Our OMNIKEY case
With a tested HID OMNIKEY 3021/3121 setup, the card, BOK and certificates worked, but C_Sign failed. Windows required the correct Windows Update driver; on our Linux setup no suitable combination was found. Another compatible CCID reader solved the issue. This is one hardware/software case, not a claim that every OMNIKEY reader is incompatible.
What to look for
Choose a contact ISO/IEC 7816 reader with USB CCID, PC/SC, T=0/T=1 and explicit operating-system support. On Linux verify libccid support. Prefer a precise model from the official Slovak eID tested-reader list.
Why login may still work
Identity reading and certificate listing use a different command flow than PKCS#11 C_Sign. A reader problem may therefore become visible only when the card creates a signature.