Lexmark MS617 Embedded Web Server Administrator s Guide - Page 43

Installing a Certificate Authority certificate on the device, Configuring the device for certificate

Page 43 highlights

Securing printers 43 Note: You can simplify the process by using the Automatic Certificate Enrollment Application, which is available when an Active Directory environment is used. For more information, see "Appendix C: Automatic Certificate Enrollment application" on page 82. Installing a Certificate Authority certificate on the device Note: This feature is available only in network printers or in printers connected to print servers. The Certificate Authority (CA) certificate is needed so that the printer can trust and validate the credentials of another system on the network. Without a CA certificate, the printer cannot determine whether to trust the certificate that is presented by the system trying to create the secure connection. Start with the certificate file (.pem format) for the CA that you want to utilize. An example of how to create this file is provided in "Appendix A: CA file creation" on page 82. 1 Open a Web browser, and then type the IP address or host name of the printer. 2 From the Embedded Web Server, click Settings > Security > Certificate Management > Certificate Authority Management. Notes: • This window lets the device administrator load a new CA certificate, delete all CA certificates, and view previously installed CA certificates. To view more details of an installed CA certificate or delete a certificate, click common name link under Certificate Authority Common Name. • There are no installed CA certificates to view on this page in new devices. 3 Click New to display the Certificate Authority Installation screen. 4 Click Browse to select the .pem format certificate authority file. 5 Click Submit. Configuring the device for certificate information The printer has a self‑generated certificate. For some operations (such as 802.1X and IPSec), the printer certificate must be upgraded to a certificate that has been signed by a certificate authority. The printer includes a process of generating a certificate signing request that can be viewed or downloaded. This facilitates the process of obtaining the signed certificate for the printer. 1 From the Embedded Web Server, click Settings > Security > Certificate Management > Set Certificate Defaults. 2 Update the information on the device to fit your organization, and then click Submit. For more information, see "Setting certificate defaults" on page 45. 3 From the Certificate Management page, click Device Certificate Management. Notes: • This window lets the device administrator load a new device certificate, delete all device certificates, and view previously installed device certificates. To view more details of an installed device certificate or delete a device certificate, click the certificate common name link under Friendly Name. • If you are configuring a new device, then a default self‑signed certificate can be viewed on this page. 4 Select the link for the preferred device certificate to obtain the certificate signing request information.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98

Note:
You can simplify the process by using the Automatic Certificate Enrollment Application, which is
available when an Active Directory environment is used. For more information, see
“Appendix C: Automatic
Certificate
Enrollment application” on page
82
.
Installing a Certificate Authority certificate on the device
Note:
This feature is available only in network printers or in printers connected to print servers.
The Certificate Authority (CA) certificate is needed so that the printer can trust and validate the credentials of
another system on the network. Without a CA certificate, the printer cannot determine whether to trust the
certificate that is presented by the system trying to create the secure connection.
Start with the certificate file (.pem format) for the CA that you want to utilize. An example of how to create this
file is provided in
“Appendix A: CA
file
creation” on page
82
.
1
Open a Web browser, and then type the IP address or host name of the printer.
2
From the Embedded Web Server, click
Settings
>
Security
>
Certificate Management
>
Certificate
Authority Management
.
Notes:
This window lets the device administrator load a new CA certificate, delete all CA certificates, and
view previously installed CA certificates. To view more details of an installed CA certificate or delete a
certificate, click common name link under Certificate Authority Common Name.
There are no installed CA certificates to view on this page in new devices.
3
Click
New
to display the Certificate Authority Installation screen.
4
Click
Browse
to select the .pem format certificate authority file.
5
Click
Submit
.
Configuring the device for certificate information
The printer has a self
generated certificate. For some operations (such as 802.1X and IPSec), the printer
certificate must be upgraded to a certificate that has been signed by a certificate authority.
The printer includes a process of generating a certificate signing request that can be viewed or downloaded.
This facilitates the process of obtaining the signed certificate for the printer.
1
From the Embedded Web Server, click
Settings
>
Security
>
Certificate Management
>
Set Certificate
Defaults
.
2
Update the information on the device to fit your organization, and then click
Submit
. For more information,
see
“Setting
certificate
defaults” on page
45
.
3
From the Certificate Management page, click
Device Certificate Management
.
Notes:
This window lets the device administrator load a new device certificate, delete all device certificates,
and view previously installed device certificates. To view more details of an installed device
certificate or delete a device certificate, click the certificate common name link under Friendly Name.
If you are configuring a new device, then a default self
signed certificate can be viewed on this page.
4
Select the link for the preferred device certificate to obtain the certificate signing request information.
Securing printers
43