Configuring Toshiba for YSoft SafeQ Embedded Terminal

Supported MFPs

SafeQ currently supports only models based on e-Bridge X architecture.

Auto-installation of YSoft SafeQ Terminal Embedded requires a MFP firmware version supporting SDK 2.4 or higher 

Configuration of MFP

Authentication

Enabling property internalLdapAllowNonsecureProtocol allows sending user credentials (entered on Toshiba device) unencrypted which could be misused by an attacker for unauthorized access. Use it only when there is no other option.

Certificates

After the first installation of YSoft SafeQ Terminal Embedded, it is necessary to upload a CA certificate to the device to make sure that communication with Terminal Server is trusted.

If you do not mind security issues you can use safeqds.cer certificate from the installation package.

In the case of updating to MU53 and higher, it is necessary to repeat this procedure. The reason is that the certificate was updated.

images/download/attachments/27004559/certificate-management.JPG

How to with certificates

You can follow the document below to select a certificate on Terminal Server:

Selecting certificate of Terminal Server

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/warning.svg Toshiba made the security more stricker and generic certificates might not work. For devices based on e-BRIDGE NEXT or later architecture, generation of IP-specific certificate is necessary to supress SSL/TLS warnings.

Allowing Direct printing

If you want to use direct printing, it is necessary to allow printing for unauthenticated jobs. Navigate to Administration -> Security -> Authentication. You need to configure the section User Authentication Setting.

Configure option Authentication failed print job/Raw Print Job to Print.

images/download/attachments/27004559/toshiba_direct.png

images/download/attachments/14976741/warning.png  As a consequence, any print performed directly to the printer would be printed with this setting. To prevent unwanted prints, setup IP filtering ( Administration -> Setup -> Network -> Filtering).

Allowing Card readers

If you do not see the configuration for Card authentication, turn off the device and follow these steps:

  1. Connect the USB card reader.

  2. Turn on the device.

  3. Enter the service menu.

  4. On the next screen, enter 3500 and press green start-button.

  5. Now enter 60001 and press OK.

  6. Now enter 9398 and press green start-button again.

  7. Enter eBMUserCard and restart the printer.

  8. Now you should be able to continue with configuration of LDAP server.

images/download/attachments/14976741/warning.png List of Toshiba devices and required FW versions that supports USB card readers is in the following article.

images/download/attachments/14976741/warning.png YSoft USB card reader registration chapter must be done when the Toshiba MFP FW is lower version than FW which has YSoft USB card reader already preregistered. The card reader registration procedure is described in the article configure Toshiba device to work with YSoft USB card reader.

Time Configuration

Time settings have to be configured for proper accounting of jobs and assignment of billing codes to these jobs.

Go to Administration > General and configure Daylight Saving Time Settings to comply with configuration of your server, where Terminal Server is running

images/download/attachments/27004559/image2015-1-5_13_17_46.png

 

Next, there are two options possible, based on the availability of SNTP (time) server in your network:

  1. If SNTP is available, set all necessary details in section SNTP Service and set your timezone

    images/download/attachments/27856877/image2014-11-21_9_39_4.png
  2. If SNTP is not available, in section Date & Time set timezone, date and time to the time of the Terminal Server. Also disable SNTP server.
    images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/warning.svg  WARNING:  Be sure to set the time as precisely as possible (in means of seconds) to avoid errors in assigning billing codes to scan jobs and copy jobs. It is better for the MFP to have the clock set slightly forward, than backward.

    images/download/attachments/27856877/image2014-11-21_9_33_6.png

Display the SafeQ application screen after successful login

To improve the experience with SafeQ Toshiba Embedded application, we recommend to do following steps to display the SafeQ application as initial screen after successful login.

  1. Enter the service menu.

  2. Press 9955 to change the Extension label to "SafeQ" and click OK to save.

  3. Press 9132 and insert value 99.

Accounting configuration

If you are planning to install accounting feature, you need to delete old job logs before installing the embedded terminal.

Go to Administration > Logs > Export Logs and click on all the buttons that are highlighted below. Optionally, the logs can be exported by using the Create New File buttons.

images/download/attachments/27004559/toshiba_delete_all_logs.png

Configuring WNLB Server Failover

Limitations

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/warning.svg When most of WNLB Cluster members are offline for about 24 hours, there is a possibility that user will not be able to enter YSoft SafeQ application. If the problem occurs, restart Terminal Server service on all nodes or wait for an hour.

  1. Follow Configuring WNLB Server Failover steps.

  2. Set property forceInternalLdapServerIp (expert view) to WNLB virtual IP address.  
     

    images/download/attachments/27004559/ldap_property.png
  3.   Install or reinstall YSoft SafeQ Embedded Terminal for each Toshiba device

Configuring HTTP and HTTPS ports

The MFP uses port numbers 40629 and 40630 for HTTP and HTTPS communication.

If you are planning to use different port numbers, you have to change values of configuration properties openPlatformHttpPort and openPlatformHttpsPort and change port numbers on MFP web.

  1. Set property openPlatformHttpPort (expert view) for HTTP communication .  

  2. Set property openPlatformHttpsPort (expert view) for HTTPS communication .  

  3. Go to Administration > Setup> ODCA and change values of ports. Then click on Save button.

images/download/attachments/27004559/Toshiba_ODCA.png

Additional requirements

  • YSoft SafeQ verifies the originating device against the list of active devices in the database. For this purpose the translation of MFP IP address to the hostname/FQDN using standard Windows features (DNS/NetBIOS) is made. Please make sure the MFP is properly registered in the DNS or WINS server as the delays in translation may lead to timeouts or failures during authentication.