Xerox WorkCentre 7525, WorkCentre 7530, WorkCentre 7535, WorkCentre 7545, WorkCentre 7556 Installation Guide

Version 4.0 09/11
Xerox® Smart Card
Xerox® WorkCentre 7525/7530/7535/7545/7556
XEROX® and XEROX and Design® are trademarks of Xerox Corporation in the United States and/or other countries.
Changes are periodically made to this document. Changes, technical inaccuracies, and typographic errors will be corrected in subsequent editions.
Document version 4.0: September 2011

Table of Contents

1Introduction
Compatibility . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6
Card Readers and Card Types . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .7
Supported Card Types . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .7
Supported Card Readers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .7
Documentation and Support . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .8
2Preparation
Server Specifications . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
Electrical Requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
3Installation
Software Enablement . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
Configuring Smart Card . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14
Hardware Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
Using the Smart Card. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25
4 Troubleshooting
Fault Clearance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28
Locating the Serial Number . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28
Troubleshooting Tips . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 29
During Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 29
After Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 30
A Retrieving the Certificate from a Domain Controller or OCSP Server
B Determining the Domain in which your Card is Registered
Xerox® Smart Card
Installation Guide
3
4
Xerox® Smart Card Installation Guide

Introduction

The Xerox Smart Card solution brings an advanced level of security to sensitive information. Organizations can restrict access to the walk-up features of a Xerox device. This ensures only authorized users are able to copy, scan, e-mail and fax information.
The key benefit of this solution is its two-factor identification requirement. Users must insert their access card and enter a unique Personal Identification Number (PIN) at the device. This provides added security in the event that a card is lost or stolen.
Once validated, a user is logged into the Xerox device for all walk-up features. The system allows for functions to be tracked for an added layer of security.
The Xerox Smart Card enablement kit integrates with Xerox multifunction printers and existing smart and personal identity verification cards and readers.
This guide explains how to install and configure the Smart Card solution. It identifies the resources and equipment required to complete a successful installation.
Should you require any further information, please contact your Local Xerox Representative.
1
Xerox® Smart Card
Installation Guide
5
Introduction

Compatibility

This solution is compatible with the following product and configurations:
Configuration Software Level
Xerox WorkCentre 7525/7530/7535/7545/7556 06x.120.xxx.xxxxx
To identify the software level on your machine, press the Machine Status button on the control
panel.
•The System Software Version number is displayed.
6
Xerox® Smart Card Installation Guide
Introduction

Card Readers and Card Types

Supported Card Types

The customer is responsible for purchasing and configuring the access cards. The following card types are recommended:
Gemalto TOP DL GX4 144K V2.6.2b Applets
Oberthur ID-One Cosmo v5.2 128K V2.6.2 Applets
Oberthur ID-One Cosmo v5.2 72K V2.6.1 Applets
Oberthur ID-One Cosmo v5.2D 72K V2.6.1 Applets
Oberthur ID-One Cosmo v5.2 72K V2.6.2 Applets
Gemalto GemCombiXpresso R4 dual interface 72K V2.6.2 Applets
Axalto Access 64KV1
Axalto Access 64KV1
Gemplus GXP3 64V2N V2.6.1 Applets
Gemalto Cyberflex Access V2C 64K V2.6.1 Applets
Oberthur ID-One Cosmo V5.2D 64K
Oberthur OCS Galactic V1 32K V1 Applets
Oberthur Cosmo V4 32K V1 Applets
Schlumberger / Axalto Cyberflex V2 32K V1 Applets
Other card types may function with the solution, but have not been validated.Supported Card Types

Supported Card Readers

The customer is responsible for providing a card reader for each Xerox device. The following card readers are compatible with the solution:
Gemplus GemPC USB SL
•Gemplus GEMPC Twin
•SCM Micro SCR3310
•SCM Micro SCR3311
OmniKey Cardman 3021 USB
OmniKey Cardman 3121 USB
ActivCard USB Reader V2 with SCR-331 firmware
Other CCID compliant readers may function with the solution, but have not been validated.
Note: Information about CCID compliant card readers can be obtained from various websites, for
example www.pcsclite.alioth.debian.org/ccid.This site is not a Xerox website and is not endorsed by Xerox.
Xerox® Smart Card
Installation Guide
7
Introduction

Documentation and Support

For information specifically about your Xerox product, the following resources are available:
System Administrator Guide provides detailed instructions and information about connecting
your device to the network and installing optional features. This guide is intended for System/Machine Administrators.
User Guide provides detailed information about all the features and functions on the device. This
guide is intended for general users.
Most answers to your questions will be provided by the support documentation supplied on disc with your product. Alternatively you can contact the Xerox Support Center or access the Xerox website at
www.xerox.com.
8
Xerox® Smart Card Installation Guide

Preparation

This section explains the preparation and resources required to install the Smart Card.
The installation will take approximately one hour for each device. The following items are required in order to complete the installation:
Item Supplier
Compatible Card Reader (refer to Supported Card Types on page 7) Customer
Compatible Access Card (refer to Supported Card Types on page 7) Customer
2
Smart Card enablement kit 498K17543 (one for each Xerox device)
Feature Enable Key Xerox
TCP/IP enabled on the device Customer
DNS Host name or static IP address assigned Customer
Network Settings to be checked to ensure network is fully functional Customer
Domain Controller (DC) information:
• Domain Controller authentication environment
• lP address or Host Name
• Domain information
• Domain Controller Root and Intermediate certificates
• Check that all certificates are in 64 bit X.509 format
• Determine if the DC is registered with the OCSP at this site
Online Certificate Status Protocol (OCSP) Server Information:
•OCSP Server URL
• OCSP - Root and Intermediate Certificates
• Check that all certificates are in 64 bit X.509 format
Proxy Server configuration details Customer
Xerox
Customer
Customer
To set up the Domain Controller (DC) validation, you will need to determine if your site validates the DC against the Online Certificate Status Protocol (OCSP) server. Many sites use OCSP to validate individuals, but do not register the DC with it. If you set up the Xerox device to validate the DC and it isn't registered, the procedure will fail.
If your site does register the DC with OCSP, you will need to decide whether:
to validate the DC against OCSP before validation of the user, or
to validate the DC after validation of the user
Xerox® Smart Card
Installation Guide
9
Preparation
The first method requires installation of the DC certificate as part of this procedure and is the more accepted method for validation. The second method retrieves the DC certificate automatically for each authentication and doesn't require installation of the DC certificate onto the Xerox device.
An additional option is to combine the first and second options and compare the retrieved DC certificate to the one stored at installation. This provides the most security as it prevents rogue DCs masquerading as the real DC.
Note: Certificates are often obtained from the Information Technology professionals that support
your organization. If you are unable to obtain the required certificates, refer to the process outlined in Appendix A. You can determine the domain that you are registered in using the process outlined in Appendix B.

Server Specifications

Prior to installation, ensure your network infrastructure supports Smart Card or Personal Identification Verification (PIV).
Names or IP addresses of all servers and domains are required during setup.

Electrical Requirements

The USB port on the back of the Xerox device network controller provides the power required for any of the supported card readers.
10
Xerox® Smart Card Installation Guide

Installation

This section provides instructions for installing and configuring the Smart Card solution.
There are 4 main installation procedures to follow in sequence.
Enabling and Configuring Smart Card
Use the Feature Enable Key to enable the Smart Card to be configured.
Configuring Smart Card
Enabling the Smart Card function and customizing the settings.
Hardware Installation
Unpacking the Smart Card Enablement kit and installing the card reader device.
•Using Smart Card
Instructions on how to use the card reader device to access the device functions.
3
Xerox® Smart Card
Installation Guide
11
Installation

Software Enablement

Prior to installing the Xerox Smart Card solution, the software requires enabling on your Xerox device using the Internet Services. The Feature Enable Key is printed on the inside cover of the Enablement guide provided within the Xerox Smart Card kit.
Follow the instructions below to enable the device software.
Note: Some of the steps shown may require the System Administration password for your device
to be entered.
1. Access Internet Services
a. Open the web browser from your Workstation.
b. In the URL field, enter http://
followed by the IP Address of the device. For example: If the IP Address is 192.168.100.100, enter the following into the URL field: http://192.168.100.100.
c. Press Enter to view the Home page.
2. Access Properties
a. Select the Properties tab.
b. If prompted, enter the
Administrator User ID and Password. The default is admin and 1111.
c. Select the Login button.
3. Enable the Smart Card software
a. Select the Security link. b. Select the Authentication link.
c. Select Setup in the directory tree.
d. In the Authentication &
Authorization Setup area, select
Edit Methods....
e. Set the Device User Interface
Authentication option to Smart
Card (CAC)/Personal Identity Ver ification (PIV) using the
drop-down menu. If you require the device to use the E-mail address registered to the authenticated user, select Personalization.
f. Select Save.
12
Xerox® Smart Card Installation Guide
Loading...
+ 26 hidden pages