Xerox VersaLink B400 CONFIGURATION GUIDE

Common Access Card
for Xerox
Version 1.5
September
2019
®
VersaLink® Printers
System Configuration Guide
© 2017 Xerox Corporation. All rights reserved. Unpublished rights reserved under the copyright laws of the United States. Contents of this publication may not be reproduced in any form without permission of Xerox Corporation.
Copyright protection claimed includes all forms of matters of copyrightable materials and information now allowed by statutory or judicial law or hereinafter granted, including without limitation, material generated from the software programs which are displayed on the screen such as styles, templates, icons, screen displays, looks, and so on.
®
and Xerox and Design®, Global Print Driver®, VersaLink®, and Mobile Express Driver® are
Xerox trademarks of Xerox Corporation in the United States and/or other countries.
PostScript
Windows
®
is a trademark of Adobe Systems Incorporated in the United States and/or other countries.
®
is a trademark of Microsoft Corporation in the United States and other countries.
Document Version 1.3 November 2017
BR22729
Contents
1 Introduction .......................................................................................................................................................................................... 1-1
Purpose.................................................................................................................................................................................................... 1-1
Target Audience .................................................................................................................................................................................. 1-1
Disclaimer .............................................................................................................................................................................................. 1-1
2 Prerequisites .......................................................................................................................................................................................... 2-2
3 Feature Overview ................................................................................................................................................................................ 4-4
S/MIME ................................................................................................................................................................................................... 5-7
Requirements .............................................................................................................................. Error! Bookmark not defined.
Secure Print Hold and Release ...................................................................................................................................................... 5-7
4 Supported Card Readers ................................................................................................................................................................. 6-8
5 Supported Card Types ...................................................................................................................................................................... 7-9
6 System Configuration ................................................................................................................................................................... 9-13
System Configuration Checklist ................................................................................................................................................ 9-13
Accessing the Embedded Web Server .................................................................................................................................... 9-14
Changing the Admin Password ................................................................................................................................................. 9-15
Enabling HTTPS ................................................................................................................................................................................ 9-16
Importing Root and Intermediate Certificates ................................................................................................................. 9-17
Enabling SNTP .................................................................................................................................................................................. 9-17
Enabling the Plug-In Feature ..................................................................................................................................................... 9-18
Downloading the CCID Terminal Service Plug-in File ..................................................................................................... 9-19
Checking the CCID Terminal Service Plug-In Version Number ................................................................................... 9-19
Updating the CCID Terminal Service Plug-in ...................................................................................................................... 9-20
Deactivating and Activating the CCID Terminal Service Plug-In .............................................................................. 9-21
Installing an Updated CCID Terminal Service Plug-in File ........................................................................................... 9-21
Enabling the CAC&PIV Smartcard Service Plug-in ........................................................................................................... 9-23
Changing the System to Smart Card Authentication ..................................................................................................... 9-23
Enabling the Smart Card Certificate Verification Option .............................................................................................. 9-24
7 Feature Configuration ................................................................................................................................................................ 10-25
Obtaining, Installing and Configuring V3 Xerox® Print Driver ................................................................................. 10-25
Enabling Email Signing and Encryption ............................................................................................................................. 10-26
8 Workflow Examples ..................................................................................................................................................................... 11-28
Secure Scan to Email ................................................................................................................................................................... 11-28
Secure Print Hold and Release ................................................................................................................................................ 11-28
Common Access Card for Xerox® VersaLink® Printers System Configuration Guide i
9 Troubleshooting and Support ................................................................................................................................................. 12-30
Troubleshooting Tips .................................................................................................................................................................. 12-30
Support at Xerox ........................................................................................................................................................................... 12-30
More Information ........................................................................................................................................................................ 12-30
10 Security Information ................................................................................................................................................................... 13-31
Security at Xerox ........................................................................................................................................................................... 13-31
Common Access Card for Xerox® VersaLink® Printers System Configuration Guide ii

1 Introduction

Purpose

The Common Access Card (CAC) solution brings an advanced level of security to sensitive information. Using the CAC, organizations can restrict access to the walk-up features of a Xerox that only authorized users are able to copy, scan, email and fax information.
®
device. This ensures

Target Audience

This document is a guideline for the configuration and set up of the CAC solution.
NOTE
Not all options listed are supported on all printers. Some options apply only to a specific printer model, configuration, operating system, network, or print driver type.

Disclaimer

The information in this document is provided without warranty of any kind. In no event shall Xerox be liable for any damages whatsoever resulting from user use or disregard of the information provided in this document, including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Xerox has been advised of the possibility of such damages.
Common Access Card for Xerox® VersaLink® Printers System Configuration Guide 1-1

2 Prerequisites

To ensure the successful configuration and subsequent operation of the device, the following conditions are required:
Existing and properly operating Transmission Control Protocol/Internet Protocol (TCP/IP) network infrastructure
Existing and properly operating Public Key Infrastructure
Certificate-based authentication server and valid certificate chains for clients
Supported USB Card Reader
Supported Smart Card
®
Administration rights to configure a Xerox
The VersaLink device is connected to the TCP/IP network with a valid IPv4 address
A workstation with a modern browser is connected to the same TCP/IP network with a valid IPv4
address
NOTE
VersaLink® device
Common Access Card for Xerox® VersaLink® Printers System Configuration Guide 2-2
3 DPI LOI CAC Installation Guide Instructions
Reference
The United States Air Force Digital Printing and Imaging (DPI) team has created a formal Letter of Instruction (LOI) document regarding the installation of CAC on MFP products like VersaLink.
This section relates the LOI to the contents of this document,
The listed sections describe how this information can be configured on the VersaLink device.
Your installation may not require setting all the below values.
1) The type of information to be gathered before installation begins, such as: a) DNS Server Primary and Secondary (Section 7.0 7-7) b) Wins Server (Section 7.0 7-7) c) Domain Controller Network Addresses (Section 8.0 8-19) d) Domain Controller Certificates Root/User/Device (Section 8.0 8-13) e) LDAP Active Directory Network Address (Section 7.0 7-8) f) OCSP Network/Server information (Section 7.0 7-8) g) SMTP (scan to email) (Section 9.0 9-22) h) Kerberos Configurations (Section 8.0 8-20) i) Root Certificates (Section 8.0 8-14) j) Add any others not noted in the list
2) Steps the administrator should follow to complete installation and configuration of the MFP­CAC, based on the following: a) Using installation information from #1 above, identify the configuration steps b) Identify the Active Directory configuration within the MFP (ex: LDAP, Kerberos, etc)
(Section 9.0 9-21) c) Identify how Certificates should be retrieved and installed (Section 8.0 8-13) d) Identify how SMTP (Scan to Email or Scan to File Share) should be configured (Section 9.0
9-21) e) Identify any additional steps needed to complete the installation (Section 9.0 9-21)
3) Other user administrator settings which should be considered after installation, based on the following: a) Identify how administrators should lock the device and require CAC Card/Pin
Authentication before permitting access to scanning/printing features
b) Identify how administrators should set the device to lock and clear user credentials after
CAC Removal
c) Identify any additional administrative settings needed to complete the installation
(Section 9.0 9-21)
(Section 9.0 9-21)
(Section 9.0 9-21)
Common Access Card for Xerox® VersaLink® Printers System Configuration Guide 3-3

4 Hardware Installation

© 2019 XeroxCorpo ration. All Rig hts Reserved.  Xerox
®
is a trademark ofXerox Corporation 
in the United States and/or other countries . BR26492
607E21290 Rev F
www.xerox.com/support
1
7
5 6
2
4
3
3.1
3.2
1.1
1.2
1.3
5.1
5.2
7.1 7.2
7.3
Refer to the diagram that most closely matches your device.
Common Access Card for Xerox® VersaLink® Printers System Configuration Guide 4-4
607E21040 Rev B607E21040 Rev B
www.xerox.com/support
6
1
5
2
2.3
2.2
2.1
2.4
1.1
1.2
1.3
4
3
3.1 3.2
Common Access Card for Xerox® VersaLink® Printers System Configuration Guide 4-5
© 2019 Xerox Corporation. All Rig hts Reserved.  Xerox
®
is a trademark ofXeroxC orporation 
in the United States and/or other countries. BR26493
7
8
8.1
8.3
8.4
8.2
8.5
6.1 6.2
6
Common Access Card for Xerox® VersaLink® Printers System Configuration Guide 4-6

5 Feature Overview

S/MIME

This product offers Secure/Multipurpose Internet Mail Extensions (S/MIME) that allows a System Administrator to configure the device to provide digital signature and encryption functionality, which requires the use of PKI certificates.

Secure Print Hold and Release

This product offers Secure Print Hold and Release that allows a System Administrator to configure the device to hide print jobs from unauthorized users, and only reveal and allow subsequent printing by users authenticated to the system.
NOTES
Only the V3 Xerox
Support for V4 Xerox
Express Driver to Section 9 of this document.
®
Print drivers for VersaLink products are CAC-enabled.
®
®
Print drivers and support for the Xerox® Global Print Driver® and Xerox® Mobile
are not available at this time. For more information about supported print drivers, refer
Common Access Card for Xerox® VersaLink® Printers System Configuration Guide 5-7
Loading...
+ 24 hidden pages