<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Common Access Card</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Common_Access_Card"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Common_Access_Card rootpage-Common_Access_Card skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Common Access Card</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<style data-mw-deduplicate="TemplateStyles:r1305433154">
/* start https://en.wikipedia.org/ */
.mw-parser-output .ambox{border:1px solid #a2a9b1;border-left:10px solid #36c;background-color:#fbfbfb;box-sizing:border-box}.mw-parser-output .ambox+link+.ambox,.mw-parser-output .ambox+link+style+.ambox,.mw-parser-output .ambox+link+link+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+style+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+link+.ambox{margin-top:-1px}html body.mediawiki .mw-parser-output .ambox.mbox-small-left{margin:4px 1em 4px 0;overflow:hidden;width:238px;border-collapse:collapse;font-size:88%;line-height:1.25em}.mw-parser-output .ambox-speedy{border-left:10px solid #b32424;background-color:#fee7e6}.mw-parser-output .ambox-delete{border-left:10px solid #b32424}.mw-parser-output .ambox-content{border-left:10px solid #f28500}.mw-parser-output .ambox-style{border-left:10px solid #fc3}.mw-parser-output .ambox-move{border-left:10px solid #9932cc}.mw-parser-output .ambox-protection{border-left:10px solid #a2a9b1}.mw-parser-output .ambox .mbox-text{border:none;padding:0.25em 0.5em;width:100%}.mw-parser-output .ambox .mbox-image{border:none;padding:2px 0 2px 0.5em;text-align:center}.mw-parser-output .ambox .mbox-imageright{border:none;padding:2px 0.5em 2px 0;text-align:center}.mw-parser-output .ambox .mbox-empty-cell{border:none;padding:0;width:1px}.mw-parser-output .ambox .mbox-image-div{width:52px}@media(min-width:720px){.mw-parser-output .ambox{margin:0 10%}}@media print{body.ns-0 .mw-parser-output .ambox{display:none!important}}
/* end https://en.wikipedia.org/ */
</style>
<p>The <b>common access card</b>, also commonly referred to as the <b>CAC</b>, is the standard identification for active duty United States defense personnel. The card itself is a <a href="Smart_card" title="Smart card">smart card</a> about the size of a credit card.<sup id="cite_ref-DODCAC_1-0" class="reference"><a href="#cite_note-DODCAC-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> Defense personnel that use the CAC include the <a href="Selected_Reserve" title="Selected Reserve">Selected Reserve</a> and <a href="National_Guard_of_the_United_States" class="mw-redirect" title="National Guard of the United States">National Guard</a>, <a href="United_States_Department_of_Defense" title="United States Department of Defense">United States Department of Defense</a> (DoD) civilian employees, <a href="United_States_Coast_Guard" title="United States Coast Guard">United States Coast Guard</a> (USCG) civilian employees and eligible DoD and USCG contractor personnel.<sup id="cite_ref-DODCAC_1-1" class="reference"><a href="#cite_note-DODCAC-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> It is also the principal card used to enable physical access to buildings and controlled spaces, and it provides access to defense computer networks and systems. It also serves as an identification card under the <a href="Geneva_Conventions" title="Geneva Conventions">Geneva Conventions</a> (especially the <a href="Third_Geneva_Convention" title="Third Geneva Convention">Third Geneva Convention</a>). In combination with a <a href="Personal_identification_number" title="Personal identification number">personal identification number</a>, a CAC satisfies the requirement for <a href="Two-factor_authentication" class="mw-redirect" title="Two-factor authentication">two-factor authentication</a>: something the user knows combined with something the user has. The CAC also satisfies the requirements for <a href="Digital_signature" title="Digital signature">digital signature</a> and <a href="Data_encryption" class="mw-redirect" title="Data encryption">data encryption</a> technologies: authentication, integrity and <a href="Non-repudiation" title="Non-repudiation">non-repudiation</a>.
</p><p>The CAC is a controlled item. As of 2008, DoD has issued over 17 million smart cards. This number includes reissues to accommodate changes in name, rank, or status and to replace lost or stolen cards. As of the same date, approximately 3.5 million unterminated or active CACs are in circulation. DoD has deployed an issuance infrastructure at over 1,000 sites in more than 25 countries around the world and is rolling out more than one million card readers and associated middleware.
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Issuance">Issuance</h2></div>
<p>The CAC is issued to active United States Armed Forces (Regular, Reserves and National Guard) in the Department of Defense and the U.S. Coast Guard; DoD civilians; USCG civilians; non-DoD/other government employees and State Employees of the National Guard; and eligible DoD and USCG contractors who need access to DoD or USCG facilities and/or DoD computer network systems:
</p>
<ul><li>Active Duty U.S. Armed Forces (to include Cadets and Midshipmen of the U.S. Service Academies)</li>
<li>Reserve members of the U.S. Armed Forces</li>
<li>National Guard (Army National Guard and Air National Guard) members of the U.S. Armed Forces</li>
<li><a href="National_Oceanic_and_Atmospheric_Administration" title="National Oceanic and Atmospheric Administration">National Oceanic and Atmospheric Administration</a></li>
<li><a href="National_Aeronautics_and_Space_Administration" class="mw-redirect" title="National Aeronautics and Space Administration">National Aeronautics and Space Administration</a></li>
<li><a href="United_States_Public_Health_Service" title="United States Public Health Service">United States Public Health Service</a></li>
<li>Emergency-Essential Employees</li>
<li>Contingency Contractor Employees</li>
<li>Contracted college & university ROTC Cadets and Midshipmen</li>
<li>Deployed Overseas Civilians</li>
<li>Non-Combatant Personnel</li>
<li>DoD/Uniformed Service Civilians residing on military installations in <a href="CONUS" class="mw-redirect" title="CONUS">CONUS</a>, <a href="Hawaii" title="Hawaii">Hawaii</a>, <a href="Alaska" title="Alaska">Alaska</a>, <a href="Puerto_Rico" title="Puerto Rico">Puerto Rico</a>, or <a href="Guam" title="Guam">Guam</a></li>
<li>DoD/Uniformed Service Civilians or Contracted Civilian residing in a foreign country for at least 365 days</li>
<li>Presidential Appointees approved by the <a href="United_States_Senate" title="United States Senate">United States Senate</a></li>
<li>DoD Civilian employees, and United States Military veterans with a Veterans Affairs Disability rating of 100% P&T</li>
<li>Eligible DoD and USCG Contractor Employees</li>
<li>Non-DoD/other government and state employees of the National Guard</li></ul>
<p>Future plans include the ability to store additional information through the incorporation of <a href="RFID" class="mw-redirect" title="RFID">RFID</a> chips or other contactless technology to allow seamless access to DoD facilities.
</p><p>The program that is currently used to issue CAC IDs is called the <a href="Real-Time_Automated_Personnel_Identification_System" title="Real-Time Automated Personnel Identification System">Real-Time Automated Personnel Identification System</a> (RAPIDS). RAPIDS interfaces with the Joint Personnel Adjudication System (JPAS), and uses this system to verify that the candidate has passed a background investigation and FBI fingerprint check. Applying for a CAC requires DoD form 1172-2 to be filled out and then filed with RAPIDS.
</p><p>The system is secure and monitored by the DoD at all times. Different RAPIDS sites have been set up throughout military installations in and out of combat theater to issue new cards.
</p>
<div class="mw-heading mw-heading2"><h2 id="Design">Design</h2></div>
<p>On the front of the card, the background shows the phrase "U.S. DEPARTMENT OF DEFENSE" repeated across the card. A color photo of the cardholder is placed on the top left corner. Below the photo is the name of the cardholder. The top right corner displays the expiration date. Other information on the front includes (if applicable) the holders's: <a href="Pay_grade" title="Pay grade">pay grade</a>, rank, and federal identifier. A <a href="PDF417" title="PDF417">PDF417</a> stacked barcode is displayed on the bottom left corner. An integrated circuit chip (ICC) is placed near the bottom-middle of the front of the card.
</p><p>There are three color code schemes used on the front of the CAC. A blue bar across the holder’s name shows that the cardholder is a non-U.S. citizen. A green bar shows that the cardholder is a contractor. Absence of a bar indicates all other personnel—including military personnel and civil workers, among others.
</p><p>The back of the card has a ghost image of the cardholder. If applicable, the card also contains the date of birth, blood type, DoD benefits number, Geneva Convention category, and DoD Identification Number of the holder (also used as the Geneva Convention number, replacing the previously used Social Security Number). The DoD number is also known as the <a href="Electronic_data_interchange" title="Electronic data interchange">Electronic data interchange</a> Personal Identifier (EDIPI). A <a href="Code_39" title="Code 39">Code 39</a> barcode and a magnetic strip are at the top and bottom of the card, respectively. The cardholder’s DoD ID/EDIPI number is permanent throughout his or her career with the DoD or USCG, regardless of department or division. Likewise, the permanent number follows retired U.S. military personnel who subsequently become DoD or USCG civilians or DoD or USCG contractors needing a card. Additionally, for non-military spouses, unremarried former spouses, and widows/widowers of active, Reserve or Retired U.S. military personnel who themselves become DoD or USCG civilians or DoD or USCG contractors, the DoD ID/EDIPI Number on their CAC will be the same as on their DD 1173 Uniformed Services Privilege and Identification Card (e.g., Dependent ID card).
</p><p>The front of the CAC is fully laminated, while the back is only laminated in the lower half (to avoid interference with the magnetic stripe).<sup id="cite_ref-2" class="reference"><a href="#cite_note-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>
</p><p>The CAC is said to be resistant to identity fraud,<sup id="cite_ref-3" class="reference"><a href="#cite_note-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup> tampering, counterfeiting, and exploitation and provides an electronic means of rapid authentication.
</p><p>There are currently four different variants of CACs.<sup id="cite_ref-DODCAC_1-2" class="reference"><a href="#cite_note-DODCAC-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> The Geneva Conventions Identification Card is the most common CAC and is given to active duty/reserve armed forces and uniformed service members. The Geneva Convention Accompany Forces Card is issued to emergency-essential civilian personnel. The ID and Privilege Common Access Card is for civilians residing on military installations. The ID card is for DOD/Government Agency identification for civilian employees.
</p>
<div class="mw-heading mw-heading2"><h2 id="Encryption">Encryption</h2></div>
<p>Until 2008, all CACs were encrypted using 1,024-bit encryption. Starting 2008, the DoD switched to 2,048-bit encryption.<sup id="cite_ref-2048bit_4-0" class="reference"><a href="#cite_note-2048bit-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> Personnel with the older CACs had to get new CACs by the deadline.<sup id="cite_ref-2048bit_4-1" class="reference"><a href="#cite_note-2048bit-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> On October 1, 2012, all certificates encrypted with less than 2,048-bits were placed on revocation status, rendering legacy CACs useless except for visual identification.<sup id="cite_ref-2048bit_4-2" class="reference"><a href="#cite_note-2048bit-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Usage">Usage</h2></div>
<p>The CAC is designed to provide <a href="Two-factor_authentication" class="mw-redirect" title="Two-factor authentication">two-factor authentication</a>: what you have (the physical card) and what you know (the <a href="Personal_Identification_Number" class="mw-redirect" title="Personal Identification Number">PIN</a>). This CAC technology allows for rapid authentication, and enhanced physical and logical security. The card can be used in a variety of ways.
</p>
<div class="mw-heading mw-heading3"><h3 id="Visual_identification">Visual identification</h3></div>
<p>The CAC can be used for visual identification by way of matching the color photo with the owner. This is used for when the user passes through a guarded gate, or purchases items from a store, such as a PX/BX that require a level of privileges to use the facility. Some states allow the CAC to be used as a government-issued ID card, such as for voting or applying for a drivers license.
</p>
<div class="mw-heading mw-heading3"><h3 id="Magnetic_stripe">Magnetic stripe</h3></div>
<p>The <a href="Magnetic_stripe_card" class="mw-redirect" title="Magnetic stripe card">magnetic stripe</a> can be read by swiping the card through a magnetic stripe reader, much like a credit card. The magnetic stripe is actually blank when the CAC is issued. However, its use is reserved for localized physical security systems.<sup id="cite_ref-5" class="reference"><a href="#cite_note-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> The magnetic stripe was removed first quarter 2018.<sup id="cite_ref-6" class="reference"><a href="#cite_note-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Integrated_circuit_chip_(ICC)">Integrated circuit chip (ICC)</h3></div>
<p>The integrated circuit chip (ICC) contains information about the owner, including the PIN and one or more <a href="Public-key_infrastructure" class="mw-redirect" title="Public-key infrastructure">PKI</a> digital certificates. The ICC comes in different capacities, with the more recent versions issued at 64 and 144 kilobytes (KB).
</p><p>The CAC can be used for access into computers and networks equipped with one or more of a variety of <a href="Smartcard" class="mw-redirect" title="Smartcard">smartcard</a> readers. Once inserted into the reader, the device asks the user for a PIN. Once the PIN is entered, the PIN is matched with the stored PIN on the CAC. If successful, the EDIPI number is read off the ID certificate on the card, and then sent to a processing system where the EDIPI number is matched with an access control system, such as <a href="Active_Directory" title="Active Directory">Active Directory</a> or <a href="LDAP" class="mw-redirect" title="LDAP">LDAP</a>. The DoD standard is that after three incorrect PIN attempts, the chip on the CAC will lock.
</p><p>The EDIPI number is stored in a PKI certificate. Depending on the owner, the CAC contains one or three PKI certificates. If the CAC is used for identification purposes only, an ID certificate is all that is needed. However, in order to access a computer, sign a document, or encrypt email, signature and encryption certificates are also required.
</p><p>A CAC works in virtually all modern computer operating systems. Besides the reader, drivers and middleware are also required in order to read and process a CAC. The only approved Microsoft Windows middleware for CAC is ActivClient—available only to authorized DoD personnel. Other non-Windows alternatives include LPS-Public—a non-hard drive based solution.
</p><p><a href="Defense_Information_Systems_Agency" title="Defense Information Systems Agency">DISA</a> now requires all DoD-based intranet sites to provide user authentication by way of a CAC in order to access the site. Authentication systems vary depending on the type of system, such as <a href="Active_Directory" title="Active Directory">Active Directory</a>, <a href="RADIUS" title="RADIUS">RADIUS</a>, or other <a href="Access_control_list" class="mw-redirect" title="Access control list">access control list</a>.
</p><p>CAC is based on <a href="X.509" title="X.509">X.509</a> certificates with software middleware enabling an operating system to interface with the card via a hardware card reader. Although card manufacturers such as <a href="Schlumberger" title="Schlumberger">Schlumberger</a> provided a suite of smartcard, hardware card reader and middleware for both <a href="Linux" title="Linux">Linux</a> and <a href="Microsoft_Windows" title="Microsoft Windows">Windows</a>, not all other CAC systems integrators did likewise. In an attempt to correct this situation, <a href="Apple_Inc" class="mw-redirect" title="Apple Inc">Apple</a> Federal Systems has done work for adding some support for Common Access Cards to their later Snow Leopard operating system updates out of the box using the MUSCLE (Movement for the Use of Smartcards in a Linux Environment) project. The procedure for this was documented historically by the <a href="Naval_Postgraduate_School" title="Naval Postgraduate School">Naval Postgraduate School</a> in the publication "CAC on a Mac"<sup id="cite_ref-7" class="reference"><a href="#cite_note-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup> although today the school uses commercial software. According to the independent military testers and help desks, not all cards are supported by the open source code associated with Apple's work, particularly the recent CACNG or CAC-NG PIV II CAC cards.<sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup> Third party support for CAC Cards on the Mac are available from vendors such as Centrify and <a href="Thursby_Software" class="mw-redirect" title="Thursby Software">Thursby Software</a>.<sup id="cite_ref-9" class="reference"><a href="#cite_note-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> Apple's Federal Engineering Management suggest not using the out-of-the-box support in Mac OS X 10.6 Snow Leopard<sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup> but instead supported third party solutions. Mac OS X 10.7 Lion has no native smart card support. Thursby's PKard for iOS software extends CAC support to Apple iPads and iPhones. Some work has also been done in the Linux realm. Some users are using the MUSCLE project combined with Apple's <a href="Apple_Public_Source_License" title="Apple Public Source License">Apple Public Source Licensed</a> Common Access Card software. Another approach to solve this problem, which is now well documented, involves the use of a new project, CoolKey,<sup id="cite_ref-11" class="reference"><a href="#cite_note-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup> to gain Common Access Card functionality. This document is available publicly from the <a href="Naval_Research_Laboratory" class="mw-redirect" title="Naval Research Laboratory">Naval Research Laboratory</a>'s Ocean Dynamics and Predictions Branch.<sup id="cite_ref-12" class="reference"><a href="#cite_note-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Bar_codes">Bar codes</h3></div>
<p>The CAC has two types of bar codes: <a href="PDF417" title="PDF417">PDF417</a> in the front and <a href="Code_39" title="Code 39">Code 39</a> in the rear.
</p>
<div class="mw-heading mw-heading4"><h4 id="PDF417_Sponsor_Barcode">PDF417 Sponsor Barcode</h4></div>
<table class="wikitable">
<tbody><tr>
<th>Example value
</th>
<th>Field name
</th>
<th>Size
</th>
<th>Description
</th></tr>
<tr>
<td><code>"IDUS"</code>
</td>
<td>Identification Code
</td>
<td>4
</td>
<td>Sponsor/Dependent card
</td></tr>
<tr>
<td><code>"3"</code>
</td>
<td>Bar Code Version
</td>
<td>1
</td>
<td>
</td></tr>
<tr>
<td>XX
</td>
<td>PDF417 Size
</td>
<td>2
</td>
<td>
</td></tr>
<tr>
<td>X
</td>
<td>PDF417 Checksum
</td>
<td>1
</td>
<td>
</td></tr>
<tr>
<td>X
</td>
<td>PDF417 RSize
</td>
<td>1
</td>
<td>
</td></tr>
<tr>
<td><code>"1"</code>
</td>
<td>Sponsor flag
</td>
<td>1
</td>
<td>1=Sponsor<br>0=Dependent
</td></tr>
<tr>
<td><code>"GREATHOUSE, TUYET"</code>
</td>
<td>Name
</td>
<td>27
</td>
<td>Last, First
</td></tr>
<tr>
<td><code>"999100096"</code>
</td>
<td>Person Designator Identifier
</td>
<td>9
</td>
<td>999-10-0096
</td></tr>
<tr>
<td><code>"1"</code>
</td>
<td>Family sequence number
</td>
<td>1
</td>
<td>
</td></tr>
<tr>
<td><code>" "</code>
</td>
<td>Reserved for future use
</td>
<td>9
</td>
<td>
</td></tr>
<tr>
<td><code>"00"</code>
</td>
<td>DEERS dependent suffix
</td>
<td>
</td>
<td>Sponsor v3
</td></tr>
<tr>
<td><code>"60"</code>
</td>
<td>Height (inches)
</td>
<td>2
</td>
<td>5' 0"
</td></tr>
<tr>
<td><code>"150"</code>
</td>
<td>Weight (pounds)
</td>
<td>3
</td>
<td>150 lbs
</td></tr>
<tr>
<td><code>"RD"</code>
</td>
<td>Hair Color
</td>
<td>2
</td>
<td>BK=Black<br>BR=Brown<br>BD=Blonde<br>RD=Red<br>GY=Gray<br>WH=White<br>BA=Bald<br>OT=Other
</td></tr>
<tr>
<td><code>"BR"</code>
</td>
<td>Eye Color
</td>
<td>2
</td>
<td>BK=Black<br>BR=Brown<br>HZ=Hazel<br>BL=Blue<br>GY=Gray<br>GR=Green<br>OT=Other
</td></tr>
<tr>
<td><code>"1992OCT31"</code>
</td>
<td>Date of birth
</td>
<td>9
</td>
<td>19921031
</td></tr>
<tr>
<td><code>"S"</code>
</td>
<td>Direct Care Flag
</td>
<td>1
</td>
<td>S=Unlimited
</td></tr>
<tr>
<td><code>"M"</code>
</td>
<td><a href="Tricare" title="Tricare">CHAMPUS</a> Flag
</td>
<td>1
</td>
<td>M=Civilian Health Care CHAMPUS
</td></tr>
<tr>
<td><code>"Y"</code>
</td>
<td>Comissary flag
</td>
<td>1
</td>
<td>Y=Eligible and active
</td></tr>
<tr>
<td><code>"Y"</code>
</td>
<td><a href="Morale%2C_Welfare_and_Recreation" title="Morale, Welfare and Recreation">MWR</a> flag
</td>
<td>1
</td>
<td>Y=Eligible and active
</td></tr>
<tr>
<td><code>"U"</code>
</td>
<td>Exchange flag
</td>
<td>1
</td>
<td>U=Unlimited
</td></tr>
<tr>
<td><code>"2011OCT31"</code>
</td>
<td>CHAMPUS Effective Date
</td>
<td>9
</td>
<td>20111031
</td></tr>
<tr>
<td><code>"2057SEP30"</code>
</td>
<td>CHAMPUS Expiration Date
</td>
<td>9
</td>
<td>20570930
</td></tr>
<tr>
<td><code>"2RET "</code>
</td>
<td>Form number
</td>
<td>6
</td>
<td>DD Form 2 - Retired
</td></tr>
<tr>
<td><code>"2011NOV04"</code>
</td>
<td>Card Issue Date
</td>
<td>9
</td>
<td>20111104
</td></tr>
<tr>
<td><code>"INDEF "</code>
</td>
<td>Card Expiration Date
</td>
<td>9
</td>
<td>Indefinite
</td></tr>
<tr>
<td><code>"8 "</code>
</td>
<td>Card Security Code
</td>
<td>4
</td>
<td>
</td></tr>
<tr>
<td><code>"H"</code>
</td>
<td>Service/Component Code
</td>
<td>1
</td>
<td>
</td></tr>
<tr>
<td><code>"RET "</code>
</td>
<td>Status
</td>
<td>6
</td>
<td>RET=Retired member entitled to retired pay
</td></tr>
<tr>
<td><code>"USA "</code>
</td>
<td>Branch of service
</td>
<td>5
</td>
<td>USA=U.S. Army
</td></tr>
<tr>
<td><code>"PVT "</code>
</td>
<td>Rank
</td>
<td>6
</td>
<td>PVT=Private
</td></tr>
<tr>
<td><code>"E2 "</code>
</td>
<td>Pay grade
</td>
<td>4
</td>
<td>
</td></tr>
<tr>
<td><code>"I "</code>
</td>
<td>Geneva Convention Code
</td>
<td>3
</td>
<td>
</td></tr>
<tr>
<td><code>"UNK"</code>
</td>
<td>Blood Type
</td>
<td>3
</td>
<td>
</td></tr></tbody></table>
<div class="mw-heading mw-heading4"><h4 id="PDF417_Dependent_Barcode">PDF417 Dependent Barcode</h4></div>
<table class="wikitable">
<tbody><tr>
<th>Example value
</th>
<th>Field name
</th>
<th>Size
</th>
<th>Description
</th></tr>
<tr>
<td><code>"IDUS"</code>
</td>
<td>Identification Code
</td>
<td>4
</td>
<td>Sponsor/Dependent card
</td></tr>
<tr>
<td>...
</td>
<td>...
</td>
<td>...
</td>
<td>...
</td></tr>
<tr>
<td><code>"0"</code>
</td>
<td>Sponsor flag
</td>
<td>1
</td>
<td>1=Sponsor
<p>0=Dependent
</p>
</td></tr>
<tr>
<td>...
</td>
<td>...
</td>
<td>...
</td>
<td>...
</td></tr>
<tr>
<td><code>"RET "</code>
</td>
<td>Sponsor Status
</td>
<td>6
</td>
<td>RET=Retired member entitled to retired pay
</td></tr>
<tr>
<td><code>"USA "</code>
</td>
<td>Sponsor Branch of service
</td>
<td>5
</td>
<td>USA=U.S. Army
</td></tr>
<tr>
<td><code>"PVT "</code>
</td>
<td>Sponsor Rank
</td>
<td>6
</td>
<td>PVT=Private
</td></tr>
<tr>
<td><code>"E2 "</code>
</td>
<td>Sponsor Pay grade
</td>
<td>4
</td>
<td>
</td></tr>
<tr>
<td><code>" TRUMBOLD, ERIC "</code>
</td>
<td>Sponsor Name
</td>
<td>27
</td>
<td>
</td></tr>
<tr>
<td><code>"999100096"</code>
</td>
<td>Sponsor Person Designator Identifier
</td>
<td>27
</td>
<td>
</td></tr>
<tr>
<td><code>"CH"</code>
</td>
<td>Relationship
</td>
<td>2
</td>
<td>SP=Spouse
<p>CH=Child
</p>
</td></tr></tbody></table>
<div class="mw-heading mw-heading3"><h3 id="RFID_technology">RFID technology</h3></div>
<p>There are also some security risks in RFID. To prevent theft of information in RFID, in November 2010, 2.5 million radio frequency shielding sleeves were delivered to the DoD, and another roughly 1.7 million more were to be delivered the following January 2011.<sup id="cite_ref-rfid_13-0" class="reference"><a href="#cite_note-rfid-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup> RAPIDS ID offices worldwide are required to issue a sleeve with every CAC.<sup id="cite_ref-rfid_13-1" class="reference"><a href="#cite_note-rfid-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup> When a CAC is placed in a holder along with other RFID cards, it can also cause problems, such as attempting to open a door with an access card when it is in the same holder as a CAC. Despite these challenges at least one civilian organization, NOAA, uses the RFID technology to access facilities nationwide. Access is usually granted after first removing the CAC from the RF shield and then holding it against a reader either mounted on a wall or located on a pedestal. Once the CAC is authenticated to a local security server either the door will release or a signal will be displayed to security guards to grant access to the facility.
</p>
<div class="mw-heading mw-heading2"><h2 id="Common_problems">Common problems</h2></div>
<p>The ICC is fragile and regular wear can make the card unusable. Older cards tend to de-laminate with repeated insertion/removal from readers, but this problem appears to be less significant with the newer (<a href="FIPS_201" title="FIPS 201">PIV</a>-compliant) cards. Also, the gold contacts on the ICC can become dirty and require cleaning with either <a href="Solvent" title="Solvent">solvents</a> or a rubber pencil eraser.
</p><p>Fixing or replacing a CAC typically requires access to a <a href="RAPIDS" class="mw-redirect" title="RAPIDS">RAPIDS</a> facility, causing some practical problems. In remote locations around the world without direct Internet access or physical access to a RAPIDS facility, a CAC is rendered useless if the card expires, or if the maximum number of re-tries of the PIN is reached. Based on the regulations for CAC use, a user on <a href="Temporary_duty_assignment" title="Temporary duty assignment">TAD / TDY</a> must visit a RAPIDS facility to replace or unlock a CAC, usually requiring travel to another geographical location or even returning to one's home location. The CAC PMO<sup id="cite_ref-14" class="reference"><a href="#cite_note-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup> has also created a CAC PIN Reset workstation capable of resetting a locked CAC PIN.
</p><p>For some DoD networks, <a href="Active_Directory" title="Active Directory">Active Directory</a> (AD) is used to authenticate users. Access to the computer's parent Active Directory is required when attempting to authenticate with a CAC for a given computer for the first time. Use of, for example a field-replaced laptop computer that was not prepared with the user's CAC before shipment would be impossible to use without some form of direct access to Active Directory beforehand. Other remedies include establishing contact with the intranet by using public broadband Internet and then <a href="VPN" class="mw-redirect" title="VPN">VPN</a> to the intranet, or even <a href="Satellite_Internet_access" title="Satellite Internet access">satellite Internet access</a> via a <a href="VSAT" class="mw-redirect" title="VSAT">VSAT</a> system when in locations where telecommunications is not available, such as in a natural disaster location.
</p>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1184024115">
/* start https://en.wikipedia.org/ */
.mw-parser-output .div-col{margin-top:0.3em;column-width:30em}.mw-parser-output .div-col-small{font-size:90%}.mw-parser-output .div-col-rules{column-rule:1px solid #aaa}.mw-parser-output .div-col dl,.mw-parser-output .div-col ol,.mw-parser-output .div-col ul{margin-top:0}.mw-parser-output .div-col li,.mw-parser-output .div-col dd{page-break-inside:avoid;break-inside:avoid-column}
/* end https://en.wikipedia.org/ */
</style><div class="div-col" style="column-width: 30em;">
<ul><li><a href="Access_badge" title="Access badge">Access badge</a></li>
<li><a href="Credential" title="Credential">Credential</a></li>
<li><a href="Electronic_Data_Interchange_Personal_Identifier" class="mw-redirect" title="Electronic Data Interchange Personal Identifier">Electronic Data Interchange Personal Identifier</a></li>
<li><a href="FIPS_201" title="FIPS 201">FIPS 201</a> (PIV)</li>
<li><a href="Identity_document" title="Identity document">Identity document</a></li>
<li><a href="Keycard" class="mw-redirect" title="Keycard">Keycard</a></li>
<li><a href="Magnetic_stripe_card" class="mw-redirect" title="Magnetic stripe card">Magnetic stripe card</a></li>
<li><a href="Physical_security" title="Physical security">Physical security</a></li>
<li><a href="Proximity_card" title="Proximity card">Proximity card</a></li>
<li><a href="Swipe_card" class="mw-redirect" title="Swipe card">Swipe card</a></li>
<li><a href="Transportation_Worker_Identification_Credential" title="Transportation Worker Identification Credential">Transportation Worker Identification Credential</a></li>
<li><a href="United_States_Uniformed_Services_Privilege_and_Identification_Card" title="United States Uniformed Services Privilege and Identification Card">United States Uniformed Services Privilege and Identification Card</a></li></ul></div>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */
.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}
/* end https://en.wikipedia.org/ */
</style><div class="reflist">
<div class="mw-references-wrap mw-references-columns"><ol class="references">
<li id="cite_note-DODCAC-1"><span class="mw-cite-backlink">^ <a href="#cite_ref-DODCAC_1-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-DODCAC_1-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-DODCAC_1-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */
.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}
/* end https://en.wikipedia.org/ */
</style><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.cac.mil/common-access-card/">"COMMON ACCESS CARD (CAC)"</a>. <i>US Department of Defense</i><span class="reference-accessdate">. Retrieved <span class="nowrap">18 January</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-2"><span class="mw-cite-backlink"><b><a href="#cite_ref-2">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.fbo.gov/index?s=opportunity&mode=form&id=f3933c2b8c2aaf22acb80c119e2f3a1a&tab=core&_cview=1">"Central Issuance Facility Common Access Card (CAC) Production - Federal Business Opportunities: Opportunities"</a>.</cite></span>
</li>
<li id="cite_note-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-3">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://www.defense.gov/News/News-Stories/id/63409/">DOD to Drop Social Security Numbers from ID Cards</a></span>
</li>
<li id="cite_note-2048bit-4"><span class="mw-cite-backlink">^ <a href="#cite_ref-2048bit_4-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-2048bit_4-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-2048bit_4-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFAirForceTimes" class="citation web cs1">AirForceTimes. <a rel="nofollow" class="external text" href="http://www.airforcetimes.com/news/2012/04/air-force-new-common-access-cards-coming-041512/">"404 - AirForceTimes"</a>.</cite> <span class="cs1-visible-error citation-comment"><code class="cs1-code">{{cite web}}</code>: </span><span class="cs1-visible-error citation-comment">Cite uses generic title (help)</span></span>
</li>
<li id="cite_note-5"><span class="mw-cite-backlink"><b><a href="#cite_ref-5">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.doncio.navy.mil/chips/ArticleDetails.aspx?ID=3381">"CHIPS Articles: Access Approved: Biometrics and Smart Cards Open Doors to Improved Efficiency"</a>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20140714201449/http://www.doncio.navy.mil/chips/ArticleDetails.aspx?ID=3381">Archived</a> from the original on 2014-07-14.</cite></span>
</li>
<li id="cite_note-6"><span class="mw-cite-backlink"><b><a href="#cite_ref-6">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20220319072414/https://www.cac.mil/Portals/53/Documents/Mag_Stripe_Removal.pdf?ver=2017-10-23-075808-193">"REMOVAL OF MAGNETIC STRIPE FROM DOD COMMON ACCESS CARDS"</a> <span class="cs1-format">(PDF)</span>. Archived from <a rel="nofollow" class="external text" href="https://www.cac.mil/Portals/53/Documents/Mag_Stripe_Removal.pdf?ver=2017-10-23-075808-193">the original</a> <span class="cs1-format">(PDF)</span> on 2022-03-19<span class="reference-accessdate">. Retrieved <span class="nowrap">2021-11-11</span></span>.</cite></span>
</li>
<li id="cite_note-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-7">^</a></b></span> <span class="reference-text"><cite id="CITEREFcisr" class="citation web cs1">cisr. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20060904130416/http://cisr.nps.edu/pub_techrep.html">"CISR - Publications - Technical Reports"</a>. Archived from <a rel="nofollow" class="external text" href="http://cisr.nps.edu/pub_techrep.html">the original</a> on 2006-09-04<span class="reference-accessdate">. Retrieved <span class="nowrap">2006-09-17</span></span>.</cite></span>
</li>
<li id="cite_note-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-8">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://militarycac.com/apple.htm">"MilitaryCAC's Mac OS X support landing page"</a>.</cite></span>
</li>
<li id="cite_note-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-9">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.thursby.com">"Thursby Software - Securing enterprise and personal mobility"</a>. <i>Thursby Software Systems, Inc</i>.</cite></span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><b><a href="#cite_ref-10">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20140222150253/http://lists.apple.com/archives/fed-talk/2011/Jan/msg00012.html">"Re: [Fed-Talk] Pkinit working on Snow Leopard but need forwardable TGT"</a>. Archived from <a rel="nofollow" class="external text" href="http://lists.apple.com/archives/fed-talk/2011/Jan/msg00012.html">the original</a> on 2014-02-22<span class="reference-accessdate">. Retrieved <span class="nowrap">2011-05-09</span></span>.</cite></span>
</li>
<li id="cite_note-11"><span class="mw-cite-backlink"><b><a href="#cite_ref-11">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20121126080942/http://directory.fedoraproject.org/wiki/CoolKey">"389 Directory Server (Open Source LDAP)"</a>. Archived from <a rel="nofollow" class="external text" href="https://directory.fedoraproject.org/wiki/CoolKey">the original</a> on 2012-11-26<span class="reference-accessdate">. Retrieved <span class="nowrap">2013-02-12</span></span>.</cite></span>
</li>
<li id="cite_note-12"><span class="mw-cite-backlink"><b><a href="#cite_ref-12">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www7320.nrlssc.navy.mil/pubs/2006/CommonAccessCardLinux.pdf">"Archived copy"</a> <span class="cs1-format">(PDF)</span>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20150715013503/http://www7320.nrlssc.navy.mil/pubs/2006/CommonAccessCardLinux.pdf">Archived</a> <span class="cs1-format">(PDF)</span> from the original on 2015-07-15<span class="reference-accessdate">. Retrieved <span class="nowrap">2009-09-09</span></span>.</cite><span class="cs1-maint citation-comment"><code class="cs1-code">{{cite web}}</code>: CS1 maint: archived copy as title (link)</span></span>
</li>
<li id="cite_note-rfid-13"><span class="mw-cite-backlink">^ <a href="#cite_ref-rfid_13-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-rfid_13-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.secureidnews.com/2010/11/29/defense-department-order-rf-shields-from-national-laminating">"Defense Department order RF shields from National Laminating - SecureIDNews"</a>. <i>SecureIDNews</i>.</cite></span>
</li>
<li id="cite_note-14"><span class="mw-cite-backlink"><b><a href="#cite_ref-14">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20141006135507/https://g2.cnic.navy.mil/my.policy">Navy CAC PMO</a></span>
</li>
</ol></div></div>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<ul><li><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://archive.today/20121212032736/https://www.us.army.mil/suite/akocac">"AKO CAC Reference Center"</a>. <i>us.army.mil</i>. Archived from <a rel="nofollow" class="external text" href="https://www.us.army.mil/suite/akocac">the original</a> on December 12, 2012.</cite></li>
<li><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.cac.mil/">"CAC: Common Access Card"</a>. <i>cac.mil</i>.</cite></li>
<li><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://militarycac.com/">"CAC Installation assistance and troubleshooting for your home computer or personal laptop"</a>. <i>militarycac.com</i>.</cite></li>
<li><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.dmdc.osd.mil/">"Defense Manpower Data Center"</a>. <i>dmdc.osd.mil</i>.</cite></li>
<li><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20070528004107/http://www.dmdc.osd.mil/rsl/">"RAPIDS Site Locator"</a>. <i>dmdc.osd.mil</i>. Archived from <a rel="nofollow" class="external text" href="http://www.dmdc.osd.mil/rsl">the original</a> on 2007-05-28<span class="reference-accessdate">. Retrieved <span class="nowrap">2007-05-30</span></span>.</cite></li></ul>
</div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-04-16" href="https://en.wikipedia.org/wiki/?title=Common_Access_Card&oldid=1285836388">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
</body></html>