definition had defaults for those values then the new smart credential will have those values set. Otherwise, it will not have values set.
Before you can create the smart credential for a user, the following must be true:
● If the type of digital ID is marked as required in the smart credential definition then it must be set in the user smart credential.
Create smart credential definitions
1. Click
>
Resources
> Smart Credential Definitions. The Smart
Credentials Definitions page appears.
2. Click Add. The Add Smart Credential Definition page appears.
3. Enter a Name for your smart credential definition.
4. Set Lifetime to the number of months before the smart credential expires. The default value is 60 (five years). The value can range between 1 month and 120 months (ten years).
5. Select the PIV Applet Config from the drop-down list. This setting specifies how information is encoded into the smart credential. The options include:
● PIV with Challenge Response PIN unblock
● Yubico YubiKey PIV
● PIV with PIN multi use
6. Define
the Digital ID Settings for your
smart credential application.
7. Define
the Smart Credential PIN Settings
of your smart credential application.
These are the PINs for mobile smart credential application user accounts. These settings define what can and cannot be included in a user PIN.
8. Define
the Definition Variables.
The Definition Variables are used to generate the mobile smart credential. For a smart credential definition to function properly, you must add all of the variables listed in the certificate authority associated with a smart credential definition.
9. Enter values for the Other settings.
a. For the Default Value, enter the default value for the variable This is the name of the user attribute, constant value, or multiple user attribute names that appear if no other value is entered for the variable. Enter the value enclosed in angle brackets.
Example: Setting Default to <User Principal Name> would cause an Identity as a Service user attribute with the name UPN to auto-populate any smart credential created with the UPN value from the profile information of the user being assigned a smart credential. The Default field is not case sensitive.
b. Select Is Required to require that a value be provided for this variable when a smart credential is configured.
c. Select Is Displayable to allow the value of this variable to be viewed by others.
d. Select Is Modifiable to allow the value of this variable to be modified after a value is entered for the variable.
10. Click Add. The variable is appears in the smart credential definition list.
11. After you have added all of the definition variables, click Save. The definition appears on the Smart Credential Definitions page.
The smart credential definition is ready to be applied to a mobile smart credential. You can assign mobile smart credential to your users provided that at least one certificate authority is also ready for use. See Manage Certificate Authorities for more information.