Smart Card Authentication Client authentication issues

“Authentication failed” error message

This error occurs when Kerberos authentication fails or domain controller validation fails while a user is attempting to log in to the printer.

Check the system log for relevant details

  1. Access the list of installed applications from the Embedded Web Server.

  2. Click System tab > Log.

  3. From the Filter menu, select an application status.

  4. From the Application menu, select the application, and then click Submit.

“Kerberos configuration file has not been uploaded” error message

This system log error indicates that the Kerberos configuration file is not installed on the printer.

Make sure the Kerberos configuration file is installed

If you want to use the device Kerberos setup file, then make sure the file is installed on the printer.

If you want to use simple Kerberos setup to create the Kerberos configuration file, then manually configure the simple Kerberos setup settings.

For information about installing a Kerberos configuration file or configuring simple Kerberos setup settings, see Configuring Kerberos settings.

“Kerberos configuration file is not properly formatted” error message

This system log error indicates that the Kerberos configuration file contains incorrect information, is missing information, or is not formatted properly.

Modify the installed Kerberos configuration file

If you used the device Kerberos setup file, then modify and reinstall the file.

If you used simple Kerberos setup, then modify the simple Kerberos setup settings. For information about configuring simple Kerberos setup settings, see Using simple Kerberos setup.

“Unable to authenticate. Check Kerberos configuration file to verify Windows support enabled” error message

This system log error indicates that the Windows domain is not specified in the Kerberos configuration file.

Make sure the Windows domain is specified

If you used the device Kerberos setup file, then add an entry to the domain_realm section of the file, mapping the lowercase Windows domain to the uppercase realm. When you are done, reinstall the file on the printer.

If you used simple Kerberos setup, then:

  1. Access the application configuration settings from the Embedded Web Server.

  2. Under the Simple Kerberos Setup heading, add the Windows domain (in lowercase) to the Domain field.

    Example: If the value in the Domain field is DomainName,.DomainName and the Windows domain is x.y.z, then change the value in the Domain field to DomainName,.DomainName,x.y.z.

  3. Click Apply.

“Unable to generate certificate from card” or “Unable to read certificate information from card” error message

These system log errors indicate that the Smart Card certificate was not found or that an error occurred while the application was attempting to retrieve data from the Smart Card certificate.

Check the certificate on the Smart Card

Verify that the certificate information on the Smart Card is correct. If the information is correct and the issue still occurs, then contact your solutions provider.

“The domain controller did not respond within the required time; the domain controller timeout may need to be increased” error message

Try one or more of the following:

Increase the domain controller timeout

If you used the device Kerberos setup file, then increase the number of seconds specified for the timeout entry in the file. When you are done, reinstall the file on the printer.

If you used simple Kerberos setup, then:

  1. Access the application configuration settings from the Embedded Web Server.

  2. Under the Simple Kerberos Setup heading, increase the number of seconds specified in the Timeout field.

  3. Click Apply.


Make sure the domain controller IP address or host name is correct

If you used the device Kerberos setup file, then:

  1. From the Embedded Web Server, click Settings or Configuration.

  2. Click Security > Security Setup > Kerberos 5 > View File.

  3. Make sure the domain controller IP address or host name specified in the configuration file is correct.

If you used simple Kerberos setup, then:

  1. Access the application configuration settings from the Embedded Web Server.

  2. Under the Simple Kerberos Setup heading, verify that the IP address or host name specified in the Domain Controller field is correct.

  3. Click Apply.


Make sure the domain controller is available

This error can occur if the domain controller is not available at the time a user is trying to authenticate to the printer. You can resolve this by specifying multiple domain controllers. If a domain controller is not available, then the next one listed will be tried. You can specify multiple domain controllers in the Kerberos configuration file or in the simple Kerberos setup Domain Controller field. If you are using the Domain Controller field, then separate each value with a comma.


Make sure Port 88 is not blocked by a firewall

Port 88 must be opened between the printer and the domain controller for authentication to work.

“The domain controller issuing certificate has not been installed” error message

This system log error indicates that the required Certificate Authority (CA) certificate is not installed or that an incorrect certificate is installed.

If an incorrect certificate is installed, then the error message specifies the name of the certificate that is needed: “The domain controller issuing certificate [NAME OF CERTIFICATE] has not been installed.”

Make sure the correct certificates are installed on the printer

See Installing certificates manually.

“The realm on the card was not found in the Kerberos configuration file” or “User’s realm was not found in the Kerberos configuration file” error message

These system log errors indicate that the user’s realm in the Kerberos configuration file is missing or incorrect.

Add the missing realm or modify the incorrect realm

If you used the device Kerberos setup file, then add the missing realm or realms to the file, or modify the incorrect realms. Make sure each realm is typed in uppercase. When you are done, reinstall the file on the printer.

If you used simple Kerberos setup, then:

  1. Access the application configuration settings from the Embedded Web Server.

  2. Under the Simple Kerberos Setup heading, add the missing realm to the Realm field or correct the realm. Make sure the realm is typed in uppercase.

    Note: The simple Kerberos setup settings do not support multiple Kerberos realm entries. If multiple realms are needed, then install a Kerberos configuration file containing the necessary realms.

“Unable to authenticate. Verify the realm was specified in UPPERCASE” error message

Make sure the Kerberos realm is in uppercase

If you used the device Kerberos setup file, then:

  1. From the Embedded Web Server, click Settings or Configuration.

  2. Click Security > Security Setup > Kerberos 5 > View File.

  3. Make sure the realm entries in the configuration file are in uppercase.

If you used simple Kerberos setup, then:

  1. Access the application configuration settings from the Embedded Web Server.

  2. Under the Simple Kerberos Setup heading, make sure the realm is correct and that it is typed in uppercase.

  3. Click Apply.

“Unable to contact the domain controller for the user’s realm” error message

This system log error indicates that the domain, realm, or domain controller specified in the Kerberos configuration file is incorrect.

Check the domain, realm, and domain controller in the Kerberos configuration file

If you used the device Kerberos setup file, then:

  1. From the Embedded Web Server, click Settings or Configuration.

  2. Click Security > Security Setup > Kerberos 5 > View File.

  3. Make sure all domain, realm, and domain controller information is correct.

If you used simple Kerberos setup, then:

  1. Access the application configuration settings from the Embedded Web Server.

  2. Under the Simple Kerberos Setup heading, make sure the values typed in the Realm, Domain Controller, and Domain fields are correct. For information about configuring these settings, see Using simple Kerberos setup.

  3. Click Apply.

“Domain controller and device clocks are different beyond an acceptable range. Check the device's date and time” error message

This system log error indicates that the printer clock is more than five minutes out of sync with the domain controller system clock.

Check the date and time on the printer

  1. From the Embedded Web Server, click Settings or Configuration.

  2. Click Security > Set Date and Time.

    • If you configured date and time settings manually, then verify or correct the settings. Make sure the time zone and daylight saving time (DST) settings are correct.

    • If you configured the printer to use a Network Time Protocol (NTP) server, then verify that the NTP settings are correct and that the NTP server is functioning correctly.

      Note: If your network uses Dynamic Host Configuration Protocol (DHCP), then verify that NTP settings are not provided by the DHCP server automatically before configuring NTP settings manually.
  3. Click Submit.

“Unable to validate certificate from domain controller” error message

This system log error indicates that the required Certificate Authority (CA) certificate or certificates are not installed on the printer or that you selected the wrong domain controller validation method. Try one or more of the following:

Make sure the correct certificates are installed on the printer

See Installing certificates manually.


Check the domain controller validation method

  1. Access the application configuration settings from the Embedded Web Server.

  2. Under the Smart Card Setup heading, make sure you selected the correct method from the Domain Controller Validation menu. For information about configuring this setting, see Selecting the domain controller validation method.

  3. Click Apply.

“An error occurred during domain controller chain validation” or “At least one of the certificates in the domain controller certificate chain has been revoked” error message

These system log errors indicate that there is a problem with one or more of the certificates needed for chain validation. Certificates may be missing, expired, or revoked, or they may contain incorrect information.

Check the certificates installed on the printer

  1. From the Embedded Web Server, click Settings or Configuration.

  2. Click Security > Certificate Management > Certificate Authority Management.

  3. Make sure all certificates required for chain validation are installed and contain correct information. Make sure none of the certificates have been revoked or are expired.

    If you need to install certificates, then see Installing certificates manually.

    If all certificates are installed correctly and these issues still occur, then contact your solutions provider.

“The OCSP responder URL or certificate has not been configured” error message

This system log error indicates that OCSP settings are not configured correctly.

Check the OCSP responder URL and responder certificate

  1. Access the application configuration settings from the Embedded Web Server.

  2. Under the Online Certificate Status Protocol (OCSP) heading, make sure the values in the Responder URL and Responder Certificate fields are correct. For information about configuring these settings, see Selecting the domain controller validation method.

  3. Click Apply.

“An error occurred while trying to connect to the OCSP responder” error message

This system log error indicates that the OCSP responder URL is configured incorrectly or that the responder timed out before the application could connect to it. Try one or more of the following:

Check the OCSP responder URL

  1. Access the application configuration settings from the Embedded Web Server.

  2. Under the Online Certificate Status Protocol (OCSP) heading, make sure the value in the Responder URL field is correct. For information about configuring this setting, see Selecting the domain controller validation method.

  3. Click Apply.


Increase the responder timeout

  1. Access the application configuration settings from the Embedded Web Server.

  2. Under the Online Certificate Status Protocol (OCSP) heading, increase the number of seconds specified in the Responder Timeout field.

  3. Click Apply.

“The status of at least one of the certificates in the domain controller certificate chain is unknown” error message

Try one or more of the following:

Check the certificates installed on the printer

  1. From the Embedded Web Server, click Settings or Configuration.

  2. Click Security > Certificate Management > Certificate Authority Management.

  3. Make sure all certificates required for chain validation are configured correctly. See Installing certificates manually.


Allow users to log in if the certificate status is unknown

  1. Access the application configuration settings from the Embedded Web Server.

  2. Under the Online Certificate Status Protocol (OCSP) heading, select Allow Unknown Status. This allows users to log in to the printer even if the status of one or more of the required certificates is unknown.

  3. Click Apply.

“The OCSP responder certificate, stored on the printer, does not match the one returned by the responder” error message

Try one or more of the following:

Check the OCSP responder certificate

  1. Access the application configuration settings from the Embedded Web Server.

  2. Under the Online Certificate Status Protocol (OCSP) heading, make sure the correct certificate has been uploaded in the Responder Certificate field.

  3. Click Apply.


Check the certificate returned from the OCSP responder

Make sure the OCSP responder is returning the correct certificate.

“An error occurred while trying to validate the domain controller certificate against the OCSP responder” error message

This system log error indicates that the domain controller is returning an incorrect certificate or that the OCSP responder is not checking the correct certificate. Try one or more of the following:

Check the domain controller certificate

Make sure the domain controller is returning the correct certificate.


Check the OCSP responder

Make sure the OCSP responder is checking the correct domain controller certificate.

“The user is not authorized to use this device. Make sure the user belongs to an Active Directory group that is authorized to use the device” error message

This system log error usually indicates that the user is not in an Active Directory group that is authorized to use the printer. Try one or more of the following:

Add the user to an authorized Active Directory group

If user authorization is enabled for the printer, then add the user to an Active Directory group that is included in the authorization list for the printer.


Add the user’s group to the authorization list for the printer

Make sure the user’s Active Directory group is listed in the Group Authorization List field in the application configuration settings.

  1. Access the application configuration settings from the Embedded Web Server.

  2. Under the Advanced Settings heading, add the user’s Active Directory group to the Group Authorization List field. Separate multiple groups with a comma.

  3. Click Apply.