Dell C3765dnf Color Laser Printer User guide

Type
User guide
CACStar™UserGuideRevA03Copyright2014DigitalImagingTechnology Page1
User Guide
CACStarfor Dell C3765dnf
Network protection for CAC/PIV enabled Multifunction Devices or Printers
CACStar™UserGuideRevA03Copyright2014DigitalImagingTechnology Page2
TableofContents
Introduction..................................................................................................................................................3
InitialSetup...................................................................................................................................................4
AdminLogin..................................................................................................................................................5
Connectivity..................................................................................................................................................5
LANSideConfiguration.............................................................................................................................5
LocalSideConfiguration...........................................................................................................................7
Security.........................................................................................................................................................8
MFDFunctionEnabling.............................................................................................................................8
EmailSetup...............................................................................................................................................9
AuthenticationMethod..........................................................................................................................11
UserLogging............................................................................................................................................15
UploadCertificate...................................................................................................................................
15
Administrator..............................................................................................................................................17
ChangePassword....................................................................................................................................17
AdministratorAccess..............................................................................................................................17
FirmwareUpdate....................................................................................................................................19
TechnicalSupport...................................................................................................................................20
SetupTest...............................................................................................................................................21
DateTime................................................................................................................................................22
HoldPrintFiles........................................................................................................................................23
Status..........................................................................................................................................................25
CardReader.............................................................................................................................................25
Network..................................................................................................................................................26
About.......................................................................................................................................................27
CACStar™UserGuideRevA03Copyright2014DigitalImagingTechnology Page3
Introduction
CACStar™providesasolutiontoHSPD12requirementsforCAC/PIVbasedprotectionofnetworkdata
toandfromprintersorMultifunctionDevices(MFD’s).Youcanconfigureittorequireanauthenticated
CACcardtocontrolScantoFolder,ScantoEmail,SNMP,FTP,orprinting.Configurableauthentication
methodsincludeBasic
X.509certificateonthecard,PINvalidation,expiration,OCSP,rootcertificate,
LDAP,andKerberos.CACStarisavailableinmodelsthatcanbedeployedasasmalladdonboxforuse
withlegacyMFD’sthatneedCAC/PIVprotection.Itisalsoavailableasanintegratedsolutionkitthat
canbe
easilyinstalledoncertainmodelsoflegacyMFD’s.
CACStarwilladopttheIPaddressoftheMFDonwhichitisinstalled,sothereisnohostnetwork
configurationchangenecessary.InstallationiseasilydoneusingsecurewebbasedaccesstoCACStarby
thenetworkadministrator.Initssimplest
form,theadminonlyneedstoconfiguretheIPaddressofthe
MFDandtheIPaddressofthelocaltimeserver.Informationaboutmanyadditionalconfiguration
optionsisdescribedlaterinthisgui de.
PriortostartingtheconfigurationofCACStaritwouldbeusefultocollecttheinformationneeded.
Appendix
Ahasaconvenientlistofquestionsthatwillhelpincollectingtheinformation.
Ifyouneedhelpobtainingcorrectfirmwareordocumentation,contactDell’sProSupportHelpDeskby
calling18665163115,orbysendingemailto[email protected].
CACStar™UserGuideRevA03Copyright2014DigitalImagingTechnology Page4
InitialSetup
1. UsingtheMFD/printeroperatorpanel,settheMFDIPaddressto172.19.10.2andtheSubnet
Maskto255.255.255.0andtheGatewayto172.19.10.1.
2. AfterInitializationiscomplete,theCardReaderdisplaywillsay
Waiting For Card.
3. Usingthecardreaderkeypad,entertheIPaddresstobeusedtoaccessboththeCACStarand
theMFD/printer.SeeFigure1below.
a. PresstheFkey;thedisplaywillsay
Information.
b. PresstheFkeyagain;thedisplaywillsay
Configuration.
c. PresstheEnterkey;thedisplaywillshow
LAN IP Address andthecurrentsetting.
d. PresstheEnter key;thedisplaywillshow
Enter New Value.
e. EnterthedesiredIPAddressandpressEnter.UsetheIPaddressyouwanttousefor
hostcomputerconnectiontotheMFD/printer.
i. Example:192.168.1.23Enter.
f. Thedisplaywillsay
Setting Valueforabout5seconds.
g. PresstheFkey;thedisplaywillsay
LAN Subnet Mask andthecurrentsetting.
h. PresstheEnter key;thedisplaywillshow
Enter New Value.
i. EnterthedesiredsubnetmasklikeyoudidtheIPAddress.
j. Ifyouwishtoenterthegateway,presstheFkeyagainandenteritasyoudidtheIP
Address.
k. PresstheExitkeytwicetoreturnto
Waiting for Card.
l. Toconfirmthisoperationwassuccessful,youcanpingtheCACStaratitsnewIPaddress
fromyourPC.
4. Fromtheadministrator’sPC,pointyourbrowsertotheCACStarusingasecureconnectionon
port8443attheIPaddressyouassignedtotheCACStar.
a.
Example:https://192.168.1.23:8443
5. YouarelikelytogetanInvalidCertificateWarningfr omthebrowser.Ifso,overridethe
warningandcontinuetotheCACStarwebsite.
6. Proceedwithanyoftheconfigurationcommandsshownbelowasnecessaryforyour
installation.

Figure1KeypadFunctionButtons
Exit
Backspace
Function
Enter
CACStar™UserGuideRevA03Copyright2014DigitalImagingTechnology Page5
AdminLogin
ConfigurationoftheCACStarwillbedonefromtheadministrator’sPCbyconnectingovertheLANusing
theIPAddressyouenteredonthecardreaderkeypad.Thismustbedoneinsecuremodeonport8443.
Forexample:https://192.168.1.23:8443
ThebrowserwillrequireanIDandpassword.ThedefaultIDis“admin”.Thedefaultpasswordis
“password”.
Afterinitiallogin,youcanchangethepasswordtooneofyourchoicebygoingtotheAdministratortab.
AccessingtheMFD/PrinterWebSite
IfyouwishtoaccesstheMFD/printer
website,gotothesameURLbutdonotuseport8443.For
example:http://192.168.1.23orhttps://192.168.1.23
Connectivity
LANSideConfiguration
CACStar™UserGuideRevA03Copyright2014DigitalImagingTechnology Page6
Step1MFDIPAddress
ThisistheIPaddressthatisusedforaccesstotheseadministratorwebpages.Itisalsousedforhost
computerconnectiontotheMFD/print er.ThisIPaddresswasalreadysetintheinitialsetupprocess
usingthecardreaderkeypad.
If
youwishtochangethisaddress,itcanbedoneusingthisscreenorfromthecardreaderkeypad.
Note:WhenyoupresstheUpdatebutton,theCACStarwillswitchtothenewIPaddresswhichwillcause
yourbrowsertobedisconnectedfromtheCACStar.Toreconnect,redirect
yourbrowsertothenewIP
addressyoujustentered.

Step2NTPServer:
SettheIPaddressoftheNTPserverinuseonthissubnet.
Step3ConfigureGatewayandDNSServer
CACStar™UserGuideRevA03Copyright2014DigitalImagingTechnology Page7
Note:ADNSServerisrequiredforOCSPsupport.ItisnotnecessarytoconfigureaDNSserverifyouare
notusingOCSP.
Step4PressUpdate
LocalSideConfiguration
ThesesettingsdefinetheIPaddressesusedforLocalcommunicationbetweentheCACStarandthe
MFD/printer.Thedefaultsarelikelytobeacceptable.Usually thereisnoneedtoenteranyIP
addressesonthisconfigurationpage.
MakesurethesevalueswereenteredintotheMFDusingtheMFD/printer
operatorpanel.
CACStar™UserGuideRevA03Copyright2014DigitalImagingTechnology Page8
Security
MFDFunctionEnabling
ChecktheboxesforFunctionsthatrequireavalidatedCACCardforuse.
IfaboxisuncheckedtheFunctionwillalwaysbeallowed.
Forexample:
IfyouwanttheMFDScan-to-FolderFunctiontoonlybeavailablewhenavalidatedCACCardisinstalled,
checktheCAC Enable Scan-To-Folder box.
If
youwanttheMFDScan-to-FolderFunctiontobeavailableallthetimewhetheraCACcardisinserted
ornot,unchecktheCAC Enable Scan-To-Folderbox.
ClicktheUpdatebuttonafterallentriesaremade.
CACStar™UserGuideRevA03Copyright2014DigitalImagingTechnology Page9
HoldPrint
Ifenabled,PrintjobswillbeheldintheCACStaruntiltheuserisauthen ticatedattheprinterbyinserting
theirCACcard.Afterauthentication,theuser’sjobswillbeprinted.
CACPrintServer
SetthistotheIPaddressoftheSecurePrintserver.
ServerPrint
Only
Ifenabled,printjobswillonlybeallowedfromtheconfiguredCACPrintServer.Ifnot,jobswillbe
allowedfromanyIPaddress.Forthistooperate,“CACEnablePrinting”mustbeselectedinthe
“Security/MFDFunctionEnabling”menu.
EmailSetup
CACStar™UserGuideRevA03Copyright2014DigitalImagingTechnology Page10
IfyouhaveelectedtocontrolMFDgeneratedemailwithyourCACcards,youwillneedtoconfigurethe
itemshowninthescreenbelow.
SMTPAddressorServerName
SettheIPaddressorServerNameoftheSMTPserver.
SMTPPortNumber
SettheTCPportnumberfor
SMTPcommunications.
UserEmailAddressFrom
Selectthesourcelocationforthe“From”emailaddress.Emailedscanscanbefromeithertheuser’s
ownemailaddressonhisCACcard,orfromtheuser’semailaddressontheLDAPserver.
ForceEmailtoSelf
Choosewhetheryouwanttoforce
allemailedscanstotheuser’sownemailaddress.Ifnotchecked,he
cansendtoanyemailaddress.
Ifthisoptionisnotselected,theusercanselecttherecipientfromtheprinter’sinternaladdressbookor
hecanusetheprintertoentertheemailaddresshewantsto
use.
EncryptEmail
Whensendingemailsofscanneddocuments,choosetoneverencrypt,alwaysencrypt,orPrompton
eachmessageforwhetherornottoencrypt.
WhentheMFDisoperationalandhasbeenconfiguredheretopromptforwhetherornottoencrypt,
thedisplayontheCACreader
willshowEncrypt Email.Line2ofthedisplayshowsNoandcanbetoggled
between
YesandNobypressingtheFkey.Whenthedesiredchoiceisselected,pressthegreenEnter
keytosendtheemailmessage.YouneedtomakethischoiceorpresstheFkeywithin10seconds.If
therearenokeypressesfor10seconds,thesystemwillsendthemessage
unencrypted.
EmailEncryptionType
Choosetheencryptiontypefromeither3DESorAES256.
SignEmail
Whensendingemailsofscanneddocuments,choosetoneversign,alwayssign,orPromptoneach
messageforwhetherornottosign.
LDAPPrimaryCertificateAttribute
SpecifytheprimaryLDAPattributenamewhichshould
beusedtoretrieveacertificate foremail
encryption.
LDAPSecondaryCertificateAttribute
SpecifythesecondaryLD AP attributenamewhichshouldbeusediftheprimaryattributefails.
CACStar™UserGuideRevA03Copyright2014DigitalImagingTechnology Page11
AuthenticationMethod

CACStar™UserGuideRevA03Copyright2014DigitalImagingTechnology Page12
Basic
ThisincludesPINvalidation,cardexpirationcheck,andX.509cardcertificatevalidation.IfanNTP
serverisnotconfiguredontheLAN Side Configurationpage,theexpirationcheckisbypassed.TheBasic
levelofauthenticationisalwaysincludedandcannotberemovedfromtheconfiguration.Insome
installations,thisissufficientauthenticationandistheonlyoneactivated.
OCSP
CheckthisboxtoenableOCSP(OnlineCertificateStatusProtocol)verificationofCACCards.Ifenabled
theOCSPserverwillbeusedtovalidatethecurrentstatusoftheCACcardPKIcertificate.
NOTE:IfOCSPisenabled,youmusthavea
DNSserverconfigured.
RootCertificate
CheckthisboxtoenableRootCertificateverificationofCACCards.Ifenabled,thecertificatechain,
includingtheRootCACertificatewillbeusedtovalidatetheCACcardPKIcertificate.Thecardisalso
checkedtobecertaintheCACcertificatehasavalid
privatekey.
NOTE:IfRoot Certificateisenabled,allIssuerCertificatesandRootCACertificatechainsforcardsinuse
atthisinstallationmustbeloadedintotheCACStar.Ifnot,VerifyFailureswilloccur.
LDAP
CheckthistoenableuseoftheActiveDirectoryserverforadditionalauthentication
LDAP
ServerIP:IPaddressoftheLDAPserver.
LDAPServerPort: PortnumberoftheLDAPserver.Thedefaultis389.
LDAPQueryUserName: UserNamefortheLDAPserviceaccountlogin.
LDAPQueryPassword: PasswordfortheLDAPserviceaccountlogin.
LDAPSearchBase: Definesthelocationin
thedirectorywhereasearchwill
start.
Example:OU=Users,DC=Itek,DC=com
LDAPSearchString: TheSearchStringisusedbytheLDAPservertofindusers.
Therearecertainkeysthatwillbeexpandedtocreatethequery.
Keysare:
%Lexpandstobecometheuser’slastname
%Fexpandstobecometheuser’sfirstname
%Mexpandstobecometheuser’smiddlename
%Eemailaddress
%eEDIPI
LDAPUserIDoptions: Choicesarecn,upn,mail,orname.
DisableLDAPReferrals: Ifthisboxischecked,theReferralssent
byLDAPServerswill
NOTbefollowed.
CACStar™UserGuideRevA03Copyright2014DigitalImagingTechnology Page13
Kerberos
IfLDAPisenabled,youmaychoosetouseKerberosauthenticationfortheLDAPserver.
KDCServerIP: IPaddressoftheKerberosserver
KDCServerPort: PortnumberoftheKerberosserver.Thedefaultis88.
KDCRealm: KerberosRealm
KDCPrincipal: UserName.Thiscan
beeithertheCNortheEDIPI,orSan
 Principal.
PKINITWin2K
Thesettingaffectsthe"PublicKeyCryptographyforInitialAuthentication"inKerberos.Check
thisboxifyouareusingaWindows2000KDCServerand/orneedtousetheolderKerberos
PKINITcommand/replyset.
DisableReverseDNS
Lookups:
CheckthisboxtodisableReverseDNSLookupsbyKerberos(andLDAP).Thisisonlynecessaryif
thereisaproblemusingReverseDNSLookups.Ifthisboxischecked,hostnamesmustbeused
for"KDCServer"and"LDAPServer"inputfields.
MFDLDAPKerberosProxy
Ifenabledand
Kerberosisenabled,LDAPsearchesfromtheMFDwillbemodifiedtouse
KerberosAuthentication.TheLDAPServerandPortsettingsmustbecorrect.
MFDSMBKerberosProxy
IfenabledandKerberosisenabled,networkscan(SMB)operationsfromtheMFDwillbe
modifiedtouseKerberosauthentication.
DefaultSMB
ServerAddress
TheIPaddressorservernameforthedefaultSMBserver.ThisaddresswillbeusediftheSMB
serveraddresscannotbeobtainedfromtheprinter.
DefaultSMBServiceName
TheServiceNameforthedefaultSMBserver,e.g.myshare$.Thisnamewillbeusedasthe
principal
forKerberosauthenticationiftheServi ceNamecannotbeobtainedfromtheprinter.
DefaultSMBPassword
ThePasswordforthedefaultSMBserver.
Thisisonlyneededif"MFDSMBKerberosProxy"isNOTchecked‐ANDthe"SMBFolderName"
isconfigured.
SMBFolderName
IfaFolderNameis
configured,anyfoldernamethatisusedbytheprinterwillbereplacedwith
thisFolderName.Keywordscanbeusedinthisdefinitionsothefoldernameis"customized"
basedonthevalidateduser.
Thesekeywordsare:
%L‐expandstotheuser'slastname
%F‐expandstotheuser's
firstname
%M‐expandstotheuser 'smiddlename
CACStar™UserGuideRevA03Copyright2014DigitalImagingTechnology Page14
%E‐expandstotheuser'sEmail
%e‐expandstotheuser'sEDIPI
%I‐expandstotheuser'sPICIdentification
%u‐expandstoLDAPAttributevalue
SMBFolderLDAPAttribute
IfaFolderNameisconfiguredusing%u,theLDAPAttributedefinedherewillbeused
toretrievethepath
valueforthe%ufield.Careshouldbetakenwhenusing
"\"charactersbeforeorafterthe%u‐basedonwhethertheLDAPAttribute
valueincludes"\"character(s)atthebeginningorend.
SSLCACertificateChecking
Ifenabled,thehostSSLcertificatewillbeverifiedagainsttheCAcertificate.
Therefore,theapplicable
CAcertificatemustbeloadedintotheCACStar.

CACStar™UserGuideRevA03Copyright2014DigitalImagingTechnology Page15
UserLogging
UserLoggingprovidesameanstocreate,viewordeleteauserlogfiletotrackuseractivity.Ifthisis
enabled,itwilllogthedate,username,andotherinformation.Thelogcanbedownloadedinacsvfile
formatforviewing.
UploadCertificate
UsethispagetoloadIssuerandRootCertificateAuthorityCertificatesintoCACStar.
CACStar™UserGuideRevA03Copyright2014DigitalImagingTechnology Page16
PKCS7,X509,PEMandDERformatsaresupported.
UsetheBrowsebuttontoselecttheCertificatefileonyourPC;thenclicktheUpload Certificatebutton.
Ifyourcertificatesareina.txtfileformat,pleasesendthemtous,andwewillconvertthemtoa
supportedformat.Ifdesired,
wecanpreloadthemintonewunits.
TheCreate Certificates SummarywillcreateatextfilelistingallcertificatesstoredintheCACStar.Thisisa
textfilethatcanbeviewedordownloadedbyselectingtheView Certificates Summarybutton.

CACStar™UserGuideRevA03Copyright2014DigitalImagingTechnology Page17
Administrator
ChangePassword
Usethisfeaturetochangethepasswordfortheadministrator.
WhentheChangePasswordbuttonis
clicked,thenextinternalwebpageaccesswillrequirethisnewpassword.

AdministratorAccess
Thesesettingsallowtheadmintoprovi deadditionalsecuritybylimitingCACStaradminaccessto
specifiedIPaddresses.IftheAllow all IPsboxischecked,anadmincanaccesstheCACStarconfiguration
itemsfromaPCatanyIPaddressifheknowstheIDandpassword.Ifitis
notchecked,theadminmust
accesstheCACStarconfigurationpagesfromtheIPaddressesspecifiedforAdministrator#1or#2.
TheseaddressesmustbeonthesamesubnetastheCACStar.
CACStar™UserGuideRevA03Copyright2014DigitalImagingTechnology Page18
AllowTelnet
IfthisisenabledCACStarwillallowaTelnetsessiontooccur.TheTelnetsessio nwillhappenoverPort
23.TelnetusewithCACStarisintendedfordiagnosticsbythede velopers.
AllowNonSecurePort8080
Ifthisisenabled,CACStarwillusePort8080andHTTPfor
HTML.Otherwise,Port8443andHTTPSwill
beusedforHTML.ChangingthissettingrequiresarebootofCACStar.
DisableFrontPanelConfiguration
Ifthisischecked,CACStarwilldisabletheFrontPanelkeyboardfromchangingtheIPaddress,subnet
mask,andgateway.Viewingofthesesettingsonthefrontpanel
LCDwillstillbeallowed.
CACStar™UserGuideRevA03Copyright2014DigitalImagingTechnology Page19
FirmwareUpdate
Firmwareisstoredinflashmemoryandcanbeupdatedasnecessaryforadditionofnewfeatures.The
CACStar.cfgfilemayalsobeuploaded.ItisatextfilethatcontainstheCACStarconfigurationitems.
CreateandExportCurrentConfiguration
CreateConfigFilewillcreateaconfigura tionfilecontainingallcurrentsettingsexceptLANIPAddress,
LANMask,andLANGateway.Thus,theConfigfilecanbeusedtoconfigureotherCACStars.The
passwordsareencryptedsotheymaynotbeedited.Thefirstlineofthefilemustnotbe
edited.The
MACaddressandSerialNumberaredisplayedforinformationpur posesonlyandwillnotbeusedasa
configurationitem.
ExportConfigFilewillallowthisfiletobesavedoutsideCACStar.Thisfileshouldbesavedasatextfile.
Itmaybeeditedwithatext
editor.ItmayalsobeuploadedtoCACStaratalaterdate.
CreateandExportCurrentCertificates
CreateCertificatesFilewillcreateafilecalledCACStarCerts.tar.gzwhichwillcontainallcurrentlyloaded
certificates.ExportCertificatesFilewillallowthisfiletobesavedoutsideCACStar.Thisfilemaybe
loadedto
anyCACStar.
CACStar™UserGuideRevA03Copyright2014DigitalImagingTechnology Page20
TechnicalSupport
Forhelpobtainingthecorrectfirmwareordocumentation,contactDell’sProSupportHelpDeskby
calling18665163115,orbysendingemailto[email protected]
ThispageisusedtoobtainLogFilesandCaptureFilestohelpdiagnosenetworkandconfiguration
concerns.Useofthesefeaturesisnormallyinconjunctionwithtechnicalsupportfromyourvendor.
CreateSysLogFile
AlogfilecanbecreatedforusebyCACStar
Engineeringtohelpres o lveproblemsthatmayoccur.
EthernetCapture
AnEthernetCapturefilecanbecreatedcontaininginformationfromeithertheLocalportortheLAN
portforusebyCACStar
Engineeringincustomersupportactivities.
PingMFD
CACStarpingstheMFDoveritsinternallocallinktoverifycommunicationbetweenCACStarandthe
MFD.
  • Page 1 1
  • Page 2 2
  • Page 3 3
  • Page 4 4
  • Page 5 5
  • Page 6 6
  • Page 7 7
  • Page 8 8
  • Page 9 9
  • Page 10 10
  • Page 11 11
  • Page 12 12
  • Page 13 13
  • Page 14 14
  • Page 15 15
  • Page 16 16
  • Page 17 17
  • Page 18 18
  • Page 19 19
  • Page 20 20
  • Page 21 21
  • Page 22 22
  • Page 23 23
  • Page 24 24
  • Page 25 25
  • Page 26 26
  • Page 27 27

Dell C3765dnf Color Laser Printer User guide

Type
User guide

Ask a question and I''ll find the answer in the document

Finding information in a document is now easier with AI