Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
4 options show up, commonaccesscard.bundle, etc

still not showing up under keychain though

gunna try flashing it to the newer firmware (.25)

When the 4 options show up, can you select 1 and then hit enter? What is the result then. I am on travel but have my macbook and CaC reader with me....
 
says "

insert your token in: SCR331 USB smart card reader 00 00

token support updated successfully !

"

still not under keychain, can't get to NMCI e-mail
 
got it, dunno what it was but I think it was my virtual machine conflicting and trying to pull the cac reader, now to get the other cac verification programs to work, has anyone gotten something other then e-mail to work?
 
got it, dunno what it was but I think it was my virtual machine conflicting and trying to pull the cac reader, now to get the other cac verification programs to work, has anyone gotten something other then e-mail to work?

Good deal! I am betting that was the case. I am able to use mine for email (using Entourage OR Apple Mail) and for websites (using Safari only). I have had no success with Firefox :mad: For websites you need to associate the root URL for the site in your keychain w/ your PKI certificate. http://support.apple.com/kb/HT1679
 
With the recent release of 10.5.6 I still can't access any *.mil sites with my CAC card. Instead of prompting for a PIN, I only get "enter username & password" boxes. I've tried everything in this thread including the workarounds.

Any suggestions?
 
Anything new on this issue. I am also on 10.5.6 and it appears from reading the Govt Mac Forums and doing research via the web Apple has not addressed this issue. I would still love to find a known good CAC Reader and How to set this up so that I can go to certain Govt Sites that I need to get to when I am on the road. Thanks!

Bill.....:apple:
 
Hoping this helps

I am retired Navy (E-9) and now am a DoD contracter. Son is Army, does that count :D

JollyRogers, are you still using your cac on your mac? I stumbled across you post and am trying to do everything you guys have so very diligently have help. Any words of wisdom would be great. Do you have step by step instructions for a not so bright nurse who has never done half of what you guys are talking about. I am using os x 10.5.6 on a macbook. Thanks in advance for your help.

Ted
 
JollyRogers, are you still using your cac on your mac? I stumbled across you post and am trying to do everything you guys have so very diligently have help. Any words of wisdom would be great. Do you have step by step instructions for a not so bright nurse who has never done half of what you guys are talking about. I am using os x 10.5.6 on a macbook. Thanks in advance for your help.

Ted

Ted,
Yes, I still use my CAC w/ a USB ACtivCard reader.

The biggest thing is to make sure you have a CAC/SmartCard reader that will be recognized by OSX. I actually had to change the firmware on mine as listed in an early post. I am using an ActivCard USB Reader V2.0 p/n ZFG-9800-AD that has been "flashed" with firmware for SC331.

Other then that, it is a matter of if when you plug it in and insert your CAC into the reader, if Key Chain sees it. IF it does, then you will be able to make it work. You will have to associate URLs with your CAC certificate so that the website will ask for your CAC PIN.

I don't have a step by step set of instructions. I guess I could make some up when I get some time...
 
I just received the cac reader last week. where/how do I go to flash the firmware and you mentioned adding url to my cac, how do I do that. Sorry for al the questions. I am going to attempt this when I get to the house. I am the TO of my unit and it is becoming more difficult not to access and I don't want windows on my mac
 
I just received the cac reader last week. where/how do I go to flash the firmware and you mentioned adding url to my cac, how do I do that. Sorry for al the questions. I am going to attempt this when I get to the house. I am the TO of my unit and it is becoming more difficult not to access and I don't want windows on my mac

Ted, What kind of reader is it?
 
Can't answer right now at work and reader is at home. Navy just gave it to me looks just like the one I had in the past and the ones that are in the reserve center not built into the keyboard. I know that does not help. I will post again when I get to the house. Thanks so much for your time.
 
My old link for the flash utility for the Activcard is no longer valid. I am trying to google it now... I am betting it is the same one I have. Kinda biege white with the word ActivCard on it.

Here is a new link for the file: (YOU NEED A WINDOWS MACHINE TO FLASH WITH THIS)
http://204.202.11.175/downloads/SCRx31CCID_FW_V5.18.zip

This is getting hard to find. I dont have a place to host it... but may keep a copy in case someone needs it.
 
So when you say I need a windows machine to flash, I will plug the reader into the usb and follow the directions
 
Yes, download the linked file above on the windows machine.
1.
-Connect smart card reader
-Go to (Start | Settings | Control Panel | Administrative Tools | Services) and stop the following services:
ActivCard Gold AutoRegister
ActivCard Gold Service
Smart Card Service
-Extract the SCRx31CCID_FW_V5.18.zip file and run fwupdate.exe
-Select OK and then Browse and select the SCR531_V518.bin file and select Open
-Select Next and verify that the new firmware value is 05.18
-Select Finish and then Close

This will flash the activcard to an SCx31 and it will be usable on your Mac.

It will take about a minute to flash and it will be usable on both windows and OSX.

2.
From there plug it into the Mac and insert your CAC. Open keychain access and see if your CAC is listed in the top left. If so you are on your way.

3.
Get the DoD certificates. I can't help you here, but if you use a the reader/CAC on the windows machine I think you can download them here: http://dodpki.c3pki.chamb.disa.mil/rootca.html and then copy them over to your Mac. Install them on your Mac-- Double click them and they will go into your keychain access.

4.
Now follow this to access .mil (in safari)websites as the root URL must be associated with your certificate to ask for your PIN. http://support.apple.com/kb/HT1679
 
Don't be dense. You never have to reboot for installing USB devices on Windows. They've always been p&p.

--Erwin

Ever?

You've used every piece of hardware/driver on Windows?

What about the hardware I've used that tell you first to install the driver, REBOOT, then attach the USB device? Well, maybe once you've installed the driver it is OK, but if the reboot is before you attach it rather than after seems to be a little nitpicky.
 
JollyRogers,

Thanks so much for all your help. I am up and running. OWA has intermittent connections issues and I can not access nsips, but I can access other stuff. See another fine reason to listen to the Master Chief. Have a good Easter. If you ever need to flash and need the file go to scm microsystems, flashed to 5.25 today and had no issues.
 
Ted,
Glad to have helped... I don't know what hospital/clinic you work, but I travel a lot and you know how Karma can be :D You have a great easter also, I get to spend mine with my son before he goes off to Afghanastan.

About 5.25... thanks that is good news and I will check it out.
 
Ted,
Glad to have helped... I don't know what hospital/clinic you work, but I travel a lot and you know how Karma can be :D You have a great easter also, I get to spend mine with my son before he goes off to Afghanastan.

About 5.25... thanks that is good news and I will check it out.

Tell your boy good luck and Godspeed.
 
Ok so I am hoping someone can help with this. I picked up a Cherry ST-1044UB today. Plugged it in and it recognized my ID right outta the box in OS X. And I added X509 anchors, unfortunately I cannot find X509 Certificate. Has anyone been able to find it in 10.5.6. I have gotten it to work and was able to log into NKO/CMSID and NMCI webmail through my virtual machine but cannot get it to work in Safari. I just get "This Page requires a Client Certificate" It never asks for one and I tried doing the New ID preference thing. This is pretty frustrating as though it appears everyone has different issues. Course I guess this is the way the Gubment operates. I really think the root problem here is the no X509 Certificate. If anybody can help I would be much appreciative. Thanks.

Edit:
So I got the NKO/CMSID site to ask for a cert once I clicked the right one it gave me this.

Safari can’t open the page “https://www.cmsid.navy.mil/jass/jcms_nko_login.m?emplid=eXZ3w87imfI=” because it couldn’t establish a secure connection to the server “www.cmsid.navy.mil”

Ok so I found one thing that worked. https://support.mozilla.com/tiki-view_forum_thread.php?locale=mk&comments_parentId=280996&forumId=1 the post by Polack helped to get to the NKO/CMS site for Safari but not FireFox. Now if I can just get Webmail to work.
 
WooHoo I finally got the stuff working. I could log into the NKO site I needed but not webmail. Finally got webmail to work by doing the identity preference. Problem was I would do it for the 3 certs showing but that wasn't working. So when I opened up the the indentity preference it had a list of certs so I added the preference to the 9 listed, yes 9(not sure why there are 9 there). Anywho so I added the preference for all 9 and tried to log into the webmail and sure enough it brought up a list of 6 certs(3 ID and then 3 email). And now I have NMCI webmail on my Mac. Man I really do love my Mac's
 
NMCI & Smartcard (CAC) Access in 10.5.6--HELP!

I'm at my wits end: I have a MacBook Pro running 10.5.6. I have an SCR331 CAC Reader with firmware 5.25. I have followed the "CAC for Mac v1.2" instructions, manually entering identity preferences for the NMCI OWA website. Still no joy. I've reviewed many of Shawn Geddis' posts on the Apple Fed-Talk posts, but have not found them helpful--more a discussion for developers than troubleshooting user problems.

I've seen "X509" referred to a number of times. I have no idea what this is, but it seems consistent that those running 10.5.6 don't have it. Is this possibly the problem?

Any help much appreciated.
 
I'm at my wits end: I have a MacBook Pro running 10.5.6. I have an SCR331 CAC Reader with firmware 5.25. I have followed the "CAC for Mac v1.2" instructions, manually entering identity preferences for the NMCI OWA website. Still no joy. I've reviewed many of Shawn Geddis' posts on the Apple Fed-Talk posts, but have not found them helpful--more a discussion for developers than troubleshooting user problems.

I've seen "X509" referred to a number of times. I have no idea what this is, but it seems consistent that those running 10.5.6 don't have it. Is this possibly the problem?

Any help much appreciated.

Urga it is frustrating. Dont worry about the X509 Certificates, just add the X509 Anchors to your keychain. Then on the Identity Preference there should be a drop down menu. Add the preference for everyone there. Mine showed 9 total yours may vary. This seemed to work for me after adding the DOD_CA15 and DOD_EMAIL16 certs to the system keychain.
 
CAC for Mac with 10.5.7?

Dear Forum Members,

Anybody upgraded to 10.5.7, then have a problem logging in with their CAC and subsequently solve the problem?

I was successful with 10.5.6 (thanks to Tombo6500!). I unwittingly updated to 10.5.7 over the weekend and now I can't access my CAC-required sites.

Any ideas?

Thanks.
 
Have you tried redoing everything, i.e. ID prefs and the such. I dont know what it is with the Activcard readers but my Cherry seems to work just fine. Not quite as slim as the AC readers but it works dagnabbit.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.