In this document explains how to setup SBM to authenticate the CAC / PIV Personal Certificate against a trust store of trusted Certificate Authorities. NOTE: To watch a video of these steps, see KB S141238 .
Browser Setup : By default, IE will not prompt for the client certificate when there is only one installed in the browser. It may be helpful during initial setup to change this setting. It is under Internet Options > Security > Pick your zone > Custom Level > uncheck the option called "Don't prompt for client certificate selection when only one certificate".
There a few work arounds. Connect to Exchange mailbox using POP3 or IMAP instead of Exchange Web Services -OR- Install the Notification Server and MailClient on a different server.
Note that in SBM 11.x, a feature was introduced under the Component Servers tab of the Configurator where you can simply check a box labeled "Use IIS to proxy all server requests" to configure SBM to do this without needing to manually implement the changes below. This article is valid for CAC / PIV / Certs stored in the user's Windows profile and other Smart Cards . Description of Issue
This only happens when using a Version Manager SSO server is running VM 8.5.0 - 8.5.2. If Version Manager was configured to use an SBM SSO server, or if the VM SSO server was running VM 8.4.x, this error would not occur.
When initially setting up CAC, if everything is not completely finished, users will get the following error after clicking on the SmartCard Login button: Invalid User ID or password