Lexmark MS818 Embedded Web Server Administrator s Guide - Page 42

Managing certificates and other settings

Page 42 highlights

Securing printers 42 Setting date and time Kerberos servers require key requests to have a recent time stamp (usually within 300 seconds). Therefore, the printer clock must be in sync or closely aligned with the KDC system clock. You can update the printer clock settings manually. You can also set it to use Network Time Protocol (NTP) to sync automatically with a clock that is also used by the Kerberos server. Note: We recommend using an NTP server. 1 Access the date and time settings. Do either of the following: • From the Embedded Web Server, click Settings > Security > Set Date and Time. • From the home screen, navigate to the menu screen, and then click Security > Set Date and Time. Note: When accessing the menu screen, log in as an administrator. 2 To manage the settings manually, enter the correct date and time in YYYY-MM-DD HH:MM format, and then select a time zone from the drop‑down menu. Notes: • Entering manual settings automatically disables the use of NTP. • If you select (UTC+user) Custom from the Time Zone list, then you must configure more settings under Custom Time Zone Setup. 3 If daylight saving time (DST) is observed in your area, then select Automatically Observe DST. 4 If you are located in a nonstandard time zone or an area that observes an alternate DST calendar, then adjust the Custom Time Zone Setup settings. 5 If you want to sync to an NTP server rather than update the clock settings manually, then select Enable NTP. Then type the IP address or host name of the NTP server. 6 If the NTP server requires authentication, then select the preferred method from the Authentication menu. Then click Install MD5 key or Install Autokey IFF params to browse to the file containing the matching NTP authentication. 7 Click Submit to save the changes, or click Reset Form to restore the default settings. Managing certificates and other settings The Certificate Management menu is used for configuring printers to utilize certificates for establishing SSL, IPSec, and 802.1x connections. Additionally, devices utilize certificates for LDAP over SSL authentication and address book look ups. Certificates are used by network devices to securely identify other devices. Certificate Authorities (CA) are trusted locations established on the network that are required in secure environments. Otherwise, the default device certificate is used to identify devices on the network. The process for creating a CA-signed certificate on a device consists of the following activities: 1 Loading of the CA certificate for a certificate authority into the device 2 Creating a Certificate Signing Request (CSR) to obtain a CA-signed device certificate 3 Generating a CA-signed certificate using the CSR by the CA administrator 4 Loading of the CA-signed certificate into the device

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98

Setting date and time
Kerberos servers require key requests to have a recent time stamp (usually within 300 seconds). Therefore,
the printer clock must be in sync or closely aligned with the KDC system clock. You can update the printer clock
settings manually. You can also set it to use Network Time Protocol (NTP) to sync automatically with a clock that
is also used by the Kerberos server.
Note:
We recommend using an NTP server.
1
Access the date and time settings.
Do either of the following:
From the Embedded Web Server, click
Settings
>
Security
>
Set Date and Time
.
From the home screen, navigate to the menu screen, and then click
Security
>
Set Date and Time
.
Note:
When accessing the menu screen, log in as an administrator.
2
To manage the settings manually, enter the correct date and time in
YYYY-MM-DD HH:MM
format, and then
select a time zone from the drop
down menu.
Notes:
Entering manual settings automatically disables the use of NTP.
If you select
(UTC+user) Custom
from the Time Zone list, then you must configure more settings
under Custom Time Zone Setup.
3
If daylight saving time (DST) is observed in your area, then select
Automatically Observe DST
.
4
If you are located in a nonstandard time zone or an area that observes an alternate DST calendar, then
adjust the Custom Time Zone Setup settings.
5
If you want to sync to an NTP server rather than update the clock settings manually, then select
Enable
NTP
. Then type the IP address or host name of the NTP server.
6
If the NTP server requires authentication, then select the preferred method from the Authentication menu.
Then click
Install MD5 key
or
Install Autokey IFF params
to browse to the file containing the matching NTP
authentication.
7
Click
Submit
to save the changes, or click
Reset Form
to restore the default settings.
Managing certificates and other settings
The Certificate Management menu is used for configuring printers to utilize certificates for establishing SSL,
IPSec, and 802.1x connections. Additionally, devices utilize certificates for LDAP over SSL authentication and
address book look ups.
Certificates are used by network devices to securely identify other devices. Certificate Authorities (CA) are
trusted locations established on the network that are required in secure environments. Otherwise, the default
device certificate is used to identify devices on the network.
The process for creating a CA-signed certificate on a device consists of the following activities:
1
Loading of the CA certificate for a certificate authority into the device
2
Creating a Certificate Signing Request (CSR) to obtain a CA-signed device certificate
3
Generating a CA-signed certificate using the CSR by the CA administrator
4
Loading of the CA-signed certificate into the device
Securing printers
42