Archive

Archive for May, 2010

ACS Tech #Impact10 Child Check-in

May 27th, 2010

While at ACS Technologies Ideas to Impact Conference I have the opportunity to participate on a panel of  peers talking about Child Security.  My primary contribution in this workshop is discussing Check-In Systems; how to evaluate and deploy check-in systems as well as use of biometrics and information security.

I have blogged in the past about checkpoint so here I have compiled a few of the previous posts that might be helpful.

ACS CheckPoint – Why Biometrics? – April 2010 
ACS CheckPoint -  Why Vein Scanning? – April 2010
ACS CheckPoint -  Installing M2sys Vein Scan Server & Configuring the Database – April 2010
ACS CheckPoint – Installing M2Sys BioPlugin Vein Scanning Client – April 2010
ACS CheckPoint – Configuring the M2sys Vein Scanning Client and ACS CheckPoint – May 2010
ACS CheckPoint – ACS Convention CheckPoint 201 – May 2009

ACS Technologies ,

ACS CheckPoint Part 5: Configuring the M2sys Vein Scanning Client and ACS CheckPoint

May 21st, 2010

This is the final post in a 5 part series of installing M2Sys Scanning and CheckPoint.

Part 1: Why Biometric?
Part 2: Why Vein Scanning?
Part 3: Installing M2sys Vein Scan Server & Configuring the Database
Part 4: Installing M2Sys BioPlugin Vein Scanning Client
Part 5: Configuring the M2sys Vein Scanning Client and ACS CheckPoint

 

In the previous installation steps: evaluating the type of scanning and installing the server and client were documented.  Now final step of configuring the scanning client to connect to the database and work with ACS CheckPoint remains.

After you have confirmed that the server is operating correctly and you have connected the scanner and installed the driver you are ready to configure the client.

Workstation Configuration MUST be done by a user who has local admin rights, a user with less rights can make the changes but once the settings window is closed all changes are lost.

Since these workstations are public machines it is wise to make them as hardened as possible to prevent non-designed use of the workstation.

Configuring Client and Server Communications

The first step is accessing the settings portion of the application. 
This is done by clicking on the icon that looks like a finger print in the System Tray (near the clock). 

SysTray

 

The Finger Scan application will display and you have two options: Fingerprint Admin or Settings. 
Selecting Settings allows us to configure the client.  FingerPrint Admin will be used later to capture scans.

VeinScan0018

 

Next you are prompted for the Admin Password which by default is ‘Admin’

VeinScan0019

 

If you are running the server application on a separate machine from the workstation you need to change the Server Address from localhost to the IP address or the DNS name of the server. 
Note: DO NOT use the Fully Qualified Domain name, only enter the Server Name or the application will not connect.

While entering the server name choose how many scans the software will prompt you to capture.

Capturing two scans during registration allows the user to scan a finger on either hand.
Two fingers scanned is helpful for two reasons:

  • People forget which hand they registered, by capturing both hands this isn’t an issue
  • When you capture two fingers the user can try the second finger if the scan fails to lookup the individual.

VeinScan0021

 

Next Select the Notifications Tab

Below are the Default Values

VeinScan0022

 

Changing the value for how long to display the scan notification to a lower value than 5 has helped so when a person’s finger fails to scan for various reasons the right side of the screen doesn’t fill up with failed scan alerts during the check-in process.

VeinScan0023

 

Next choose the Security Tab

VeinScan0025

 

The default is to require a password for both Settings, Exiting the application and FingerPrint Admin

We elected to turn off requiring the password for FingerPrint (Vein Scan) admin for several reasons:

  • You can only set one password, and we didn’t want to give the password to change settings to volunteers.
  • It becomes very cumbersome for the volunteers to have to enter a password for registration admin.
  • Volunteers who have access to the workstations that can capture scans don’t really need restricted from accessing the scan admin.

VeinScan0026

 

Testing Client and Server Communications

At this time the client application has been configured and can be tested to confirm the client and server are communicating.

Open the BioPlugin application from the SysTray

SysTray

 

Select FingerPrint Administration

FingerPrintAdmin

 

Enter the Member ID for a test. 
Later once CheckPoint is configured the Member ID is the individual barcode assigned to each person in the database.

LaunchFPA

 

Enter the Value of the Member ID.
EnterID

 

Select the finger that you are scanning (the index fingers will be captured in the example below)
After selecting the finger “Click Here to Capture Finger Vein” and the application will go into capture mode.

Register

 

Once the scanner is in Capture mode, the following screen will display until the scanner has captured a vein scan.  The individual being scanned should lay the finger completely across the scanner and rest the finger on both the front and back ‘finger rests’ in the scanner.  After the scan is captured you will be returned to the previous window.

Capture

 

After the scan has been captured close the FingerPrint Administration window.
Launch Notepad and scan one of the fingers captured for the test.  If the system is working correctly notepad should display the value you used when register the test user on the first line and the cursor will move to the next line in the document.

Result

 

Configure BioPlugin and CheckPoint

After completing the test scan, re-launch the settings window and select Destination Window Tab.

VeinScan0027

 

Right Click on “My Test Keystroke Destination” and choose Rename.

VeinScan0028

 

Enter Destination Name ‘CheckPoint”
This is not telling BioPlugin where to send the scan, simply naming the destination you are going to define.

VeinScan0029

 

Next Change the Window Title from ‘Notepad’ to ‘Checkpoint’
Note: Window Title value is case sensitive

VeinScan0030

 

Next choose the Startup Tab

VeinScan0024

 

It is helpful to the end user if you define select several settings on this tab:

  • Load BioPlugin Snap-On when windows starts (for all users)
  • On Kiosks (self-service) choose Start Minimized
  • On Assisted Check-in/out locations it might be a helpful choice to not start minimized since these locations will be used to capture scans and it is helpful to have the application maximized for ease of use.
  • Select Launch another application after BioPlugin Loads and enter “c:\winacs\awcpkio.exe’

VeinScan0031

 

The BioPlugin client is now configured to work with Checkpoint. 

The final step to configure Check-in via vein scanning you must enable the setting ‘By scanning barcode’
Setup 

After the settings are complete restart the kiosk. After the reboot, you will be prompted to activate the software license.  You will need to login to the workstation as an Administrator to activate the software license.

  • If you purchased the licensing from ACS directly, contact support and provide support the Installation ID and they will activate the install and provide you with the Activation ID.  Enter this value and reboot the kiosk.

Once the client machine is configured, Launch CheckPoint Express Check-In start a session.  Users can now scan their finger and  CheckPoint will return the individual/families record for Check-in.

Register CheckPoint users to Check-in With Biometrics

When registering users, Open both ACS Desktop (CheckPoint Tab>Check IN/Out) and BioPlugin FingerPrint Administration.

Lookup the individual that you are registering.
Right click on the name of the person in the Individual List and select Copy BarCode

BarCode

 

Go to FingerPrint Admin and Paste the barcode into the BioPlugin Screen and proceed with the registration process that was used in the testing scenario above.  Once the individual is registered they can immediately visit any other kiosk running Express Check-in and scan their finger and Check-in.

enterbarcode

 

Optional Settings
If you would like for the Registration Admin to default to a finger other than the middle finger you can edit the client.ini file.  Since our first roll out of vein scanning was with Jr. High ministry we elected to change the default finger to the index finger.

Finger Print Scanning returnes the best results when the middle finger is the print registered, and M2sys has indicated that remains the same for vein scanning

Access the Client.ini file by browsing to c:\program files\BioPlugin\

VeinScan0032

Right Click on client.ini and choose Open.
Edit the line Default_LeftFinger=3 and change it to Default_LeftFinger=2
Edit the line Default_RightFinger=3 and change it to Default_RightFinger=2
Note: Thumb is = 1 and pinky is =  5

VeinScan0035

 

Previous Part 4: Installing M2Sys BioPlugin Vein Scanning Client

ACS Technologies, Church IT , ,

ACS CheckPoint Part 4 Installing M2sys BioPlugin Vein Scan Client

May 10th, 2010

This post is post 4 in a series of 5 posts on ACS CheckPoint and M2Sys Biometric Scanning.

Part 1: Why Biometric?
Part 2: Why Vein Scanning?
Part 3: Installing M2sys Vein Scan Server & Configuring the Database
Part 4: Installing M2Sys BioPlugin Vein Scanning Client
Part 5: Configuring the M2sys Vein Scanning Client and ACS CheckPoint

Previously I documented our process of selecting hardware and software as well as installing the server, now I will document Installing & Configuring M2Sys Vein Scanning Client.

This part of the installation is to install the application that allows the scanner to work and talk to the database to recall a record and identify a person to the application (in our case CheckPoint).

As previously mentioned, the M2sys Vein Scanning and Fingerprint Scanning applications are two separate applications for the related technology. At the time of writing this documentation it is not possible to use a vein and finger print scanners on the same computer concurrently.  Although I have been told by M2sys that a combined solution is in development to allow both scanners to be connected to the same workstation concurrently.

Note: Most steps are identical for Fingerprint Scanning Server and DB but Vein Scanning install requires a different installer than the BioPlugin for Finger Print Scanning.
Your mileage may very depending upon your environment, do due diligence before following these procedures.

Installing M2Sys BioPlugin Client
After downloading the installer running it on a XP, Vista, or Windows 7 workstation is fairly standard.  This installer does not install the server application and the software will not work without the proper install of the server application.

Do not connect the Scanner to the computer before starting the client install process.  Connecting the hardware prior to the client install can make the device driver install significantly more difficult.

Start the installer:

VeinScan0001

 

Agree to the Licensing Agreement

VeinScan0003

 

Enter your User and Organization Names

VeinScan0004

 

Choose your Installation Location
The Default is C:\Program Files\BioPlugin\

VeinScan0005

 

Choose Install to confirm the installation configuration

VeinScan0006

 

Installation Continues without any additional user interaction

VeinScan0007

 

Click Finished when the Install is done.

VeinScan0010

 

After the installer finishes you are prompted to install the scanner

VeinScan0012

 

After you connect the scanner you may be prompted to locate the driver.

VeinScan0013

 

Hit Browse and navigate to C:\Program Files\BioPlugin\Drivers\ and locate the file HjmCap.sys
The file will be located in the Installation Destination that you choose earlier in the install process.

VeinScan0014

 

VeinScan0015

 

VeinScan0016

 

After you have located the driver the installation process is complete.

The next step is to configure the M2sys Vein Scanning Client and ACS CheckPoint.

Previous Part 3: Installing M2sys Vein Scan Server & Configuring the Database

Next Part 5: Configuring the M2sys Vein Scanning Client and ACS CheckPoint

ACS Technologies, Church IT , ,

ACS Livestor and RDS 2008R2

May 10th, 2010

Livestor is a backup product offered by ACS Technologies.  We use this product to backup our ChMS Data to get the data off site.  The off site primary storage is in the ACS Datacenter in Florence and replicated to their DR Datacenter in Charlotte.

While the pricing model doesn’t scale well for large amounts of data backup, it has proven cost effective for our ACS Database backup to be stored in the Florence datacenter.  We have from time to time given ACS authorization to access the backup and test an upgrade specifically on our data. Additionally it has saved time when ACS needs our dataset to troubleshoot an issue and the backup is already local to their support group.

So in the continued process of migrating our ACS server to 2008 R2 there are a couple items to note when installing Livestor on a 2008 R2 server. 

Getting on my soap box for a few seconds, if the Livestor application would run as a service, these notes would be completely a NON-ISSUECome on ACS MAKE LIVESTOR A SERVICE!!!!  Having a server stay logged in for your backup application is CRAZY!  Even ACS Desktop Backup runs as a service!

When Livestor installs it defaults to add the application to the start menu start up for all users, so when you are using ACS in a Remote Desktop Server (formerly Terminal Server) environment Livestor attempts to launch when every user logs in.  In 2003 this was a quick fix to move the application to a single user’s startup but the Path for the all users Start menu has changed in 2008.

To make Livestor work on a 2008R2 RDS server and not start for ever user you will have to:

  • Copy Livestor Service Center shortcut to:
        C:\Users\%username%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
  • Delete the Livestor Service Center shortcut from:
        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup

One other 2008R2 item to be aware of, Disable UAC – Livestor has a built in updater, in order to update UAC has to be turned off for the update to process.  Once the updater is finished you can re-enable UAC and launch Livestor (or leave UAC disabled so it doesn’t fail every time Livestor updates)

ACS Technologies ,

Serving & Security Best Practices Web Event

May 7th, 2010

Check out this web event Hosted by ACS Technologies.  Angus Davis has great insight on Volunteer and Children’s security and you should check out the web event. Register by clicking one of the options below. 

ACSWebevent

 

Note: NON-ACS Customers, when registering Enter “CITRT” as your ‘Site Number’.

register1

                                                                                OR

register2

Church IT ,