PayloadKit

SmartCard

com.apple.security.smartcard

The payload that configures a smart card.

macOS 10.12.4+
Apple schemaexclusive

Not available with User Enrollment · Only one instance per profile · macOS: device channel only

Configuration Keys (7)

KeyTypeTitle
allowSmartCard

If 'false', the system disables smart cards for logins, authorizations, and screen saver unlocking. It's still allowed for other functions, such as signing emails and accessing the web. The device requires a restart for a setting change to take effect.

Default: true

booleanAllow SmartCard
allowUnmappedUsers

If set to integer 1, allows users who aren't paired with a smart card to log in with password.

Range: Disallow (0), Allow (1)

integerAllow Unmapped Users
UserPairing

If 'false', users don't get the pairing dialog, although existing pairings still work.

Default: true

booleanUser Pairing
oneCardPerUser

If 'true', a user can pair with only one smart card, although existing pairings are allowed if already set up.

Default: false

booleanRestrict One Card Per User
checkCertificateTrust

Configures the certificate trust check and has one of the following possible values: '0': Turns off certificate trust check. '1': Turns on certificate trust check. The device performs a standard validity check but doesn't include additional revocation checks. '2': Turns on certificate trust check. The device also performs a soft revocation check. Until CRL/OCSP explicitly rejects the certificate, the device considers it valid. This setting means that unavailable or unreachable CRL/OCSP allow this check to succeed. '3': Turns on certificate trust check. The device also performs a hard revocation check. Unless CRL/OCSP explicitly says "This certificate is OK," the device considers it invalid. This option is the most secure.

Default: 0

Range: Off (0), On (1), On & revocation check is set to the soft level (2), On & revocation check is set to the hard level (3)

integerCertificate Trust Validation
enforceSmartCard

macOS 10.13.2+

If 'true', a user can only log in or authenticate with a smart card.

Default: false

booleanRequire SmartCard
tokenRemovalAction

macOS 10.13.4+

If '1', the device enables the screen saver when the user removes the smart card.

Default: 0

Range: 0, 1

integerEnable Screen Saver on Removal