Updated 10/11/2019 2
TEST CARD REQUEST INSTRUCTIONS
Customers may wish to use Test PIV Credentials to simplify testing with systems that interface to an identity credential.
Examples include physical security systems as well as systems that use PKI credentials for logical access. Often agency
vendors will want to have Test Cards to test their hardware and software as it is not convenient or practical to give them a
real card belonging to a Federal employee. Test Cards allow test processes to proceed in a way that does not
inconvenience anyone or force a real credential to be used. Additionally, new versions of cards will come to market or
hardware or software is changed. Therefore, customers can use Test Cards before either are introduced to an agency’s
production environment.
A Test Card is different from a production credential that is issued to a government sponsored employee or contractor. For
security purposes, a Federal Information Processing Standard 201 (FIPS 201) compliant system will never recognize a test
card as a valid credential. There are two major forms of test cards available: a “Generic” test card and a “Tailored” test
card. These are described below:
GENERIC - A generic test card is the simplest test card available. It is a test credential that acts as a credential for PIV
system testing. The test cards are made with “dummy” data to enable a vendor to test with various data sets. For instance,
one card will be “John Doe” and another one will be “Jane Doe.” The vendor will use them to ensure that each card is
properly read and that different data are presented.
The best example is testing a physical access system. The test cards provide the ability to test multiple people as well as
the speed and real distances for example.
To order generic test cards, specify xx generic test cards on this request form to receive cards with different data on them.
Note: These cards will have test PKI certificates on them. They are available for use with the Test Certificate Authority
(Entrust offers this service at MSO request.)
CUSTOM - A Custom test card is tailored specific to the agency affording the capability to define the User Principal
Name (UPN) and the network DNS suffix. This allows you to set up accounts on a network with dummy email addresses
for testing logical access for example. In this case, you would order 3 test cards with Mike.Jones@army.mil,
Mindy.Smith@army.mil, and Sally.Lars@army.mil as the preferred UPN. Alternatively, you could ask for 870003007@
Fedidcard.gov and cards will be produced (with associated test certificates from the Entrust Test SSP.) Now network
engineers can set up accounts for testing without involving acactive credentials.
The MSO offers credentials that can be tailored to your specific network and used to test PKI. Another example is that you
may have an agency-defined field that you want to be used in an application. For example at GSA, “P” stands for
“Property Pass.” The narrative tells us what you want to do so the card is created with the right data. You may want to
order a card with a “P” and maybe some without the “P.”
The Request Form
This form has four main objectives: 1) To produce your test card, 2) To obtain authorization to bill (form must be
completed by a government employee), 3) To deliver the cards to the right person, and 4) accountability. The test cards
can only be shipped in to locations in the United States and should only be given to known companies and vendors outside
your enterprise. Any deviation from that ruling should be discussed with the GSA MSO Test Card point of contact.