X7500 Series, X4500 Scanner Series MFPs: LDAP Address Bk and Authenticatin Cnfiguratin and Basic Trubleshting Tips Lexmark Internatinal 1
Prerequisite Infrm atin In rder t cnfigure a Lexmark MFP fr LDAP Authenticatin and/r Address Bk Lkups, yu ll need the fllwing infrmatin: 1. The DNS name r IP address f the system that s acting as the Directry Server. 2. The prt number that the Directry Server mnitrs fr LDAP traffic. This is nrmally prt 389. 3. Unless the Directry Server allws annymus access, the MFP will need a set f credentials (DN, and passwrd) that crrespnd t a user accunt. Often, this accunt will be a dedicated service accunt, and it wuld typically be shared amng multiple MFPs. Nte that yu will need the fully-qualified Distinguished Name (DN) fr this accunt, which will lk smething like cn=mfp Accunt,u=Equipment,dc=<dmain name>,dc=cm. 4. The Search Base fr the directry needs t be knwn. This can usually be the rt f the directry (such as dc=cmpany,dc=cm, althugh in a large directry there will be perfrmance benefits if this reflects a subset f the directry under which all f the user accunts reside. 5. The attribute against which users lgin infrmatin is t be cmpared. Fr an Active Directry envirnment this is typically the samaccuntname attribute. Fr ther envirnments, it can be ne f the ther attributes (uid, userid, etc.) Lexmark Internatinal 2
Cnfiguratin Instr uctins Part I f II Basic LDAP Cnfiguratin T cnfigure the MFP s that it searches the directry fr addresses and/r fax numbers, perfrm the fllwing steps: 1. Pint yur brwser t the MFP s IP address, and check the MFP Sftware versin number: Figure 1.0 The MFP s sftware level shuld be 906.xxx r higher. Lexmark Internatinal 3
2. Starting at the MFP s hme page, select the Cnfiguratin link, then the Manage Functin Access and LDAP Setup links. Figure 2.0 The MFP s LDAP settings are specified n the LDAP Setup page: Cnfiguratin->Manage Functin Access->LDAP Setup 3. On this page, fill in the Server Address, Prt, MFP s Distinguished Name, MFP s Passwrd, and Search Base fields. All f these fields are required. Nte that the Userid Attribute field is nt required fr LDAP Queries, althugh it will be required fr the MFP t authenticate users via LDAP. Fr nw, it can be filled in r left blank. 4. The remaining fields and values shuld be left in their default state. 5. Scrll dwn and click n Submit. At this pint, the MFP shuld be able t perfrm LDAP queries t lk up addresses r phne numbers in the directry serviced by the specified Directry Server. Lexmark Internatinal 4
T test this, tuch the E-mail icn n the MFP s panel. On the screen that appears (see Figure 3.0), type in part r all f a persn s name and select Search Address Bk. The MFP will use LDAP t query the directry fr anyne whse name r email address matches the infrmatin entered, and will prvide yu a list f pssible matches frm which t chse. Figure 3.0 The MFP can use LDAP t lk up the phne numbers r email addresses f recipients during fax r scan-t-email jbs Figure 3.1 The MFP has searched the directry, and fund five users whse first name, last name, r email start with ma If this peratin fails and there are n results fund fr users that are knwn t be in the directry, refer t the Setup Trubleshting sectin, belw. Lexmark Internatinal 5
Part II f II Using LDAP fr Authenticatin Once the Basic LDAP Cnfiguratin as described abve has been successfully applied and tested, the MFP can easily be cnfigured t authenticate users via LDAP. 1. Starting at the MFP s default web page (i.e. http://<mfp s IP address>), select the Cnfiguratin and Manage Functin Access links. 2. Set the Authenticatin Methd t LDAP. 3. Users can be required t authenticate prir t perfrming Cpy, Fax, r E-mail jbs, and befre they can select predefined Prfiles r Frms. T prtect each srt f access, select ID and Passwrd in the cntrls that crrespnd t each peratin. 4. Click n Submit. When the MFP s web page refreshes, select Cnfiguratin- >Manage Functin Access->LDAP Setup, and make sure that the Userid Attribute field is set t reflect the attribute against which the user ID that s prvided during authenticatin will be cmpared. If this value is mdified, select Submit at the bttm f the page. At this pint the MFP will require users t authenticate befre prceeding with the specified functins. T test this, select ne f the icns n the MFP panel that crrespnds t a functin that was prtected with authenticatin in step #3, abve. The MFP shuld prmpt fr the user s ID and passwrd, as shwn belw. Figure 3.1 The MFP will prmpt fr the User ID and Passwrd during authenticatin If the authenticatin fails fr user ID/passwrd cmbinatins that are knwn t be valid, refer t the Setup Trubleshting sectin, belw. Lexmark Internatinal 6
Setup Trubleshting Check the MFP s basic IP settings, via the links Cnfiguratin->Setup and Cnfiguratin->TCP/IP. In particular, make sure the MFP s DNS Server Address field is filled in, and crrect. Check the value f the Server Address n the MFP s LDAP Setup page (Cnfiguratin- >Manage Functin Access->LDAP Setup). Cnfirm that the system indicated by the Server Address is respnding t pings, and cnfirm that it is a Directry Server. If the Server Address is specified as a DNS name, make sure the name is spelled crrectly. Make sure yu can ping it as a DNS name, and that the ping is successful. Check the MFP s DN and passwrd, t make sure they are valid The ADSI Edit tl is an excellent tl fr cnfirming the DN in a Windws Active Directry envirnment. This tl is a standard part f the Supprt Tls, which can be installed frm the \supprt\tls flder n the Windws Server CD. The Active Directry Users and Cmputers tl is a standard cmpnent n dmain cntrllers in an Active Directry envirnment. This is als a gd tl fr verifying the DN that s been prvided t the MFP. And, this is the default path fr changing/verifying the passwrd assciated with the MFP s accunt. A methd fr cnfirming the Server Address, Prt, and the MFP s credentials fr any LDAP server platfrm is t use an LDAP brwser tl such as the Sfterra LDAP brwser, available at www.sfterra.cm/prducts/ldapbrwser.php This brwser can be cnfigured t query the directry in a way that reflects the MFP s use f directry queries. If the Sfterra brwser can successfully query a given server, then the MFP can be cnfigured t use the same server address, prt number, DN, passwrd, and search base. Similarly, the LDP tl that s included as part f the Supprt Tls (which can be installed frm the \supprt\tls flder n the Windws Server CD) is a gd tl fr brwsing the directry. ~Check the Search Base that s specified n the MFP s LDAP Setup page. The Search Base will usually indicate the rt f the directry smething like dc=prductin,dc=acme,dc=cm Lexmark Internatinal 7
If authenticatin is failing but Address Bk lkups are wrking, the prblem may be related t the Userid Attribute value n the MFP s LDAP Setup page. This value is used during authenticatin, but nt used during Address Bk lkups. Make sure that the attribute specified crrespnds t a valid attribute in the directry, and that this attribute reflects the lgin infrmatin that the user prvides n the first lgin screen, during authenticatin. Nte that the Sfterra LDAP brwser is a gd tl fr validating this infrmatin by brwsing the directry. Fr the X7500/5500/X4500 : Use the MFP s UI lg and/r a sniff trace f the netwrk traffic between the MFP and the Directry Server t get insight int the rt cause f the failure. Fr the X644e/X646e/X85xe : Use the MFP s Histry lg and/r a sniff trace f the netwrk traffic between the MFP and the Directry Server. Lexmark Internatinal 8