Session Logon Settings and Related Advanced Settings

 

Glossary

Authentication provider (AP):

An external system which is capable to authenticate the device user and capable provide the user credentials to ShareScan

Authentication providers can be grouped as:

Server Authentication provider (SAP):

An external system integrating to ShareScan via the Cost Recovery Service (like Equitrac or Copitrak) or the ID Service (like NTWare Uniflow or Canon ScanFront Fingerprint Authentication).

Device Authentication Provider (DAP):

There is an authentication application installed on the device that is able to pass on username and domain name data to the ShareScan application. Examples: Ricoh AAA, Xerox SecureAccess etc.

 

Session Logon Service settings

Session Logon Mode:

Disable manual credential entry on Session Logon screen

When this setting is chosen, the manual entry of the user name and domain fields are disabled on the Session Logon screen, displayed on the MFP, but the password filed can be edited. This is meaningful (and strongly recommended) to check when ShareScan is integrated with an Authentication system, because these systems provide the username and other data without manual entry.

When integrating with such systems, leaving this setting unchecked may lead to a security issue in certain cases, depending on the configuration.

If Session logon mode is set to Bypass session logon (authenticate user) or to Bypass session logon (no authentication) then the username and the domain fields are automatically disabled (not necessary to check this setting).

Hide Logout button

The Logout button will be hidden on the MFP screens (Main screen, Redirect screen) if this setting is chosen. It is recommended to select this setting when ShareScan is integrated with an External Authentication system.

Hiding the Logout button prevents the users to log out from ShareScan by hitting the Logout button (it could appear on the Main screen or on the Redirect screen). This is useful when we want to force the users to use the card swipe or the hardware logout button to log out from the External Authentication system on the MFP device.

Cost Recovery Service settings

Show Lock Button

ScanStation only setting. When this setting is enabled (checked) a Lock button will be shown on the ShareScan Session Logon screen. If the user clicks this button, the Cost Recovery session will be terminated (the AP / CR server will be notified) and a lock cover screen is displayed on the ScanStation application, blocking any access to ShareScan until the user unlocks (logs in into) the Cost Recovery system.

ID Service settings

Accept UserID only requests from External Service

If configured in a certain way, the AP is able to send a ‘user ID’ instead of the user name (domain user account name). This setting must be checked if we want to use that type of integration.

Advanced Settings

AutoQuitShareScanOnAutoLogout

Supported only on certain platforms like KonicaMinolta, Xerox, Ricoh and HP.

The setting plays a role only for the workflows when ’Bypass redirect screen’ and ’Logoff automatically’ settings of the connector settings are both enabled.

It is reasonable to have these two settings enabled when we want to allow the users to execute only one scanning workflow (i.e. one connector usage) in a session.

The behavior controlled by this setting is the following:

When AutoQuitShareScanOnAutoLogout is set to

AutoQuitShareScanOnLogoff (formerly called SingleSignOff)

Supported only on certain platforms like KonicaMinolta, Xerox, Ricoh and HP.

Enables (true) or disables (false) closing/leaving the ShareScan application on the MFP when the user logs out manually by clicking the Logout button on the ShareScan Main screen or Redirect screen.

RicohCRClientProductID

Product ID of the application to switch to, when AutoQuitShareScanOnAutoLogout or AutoQuitShareScanOnLogoffis used.

E.g.: if Equitrac PCC is the authentication client on the Ricoh device, then the Application ID of PCC should be set for this setting.

SessionLogonDomainCacheEnabled

If domain information is unavailable, Session Logon attempts to retrieve it from the credential cache.

It is possible to use this setting in conjunction with Session Logon mode ‘Bypass Session Logon (authenticate user)’, in cases when the integrating AP or DAP is not providing a domain name.

When this setting is true, ShareScan will use only the user name (as a key) to store / fetch the corresponding password and it stores / fetches the domain name as well.

SessionLogonOverrideHomeDirectory

If set, the home directory location specified in this setting will be used in some of the Connectors as the home folder of the logged in user, ignoring the actual LDAP query result. (i.e. the home folder will be the same for all users – this is useful in some special scenarios).

UseSecureLDAP

Use Secure LDAP (LDAPS) for LDAP operations; it can be: true, false.

DirectLockScanStation (formerly called DirectLock)

Locking ScanStation along with the device when the Lock button is pushed on Session logon or Main screens.

If set to