Lexmark X782e PKI-Enabled Pre-Installation Guide - Page 18

Manual Login Configuration

Page 18 highlights

PKI Pre-Installation Guide LDAP Attribute 3.2.2.2 Manual Login Configuration If manual login is allowed, a button appears in the lower right corner of the login screen that says "Login". The user will press the Login button and be prompted for their username and password. 1. The default domain to be associated with usernames. In a Kerberos login, the id is typically: \ OR @domain. By specifying the default domain, users will not need to provide the "domain\" or " @domain" part when entering their username. This value is typically the same as the Kerberos Realm (but in lowercase). Default Manual Login Domain 2. In order to lookup information about the user, the LDAP Attribute that corresponds to the user's id is needed. This attribute is typically named: samaccountname. Manual Login Search Attribute 3. If the username or password can contain non-US English characters, the code page used to process those characters must be set. The code page already configured on the device can be used or an explicit one can be used. Select the choice below: □ Device Default □ ISO 8859-2 □ ISO 8859-5 □ ISO 8859-9 □ PC 858 3.3 User Authorization In addition to providing user authentication, the PKI Authentication application can also provide user authorization to allow or disallow to the device as a whole or to individual functions on the device. The authorization is based on Active Directory groups; users can be allowed or denied access based on their membership to the specified groups. Version 2.0.0 Page 14

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42

PKI Pre-Installation Guide
Version 2.0.0
Page 14
LDAP Attribute:
___________________________________________
3.2.2.2
Manual Login Configuration
If manual login is allowed, a button appears in the lower right corner of the login screen that says
“Login”.
The user will press the Login button and be prompted for their username and
password.
1.
The default domain to be associated with usernames.
In a Kerberos login, the id is
typically:
<domain>\<id> OR <id>@domain. By specifying the default domain, users
will not need to provide the “domain\” or “ @domain” part when entering their username.
This value is typically the same as the Kerberos Realm (but in lowercase).
Default Manual Login Domain:
_______________________________________
2.
In order to lookup information about the user, the LDAP Attribute that corresponds to the
user’s id is needed.
This attribute is typically named:
samaccountname.
Manual Login Search Attribute:
_______________________________________
3.
If the username or password can contain non-US English characters, the code page used
to process those characters must be set.
The code page already configured on the device
can be used or an explicit one can be used.
Select the choice below:
Device Default
ISO 8859-2
ISO 8859-5
ISO 8859-9
PC 858
3.3 User Authorization
In addition to providing user authentication, the PKI Authentication application can also provide
user authorization to allow or disallow to the device as a whole or to individual functions on the
device.
The authorization is based on Active Directory groups; users can be allowed or denied
access based on their membership to the specified groups.