Skip to content
English
  • There are no suggestions because the search field is empty.

C•CURE ACS Integration Configuration Guide

This guide walks you through integrating the Alcatraz Platform with Software House C•CURE 9000 via the Victor Web Service. Once configured, the Platform syncs credentials, clearances, and personnel data from C•CURE, and sends Alcatraz security events to the C•CURE Journal.

NOTE: Software-based ACS Integrations are a licensed feature from Alcatraz and are not required for a functioning Alcatraz system. Contact Alcatraz Sales for more information.

1. Requirements

Alcatraz Platform Software

v3.6.6 or newer (On-prem or Cloud*)

C•CURE 9000

2.9-SP4, SP5, SP6 Enterprise

3.0-SP1, 3.0.3, 3.0.4

3.1

C•CURE 9000 License

CC9WS-ALCAI - "Alcatraz AI - Frictionless Access - Integration"

For C•CURE 9000 v2.9.0 the license option must be added with an injection script (see Section 2.1). This step is not required for v3.0 or newer.

Network Ports

TCP 443 - outbound from the Alcatraz Platform (or Proxy Service) to the victor Web Service server.

TCP 3033 - outbound from the Alcatraz Proxy Service to the Alcatraz Cloud (cloud deployments only).

* Cloud deployments require the Alcatraz Proxy Service, see Section 4.

Cloud-hosted deployments connect the Alcatraz Proxy Service to your Alcatraz-hosted cloud instance.

2. Configure C•CURE

The following procedure verifies the Alcatraz license and creates the Privilege and Operator that the Alcatraz Platform will use for syncing with C•CURE via the victor Web Service.

2.1. Verify the Alcatraz Integration License

Open License Administration and confirm that "Alcatraz AI - Frictionless Access - Integration" appears under Options.

C•CURE 9000 v2.9.0 only: the license option must be added with an injection script, executed on each C•CURE server (each SAS) that the Alcatraz Platform will connect to. This step is not required for v3.0 or newer.

Create a batch file (sample.bat) with the following contents:

InsertLicenseOption /U /V /S:"WIN-L4C78I7S7D5\SQLEXPRESS" /N:"Alcatraz AI - Frictionless Access - Integration" /A:"Alcatraz AI" /G:5eb9318d-8e8b-49bf-9c61-0f012cb0123f /C:2 /P:0

@pause

In the sample, WIN-L4C78I7S7D5\SQLEXPRESS is the name of the SQL instance where the C•CURE database is located - update it to your actual SQL instance name. The Alcatraz Integration GUID 5eb9318d-8e8b-49bf-9c61-0f012cb0123f must NOT be changed.

EXECUTION

  1. Copy the batch file to the computer running C•CURE, into: C:\Program Files (x86)\Tyco\CrossFire\Tools
  2. Right-click the batch file and select Run as Administrator.
  3. Verify success: launch License Administration and check that Options shows "Alcatraz AI - Frictionless Access - Integration 0/10".

2.2. Create the Privilege

1. In the C•CURE Administration application, select Configuration → Privilege → New.

 

 

 

 

 

 

 

 

 

2. Assign the appropriate partitions to the privilege.

3. Create read-only permissions for the following:
  • Personnel → Personnel Records → Credential
  • Personnel → Personnel Records → Personnel
  • Personnel → Personnel Records → Custom Clearance
  • Personnel → Personnel Related → Clearance
  • Personnel → Personnel Related → Personnel Type
  • Personnel → Personnel Related → CHUID Format
  • Controllers → iSTAR → iSTAR Readers
  • Controllers → iSTAR → iSTAR Door
  • Controllers → Elevators → Elevator
  • Configuration → Group

 

4. Check Enabled, then Save and Close.

5. Under Configuration → Journal Trigger, select Edit → New, check Enabled, then Save and Close. (The Journal Trigger is required for Send Security Events - it allows Alcatraz events to be written to the C•CURE Journal.)

IMPORTANT - partition access. The privilege must include the partitions that contain the doors, readers, personnel, and credentials you want to sync. If a required entity is in a partition the Operator cannot access, synchronization fails even with the permissions above. Grant only the partitions Alcatraz needs - assigning everything makes the integration load unnecessary entities and can slow synchronization.

2.3. Create the Operator

  1. In the C•CURE Administration application, create an Operator and Add the read-only privilege created in Section 2.2.
  2. Note the User Name and Password - you will enter them in the Alcatraz Admin Portal in Section 3.2.

NOTE: You can see when this Operator logs in and out in the C•CURE Monitoring Station's Activity Viewer.

3. Configure the ACS Integration in the Alcatraz Admin Portal

3.1. Before You Start

WARNING: When initially enabled, the ACS Integration will delete profiles that do not have at least one badge that is also present in the ACS. It is recommended that a VM snapshot is generated and the system is backed up before attempting to configure an ACS Integration.

IMPORTANT: Card Format Mapping (facility codes): The facility codes for cards to be synced must be configured BEFORE enabling the ACS Integration. Failure to do so could result in the deletion of profiles. In the Card Format Mapping list (Account → ACS Integration), assign facility codes to each card format the Alcatraz Platform should sync with C•CURE. If a card format is missing from the list, add it in the Card Formats section - see Adding Card Formats.

Pre-enable checklist

  • Take a full system backup.
  • Assign facility codes to the card formats that the Alcatraz Platform should sync with C•CURE.
  • If you plan to use CHUID Format Mapping, configure at least one CHUID format before enabling the integration.
  • Plan reader-to-Rock mapping.
  • Confirm network ports are open (see Requirements).
  • Confirm the C•CURE Operator has only the permissions it needs - not full partition access.

Planned C•CURE maintenance: Disable the ACS Integration in the Alcatraz Admin Portal before performing maintenance, upgrades, or restarts on the C•CURE server or the victor Web Service, and re-enable it once C•CURE is fully back online.A full sync starts automatically when the integration comes back online - no manual sync is needed. Disabling matters because the automatic sync also runs whenever a dropped connection re-establishes on its own - if the integration stays enabled while C•CURE is only partially available, that sync may treat missing data as deleted and remove valid profiles.

3.2. Main Settings

In the Alcatraz Admin Portal, go to Account → ACS Integration → Enable ACS Integration, then select C•CURE from the ACS Integration list.

ACS Integration

C•CURE

Client version

Select the option matching your C•CURE 9000 version: 2.9 - 3.0 or 3.1. (Selecting 3.1 requires Platform v3.4.2 or newer.)

Victor Web Service URL

victor Web Service URL including the protocol prefix.

Example: https://192.0.2.32/victorwebservice/

The victor Web Service may run on a machine other than the C•CURE server - in that case, use that machine's hostname, IP address, or FQDN.

Username

The C•CURE Operator created in Section 2.3.

Password

Password for the C•CURE Operator.

Schedule Full Sync

Time of day to start a full synchronization with the ACS.

Use Proxy



Certificate in PEM format

Enables the Certificate in PEM format download, for use with the Alcatraz Proxy Service (for cloud deployments - see Section 4).


Available only when Use Proxy is checked. Click Download to save the PEM certificate, then use it when installing the Alcatraz Proxy Service

Bio opt-out sync

The C•CURE personnel field used to identify people who have opted out of facial authentication (default: Logical3). Personnel flagged in this field are excluded from biometric enrollment.

Auto delete disabled profiles after

Grace period after which Alcatraz profiles tied to disabled ACS personnel records are automatically deleted: Do Not Delete (default), 10, 30, or 90 days, or a custom value. Profiles are deleted at midnight based on the chosen time period.

Use CHUID Format Mapping

Syncs credentials using the CHUID formats defined in C•CURE. Configure at least one CHUID format before enabling this option - enabling it with no CHUID format configured can produce an incorrect initial sync.

Manage Visitors from the ACS

Syncs C•CURE visitor records so visitors are managed from the ACS.

Send Security Events

Sends Alcatraz security events to the C•CURE Journal. Requires the Journal Trigger created in Section 2.2, step 5.

Advanced Logging

Produces more detailed ACS Integration logs, listing exactly which credentials were skipped and why, instead of an aggregate count.

Use Alternate Keep Alive

Uses an older keep-alive mechanism for compatibility with older C•CURE versions. Enable this only if you experience frequent connection losses.

Disable Data Deletion

When enabled, Alcatraz only receives information from your ACS - no biometric profiles, credentials, readers, clearance levels, or other applicable information will be deleted in Alcatraz. (Requires Platform v3.4.2 or newer.)

Bio Consent Enrollment*

Requires explicit consent as part of biometric enrollment for synced personnel.

* Bio Consent Enrollment: is a specific feature. If checked, ACSI will look for the specified field in CCure and look for a match in the field's value - the value is free text and must match exactly between AHP and CCure. The field is a User-Defined Field in CCure that the customer has configured. It controls who is allowed to enroll. The idea is that users who have consented to biometrics are marked in CCure and allowed to enroll. The Rock/AHP does a live check with CCure when enrollment is started.
 

Card Format Mapping: below the settings, the Card Format Mapping list shows the card formats and facility codes the integration will use. Card formats themselves are managed in the Card Formats section above (see Adding Card Formats).

Notes:

  • Test Connection: click Test Connection to verify communication with C•CURE, then Save. When using the Alcatraz Proxy Service, Test Connection always reports unsuccessful - this is expected; verify via Section 6 instead.
  • ACS Integration status can be seen at the top of the "Account" page and in the "ACS Integration" section under "Account."

4. Installing Alcatraz Proxy Service (Cloud Deployments)

Alcatraz Proxy Service opens a connection between the Alcatraz Platform and C•CURE when the two are running in separate networks. Install it on a server that can reach the victor Web Service directly over the network - usually on your own network, often on the C•CURE server itself. The Proxy connects locally to the victor Web Service (TCP 443) and opens a single outbound-only TLS connection to your region's Alcatraz cloud endpoint (US / EU) on TCP 3033, authenticated with your PEM certificate. No inbound firewall ports are required.

Alcatraz Proxy Service is required in the following cases:

  • You are an Alcatraz Enterprise Cloud user.
  • Your Alcatraz Platform runs on-premises, but it cannot reach the C•CURE server over the network (the two are in separate networks).
  1. In the ACS Integration settings, check Use Proxy.
  2. Click Download under Certificate in PEM format and save the file.
  3. Install the Proxy Service on a Windows Server with visibility to the victor Web Service - follow Installing Alcatraz Proxy Service for OS requirements and installer steps.
  4. During installation, enter your region's (US/EU) Alcatraz cloud endpoint on port 3033 (endpoints are listed in the install guide).

5. Map C•CURE Card Readers to Rocks

  1. In the Admin Portal, go to Device Management → Readers.
  2. Click Add Reader, then type a few characters from the reader's name as it appears in C•CURE - the list shows all readers containing those characters. Select the one you want and map it to the Rock.

NOTE: After mapping a reader to a newly added Rock, run a Full Sync so existing profiles receive access on the new device. Until a sync completes, enrolled users may not be able to authenticate at the new Rock.

6. Verifying the Integration

 1. Confirm the service is running (Proxy deployments only): open Services (services.msc) and check that Alcatraz Proxy Service shows Running.

2. In the Alcatraz Admin Portal, open Account. The status at the top of the page should show ACS Online.

3. Run a Full Sync and confirm entries appear in the ACS Integration logs. The ACS Integration section includes the integration logs, a button to start a full sync, and an option to export the logs as a CSV file.

Proxy logs are stored under the Data Directory (default C:\ProgramData\Alcatraz AI\Proxy).

7. Troubleshooting

7.1. Connection

Symptom

Likely cause

What to check / fix

Test Connection fails (no Proxy)

Wrong URL or protocol; victor Web Service not running; port 443 blocked

Verify the URL format (https://<host>/victorwebservice/); confirm the victor Web Service is running (IIS) on the correct machine; confirm TCP 443 is reachable from the Alcatraz Platform. Tip: browse to the Victor Web Service URL from the Platform server — a response page or credential prompt means the service is reachable.

Test Connection fails (Use Proxy enabled)

Expected behavior

Verify via the ACS Integration status and sync logs (Section 6) instead.

Authentication error on connect

Wrong Operator credentials; privilege not enabled; Alcatraz license option missing

Verify the Operator's username and password; confirm the privilege from Section 2.2 is Enabled and assigned; confirm "Alcatraz AI - Frictionless Access - Integration" appears in License Administration.

Frequent connection drops, especially with older C•CURE versions

Keep-alive incompatibility

Enable Use Alternate Keep Alive (Section 3.2).

Integration stays offline after an extended C•CURE outage or network interruption

The connection does not always re-establish automatically

Disable and re-enable the ACS Integration in the Admin Portal. In HA environments, verify the integration after failover and failback.



7.2. Synchronization

Symptom

Likely cause

What to check / fix

Full sync fails repeatedly

A facility code used by synced badges is not configured in the Alcatraz Platform

Configure every facility code in use for the card formats being synced, then run a Full Sync. A single missing facility code will cause the sync to keep failing.

Full sync fails on specific credentials

A badge number exceeds the parameters of its card format (for example, more bits or digits than the format allows)

Enable Advanced Logging to identify the affected credentials, then correct the badge number or the card format in C•CURE.

Incorrect or incomplete initial sync with Use CHUID Format Mapping enabled

No CHUID format is configured

Configure the required CHUID formats before enabling the option, then run a Full Sync.

Credentials with facility code 0 do not sync, or enrollment fails for them

Facility code 0 handling conflicts - for example, a Default Facility Code is set in the Platform, or multiple card formats share facility code 0

Use only one card format with facility code 0 per account and avoid combining it with a Default Facility Code. Contact Alcatraz Support when planning a facility-code-0 deployment.

Sync runs but some personnel, credentials, or readers are missing

The Operator's privilege lacks access to the partition containing those entities

Add the required partitions to the privilege (Section 2.2), then run a Full Sync.

A change made in C•CURE (badge status, clearance, door group) is not reflected in the Platform

The incremental sync did not capture the change

Run a Full Sync. If the issue persists, contact Alcatraz Support.

Profiles or access unexpectedly removed after C•CURE maintenance or a network interruption

A synchronization ran while C•CURE was only partially available, and the sync treated the missing data as deleted

Disable the ACS Integration before planned C•CURE maintenance (Section 3.1) and re-enable it afterward. Consider enabling Disable Data Deletion (Section 3.2) as a safeguard. If deletions have already occurred, contact Alcatraz Support before running further syncs.

Enrolled users cannot authenticate at a newly added Rock

Profiles have not yet propagated to the new device

After mapping the new Rock's reader, run a Full Sync (Section 5).

 

7.3. Events

Symptom

Likely cause

What to check / fix

Alcatraz events not visible in the C•CURE Journal

Send Security Events disabled; Journal Trigger missing or not enabled

Enable Send Security Events (Section 3.2) and create/enable the Journal Trigger (Section 2.2, step 5).

 

7.4. Upgrades and Proxy

Symptom

Likely cause

What to check / fix

Integration goes offline after a C•CURE upgrade

The victor Web Service version no longer matches C•CURE, or the Client version setting no longer matches the installed version

Upgrade the victor Web Service together with C•CURE; set Client version (Section 3.2) to match. C•CURE 3.1 requires Platform v3.4.2 or newer.

Proxy installed but integration stays offline

Wrong regional endpoint; outbound TCP 3033 blocked; SSL/TLS inspection; outdated PEM certificate

Verify the endpoint for your region; check firewall rules and SSL-inspection exemptions; re-download the certificate, replace the file, and restart the Proxy Service.

Profiles were deleted when the integration was first enabled

Facility codes not configured before enabling; badges not present in C•CURE

Follow the pre-enable checklist (Section 3.1); restore from backup if needed.