Dell S2815dn Smart Multifunction Printer CACStar Smart Card Reader Configurati - Page 18

Basic, Root Certificate, LDAP Server IP, LDAP Query User Name

Page 18 highlights

Basic This includes PIN validation, card expiration check, and X.509 card certificate validation. If an NTP server is not configured on the LAN Side Configuration page, the expiration check is bypassed. The Basic level of authentication is always included and cannot be removed from the configuration. In some installations, this is sufficient authentication and is the only one activated. OCSP Check this box to enable OCSP (Online Certificate Status Protocol) verification of CAC Cards. If enabled the OCSP server will be used to validate the current status of the CAC card PKI certificate. NOTE: If OCSP is enabled, you must have a DNS server configured. Root Certificate Check this box to enable Root Certificate verification of CAC Cards. If enabled, the certificate chain, including the Root CA Certificate will be used to validate the CAC card PKI certificate. The card is also checked to be certain the CAC certificate has a valid private key. NOTE: If Root Certificate is enabled, all Issuer Certificates and Root CA Certificate chains for cards in use at this installation must be loaded into the CACStar. If not, Verify Failures will occur. LDAP Check this to enable use of the Active Directory server for additional authentication LDAP Server IP: IP address of the LDAP server. LDAP Server Port: Port number of the LDAP server. The default is 389. LDAP Query User Name: User Name for the LDAP service account login. CACStar User Guide Rev A27 Copyright 2017 Digital Imaging Technology Page 18

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40

CACStar User Guide Rev A27
Copyright 2017 Digital Imaging Technology
Page 18
Basic
This includes PIN validation, card expiration check, and X.509 card
certificate validation.
If an NTP server is not configured on the
LAN
Side Configuration
page, the expiration check is bypassed.
The Basic
level of authentication is always included and cannot be removed
from the configuration.
In some installations, this is sufficient
authentication and is the only one activated.
OCSP
Check this box to enable OCSP (Online Certificate Status Protocol)
verification of CAC Cards.
If enabled the OCSP server will be used to
validate the current status of the CAC card PKI certificate.
NOTE:
If OCSP is enabled, you must have a DNS server configured.
Root Certificate
Check this box to enable Root Certificate verification of CAC Cards.
If
enabled, the certificate chain, including the Root CA Certificate will
be used to validate the CAC card PKI certificate.
The card is also
checked to be certain the CAC certificate has a valid private key.
NOTE:
If
Root Certificate
is enabled, all Issuer Certificates and Root
CA Certificate chains for cards in use at this installation must be
loaded into the CAC
Star
.
If not, Verify Failures will occur.
LDAP
Check this to enable use of the Active Directory server for additional
authentication
LDAP Server IP:
IP address of the LDAP server.
LDAP Server Port:
Port number of the LDAP server.
The default is 389.
LDAP Query User Name:
User Name for the LDAP service
account login.