All supported versions of Centrify DirectControl on Red Hat Enterprise Linux 7.0 and later. Problem:
Initial login using smart card (CAC card) is successful; however, locked screen cannot be unlocked with Smart Cards.
Error messages similar to the following may also be displayed:
[gdm-smartcard]: pam_centrify_pkcs11(gdm-smartcard:auth): No valid certificate which meets all requirements found
The problem is caused by the pam_pkcs11 package which handles x.509 certificate based user login. The package provided in RHEL 7.0+ does not handle user login requests correctly. This is a problem with the package, pam_pkcs11, which is supplied by Red Hat.
Red Hat has acknowledged the problem and is working on a fix. Current ETA for the fix is RHEL 7.4. Please see the following Red Hat bug for more information: https://bugzilla.redhat.com/show_bug.cgi?id=1238342Workaround:
Instead of entering PIN directly into the lock screen, please use "Log in as another user" button on the lock screen, then enter the correct PIN to unlock the screen. Resolution:
There are currently no permanent fix which Centrify can provide for this problem.