* Enter the name of the utility key. You can search descriptions of utility keys.
Server Registration
To display: [Utility][Administrator][User Auth/Account Track][LDAP-IC Card Authentication Setting][Server Registration]
Register the authentication server to be used for card authentication.
Configure the following settings on the primary server registration screen.
Setting | Description |
---|---|
[LDAP-IC Card Authentication Server Name] | Enter the name of the authentication server (using up to 32 characters). |
[External Authentication Server] | Select the external authentication server used to associate the LDAP-IC card authentication (default: [No Selection]). When authentication succeeds, user authentication information is registered on the machine to manage users on the machine. This authentication information includes the user name and external authentication server name. The external authentication server name selected here is registered on the machine together with the user name. |
[Card Information Registration Settings] | When authentication is performed on the machine using an IC card not registered in the LDAP server, select whether to register the card information in the LDAP server (default: [OFF]).
|
[Card Information Character Type During Search] | Select the search string conversion method to search for the card ID via the LDAP server (default: [Uppercase Letters/ Lowercase Letters]). When the target card attribute information on the server is unified into upper and lower case letters, in some cases, you can convert the character type of the search string and subsequently reduce the search speed.
|
[Server Address] | Enter the LDAP server address. Use one of the following formats.
|
[Port No.] | If necessary, change the LDAP server port number (default: [389]). |
[Enable SSL] | When using SSL communications, set this option to ON (default: OFF).
|
[Certificate Verification Level Settings] | To validate the certificate during SSL communication, select items to be verified.
|
[Search Base 1] to [Search Base 3] | Specify the starting point and range to search for a user to be authenticated.
|
[Timeout] | If necessary, change the time-out time to limit a communication with the LDAP server (default: [60] sec.). |
[General Settings] | Select the authentication method to log in to the LDAP server depending on your environment (default: [Simple]).
|
[Use Referral] | Select whether to use the referral function (default: [ON]). |
[Search Attribute] | When performing LDAP search, enter the search attribute to be automatically added before the user name (using up to 64 characters). The attribute must start with an alphabet character (default: [uid]). |
[User Name] | Select how to obtain the user name when logging in to this machine (default: [Use Card ID]). If [ON] is selected in [Card Information Registration Settings], [Acquiring] is selected, and any change cannot be made.
|
[Search Directory Service] | If you select [Active Directory], you can limit a search target for authentication to users (default: [Other]). However, when a search target for authentication is limited to users, search target identification processing occurs on the server side, so the authentication time may be delayed. This function is available when the authentication server is set to Active Directory (Windows Server 2008 or later). |
Configure the following settings on the secondary server registration screen.
Setting | Description |
---|---|
[2nd Server Setting] | When using the secondary server, set this option to ON (default: OFF). |
[Round Robin function] | When using the round-robin function, set this option to ON (default: OFF). If you select round-robin function, you can alternately connect the primary and secondary servers to distribute the server load. |
[Reconnection Settings] | Configure a setting to connect to the secondary server when the machine cannot be connected to the primary server (default: [Set Reconnect Interval]). When the round-robin function is enabled, this setting can also be used to connect to the primary server when the machine cannot be connected to the secondary server.
|
[Card Information Registration Settings] | When authentication is performed on the machine using an IC card not registered in the LDAP server, select whether to register the card information in the LDAP server.
|
Secondary Server Information | Register the secondary server. For details, refer to the registration contents of the primary server. To extract the primary server setting and configure the secondary server setting, tap [Same as 1st Server]. |
To check the status of the connection of the primary authentication server and the secondary authentication server, select [User Auth/Account Track] - [Authentication Server Connection status] - [LDAP-IC Card Authentication]. If [Connection Enabled] is displayed, you can connect to both the primary and secondary authentication servers.