CACHelp

Set up CAC on Linux

Linux CAC support is excellent if you know what to install. Works on Ubuntu, Fedora, Arch, and most distros.

~20 min · 5 steps

Stuck on a specific error? Describe it to the AI assistant for a tailored fix — or check our error code reference.

Steps

  1. 1

    Install packages

    Ubuntu / Debian: 'sudo apt install pcscd pcsc-tools libccid opensc libnss3-tools'. Fedora: 'sudo dnf install pcsc-lite pcsc-tools ccid opensc nss-tools'. Then enable pcscd: 'sudo systemctl enable --now pcscd'.

  2. 2

    Verify the reader

    Run 'pcsc_scan' in a terminal with your CAC inserted. You should see your reader name and 'Card inserted' with an ATR. If you see 'No reader found', your reader needs a different driver — check the readers page.

  3. 3

    Install DoD certificates

    Download AllCerts.zip from cyber.mil. Unzip. Import each .cer into your browser's NSS store: 'certutil -d sql:$HOME/.pki/nssdb -A -t TC -n "DoD Root CA 3" -i DoD_Root_CA_3.cer' (repeat per cert).

  4. 4

    Register the PKCS#11 module in Firefox/Chrome

    Firefox: Preferences → Privacy & Security → Security Devices → Load. Module name: OpenSC, file: /usr/lib/x86_64-linux-gnu/opensc-pkcs11.so (path varies). Chrome reads the same NSS store as the certutil command above.

  5. 5

    Test

    Insert CAC, open Firefox, browse to a .mil site. Firefox will ask you to unlock the token (your CAC PIN). Select the right certificate when prompted.

Common problems

pcsc_scan shows reader but no card

Reseat the CAC. Make sure chip side is correct. Some cheap readers need a firmware update.

Firefox doesn't prompt for PIN

Re-load the OpenSC PKCS#11 module. Restart Firefox.

Chrome can't see CAC

Run 'modutil -dbdir sql:$HOME/.pki/nssdb -add "CAC Module" -libfile /usr/lib/x86_64-linux-gnu/opensc-pkcs11.so' then restart Chrome.