Redacted_J A.doc

DOC document 66 KB Posted

Attached to
ActivIdentity Software Maintenance Renewal Federal contract opportunity
Solicitation number
HC1028-13-T-0230
Issued by
Defense Information Systems Agency

About this file

Redacted Justification Approval

View the file

Other files for this federal contract opportunity

Other files attached to ActivIdentity Software Maintenance Renewal, newest first.
File Type Posted
Solicitation.doc DOC document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ActivIdentity Software License Renewals-JA13-120

JUSTIFICATION FOR OTHER THAN FULL AND

OPEN COMPETITION (OTFAOC)

Federal Acquisition Regulation (FAR) Part 6 Justification, Supporting Procurements under

FAR Part 12, FAR Subpart 13.501, and FAR Part 15

Procurement Title: ActivIdentity Software License Renewals

Contracting Office: Defense Information Systems Agency (DISA) / Defense Information Technology Contracting Organization (DITCO) / PL8321 Statutory Authority: Section 4202 of the Clinger Cohen Act of 1996, FAR Subpart 13.501, and FAR 6.302-1

JUSTIFICATION FOR OTFAOC

Justification for OTFAOC Number: JA13-120 Upon the basis of the following justification, I, as the Procuring Activity Competition Advocate, hereby approve the use of OTFAOC of the proposed contractual action pursuant to the authority of Section 4202 of the Clinger-Cohen Act of 1996. The regulatory authorities that apply to the requirement are FAR Subpart 13.501, Test Program for Certain Commercial Items and FAR 6.302-1, only one responsible source and no other supplies or services will satisfy the agency’s requirements.

JUSTIFICATION

1. REQUIRING AGENCY AND CONTRACTING OFFICE:

a. Requiring Agency:

DISA Program Executive Office - Mission Assurance (PEO-MA)

6910 Cooper Avenue

Fort Meade, Maryland 20755-7088

b. Contracting Activity:

DISA/DITCO

2300 East Drive, Building 3600

Scott Air Force Base, Illinois 62225-5406

2. NATURE/DESCRIPTION OF ACTION(S):

a. The nature of this requirement is to procure ActivIdentity commercial off-the-shelf (COTS) software license support/renewals (updates and releases) required by DISA to support the Department of Defense (DoD) Public Key Infrastructure (PKI) Program, Privilege Management (PvM) Program, and Global Enterprise Directory Service (GDS) Program enclaves. The requirement will be a sole source, firm-fixed-price (FFP), open market contract award to ActivIdentity, Inc.

b. The period of performance (PoP) will be from the date of award, estimated on September 16, 2013 through June 30, 2014, and includes four, 1-year options. The applicable North American Industry Classification System code is 511210 with a sales size standard of $35.5 million. This effort will be funded using a mix of fiscal year 2013 defense working capital funds and operations and maintenance funds.

3. DESCRIPTION OF SUPPLIES/SERVICES:

a. The purpose of this requirement is to procure ActivIdentity software license support/renewals. The software renewals are needed to support systems maintained at the test labs located at Fort Huachuca, Arizona, in the National Capital Region, and in operational environments deployed at the Defense Enterprise Computing Centers (DECCs). The software license support (updates and releases) will support the following three programs: PKI, PvM, and GDS. Although this procurement is to support the requirements for each of the three programs, descriptions of all the ActivIdentity software renewal requirements for each program are listed separately below to clarify the needs of each program.

i. DoD PKI Program – DISA’s Identity Management PKI Program utilizes the ActivIdentity software within the Robust Certificate Validation Systems (RCVS) for On-line Certificate Status Protocol (OCSP) responses received from various DoD related clients. The software support for the current software license suite allows RCVS to support the Simple Certificate Validation Protocol for DoD PKI users. This software is validation authority and responder software currently in use as part of the RCVS portion of the PKI architecture. It provides a user authentication mechanism at the enterprise level for the DoD. Furthermore, this software allows for Delta Certification Revocation Lists (CRLs), OCSP responses, and mini CRL capabilities. In short, the software allows DoD users to log on to their system, and validate digitally signed and encrypted email. PKI is a service of products that provides and manages X.509 certificates for public key cryptography. Certificates identify the individual named in the certificate and bind that person to a particular public/private key pair. The RCVS provides responses to users’ requests to the validity status of certificates via the OCSP, so that personnel may log into web sites and personal computers. This service is provided directly to various DoD networks or to the services for redistribution throughout their domains.

ii. PvM Program - DISA’s Identity Management Division, in collaboration with the National Security Agency, is working to develop a DoD Enterprise solution for Identity and Access Management (IdAM). In support of these efforts, DISA is providing engineering support, participating in exercises to evaluate products, conducting product evaluations, and developing implementation guides for selected best value COTS product solutions. The DISA Identity Management PvM program utilizes the ActivIdentity software within the developed architecture to serve as a function similar to a Certificate Authority. It houses certificates so the function can be tested in the lab environment. The software support/renewals will allow the ability to support the Certificate Validation-like function during the testing phase of the project. ActivIdentity software provides a user authentication-like mechanism at the enterprise level for the DoD. This software allows for CRLs and mini CRL capabilities. In short, the software allows DoD users to log on to their system and validate digitally signed and encrypted email. The PvM program has spent several millions of dollars over the past three years building the architecture for the IdAM solution, into which the software is specifically incorporated. The software license renewals for the Tactical Attribute Repository (TARR) and Identity & Privilege List publisher must be maintained annually to support these efforts.

iii. GDS Program enclaves - The renewal of the current licensing is required for the GDS nodes at the Mechanicsburg, Pennsylvania, DECC’s Oklahoma City, Oklahoma, Joint Interoperability and Test Command (JITC) Lab, Fort Huachuca, and Development Labs. The GDS requires the use of two copyrighted java libraries: com.ActivIdentity.rtc.cert.FastX509CRL and com.ActivIdentity.rtc.cert.FastX509CRLEntry. These libraries greatly enhance the code’s memory usage and performance handling of PKI certificate validation requests against DoD’s very large PKI CRL. Usage of these libraries will also enhance the enterprise support that GDS provides the DoD to distribute CRLs across the Global Information Grid architecture in support of the CRL validation request processing from the mandated Common Access Card logon effort. Use of these copyrighted Java libraries will result in significant improvement in memory processing such that it will reduce the amount of additional hardware and maintenance required to support the continued growth of CRL validation requests and processing within the architecture. These libraries have been vetted and tested as part of the existing DoD PKI architecture OCSP implementation. The GDS program is a key directory component supporting DoD PKI architecture and NetCentric Enterprise Service’s core Service-Oriented Architecture services.

4. IDENTIFICATION OF STATUTORY AUTHORITY:

This acquisition, using OTFAOC, is conducted under the statutory authority of 10 U.S.C. 2304 (c)(1), the regulatory authority of FAR 6.302-1/Defense FAR Supplement 206.302-1, only one responsible source and no other supplies or services will satisfy the agency’s requirements, FAR Subpart 13.501, Test Program for Certain Commercial Items, as well as Section 4202 of the Clinger-Cohen Act of 1996. The items/services are peculiar to one manufacturer’s brand name. Only the original equipment manufacturer will satisfy the requirement.

5. DEMONSTRATION OF CONTRACTOR’S UNIQUE QUALIFICATIONS:

a. Some ActivIdentity products and support are authorized to be sold by resellers such as Four Points Technology and Envoy Data Corporation. While resellers do exist for the ActivIdentity software support, the TARR bundle and Standard Kit (SDK) PKI Tool kit software support is not sold through them. None of ActivIdentity’s resellers are currently trained on these products to provide license renewal support. If there are issues with downloading the software renewals or software license updates throughout the year for these specific licenses, PKI support will have to reach out to ActivIdentity directly because they are the only known source for this proprietary software support. ActivIdentity license support for these licenses is not authorized by resellers.

b. The Government has determined it would be too costly to introduce different software to the enclaves to procure an alternative solution. The cost to the Government to introduce a new software and support contractor would literally result in stoppage of existing data mining work. To retrofit a different contractor’s product would mean implementing and testing the new product on all Integrated Data Environment/Global Transportation Network Convergence enclaves, discarding current software licenses in favor of the replacement product, recoding existing reports and views, retraining the developer and user community to become familiar with the replacement product, requiring ActivIdentity users to recode their own customized reports, and diverting the focus of this program on development to ramp-up with the new product as quickly as possible. Total impact costs for replacements are estimated to be as high as $15,000,000.00 (includes analysis, recoding software, re-licensing, report redesign, possible database view redesign, installation, testing, and possible hardware modifications) to occur over a two-year period that re-integrates the replacement platform to all environments. In addition, the current investment in COTS software would be lost. DISA would also suffer unquantifiable losses, such as the inability to work new requirements because contractor personnel resources would otherwise have to be diverted to stand-up a replacement data quality solution, and the corporate information technology knowledge and experience associated with ActivIdentity that would have to be re-acquired with a replacement product. It also takes significant time to integrate replacement products into operational software architecture, and that time results in an unplanned expense to the Government that would not be recovered through a re-competition.

c. ActivIdentity has proprietary rights to the software and associated software support in this procurement action and, as such, is the only known contractor that can provide the needed license renewal support. The ActivIdentity software development kit has been certified for interoperability with the DoD PKI by the JITC. Delaying the procurement of this critical software renewal places the GDS Program at risk of not being able to meet expanding customer directory services and PKI CRL validation demands.

6. FEDERAL BUSINESS OPPORTUNITIES (FBO) ANNOUNCEMENT/POTENTIAL SOURCES:

A synopsis for this requirement will be published to the FBO website with the intention to award a sole source contract to ActivIdentity. A copy of the redacted justification and approval (J&A) will be posted with this intention.

7. DETERMINATION OF FAIR AND REASONABLE COST:

The Government will perform an evaluation of the offeror’s proposal and proposed costs to ensure the costs are fair and reasonable. The Contracting Officer will determine that the resultant contract’s cost or prices will be fair and reasonable based on comparison with the cost or prices outlined below. The Contracting Officer will also determine the pricing information valid for comparative purposes. The technical team will perform an evaluation of the offeror’s price proposal to ensure the proposal meets the needs of the Government. Certified cost and price data is not required for this commercial item acquisition in accordance with FAR 15.403-1(b)(3). The Contracting Officer will determine whether the price is fair and reasonable based on:

a. Comparison of the proposed prices to historical and existing prices paid, whether by the Government or other than the Government for the same or similar items.

b. Comparison with a competitive published price list or published market prices of the same commodities.

c. Comparison of proposed prices with the independent Government cost estimate.

File details come from the government source that posted it. Updated .