Lexmark X864 PKI-Enabled Device Installation and Configuration Guide - Page 23

The Domain Controller Issuing Certificate has not been installed

Page 23 highlights

"The Domain Controller Issuing Certificate has not been installed" error message This error indicates that no certificate, or an incorrect certificate, has been installed on the printer. If a certificate has been installed but it is not the correct certificate, the error message displayed will be "The Domain Controller Issuing Certificate [NAME OF CERTIFICATE] has not been installed. For information on installing, viewing, or modifying certificates, see "Certificate management" on page 10. "The KDC did not respond within the required time" error message THE IP ADDRESS OR HOSTNAME OF THE KDC IS NOT CORRECT 1 From the Embedded Web Server, click Settings > Embedded Solutions > PKI Authentication > Configure. 2 If the Simple Kerberos Setup has been configured in PKI Authentication, verify the IP address or hostname specified for the Domain Controller, and then click Apply to save any needed changes. 3 If a krb5.conf file has been uploaded, verify that the IP address or hostname specified for the Domain Controller is correct. THE KDC IS NOT CURRENTLY AVAILABLE You can specify multiple KDCs in the PKI Authentication settings, or in the krb5.conf file. This will typically resolve the issue. PORT 88 IS BLOCKED BY A FIREWALL Port 88 must be opened between the printer and the KDC in order for authentication to work. "User's Realm was not found in the Kerberos Configuration file" error message This error occurs during manual login, and indicates the Windows Domain is not specified in the Kerberos settings. 1 From the Embedded Web Server, click Settings > Embedded Solutions > PKI Authentication > Configure. 2 Under Simple Kerberos setup, add the Windows Domain in lowercase to the Domain setting. Example: If the Domain setting is "mil,.mil" and the Windows Domain is "x.y.z", change the Domain setting to "mil,.mil,x.y.z". 3 If using a krb5.conf file, add an entry to the domain_realm section, mapping the lower case Windows Domain to the uppercase realm (similar to the existing mapping for the "mil" domain). Troubleshooting 23

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38

“The Domain Controller Issuing Certificate has not been installed”
error message
This error indicates that no certificate, or an incorrect certificate, has been installed on the printer. If a certificate has
been installed but it is not the correct certificate, the error message displayed will be “The Domain Controller Issuing
Certificate [NAME OF CERTIFICATE] has not been installed.
For information on installing, viewing, or modifying certificates, see “Certificate management” on page 10.
“The KDC did not respond within the required time” error message
T
HE
IP
ADDRESS
OR
HOSTNAME
OF
THE
KDC
IS
NOT
CORRECT
1
From the Embedded Web Server, click
Settings
>
Embedded Solutions
>
PKI Authentication
>
Configure
.
2
If the Simple Kerberos Setup has been configured in PKI Authentication, verify the IP address or hostname
specified for the Domain Controller, and then click
Apply
to save any needed changes.
3
If a krb5.conf file has been uploaded, verify that the IP address or hostname specified for the Domain Controller
is correct.
T
HE
KDC
IS
NOT
CURRENTLY
AVAILABLE
You can specify multiple KDCs in the PKI Authentication settings, or in the krb5.conf file. This will typically resolve
the issue.
P
ORT
88
IS
BLOCKED
BY
A
FIREWALL
Port 88 must be opened between the printer and the KDC in order for authentication to work.
“User's Realm was not found in the Kerberos Configuration file”
error message
This error occurs during manual login, and indicates the Windows Domain is not specified in the Kerberos settings.
1
From the Embedded Web Server, click
Settings
>
Embedded Solutions
>
PKI Authentication
>
Configure
.
2
Under Simple Kerberos setup, add the Windows Domain in lowercase to the Domain setting.
Example: If the Domain setting is “mil,.mil” and the Windows Domain is “x.y.z”, change the Domain setting to
“mil,.mil,x.y.z”.
3
If using a krb5.conf file, add an entry to the domain_realm section, mapping the lower case Windows Domain to
the uppercase realm (similar to the existing mapping for the “mil” domain).
Troubleshooting
23