Activclient Download Mac



Individuals who have a valid authorized need to access DoD Public Key Infrastructure (PKI)- protected information but do not have access to a government site or government-furnished equipment will need to configure their systems to access PKI-protected content.

Accessing DoD PKI-protected information is most commonly achieved using the PKI certificates stored on your Common Access Card (CAC). The certificates on your CAC can allow you to perform routine activities such as accessing OWA, signing documents, and viewing other PKI-protected information online. For more information about your CAC and the information stored on it, visit http://www.cac.mil.

Middleware enables the DoD PKI certificates stored on your Common Access Card (CAC) to interface with the many Public Key Enabled (PKE) applications on your system and across the Internet. Two of the most common middleware applications used across DoD are ActivClient and Spyrus. Download and install the OS X Smartcard Services package The OS X Smartcard Services Package allows a Mac to read and communicate with a smart card. In order for your machine to recognize your CAC certificates and DoD websites as trusted, the installer will load the DoD CA certificates on OS X.

  1. Windows 10, 8.1, or 8 (64bit) Army users download ActivClient 7.1.0.153 from: NOTE: Please Right click the link below and select Copy (the new links are like SharePoint Links 1 mile long as you will need to paste it a 2nd time after logging into AKO 2.0. Direct links will only dump you at the home page. Like AKO 1.0 used to be like.
  2. ActivClient supports standard US government-issued smart cards such as CAC and PIV. ActivClient is the main DoD CAC software. ActivClient is the smart card middleware from HID that allows government organizations to easily use smart cards and USB tokens for a wide variety of desktop, network security and productivity applications.
  3. ActivClient 6.2 for Windows 7, Vista. The file will automatically be saved in the computer's 'Downloads' folder. Double click on the file to launch it, Mac OS.

Before you begin, make sure you know your organization’s policies regarding remote use.

Windows

To get started you will need:

  • CAC
  • Card reader
  • Middleware (if necessary, depending on your operating system version)

You can get started using your CAC by following these basic steps:

Mac
  1. Get a card reader.
    At this time, the best advice for obtaining a card reader is to work with your home component to get one. In addition, please review the DoD CAC Reader Specifications for more information regarding the requirements for a card reader.
  2. Install middleware, if necessary.
    You may need additional middleware, depending on the operating system you use. Please contact your CC/S/A for more information on the middlew​are requirements for your organization. You can find their contact information on our Contact Us tab.
  3. Install DoD root certificates with InstallRoot (32-bit, 64-bit or Non Administrator).
    In order for your machine to recognize your CAC certificates and DoD websites as trusted, run the InstallRoot utility (32-bit, 64-bit or Non Administrator) to install the DoD CA certificates on Microsoft operating systems. If you’re running an alternate operating system such as Mac OS or Linux, you can import certificates from the PKCS 7 bundle. The InstallRoot User Guide is available here.
  4. Make certificates available to your operating system and/or browser, if necessary.
    Pick your browser for specific instructions.

Mac

To get started you will need:

  • CAC (see note below)
  • Card reader

You can get started using your CAC on your Mac OS X system by following these basic steps:

  1. Get a card reader
    Typically Macs do not come with card readers and therefore an external card reader is necessary. At this time, the best advice for obtaining a card reader is through working with your home component. In addition, please review the DoD CAC Reader Specifications for more information regarding card reader requirements.
  2. Download and install the OS X Smartcard Services package
    The OS X Smartcard Services Package allows a Mac to read and communicate with a smart card. In order for your machine to recognize your CAC certificates and DoD websites as trusted, the installer will load the DoD CA certificates on OS X. Please refer to this page for specific installation instructions.
  3. Address the cross-certificate chaining Issue
    These instructions walk through adjusting the trust settings on the Interoperability Root CA (IRCA) > DoD Root CA 2 and the US DoD CCEB IRCA 1 > DoD Root CA 2 certificates to prevent cross-certificate chaining issues. This can make it appear that your certificates are issued by roots other than the DoD Root CA 2 and can prevent access to DoD websites.
  4. Configure Chrome and Safari, if necessary
    Safari and Google Chrome rely on Keychain Access properly recognizing your CAC certificates.
    1. In Finder, navigate to Go > Utilities and launch KeychainAccess.app
    2. Verify that your CAC certificates are recognized and displayed in Keychain Access

Note: CACs are currently made of different kinds of card stock. To determine what card stock you have, look at the back of your CAC above the magnetic strip. Most CACs are supported by the Smartcard Services package, however Oberthur ID One 128 v5.5 CACs are not. Third party middleware is available that will support these CACS; two such options are Thursby Software’s PKard and Centrify’s Express for Smart Card.

Linux

To get started you will need:

  • CAC
  • Card reader
  • Middleware

You can get started using your CAC with Firefox on Linux machines by following these basic steps:

  1. Get a card reader.
    At this time, the best advice for obtaining a card reader is to work with your home component to get one. In addition, please review the DoD CAC Reader Specifications for more information regarding the requirements for a card reader.
  2. Obtain middleware.
    You will need middleware for Linux to communicate with the CAC. The CoolKey PKCS#11 module provides access to the CAC and can be installed using Linux package management commands.
    • For Debian-based distributions, use the command apt-get install coolkey
    • For Fedora-based distributions, use the command yum install coolkey. The CoolKey PKCS #11 module version 1.1.0 release 15 ships with RHEL 5.7 and above and is located at /usr/lib/pkcs11/libcoolkeypk11.so.

    If you prefer to build CoolKey from source, instructions are included in the Configuring Firefox for the CAC guide.

  3. Configure Firefox to trust the DoD PKI and use the CAC.
    To configure Firefox to communicate with the CAC, follow these steps to install the DoD root and intermediate CA certificates into the Firefox NSS trust store, load the CoolKey library, and ensure the Online Certificate Status Protocol (OCSP) is being used to perform revocation checking.

Next Steps

Your internet browser is now configured to access DoD websites using the certificates on your CAC. Now that your machine is properly configured, please login and visit our End Users page for more information on using the PKI certificates on your CAC.

  1. Ensure your CAC reader works with Mac
  2. Check to ensure your Mac accepts the reader
  3. Check your Mac OS version
  4. Check your CAC’s version
  5. Update your DOD certificates
  6. Guidance for Firefox Users
  7. Look at graphs to see which CAC enabler to use

Step 1: Purchase a Mac Friendly CAC Reader

Purchase a CAC reader that works for your Mac. There are only a couple that you can choose from and I’ve listed them below.

If you already have a CAC reader and it isn’t Mac friendly, you could update the firmware, however, for the non-tech savvy people out there, it’s probably better to just purchase a new one and save the headache – they’re only ~$11-13 dollars.

Best Mac Compatible CAC USB Readers

Best Mac Compatible CAC Desk Readers

Step 2: Plug in and Ensure It’s Accepted

Once you have your CAC reader, plug it into your Mac and ensure your computer recognizes it. If you have one of the CAC readers we suggested above, then you should be good to go.

Activclient Va Download Mac

If you are testing a different version, then verify that your Mac accepts your CAC reader by following these steps.

If for some reason your CAC reader isn’t working, then try the following steps.

Step 3: Update Your DOD Certificates

Now that you have your CAC reader connected and accepted on your Mac computer, it’s time to ensure you have the right certificates in order to access DOD CAC required web pages.

If you are using Chrome or Safari, then follow step 3a below. If you are using Firefox, you’ll need to do some extra steps:

  1. Type ⇧⌘U (Shift + Command + U) to access your Utilities
  2. Find and Double click “Keychain Access”
  3. Select “Login” and “All Items”
  4. Download the following four files and double click each once downloaded so as to install in your Keychain Access.
  5. When you double-click the Mac Root Cert 3 and 4, you’ll need to tell your browser to always trust them. Click the button like you see below:

Activclient Download Mac

Additional Steps for Firefox

  1. Download All Certs zip and double click to unzip all 39 files
  2. While in Firefox, click “Firefox” on the top left, then “Preferences”
  3. Then Click “Advanced” > “Certificates” > “View Certificates”
  4. Then Click “Authorities” and then “Import”
  5. Import each file individually from the “AllCerts” folder. When you do this, the below box will popup. Check all three boxes and click “OK”

Step 4: Download and install CAC Enabler

  1. Download zip
  2. Double click the .zip file
  3. Because this is from an unidentified developer, you’ll need to hold down “Control” and click the program. Now select open and continue with install procedure.
  4. After installing, restart your computer

CAC Access at Home Success

Download Cac Reader For Mac

Now that you have a CAC reader, certificates, and a CAC Enabler, you should now be able to access any CAC-enabled website and log on using your CAC password and data.

Common Reasons Why Your CAC Card Won’t Work On Your Mac

Activclient Download For Mac

Ensure Your CAC Card Meets the Standards: In order for your CAC card to work, it must meet the minimal requirements. Currently, there are only four types of CAC cards that can be used. The ensure you have the right CAC card for online access, flip your CAC card to the back and if you have one of the below numbers written on the top left, then you are good to go:

Mac Smart Card Reader Software

  • G&D FIPS 201 SCE 3.2
  • Oberthur ID one 128 v5.5 Dual
  • GEMALTO DLGX4-A 144
  • GEMALTO TOP DL GX4 144

Active Client Download Mac

If you do not have any of the above written on the back, then proceed to your nearest PSD to get a new CAC card issued.