PaperCut MF - Xerox Secure Access Manual
PaperCut MF - Xerox Secure Access Manual
PaperCut MF - Xerox Secure Access Manual
Manual
Contents
1
Overview ........................................................................................................... 3
1.1
Consistency: ............................................................................................... 3
1.2
Integration: .................................................................................................. 3
1.3
1.4
1.5
Security: ...................................................................................................... 3
Installation ......................................................................................................... 4
2.1
2.2
Requirements.............................................................................................. 4
2.3
2.3.1
2.3.2
2.1
2.2
2.2.1
Introduction .......................................................................................... 7
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.3
2.3.1
Introduction ........................................................................................ 18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
1 of 38
2015-02-17
3.1
3.2
3.3
3.4
3.5
Configuration ................................................................................................... 30
4.1
4.2
4.3
4.4
5.2
5.3
5.4
5.5
6.2
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
2 of 38
2015-02-17
This manual covers Xerox Secure Access setup. For general PaperCut MF
documentation, please see the PaperCut MF manual.
Overview
1.1 Consistency:
The embedded solutions are developed in-house by the PaperCut Software
development team. This ensures that the copier interface is consistent with the
workstation print interface, meaning users only have to learn one system.
1.2 Integration:
PaperCut is a single integrated solution where print, internet and copier control are all
managed in the one system. Users have a single account and administrators have
the same level of reporting and administration for all services. The embedded
solution interacts with the PaperCut server using a Service Oriented Architecture
(SOA) and web services based protocols.
1.5 Security:
A large percentage of PaperCuts user base is in Education environments where
security is important. All embedded solutions are developed with security in mind.
Where security objectives cant be satisfied, any deficiencies are fully disclosed.
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
3 of 38
2 Installation
This section covers the installation of the PaperCut embedded application for
compatible Xerox devices. The embedded application will allow the control, logging
and monitoring of walk-up off-the-glass MFD usage and may serve as a print release
station for network prints (for information on just tracking network printing see the
PaperCut user manual).
To track the device usage the Xerox Network Accounting module must also be
enabled (Network Accounting is also known as JBA accounting). The Network
Accounting module is often included with the device, but for some devices it is
necessary to have this enabled by your Xerox supplier. Please contact your Xerox
supplier for details.
Secure print release and find-me printing is also supported on Xerox devices. The
administrator has the option to automatically release all pending jobs when the user
logs in, or of giving the user the option to release these documents at the time of
login.
NOTE: The FujiXerox devices available in the Asia-Pacific region do not support
Xerox Secure Access. These devices can instead make use of the Network
Accounting features to control access to the copier. See the PaperCut Xerox
Network Accounting Embedded manual for information.
2.2 Requirements
Ensure that the following points are checked off before getting started:
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
4 of 38
2015-02-17
Have available the network name and IP address of the system running
PaperCut (e.g. the print server).
Ensure that the Xerox MFD is connected to the network.
Have available the network address of the Xerox MFD. It is recommended
that the MFD is configured with a static IP.
Network card readers (i.e. not physically connected to the MFP. The
PaperCut server communicates with these over the network)
USB card readers (some recent Xerox devices with updated firmware now
support a limited number of USB card readers contact Xerox for details).
The Network Card Reader option will work with any Xerox device supporting Xerox
Secure Access.
2.3.1 Network Card Readers
Network card readers may be used on any Xerox device. PaperCut supports two
cost effective network card readers:
These readers are available directly from the card reader distributors and PaperCut
Authorized Solution Centers in your region.
These network card readers are located on the MFP device and are connected to the
network. When a user swipes their card at the reader the card number is sent to the
PaperCut server for validation. If the card number is valid the user will be granted
access to the MFP.
2.3.2 USB Card Readers
Xerox updated their platform in late 2011 to support USB card readers through Xerox
Secure Access. At the present time (April 2012) only a subset of current devices
support USB card readers and they may require firmware upgrades, and include:
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
5 of 38
2015-02-17
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
6 of 38
2015-02-17
inbound connections from the Xerox devices to the PaperCut server on ports
9191 and 9192.
outbound connections from the PaperCut server to the Xerox device on ports
80 and 443.
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
7 of 38
2015-02-17
1. Navigate to Properties->Connectivity->Protocols->HTTP
2. Enable the "Secure HTTP (SSL)" option
3. Press Apply
2.2.4 Enable SNMP v3 support
The Xerox Secure Access feature is configured by PaperCut using SNMP v3. This
protocol must be enabled before configuring the Xerox device in PaperCut.
1. Login to the devices web admin.
2. Navigate to Properties -> Connectivity -> Protocols -> SNMP Configuration.
3. Enable the SNMP v3 option and press "Apply".
4. Go back to the SNMP page and press the "Edit SNMP v3 properties" button.
5. Enable the "Administrator" account.
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
8 of 38
2015-02-17
6. Enter the authentication and privacy passwords. Take note of this and the
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
9 of 38
2015-02-17
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
10 of 38
2015-02-17
9. Select Disabled on the Code Entry Validation screen and press Save
3. Press Apply.
4. Navigate to the Devices tab.
5. Click Create Device action from the left.
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
11 of 38
2015-02-17
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
12 of 38
2015-02-17
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
13 of 38
2015-02-17
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
14 of 38
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
2015-02-17
15 of 38
2015-02-17
10. Change the Services Pathway setting to Locked. This locks access to the
copier functions unless the user is logged in
NOTE: On newer devices the Pathway Options screen may look different
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
16 of 38
2015-02-17
You may need to reboot the device for the settings to take effect.
Once the device is rebooted the device should display a screen to login. Perform
testing and verify you can login and that copies are tracked by PaperCut.
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
17 of 38
2015-02-17
inbound connections from the Xerox devices to the PaperCut server on ports
9191 and 9192.
outbound connections from the PaperCut server to the Xerox device on ports
80 and 443.
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
18 of 38
2015-02-17
6. Enter the authentication and privacy passwords. Take note of this and the
username (usually Xadmin) as these will be required later with the
configuration of the device in PaperCut.
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
19 of 38
2015-02-17
Once these settings are changed you might need to reboot the Xerox for them to
have an effect. The device usually prompts you when a reboot is required.
19. Enter a descriptive name for the device under Device name.
20. Enter the Xerox devices IP address under Hostname/IP.
21. Optionally enter location/department information.
22. Enter the admin username and password and privacy password (those
entered in the SNMPv3 settings on the MFP). NOTE: The username is casesensitive and is usually Xadmin.
23. Under Function tick the options you would like to enable. E.g. Track &
control copying.
24. Click OK.
At this point PaperCut should try to connect to the device to configure various options
over SNMP. The page displayed after the device is created displays the device
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
20 of 38
2015-02-17
status. If there are problems communicating with the device then the status will show
an error message. Press the "Refresh" link next to the status to see if the status is
updated.
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
21 of 38
2015-02-17
9. Enable the "Get Accounting Code" option. (On some devices this is option is
called Accounting codes provided by server).
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
22 of 38
2015-02-17
5. Enter the network address and the port of the network card reader.
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
23 of 38
2015-02-17
3 Post-install testing
After completing installation and basic configuration it is recommended to perform
some testing of the common usage scenarios. This important for two reasons:
1. To ensure that the embedded application is working as expected
2. To familiarize yourself with the features and functionality of PaperCut and the
embedded application.
This section outlines four test scenarios that are applicable for most organizations.
Please complete all the test scenarios relevant for your site.
If you have existing users that can be used for these tests, then they can be used
instead.
To setup these users in PaperCut:
4. Verify that this user is set to Automatically charge to personal account in the
Account selection options.
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
24 of 38
2015-02-17
To configure testuseradvanced:
1. In PaperCut, select the Users tab
2. Select the testuseradvanced user.
3. Change the Account Selection option to Standard account selection popup
and enable all the account selection options.
Back in the PaperCut application verify that the copier activity was recorded and the
users account deducted.
1. Log in to PaperCut.
2. Select the device from the Devices tab.
3. Select the Job Log tab. This will list all recent copying activity on the copier.
The copying just performed as the test user should be listed. Verify the
details of the copy job that was just performed.
4. Click on the users name in the user column to view the users account details
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
25 of 38
2015-02-17
5. Select the Job Log tab to display all print/copy activity for the user.
6. Select the Transaction History tab and verify that the cost of the
photocopying was deducted from the users account.
1.
2.
3.
4.
5.
At the photocopier:
1. The photocopier should be displaying a screen to prompt the user to login.
Follow the prompts to login.
2. When prompted username (testuseradvanced) and password in the login
fields.
3. The user will then be prompted to enter the account code/PIN. Enter the
account code of 2233 to select the Test Account 1 created earlier.
4. At this point the copier will be enabled for usage. Follow the onscreen
instructions and perform some test copying. I.e. press the Copy key on the
device and perform a copy as normal.
5. Once completed copying press Logout button.
Back in the PaperCut application verify that the copier activity was recorded and the
users account deducted.
1. Log in to PaperCut
2. Select the device from the Devices tab
3. Select the Job Log tab. This will list all recent copying activity on the copier.
The copying just performed as the test user should be listed.
4. Verify the details of the job (i.e. that the job was charged to the selected
account).
5. In the log details, click on the Charged To account name to view the
accounts details.
6. Selecting the Job Log tab will display all print/copy activity for the account,
and will show the test photocopying that was performed.
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
26 of 38
2015-02-17
Press OK/Apply to save the changes. All printing to this queue will now be
held until released by a user.
5. Press OK to save.
6. Login to a computer workstation as testusersimple.
7. Print a few jobs to the print queue that was configured above. The jobs will
be held in the hold/release queue.
8. Confirm that the jobs are held, by checking that the jobs are listed in the
Printers -> Jobs Pending Release page of the PaperCut administration
interface.
9. Confirm that the username is testusersimple.
At the device:
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
27 of 38
2015-02-17
At the photocopier, log in and scan a few documents and send a few faxes. At the
end, make sure to press the Logout button on the devices keypad.
In the PaperCut administration interface verify that the scan and fax activities were
recorded and the users account was deducted. This can be done as follows:
1. Log in to the PaperCut administration interface.
2. Select the device from the Devices tab.
3. Select the Job Log tab. This will list all recent activity on the copier,
including copying, scanning and faxing. The jobs just performed as the test
user should be listed. Verify the details of the jobs that were just performed.
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
28 of 38
2015-02-17
4. Click on the users name in the user column to view the users account
details.
5. Select the Job log tab to display all activity for the user.
6. Select the Transaction History tab and verify that the cost of the scans and
faxes was deducted from the users account.
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
29 of 38
2015-02-17
4 Configuration
After completing the Installation section and registering the device with PaperCut, it will have
been configured with reasonable default settings that are suitable for most environments.
This section covers how to change the default settings. All the following settings are
available via the devices Summary tab in the PaperCut administration interface.
Description
Not all authentication methods are supported on all devices. A grayed-out option indicates
that the option is not supported on this device.
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
30 of 38
2015-02-17
Description
Username and
password
Identity number
The user may log in with their identity number. Identity numbers
are convenient when usernames are long or cumbersome to enter.
For example, rather than entering a username like
john.smith.001, it may be more convenient to enter an employee
ID of 1234. See the PaperCut user manual for information about
user identity numbers, including importing identity numbers from
an external source.
When a user logs in with their identity number, they must also
provide their associated PIN. This provides additional security for
identity number logins.
Automatically login as
user
A typical case is the checksum being reported after the card number, separated by
an equals sign, such as in 5235092385=8. PaperCut can handle this case by default;
it will extract the number before the equal sign as the card number: 5235092385.
For some cases, a regular expression may be required that will filter the card
number from the complete string of characters reported by the card reader.
Documentation on regular expressions can be found on the Internet, e.g. at
www.regular-expressions.info.
o The regular expression must be fashioned so that the card number is
returned as the first match group.
o Usually one regular expression will be used for all the devices managed by
PaperCut; this must be entered in the Config editor (advanced) which you
will find on the Options tab under Actions. The key is called ext-device.cardno-regex.
o The global setting however can be overridden on a per-device basis: The key
ext-device.card-no-regex can also be found on the Advanced Config tab in
the device details screen. This setting will override the global setting unless
the keyword GLOBAL is specified.
o PaperCut developers will gladly assist in producing a regular expression
when supplied with a few sample outputs from your card reader. Please
contact PaperCut support.
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
31 of 38
2015-02-17
If you would like to write your own regular expressions, here are some
examples:
Use the first 10 characters (any character): (.{10})
Use the first 19 digits: (\d{19})
Extract the digits from between the two = characters in
123453=292929=1221: \d*=(\d*)=\d*
Once the user starts copying it is not possible to forcibly stop the copying and log
them out of the system.
Restricted users with available credit can start copying and continue copying even
once they have used their credit. Their copier usage will still be recorded in
PaperCut and the cost will be deducted from their account (which will go into
negative balance).
NOTE: PaperCut will forcibly logout the user if the users job completes and they have no
credit remaining. PaperCut can only force them out after the job is completed. This is
because we are only informed of completed jobs, and its only after the job is charged that
the users credit will be reduced.
This is a limitation of the Xerox Secure Access and Network Accounting module.
32 of 38
2015-02-17
Please check with Xerox whether your device model supports fax tracking via Network
Accounting.
The following list of Xerox devices that do and do not support tracking faxes (at the time of
writing on 25th Jan 2013).
Devices NOT supporting tracking faxes:
ColorQube 8700
ColorQube 8900
ColorQube 9201/9202/9203
ColorQube 9301/9302/9303
Phaser 3635MFP
WorkCentre 232/238
WorkCentre 245/255
WorkCentre 265/275
WorkCentre 4250
WorkCentre 4260
WorkCentre 5030/5050
WorkCentre 5135/5150
WorkCentre 5632/5638
WorkCentre 5645/5655
WorkCentre 5665/5675/5687
WorkCentre 5735/5740/5745/5755
WorkCentre 5765/5775/5790
WorkCentre 6400
WorkCentre 7525/7530/7535/7545/7556
WorkCentre 7655/7665/7675
WorkCentre 7120/7125
WorkCentre 7132
WorkCentre 7232/7242
WorkCentre 7328/7335/7345/7346
WorkCentre 7425/7428/7435
Xerox Color 550/560
WorkCentre 5222
WorkCentre 5225/5230
WorkCentre 5325/5330/5335
If your device is not listed, please check with Xerox on whether the device supports tracking
faxes.
A text input field (which can be optionally masked for password input)
A prompt with Yes and No buttons.
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
33 of 38
2015-02-17
These limitations restrict the richness and flexibility that we can provide in the login process.
This is a limitation of the Xerox Secure Access system.
The copiers built in admin password should be changed from the default and always
kept secure.
6 Advanced Configuration
6.1 Config Editor
The common configuration options for a device in PaperCut are available on the devices
Summary tab, and are discussed in more detail in the Configuration section. This section
covers the more advanced or less common configuration options which are available via the
Advanced Config tab.
Config name
Description
ext-device.card-selfassociation.usesecondary-cardnumber
Set to "Y" to use the secondary card number, "N" to use the primary
card number. Default: "GLOBAL" to defer to the global configuration
option.
ext-device.xerox.limitreference.paper-size
and
ext-device.xerox.limitreference.duplex
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
34 of 38
2015-02-17
America: Letter
Default for ext-device.xerox.limit-reference.paper-size worldwide: A4
ext-device.xerox.logininstruction
Defines the text to display on the initial login screen displayed by the
Xerox device. If set to DEFAULT PaperCut will set this message
based on the authentication settings of the device.
IMPORTANT: The Xerox device has very limited support for nonASCII characters. If you have problems please only use ASCII
characters.
ext-device.xerox.jobdownload-after-loginperiod-secs
ext-device.xerox.authuser-prefix
When users login to the Xerox their credentials like username (and
password if provided) are passed to the Xerox device by PaperCut.
This allows the device to use these credentials for other
authentication. E.g. To authenticate the use when using the Scan
to Home features.
In some environments, the username must be prefixed with the
windows domain for this to work properly. This setting allows the
domain to be prefixed to the username so that the user does not
need to enter it manually.
For example, if this setting this set to: DOMAIN\ and the user
names john logs in, PaperCut will pass the username
DOMAIN\john to the Xerox.
extdevice.xerox.card.m
agstripe-track-no
When a USB Magstripe card reader is used, the card data can be
found on one of 3 tracks. Typically the track of interest is track
number 2. This configuration parameter specifies a comma
separated list of track numbers to look at in order to retrieve the card
data. For example if the list was: 2, 3 then it would look to see if
there was data for track 2 and if there wasnt then it would look to
see if there was data for track 3. If it cant find any valid track data,
then it will show an error message on the Xerox Panel and a more
detailed message in the logs. Note: Prior to PaperCut 13.4, this list
can only contain one value.
Default: 2 (by default only look at the data associated with track 2)
ext.device.xerox.swi
pe-to-logout
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
35 of 38
2015-02-17
address (if the server has multiple IPs (i.e. multi-homed) then PaperCut will select one of
them), but on some networks this address may not be publicly accessible from other parts of
the network.
If the PaperCut server has a public IP address or DNS name then this can be used instead,
which allows the copiers to use the public network address instead of the IP address that
PaperCut detects. To do this:
Login to PaperCut
Go to the "Options" tab.
Select "Config Editor (advanced)", from the action links on the left.
Find the "system.network-address" setting.
Enter the public network address for the PaperCut server.
Press the "Update" button next to the setting and confirm the setting is updated.
When connecting devices to a PaperCut site server, you can configure the sites Network
address used by devices:
Login to PaperCut
Go to the Sites tab.
Select the site to edit.
Change the Network address used by devices.
Save the site details.
To have either of these changes take effect immediately, restart the PaperCut Application
Server service (i.e. on Windows use: Control Panel->Admin Tools->Services).
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
36 of 38
2015-02-17
7 How it works
The following section gives a brief overview of the internal workings of PaperCuts on-board
solution for Xerox devices. Its provided as background information and may be useful for
technical administrators troubleshooting problems.
Typical function workflow:
1. A user logs into the MFP via the panel. The MFP is configured to contact PaperCut
(via SOAP web sevices) to verify login information.
2. The user ID and password is validated and devices access is granted as appropriate.
3. If release jobs on login is enabled any waiting jobs are immediately queued for
printing. (called secure print release or find-me printing)
4. If the user performs any device functions such as Copy, Fax or Scan, these are
recorded against the user ID in the devices onboard logs.
5. At regular periods (e.g. every minute) PaperCut contacts the device looking for new
log entries (logs are downloaded via HTTP using JBA network accounting).
6. Any new log entries are analyzed and recorded in PaperCuts usage database. Any
cost associated with the usage is charged from the users account (or their selected
Shared Account).
PaperCut shows an error status for the device. What could cause this?
In the Devices list the Xerox device may appear with an error status (hover your mouse
over the status to see the full status message). The status message will help understand
the cause of the error. The most common cause of problems is due to a networking issue,
to resolve:
Verify that the device network address (or IP) is entered correctly in PaperCut
Verify that networking and firewalls allow PaperCut to establish a connection to the
device on TCP ports 80 and 443 and UDP port 161 for SNMP.
Verify that networking and firewall settings allow the device to establish connections
to the PaperCut server on ports 9191 and 9192.
Another common cause of errors is that Network Accounting / JBA has not been
enabled/configured on the device. Ensure that the Network Accounting is enabled as
described in section 2.1.
Another possible cause of problems is if the device firmware does not support the Off-box
validation features required by PaperCut. This feature should be available for recent Xerox
copiers supporting Network Accounting, however sometimes a firmware upgrade is
required.
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
37 of 38
2015-02-17
PaperCut is tracking the copy/scan/fax jobs to the personal account instead of the
specified shared account.
Please ensure that the Accounting Display Prompts are set for both the user ID and the
account ID.
Copyright 2015 PaperCut Software International Pty. Ltd., All Rights Reserved.
38 of 38