Lexmark MS818 Embedded Web Server Administrator s Guide - Page 83

RAS and IAS Server

Page 83 highlights

Appendix 83 Note: The following example usage instructions assume that the Certificate Enrollment Web Services is installed on a Windows 2008 R2 server. 1 Open a web browser, and then type the IP address or host name of the printer in the address field. 2 From the Embedded Web Server, click Settings > Security > Certificate Management > Device Certificate Management. 3 Click Advanced Management to use the Automatic Certificate Enrollment application, and then click Request new Certificate. Note: The screen may refresh for 10 to 15 seconds. During this time, the device is contacting the Certificate Enrollment Web Service on the server and capturing the certificate templates that are available to the device. 4 Return to the Device Certificate Management page, and then click Advanced > Templates. 5 Select any of the following displayed template options to use when requesting a certificate: • IPSec-If you want to install a device certificate that is used for IPSec negotiations. • Web Server-If you want to secure any SSL/TLS connections such as the EWS or LDAP over SSL. • RAS and IAS Server-If you want to install a device certificate that is used for 802.1X negotiations. 6 Click Request Certificate. From this screen, you can customize the certificate for this device. Note: If you want to view the template details first, then click View instead of Request Certificate. 7 If necessary, modify the settings from the Request Certificate page. Notes: • The fields that are filled in with the data and the selected check boxes are the template defaults that were pulled from the CA. You can change them if you choose, but remember that the default templates are generally configured with the appropriate settings by the CA administrator. Changing some settings may cause the request to be denied. • The Collapse/Expand Subject Name link is used to change any of the device information that is used to create or generate a certificate. This includes the same information as the Set Certificate Defaults link under Certificate Management. 8 Click Submit to send the Certificate Signing Request (CSR) to the CA. Note: The screen may refresh for 10 to 15 seconds. During this time, the device is contacting the Certificate Enrollment Web Service requesting the CA signed certificate be generated. 9 If successful, you will return to the Advanced page. The new CA‑signed device certificate with the specified name is included in the list of certificates. If not, an error message is displayed. Note: If a template is specified at the server to require CA administrator approval, then a separate table of pending certificates is displayed. A message indicating that a request is pending admin approval is displayed on the Device Certificate Management screen where the certificate is listed. The certificate is not valid until approved. Once approval is granted, the message disappears and the certificate(s) is displayed in the installed certificates table. If you would like to see the information associated with the new certificate, click the link with the certificate name. The Renew link is used to renew the certificate when the current CA certificate is about to expire (default of 2 years).

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98

Note:
The following example usage instructions assume that the Certificate Enrollment Web Services is
installed on a Windows 2008 R2 server.
1
Open a web browser, and then type the IP address or host name of the printer in the address field.
2
From the Embedded Web Server, click
Settings
>
Security
>
Certificate Management
>
Device Certificate
Management
.
3
Click
Advanced Management
to use the Automatic Certificate Enrollment application, and then click
Request new Certificate
.
Note:
The screen may refresh for 10 to 15 seconds. During this time, the device is contacting the
Certificate Enrollment Web Service on the server and capturing the certificate templates that are available
to the device.
4
Return to the Device Certificate Management page, and then click
Advanced
>
Templates
.
5
Select any of the following displayed template options to use when requesting a certificate:
IPSec
—If you want to install a device certificate that is used for IPSec negotiations.
Web Server
—If you want to secure any SSL/TLS connections such as the EWS or LDAP over SSL.
RAS and IAS Server
—If you want to install a device certificate that is used for 802.1X negotiations.
6
Click
Request Certificate
. From this screen, you can customize the certificate for this device.
Note:
If you want to view the template details first, then click
View
instead of
Request Certificate
.
7
If necessary, modify the settings from the Request Certificate page.
Notes:
The fields that are filled in with the data and the selected check boxes are the template defaults that
were pulled from the CA. You can change them if you choose, but remember that the default
templates are generally configured with the appropriate settings by the CA administrator. Changing
some settings may cause the request to be denied.
The Collapse/Expand Subject Name link is used to change any of the device information that is used
to create or generate a certificate. This includes the same information as the Set Certificate Defaults
link under Certificate Management.
8
Click
Submit
to send the Certificate Signing Request (CSR) to the CA.
Note:
The screen may refresh for 10 to 15 seconds. During this time, the device is contacting the
Certificate Enrollment Web Service requesting the CA signed certificate be generated.
9
If successful, you will return to the Advanced page. The new CA
signed device certificate with the specified
name is included in the list of certificates. If not, an error message is displayed.
Note:
If a template is specified at the server to require CA administrator approval, then a separate table
of pending certificates is displayed. A message indicating that a request is pending admin approval is
displayed on the Device Certificate Management screen where the certificate is listed. The certificate is
not valid until approved. Once approval is granted, the message disappears and the certificate(s) is
displayed in the installed certificates table.
If you would like to see the information associated with the new certificate, click the link with the certificate
name. The Renew link is used to renew the certificate when the current CA certificate is about to expire (default
of 2 years).
Appendix
83