Chapter 11
11-34
Default Authentication overview
Default Authentication is the login service that is selected when Department ID management is being used, or when no authentication function has been set. When
Department ID management has been set [ON] in the MEAP device user mode, by entering a seven digit department ID for each department, and a password number
for each department ID, access to the MEAP device can be restricted to those users who enter the code numbers. The department ID and password number can be
entered using the MEAP device touch panel display and Remote UI.
SSO-H (Single Sign-On-H) overview
This is a merger of the existing SDL and SSO login services and has the following features.
- Both the domain authentication and local device authentication login services can be used.
- There is no need to have a separate SA server.
- Login is not via SA, so SSO-H refers directly to DNS for authentication.
- Kerberos and NTML protocols are supported.
- The following three authentication methods may be selected from.
Domain authentication
Local device authentication
Domain authenti local authentication
SSO overview
This is a login service that can be operated on the Active Directory environment network domain and on iR devices. The following user authentication methods
can be selected from.
Domain authentication
Local device authentication
Domain authenti local device authentication
Authentication methods
Both SSO-H and SSO can use multiple authentication methods, and the user can toggle between them from a Web browser. (Refer to the MEAP Authentication
System Settings Guide 'User Authentication Method Settings'.)
Domain authentication
This is a form of user authentication which operates in collaboration with the domain controller on the Active Directory environment network and, as soon as the
iR device is logged into, carries out authentication of the domain on the network. In addition to users belonging to the domain that includes the iR device, users
belonging to domains that have a reliable relationship with the domain (multi-domain) can also be authenticated. The domain name of the login destination can be
selected by the users themselves upon login.
The function makes use of options Net Spot Accountant/ iW Accounting Manager/ iW EMC Accounting MAnagement Plig-in to enable analysis and management
of the iR device usage status.
Depending on the login service, different protocols are used.
- SSO-H
- Kerberos:LLS/RLS/ILS
- NTLMV2:WLS(Web Service Login Service. WLS can only be used in collaboration with iW AMS Ver2 AMS printer driver add-in and iWEMC user
management plug-in.)
- SSO
- NMTLM only
User information acquisition is done by LADP, so the Active Directory LDAP port needs to be made accessible.
If LDAP connection fails, the authentication will end in error.
No. of supported domains: 200 (unchanged from SSO)
Site access supported.
Important information when using conventional SSO and SDL
- When the login method setting is for SDL, the information registered in SDL must match the Department ID management user information (department ID and
password).
- When the login method setting is for SDL and SSO, Department ID management needs to be [OFF] before making any changes. To use SDL and Department ID
management together, switch the login service to SDL and then turn the Department ID management ON.
- To run Department ID management when the setting is for SSO, the options Net Spot Accountant / imageWARE Accounting Manager are required.
- When the setting is SSO, the option card reader cannot be used.
- When using SSO, the clock settings of the server managing the Active Directory and the MEAP device (and the PC used to log in), must be matched. If there is a
time difference of greater than 30 minutes in the clock settings, an error will be generated when login is attempted with SSO.
- When the setting is for SDL or SSO, startup may take a little longer.
...To use the SEND function when the setting is for SDL and SSO, when sending email, mail addresses need to be programmed against each user. If they are not,
email cannot be sent. Note, however, that when sending i-Fax, the mail addresses set in the device are used.
- The system configuration is different from previous SSO, so individual management is required.
- If MEAP is supported, installation into devices prior to SSO-H release is possible.
- Data porting of user information that was being used with the earlier SSO local device authentication and SDL can be done by exporting/ importing. However,
application settings information cannot be ported.
SSO was pre-installed in earlier released devices, but from iR3245 onward it will only be provided with the Administrator's CD.
The factory shipment setting is 'Domain authenti local device authentication'. In order to provide increased security, as soon as SSO is used, it is recommended
that the administrator's user name and password in local device authentication be changed from the factory shipment settings as soon as possible.
Summary of Contents for iR3245
Page 1: ...Jul 3 2008 Service Manual iR3245 3235 3230 3225 Series...
Page 2: ......
Page 6: ......
Page 25: ...Chapter 1 Introduction...
Page 26: ......
Page 28: ......
Page 64: ......
Page 65: ...Chapter 2 Installation...
Page 66: ......
Page 120: ......
Page 121: ...Chapter 3 Basic Operation...
Page 122: ......
Page 124: ......
Page 128: ......
Page 129: ...Chapter 4 Main Controller...
Page 130: ......
Page 132: ......
Page 134: ...Chapter 4 4 2 F 4 1 1 5 8 9 11 14 12 3 4 10 2 13 7 15 16 17...
Page 152: ......
Page 153: ...Chapter 5 Original Exposure System...
Page 154: ......
Page 184: ......
Page 185: ...Chapter 6 Laser Exposure...
Page 186: ......
Page 188: ......
Page 197: ...Chapter 7 Image Formation...
Page 198: ......
Page 227: ...Chapter 8 Pickup Feeding System...
Page 228: ......
Page 232: ......
Page 244: ...Chapter 8 8 12 For iR3245 3235 3230 F 8 14 1 2 3 4...
Page 261: ...Chapter 8 8 29 10 11 12 13 14 3 1 2 4 5 4 4 1 2 3 5 4 1 2 3 5 5 4 1 2 3 5 4 1 2 3 5...
Page 278: ......
Page 279: ...Chapter 9 Fixing System...
Page 280: ......
Page 282: ......
Page 297: ...Chapter 10 External and Controls...
Page 298: ......
Page 302: ......
Page 315: ...Chapter 10 10 13 2 Uncheck SNMP Status Enabled F 10 11...
Page 342: ......
Page 343: ...Chapter 11 MEAP...
Page 344: ......
Page 346: ......
Page 397: ...Chapter 12 e maintenance imageWARE Remote...
Page 398: ......
Page 400: ......
Page 408: ......
Page 409: ...Chapter 13 Maintenance and Inspection...
Page 410: ......
Page 412: ......
Page 424: ...Chapter 13 13 12...
Page 425: ...Chapter 14 Standards and Adjustments...
Page 426: ......
Page 428: ......
Page 436: ......
Page 437: ...Chapter 15 Correcting Faulty Images...
Page 438: ......
Page 440: ......
Page 465: ...Chapter 16 Self Diagnosis...
Page 466: ......
Page 468: ......
Page 493: ...Chapter 17 Service Mode...
Page 494: ......
Page 498: ......
Page 690: ......
Page 691: ...Chapter 18 Upgrading...
Page 692: ......
Page 694: ......
Page 738: ...Chapter 18 18 44...
Page 739: ...Chapter 19 Service Tools...
Page 740: ......
Page 742: ......
Page 744: ......
Page 745: ...Jul 3 2008...
Page 746: ......