Danielfromst petersburg

Q: PIV Card Woes with Citrix Viewer

I'm wondering if anyone has gotten their PIV Smart Card to work reliably for remote access to their Department of Veteran's Affairs computer account using Citrix Viewer.

 

I have:

MacBook Pro running OS X El Capitan 10.11.3

SCM SCR3500 A smart card reader

PKard 'middleware' smart card software

Citrix Viewer 12.0.0

Safari 9.0.3

 

After many hours of tech support calls I was finally able to log on remotely with my PIV card and PIN, but when the Citrix viewer window times out- it prompts me for my PIN three times then crashes.  I get a "Safari Cannot find server....' message.  If I have apps open I can continue to work, but if I close them, I cannot usually log back on.  I've tried closing the Safari window, closing Safari and restarting it and even restarting the computer and usually still can't log back in.  If I wait a few hours or overnight, I might be able to log in.

 

Has anyone had similar problems and found a fix?

MacBook Pro, OS X El Capitan (10.11.3)

Posted on Mar 7, 2016 2:50 PM

Close

Q: PIV Card Woes with Citrix Viewer

  • All replies
  • Helpful answers

  • by GunnyFitz,

    GunnyFitz GunnyFitz Mar 21, 2016 7:30 AM in response to Danielfromst petersburg
    Level 1 (8 points)
    iTunes
    Mar 21, 2016 7:30 AM in response to Danielfromst petersburg

    Dan

     

    Before posting my thread I did a search and did NOT find yours until afterward for some reason.  I think we are both dealing with the same crazy issue and I was wondering if you found anything to use with your Mac system for a PIV Card?

    This is what I just posted now:

     

    Any Gov Employees Using "PIV Card" Readers?

     

    I was told there are ZERO chances of using a PIV Card on any Mac but this cannot be so (Can it?) lol.

    Ive read there are others using "CAC Cards" via Mac but why no PIV use? And why isn't there any software to allow the Gov Car Reader to be recognized for the purpose of using our VA Badges to log on?  Are you also using the Mobile Pass OTP Token System to log in via CAG?  UGH!!

  • by Danielfromst petersburg,

    Danielfromst petersburg Danielfromst petersburg Mar 21, 2016 8:35 PM in response to GunnyFitz
    Level 1 (0 points)
    Mar 21, 2016 8:35 PM in response to GunnyFitz

    GunnyFitz

     

    I am using my PIV card with my Mac but it is pretty clunky.  Here's what I have to do.

    Insert the PIV card in the reader before connecting to the CAG site

    Log in by Clicking the PIV login Icon and entering my PIN

    Wait for Citrix to load- THEN REMOVE THE CARD FROM THE CARD READER

    If you don't remove the card you cannot start any applications

    When you start an application- you get a Windows Log On screen- DON'T TRY TO USE YOUR CARD- click Other User and use your password

    The App will start

    When you start subsequent apps- a dialog box will pop up with a certificate highlighted- click CANCEL and the app will start (if you click CONTINUE it will prompt you 3 times and crash)

    Not elegant, tiresome, but it works.

    The only thing is that if you need to log back on with in an hour or so of logging off- you may have to restart your computer.

  • by Danielfromst petersburg,

    Danielfromst petersburg Danielfromst petersburg Mar 21, 2016 8:41 PM in response to GunnyFitz
    Level 1 (0 points)
    Mar 21, 2016 8:41 PM in response to GunnyFitz

    Forgot to mention- I am in a "PIV Enforced" group, from my understanding I am not permitted to use Mobile Pass so I haven't tried.  (But, I have considered removing my Sun Pass transponder from my car and sticking it on the computer- If it works at all- it might be better than my PIV card.)

  • by dr.nixon,

    dr.nixon dr.nixon Jul 18, 2016 7:02 AM in response to Danielfromst petersburg
    Level 1 (9 points)
    Jul 18, 2016 7:02 AM in response to Danielfromst petersburg

    Absolutely. This is the same "fix" that was found to work at our VA - pull card out BEFORE launching the CAG. However, once CAG has been launched, and you get the login prompt, you're safe to plug the card back in again and then use PIV for login (as of Aug 4 2016, you will HAVE to do this - no password accepted for login after that date).

     

    One user has had issues with incorrect credentials - he has to open Keychain and clear anything saved that includes "CAG" between logins, but otherwise things work.

     

    With proper middleware installed (OpenSC, pre-release beta) we got it to work in Firefox as well, same issue with having to pull card, but the behavior was more erratic - user was unable to log out without a program hang, and was hit with weird repeated login requests during the process. Stick with Safari for now, unless the middleware has finally been updated to a release version that works with El Capitan.

  • by Redaunt,

    Redaunt Redaunt Sep 12, 2016 5:53 AM in response to Danielfromst petersburg
    Level 1 (4 points)
    Sep 12, 2016 5:53 AM in response to Danielfromst petersburg

    when I try to log in using PIV (and by that I mean just clicking on the PIV log on icon), I get this message:

    Error: Access is Denied. Client SSL Certificate Invalid.


    I can't even do the put the PIV card in, take it out maneuver.