pete Posted January 6, 2025 Posted January 6, 2025 We run Kyocera copiers (Taskalfa 3000, 5000 & 7000 series, depending on volume at each school) and use a Let's Encrypt certificate (print.int.ourdomain.whatever). On the previous copier hardware (Konica) renewing the PaperCut certificate required no intervention on a per-copier basis. On the current copier hardware (Kyocera), any change in certificate on the server side requires manual confirmation via the papercut frontend running on each copier: "A new certificate has been detected when connecting to print.int.ourdomain.whatever:443 Fingerprint: (fingerprint goes here) Permanently accept this certificate?" We ran into this in October and assumed (wrongly, it turns out) it was due to the Kyocera techs using the server IP rather than the DNS name, so we amended the config to avoid a repeat. Today (Jan) we got the prompt again. Is there a hidden "only whine about certs that aren't valid" option that we're missing?
RobFuller Posted January 8, 2025 Posted January 8, 2025 Did you find a workaround for this Pete? About to face my annual cert update challenge in same way on our Ricoh machines.
pete Posted January 8, 2025 Author Posted January 8, 2025 (edited) ^ Not yet (dealing with another issue atm). I'm going to chase with PaperCut directly to see if it's them (would hope not - I expect better from them) or a PaperCut + certain copiers issue. We could have just missed a setting because it's in a daft place (or poorly labelled) in the copier config. Hopefully it's not a DenverCoder9 (https://xkcd.com/979/) problem. Edited January 8, 2025 by pete
old_n07 Posted January 8, 2025 Posted January 8, 2025 We have this when we renew the cert on our Papercut server, this is with Ricoh copiers. While it is a pain it can be done via the remote operations panel for the copiers so we don't have to visit each one in person. Neil
pete Posted January 8, 2025 Author Posted January 8, 2025 We have this when we renew the cert on our Papercut server, this is with Ricoh copiers. While it is a pain it can be done via the remote operations panel for the copiers so we don't have to visit each one in person. Neil Yeah, but it falls under "things I shouldn't have to do given how much this hardware costs on a yearly basis" and we're up to 20 copiers already. 1
Steve21 Posted January 9, 2025 Posted January 9, 2025 Haven't used it for a while for PaperCut, but it used to be an option in the renewal tools as to whether you wanted the same fingerprint or not. Most LE things like CertifyTheWeb etc change the fingerprint each renewal if you just do a standard "auto" renewal, and then yes you need to accept to the change on every printer each time Steve
pete Posted January 9, 2025 Author Posted January 9, 2025 PaperCut support did point me towards the Kyocera NetViewer tool that they believe allows a bulk "yes, the cert's fine shut up and get on with it" acceptance across N+1 copiers. 1
RobFuller Posted January 21, 2025 Posted January 21, 2025 Just updated the PaperCut server cert and our Rioch's with the PaperCut Smart client just accepted it without prompt .. Perhaps PaperCut rolled out an update that auto accepts valid certificates, either way very happy! 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now