Skip to main content

Creating Secure Release Certificates

The ScrewDrivers Secure Release service talks to your printers over HTTPS, so it needs a server certificate. The installer creates a self-signed one and the service uses it automatically, which is all many deployments need. This page covers the optional next step: creating your own certificate authority (CA) and a CA-signed server certificate with the two scripts Tricerat provides, so printers running the certificate-validating version of the Secure Release app can verify the release server.

Beta feature

Secure Release is available as a beta feature starting in ScrewDrivers 7.10, for Enterprise edition. See Setting Up ScrewDrivers Secure Release for the full deployment walkthrough.

Two versions of the printer app​

The Secure Release app for your printers comes in two versions, and the difference is how the app treats the release server's certificate. Traffic between the printer and the release server is encrypted either way. The choice is only about whether the printer also verifies who issued the server's certificate.

Choosing the version that fits your environment

The certificate-validating version checks the release server's certificate against a CA certificate you install on each printer. It's the right choice when your security policy calls for certificate validation on every connection, or when you already run an internal CA. It needs the CA and server certificate described on this page, and the CA certificate installed on each printer.

The standard version connects to the release server without checking the issuer, so it works with the self-signed certificate the installer creates and needs no certificate work at all. Because the release server and printers live on your own network and never talk across the internet, this is a sound choice for most environments, and it's the quickest way to get the beta running.

Both versions encrypt the connection. Pick the one that matches how much certificate management you want to take on. Your account team can tell you which version you have and provide the other if you need it.

If you're using the standard version, you can skip the rest of this page. Continue with Installing Secure Release on Ricoh Printers.

Before you begin​

  • The Secure Release feature is installed on the release server (see Setting Up ScrewDrivers Secure Release).
  • You can run PowerShell as an administrator on the release server. The scripts use New-SelfSignedCertificate with the -NotBefore parameter, which requires a current version of PowerShell; the scripts check for it and stop with a message if it's missing.
  • You have the two scripts, CreateBadgeReleaseRootCertificate.ps1 and CreateBadgeReleaseLeafCertificate.ps1, which Tricerat provides with the Secure Release feature.
  • Decide whether printers will reach the release server by its fully qualified domain name (FQDN) or by IP address. FQDN is the recommended choice. If you must use an IP address, you'll add the -addIP switch in Step 2.

Step 1: Create the root certificate​

On the release server, open an elevated PowerShell prompt and run:

.\CreateBadgeReleaseRootCertificate.ps1

The script creates a self-signed CA certificate named Tricerat ScrewDrivers Badge Release CA, valid for ten years, and places it in the local machine's Trusted Root Certification Authorities store so the server itself trusts it. A copy with the private key stays in the Personal store, where the next script uses it to sign the server certificate.

Step 2: Create the server certificate​

Still in the elevated prompt, run:

.\CreateBadgeReleaseLeafCertificate.ps1

This creates the server certificate the Secure Release service presents to printers, signed by the CA from Step 1. Its Subject Alternative Name lists the server's hostname and FQDN, so printers configured with either name can validate it. The script stores the certificate in the Tricerat certificate store, where the service looks for it, and removes any earlier Secure Release server certificate from that store first, so you can rerun it safely.

The script takes two optional parameters:

ParameterWhat it does
-addIPAdds the server's IPv4 addresses to the certificate's Subject Alternative Name. Use it when printers will be configured with the release server's IP address instead of its FQDN.
-validityDays <days>Sets how many days the server certificate stays valid. Without it, the server certificate expires when the CA does. The server certificate never outlives the CA; if you ask for a longer period, the script caps it to the CA's expiration.

For example, to create a certificate that also covers the server's IP address and expires in one year:

.\CreateBadgeReleaseLeafCertificate.ps1 -addIP -validityDays 365

After the script finishes, restart the ScrewDrivers Secure Release service so it loads the new certificate:

Restart-Service -Name "ScrewDrivers Secure Release"

Step 3: Export the CA certificate for your printers​

The printers need the CA's public certificate, and only that, to validate the server. Export it as a Base-64 encoded .cer file:

  1. Run certlm.msc to open the local machine certificate console.
  2. Expand Trusted Root Certification Authorities and open Certificates.
  3. Find the certificate issued to Tricerat ScrewDrivers Badge Release CA. Right-click it and select All Tasks > Export.
  4. In the Certificate Export Wizard, choose Base-64 encoded X.509 (.CER) and save the file.

The export doesn't include the private key, which is what you want. This file is safe to copy onto an SD card or share for installation on printers.

Step 4: Install the CA certificate on each printer​

Load the .cer file onto each printer that runs the certificate-validating version of the app. The steps for Ricoh devices are in Installing Secure Release on Ricoh Printers.

Renewing certificates​

When the server certificate approaches expiration, rerun CreateBadgeReleaseLeafCertificate.ps1 with the same parameters and restart the service. The CA stays the same, so the printers don't need any changes. If the CA itself expires or you replace it, repeat all four steps, including reinstalling the exported CA certificate on every printer.