Cardinal Key Troubleshooting User Guide
If you are having an issue with Cardinal Key, we encourage you to read through the following recommendations before submitting a Help request.
Firefox troubleshooting
Quick fix for Firefox browsers
If you already have Cardinal Key installed and it has suddenly stopped working, try the following:
- Ensure you are running at least version 75 (if not, upgrade to the latest version).
- Ensure that “security.osclientcerts.autoload” is set to True in about:config.
- See instructions at https://uit.stanford.edu/service/cardinalkey/install_mac or https://uit.stanford.edu/service/cardinalkey/install_windows for additional configuration steps.
- Test via the Cardinal Key test page: https://cardinalkey-test.stanford.edu.
Cardinal Key not working on Firefox
If Cardinal Key isn't working in the Firefox browser, launch Firefox and take the following steps:
- Go to settings (three horizontal lines at the upper right corner of the browser window)
- In the search window, search for Certificates and select "View Certificate”
- In the pop-up window, select the "authentication decisions" tab
- See if login.stanford.edu has a setting of "send no client certificate," and if so, highlight and delete it
- Close and relaunch Firefox
Confirm Cardinal Key is installed on your device
IMPORTANT: Do not reinstall Cardinal Key as a troubleshooting method (unless you’ve confirmed there are no valid Cardinal Keys installed on the device).
Follow the instructions for your device to confirm that Cardinal Key is installed:
- Mac: Finder → Applications → Utilities → Keychain Access. Check “My Certificates” and “Keys.”
- Windows: Start menu → Run → Type certmgr in the Run box → Select Manage User Certificates → A window will appear → Select Personal and drill down the Certificates → If the Cardinal Key exists on the machine, you should see something listed with {sunetid}/Enrollment.
If you find multiple Cardinal Keys installed, we encourage you to keep a single valid Cardinal Key and delete the rest.
Standard installation steps
- Ensure that the device is in MyDevices and shows as compliant. If not, follow setup instructions at https://encrypt.stanford.edu.
- Download a Cardinal Key via https://cardinalkey.stanford.edu. You need to install a unique Cardinal Key for each device (Cardinal Keys uniquely identify a device). Ensure that you are logged into the correct profile on the local machine.
- The new Cardinal Key will not show up in MyDevices right away. This is OK — a new Cardinal Key can be used for a grace period of 48 hours (even if the device is not yet compliant).
Troubleshooting steps
- Confirm that the device is in MyDevices and showing as compliant (searching by SUNet ID is fastest). If unsure, confirm the device’s serial number against the info in MyDevices.
- Confirm that the device has checked in via BigFix/MDM sometime within the past 24 hours.
- Confirm that Cardinal Key(s) for that device have not been revoked.
- On the device in question, confirm the Cardinal Key is properly installed:
- Mac: Finder → Applications → Utilities → Keychain Access. Check “My Certificates” and “Keys.”
- Windows: certmgr
- Go to "Type here to search" → Run
- Type certmgr in the Run box
- Select Manage User Certificates
- A window will appear
- On the left-hand column, select Personal and drill down to the Certificates
- If the Cardinal Key exists on the machine, you should see something listed with {sunetid}/Enrollment-*
- iOS: Settings → General → Profiles & Device Management → Stanford Client Configuration → More Details → Confirm that {SUNetID}/Enrollment-xxx is listed under the certificates.
- Note: If Cardinal Key shows This certificate has expired or is not yet valid, ensure the local computer’s date/time is accurate.
- Check to see what Cardinal Key(s) is/are listed in MyDevices for the device.
- If the Cardinal Key listed matches the certificate in Step 4 and the status is revoked, then you will need to get a new Cardinal Key.
- If the Cardinal Key listed matches the certificate in Step 4 and the status is OK, you are good to go.
- If there are multiple Cardinal Keys, you will want to make sure that the ones(s) that have OK statuses exist on your machine.
- If no Cardinal Key is showing, ensure that you are logged into the same profile where the Cardinal Key was installed.
- Restart the browser.
- Test via the Cardinal Key test page: https://cardinalkey-test.stanford.edu.
- When trying to access [drive.google.com|axess.stanford.edu|webmail.stanford], it should either:
- Log directly into the site, or
- You'll be prompted to choose a certificate. Make sure you choose the one that does not have a revoked status in MyDevices.
- If all else fails, temporarily request to be added to the Cardinal Key exemption list.
