Print Controller Design Guide for Information Security
Page 21 of 86
1-5 Authentication, Access Control
1-5-1 Authentication
When enabled, User Authentication requires all users to go through a username and password-based
authentication process before MFP/LP operations can be performed. This is true in cases where the
user attempts to access MFP/LP functions via the operation panel as well as via a network connection.
There are five types of User Authentication:
Basic Authentication
User Code Authentication
Windows Authentication
LDAP Authentication
Integration Server Authentication
As the authentication server, the MFP/LP can be used for Basic Authentication, a Windows NT4.0
server, Windows 2000 server or Server2003 can be used for Windows Authentication, and an LDAP
server can be used for LDAP Authentication. In addition, when “Integration Server Auth” is selected
from the User Authentication menu, the MFP/LP connects to the actual authentication server via an
Integration Server. In this case, the authentication is performed using the User Authentication
functions of ScanRouter, ScanRouter Document Server, Web SmartDeviceMonitor Professional IS or
ScanRouter Web Navigator.
Note: See “Windows Authentication, LDAP Authentication” and “Integration Server Authentication”
diagrams below.
Usernames:
Format: US-ASCII, WinLatin1, WinLatin2, WinCyrillic
Length: Maximum 32 characters
Note:
Although it is possible to input the 2-byte characters used in display languages such as
Chinese, Japanese, Taiwanese, and Korean, they are not supported.
Although usernames longer than 32 characters are invalid, the input field will accept up to
128 characters in order to make the 32-character limit more difficult to surmise.
Passwords:
Format: US-ASCII, WinLatin1, WinLatin2, WinCyrillic
Length: Maximum 128 characters (general users), 32 characters (Administrators).
Note: Although it is possible to input the 2-byte characters used in display languages such as
Chinese, Japanese, Taiwanese, and Korean, they are not supported.
Before authentication at the MFP/LP operation panel can be performed, uses must be pre-registered