DoD PKI Certificates: Eligibility, Issuance, and Renewal

DoD PKI certificates are the digital credentials the Department of Defense uses to confirm who you are on its networks, sign your documents and emails, and encrypt your communications so only the intended recipient can read them. For most people, these certificates live on the chip inside a Common Access Card and get used every time you swipe in and enter a PIN. You obtain them by registering in the Defense Enrollment Eligibility Reporting System (DEERS), clearing at least a Tier 1 background investigation, and showing up in person at a RAPIDS site with two identity documents.

What the Certificates on Your CAC Actually Do

Three certificates typically load onto a single CAC at issuance, and each one has a different job.

The identity certificate is what gets you through the door. When you log in to a DoD network, website, or application, swiping your card and entering your PIN triggers this certificate to prove you are who your record says you are.

The digital signature certificate lets you sign documents and emails electronically. A valid signature shows the content has not been altered since you signed it and ties the action to your identity, which means you cannot later deny signing.

The encryption certificate protects the contents of emails and attached files. The sender uses your public key to lock a message, and only your private key, sitting on your card behind your PIN, can unlock it.

Servers, workstations, and other network devices that need to authenticate without a person present receive their own software-based certificates instead of card-based ones. Those are handled by administrators through a separate portal, not by the end user.

Who Is Eligible

Authorization for DoD PKI certificates tracks who needs access to DoD networks and facilities:

  • Active duty military across all branches, including Selected Reserve members.
  • DoD civilian employees who need system access.
  • Contractors whose contract specifically requires DoD network or facility access, verified by a government sponsor.
  • Non-person entities such as servers and network devices, which receive software-based certificates.

Partner organizations that work with the DoD from outside its internal networks use External Certification Authority (ECA) certificates rather than standard DoD-issued ones. Those come from approved commercial vendors and follow a separate process from the CAC issuance described here.

Background Investigation Comes First

You cannot receive a CAC or PIV credential until at least a Tier 1 background investigation has been initiated. Under federal credentialing standards, an agency can issue an interim credential once your investigative questionnaire has been reviewed favorably, the investigation request has been submitted, and the FBI fingerprint check has returned clean. Otherwise the agency waits for the full investigation to complete.1Office of Personnel Management. Credentialing Standards Procedures for Issuing Personal Identity Verification Credentials

Extra Step for Contractors

If you are a contractor, a government official has to formally sponsor your credential by confirming your contract requires the access. That sponsorship is documented on DD Form 2875, the System Authorization Access Request.2Washington Headquarters Services. DD Form 2875 – System Authorization Access Request (SAAR) You complete your personal details, your supervisor verifies your clearance level and the systems you need, and a Trusted Agent or Sponsor reviews the form against government records before it moves forward. The form is available through your unit’s administrative office or the official DoD forms website.

Documents to Bring

Federal Identity Processing Standard 201 requires two original identity source documents at identity proofing, split into a primary and a secondary tier.3National Institute of Standards and Technology. FIPS 201 – Common Identification, Security, and Privacy Requirements

Your primary document must meet “Strong evidence” requirements. Acceptable options include:

  • U.S. passport or passport card
  • REAL-ID compliant driver’s license or state-issued ID with a photograph
  • Permanent Resident Card (Form I-551)
  • Foreign passport
  • Employment Authorization Document with photo (Form I-766)
  • U.S. military ID card or dependent’s ID card
  • Existing PIV card

Your secondary document can be another item from the primary list, as long as it is not the same type, or something from a broader set including a Social Security card, certified birth certificate, voter registration card, government-issued photo ID from any level of government, or a U.S. Coast Guard Merchant Mariner card.

How Issuance Works

Getting the certificates onto a CAC is a two-stage process: registration in DEERS, then an in-person visit to a Real-Time Automated Personnel Identification System (RAPIDS) site. Your DEERS registration has to be complete before you go to RAPIDS.4ID Card Office Online. ID Card Office Online

At the RAPIDS site, a Verifying Official reviews your two identity documents and, if you are a contractor, your approved DD Form 2875. They confirm your identity matches DEERS and load the identity, signature, and encryption certificates onto the card’s chip. You then select a PIN of six to eight digits, which unlocks the private keys on your card every time you use it.5Department of the Navy Chief Information Officer. Introducing the Next-Generation Common Access Card Pick something you can remember without writing it down.

Certificates for Phones and Tablets

Because a phone cannot accept a physical CAC, the DoD issues Mobile PKI Credentials, previously called derived credentials, through a system called Purebred. Purebred is the only DoD-approved system for provisioning these credentials.6Cyber Exchange. Purebred A Purebred Agent enrolls your device, and the app delivers certificates to it after verifying your identity electronically through your existing CAC.

Mobile credentials come in two assurance levels. Medium Mobile credentials (AAL 2) cover authentication to most information systems, Wi-Fi and VPN access, and email signing and encryption. Medium-Hardware Mobile credentials (AAL 3) add access to higher-sensitivity systems and network logon capabilities such as Windows sign-in.7DoD CIO. DoD Mobile Public Key Infrastructure (PKI) Credentials The credentials must sit in the device’s hardware-backed keystore or a Trusted Platform Module, be managed by a DoD enterprise management system, and be protected by at least a six-digit PIN or biometric lock. If the device is lost, the credentials get revoked and the device gets remotely wiped.

Getting Your Computer to Use the Card

A CAC in hand is only useful once your workstation can read it. Three pieces have to be in place.

You need a smart card reader that is PC/SC certified, supports both T=0 and T=1 protocols, handles 3V and 5V cards, and meets ISO 7816 standards. On Linux or macOS the reader also needs PC/SC M.U.S.C.L.E.-compliant drivers.8CAC.mil. DoD CAC Release 1.0 Reader Specifications For a personal computer, any USB reader advertised as CAC-compatible and PC/SC certified works.

You need middleware, the software layer that lets your operating system and applications talk to the certificates on the card. The two most common products across the DoD are ActivClient and 90meter.9Cyber Exchange. Middleware Distribution runs through your organization’s software licensing office. Government-furnished equipment usually has it pre-installed.

You need the DoD root and intermediate Certificate Authority certificates installed so your browser and operating system will trust DoD sites and your card. On Windows, the InstallRoot utility handles this across Internet Explorer, Chrome, Firefox, and Java certificate stores. On macOS, a separate Smartcard Services package loads the DoD CA certificates, and you may need to adjust trust settings to prevent cross-certificate chaining issues. On Linux, you import the certificates into Firefox’s NSS trust store manually.10Cyber Exchange. Getting Started Restart every browser after installing.

Locked PINs and Certificate Updates

Enter your PIN wrong too many times and the card locks. There is no way to reset it remotely.11DoD Common Access Card. Managing Your CAC You go to the nearest RAPIDS site, prove ownership by matching your fingerprint against the one stored in DEERS when the card was issued, and select a new PIN on the spot. Same process at every location, regardless of branch.

Some certificate work can be done online through the ID Card Office Online portal. If your CAC is within 30 days of expiration but has not expired, and your affiliation in DEERS extends past the card’s expiration date, you may be able to rekey your certificates remotely without visiting RAPIDS.12CAC.mil. Guide for Cardholders to Use Temporary Capability for CAC/VoLAC Certificate Update If your affiliation ends before the card does, or the rekey throws an error, contact your HR representative or Service Helpdesk.

Renewal and Revocation

CACs and their certificates are typically valid for three years. When that window closes you lose access to every network and communication channel tied to them, so do not wait until the last week. A legal name change, a change in duty status, or a shift in employment also means a trip to a RAPIDS site to update the card and reissue certificates that reflect the new information.

Revocation permanently invalidates a certificate before its scheduled expiration. Security protocols require immediate revocation if a card is lost or stolen, if the holder separates from service or employment, or if a mobile device carrying derived credentials goes missing. For mobile credentials, the device must also be remotely wiped.7DoD CIO. DoD Mobile Public Key Infrastructure (PKI) Credentials Report a lost card immediately so revocation can happen before someone else tries to use it.

Unauthorized Use Is a Federal Crime

Using a revoked, stolen, or unauthorized credential to access DoD systems is prosecutable under the Computer Fraud and Abuse Act. Penalties range from up to one year in prison for basic unauthorized access to 10 or 20 years for offenses involving government computers, fraud, or damage to systems. If the unauthorized access recklessly causes serious bodily injury, the maximum is 20 years; if it causes death, life imprisonment is available.13Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection With Computers Treat the card and its PIN accordingly.