Owner's Manual
310 Using the CMC Directory Service
Troubleshooting the Smart Card Login
The following tips help you to debug an inaccessible Smart Card:
ActiveX plug-in is unable to detect the Smart Card reader
Ensure that the Smart Card is supported on the Microsoft Windows
operating system. Windows supports a limited number of Smart Card
cryptographic service providers (CSPs).
As a general check to see if the Smart Card CSPs are present on a
particular client, insert the Smart Card in the reader at the Windows login
(Ctrl-Alt-Del) screen and check to see if Windows detects the Smart Card
and displays the PIN dialog-box.
Incorrect Smart Card PIN
Check to see if the Smart Card has been locked out due to too many
attempts with an incorrect PIN. In such cases, the issuer of the Smart Card
in the organization is able to help you get a new Smart Card.
Unable to Log into CMC as an Active Directory User
If you cannot log into CMC as an Active Directory user, try logging into
CMC without enabling the Smart Card logon. You also have the option of
disabling the Smart Card Logon through the local RACADM using the
following commands:
racadm config -g cfgActiveDirectory -o cfgADSCLEnable 0
racadm config -g cfgActiveDirectory -o cfgADSSOEnable 0
Using CMC with Generic LDAP
A CMC administrator can now integrate the LDAP server user logins with
CMC. This integration requires configuration on both LDAP server and
CMC. On the LDAP server, a standard group object is used as a role group. A
user who has CMC access becomes a member of the role group. Privileges are
still stored on CMC for authorization similar to the working of the Standard
Schema setup with Active Directory support.