Specifications
6
White Paper: Canon imageRUNNER/imagePRESS Security
Simple Device Login (SDL)
Simple Device Login is a MEAP login service that can be used stand-alone with the device. User
data is registered in the device’s memory using a web browser.
The SDL login service provides the following functions:
• Displays a login screen on the touch panel display of the device, and performs user
authentication
• Displays a login page when the device is accessed from a web browser, and performs
authentication
• Enables you to limit and keep track of the print/scan totals for department IP, by linking
to the department ID Management functions of the device
The SDL login service can be configured using the MEAP Service Management Service.
To enable the SDL login Service, open a web browser and enter the URL
http://<imageRUNNER IP Address or host name>:8000/sms. On the login page type the
password. Click on the System Management tab. Click on the Enhanced Sys. App tab.Under
login service select “Simple Device Login.” Click the select button. Reboot the device.
Single Sign On Login
Single Sign On (SSO) is a MEAP login service that can be used in conjunction with an Active
Directory (AD) network environment. SSO supports the following modes:
• Local Device Authentication
• Domain Authentication – in this mode, user authentication can be linked to an Active
Directory environment on the network
• Domain authentication + local device authentication
When used in Domain Authentication mode, a user must successfully authenticate using valid
Windows AD credentials prior to gaining access the any of the MFP device functions.
SSO ships standard with MEAP capable imageRUNNER and imagePRESS devices and can
support up to 200 domains. The latest device models ship with a version of SSO called SSO-H,
which supports direct authentication against AD using Kerberos or NTLMv2 as the
authentication protocol. In local device authentication, SSO-H can support up to 5,000 users.
Earlier MEAP devices support a version of SSO that utilizes a Security Agent (SA) to accomplish
authentication against AD. The SA is a small Windows application which can be run on any PC
system that is a member of the same Windows domain. This earlier version of SSO only
supports NTLMv2 as the authentication protocol and can support up to 1,000 users.
To enable the SSO login Service, open a web browser and enter the URL http://<imageRUNNER
IP Address or host name>:8000/sms. On the login page type the password. Click on the
System Management tab. Click on the Enhanced Sys. App tab. Under login service select
“Single Sign-On.” Click the Select button. Reboot the device
Section 2 — Canon’s Imaging & Printing Security Framework