Getting CAC/PIV logins working on Linux

Trier

This will probably be useful to maybe 3 people who uses linux and want to log into military crap without using a Windows virtual machine. I’ll sum up what you basically have to do and provide the links that helped me.

  1. install openSC —- You load this security module into firefox (instructions wil be linked below) for your cac card to work. If you googled or searched militarycac linux you’ll get some suggestions to search your package manager for “coolkey” or “pcsc”. These modules DO actually work, however they DO NOT work with your PIV authentication cert, which is required for some military websites, especially MS Teams logins. So it’s highly recommended you specifically load this if you’ve been noticing you can log into other military websites but you get errors on teams.
  2. Load your authority certificates – Load these certs into the authority tab of firefox’s “view certificates” section or whatever it looks like to you and make sure that all of the certificates you add are “trusted” in every box. https://www.hagensieker.com/wordpress/2018/07/10/dod-cac-card-on-ubuntu-linux/ this page has instructions on how to load the certs, but really only follow this page for that and remember to install and load openSC and NOT pcsc or coolkey because your PIV certs won’t show up and you’ll be a sad panda.
  3. Just use firefox for this. I don’t know why they said teams only works on edge because it does and works well. Yes it is technically possible to get it working for linux on chromium based browsers like chrome, brave, or edge but it requires some stuff I don’t understand. It can be done but it requires some minor terminal stuff. If you ctrl+f opensc in the comments of this page https://www.hagensieker.com/wordpress/2018/07/10/dod-cac-card-on-ubuntu-linux/ you’ll find some commenters talking about it. It’s basically just saying that you have to run a “cac_module” comment for openSC or something but it was too annoying for me to troubleshoot so I gave up.
  4. It’ll prompt you for a “password” instead of a pin and likely before you choose what cert to use so just put in your pin and pick your certs.

https://public.cyber.mil/pki-pke/ <— where you can get your certs from

https://www.hagensieker.com/wordpress/2018/07/10/dod-cac-card-on-ubuntu-linux/ – instructions on loading your certs

I’m posting this specifically for people in my situation to hopefully find during a google search or something, but feel free to message me on reddit if you have any questions on how to get it working.

Also chances are you’re probably some 6 shop nerd if this applies to you so feel free to message me about other niche tech issues, I get bored.

Edit:

I also noticed that if you have your cac in before you open your browser, it’ll prompt you for a pin as soon as you open up Firefox. It seems like Ike if it doesn’t do that upon initially logging in you might get errors trying to log into anything after that and it won’t prompt you for your pin. So save yourself the time and just have your card in before you open your browser and ensure you get that initial prompt. This might be my imagination but if seems like this is indeed the case. the cool thing is you won’t have to put in your pin again for the rest of the session.

submitted by /u/NomadFH
[link] [comments]

(Visited 1 times, 1 visits today)

Tags: suchen suche search tag anzeigen besucherzahl browser design domain inhalt jahr karpfen konto problem inhalt schalten modellbahn spielemax spiel tag webseite preise werbung

Reichsmarschall Göring hatte eine Märklin Modelleisenbahn >>> read more




ID for Download Paper 139418