Chapter 10 - Managing Print Security
Overview of Managing Print Security
This chapter discusses how to specify access privileges, which determine who can administer and use a print service.
A StreetTalk print service specifies three levels of access privileges. Each level is defined by one of the following access lists:
![]()
The AdminList for the group in which you create the service ![]()
The Operator List for the service ![]()
The User List for the service
AdminList
Users listed on the Admin List for the service have complete administrative privileges for the service. These users can modify all settings for a StreetTalk print service and StreetTalk print queues, modify each of the access lists, stop and start the service, and delete the service.
Operator List
Users listed on the Operator List have a subset of the administrative privileges that belong to those on the Admin List. By default, this list includes only members of the Admin List for the group in which the service is created. Changing the Admin List changes the membership of the default Operators List.
Users List
Users listed on the Users List have the right to send jobs to the print service and to control the jobs they send to the queue. The default entry in the User List (*@*@*) lets all users logged in to the network send jobs to this print service.
Note: StreetTalk for Windows NT does not support Macintosh clients. Macintosh users cannot send print jobs to StreetTalk Print destinations. However, if you provide Macintosh clients with direct access to a Windows NT print queue, those clients can share the same printer without conflicts.
Task | Users | Operators | Administrators |
View jobs in the queue | Own jobs only | Yes | Yes |
Place jobs on hold or take them off hold | Own jobs only | Yes | Yes |
Reschedule jobs | Own jobs only | Yes | Yes |
Cancel jobs | Own jobs only | Yes | Yes |
Reprint jobs | Own jobs only | Yes | Yes |
Rearrange jobs in the queue | Own jobs only | Yes | Yes |
Move jobs to a different queue | Own jobs only | Yes | Yes |
Change the format of jobs | Own jobs only | Yes | Yes |
Change the paper format of a service | No | Yes | Yes |
Change the job limits of a service | No | Yes | Yes |
Change the queue options | No | Yes | Yes |
Change the status of the StreetTalk queue | No | Yes | Yes |
Stop and Start a Print Service | No | No | Yes |
Change the Windows NT print queue | No | No | Yes |
Create and delete print services | No | No | Yes |
Add or remove users from access lists | No | No | Yes |
Change event logging | No | No | Yes |
Refer to Chapter 9 for information about managing a print service. Refer to Chapter 11 for information about managing print jobs.
You can modify default entries on each list as needed. For example, modify the access list for a print service to allow designated users to administer certain print service operations; to restrict use of a printer to a specific group; or to balance the load between printers.
Note: If a physical printer serves as the destination for multiple print services, you need to specify access privileges for each of those print services to limit access to that printer.
An access list can contain the following types of entries:
![]()
StreetTalk names of individual users ![]()
StreetTalk group names ![]()
StreetTalk organization names ![]()
StreetTalk nicknames ![]()
StreetTalk list names ![]()
StreetTalk templates
You can enter a maximum of five StreetTalk names on each access list. StreetTalk Explorer verifies the StreetTalk names that you enter on the access list. If you enter an invalid or non-existent StreetTalk name or template, you receive an error message when you proceed with the configuration and any invalid names are removed from the list.
You cannot save an access list that contains no entries. If you attempt to save an empty access list, you receive an error, and the list reinstates the default entries. You can edit the list again or save the default lists.
Entering a StreetTalk Template on a Print Service Access List
To include more than five users on an access list, enter a StreetTalk list or template. A StreetTalk template uses a wildcard character (*) as a placeholder for the following portions of a StreetTalk name:
![]()
Item (for example, *@group@organization) ![]()
Item@Group (for example *@*@organization) ![]()
Item@Group@Organization (for example *@*@*)
Only templates that begin with asterisks to indicate a wildcard value are valid. You cannot specify an item name and then use a wildcard as a placeholder for the StreetTalk group name. For example, the following are valid StreetTalk templates:
*@Mkt@WCTUS
*@*@WCTUS
*@*@*
The following are not valid StreetTalk templates: Bill Jones@*@WCTUS, item@*@organization.
Templates that use a wildcard in place of the StreetTalk organization name are only valid if the StreetTalk item name and group name are also wildcards. The following is not a valid StreetTalk template: *@mkt@*
You cannot use a wildcard character as a placeholder for part of an item, group, or organization name. The following are not valid StreetTalk templates: B*@group@organization, Juan*@Mkt@WCTUS..
Example: Using Templates to Add Members to an Access List
To add everyone in the group Mkt in the organization WCTUS to the access list, enter the following template:
*@Mkt@WCTUS
1. From StreetTalk Explorer, open the Access property sheet for the print service.
2. From the Category drop-down list box, select the access list to which you want to add members. The window displays the current members of the selected list.
3. Do one of the following:
- To add users to the access list, click Add. The Select StreetTalk ID dialog box appears. Go to step 4.
- To remove users from the access list, highlight the item in the window displaying the current access list, and click Delete. The user is removed from the list. Continue with step 8.
4. In the Pattern text box, enter a wildcard pattern for a group or organization from which you want to add items. For example, to add items from the group group@org, enter:
*@group@org
5. Do one of the following:
- To add the StreetTalk template, click OK. Do not select an item from the window. The print service Access property sheet appears, and the template you specified appears in the window listing the StreetTalk objects on the access list. Continue with step 7.
- To add a StreetTalk name, select the type of StreetTalk item to add to the list from the Criteria drop-down list box, and click Reset List. The following items are available: users, groups, organizations, lists, nicknames. Continue with step 6.
6. The window lists the specified items in the group and organization. Select an item from the window and click OK. The Access property sheet appears, and the item you selected appears on the list of StreetTalk objects for the access list.
7. To continue adding list items, repeat steps 2 through 5. When you have finished modifying the access lists, do one of the following:
- Click OK. The property sheets for the print service close.
- Click Apply. The Apply button is dimmed. Proceed to another task or click OK to finish.