Lexmark X652DE Common Criteria Installation Supplement and Administrator Guide - Page 40

The Domain Controller Issuing Certificate has not been installed

Page 40 highlights

"The KDC and MFP clocks are different beyond an acceptable range; check the MFP's date and time" error message This error indicates the printer clock is more than five minutes out of sync with the domain controller clock. Verify the date and time on the printer: 1 From the Embedded Web Server, click Settings > Security > Set Date and Time. 2 If you have manually configured date and time settings, verify and correct as needed. Make sure the time zone and daylight savings time settings are correct. Note: If your network uses DHCP, verify that NTP settings are not automatically provided by the DHCP server before manually configuring NTP settings. 3 If you have configured the printer to use an NTP server, verify that those settings are correct, and that the NTP server is functioning correctly. "Kerberos configuration file has not been uploaded" error message This error occurs when PKI Authentication is configured to use the Device Kerberos Setup, but no Kerberos file has been uploaded 1 From the Embedded Web Server, click Settings > Embedded Solutions > PKI Authentication > Configure. 2 If the Simple Kerberos Setup has been configured in PKI Authentication, clear the Use Device Kerberos Setup check box, and then click Apply. 3 If a Kerberos configuration file is needed: a From the Embedded Web Server, click Settings > Security > Security Setup >Kerberos 5. b Under Import Kerberos File, Browse to locate the appropriate krb5.conf file, and then click Submit. Users are unable to authenticate THE REALM SPECIFIED IN THE KERBEROS SETTINGS IS IN LOWERCASE 1 From the Embedded Web Server, click Settings > Embedded Solutions > PKI Authentication > Configure. 2 If the Simple Kerberos Setup has been used, verify that the Realm is correct, and has been typed in UPPERCASE. 3 If a krb5.conf file has been uploaded, verify that the Realm entries in the configuration file are in UPPERCASE. "The Domain Controller Issuing Certificate has not been installed" error message If a certificate has been installed but it is not the correct certificate, the error message displayed will be "The Domain Controller Issuing Certificate [NAME OF CERTIFICATE] has not been installed. NO CERTIFICATE, OR AN INCORRECT CERTIFICATE HAS BEEN INSTALLED ON THE PRINTER For information on installing, viewing, or modifying certificates, see "Creating and modifying digital certificates" on page 16. 40

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58

“The KDC and MFP clocks are different beyond an acceptable range;
check the MFP's date and time” error message
This error indicates the printer clock is more than five minutes out of sync with the domain controller clock.
Verify the date and time on the printer:
1
From the Embedded Web Server, click
Settings
>
Security
>
Set Date and Time
.
2
If you have manually configured date and time settings, verify and correct as needed. Make sure the time zone
and daylight savings time settings are correct.
Note:
If your network uses DHCP, verify that NTP settings are not automatically provided by the DHCP server
before manually configuring NTP settings.
3
If you have configured the printer to use an NTP server, verify that those settings are correct, and that the NTP
server is functioning correctly.
“Kerberos configuration file has not been uploaded” error message
This error occurs when PKI Authentication is configured to use the Device Kerberos Setup, but no Kerberos file has
been uploaded
1
From the Embedded Web Server, click
Settings
>
Embedded Solutions
>
PKI Authentication
>
Configure
.
2
If the Simple Kerberos Setup has been configured in PKI Authentication, clear the
Use Device Kerberos Setup
check box, and then click
Apply
.
3
If a Kerberos configuration file is needed:
a
From the Embedded Web Server, click
Settings
>
Security
>
Security Setup
>
Kerberos 5
.
b
Under Import Kerberos File,
Browse
to locate the appropriate krb5.conf file, and then click
Submit
.
Users are unable to authenticate
T
HE
R
EALM
SPECIFIED
IN
THE
K
ERBEROS
SETTINGS
IS
IN
LOWERCASE
1
From the Embedded Web Server, click
Settings
>
Embedded Solutions
>
PKI Authentication
>
Configure
.
2
If the Simple Kerberos Setup has been used, verify that the Realm is correct, and has been typed in UPPERCASE.
3
If a krb5.conf file has been uploaded, verify that the Realm entries in the configuration file are in UPPERCASE.
“The Domain Controller Issuing Certificate has not been installed”
error message
If a certificate has been installed but it is not the correct certificate, the error message displayed will be “The Domain
Controller Issuing Certificate [NAME OF CERTIFICATE] has not been installed.
N
O
CERTIFICATE
,
OR
AN
INCORRECT
CERTIFICATE
HAS
BEEN
INSTALLED
ON
THE
PRINTER
For information on installing, viewing, or modifying certificates, see “Creating and modifying digital certificates”
on page 16.
40