Requirements
Use this checklist before you install BioTrack. It is for the person doing the installation, usually IT or an Alcra installer.
The PC
Section titled “The PC”| Requirement | Details |
|---|---|
| Operating system | Windows 11, x64 (Intel or AMD) or ARM64. |
| ARM64 PCs | .NET Framework 4.8.1 must be installed. The collector service needs it to run natively on ARM64. |
| Installer | The signed BioTrack installer that matches the PC: biotrack-<version>-x64-setup.exe or biotrack-<version>-arm64-setup.exe. |
| Administrator approval | Someone who can approve the Windows administrator (UAC) prompt, during installation and once more during setup for the firewall rule. |
| Windows account | The account the PC is normally used with. Standard and administrator accounts both work; you do not need to create a new account. |
| Disk encryption | BitLocker is not required. BioTrack encrypts its own database. |
| Always on | The PC should stay on during working hours. Scans are only saved while the PC and its collector service are running. |
The installer puts BioTrack in Program Files for all users. Setup uses the Windows account that is signed in when you run it, and that account is the one allowed to open BioTrack afterwards (Windows administrators are also allowed).
The terminal
Section titled “The terminal”- A Hikvision biometric terminal, with employees already enrolled on it. BioTrack does not enrol faces, fingerprints or cards.
- The terminal’s own administrator username and password. BioTrack uses them to check the terminal, set its callback and read the employee list.
- The terminal’s date, time and timezone set correctly, ideally from a time server. BioTrack records the time the terminal reports.
- A connection security choice:
- HTTPS with a trusted certificate (the default). The terminal must present a certificate the PC trusts; expired, untrusted or mismatched certificates are rejected.
- HTTP Digest (isolated network). Not encrypted. Use it only when the terminal is on a dedicated, isolated device network.
The network
Section titled “The network”- The PC and the terminal on the same local network, so the terminal can send scans straight to the PC.
- Private IPv4 addresses for both, such as
192.168.x.x,10.x.x.xor172.16.x.xto172.31.x.x. BioTrack refuses public addresses. - A fixed address for the terminal, reserved on your router or set on the terminal. The Windows firewall rule allows callbacks from that one address, and changing it later means reinstalling.
- A free port on the PC for callbacks. BioTrack uses 8089 unless another program already uses it; any port from 1024 to 65535 works.
- Approval for a Windows firewall rule. During setup, Windows asks an administrator to allow a rule that accepts callbacks only from the chosen terminal, on every network profile.
Publisher trust
Section titled “Publisher trust”BioTrack is signed with a private Alcra publisher certificate. Before installing, get the certificate’s SHA-256 fingerprint from your administrator or Alcra through a separate, trusted channel (not the same email or download as the installer). You compare it with the fingerprint the installer shows. Organisations can also trust the certificate in advance through Group Policy or Intune.
Optional: cloud reporting
Section titled “Optional: cloud reporting”To send attendance to your organisation’s cloud service you also need the cloud address and a one-time activation code from the person who commissions your cloud service. The PC needs outbound HTTPS access to that address. You can turn this on after installation.