Turn on debug logging with HKLM\SOFTWARE\Aloaha\pdf\debug = 1 (on 64-bit Windows under WOW6432Node), reproduce the problem and read C:\Windows\Logs\CodeBProvider\. Test the tile without signing out with CredentialProviderInstaller.exe /test. Send the log files to info@codeb.io if you need help.
First checks
- Is the provider installed and licensed? Run the installer again with
/installand check the licence inSmartLoginLicensing.exe. - Does the token work outside the logon screen? Open the linking tool (for example
LinkNFCCard.exe) and check that the card serial appears. - Was the Windows password changed after the token was linked? Then link again or use
/changepw(see password changes). - Test without signing out:
CredentialProviderInstaller.exe /test.
Debug logging and log files
Logging is off by default. To turn it on, set this value (string or DWORD) and open the logon screen again:
:: 64-bit Windows (32-bit registry view)
reg add "HKLM\SOFTWARE\WOW6432Node\Aloaha\pdf" /v debug /t REG_SZ /d 1 /f
:: turn it off again
reg add "HKLM\SOFTWARE\WOW6432Node\Aloaha\pdf" /v debug /t REG_SZ /d 0 /f
| Where | What |
|---|---|
C:\Windows\Logs\CodeBProvider\CodeBProvider-YYYY-MM-DD.log | The credential provider: tiles, fields, token events, logon result. One file per day, kept for 14 days. |
C:\Windows\Logs\CodeBProvider\aLog-<number>.txt | The helper libraries of one process: card reader, AD and domain-controller checks, TOTP, certificates. The lines show process (P), session (S) and thread (T). |
Event Viewer → Windows Logs → Application, source CodeB Credential Provider V2 | Card-removal actions (“Card was removed”, “Do Action was called”). |
Useful lines when reading a provider log: ReportResult ntsStatus: 0 means Windows accepted the logon; Found user on smartcard / Found user on usb stick show which token matched; Cards with serials found: 0 means no card was seen.
Debug logs contain user names, card serials and other account details. Switch logging off when you are done and delete old logs you no longer need.
The CodeB tile does not appear
- Install again as administrator:
CredentialProviderInstaller.exe /install. Edition 1: startcodeb_tray.exeonce with Run as administrator. - Only one tile per user is shown when the user is already selected; click Sign-in options or Other user to see all providers.
- Check
HideExtraTileand the filter values in the registry. - Check that the .NET Framework 4.7.2 or later is installed.
The card is not detected at the logon screen
- Check the reader in
LinkNFCCard.exe: if the serial does not appear there, it is a reader, driver or card problem, not a logon problem. - The Windows service Smart Card (
SCardSvr) must run. Windows stops it when the last reader is removed; current builds re-connect automatically when it restarts. - Several readers (for example a contact and a contactless one on the same device): the contactless one is used for NFC cards. Virtual readers are skipped.
- Lifting the card too fast: raise
DelayCardRemovalEventSEC(default 10 seconds) a little. If you need very long values, look for the real cause (reader driver, cold-boot timing). - In the provider log, look for
Card readers attachedorNo card reader found.
Remote Desktop
- Enable smart card redirection in the RDP client (Local Resources → More → Smart cards, or
redirectsmartcards:i:1in the .rdp file). The reader must be connected to the client PC. - A redirected reader can appear a few seconds after the logon screen, especially after a quick disconnect and reconnect. Current builds keep checking every 2 seconds for up to 10 minutes and pick it up; the log shows
Card reader appeared after … s. With older builds, wait a moment and reconnect. - The removal action lock (
1) disconnects an RDP session; that is expected. - Do not use
RestartSmartCardServiceIfNoReaderDetectedwith Remote Desktop.
The token is found but the logon fails
- Most often the Windows password changed after linking. Link again, or use
CodeBAdminCLI.exe /changepwfor AD tokens. WithShowWrongPasswordDialog = 1(default) the user sees a message. - Wrong card PIN: the PIN typed on the tile must match the one set when linking (empty = default PIN
0000, seeDefaultSerialPIN). - Token created on another PC: shared tokens need the shared certificates (
/cert) on every PC. - Account locked or disabled in AD: Windows reports it as for a typed password.
TOTP codes are rejected
- TOTP depends on the clock. Check the time and time zone of the PC and the phone. At the logon screen type
timein the password or PIN field to open the time dialog (unless keywords are disabled). - Digits and algorithm in
LinkTOTPmust match the app; most apps only support 6 digits with SHA-1.
Offline laptops and slow logon
On domain PCs CodeB checks in the background whether a domain controller is reachable and remembers the answer (5 minutes when reachable, 30 seconds when not). When the domain is offline, AD lookups are skipped and Windows logs on with its cached credentials, so an offline logon is not delayed. The log line DC reachable = False shows this state.
The first logon of a user on a PC always needs the domain controller, as with any Windows logon.
Active Directory storage problems
LinkNFCCardwarns that it cannot write: grant read/write onaltSecurityIdentitiesto Domain Computers (see storage).- Card works on one PC only: check
Use_AD_altSecurityIdentities = 1on the other PCs and the shared certificates. - Find out which user a card belongs to:
CodeBAdminCLI.exe /list2fa /serial <UID>.
Locked out after hiding the password tile
- Log on with a token-enabled administrator account, or with an account listed under
Filter\UserExceptions. - Remotely: set the filter value
HKLM\SOFTWARE\Aloaha\CP\<CLSID>back to0with the remote registry or PowerShell remoting.
Getting support
Email info@codeb.io (or info@aloaha.com) with:
- what you did, what you expected and what happened, with the time of the attempt;
- the files from
C:\Windows\Logs\CodeBProvider\of that day (debug logging on); - the Windows version, the card reader model and whether the logon was local or over Remote Desktop.
Email support is included with every licence. More answers are on the support & FAQ page.
Frequently asked questions
Where are the CodeB log files?
With debug logging on (HKLM\SOFTWARE\Aloaha\pdf\debug = 1, 32-bit view), in C:\Windows\Logs\CodeBProvider\: one CodeBProvider-YYYY-MM-DD.log per day and one aLog-….txt per process. Card-removal actions are also recorded in the Windows Application event log (source CodeB Credential Provider V2).
Can I test the logon tile without signing out?
Yes: run CredentialProviderInstaller.exe /test or click Test Credential Provider. A Windows credential prompt with the CodeB tile opens.
Does card logon work over Remote Desktop?
Yes, when the RDP client redirects the smart card reader (Local devices and resources → Smart cards). The redirected reader can appear a few seconds after the logon screen; current builds keep looking for it. A lock removal action disconnects the RDP session.