KofaxEquitracClientSetupGuide612 EN SecurityFramework
KofaxEquitracClientSetupGuide612 EN SecurityFramework
Date: 2019-12-20
Kofax Equitrac® Client Setup Guide
Kofax is a trademark of Kofax, Inc., registered in the U.S. and/or other countries. All other trademarks are the property of their respective owners. No
part of this publication may be reproduced, stored, or transmitted in any form without the prior written permission of Kofax.
Note The accompanying text provides cross-reference links, tips, or general information
that can add to your understanding of the topic.
Caution The accompanying text provides key information about a step or action that might
produce unexpected results if not followed precisely.
Warning Read the accompanying text carefully. This text can help you avoid making errors
that might negatively affect program behavior.
2
Kofax Equitrac® Client Setup Guide
Contents
Silent Installation 14
Running Windows Installer in Silent Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14
Installing the Windows Print Client with DRC . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15
Print Client Parameters. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16
Setting I-Queue Driver Defaults . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16
Installation Example . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
3
Kofax Equitrac® Client Setup Guide
Select Account . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21
Rename Document Prompt. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22
Release Key Prompt. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22
Setting Client-Side Popup Look & Feel . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23
I-Queue Direct Printer. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23
Desktop Printing 32
User Workflow for Desktop Printing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32
4
kofax Equitrac® Client Setup Guide
System Requirements
Workstation Client is available in both 32-bit and 64-bit installers, and is supported on the following platforms.
• Windows 7 Professional/Enterprise/Ultimate
• Windows 8.1 Professional/Enterprise
• Windows 10
• Citrix /Remote Desktop Services
• Mac OS 10.10 to 10.14
Microsoft .NET Framework 4.5 must be installed on Windows 7, 8.1 and 10 prior to installing the Windows Client.
5
kofax Equitrac® Client Setup Guide
6
kofax Equitrac® Client Setup Guide
WARNING: Do not install any Equitrac Client services on any computer running any Equitrac Server services. If these
services are installed on the same computer, the Equitrac Server may crash and will need to be reinstalled. You cannot
run the Repair option on the server if it crashes, a complete reinstall is required.
Before installing Workstation Client, confirm that the Windows workstation is resolving communications to the CAS
and DRE servers by hostname. On a Client machine, open a command prompt and type ’ping hostname’ where
the hostname is the name of the machine hosting the master CAS or DRE.
To install Windows Client on a single workstation, do the following:
1 Close all other applications on the server prior to installation.
2 Obtain the Equitrac Client software file from the Equitrac Product Download site. The Client Installer is available
as an individual 32-bit (Equitrac.Client.x86.msi) or 64-bit (Equitrac.Client.x64.msi) installation file.
3 Ensure that Windows 10 Universal CRT for Visual Studio 2015 is installed prior to installing Workstation Client
on a non-Windows 10 OS (such as Windows 7 and 8.1, and Server 2012 R2). Server 2016 does not require CRT to
be installed.
4 Select and run the 32-bit or 64-bit Installer file to launch the Equitrac Client Installation wizard.
5 On the Welcome screen, click Next.
6 Read and accept the Kofax End User License Agreement, and then click Next to continue.
7 Select the language for the client installation.
8 On the Custom Setup screen, select the client applications to install on the workstation, and click Next.
To select or deselect an item, click on the hard drive icon beside the feature and select one of the following options:
• Will be installed on local hard drive.
• Entire feature will be installed on local hard drive.
• Entire feature will be unavailable.
NOTE: You must install Desktop Printing feature in order for several client features (Prompt for Login, Cost Preview,
Interactive Print Rules, Print Assistant, Client Billing popup and DRC) to work.
NOTE: You can click Disc Usage to check the disk space requirements on the workstation to ensure that enough
space is available for the selected components.
9 On the Core Accounting Server Location screen, enter the fully qualified domain name or fixed IP address of the
CAS server, and click Test Connection to validate a connection across the network, and then click Next to
continue. Otherwise just click Next without testing the CAS server.
10 On the Windows Firewall Exceptions screen, select either a manual or automatic setup method for the firewall
exceptions, and then click Next to continue.
7
kofax Equitrac® Client Setup Guide
11 Click Install to start the installation process. The installation wizard copies files, sets up services, and creates
shortcuts to the Administrative Applications.
CAUTION: If the cache directory specified for the Temporary File Location during the client installation is on the
network, the shared engine (SE) will not start. The SE runs under the system account and you cannot give Equitrac
\SYSTEM access to the share on the network. You must ensure that the Local System account has write access into
this directory. The cache directory also must reside on the local client machine, not on the network.
CAUTION: If the cache directory specified for the Temporary File Location during the client installation is on the
network, the shared engine (SE) will not start. This happens since the SE runs under the system account and there is
no way to give the Equitrac \SYSTEM access to the share on the network. You must therefore ensure that the Local
System account has write access into this directory. The cache directory also must reside on the local client machine,
not on the network.
8
kofax Equitrac® Client Setup Guide
4 Run Terminal.app navigate by changing directory (cd) into Mac client archive folder “security” subfolder and
run:
sudo ./NDI.SecurityConfig.sh enroll __security_admin_user_name__
__security_admin_user_passsword__ __sfs_host_name__ __datacenter_name__ enroll_drc
9
kofax Equitrac® Client Setup Guide
NOTE: When entering admin name into command line if it has back slash “\” (i.e. nuance\securityadmin must
escape backslash by double slash: nuance\\securityadmin).
NOTE: Enroll_drc parameter is optional – specify only if Mac DRC will be installed.
8 In the DRC system name section, select what identifier to use for the Mac DRC.
• IP address – the Mac computer IP address.
• Bonjour name – the Mac computer’s local network name.
• DNS hostname – the user-specified string.
NOTE: The identifier must be stable and unique across the CAS database, and must be resolvable from Windows,
since it will be used by other system components to open the network connection and to communicate with the
Mac DRC.
10
kofax Equitrac® Client Setup Guide
If using Bonjour name, then your computer’s name is appended with ".local", and any spaces are replaced with
hyphens. For example, if your computer’s name is My Computer, the its Bonjour name would be My-
Computer.local. The Bonjour name is generated by Mac OS X.
If using DNS hostname, do the following:
• Enter the hostname identifier or click Generate to populate the field. It is recommended to qualify the DNS
hostname with the network domain name. For example, computer_1.kofax.com
• Select Register with DNS server to enable the Mac client to register the specified hostname with DNS server
every 24 hours.
9 In the Login options section, do the following:
a Select Cache login to enable the user login credentials to be cached locally, and validated against CAS. If
selected, the user is only prompted to login at the first print job, and all following print jobs do not require a
login. However, if the user’s cached credentials change (e.g. new PIN1 or password), they will be prompted to
login again. The Prompt For Login option must be selected in order to cache the user login credentials. The
user credentials are cached on the Mac Keychain for secure password storage.
b Select Prompt for password if you want users to enter a password at login. If selected, the user must enter both
primary and secondary user credentials.
c In the User ID label field, enter the display name for the User ID on the login popup. For example, enter ‘PIN1’
as the User ID label if user’s are to enter their Primary PIN as the user ID.
10 Select the Ignore ‘Command and Control’ print jobs checkbox to skip ‘control’ print jobs that are issued by some
print drivers to send commands to the printer hardware.
For example, a user prints document "Untitled” but gets two popups: one for document named “Untitled”, and one
for document named “Report Status - 16”. Report Status - 16 is a ‘control’ print job issued by the driver. If the
checkbox is selected, then the printer ignores any job named “Report Status - 16”. Extra popups can be suppressed
by filtering out ‘control’ print jobs by name.
11 Click OK to save the settings and close the Preferences window.
Setting Languages
The Mac OS allows users to set the Preferred languages list in the System Preferences. The EQLoginController
application goes through the Preferred languages list until it finds the first supported language in the list. If no
localized language is supported (or selected), it defaults to English. If the Preferred languages list is changed in the
System Preferences, then the EQLoginController must be restarted.
11
kofax Equitrac® Client Setup Guide
3 In the DRE Address field, enter the DRE server IP address, and click Get Printers.
The Equitrac Printer Utility queries DRE for a list of accessible printers.
4 Select the appropriate printer from the list, and click OK.
3 Enter the IP Address and Name of the printer, and click OK.
The new printer displays in the available printers list.
12
kofax Equitrac® Client Setup Guide
/Library/LaunchAgents/
/Library/LaunchDaemons/
/usr/libexec/cups/backend/eqtrans
/usr/libexec/cups/backend/eqpmon
Ownership:
eqpmon - root
eqtrans - root
Troubleshooting
If there is an MAC Client installation problem, verify the following:
• The Name/IP displayed in the CAS Server field in the EQPrintUtilityX.app > Preferences dialog is set to a valid
CAS machine name IP, and not 127.0.0.1.
• The Name/IP displayed in the CAS Server field in the EQPrintUtilityX.app > Preferences dialog can be pinged
from a MAC workstation.
• Ensure EQLoginController is version 4.1.1.3454 or higher. Mac DCR is not compatible with previous versions of
EQLoginController.
13
kofax Equitrac® Client Setup Guide
Silent Installation
If you plan to deploy the same Equitrac Workstation Client features across several servers, silent installation can be
used to simplify the installation process. Silent installation is handled by the Microsoft Windows Installer by
specifying options and features to install from the Equitrac install package to the Windows installer.
If you are upgrading to Equitrac version 6.1 from an earlier version, refer to Upgrade Equitrac Client.
NOTE: For Windows Servers 2012, 2012 R2 and 2016, make sure the server is up to date with the latest service packs, or
manually download and install the latest version of Windows Installer from www.microsoft.com.
14
kofax Equitrac® Client Setup Guide
Options
To silently install the Equitrac Workstation Client, the following options must be specified.
Common – Required option for all commands. Installs the common files required for any type of install.
DesktopPrinting – Installs the Desktop Print Tracking feature.
ClientBilling – Installs the Client Billing feature.
PromptForLogin – Installs the Prompt for Login feature.
DocumentRename – Use this option to install the Document Rename feature that allows users to rename documents.
ReleaseKey – Use this option to install the release key feature. This is not compatible with Login or Billing Code
prompts.
CostPreview – Installs the Cost Preview feature.
NetworkPrinting – This option tracks Windows DRE printing to Windows print servers.
DRC – Installs the Document Routing Client for Direct IP printing.
NOTE: For the DRC option, you must also select DesktopPrinting if you require a popup from one of the other options
(Client Billing, Prompt for Login, Cost Preview, ReleaseKey, DocumentRename, Interactive Rules). Do not install on a
server where DRE is installed, as they are not compatible.
IQueue – This feature enables I-Queue printing.
ManagedQueue – This feature enables Managed Queue printing.
InteractiveRules – This function allows a server-based print rule to interact with the end user when running on a
Windows print server. This change does not apply to workstation rules or copy rules.
EQMsg – This option displays messages in the Windows system tray via the Equitrac Message Client.
15
kofax Equitrac® Client Setup Guide
10 Right-click the Kofax certificate and click All Tasks > Export.
11 In the Certificate Export Wizard, click Next.
12 Leave the default setting DER encoded binary x.509 (.CER), and click Next.
13 Enter a file name and path, and then click Save. Alternatively, click Browse to select a file name and path.
14 Click Next, and then click Finish.
This certificate needs to be distributed to all of your computers that will install this software. To distribute the
certificate, do the following:
1 Open the Group Policy Editor and navigate to Computer Configuration\Windows Settings\Security
Settings\Public Key Polices.
2 Import the certificate under the Trusted Publishers Certificates.
16
kofax Equitrac® Client Setup Guide
IQUEUE_DEFAULT_COLOR – This option specifies a default value for color. The following values can be specified:
"1" – Monochrome
"2" – Color
IQUEUE_DEFAULT_DUPLEX – This option specifies a default value for duplex. The following values can be
specified:
"1" – Simplex
"2" – Duplex long-edge
"3" – Duplex short-edge
Example for installing Equitrac interactively with the I-Queue defaulted to A4, color, duplex:
msiexec /i Equitrac.Client.x64.msi IQUEUE_DEFAULT_PAPERSIZE=9 IQUEUE_DEFAULT_COLOR=2
IQUEUE_DEFAULT_DUPLEX=2
Example for installing Equitrac interactively with the I-Queue defaulted to monochrome:
msiexec /i Equitrac.Client.x64.msi IQUEUE_DEFAULT_COLOR=1
Installation Example
This example installs Client Billing and Cost Preview for Network DRE Windows print servers on the client
workstations. The client UI will be in English. All parameters are case-sensitive and must be typed as shown.
msiexec /i Equitrac.Client.x64.msi CASNAME="EQU_CAS_SRV" LANGUAGE ="en"
ADDLOCAL="Common,ClientBilling,CostPreview,NetworkPrinting" /q
NOTE: The Kofax certificate must be pre-trusted before running a silent install. If the Kofax certificate is not already
added, then a Windows security popup appears requesting that you Always trust software from "Kofax, Inc" to add the
certificate, and the silent install stops.
17
kofax Equitrac® Client Setup Guide
18
kofax Equitrac® Client Setup Guide
where <path> is the full path to the location where you copied the client.msi file.
The workstation will reboot automatically after the uninstall is complete. If you need to suppress the reboot, enter the
following command instead:
msiexec /x "<path>\Equitrac.Client.x64.msi" /q /norestart
Mac Uninstall
To uninstall the Mac Client, do the following:
1 Login to the Mac Client with Administrator privileges.
2 Unpack the Equitrac_MacOSX_xxxx.zip file.
3 To remove the Mac Client from a single workstation, do the following:
a Select Uninstall > EquitracUninstall from the Finder.
b Click Run.
c Enter your Name and Password, and click OK.
4 To remove the Mac Client from multiple workstations at one time, do the following:
a Copy the EquitracUninstall.sh script onto each workstation via Apple Remote Desktop (ARD).
Run the uninstall script via ARD on each workstation.
19
Kofax Equitrac® Client Setup Guide
The user credentials are authenticated against the CAS database. If the credentials pass authentication, other popups
appear (if configured), and the user can submit the print job.
NOTE: Do not install Prompt for Login if you plan to install the Release Key Prompt (part of the Print Assistant feature
within the Equitrac Client installer). These two features are not compatible. Choose one validation method only.
20
Kofax Equitrac® Client Setup Guide
Cost Preview
Install the Cost Preview feature on a user workstation to provide the user with a print cost summary prior to sending
the document to the printer. A small pop-up window allows the users to review the costs, then decide if they want to
continue with the print job, or cancel it. The popup window provides information about the amount of funds available
to the user, giving the user the opportunity to make changes to the print job characteristics if their funds are low. If the
user has insufficient funds, Equitrac will not accept the transaction, and the job will not be queued.
Select Account
In addition to displaying the balance in CAS and Campus Card accounts, the Equitrac user can also select which
account to charge. Once the account has been selected, the job will be printed and charged to the selected account. A
requirement for both of these features is that the print queue not be configured to hold documents for print release. If
jobs are held for release then the user would have the opportunity to select a different account at a release endpoint.
Hence, this feature is not available when jobs are held for release (i.e., not compatible with SDR, Follow-You Printing,
and Release Key).
NOTE: Campus Card account balance display and account selection are not supported on Mac.
21
Kofax Equitrac® Client Setup Guide
NOTE: This feature is not compatible with Prompt for Login. Do not install both Prompt for Login and Release Key
Prompt on the same user workstation.
22
Kofax Equitrac® Client Setup Guide
23
Kofax Equitrac® Client Setup Guide
3 The user selects one of the following options: Recipients or Release key, Printing costs, or Job settings.
4 The user clicks OK to submit the print request.
NOTE: The user cannot recall the print job once it has been sent.
Recipients
Recipients of a print job can be any combination of Equitrac User Accounts, Equitrac Departments, or Windows
Active Directory Groups. Alternatively, users can enter a Release key.
Recipients must meet one of the following criteria:
• a user ID in the current domain
• a domain-qualified user ID, such as rtm\bleatham (where rtm is the domain name)
• a valid Active Directory Groups distribution list
Users can either type these recipients directly in the Users or lists field, or click the Add button to search for recipients.
24
Kofax Equitrac® Client Setup Guide
NOTE: As a best practice, encourage users to select recipients from the Search dialog box. For users and departments,
these names are validated by Equitrac before populating the list. If a user types in a recipient incorrectly, CAS notifies
DRE, and the user receives an notification message that a recipient is invalid. The print job is not added to the secure
queue for any invalid recipients.
For users or departments, clicking Add brings up the Search dialog box. Users can leave the Criteria field blank to
view all users/departments within the database, or they can enter criteria to narrow the search.
After making selections and clicking OK, the recipients are added to the Users or lists field. Recipients selected from
the Search dialog boxs are prefaced with a "D" for departments, or an "AD" for active directory groups. If the user
manually enters a department or Active Directory group, and does not preface the name with an A or AD, Equitrac
tries to resolve the name against the User Accounts database first, then against departments, then against the Active
Directory Groups list.
In cases where departments and Active Directory Groups have the same name, the user must enter the correct prefix.
Otherwise, the department name is used to determine the recipients.
25
Kofax Equitrac® Client Setup Guide
If the user clicks Add Groups, the Select Groups dialog box opens. The user can choose the Object Types or locations
to search, or just type a group name in the Enter field, then click Check Names to verify the name against the list of
available Windows Active Directory Groups.
Release Keys
Release keys are Equitrac features that must be enabled on the DRE print server in Web System Manager > System
Configuration > Global Configuration Settings User Interaction > Session Flow to support the release key option.
Users can assign a release key to a print job and allow other users to walk up to any release device, and print any jobs
in the queue that were submitted using that release key.
Printing Costs
The originating user can set the Printing Costs before they submit the Send To printing job:
• Charge normal costs to recipient
Applies the system price lists, if configured. See Creating Price Lists in Kofax Equitrac® Administration Help file
for details.
• Charge fixed cost to recipient
Overrides the system price lists and charges a specified fixed price instead. This charge is applied to each recipient.
If the “Reprice after release” feature is enabled, the job may be repriced if the job properties change upon release.
See Departmental Pricing s in Kofax Equitrac® Administration Help file for details.
• Accept all costs for this job
The originating user accepts the costs for the print job. The system price lists are applied and their account balance
are validated when they click OK to submit the Send To printing job.
26
Kofax Equitrac® Client Setup Guide
Job Settings
The originating user can replace the current document name with any name of their choosing. This name appears in
the control terminal queue.
The originating user can also override the default job expiry time. By default, Send To printing jobs remain in the
secure queue for one hour. However, Administrators can change this default within the System Configuration, and
originating users can enter any job expiry time they deem fit. The print job remains in the secure queue for this length
of time, requiring enough disk space to store the jobs until they are either released or expired.
27
Kofax Equitrac® Client Setup Guide
4 Under Popup Behavior, select Suppress popup for N minutes to prevent the popup from appearing on a user’s
desktop when printing.
5 Enter a value in the minutes field and click OK.
When the selected time period ends, the billing code popup behavior returns to the "enabled" state.
You can right-click the tool tray icon in the Windows task tray, and click Suppress Popup to quickly turn On or Off
the billing code prompt without opening the Equitrac User Client Settings dialog box.
28
Kofax Equitrac® Client Setup Guide
NOTE: This feature is supported on user workstations that are authenticated on Windows Servers only. This feature
does not work when workstations are authenticated under UNIX DRE Print Servers.
29
Kofax Equitrac® Client Setup Guide
30
Kofax Equitrac® Client Setup Guide
31
Kofax Equitrac® Client Setup Guide
Desktop Printing
Desktop printing tracks the use of local printers connected to a user workstation. These printers are not controlled by
a DRE print server. A user may attach a device directly to their user workstation via an LPT or USB connection, rather
than print through an Equitrac print server or the workstation direct IP printing feature in the Equitrac Client
Workstation. Equitrac groups these devices as Workstation devices.
Charging for color attributes is also possible but depends upon the properties of the printing application and the
printer driver. If the application and print driver do not differentiate between color and monochrome pages, color
attribute charges for desktop print jobs will not be accurate.
NOTE: Desktop printing does not enforce Account Limits.
Desktop printing is often deployed when you need to track print volume for users who require private printers. For
example, legal documents, accounting documents, or HR documents are often proprietary and should not be left
unattended on a printer. You can install the Desktop printing feature per device, limiting access and applying
specialized pricing scenarios. You can also create special rules that determine the types of jobs that can print to these
devices.
• user
• userverification
verification
• print
• printcharge
chargecalculations
calculations
• account
• output balance
tracking
management
• output
• account tracking
balance mgmt
The Desktop Port Monitor intercepts print requests to the local printer
32
Kofax Equitrac® Client Setup Guide
NOTE: Clicking No directs the job to the original printer. Clicking Cancel cancels the print job. Users may get a deny,
redirect or hold message asking them to select Yes or No.
Upon successful routing, a message pops up confirming the print job has been redirected to the selected MFP.
33
Kofax Equitrac® Client Setup Guide
Logging In to Equitrac
When you make a print request from a Mac workstation, you must log on to the Equitrac system. Equitrac must
validate your User ID and password before it sends the print request to the printer.
The login information stays with Equitrac until the session expiry time is exceeded. If you make another print request
before the login timeout expires, you do not have to enter information in the login dialog box again.
NOTE: If your Windows credentials originate from a different domain than the core accounting server, you must enter
the domain with your user ID in the format: domain\userID.
NOTE: Depending on the logon timeout configuration, the logon dialog box may not appear every time you print.
34
Kofax Equitrac® Client Setup Guide
35