CACStar™UserGuideRevA03Copyright2014DigitalImagingTechnology Page12
Basic
ThisincludesPINvalidation,cardexpirationcheck,andX.509cardcertificatevalidation.IfanNTP
serverisnotconfiguredontheLAN Side Configurationpage,theexpirationcheckisbypassed.TheBasic
levelofauthenticationisalwaysincludedandcannotberemovedfromtheconfiguration.Insome
installations,thisissufficientauthenticationandistheonlyoneactivated.
OCSP
CheckthisboxtoenableOCSP(OnlineCertificateStatusProtocol)verificationofCACCards.Ifenabled
theOCSPserverwillbeusedtovalidatethecurrentstatusoftheCACcardPKIcertificate.
NOTE:IfOCSPisenabled,youmusthavea
DNSserverconfigured.
RootCertificate
CheckthisboxtoenableRootCertificateverificationofCACCards.Ifenabled,thecertificatechain,
includingtheRootCACertificatewillbeusedtovalidatetheCACcardPKIcertificate.Thecardisalso
checkedtobecertaintheCACcertificatehasavalid
privatekey.
NOTE:IfRoot Certificateisenabled,allIssuerCertificatesandRootCACertificatechainsforcardsinuse
atthisinstallationmustbeloadedintotheCACStar.Ifnot,VerifyFailureswilloccur.
LDAP
CheckthistoenableuseoftheActiveDirectoryserverforadditionalauthentication
LDAP
ServerIP:IPaddressoftheLDAPserver.
LDAPServerPort: PortnumberoftheLDAPserver.Thedefaultis389.
LDAPQueryUserName: UserNamefortheLDAPserviceaccountlogin.
LDAPQueryPassword: PasswordfortheLDAPserviceaccountlogin.
LDAPSearchBase: Definesthelocationin
thedirectorywhereasearchwill
start.
Example:OU=Users,DC=Itek,DC=com
LDAPSearchString: TheSearchStringisusedbytheLDAPservertofindusers.
Therearecertainkeysthatwillbeexpandedtocreatethequery.
Keysare:
%L–expandstobecometheuser’slastname
%F–expandstobecometheuser’sfirstname
%M–expandstobecometheuser’smiddlename
%E–emailaddress
%e–EDI‐PI
LDAPUserIDoptions: Choicesarecn,upn,mail,orname.
DisableLDAPReferrals: Ifthisboxischecked,theReferralssent
byLDAPServerswill
NOTbefollowed.