Loading

Configure EAP-TLS with printer name authentication

Before you begin

This instruction applies to the [Printer name from domain; EAP-TLS] authentication method. The authentication method refers to the method you selected on PRISMAsync Print Server.

The instructions below refer to Windows Server 2016. Other systems may need other configuration. See the vendor documentation for complete instructions.

These configurations have been done.

  1. Configure IEEE 802.1X on the authentication server (phase 1)

  2. Configure IEEE 802.1X on the authenticator

  3. Configure IEEE 802.1X on PRISMAsync Print Server

Perform the instructions in the order they are listed.

Instruction 1. On Active Directory, create a group on the domain

  1. In [Server Manager] click [Tools].

    [Server Manager] options
  2. Open the [Active Directory Users and Computers] console.

  3. Right-click the domain name, click [New]. Then click [Group].

  4. Enter a name for the group.

    New group
  5. Select [Global] in the [Group scope] option group.

  6. Select [Security] in the [Group type] option group.

  7. Click [OK].

Instruction 2. On Active Directory, add printer name as computer name

  1. In [Server Manager], click [Tools].

    [Server Manager] options
  2. Open the [Active Directory Users and Computers] console.

  3. Expand the domain entries.

  4. Right-click [Computers].

  5. Click [New]. Then, click [Computer].

  6. Enter the hostname of the printer.

    DNS uses the hostname and appends the DNS domain hierarchy to that name to create the FQDN name.

    Find the hostname on the Identity certificate of PRISMA Print Server.

    The [Subject alternative name 1], [Subject alternative name 2] or [Subject alternative name 3] field contains the contents of the [Common name] field. This is the Fully Qualified Domain Name (FQDN) printer name, such as: hostname.example.net. Here you enter the hostname part of the FQDN.

    New computer
  7. Click [OK].

  8. When the printer name is added, right-click the name. Then click [Properties].

  9. Click the [Member Of] tab and select the group you created in instruction 1.

    Select group
  10. Click the [Dial-in] tab.

  11. In the [Network Access Permission] option group, select [Control access through NPS Network Policy].

    [Dial-in] options
  12. Click [OK].

  13. Open the ADSI Edit editor.

    ADSI Edit editor
  14. Browse to the CN=Computers directory.

  15. Right-click the printer name and click [Properties].

  16. Select [servicePrincipalName] and click [Edit].

  17. Enter the printer name according to this format: host/<hostname>.<DNS domain hierarchy> . For example: host/PRISMAprinter.ft5.cppvenlo.cpp.net.

  18. Click [OK].

Instruction 3. On authentication server, configure network policy for EAP-TLS with printer name authentication

  1. In [Server Manager], click [Tools].

    [Server Manager] options
  2. Open the [Active Directory Users and Computers] console.

  3. Open the [Policies] directory.

  4. Right-click [Network Policies]. Then click [New] to open the [New Network Policy] wizard.

  5. Enter a policy name.

    [New Network Policy] wizard
  6. Ensure [Unspecified] is selected in the [Type of network access server] option.

  7. Click [Next].

  8. On the [Specify Conditions] page, click [Add...]. Then select [Machine Groups].

    [New Network Policy] wizard
  9. Click [Add...] to add and select the group you created in instruction 1.

    [New Network Policy] wizard
  10. Click [OK] to close the [Select Group] dialog box.

  11. Click [Next].

    [New Network Policy] wizard
  12. On the [Specify Access Permission] page, select [Access granted].

    [New Network Policy] wizard
  13. Click [Next].

  14. On the [Configure Authentication Methods] page, click [Add...]].

    [New Network Policy] wizard
  15. In the [Add EAP] dialog box, select [Microsoft: Smart Card or other certificate].

  16. Click [OK].

    [New Network Policy] wizard
  17. From the [EAP Types] list, select [Microsoft: Smart Card or other certificate]. Then, click [Edit].

  18. In the [Smart Card or other Certificate Properties] dialog box, select the Identity certificate of the RADIUS server. This certificate refers to the trusted certificate available on PRISMAsync Print Server.

    [New Network Policy] wizard
  19. Click [OK].

  20. Clear the [Less secure authentication methods] check boxes that refer to authentication methods you do not want to use.

    [New Network Policy] wizard
  21. Click [Next].

  22. On the [Configure Constraints] page, click [Next].

    [New Network Policy] wizard
  23. On the [Configure settings] page, click [Next].

    [New Network Policy] wizard
  24. On the [Completing New Network Policy ] page, click [Finish].

    [New Network Policy] wizard