Download the 5 files via links below (you may need to <ctrl> click, select Download Linked File As.. on each link) Save to your downloads folder
Please know.. IF You have any DoD certificates already located in your keychain access, you will need to delete them prior to running the AllCerts.p7b file below.
https://militarycac.com/maccerts/AllCerts.p7b,
https://militarycac.com/maccerts/RootCert2.cer,
https://militarycac.com/maccerts/RootCert3.cer,
https://militarycac.com/maccerts/RootCert4.cer, and
Double click each of the files to install certificates into the login section of keychain
Select the Kind column, verify the arrow is pointing up, scroll down to certificate, look for all of the following certificates:
DOD EMAIL CA-33 through DOD EMAIL CA-34,
DOD EMAIL CA-39 through DOD EMAIL CA-44,
DOD EMAIL CA-49 through DOD EMAIL CA-52,
DOD EMAIL CA-59,
DOD ID CA-33 through DOD ID CA-34,
DOD ID CA-39 through DOD ID CA-44,
DOD ID CA-49 through DOD ID CA-52,
DOD ID CA-59
DOD ID SW CA-35 through DOD ID SW CA-38,
DOD ID SW CA-45 through DOD ID SW CA-48,
DoD Root CA 2 through DoD Root CA 5,
DOD SW CA-53 through DOD SW CA-58, and
DOD SW CA-60 through DOD SW CA-61
NOTE: If you are missing any of the above certificates, you have 2 choices,
1. Delete all of them, and re-run the 5 files above, or
2. Download the allcerts.zip file and install each of the certificates you are missing individually.
Errors:
Error 100001 Solution
Error 100013 Solution
Smart card for mac os x 10.7
You may notice some of the certificates will have a red circle with a white X . This means your computer does not trust those certificates
You need to manually trust the DoD Root CA 2, 3, 4, & 5 certificates
Double click each of the DoD Root CA certificates, select the triangle next to Trust, in the When using this certificate: select Always Trust, repeat until all 4 do not have the red circle with a white X.
You may be prompted to enter computer password when you close the window
Once you select Always Trust, your icon will have a light blue circle with a white + on it.
The 'bad certs' that have caused problems for Windows users may show up in the keychain access section on some Macs. These need to be deleted / moved to trash.
The DoD Root CA 2 & 3 you are removing has a light blue frame, leave the yellow frame version. The icons may or may not have a red circle with the white x
or DoD Interoperability Root CA 1 or CA 2 certificate
DoD Root CA 2 or 3 (light blue frame ONLY) certificate
or Federal Bridge CA 2016 or 2013 certificate
or Federal Common Policy CAcertificate
or or SHA-1 Federal Root CA G2 certificate
or US DoD CCEB Interoperability Root CA 1 certificate
If you have tried accessing CAC enabled sites prior to following these instructions, please go through this page before proceeding
Clearing the keychain (opens a new page)
Please come back to this page to continue installation instructions.
Step 5a: DoD certificate installation instructions for Firefox users
NOTE: Firefox will not work on Catalina (10.15.x), or last 4 versions of Mac OS if using the native Apple smartcard ability
Download AllCerts.zip, [remember where you save it].
double click the allcerts.zip file (it'll automatically extract into a new folder)
Option 1 to install the certificates (semi automated):
From inside the AllCerts extracted folder, select all of the certificates
<control> click (or Right click) the selected certificates, select Open With, Other..
In the Enable (selection box), change to All Applications
Select Firefox, then Open
You will see several dozen browser tabs open up, let it open as many as it wants.
You will eventually start seeing either of the 2 messages shown next
If the certificate is not already in Firefox, a window will pop up stating 'You have been asked to trust a new Certificate Authority (CA).'
Check all three boxes to allow the certificate to: identify websites, identify email users, and identify software developers
or
Albion for mac. 'Alert This certificate is already installed as a certificate authority.' Click OK
Once you've added all of the certificates..
• Click Firefox (word) (upper left of your screen)
• Preferences
• Advanced (tab)
• Press Network under the Advanced Tab
• In the Cached Web Content section, click Clear Now (button).
• Quit Firefox and restart it
Option 2 to install the certificates (very tedious manual):
Click Firefox (word) (upper left of your screen)
Preferences
Advanced (tab on left side of screen)
Certificates (tab)
View Certificates (button)
Authorities (tab)
Import (button)
Browse to the DoD certificates (AllCerts) extracted folder you downloaded and extracted above.
Note: You have to do this step for every single certificate
Note2: If the certificate is already in Firefox, a window will pop up stating: 'Alert This certificate is already installed as a certificate authority (CA).' Click OK
Note3: If the certificate is not already in Firefox, a window will pop up stating 'You have been asked to trust a new Certificate Authority (CA).'
Check all three boxes to allow the certificate to: identify websites, identify email users, and identify software developers
Once you've added all of the certificates..
• Click Firefox (word) (upper left of your screen)
• Preferences
• Advanced (tab)
• Press Network under the Advanced Tab
• In the Cached Web Content section, click Clear Now (button).
• Quit Firefox and restart it
Step 6: Decide which CAC enabler you can / want to use
Only for Mac El Capitan (10.11.x or older) Osiris for mac.
After installing the CAC enabler, restart the computer and go to a CAC enabled website
NOTE: Mac OS Sierra (10.12.x), High Sierra (10.13.x), Mojave (10.14.x) or Catalina (10.15.x) computers no longer need a CAC Enabler.
Try to access the CAC enabled site you need to access now
Mac support provided by: Michael Danberry

General

In several places in this instruction you have to run a command in Terminal. You can start Terminal from Applications/Utilities or you can write Terminal in Spotlight.
The text writen this way are commands, which you have to run in Terminal. You dont have to write them just copy them with the clipboard. To work correctly commands which starts with sudo,is nessesary for you to have a password for the user. If you don't have set a temporary one during the settings. After you use one of the commands you will be propted for password.

What is nessesary to work with digital signature

In order to use your digital sigature is nessesary to install the driver for the smart card reader, the middleware for the smart card and the service for smart card resders (pcscd) running. The service pcscd must start automatically when you plug a reader.

System requerments

The software requered to work with certificates on Mac, supports Mac OS X 10.5 or newer.
Support for 10.5 is paritial. All needed drivers work on 10.5 but InfoNotary software for signing of documents and card management does not.

Driver for readers

ACR 38C

How To Update Mac Os X

If the your reader is labeled with ACR38C-SPC-R at the bottom, have a sign SIMLector 38T on the inside or a sign mLector-S, then your device works with the build in driver in the OS and you don't have to install any drivers.

ACR 38U

Reader that are labeled ACR 38U,are not compatible with this driver, so if you use such a device you have to install driver from the site of the manifactorer.

Omnikey (HID Global)

For you to use OmniKey CardMan, you have to install the driver from HID Global for your version of OS X:
After update of the OS X you have to install the drivers again.

Bit4id miniLector-S

If your reader is labeled with miniLector-S you must install this driver -driver for miniLector-S for OS X from 10.6 to 10.9 inclusive.
In OS X 10.10 Yosemite this readder is supported by Apple driver, so there is no need to install another driver.

Todos

To use Todos Argos Mini II you have to install the driver. Depends on what version of Mac OS X you use install the following:

Install Smart Card driver

Depend of the model of your card you have to use different software. The model of the card is on the Personal Access Rights, which you receive with your card. In case your model is „T&S DS/2048 (L)“, you have to install Bit4id Universal Middleware from you installation CD. If the model is „CardOS V4.3B (C)“, you have to install OpenSC.
Incase you dont have Personal Access Rights, you can check your card model with this command pcsctest from terminal. She will ask you for the reader number, you have to press 1. If there is no problem with the reader installation you will get a row beginning with „Current Reader ATR Value“. Against this text is an indetifier for the card.

Installation of Bit4id Universal Middleware

To use Bit4id on Mac OS X, you must install Bit4id Universal Middleware. You can find it on the installation CD, in folder Install/MacOSX. to work with Firefox и Thunderbird, you have to install Bit4id Cryptoki Libraries 1.2.12.pkg, and for integration with the OS and the other programs for Mac OS X - bit4id-tokend-ts-en-1.2.9.0.pkg.dmg.

Mac Os X Latest

In case you have to register the PKCS#11 module на Bit4id in a program different from Firefox, Thunderbird or InfoNotary Smart Card Manager you have to specify a path - /System/Library/bit4id/cryptoki/libbit4ipki.dylib.
After the installation continue with configuration Firefox or Safari.
Note: In case you didn't receive a CD or your laptop doesn't have a CD drive, please write to [email protected] , and we will send you the drivers.

Download and install OpenSC

To use your certificate on OSX you must install OpenSC. With OpenSС you dont install any program with graphic interface so you wont find anything in Applications. You can download the latest version for your OS from here:
In case you have to register the PKCS#11 module на Bit4id in a program different from Firefox, Thunderbird or InfoNotary Smart Card Manager you have to specify a path - /Library/OpenSC/lib/onepin-opensc-pkcs11.so.
After the installation continue with configuration Testing Installation or Firefox and Safari.

Use both OpenSC and Bit4id Universal Middleware

In case you want to use both OpenSC and Bit4id Universal Middleware on the same computer you have to forbid OpenSC to access T&S DS/2048 smart cards. The easiest way to do it is to use following program:
Disable Bit4id cards in OpenSC.

Gemalto Smart Card Reader Mac Os X

If you prefer to do it manually you can find instructions on OpenSC page.

Testing Installation

If you have problem using your certificate, you can run the following program to identify it:
It can send information directly to us. After report is accepted, it will show nine digit number, that can be used by our support team to see test result. If you do not have Internet connection or direct sending failed, you can save report and send it to [email protected].
Reader and card should be connected to the computer when test program is started.

Uninstall

OpenSC can be uninstalled with this program - OpenSC uninstaller.
Bit4id Universal Middleware can be uninstaled, by running the program Uninstaller from the folder /System/Library/bit4id.

Documentation

Documentation for OpenSC is available on Internet or in folder /Library/OpenSC/doc/ after the installation.
On the page Working with OpenSC you can find instruction for th most common operation with OpenSC.
Взето от „http://wiki.infonotary.com/index.php?title=Installation_of_smart_card_reader_and_smart_card_drivers_in_macOS&oldid=1689“.