This section defines smart card issuance and initialization parameters. The description of section parameters is given in the Table 5.
Table 5 – Smart card issuance parameters.
Option
Description
Maximum number of cards per user
The number that limits card quantity per user. Default value is 1.
Initialize card
If enabled, the card is initialized before issuance. Initialization deletes all the data stored on the card.
Set random user PIN
If enabled, a random user PIN will be set while issuing a card. If this option is enabled, the User PIN generation settings become available for editing:
Use only digits
Length (4 - 31 symbols)
Show generated user PIN to administrator
Show generated user PIN to user
The length of randomly generated PIN depends on the Minimum PIN length parameter value at the Card initialization tab.
The randomly generated PIN conforms to the following rules:
Contains Latin lowercase letters
Contains Latin capital letters
Contains digits
Contains special characters
Any symbol can be used only once
The randomly generated PIN can be communicated to the employee who performs card issuance. The randomly generated PIN can be communicated to the user or his/her manager via email notifications (see Notifications).
If the Issuance and Card initialization sections contain different values of user PIN length, then the greater value is used while issuing the card.
User PIN must be changed on first logon
If enabled, the user must change their card PIN upon first login to a workstation.
The option is supported by Thales (eToken and IDPrime) smart cards only.
Lock card
If enabled, the card is blocked after issuance. Therefore, the user must first unlock it by any of available methods (online or offline) and define a new PIN.
This option and Set random user PIN and User PIN must be changed on first logon are mutually exclusive.
Generate card name automatically
If enabled, one of the following user property values can be used as card name:
Common name
Logon name
Last name
E-mail
Organizational unit
String
Selected value would be automatically placed to the card name field in the issuance window. If Allow editing card name option is enabled, the name of the card can be changed before issuance by the user or by employee who performs card issuance.
Require a comment to the card
If enabled, the system administrator or operator must specify a comment while issuing the smart card in the management console.
Require tags to the card
If enabled, the system administrator or operator must specify the tags while issuing the smart card in the management console.