CACHelp

Set up CAC on macOS

macOS has built-in smart card support since 10.12. With the right cert bundle and Safari, you can be on .mil sites in 10 minutes.

~10 min · 5 steps

Stuck on a specific error? Describe it to the AI assistant for a tailored fix — or check our error code reference.

Steps

  1. 1

    Plug in your CAC reader

    Most readers work driverless on macOS via PCSC. Plug in, wait ~15 seconds. To confirm: System Information → USB — your reader should appear.

  2. 2

    Download the DoD All Certs Bundle for macOS

    From cyber.mil → PKI/PKE → Tools, download 'AllCerts.zip' or the .pkg installer for macOS. Unzip if needed.

  3. 3

    Install certificates into Keychain

    Double-click each .cer file (or run the .pkg). Keychain Access opens — install into the SYSTEM keychain (not Login), enter your admin password. Then in Keychain Access, find each DoD Root CA, right-click → Get Info → Trust → set 'When using this certificate' to 'Always Trust'.

  4. 4

    Use Safari (recommended) or Firefox

    Safari uses Keychain natively and 'just works' for CAC. Chrome on macOS is unreliable for CAC (see Error 141). Firefox works but needs the DoD certs imported into Firefox's own cert store separately.

  5. 5

    Insert CAC and authenticate

    Insert your CAC, browse to a .mil site, pick your cert when prompted. If Safari doesn't prompt, open Keychain Access — your CAC certs should appear under a 'pivtoken' or similar smart-card keychain.

Common problems

Chrome unreliable

Use Safari or Firefox. If you must use Chrome, install Thursby PKard ($30) for a proper middleware experience.

Cert not trusted

Open Keychain Access, find DoD Root CA 3 / 4 / 5 / 6, set Trust to Always Trust.

Cached cert

Open Keychain Access → delete old DoD certs and re-import.