Overview This document contains instructions for resolving problems when logging in to TAMIS using your Common Access Card (CAC). Unable to Select CAC Certificate After Clicking the Log in to TAMIS Button: After accepting the terms and conditions of the Privacy and Security Notice and clicking the Log in to TAMIS button, TAMIS bypasses the Select a Certificate dialog box, and you are taken directly to the TAMIS Login screen where you enter your TAMIS Username and Password. Because of this, you cannot select your CAC certificate or enter your PIN. Access Denied After Clicking the Log in to TAMIS Button: After accepting the terms and conditions of the Privacy and Security Notice and clicking the Log in to TAMIS button, you received an access denied error. Access Denied Prior to Entering CAC PIN: When logging in to TAMIS using your CAC, you received an access denied error after selecting your CAC certificate, but prior to entering your PIN. Access Denied After Entering CAC PIN: When logging in to TAMIS using your CAC, you received an access denied error after entering your CAC PIN. This problem is caused by the DoD Root Certificate Chaining Problem. Two solutions are available: o o The TAMIS instructions guide you through a manual fix to help you resolve the problem now. The DISA instructions offer guidance for using the Federal Bridge Certification Authority (FBCA) Cross-Certificate Removal Tool to resolve the problem. If you keep experiencing this problem, these instructions are highly recommended. Unclassified/For Official Use Only Page 1 of 7 July 25, 2014
Unable to Select CAC Certificate After Clicking the Log in to TAMIS Button After accepting the terms and conditions of the Privacy and Security Notice and clicking the Log in to TAMIS button, TAMIS bypasses the Select a Certificate dialog box, and you are taken directly to the TAMIS Login screen where you enter your TAMIS Username and Password. Because of this, you cannot select your CAC certificate or enter your PIN. What Causes this This problem is caused by a caching issue with Internet Explorer and may happen if your first, initial login was with your TAMIS username and password rather than with your CAC. How to Resolve the 1. Close ALL Internet Explorer windows and tabs. 2. Close ALL email programs (e.g. Outlook, Pegasus, Eudora, etc.). 3. Re-open Internet Explorer. 4. Log in to TAMIS using your CAC. Access Denied After Clicking the Log in to TAMIS Button After accepting the terms and conditions of the Privacy and Security Notice and clicking the Log in to TAMIS button, you received an access denied error. What Causes this This problem can be caused by any of the following issues: Caching Issue The caching issue happens with Internet Explorer and may occur if your previous login attempts were cancelled or abruptly negated. Wrong CAC Certificate Selected This happens when the wrong CAC certificate was selected during the TAMIS Login process. Incorrect CAC Certificate Path This happens when there is a problem with the CAC certificate path on your computer due to the DoD Root Certificate Chaining Problem. How to Resolve the 1. To resolve the caching issue: a. Close ALL Internet Explorer windows and tabs. b. Close ALL email programs (e.g. Outlook, Pegasus, Eudora, etc.). c. Re-open Internet Explorer. d. Log in to TAMIS using your CAC. e. If you are still receiving the access denied error, continue to Step 2. Unclassified/For Official Use Only Page 2 of 7 July 25, 2014
2. To resolve the wrong CAC certificate selected issue: a. Go to Access Denied Prior to Entering CAC PIN and follow the instructions in this section. b. If you are still receiving the access denied error, continue to Step 3. 3. To resolve the CAC certificate path issue, go to Access Denied After Entering CAC PIN and follow the instructions in this section. Access Denied Prior to Entering CAC PIN When logging in to TAMIS using your CAC, you received an access denied error after selecting your CAC certificate, but prior to entering your PIN. What Causes this This error happens when the wrong CAC certificate was selected during the TAMIS Login process. How to Resolve the When selecting the CAC certificate, make sure that you select the DoD certificate. DO NOT select the DoD Email certificate. Select this DoD Certificate. Do not select this DoD Email Certificate. Access Denied After Entering CAC PIN When logging in to TAMIS using your CAC, you received an access denied error after entering your CAC PIN. What Causes this This error happens when there is a problem with the CAC certificate path on your computer due to the DoD Root Certificate Chaining Problem. Unclassified/For Official Use Only Page 3 of 7 July 25, 2014
How to Verify the First, log in to TAMIS to ensure that you receive the access denied error related to this problem. 1. Go to https://tamis.army.mil. 2. Check the I accept box. 3. Click the Log in to TAMIS button. 4. Select your CAC Certificate. 5. Enter the PIN associated with your CAC. 6. The Access Denied screen displays. Second, verify the certificate path for your CAC. 1. Open Internet Explorer. 2. Select Tools > Internet Options. 3. On the Internet Options dialog box, select the Content tab. 4. Click on the Certificates button. 5. Click on the Personal tab. 6. Select and double-click on your DoD Root Certificate (DoD CA). Do NOT select the DoD Email certificate. 7. On the Certificate dialog box, click the Certification Path tab. 8. If your DoD Root Certificate has several other certificates above DoD Root CA 2 (as seen in the screenshot below), then you will need to remove these certificates before you can successfully log in to TAMIS. Unclassified/For Official Use Only Page 4 of 7 July 25, 2014
How to Resolve the If your DoD Root Certificate has several other certificates above it, follow these steps to remove them. 1. Open Internet Explorer. 2. Select Tools > Internet Options. 3. On the Internet Options dialog box, select the Content tab. 4. Click on the Certificates button. 5. Click on the Trusted Root Certificate tab, and then select and remove the following certificate: a. In the certificate list, click on and select the Common Policy certificate. Next, click on the Remove button, and then click Yes to confirm. b. If you are unable to remove the Common Policy certificate, continue to Step 6. Removing the certificates in Step 6 may resolve this issue. Note: After the certificates in Step 6 have been removed, return to this step and try to remove the Common Policy certificate again. If the issue is not resolved, your system administrator will need to complete this procedure for you. Important: If the Remove button is disabled, then you are not an administrator for your computer. If necessary, please contact your system administrator and have them perform this procedure for you. Unclassified/For Official Use Only Page 5 of 7 July 25, 2014
6. Click on the Intermediate Certification Authorities tab, and then select and remove the following certificates: a. In the certificate list, click on and select the SHA-1 Federal Root CA certificate. Next, click on the Remove button, and then click Yes to confirm. b. In the certificate list, click on and select the DoD Interoperability Root CA 1 certificate. Next, click on the Remove button, and then click Yes to confirm. c. In the certificate list, click on and select the Common Policy certificate. Next, click on the Remove button, and then click Yes to confirm. d. In the certificate list, click on and select the DoD Root CA 2 certificate. Next, click on the Remove button, and then click Yes to confirm. Tip: You can select all of the certificates at one time by holding down the [Ctrl] key, and then clicking on each of the certificates. Important: If the Remove button is disabled, then you are not an administrator for your computer. If necessary, please contact your system administrator and have them perform this procedure for you. 7. If you were unable to remove the Common Policy certificate on the Trusted Root Certificate tab in Step 5, return to that step and try again. If the issue is not resolved, your system administrator will need to complete this procedure for you. 8. Click on the Close button. 9. Click on the OK button. 10. Close Internet Explorer. 11. Reopen Internet Explorer and confirm that the path is now correct. a. Select Tools > Internet Options. b. On the Internet Options dialog box, select the Content tab. c. Click on the Certificates button. d. Click on the Personal tab. e. Select and double-click on your DoD Root Certificate. f. On the Certificate dialog box, click the Certification Path tab. Your DoD Root Certificate path should look similar to the one below (see screenshot). Unclassified/For Official Use Only Page 6 of 7 July 25, 2014
What to do if the Problem Continues: If the problem persists, make sure that the DoD Root Certificates are available and installed on your computer. For assistance, please contact your system administrator. In addition, the DISA instructions offer guidance for using the Federal Bridge Certification Authority (FBCA) Cross-Certificate Removal Tool to resolve the problem. For details, refer to the DoD Root Certificate Chaining Problem document: http://iase.disa.mil/pki-pke/getting_started/downloads/unclass-faq_dod_root_cert_chaining_issue.pdf Note: If you are still experiencing problems after following the instructions in this document, please contact TAMIS Support: Email: tamis.support@hp.com Phone: 1-855-752-8111 Unclassified/For Official Use Only Page 7 of 7 July 25, 2014