APPLE MACINTOSH COMPUTER HOW TO CLEAR THE LOGIN SECTION OF KEYCHAIN |
|||
|
This has cured many problems, so, I decided to put it into a webpage
for you to follow.
If you have received a new CAC and was successfully using your old CAC on your Mac before, but now are having problems, keep reading.
Several things can be causing this problem, depending on how old your previous CAC was:
Most new CACs come in 2 "versions:" Gemalto TOP DL GX4 144 or Oberthur ID One 128 v5.5 Dual. (see below)
You can verify by looking on the back of your ID card above the black magnetic strip for either of these:
Gemalto TOP DL GX4 144 cardholders should first download the CAC-NG (BETA v0.96) (for Leopard 10.5.8), or Mac OS X 10.6.8 Update Combo v1.1 (for Snow Leopard 10.6.8), restart your computer, then proceed with the instructions below. If it still doesn't work, you may need PKard. Lion users look here
Oberthur ID One 128 v5.5 Dual cardholders only have 2 options: 1. Purchase PKard, or 2. Try the information located on this page, as these are the only ways we've been able to find to support your particular CAC.
We're seeing a lower success rate of Leopard working with the newer PIV II CACS, it seems to work fine with the older CACs.
A 100% success
rate fix for Leopard users with the
Gemalto TOP DL GX4 144 CAC [and
Intel Chip]
is to
upgrade your computer to Snow Leopard.
However, if you have a PPC chip, your only option is to
purchase PKard, OR it may be time for a new computer.
PKard is the only solution [with support] for all CACs, and specifically if you have an Oberthur ID One 128 v5.5 Dual & some V5.2a Dual CACs. Purchase it from Thursby Software or TX Systems
You may also take the risk of using the [no support] (open source) OpenSC, CACkey, or Charismathics Smart Security Interface (CSSI-PIV) programs.
Run the Keychain First Aid (information taken from Thursby forums)
Step 1: Click: Go (top of screen), Utilities, double click Keychain Access.
NOTE: If you don't see Go, click the finder
Step 2: Look in the left column, click login
Step 3: Click Keychain Access (from the menu bar), then choose: Keychain First Aid
Step 4: Enter your username and password, select verify, then click Start
Step 5: It may return Verification failed. This is expected. If there is more than 1 red line, select Repair, then click Start
Step 6: When complete, quit Keychain Access, then try accessing the CAC enabled website again
If the above did not work, continue with either of the instructions listed below
sudo rm -rf /var/db/TokenCache/tokens/ Above instructions taken from this webpage
For the people who would rather click the mouse, follow these steps.
Step 1: Click: Go (top of screen), Utilities, double click Keychain Access.
NOTE: If you don't see Go, click the finder
Step 2: Look in the left column, click login, and make sure All Items is highlighted under Category. You will see all items that are being saved on your computer. These can include your Airport password for your home Wi-Fi network and / or CAC websites that you have visited and used your CAC. Step 3: Any CAC enabled websites that you visited previously will need to be removed. You can hold your control key down and then click your single button Mac mouse and delete it, or if you have a two button mouse simply right click and select remove / delete. Once they are deleted, close keychain and revisit the CAC enabled website you are having problems accessing.
NOTE: If you accidently delete the login folder rather than the items inside it, you can restore it by navigating to: /users/<username>/library/keychains/login.keychain and double clicking it. Found at: http://discussions.apple.com/thread/1948993?threadID=1948993
Please try one more thing before contacting us:
There may be a corrupt preference.
Go into Safari and reset it (Under the "Safari" menu) this will clear out
cached pages.
If you are still having problems, contact us
|
|||
If you have questions or suggestions for this site, contact Michael J. DanberryAre you interested in subscribing to the CACNews email list?
Last Update or Review: Tuesday, 28 February 2012 18:47 hrs
The following domain names all resolve to the same website: ChiefsCACSite.com, CommonAccessCard.us, CommonAccessCard.info, ChiefGeek.us, MilitaryCAC.info, MilitaryCAC.us, MilitaryCAC.org, MilitaryCAC.net, & MilitaryCAC.mobi
|