Initial login using smart card (CAC card) is successful; however, locked screen cannot be unlocked with Smart Cards.
Error messages similar to the following may also be displayed:
[gdm-smartcard]: pam_centrify_pkcs11(gdm-smartcard:auth): No valid certificate which meets all requirements found
The problem is caused by the pam_pkcs11 package which handles x.509 certificate based user login. The package provided in RHEL 7.0+ does not handle user login requests correctly. This is a problem with the package, pam_pkcs11, which is supplied by Red Hat.Workaround:
Instead of entering PIN directly into the lock screen, please use "Log in as another user" button on the lock screen, then enter the correct PIN to unlock the screen. Resolution:
There are currently no permanent fix which Centrify can provide for this problem.
Red Hat acknowledged the problem and according is working on a fix. Current ETA for the fix is RHEL 7.4. Please see the following Red Hat bug for more information: https://bugzilla.redhat.com/show_bug.cgi?id=1238342Update November 2017
: Centrify is investigating reports that the issue described in this knowledge article is not addressed after upgrading to RHEL 7.4. We will update this article as new information is determined. For any further questions please contact Centrify Support.