

FEMA-issued PIV Card holders must employ FEMA single sign-on to access NFIRS accounts. You'll need to enter your PIN here, rather than clicking Sign and then getting the standard OS X dialog to enter your PIN. Students can receive a max of two cards per semester. Once this configuration change has been made, the signature dialog box will change slightly to include a field to enter your PIN (or as Adobe calls it, "certificate password"), as shown in the screen shot below. If you have Firefox or Thunderbird installed, then it's the same as the one you have configured in those applications in order to use your CAC. If you're using something other than CACKey, then you'll need to determine the path for your PKCS#11 module. The above steps will need to be repeated for each user account on the machine.

Token2Shell stores all its essential settings ( ex. You just need to plug it in and use it as any other private key. YubiKey 4/Neo), you can use it for the SSH public key user authentication in Token2Shell. sudo chmod 755 /Library/CACKey/libcackey.dylib Using PIV Smart Cards for SSH Public Key Authentication (YubiKey) If you have a PIV smart card ( ex.sudo chown root:admin /Library/CACKey/libcackey.dylib.If they're not, change them using Terminal.app: Verify permissions of /Library/CACKey/libcackey.dylib are correct they should be -rwxr-xr-x (755) and owned by root, group admin.This is the solution: it assumes you are using CACKey, but can probably be translated to other middleware:
