and the sphere of connectivity design are trademarks of Xerox Corporation in the United States and/or other countries.
Copyright protection claimed includes all forms of matters of copyrightable materials and information now allowed by statutory or
judicial law or hereinafter granted, including without limitation, material generated from the software programs which are displayed
on the screen such as styles, templates, icons, screen displays, looks, etc.
Changes are periodically made to this document. Changes, technical inaccuracies, and typographic errors will be corrected in
subsequent editions.
ARetrieving the Certificate from a Domain Controller or OCSP Server
BDetermining the Domain in which your Card is Registered
Xerox Common Access Card
Common Access Card Installation Guide
3
4
Xerox Common Access Card
Common Access Card Installation Guide
Introduction
The Xerox Common Access Card solution brings an advanced level of security to sensitive information.
Organizations can restrict access to the walk-up features of a Xerox device. This ensures only
authorized users are able to copy, scan, e-mail and fax information.
The key benefit of this solution is its two-factor identification requirement. Users must insert their
access card and enter a unique Personal Identification Number (PIN) at the device. This provides
added security in the event that a card is lost or stolen.
Once validated, a user is logged into the Xerox device for all walk-up features. The system allows for
functions to be tracked for an added layer of security.
The Xerox Common Access Card enablement kit integrates with Xerox multifunction printers and
existing common access and personal identity verification cards and readers.
This guide explains how to install and configure the Common Access Card solution. It identifies the
resources and equipment required to complete a successful installation.
Should you require any further information, please contact your Local Xerox Representative.
1
Xerox Common Access Card
Common Access Card Installation Guide
5
Introduction
Compatibility
This solution is compatible with the following product and configurations:
ConfigurationSoftware Level
06x.050.xxx.xxxxx
ColorQube™ 9201/9202/9203
Xerox WorkCentre 7755/7765/777506x.090.xxx.xxxxx
•To identify the software level on your machine, press the Machine Status button on the control
panel.
•The System Software Version number is displayed.
06x.080.xxx.xxxxx
6
Xerox Common Access Card
Common Access Card Installation Guide
Introduction
Card Readers and Card Types
Supported Card Readers
The customer is responsible for providing a card reader for each Xerox device. The following card
readers are compatible with the solution:
•Gemplus GemPC USB SL
•Gemplus GemPC Twin
•SCM Micro SCR3310
•SCM Micro SCR3311
•OmniKey Cardman 3021 USB
•OmniKey Cardman 3121 USB
•ActivCard USB Reader V2 with SCR-331 firmware
Other CCID compliant readers may function with the solution, but have not been validated.
Note: Information about CCID compliant card readers can be obtained from various websites, for
example www.pcsclite.alioth.debian.org/ccid.This site is not a Xerox website and is not endorsed
by Xerox.
Supported Card Types
The customer is also responsible for purchasing and configuring the access cards. The following card
types are recommended:
•Axalto Pegasus 64K / V2
•Axalto Cyberflex 32K / V1
•Axalto Cyberflex 64K / V2
•Gemplus GemXpresso 64K / V2
•Oberthur 72K / V2
•Oberthur CosmopoIIC 32K / V1
•Oberthur D1 72K / V2 (contact-less and PIV)
Other card types may function with the solution, but have not been validated.
Additional information from your System Administrator may be required to validate which card reader
works best in your environment.
Note: Information about CCID compliant card types can be obtained from various websites, for
example www.pcsclite.alioth.debian.org/ccid.This site is not a Xerox website and is not endorsed
by Xerox.
Xerox Common Access Card
Common Access Card Installation Guide
7
Introduction
Documentation and Support
For information specifically about your Xerox product, the following resources are available:
•System Administrator Guide provides detailed instructions and information about connecting
your device to the network and installing optional features. This guide is intended for
System/Machine Administrators.
•User Guide provides detailed information about all the features and functions on the device. This
guide is intended for general users.
Most answers to your questions will be provided by the support documentation supplied on disc with
your product. Alternatively you can contact the Xerox Support Center or access the Xerox website at
www.xerox.com.
8
Xerox Common Access Card
Common Access Card Installation Guide
Preparation
This section explains the preparation and resources required to install the Common Access Card.
The installation will take approximately one hour for each device. The following items are required in
order to complete the installation:
ItemSupplier
Compatible Card Reader (refer to Supported Card Readers on page 7)Customer
Compatible Access Card (refer to Supported Card Types on page 7)Customer
2
Common Access Card enablement kit 498K17543
(one for each Xerox device)
Feature Enable KeyXerox
TCP/IP enabled on the deviceCustomer
DNS Host name or static IP address assignedCustomer
Network Settings to be checked to ensure network is fully functionalCustomer
Domain Controller (DC) information:
• Domain Controller authentication environment
• lP address or Host Name
• Domain information
• Domain Controller Root and Intermediate certificates
• Check that all certificates are in 64 bit X.509 format
• Determine if the DC is registered with the OCSP at this site
Online Certificate Status Protocol (OCSP) Server Information:
•OCSP Server URL
• OCSP - Root and Intermediate Certificates
• Check that all certificates are in 64 bit X.509 format
Proxy Server configuration detailsCustomer
Xerox
Customer
Customer
To set up the Domain Controller (DC) validation, you will need to determine if your site validates the DC
against the Online Certificate Status Protocol (OCSP) server. Many sites use OCSP to validate
individuals, but do not register the DC with it. If you set up the Xerox device to validate the DC and it
isn't registered, the procedure will fail.
If your site does register the DC with OCSP, you will need to decide whether:
•to validate the DC against OCSP before validation of the user, or
•to validate the DC after validation of the user
Xerox Common Access Card
Common Access Card Installation Guide
9
Preparation
The first method requires installation of the DC certificate as part of this procedure and is the more
accepted method for validation. The second method retrieves the DC certificate automatically for each
authentication and doesn't require installation of the DC certificate onto the Xerox device.
An additional option is to combine the first and second options and compare the retrieved DC
certificate to the one stored at installation. This provides the most security as it prevents rogue DCs
masquerading as the real DC.
Note: Certificates are often obtained from the Information Technology professionals that support
your organization. If you are unable to obtain the required certificates, refer to the process
outlined in Appendix A. You can determine the domain that you are registered in using the process
outlined in Appendix B.
Server Specifications
Prior to installation, ensure your network infrastructure supports Common Access Card or Personal
Identification Verification (PIV).
Names or IP addresses of all servers and domains are required during setup.
Electrical Requirements
The USB port on the back of the Xerox device network controller provides the power required for any of
the supported card readers.
10
Xerox Common Access Card
Common Access Card Installation Guide
Installation
This section provides instructions for installing and configuring the Common Access Card solution.
There are 4 main installation procedures to follow in sequence.
•Enabling and Configuring Common Access Card
Use the Feature Enable Key to enable the Common Access Card to be configured.
•Configuring Common Access Card
Enabling the Common Access Card function and customizing the settings.
•Hardware Installation
Unpacking the Common Access Card Enablement kit and installing the card reader device.
•Using Common Access Card
Instructions on how to use the card reader device to access the device functions.
3
Xerox Common Access Card
Common Access Card Installation Guide
11
Loading...
+ 25 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.