Xerox AltaLink B8045, AltaLink B8055, AltaLink B8065, AltaLink B8075, AltaLink B8090 CONFIGURATION GUIDE

Version 3.0 December 2020 702P08579
Xerox
®
AltaLink
®
Series Smart Card
Installation and Configuration Guide
©2020 Xerox Corporation. All rights reserved. Xerox®, Xerox and Design®, AltaLink®, WorkCentre®, FreeFlow®, SMARTsend®, Scan to PC Desktop Interface Platform
®
, MeterAssistant®, SuppliesAssistant®, Xerox Secure Access Unified ID System®, Xerox Extensible
®
, Global Print Driver®, and Mobile Express Driver®are trademarks of Xerox Corporation in the United
States and/or other countries.
®
Adobe
, Adobe PDF logo, Adobe®Reader®, Adobe®Type Manager®, ATM™, Flash®, Macromedia®, Photoshop®, and
PostScript
Apple OS
HP-GL
®
are trademarks or registered trademarks of Adobe Systems, Inc.
®
, Bonjour®, EtherTalk™, TrueType®, iPad®, iPhone®, iPod®, iPod touch®, AirPrint®and the AirPrint Logo®, Mac®, Mac
®
, and Macintosh®are trademarks or registered trademarks of Apple Inc. in the U.S. and other countries.
®
, HP-UX®, and PCL®are registered trademarks of Hewlett-Packard Corporation in the United States and/or other
countries.
Microsoft
®
, Windows Vista®, Windows®, Windows Server®, and OneDrive®are registered trademarks of Microsoft
Corporation in the United States and other countries.
Wi-Fi CERTIFIED Wi-Fi Direct
®
is a trademark of the Wi-Fi Alliance.
Table of Contents
1 Introduction...............................................................................................................................5
Introduction .............. ..... ..... ...................... ..... ...................... ..... ..... ...................... ..... ..... ......... 6
Supported Printers ................. ..... ...................... ..... ..... ...................... ..... ..... ................. ..... . 6
Minimum Software Levels . ..... ...................... ..... ..... ..... ............ ..... ..... ..... ..... ............ ..... ..... . 6
Smart Card Feature Overview .......... ..... ..... ..... ................. ..... ..... ...................... ..... .................... 7
Authentication... ..... ..... ................. ..... ..... ..... ................. ..... ..... ..... ................. ..... ..... ........... 7
Hold All Jobs ... ..... ..... ............ ..... ..... ..... ................. ..... ..... ..... ...................... ..... ................... 7
Email Signing and Encryption........ ..... ..... ..... ................. ..... ..... ..... ................. ..... ..... ........... 7
Supported Card Readers... ...................... ..... ..... ................. ..... ..... ..... ................. ..... ..... ..... .. 8
Supported Card Types.... ..... ...................... ..... ..... ................. ..... ..... ..... ................. ..... ..... .... 8
Documentation and Support.. ..... ...................... ..... ..... ...................... ..... ...................... ..... ..... .. 9
2 Preparation...............................................................................................................................11
Preparation Overview ..... ..... ..... ..... ................. ..... ..... ..... ................. ..... ..... ...................... ..... ... 12
Configuration Checklist . ..... ................. ..... ..... ...................... ..... ...................... ..... ..... .............. 13
3 Installation...............................................................................................................................15
Installation Overview ............... ..... ..... ..... ................. ..... ..... ..... ................. ..... ..... ..... ............... 16
Hardware Installation ... ..... ................. ..... ..... ...................... ..... ........................... ..... .............. 17
Connect the USB Smart Card Reader to the Printer . ..... ...................... ..... ...................... ... 17
Software Configuration....... ..... ..... ................. ..... ..... ..... ................. ..... ..... ..... ................. ..... ... 20
Accessing Administration and Configuration Settings.... ..... ..... ...................... ..... .............. 20
Enter the Smart Card Enablement Key ..... ..... ..... ..... ................. ..... ..... ...................... ..... ... 20
Configuring the Smart Card ........ ..... ..... ..... ..... ............ ..... ..... ..... ...................... ..... ................. 23
Configure Smart Card Authentication ....................... ..... ...................... ..... ..... ................. . 23
Enable NTP Service . ..... ...................... ..... ..... ...................... ..... ..... ................. ..... ..... ..... .... 25
Configure Alternate Authentication ..... ..... ................. ..... ..... ..... ................. ..... ..... ..... ....... 26
Certificate Validation ..... ..... ..... ..... ..... ............ ..... ..... ..... ................. ..... ..... ..... ................... 28
Configure Transport Layer Security (TLS)...... ..... ..... ..... ............ ..... ..... ..... ..... ............ ..... .... 32
Configure Certificate Validation.. ..... ..... ................. ..... ..... ...................... ..... ..................... 33
Configure Smart Card Inactivity Timer.. ................. ..... ..... ..... ................. ..... ..... ................ 35
Configure Acquiring Logged-In Email Addresses for Users . ..... ..... ...................... ..... .......... 36
Printing Features................ ..... ..... ...................... ..... ..... ..... ............ ..... ..... ..... ................. ..... .... 54
Configure Hold All Jobs ................. ..... ..... ...................... ..... ........................... ..... .............. 54
Configure Secure Print Driver Defaults.......................... ..... ...................... ..... ..... ............... 55
Configure the Print Driver..... ..... ...................... ..... ...................... ..... ..... ...................... ..... . 57
Confirm the Installation.. ..... ...................... ..... ...................... ..... ..... ...................... ..... ..... ....... 60
Using the Smart Card........ ..... ........................... ..... ...................... ..... ..... ................. ..... ..... ..... 61
4 Troubleshooting......................................................................................................................63
Xerox®AltaLink®Series Smart Card
Installation and Configuration Guide
3
Table of Contents
Troubleshooting.................... ..... ...................... ..... ...................... ..... ..... ..... ............ ..... ..... ..... . 64
Fault Clearance ........................... ..... ...................... ..... ..... ................. ..... ..... ..... ................. ..... 65
Locating the Serial Number. ..... ..... ..... ............ ..... ..... ..... ..... ............ ..... ..... ..... ................... 65
Troubleshooting Tips... ..... ..... ................. ..... ..... ..... ................. ..... ..... ..... ................. ..... ..... ...... 66
During Installation... ..... ..... ..... ................. ..... ..... ...................... ..... ...................... ..... ..... ... 66
After Installation ............... ..... ..... ...................... ..... ........................... ..... ...................... ... 66
4
Xerox®AltaLink®Series Smart Card Installation and Configuration Guide
1

Introduction

This chapter contains:
Introduction ................. ..... ..... ...................... ..... ...................... ..... ..... ...................... ..... ..... ..... ..... 6
Smart Card Feature Overview . ................. ..... ..... ...................... ..... ...................... ..... ..... ................ 7
Documentation and Support ..... ..... ........................... ........................... ..... ..... ................. ..... ..... ... 9
Xerox®AltaLink®Series Smart Card
Installation and Configuration Guide
5

Introduction

Introduction
The Smart Card solution brings an advanced level of security to sensitive information. Organizations can restrict access to the walk-up features of a Xerox
®
multifunction printer. This practice ensures that
only authorized users are able to print, copy, scan, email, and fax information.
After validation, you are logged in to the Xerox
®
printer for all walk-up features. For added security,
the functions are tracked.
This guide explains how to install and configure the Smart Card solution. The guide identifies the resources and equipment required for a successful installation.
Note: Depending on the printer model and software version you are using, the configuration
instructions can vary.
For more information, contact your local Xerox Representative.
SSuuppppoorrtteedd PPrriinntteerrss
Xerox®AltaLink®Series B8045/8055/8065/8075/8090 Multifunction Printers
Xerox
Xerox
Xerox
Xerox
®
AltaLink®Series C8030/8035/8045/8055/8070 Multifunction Printers
®
WorkCentre®EC7856/7836 Multifunction Printers
®
AltaLink®B8145/B8155/B8170 Multifunction Printers
®
AltaLink®C8130/C8135/C8145/C8155/C8170 Multifunction Printers
MMiinniimmuumm SSooffttwwaarree LLeevveellss
Printer Minimum Printer Software Version
Xerox®AltaLink®B8045/8055/8065/8075/8090 Multifunction Printer
®
Xerox Multifunction Printer
Xerox Multifunction Printer
Xerox C8170 Multifunction Printer
Xerox Printer
AltaLink®C8030/8035/8045/8055/8070
®
AltaLink®B8145/B8155/B8170
®
AltaLink®C8130/C8135/C8145/C8155/
®
WorkCentre®EC7856/7836 Multifunction
To identify the software version on your printer, at the control panel, touch Device, then touch About. The software version number appears.
100.008.037.03831
100.xxx.037.03830
105.xxx.009.34422
105.xxx.009.34422
073.xxx.167.17200
6
Xerox®AltaLink®Series Smart Card Installation and Configuration Guide
Introduction

Smart Card Feature Overview

AAuutthheennttiiccaattiioonn
Xerox offers the Smart Card authentication feature. This authentication enables users who possess smart cards to use the card for network authentication at the multifunction printer. Smart cards contain user identity certificates and public and private keys. This certificate enables the multifunction printer to perform a Kerberos authentication to the Windows active domain controller that issued the identity certificate.
The Smart Card feature was developed to support smart cards and has been extended to support PIV, CAC, Gemalto IDPrime MD, and other smart cards. This document describes the configuration settings for these smart cards.
The multifunction printer determines automatically which type of smart card is inserted in the card reader. The multifunction printer uses the appropriate software libraries to communicate with the specific card. Authentication settings are configured on the multifunction printer, according to the network infrastructure.
HHoolldd AAllll JJoobbss

The Xerox Hold All Jobs feature ensures that jobs are held securely at the multifunction printer. Jobs are available for release only after you authenticate at the printer. The printer holds the jobs for a specified time until they are released. It is not necessary to enter a Secure Print PIN to use this feature.

To use the Hold All Jobs feature, configure the print driver to pull the user name alias from the Smart Card certificate or Windows operating system. Refer to Configure the Print Driver.
This feature provides the following benefits:
Banner Pages are not required to separate jobs, which reduces waste.
You can manage your held jobs more efficiently. You can select only the jobs that you want to print, and delete older versions of documents that you no longer want to print.
Confidential jobs are held in the queue for the owner to release them, rather than the documents waiting in the output tray to be picked up.
EEmmaaiill SSiiggnniinngg aanndd EEnnccrryyppttiioonn
With Smart Card authentication, the multifunction printer has full access to the public and private keys of the user. The printer can use these keys to sign and encrypt emails.
You can sign an email payload through the Smart Card with your private key. This action enables other users to validate the signature with your public key, which they can obtain from you or from LDAP. This validation assures the recipient that the content is original and was not compromised in transit.
You can encrypt an email payload with your public key through the Smart Card or LDAP, then send the encrypted email to the user. This option offers the benefit that, while in transit through the infrastructure, no one can decipher the contents of the email. After the email is in your Inbox, you can decrypt the email with your private key, making the payload readable again.
®
Xerox
Installation and Configuration Guide
AltaLink®Series Smart Card
7
Introduction
SSuuppppoorrtteedd CCaarrdd RReeaaddeerrss
The customer is responsible for providing a card reader for each Xerox®multifunction printer. Most Chip Card Interface Device (CCID)-compliant card readers can be used, but not all card readers are validated. It is recommended that you use the Indentive SCR3310 v2.0 smart card reader.
SSuuppppoorrtteedd CCaarrdd TTyyppeess
Customers are responsible for purchasing and configuring the access cards. The following card types are supported:
CAC
PIV
Gemalto IDPrime MD
Other card types function with the Smart Card solution, but they are not validated.
8
Xerox®AltaLink®Series Smart Card Installation and Configuration Guide
Introduction

Documentation and Support

For information about your Xerox®multifunction printer, the following resources are available:
A System Administrator Guide provides detailed instructions and information about connecting your printer to the network and installing optional features. This guide is intended for system administrators.
A User Guide provides detailed information about all the features and functions on your printer. This guide is intended for general users.
Most answers to your questions are provided by the support documentation supplied for your printer. Alternatively, you can contact Xerox Technical Support or access the Xerox website at www.xerox.com.
®
Xerox
Installation and Configuration Guide
AltaLink®Series Smart Card
9
Introduction
10
Xerox®AltaLink®Series Smart Card Installation and Configuration Guide
2

Preparation

This chapter contains:
Preparation Overview ........ ..... ..... ..... ................. ..... ..... ..... ................. ..... ..... ...................... ..... .... 12
Configuration Checklist ..... ..... ..... ...................... ..... ..... ...................... ..... ...................... ..... ..... .... 13
Xerox®AltaLink®Series Smart Card
Installation and Configuration Guide
11
Preparation

Preparation Overview

This section explains the preparation and resources required to install the Smart Card feature.
12
Xerox®AltaLink®Series Smart Card Installation and Configuration Guide

Configuration Checklist

The following items are required to complete the installation:
Preparation
Summary
1. Obtain the IP address or host name for each applicable Windows domain controller.
2. If domain controller certificate validation is required, obtain the certificate for each applicable domain controller, including all intermediate certificates up to the root certificate.
Note: Typically, this procedure is required only for the Smart Card solution.
3. If Online Certificate Status Protocol (OCSP) is available, obtain the IP address or host name for the OCSP server.
4. If a software upgrade is required, obtain and install the required software release.
5. Mount the Smart Card Reader to the multifunction printer, then connect the USB cable to one of the rear ports. Refer to Connect the USB Smart Card Reader to the Multifunction
Printer.
6. Install the Smart Card software feature enablement key. Refer to Enter the Smart Card
Enablement Key.
7. Configure Smart Card authentication, the optional NTP, and the optional Alternate Control Panel Login. Refer to Configuring the Smart Card.
Status
8. Install any required certificates, then configure the validation settings. Refer to Configure a
Security Certificate.
9. Configure the multifunction printer LDAP settings. Refer to Configure Acquiring Logged-In
User's Email Address.
10. Configure the multifunction printer SMTP email, signing and encryption settings. Refer to
Configure SMTP (Email) Settings.
11. Configure the Hold All Jobs and Secure Print policies, if necessary. Refer to Printing
Features.
Xerox®AltaLink®Series Smart Card
Installation and Configuration Guide
13
Preparation
14
Xerox®AltaLink®Series Smart Card Installation and Configuration Guide
3

Installation

This chapter contains:
Installation Overview . ..... ................. ..... ..... ..... ................. ..... ..... ...................... ..... ..................... 16
Hardware Installation . ..... ..... ................. ..... ..... ...................... ..... ........................... ..... ............... 17
Software Configuration.......... ..... ..... ................. ..... ..... ..... ..... ............ ..... ..... ..... ................. ..... .... 20
Configuring the Smart Card .. ..... ............ ..... ..... ..... ..... ................. ..... ..... ...................... ..... .......... 23
Printing Features.. ................. ..... ..... ..... ................. ..... ..... ..... ................. ..... ..... ...................... ..... 54
Confirm the Installation ..... ..... ...................... ..... ...................... ..... ..... ...................... ..... ..... ..... ... 60
Using the Smart Card................ ........................... ..... ...................... ..... ..... ..... ............ ..... ..... ..... . 61
Xerox®AltaLink®Series Smart Card
Installation and Configuration Guide
15
Installation

Installation Overview

This section provides instructions for installing and configuring the Smart Card solution.
There are four main installation procedures to follow in the sequence given:
1. Hardware Installation: Unpack the Smart Card Enablement kit, then install the card reader device.
2. Enabling the Smart Card: To enable the Smart Card for configuration, use the feature enable key.
3. Configuring the Smart Card: Enable the Smart Card function, then customize the settings.
4. Using the Smart Card: For instructions on how to use the card reader to access the printer functions, refer to Using the Smart Card.
Note: Depending on the printer model and software version you are using, the configuration
instructions can vary.
16
Xerox®AltaLink®Series Smart Card Installation and Configuration Guide
Installation

Hardware Installation

CCoonnnneecctt tthhee UUSSBB SSmmaarrtt CCaarrdd RReeaaddeerr ttoo tthhee PPrriinntteerr
To install the card reader:
1. Unpack the Xerox
Xerox
Card Reader SCR3310v2
Four Velcro
Two cable ties
One ferrite bead
Five cable clamps Before you install the hardware, ensure that you have read the license agreement and agree to the terms and conditions.
®
Smart Card Enablement Guide (CAC/PIV)
®
Smart Card Enablement Kit (CAC/PIV). The kit contains the following items:
®
dual-lock fastener pads
2. Locate the card reader device, then install and configure the device.
Note: The system administrator configures the cards before the card reader is installed on
the printer.
Xerox®AltaLink®Series Smart Card
Installation and Configuration Guide
17
Installation
3. Attach the ferrite bead to the reader cable.
Note: Clip the ferrite bead onto the cable that is behind the connector.
4. Attach the dual-lock fastener pads to the card reader device.
Fasteners are provided to secure the card reader to the multifunction printer.
Peel back the fastener pad backing strip, then position the fastener pad on the under-side of the card reader, as shown.
Repeat these steps for each of the fastener pads supplied.
18
Xerox®AltaLink®Series Smart Card Installation and Configuration Guide
Installation
5. When all the dual-lock fastener pads are attached to the card reader, remove the backing strips on each of the pads.
6. Place the card reader on the multifunction printer.
Gently place the card reader on the printer. Do not fix the card reader in place at this time.
Position the card reader in a suitable location. Ensure that the card reader does not obstruct
any access points or the opening of doors or covers.
Verify that the cable has sufficient length to connect to the rear of the network controller.
When the card reader is in a suitable location, to fix the card reader device in place, press
firmly on the reader.
7. Connect the card reader to the multifunction printer.
Insert the USB connection into the slot provided on the rear of the network controller.
Use the cable clamps and cable ties provided to bundle the cables and ensure that the
cabling is neat.
The hardware installation is now complete.
®
Xerox
AltaLink®Series Smart Card
Installation and Configuration Guide
19
Installation

Software Configuration

AAcccceessssiinngg AAddmmiinniissttrraattiioonn aanndd CCoonnffiigguurraattiioonn SSeettttiinnggss
The Embedded Web Server is the administration and configuration software installed on the printer. This software allows you to configure and administer the printer from a Web browser.
The administrator password is required to access locked settings in the Embedded Web Server or at the control panel. Most printer models have a default configuration that restricts access to some settings. In the Embedded Web Server, you can restrict access for settings on the Properties tab. At the device touch screen, you can restrict settings in the Tools menu.
To access the Embedded Web Server and log in as the administrator:
1. At your computer, open a Web browser.
2. In the URL address field, type http:// followed by the IP Address of the multifunction printer. For example: If the IP Address is 192.168.100.100, type the following into the URL address field: http://192.168.100.100. Press Enter or Return.
3. In the top-right area of the page, click Login.
a. For User ID, type admin.
b. For Password, type the administrator password. The default administrator password is 1111,
or the printer serial number. You can obtain the serial number from inside the front door of the printer, from the configuration report, and from the home page of the Embedded Web Server. The password is case-sensitive.
4. Click Login.
For more information about accessing and configuring the Embedded Web Server settings, refer to the System Administrator Guide for your Xerox multifunction printer.
EEnntteerr tthhee SSmmaarrtt CCaarrdd EEnnaabblleemmeenntt KKeeyy
Before you configure the Smart Card solution, use the Embedded Web Server to enable the Smart Card feature on your Xerox inside cover of the enablement guide provided within the Xerox
®
multifunction printer. The Feature Enablement Key is printed on the
®
Smart Card (CAC/PIV) kit.
To enable the device software:
1. Access the Embedded Web Server, then click the Properties tab. For more information, refer to

Accessing Administration and Configuration Settings.

20
Xerox®AltaLink®Series Smart Card Installation and Configuration Guide
2. Click the Login/Permissions/Accounting link.
3. Click the Login Methods link.
4. Click the Control Panel Login button.
a. From the Control Panel Login menu, select Smart Cards.
b. If users need an alternate method of authentication, from the Alternate Control Panel
Login menu, select User Name/Password — Validate on the Network.
Installation
c. If the device uses the email address registered to the authenticated user, select the check
box for Personalized User Profile.
Xerox®AltaLink®Series Smart Card
Installation and Configuration Guide
21
Loading...
+ 49 hidden pages