Skip to main content

Setting Up ScrewDrivers Secure Release

ScrewDrivers Secure Release holds a user's print jobs until that user taps their badge at the printer and chooses what to print. Documents never sit in an output tray waiting for someone to collect them, and users can send a job from anywhere and release it at whichever supported printer they walk up to. This page is the high-level walkthrough for a new deployment; it links out to breakout pages for the certificate work and the printer app.

Beta feature

Secure Release is available as a beta feature starting in ScrewDrivers 7.10, for Enterprise edition. It's ready to use today, and Tricerat is refining it based on customer feedback. Questions, requests, and anything unexpected you run into: contact Tricerat Support.

How it fits together​

A Secure Release deployment has five parts, and you'll touch each one in the steps below:

  • ScrewDrivers Database — the shared SQL database every ScrewDrivers server component uses. Held jobs are tracked here until they're released. You install it once per environment.
  • The release server — a Windows server running the ScrewDrivers Secure Release service. Printers connect to this server over HTTPS (port 5286 by default) to show users their held jobs. You'll enter this server's address into the printer app's configuration file, so pick a server whose fully qualified domain name (FQDN) the printers can resolve.
  • Print servers — any computer running the ScrewDrivers Print Server service that hosts printers you want users to release to. When a job is released, this is where it prints from.
  • ScrewDrivers Administration — where you create Secure Release users, tell ScrewDrivers which physical printer is which, and assign printers to users.
  • The Secure Release app on each printer, paired with a badge or card reader. The beta supports Ricoh printers.

The flow, once everything is in place: a user prints from their session, ScrewDrivers holds the job instead of printing it, the user taps their badge at a printer, the app on the printer asks the release server for that user's held jobs, and the user taps Print Document next to the one they want.

Before you begin​

  • Enterprise edition with ScrewDrivers 7.10 or newer on every server component. Your account team or Tricerat Support provides the downloads link, including the Secure Release app package for your printers.
  • A Windows server for the release role, with administrator rights on it. Its FQDN must resolve from the printers' network. An IP address works too, with one extra step covered on the certificates page.
  • Network access from each printer to the release server on TCP 5286, or whichever port you choose. See Ports and Firewall Rules.
  • Badge IDs for your users. The ID you'll enter for each user is the card or badge ID exactly as the printer's card reader reports it.
  • The serial number of each printer, from the printer's configuration page or its label.

Step 1: Install the server components​

  1. Install the ScrewDrivers Database on a computer with access to your SQL Server, if you don't already have one. Run the ScrewDriversDatabase installer once per environment.
  2. Install the Secure Release feature on the release server. Run the ScrewDriversProOrEnterprise installer on the server you chose and select the Secure Release feature in the component list. This installs and starts the ScrewDrivers Secure Release service. Note the server's FQDN; you'll need it when you configure the printer app.
  3. Install the Print Server service on every computer that hosts printers you want users to release to. Follow Installing the ScrewDrivers Print Server Service.
  4. Install ScrewDrivers Administration on a management computer, if it isn't installed already.

Step 2: Create Secure Release users​

Open ScrewDrivers Administration and go to the Secure Release tab. Click Add User, enter the user's user ID and username, and click Add User to save.

The user ID is the card or badge ID that the printer's card reader reports when that badge is tapped. It's what links a badge tap to a user's held jobs, so it has to match what the reader sends, character for character. The username is the account whose print jobs this badge releases.

Step 3: Create Secure Release print server printers​

  1. On the Printers tab, right-click Print Servers and select New Print Server. Give it a name, enter the hostname or IP address of a computer running the ScrewDrivers Print Server service, and click Add. For the full print server object reference, including importing its printers, see Print Server Printers.
  2. Select the print server object and, under Pull Printing, select Hold all print jobs on this server. Jobs sent to this server's printers are now held instead of printing immediately. Each printer inherits this setting by default, and you can override it per printer on the printer's own properties if you want some printers on the server to keep printing straight through.
  3. Select each printer users will release to and open its Information tab. Enter the printer's Serial Number. This is how the release server recognizes which printer a badge was tapped at, so it must match the serial number the printer itself reports. Optionally fill in Vendor (for example, Ricoh) and Model; they keep printers distinct if two devices ever share a serial number.
  4. Click Save.

Step 4: Create single queue printers (optional)​

A single queue printer gives users one printer in their session instead of a list. Jobs sent to it are held, and the user decides where to print at release time: whichever assigned print server printer they tap their badge at.

On the Printers tab, right-click Single Queue Printers, select New Single Queue Printer, give it a name, and click Add.

Step 5: Assign printers to users​

On the Assignments tab, drag each printer from the Printers tab onto the user who should get it.

When you assign a print server printer, ScrewDrivers asks how it should appear in the user's session: Admin Assigned (always present), User Assigned (present by default, but the user can remove it), or User Allowed (hidden by default, but the user can add it). The assignment modes reference explains the trade-offs.

If you assign a single queue printer, the user also needs at least one print server printer assigned. The single queue printer is the front door; the print server printers are where the jobs can actually go.

Step 6: Set up the release server certificate​

The printers talk to the release server over HTTPS. The installer gives the service a self-signed certificate that works out of the box; if your environment calls for certificate validation on the printers, create a certificate authority and server certificate with the scripts described in Creating Secure Release Certificates. That page also explains the two versions of the printer app and how to choose.

Step 7: Install the app on your printers​

Configure the app package with your release server's address and install it on each printer through the printer's web interface. Follow Installing Secure Release on Ricoh Printers.

Step 8: Test the flow​

  1. Sign in to a session as one of the users you created and print a document to an assigned printer. The job is held rather than printed.
  2. Walk to that printer, open the Secure Release app, and tap the user's badge. The list of held jobs appears.
  3. Tap Print Document next to the job. It prints, and the row disappears from the list.

If the list comes up empty, check the three values that have to line up: the badge ID in Administration matches what the reader reports, the printer's serial number in Administration matches the device, and the printer can reach the release server's address and port.

Next steps​