Installation Steps |
Step 1: Obtain a CAC Reader |
Step 2:CAC Reader driver |
Step 3:DoD Certificates |
Step 4:ActivClient |
Step 4a:Update ActivClient |
Step 5: IE adjustments |
Log into a CAC enabled website now |
Insurance contracts are obvious to most readers, there are other benefits. Indirect costs generated by the existence of these contracts. Definition of an Insurance Contract. This website was created because of the lack of information available to show how to utilize Common Access Card (CAC)s on Personal Computers. MilitaryCAC has been online since 9 November 2007 and has over 121 individual pages of information and support. Install DoD Certificates. Microsoft Current User. In the top right corner of the. InstallRoot window, click X to close the InstallRoot program. If the InstallRoot program asks you to save before exiting, click Yes. This completes the CAC Reader and DOD Certificates installation process. You should now be able to. .CAC Reader Driver (reader “talks” to computer).ActivClient (card “talks” to Windows).LotusForms (view forms) (replaced PureEdge).ApproveIt (sign forms).All software is accessed using your AKO username / password. However, do download Lotus & ApproveIt requires you can login with your CAC first.
InstallRoot automates the install of the DoD certificates onto your Windows computer
To access DoD websites from your computer, you need these certificates on your computer. You may need to reinstall the certificates if the CAC enabled web site won't load, the website you are visiting is prompting you with the message there is a problem with the website's Security Certificate / site is not trusted, you have received a new CAC, or your DoD website worked up until recently and doesn't now.
Apple computer users follow these instructions
Windows RT / Windows 10 S mode users follow these instructions (or anyone not wanting to install the InstallRoot 5.5 program below)
InstallRoot is created by DISA for Windows computers, if you have any problems with this file, please contact them.
NOTE: If you do not want to install the InstallRoot program, or having problems with the InstallRoot file, you can install the certificates manually by, following these instructions.
Windows users, Download InstallRoot 5.5 from:
MilitaryCAC (.msi version) (27.7 MB),
MilitaryCAC (.zip version) (25.9 MB), or
DoD Cyber Exchange (.msi version) (27.7 MB)
(It is the same file [except for .zip version] from two different servers, in the event one of the links don't work)
Select Next >
.
Leave the default installation location, then select Next >
.
Select Next >
.
Select Install
.
Wait for it
.
.
Select Run InstallRoot
.
.
Click Install Certificates
If you have Firefox installed, you may see 2 or 3 tabs
NOTE: I have one report that a person had to select Restart as Administrator. This was the first and only person in the several years this program has been in existence that I have heard this.
InstallRoot not updating was fixed in InstallRoot 5.2
Select Yes, (this screen may show 2 - 4 times) as it is installing each of the DoD Root CA 2, 3, 4, & 5 certificates
.
Select OK (your number of Adds will vary)
.
How to verify you have the certificates installed
Open Internet Explorer, Select Tools (Gear), Internet Options
Select Content (tab), Certificates (button)
Intermediate Certification Authorities (tab) scroll down the Issued To (column) to the letters DOD to verify you have:
DOD EMAIL CA-33 through DOD EMAIL CA-34
DOD EMAIL CA-39 through DOD EMAIL CA-44
DOD EMAIL CA-49 through DOD EMAIL CA-52
DOD EMAIL CA-59
DOD ID CA-33 through DOD ID CA-34
DOD ID CA-39 through DOD ID CA-44
DOD ID CA-49 through DOD ID CA-52
Iogear Cac Reader Troubleshooting
DOD ID CA-59
DOD ID SW CA-35 through DOD ID SW CA-38
DOD ID SW CA-45 through DOD ID SW CA-48
DOD SW CA-53 through DOD SW CA-58
and
DOD SW CA-60 through DOD SW CA-61
Please verify the Root certificates installed (sometimes the Antivirus program doesn't allow these to be installed)
Open the Trusted Root Certification Authorities (tab) verify you have:
DoD Root CA 2 through DoD Root CA 5
If you see 'There is a problem with this website's security certificate' after installing the DoD InstallRoot file or the Red Certificate error below, follow this guide
PROCEED TO STEP 4 - INSTALL ACTIVCLIENT
The Cross Cert Remover tool is 'supposed' to be an automated way of removing some certificates that cause access problems. From what I've experienced, you still need to follow my guide [slides 16&17] and manually remove certificates the Cross Cert Removal Tool fails to remove. Feel free to use if you want to waste your time.
You can install both the InstallRoot and the Cross Cert Removal tool in one single file which was created by NETCOM (Army Network Enterprise Technology COMmand)
This file is created for Home Users ONLY, you can download it from:
Information:
A certificate is a digital document providing the identity of a Web site or individuals. DoD Web sites use a certificate to identify themselves to their users and to enable secure connections. If you are receiving a warning that a site is untrusted / insecure, you will need to install the 'DoD Certificates.' In order to access sites enabled with a DoD PKI certificate without being prompted to accept the DoD Certificate chain at each log on [like Firefox and Safari do], people using Internet Explorer and Chrome should install the DoD certificates. These are separate from the personal certificates that are on your CAC, but they are related.
Root Certificates
How can you (or your web server) trust the identity of someone over the network? An infrastructure of trusted third parties has been put in place to distribute trust between end-users. This infrastructure verifies that we are who we say we are. If we trust the DoD PKI infrastructure, then the infrastructure can vouch for us to trust others that have certificates issued from the DoD PKI.
Click to see larger image
.
The DoD PKI Infrastructure is comprised of two Root Certification Authorities and a number of Intermediate Authorities. If all of the DoD root certificates are not installed on your computer, various applications will not be able to trust all DoD PKI certificates.
Click to see larger image
.
Iogear Cac Reader Certificates
More information about this image can be found here: https://iase.disa.mil/pki-pke/interoperability/Pages/index.aspx