This article describes how to pre-personalize a batch of smart cards in Smart ID Certificate Manager, using the Key Generation System (KGS). KGS is not supported on Linux.
Smart card reader
To use a smart card reader to pre-personalize smart cards is only recommended for small scale production, and a smart card reader can only be used for electrical pre-personalization.
Smart card printer
For large volume production and surface printing on the cards, a smart card printer is required.
Prerequisites
Prerequisites
The following prerequisites apply:
- The KGS is running
- A card reader or a card printer is configured.
- If a batch card is required an associated batch card reader must be configured.
- An appropriate card profile exists.
- A file containing the PIN encryption key exists.
Step-by-step instruction
Produce smart cards
If you are using a printer with a card feeder, you may control the number of cards to produce in two different ways:
- Put the exact number of cards in the feeder.
OR - Specify the number of cards in the KGS Start window.
To pre-personalize smart cards:
- If you use a card printer with feeder, specify the number of cards in either of the following ways:
- Collect as many cards you want to pre-personalize and put them in the card feeder.
OR - Put any number of cards in the card feeder.
Later in the procedure, you need to specify the Number of card(s) in the KGS Start dialog box.
OR - If you use a card reader, put a card in the target card reader.
- If the current card type requires a batch card, insert the batch card in the card reader.
- Start the KGS by clicking Start on the taskbar. Select Programs > Certificate Manager – KGS. The Start dialog box will appear.
- In Card profile, browse to select the appropriate card profile (extension .cpf).
Card profiles are located in the directory: <install_root>\cardprofiles
For more information about card profiles, see “Card Profiles” in Certificate Manager Key Generation System Operator's Guide. - In PIN encryption certificate, browse to select the appropriate certificate (extension .crt). Select a certificate delivered by the current CA.
The certificate files are normally located in the directory: <install_root>\certs
For more information about the PIN encryption key in certificates, see “PIN Encryption Key” in Certificate Manager Key Generation System Operator's Guide. - If you use a card printer with feeder, specify the Number of card(s) if needed.
- Click Start. The Generate seed window will appear.
- To generate a seed required for key generation, move the cursor over the window until the box disappears.
If you stop moving the cursor too soon, you will get a warning. - When the seed has been generated, the pre-personalization starts.
During the process, the Status window is displayed.