Uniprint 9.2 SignUp Server Update Rev 409

Prev Next

SignUp Service updates are cumulative. This update includes previously released SignUp Service fixes and improvements.

Before You Start

  • This update should be applied to installations using Uniprint Suite 9.2.

  • This update relates to Microsoft's phasing out of NTLM authentication in Windows. Depending on how your site authenticates users, further action may be required after applying it. See Details below.

  • Apply the Print Server Update as well. The same improvements are required on both services.

  • If you use the Pharos Active Directory LDAP Plug-in (adldaplogon.exe), there is a separate plug-in hot-fix to apply. It is not delivered by the Updater Service.

Installation

The update affects the SignUp Server and should be applied to all machines running the Pharos SignUp Service.

The SignUp Service is offered as an update via the Updater Service in Pharos Administrator

For Servers with Internet access:

  1. Open the Pharos Administrator application and access the Updater Service context under System.

  2. Click to Download and Install the update for SignUp Service version 9.2.10000.409

For Servers without access to the Internet, the update can be applied as follows:

  1. Download the 9.2.10000.409-SignUpServerUpdate.zip file from the Pharos Hot Fixes web page.

  2. In the properties of the zip file, choose to unblock and then unzip the file.

  3. Copy the unzipped contents (all .nupkg files) and paste into the following location on the Principal Server (the server hosting the Pharos Database Service):
    \ProgramData\PharosSystems\UpdaterService\cache-v2.0\

  4. Note: Copying the package files onto the Principal Server will make the SignUp Service update available to all Pharos SignUp Servers on the site. If you are unable to copy the packages to the Principal Server, then they will need to be copied to the same ..\cache-v2.0\ location on each SignUp Server.

  5. Open the Pharos Administrator application and access the Updater Service context under System.

  6. The SignUp Service update should now be listed as an update for all SignUp Server machines.

  7. Click to Download, and then Install the package on all Pharos SignUp Servers.

The application of this update constitutes acceptance of the conditions specified in your license agreement. To view the license agreement, please refer to the license.rtf file on your Pharos CD.

Details

This update addresses the following:

  • Kerberos support in the Auth scripting namespace. Microsoft is phasing out NTLM authentication in Windows and will disable network NTLM by default in a future Windows release. A SignUp Bank can use a Logon plug-in in the same way a Print Bank can, so where a scripted Logon plug-in authenticates users against Active Directory using the Auth namespace functions LdapAD or LdapKerberos, the bind is performed through Windows and may currently be using NTLM. This update improves the handling of Kerberos authentication in those functions, covering a wider range of logon name formats and account states.

There is no change to how these functions are called. Function names, parameters and return values are unchanged, so existing logon scripts continue to compile and run as before.

A note for sites using individual network accounts

SignUp authenticates a user twice: once against the Pharos reservation system, and once against the network so that they can use the computer itself. How the second logon is performed is set by the LAN Logons property at SignUp > SignUp Global Settings > Reservations.

Where an Environment supplies a common network account that a group of users are logged on with, no change is required. The credentials belong to the Environment and are configured in Pharos rather than typed by the user.

Where LAN accounts only is selected, each user supplies their own network credentials. sAMAccountName logons are unaffected. If your users sign on with a user principal name, for example jsmith@example.com, authentication will succeed but the name recorded against the session is the name the user typed, which may not match the user's Pharos Logon ID. A script change may be needed so that reservations and their transactions are attributed to the right user. The TechNote below explains the approach and points at a worked example that ships with the product.

Action may be required. Applying this update does not change how your system authenticates users today. However, once NTLM is disabled in your environment, authentication depends on Kerberos succeeding, and some configurations need attention first. For guidance on determining whether your site is affected, and for the recommended migration and testing procedure, refer to the Preparing Uniprint for NTLM Disablement TechNote.

For details on all improvements and bug fixes, please see the 9.2 Release Notes information in the Pharos Help Center.