Want to highlight a helpful answer? Upvote!

Did someone help you, or did an answer or User Tip resolve your issue? Upvote by selecting the upvote arrow. Your feedback helps others! Learn more about when to upvote >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

MacOS 10.15.3 broke CAC reader recognition, needs to be fixed next update!

Hi, after recently updating to MacOS 10.15.3 I started to have issues.  I work for the federal government and have a CAC (Common Access Card) and card reader connected to my Mac to provide two-factor authentication to specific websites as well as access to my organization’s VPN.  I never had an issue before this update.  The issue is that it won’t recognize my certificate from my card in safari and will not prompt me for my pin so I cannot access the websites.  The only solid work around has been to dual boot to windows 10 where I am not having any issues.  Please fix this ASAP.  It is a common problem ( https://www.facebook.com/groups/militarycac) here everyone is having the same issue after updating to 10.15.3. Today I updated to 10.15.4 but I am still having the same issue.  This is affecting 1,000s of workers daily and was hoping it could get fixed in the next update.

MacBook Pro 13", macOS 10.15

Posted on Apr 21, 2020 5:41 AM

Reply
Question marked as Best reply

Posted on Apr 21, 2020 10:49 AM


What OS version did you update from? If it was pre-Catalina, then you will need to remove any software you added to use your CAC. MilitaryCAC.com has information on how to do this.


Regardless of where you updated from, check your login keychain for Identity Preferences for the domains that are not asking for cert. If you find any, delete them.

If you click on All Items and sort by kind, you can scroll down to the section for identity preferences and see if you can find any of the domains you need to connect to.


Once deleted, try to connect and If it asks you for certificates, make sure you choose the one that has the 16-digit edpi. If you view each certificate, you can find the edpi listed in NT Principal Name. Mine has always been the top listed one that doesn't say it is for Email.


I haven't had any problems short of the sites failing due to load.

Similar questions

3 replies
Question marked as Best reply

Apr 21, 2020 10:49 AM in response to senorpapi


What OS version did you update from? If it was pre-Catalina, then you will need to remove any software you added to use your CAC. MilitaryCAC.com has information on how to do this.


Regardless of where you updated from, check your login keychain for Identity Preferences for the domains that are not asking for cert. If you find any, delete them.

If you click on All Items and sort by kind, you can scroll down to the section for identity preferences and see if you can find any of the domains you need to connect to.


Once deleted, try to connect and If it asks you for certificates, make sure you choose the one that has the 16-digit edpi. If you view each certificate, you can find the edpi listed in NT Principal Name. Mine has always been the top listed one that doesn't say it is for Email.


I haven't had any problems short of the sites failing due to load.

Apr 21, 2020 1:52 PM in response to Barney-15E

I’ve done all of that. Please see the Facebook page I linked for a deeper understanding of what everyone is experiencing. The issue is MacOS isn’t seeing CAC reader/prompting user to select cert. The only fix is to restart the system and it will work. If you let it sleep or hang out for a few hours the only way to get the CAC prompt is to restart the machine.

MacOS 10.15.3 broke CAC reader recognition, needs to be fixed next update!

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.