background image

Troubleshooting

Xerox® Smart Card
Installation Guide

38

After Installation:

Problem

Possible Cause

Solution

Authentication failures

• Incorrect PIN has been 

entered.

• Retry entering the correct PIN. 

If problem persists, contact the 
System Administrator for 
advice.

• Card is locked due to too many 

failed PIN attempts.

• Contact Registration Authority 

to reload or to get a new card.

• Unable to find identity 

certificate.

• Identity certificate has been 

revoked.

• Authentication with Domain 

Controller Failed.

• Check network cable is firmly 

connected.

• Contact the System 

Administrator.

• Unable to validate server 

certificate.

Smart Card

 Authentication 

System Failed.

• Authentication Failed.

• System Administrator has not 

selected All Features or 
Scanning Service Only.

• Contact the System 

Administrator.

Time for date mismatch error

• There is a mismatch between 

the time and date setting on 
the Xerox WorkCentre and the 
authentication server time or 
date setting.

• Verify that Network Time 

Protocol is properly set up.

• Verify that GMT offset is 

correct for your region, refer to 

Configure the date and time to 
update automatically 

on 

page 13.

• Verify that GMT offset is 

correct for Daylight Savings 
Time.

• Contact  your  System 

Administrator.

Cannot see the Internet Services 
web page after software upgrade

• IP Address incorrect or has 

been reset.

• Check the IP Address printed 

on the configuration report. 
Ensure the DHCP settings 
match your site settings.

• To print a configuration report 

at the Xerox WorkCentre.

Summary of Contents for WORKCENTRE 5030

Page 1: ...rox Smart Card Installation Guide Xerox WorkCentre 5632 5638 5645 5655 5665 5675 5687 Xerox WorkCentre 5735 5740 5745 5755 5765 5775 5790 Xerox WorkCentre 5135 5150 Xerox WorkCentre 5030 5050 software version 05 004 xx xxx ...

Page 2: ...ot be reproduced in any form without permission of Xerox Corporation XEROX and XEROX and Design are trademarks of Xerox Corporation in the United States and or other countries Changes are periodically made to this document Changes technical inaccuracies and typographic errors will be corrected in subsequent editions Document version 7 0 September 2011 ...

Page 3: ...ifications 10 Electrical Requirements 10 3 Installation Software Enablement 12 Configuring the Smart Card 13 Hardware Installation 26 Using the Smart Card 34 4 Troubleshooting Fault Clearance 36 Locating the Serial Number 36 Troubleshooting Tips 37 During Installation 37 After Installation 38 A Retrieving the Certificate from a Domain Controller or OCSP Server B Determining the Domain in which you...

Page 4: ...Xerox Smart Card Installation Guide 4 ...

Page 5: ...on Number PIN at the device This provides added security in the event that a card is lost or stolen Once validated a user is logged into the Xerox device for all walk up features The system allows for functions to be tracked for an added layer of security The Xerox Smart Card enablement kit integrates with Xerox multifunction printers and existing smart and personal identity verification cards and...

Page 6: ... a If your machine has software level 05 003 xx xxx the Smart Card software can not be installed without first upgrad ing the machine software Please contact your Xerox Representative for details 05 004 xx xxx Xerox WorkCentre 5632 5638 5655 5665 5675 5687 Multifunction 21 113 xx xxxb 21 120 xx xxx 25 054 xx xxx b If your machine has software level 21 113 02 070 or lower the Smart Card software ca...

Page 7: ... V5 2D 64K Oberthur OCS Galactic V1 32K V1 Applets Oberthur Cosmo V4 32K V1 Applets Schlumberger Axalto Cyberflex V2 32K V1 Applets Other card types may function with the solution but have not been validated Supported Card Types Supported Card Readers The customer is responsible for providing a card reader for each Xerox device The following card readers are compatible with the solution Gemplus Ge...

Page 8: ...your device to the network and installing optional features This guide is intended for System Machine Administrators User Guide provides detailed information about all the features and functions on the device This guide is intended for general users Most answers to your questions will be provided by the support documentation supplied on disc with your product Alternatively you can contact the Xero...

Page 9: ...DC after validation of the user Item Supplier Compatible Card Reader refer to Supported Card Types on page 7 Customer Compatible Access Card refer to Supported Card Types on page 7 Customer Smart Card enablement kit 498K17544 one for each Xerox device Xerox Feature Enable Key Xerox TCP IP enabled on the device Customer DNS Host name or static IP address assigned Customer Network Settings to be che...

Page 10: ...revents rogue DCs masquerading as the real DC Note Certificates are often obtained from the Information Technology professionals that support your organization If you are unable to obtain the required certificates refer to the process outlined in Appendix A You can determine the domain that you are registered in using the process outlined in Appendix B Server Specifications Prior to installation e...

Page 11: ...follow in sequence Software Enablement Use the Feature Enable Key to enable the Smart Card to be configured Configuring Smart Card Enabling the Smart Card function and customizing the settings Hardware Installation Unpacking the Smart Card Enablement kit and installing the card reader device Using Smart Card Instructions on how to use the card reader device to access the device functions ...

Page 12: ...ption c Select Smart Card If necessary use More to navigate to the option d When prompted select the Option Kit Number entry box and enter the unique Feature Enable Key provided on the inside cover of the Smart Card Enablement Guide e Select Exit Tools Xerox WorkCentre 5735 5740 5755 5765 5775 5790 1 Access Tools at the device a At the WorkCentre press the Machine Status button on the control pane...

Page 13: ...me to update automatically a Select Connectivity b Select Protocols and then NTP Note A pop up window may appear requiring you to login c Ensure the NTP Enabled box is checked for the Network Time Protocol option then enter the IP Address or the NTP Host Server Name In most cases this will be your DHCP server and it will provide the time in Greenwich which must be corrected for your time zone by t...

Page 14: ...755 5765 5775 5790 a At the WorkCentre press the Machine Status button on the control panel b Select the Tools tab c Enter the appropriate User ID and Password to access Tools Note The default user name and password are admin and 1111 d Select Device Settings e Select General f Select Date Time Date Select the Format required and enter the Month Day and Year Time Enter the correct Hour and Minutes...

Page 15: ...5687 Xerox WorkCentre 5135 5150 and Xerox WorkCentre 5735 5740 5755 5765 5775 5790 refer to page 16 Xerox WorkCentre 5030 5050 a Select Security and select Authentication Configuration Note If this is the first time you are entering the authentication wizard you may be prompted to enter a password b Enter the password and select Next c Select Next d Select CAC PIV and select Next e Select Configur...

Page 16: ...665 5675 5687 Xerox WorkCentre 5135 5150 and Xerox WorkCentre 5735 5740 5755 5765 5775 5790 System Software 06x 130 xxx xxxxx a Select Security and select Authentication Configuration Note If this is the first time you are entering the authentication wizard you may be prompted to enter a new password that is different from the default password b Enter new password and select Next c Select Next d S...

Page 17: ...th OCSP a Uncheck all three Domain Controller OCSP Certificate Validation boxes and add the required Domain Controller b Select Save Go back and add other Domain Controllers as required If you wish to validate the DC against OCSP before validation of the user a Check the box for Validate Before CAC PIV Authentication b Enter the OCSP Server Service URL details Note Depending on your environment th...

Page 18: ...ion environment f Enter the IP Address or enter the Domain Controller Host Name this must be the fully qualified Host Name g Ensure Port 88 is selected unless your Kerberos Port is different h Enter the Domain Name this must be the fully qualified Domain Name i Select Save If you selected the option that the Domain Controller Signature must match the uploaded Domain Controller Certificate then a f...

Page 19: ... the Domain Controller search order select the controller and use the up and down arrows on the right side of the screen to promote or demote the controller order 7 Upload certificates Note These steps are Read Only if using any of the OCSP Certificate Validation options Load the DC root and intermediate certificates and the OCSP root and intermediate certificates a Select the Link to Security Tru...

Page 20: ...onfigured You are now ready to install the Smart Card hardware using the instructions starting on page 26 Xerox WorkCentre 5735 5740 5755 5765 5775 5790 System Software 06x 131 xxx xxxxx 1 At the WorkCentre press the Machine Status button on the control panel 2 Select the Tools tab 3 Enter the appropriate User ID and Password to access Tools Note The default user name and password are admin and 11...

Page 21: ...Xerox Machine or Remotely on the Network 8 Click Save 9 A list of configuration settings appears at the bottom of the Authentication Setup page 10 Click Edit to configure any settings that are marked in red text as Required Not Configured Configuring Domain Controller Settings 1 In the related services table on the Authentication Setup page click Edit on the Domain Controller s row The domain cert...

Page 22: ...k Next 3 On the Required Settings page type the URL of the OCSP server 4 To ensure that the printer can communicate with the OCSP server and the domain controller configure your proxy server settings if necessary 5 Click the appropriate link to install the root CA certificates for the OCSP server and your domain controller 6 Click Save to apply the new settings and return to the Authentication Set...

Page 23: ...lt e mail address to populate the field If required the System Administrator can change the setting to obtain the user s e mail address from the Smart Card only or from the Network Address Book LDAP only 1 In the related services table on the Authentication Setup page click Edit on the Acquiring Logged in User s E mail Address row 2 Select the option required for obtaining the logged in user s e m...

Page 24: ... 2 To enable E mail Encryption under E mail Encryption Enablement select an option Always On Not editable by user Restrict users from turning E mail Encryption on or off at the control panel Editable by user Allow users to turn E mail Encryption on or off at the control panel 3 If you select Editable by user select the default setting for users at the control panel Under E mail Encryption Default ...

Page 25: ...e control panel Editable by user Allow users to turn E mail Signing on or off at the control panel 6 If you select Editable by user specify the default setting for users at the control panel Under E mail Signing Default select On or Off 7 Click Save to apply the new settings and return to the Authentication Setup page Click Cancel to return to the Authentication Setup page The Smart Card settings ...

Page 26: ...lowing instructions 1 Unpack the Smart Card Enablement Kit The kit contains the following items Xerox Smart Card Enablement Guide 1 Four Dual Lock Fastener pads Velcro 2 Three Cable Ties 3 One Ferrite Bead 4 Ensure you have read the licence agreement and agree to the terms and conditions specified prior to installation ...

Page 27: ...being installed There are four types of card reader available one upright model or three slimline models Locate the device being installed and ensure it has been configured Note The System Administrator should configure the cards prior to the card reader being installed on the machine ...

Page 28: ...Installation Xerox Smart Card Installation Guide 28 3 Attach the ferrite bead to the reader cable Note The ferrite bead should be clipped onto the cable directly behind the connector ...

Page 29: ... the fasteners to the card reader device Fasteners have been provided to secure the card reader to the Xerox device Peel back the fastener backing strip Position the fastener on the under side of the card reader as shown Repeat for each of the fasteners supplied ...

Page 30: ...Installation Xerox Smart Card Installation Guide 30 5 Remove the fastener backing strips When all the fasteners have been attached to the card reader remove the backing strips on each of the fasteners ...

Page 31: ...evice do not fix in place at this point Position the card reader in a suitable location ensure it does not obstruct the opening of the document handler side cover Check the cable has sufficient length to connect to the rear of the network controller Once it is in a suitable location press firmly on the card reader to fix it in place ...

Page 32: ...de 32 7 Connect the card reader to the Xerox device Insert the USB connection into the slot provided on the rear of the network controller Use the cable ties provided to ensure the cabling is neat and tidy The hardware installation is now complete ...

Page 33: ... card reader and the software has been installed and configured the Card Reader Detected screen displays on the Xerox WorkCentre local user interface Select OK Smart Card is now ready for use Note If the card reader is not detected refer to Troubleshooting Tips on page 37 for information ...

Page 34: ... session automatically after a specified period of inactivity Follow the instructions below to use the Smart Card 1 The Authentication Required window may display on the touch screen depending on your machine configuration 2 Insert your card into the card reader 3 Use the touch screen and numeric keypad to enter your PIN and then select Enter If the card and PIN are authenticated access is granted...

Page 35: ...ader is only compatible with network connected products Ensure the Card Reader is plugged into the Network Controller Refer to Connect the card reader to the Xerox device on page 32 for instructions Do not position the Card Reader in direct sunlight or near a heat source such as a radiator Ensure the Card Reader does not get contaminated with dust and debris ...

Page 36: ...er assistance For problems relating to the Xerox device contact the Xerox Welcome and Support Center The Welcome and Support Center will want to know the nature of the problem the Machine Serial number the fault code if any plus the name and location of your company Contact Xerox using the numbers 1 800 ASK XEROX or 1 800 275 9376 Locating the Serial Number 1 Press the Machine Status button on the...

Page 37: ... Card reader is installed but no message displays on the User Interface Card reader is faulty Try a different card reader Contact the System Administrator Card reader connection is faulty Check the cable is plugged in correctly Refer to Hardware Installation on page 26 for instructions Unplug the card reader cable then plug back in Plug the card reader into a different USB port Card reader is not ...

Page 38: ... Failed Authentication Failed System Administrator has not selected All Features or Scanning Service Only Contact the System Administrator Time for date mismatch error There is a mismatch between the time and date setting on the Xerox WorkCentre and the authentication server time or date setting Verify that Network Time Protocol is properly set up Verify that GMT offset is correct for your region ...

Page 39: ...of the Domain Controller 636 For example https 111 222 33 44 636 where 111 222 33 44 is the IP address of the appropriate server A Security Alert warning window is displayed similar to the one shown 2 Click on View Certificate to proceed If the window does not display double click on the padlock icon in the lower right hand corner of your browser window The Certification Information window is disp...

Page 40: ...t the Details tab Record the name of the Certificate Authority CA that issued this certificate the Issuer A certificate from this CA will be required during Smart Card setup 4 Select the Copy to File button The Certification Export Wizard is displayed 5 Select Next 6 Select Base 64 encoded X 509 CER 7 Select Next ...

Page 41: ...ename for the Certificate and select Save 10 Select Next 11 Select Finish The Certificate is retrieved from the server and saved in the selected directory A pop up message will confirm that the Certificate has been successfully saved Once saved the Certificate can be loaded onto the device This process can be repeated to retrieve the Certificates from each of the required servers ...

Page 42: ...Retrieving the Certificate from a Domain Controller or OCSP Server Xerox Smart Card Installation Guide 42 ...

Page 43: ...drop down list select Properties When the System Properties window opens click on the Computer Name tab Beneath the Full Computer name is the Domain Name 3 Copy and paste the Domain Name directly into the CAC setup page on the Internet Services user interface Refer to Configuring the Smart Card on page 13 for instructions 4 Select Cancel to close the System Properties window ...

Reviews: