Set up CAC on Linux
Linux CAC support is excellent if you know what to install. Works on Ubuntu, Fedora, Arch, and most distros.
~20 min · 5 steps
Stuck on a specific error? Describe it to the AI assistant for a tailored fix — or check our error code reference.
Steps
- 1
Install packages
Ubuntu / Debian: 'sudo apt install pcscd pcsc-tools libccid opensc libnss3-tools'. Fedora: 'sudo dnf install pcsc-lite pcsc-tools ccid opensc nss-tools'. Then enable pcscd: 'sudo systemctl enable --now pcscd'.
- 2
Verify the reader
Run 'pcsc_scan' in a terminal with your CAC inserted. You should see your reader name and 'Card inserted' with an ATR. If you see 'No reader found', your reader needs a different driver — check the readers page.
- 3
Install DoD certificates
Download AllCerts.zip from cyber.mil. Unzip. Import each .cer into your browser's NSS store: 'certutil -d sql:$HOME/.pki/nssdb -A -t TC -n "DoD Root CA 3" -i DoD_Root_CA_3.cer' (repeat per cert).
- 4
Register the PKCS#11 module in Firefox/Chrome
Firefox: Preferences → Privacy & Security → Security Devices → Load. Module name: OpenSC, file: /usr/lib/x86_64-linux-gnu/opensc-pkcs11.so (path varies). Chrome reads the same NSS store as the certutil command above.
- 5
Test
Insert CAC, open Firefox, browse to a .mil site. Firefox will ask you to unlock the token (your CAC PIN). Select the right certificate when prompted.
Common problems
pcsc_scan shows reader but no card
Reseat the CAC. Make sure chip side is correct. Some cheap readers need a firmware update.
Firefox doesn't prompt for PIN
Re-load the OpenSC PKCS#11 module. Restart Firefox.
Chrome can't see CAC
Run 'modutil -dbdir sql:$HOME/.pki/nssdb -add "CAC Module" -libfile /usr/lib/x86_64-linux-gnu/opensc-pkcs11.so' then restart Chrome.
Still stuck?
Ask the AI assistant