
Configuring Settings for Key Pairs and Digital
Certificates
1053-0AR
In order to encrypt communication with a remote device, an encryption key must be sent and received over an
unsecured network beforehand. This problem is solved by public-key cryptography. Public-key cryptography ensures
secure communication by protecting important and valuable information from attacks, such as sniffing, spoofing, and
tampering of data as it flows over a network.
Key Pair
A key pair consists of a public key and a secret key, both of which are required for encrypting or
decrypting data. Because data that has been encrypted with one of the key pair cannot be
returned to its original data form without the other, public-key cryptography ensures secure
communication of data over the network. Up to five key pairs can be registered ( Using CA-
issued Key Pairs and Digital Certificates(P. 287) ). On this machine, you can also perform
"Generate Network Communication Key" and "Generate Key and Certificate Signing Request
(CSR)" ( Generating Key Pairs(P. 280) ).
CA Certificate
Digital certificates including CA certificates are similar to other forms of identification, such as
driver's licenses. A digital certificate contains a digital signature, which enables the machine to
detect any spoofing or tampering of data. It is extremely difficult for third parties to abuse
digital certificates. A digital certificate that contains a public key of a certification authority (CA)
is referred to as a CA certificate. CA certificates are used for verifying the device the machine is
communicating with for features such as printing with AirPrint. Up to five CA certificates can be
registered ( Using CA-issued Key Pairs and Digital Certificates(P. 287) ).
◼
Key and Certificate Requirements
The certificate contained in a key pair generated with the machine conforms to X.509v3. If you install a key pair or a CA
certificate from a computer, make sure that they meet the following requirements:
Format
●
Key pair: PKCS#12
*1
●
CA certificate: X.509v1 or X.509v3, DER (encoded binary), PEM
File extension
●
Key pair: ".p12" , ".pfx" or ".cer"
●
CA certificate: ".p12" , ".pfx" or ".cer"
Public key algorithm
(and key length)
RSA (512 bits, 1024 bits, 2048 bits, or 4096 bits)
Certificate signature algorithm
SHA1-RSA, SHA256-RSA, SHA384-RSA
*2
or SHA512-RSA
*2
Certificate thumbprint algorithm SHA1
*1
Requirements for the certificate contained in a key pair are pursuant to CA certificates.
*2
SHA384-RSA and SHA512-RSA are available only when the RSA key length is 1024 bits or more.
The machine does not support use of a certificate revocation list (CRL).
Linking with Mobile Devices (imageRUNNER 2204F / 2204N / 2004N)
279
Summary of Contents for imageRunner 2204F
Page 28: ...Control Panel 1053 00A imageRUNNER 2204F 2204N 2004N Basic Operations 20...
Page 56: ...You can use only the paper printed with this machine Basic Operations 48...
Page 59: ...Basic Operations 51...
Page 100: ...LINKS Basic Copy Operations P 77 2 Sided Copying imageRUNNER 2204F 2204N 2004N P 88 Copying 92...
Page 103: ...Basic Copy Operations P 77 Copying 95...
Page 108: ...Basic Copy Operations P 77 Copying 100...
Page 213: ...Printing a Document P 174 Using the Machine as a Printer 205...
Page 246: ...LINKS Configuring Scan Settings in ScanGear MF P 239 Using the Machine as a Scanner 238...
Page 279: ...6 Click Print Printing starts Linking with Mobile Devices imageRUNNER 2204F 2204N 2004N 271...
Page 283: ...6 Click Fax Fax sending starts Linking with Mobile Devices imageRUNNER 2204F 2204N 2004N 275...
Page 358: ...4 Click Edit 5 Specify SNMPv1 settings Network imageRUNNER 2204F 2204N 2004N 350...
Page 388: ...LINKS Configuring Printer Ports P 333 Security 380...
Page 394: ...Registering Address Book from Remote UI imageRUNNER 2204F P 416 Security 386...
Page 483: ...Troubleshooting 475...
Page 531: ...Page Setup tab Paper Type Plain L Troubleshooting 523...
Page 612: ...Appendix 604...
Page 624: ...Appendix 616...
Page 637: ...10 this software is based in part on the work of the Independent JPEG Group...