Print Service updates are cumulative. This update includes previously released Print Service fixes and improvements.
Before You Start
This update should be applied to installations using Uniprint Suite 9.2.
This update relates to Microsoft's phasing out of NTLM authentication in Windows. Depending on how your site authenticates users, further action may be required after applying it. See Details below.
If you also run the Pharos SignUp Service, apply the SignUp Server Update as well. The same improvements are needed there, because a SignUp Bank can also use a Logon plug-in.
If you use the Pharos Active Directory LDAP Plug-in (adldaplogon.exe), there is a separate plug-in hot-fix to apply. It is not delivered by the Updater Service.
Installation
The update affects the Print Server and should be applied to all machines running the Pharos Print Service.
The Print Service is offered as an update via the Updater Service in Pharos Administrator
For Servers with Internet access:
Open the Pharos Administrator application and access the Updater Service context under System.
Click to Download and Install the update for Print Service version 9.2.10000.409
For Servers without access to the Internet, the update can be applied as follows:
Download the 9.2.10000.409-PrintServerUpdate.zip file from the Pharos Hot Fixes web page.
In the properties of the zip file, choose to unblock and then unzip the file.
The zip file contains three files. All three files are required for the Print Service update to be available:
Uniprint.PrintService.9.2.1000.409.nupkg
Uniprint.LPD.Service.194.nupkg
Uniprint.SecureRelease.Service.4.21.30.2.nupkg
Copy the unzipped contents (all three .nupkg files) and paste into the following location on the Principal Server (the server hosting the Pharos Database Service):
\ProgramData\PharosSystems\UpdaterService\cache-v2.0\Note: Copying the package files onto the Principal Server will make the Print Service update available to all Pharos Print Servers on the site. If you are unable to copy the packages to the Principal Server, then they will need to be copied to the same ..\cache-v2.0\ location on each Print Server.
Open the Pharos Administrator application and access the Updater Service context under System.
The Print Service update should now be listed as an update for all Print Server machines.
Click to Download, and then Install the package on all Pharos Print Servers.
The application of this update constitutes acceptance of the conditions specified in your license agreement. To view the license agreement, please refer to the license.rtf file on your Pharos CD.
Details
This update addresses the following:
Kerberos support in the Auth scripting namespace. Microsoft is phasing out NTLM authentication in Windows and will disable network NTLM by default in a future Windows release. Where a scripted Logon plug-in authenticates users against Active Directory using the
Authnamespace functionsLdapADorLdapKerberos, the bind is performed through Windows and may currently be using NTLM. This update improves the handling of Kerberos authentication in those functions, covering a wider range of logon name formats and account states.
There is no change to how these functions are called. Function names, parameters and return values are unchanged, so existing logon scripts continue to compile and run as before.
Action may be required. Applying this update does not change how your system authenticates users today. However, once NTLM is disabled in your environment, authentication depends on Kerberos succeeding, and some configurations need attention first. The most common is a logon script that passes a directory server's IP address rather than its name, which works under NTLM but generally cannot work under Kerberos. For guidance on determining whether your site is affected, and for the recommended migration and testing procedure, refer to the Preparing Uniprint for NTLM Disablement TechNote.
For details on all improvements and bug fixes to the Print Server, please see the 9.2 Release Notes information in the Pharos Help Center.