Precautions for Operation in Environments where the FIPS Mode Is Enabled

This software operates when the FIPS mode of Windows is enabled. However, some limitations apply. It may also be necessary to change the settings, depending on the printer.
IMPORTANT
Enable/disable the FIPS mode of Windows before installing this software.
For information on the procedure for enabling/disabling the FIPS mode of Windows with this software installed, see the following.
NOTE
For information on setting the FIPS mode of Windows, see the documentation for Windows.
This software does not have any settings regarding the FIPS mode. In operating systems with the FIPS mode enabled, it operates in the FIPS mode.

Target Devices

When the FIPS mode is enabled, the following models can be managed with this software.
Type I model printers with platform version 3.13 or later
NOTE
This software will not operate correctly unless the platform version 3.13 is applied to the printers.
For information on printer types and the corresponding printer models, see the following.
The method for checking the platform version of the printer is as follows.
1.
Press (Counter/Device Information) or the [Counter/Device Information] key on the printer.
2.
Press [Device Information/Other] > [Check Device Configuration].
3.
Check the version in [Platform Version].

Printer Settings

NOTE
For details on the setting method, see the following.
Printer instruction manuals
Remote UI Settings
Printer control panel menu:
(Settings/Registration) > [Management Settings] > [License/Other]
[Remote UI]
On
[Use TLS]
On
If the Remote UI is already able to be used, this setting can be configured in the Remote UI.

Limitations

Settings for using SNMPv3 in communication with the printer
Only the following algorithms can be used. If they are set in the printers for management, change the settings.
Authentication password algorithm: SHA
Encryption password algorithm: AES
Address Book Management
Click [Data Management] > [Address Books] > click [Import] > [Import Destinations]
Address books exported from a printer or this software with [Security Level] set to [Level1] cannot be imported to this software.
Device Setting Values Management
Click the [Devices] menu > [Security Data] > [Device Setting Values Monitoring Logs] > select data > [Device Setting Values Monitoring Information] > select data in [Monitoring Logs] > [Device Setting Values Monitoring Log Details]
To make the [Data Path] and setting values displayed on the screen readable, it is necessary to upload the settings file of Device Settings Configurator version 2.0.8 or later to this software.
Login Services
The following login services can be used. If a login service other than the following is set in a printer for management, change the login service.
User Authentication
Register the authentication information of a user with administrator privileges to this software in the following format.
[Devices] menu > [Device Communication Settings] > [Authentication Information]
[Authentication Method]:
For Server Authentication: [Domain Authentication]
For Local Device Authentication: [User Authentication]
DepartmentID Authentication
Register the authentication information of a user with administrator privileges to this software in the following format.
[Devices] menu > [Device Communication Settings] > [Authentication Information]
[Authentication Method]: [System Manager ID]
Universal Login Manager
Local or uniFLOW can be used as the authentication mode.
Encrypted communication with the Remote UI must be set.
When using local authentication as the authentication mode, register the authentication information of a user with administrator privileges to this software in the following format.
[Devices] menu > [Device Communication Settings] > [Authentication Information]
[Authentication Method]: [User Authentication]
When using uniFLOW as the authentication mode and the uniFLOW server is linked with Active Directory or an LDAP server, register the authentication information of a user with administrator privileges to this software in the following format.
[Devices] menu > [Device Communication Settings] > [Authentication Information]
[Authentication Method]: [Domain Authentication]
When using uniFLOW as the authentication mode and the uniFLOW server is not linked with Active Directory or an LDAP server, register the authentication information of a user with administrator privileges to this software in the following format.
[Devices] menu > [Device Communication Settings] > [Authentication Information]
[Authentication Method]: [User Authentication]
NOTE
For information on the Active Directory, LDAP server, Universal Login Manager, and uniFLOW settings, see the instruction manual for the corresponding software.

Changing the FIPS Mode Setting with This Software Installed

The procedure for changing the FIPS mode setting with this software installed is indicated below. When upgrading this software, follow this procedure to change the FIPS mode setting before upgrading.
1.
Stop the services of this software.
Open [Windows Administrative Tools] > [Services] from the Start menu.
Stop the services in the following order.
Canon Management Console Agent (only when the Manager and Agent are running on the same computer)
Canon Management Console Manager
2.
Change the FIPS mode settings of Windows.
For information on the FIPS mode setting of Windows, see the documentation for Windows.
3.
Start the services in the following order.
Canon Management Console Manager
Canon Management Console Agent (only when the Manager and Agent are running on the same computer)
4.
If you enabled the FIPS mode with the settings file of Device Settings Configurator version 2.0.7 registered to this software, upload the settings file of Device Settings Configurator version 2.0.8.
For details, see the following.