Troubleshooting & logs.

Turn on debug logging, find the log files and solve the common problems: missing tile, card not detected, Remote Desktop, failed token logon, TOTP time drift, offline laptops and lock-outs.

CodeB Credential Provider V2 · User manual · Updated 2026-09-30

In short

Turn on debug logging with HKLM\SOFTWARE\Aloaha\pdf\debug = 1 (on 64-bit Windows under WOW6432Node), reproduce the problem and read C:\Windows\Logs\CodeBProvider\. Test the tile without signing out with CredentialProviderInstaller.exe /test. Send the log files to info@codeb.io if you need help.

First checks

  1. Is the provider installed and licensed? Run the installer again with /install and check the licence in SmartLoginLicensing.exe.
  2. Does the token work outside the logon screen? Open the linking tool (for example LinkNFCCard.exe) and check that the card serial appears.
  3. Was the Windows password changed after the token was linked? Then link again or use /changepw (see password changes).
  4. Test without signing out: CredentialProviderInstaller.exe /test.

Debug logging and log files

Logging is off by default. To turn it on, set this value (string or DWORD) and open the logon screen again:

:: 64-bit Windows (32-bit registry view)
reg add "HKLM\SOFTWARE\WOW6432Node\Aloaha\pdf" /v debug /t REG_SZ /d 1 /f

:: turn it off again
reg add "HKLM\SOFTWARE\WOW6432Node\Aloaha\pdf" /v debug /t REG_SZ /d 0 /f
WhereWhat
C:\Windows\Logs\CodeBProvider\CodeBProvider-YYYY-MM-DD.logThe credential provider: tiles, fields, token events, logon result. One file per day, kept for 14 days.
C:\Windows\Logs\CodeBProvider\aLog-<number>.txtThe helper libraries of one process: card reader, AD and domain-controller checks, TOTP, certificates. The lines show process (P), session (S) and thread (T).
Event Viewer → Windows Logs → Application, source CodeB Credential Provider V2Card-removal actions (“Card was removed”, “Do Action was called”).

Useful lines when reading a provider log: ReportResult ntsStatus: 0 means Windows accepted the logon; Found user on smartcard / Found user on usb stick show which token matched; Cards with serials found: 0 means no card was seen.

Privacy

Debug logs contain user names, card serials and other account details. Switch logging off when you are done and delete old logs you no longer need.

The CodeB tile does not appear

  • Install again as administrator: CredentialProviderInstaller.exe /install. Edition 1: start codeb_tray.exe once with Run as administrator.
  • Only one tile per user is shown when the user is already selected; click Sign-in options or Other user to see all providers.
  • Check HideExtraTile and the filter values in the registry.
  • Check that the .NET Framework 4.7.2 or later is installed.

The card is not detected at the logon screen

  • Check the reader in LinkNFCCard.exe: if the serial does not appear there, it is a reader, driver or card problem, not a logon problem.
  • The Windows service Smart Card (SCardSvr) must run. Windows stops it when the last reader is removed; current builds re-connect automatically when it restarts.
  • Several readers (for example a contact and a contactless one on the same device): the contactless one is used for NFC cards. Virtual readers are skipped.
  • Lifting the card too fast: raise DelayCardRemovalEventSEC (default 10 seconds) a little. If you need very long values, look for the real cause (reader driver, cold-boot timing).
  • In the provider log, look for Card readers attached or No card reader found.

Remote Desktop

  • Enable smart card redirection in the RDP client (Local Resources → More → Smart cards, or redirectsmartcards:i:1 in the .rdp file). The reader must be connected to the client PC.
  • A redirected reader can appear a few seconds after the logon screen, especially after a quick disconnect and reconnect. Current builds keep checking every 2 seconds for up to 10 minutes and pick it up; the log shows Card reader appeared after … s. With older builds, wait a moment and reconnect.
  • The removal action lock (1) disconnects an RDP session; that is expected.
  • Do not use RestartSmartCardServiceIfNoReaderDetected with Remote Desktop.

The token is found but the logon fails

  • Most often the Windows password changed after linking. Link again, or use CodeBAdminCLI.exe /changepw for AD tokens. With ShowWrongPasswordDialog = 1 (default) the user sees a message.
  • Wrong card PIN: the PIN typed on the tile must match the one set when linking (empty = default PIN 0000, see DefaultSerialPIN).
  • Token created on another PC: shared tokens need the shared certificates (/cert) on every PC.
  • Account locked or disabled in AD: Windows reports it as for a typed password.

TOTP codes are rejected

  • TOTP depends on the clock. Check the time and time zone of the PC and the phone. At the logon screen type time in the password or PIN field to open the time dialog (unless keywords are disabled).
  • Digits and algorithm in LinkTOTP must match the app; most apps only support 6 digits with SHA-1.

Offline laptops and slow logon

On domain PCs CodeB checks in the background whether a domain controller is reachable and remembers the answer (5 minutes when reachable, 30 seconds when not). When the domain is offline, AD lookups are skipped and Windows logs on with its cached credentials, so an offline logon is not delayed. The log line DC reachable = False shows this state.

The first logon of a user on a PC always needs the domain controller, as with any Windows logon.

Locked out after hiding the password tile

  • Log on with a token-enabled administrator account, or with an account listed under Filter\UserExceptions.
  • Remotely: set the filter value HKLM\SOFTWARE\Aloaha\CP\<CLSID> back to 0 with the remote registry or PowerShell remoting.

Getting support

Email info@codeb.io (or info@aloaha.com) with:

  • what you did, what you expected and what happened, with the time of the attempt;
  • the files from C:\Windows\Logs\CodeBProvider\ of that day (debug logging on);
  • the Windows version, the card reader model and whether the logon was local or over Remote Desktop.

Email support is included with every licence. More answers are on the support & FAQ page.

Frequently asked questions

Where are the CodeB log files?

With debug logging on (HKLM\SOFTWARE\Aloaha\pdf\debug = 1, 32-bit view), in C:\Windows\Logs\CodeBProvider\: one CodeBProvider-YYYY-MM-DD.log per day and one aLog-….txt per process. Card-removal actions are also recorded in the Windows Application event log (source CodeB Credential Provider V2).

Can I test the logon tile without signing out?

Yes: run CredentialProviderInstaller.exe /test or click Test Credential Provider. A Windows credential prompt with the CodeB tile opens.

Does card logon work over Remote Desktop?

Yes, when the RDP client redirects the smart card reader (Local devices and resources → Smart cards). The redirected reader can appear a few seconds after the logon screen; current builds keep looking for it. A lock removal action disconnects the RDP session.

Stuck on a step?

A real engineer reads every support email. Send the log files from the troubleshooting chapter and we usually answer within one business day.