Canon CPA 2.0

Last Updated: August 26, 2026

Complete the requirements, and follow the steps below to install the second-generation Control Panel Application (CPA) on a Canon printer. For a list of supported devices, refer to Supported Printers for Printer Apps.

Installation Requirements

Complete all Universal Requirements, and ensure functionality prior to CPA setup. Canon also requires the following:

  • Canon has authorized the installation of the PrinterLogic CPA on its devices in the U.S., LATAM, EMEA, Australia and New Zealand, and South Asia and India regions. The installation fails when attempted in other regions, including China and Japan.
  • Have the Canon Multifunctional Embedded Application Platform (MEAP) web access software on the printer. The Web Connection Kit includes this software and is available from any authorized Canon dealer.
  • Have the Auth JAR file, Web JAR file, and license file. You can email canonlicensefile@printerlogic.com for these files. Provide the following:
    • Model and serial number of the printer for the installation.
    • The printer's geographical location, such as EMEA, APAC, etc.
  • To install Simplified Scanning features on Canon devices, use the following:
    • Printer Apps v25.0.2457 or later, which you can confirm in the PrinterLogicServiceManager log.
    • Multifunctional Embedded Application Platform (MEAP) Auth JAR v1.1.103 or later, which you can confirm after installing the license file by going to the Enhanced System Application Management section in the printer's web interface and finding the version next to PrinterLogic Auth.
    • PrinterLogic MEAP v1.2.16 or later, which you can confirm in the MEAP Application Management section in the printer's web interface after you install the app.
  • When setting up Simplified Scanning Global Scan Settings, please note that Canon devices do not allow users to change the orientation or paper size at the CPA even with the User can adjust this setting checkbox selected. Duplex, file type, color mode, and DPI can be adjusted.
  • Ensure that the Canon printer is in production mode, which is usually the default, so that the JAR files work correctly.
  • Turn on Transport Layer Security (TLS) 1.2 on the multifunction printer (MFP).
  • If you use a USB badge reader to release print jobs, some Canon models require you to turn on the Use MEAP Driver for USB Input Device option in the USB Settings section.
  • When updating authentication settings, including Single Sign-On (SSO), you must restart the printer for the settings to take effect.

Additional Port Information

CPA installation and uninstallation occur between the Service Agent and the printer over TCP ports 8000 and 8443.

CPA operation requires two main communication paths:

  • From the printer to the Service Agent object over TCP 31988.
  • From the printer to the PrinterLogic instance, cpp-ui.app.printercloud-fed.us and cpa-api.app.printercloud-fed.us, over TCP 443.

Everyday print communication occurs from the device to the printer over TCP 9100 or TCP 515 for Line Printer Remote (LPR) queues.

By default Certificate Revocation List (CRL) checks occur over TCP 80 from the Service Agent. The installation might fail if the CRL check cannot complete over port 80.

Certificates

You must download and install the PrinterLogic Certificate Authority (CA) on the printer. The following steps guide you through that process.

Download and Install the CA

Download the Certificate

In the Admin Console, complete the following steps:

  1. From the tree structure, select the Canon printer on which you want to install the CPA.
  2. Select the Apps tab.
  3. Scroll down to the Certificates section, and select Download certificate for CA. Note the location in which you save the certificate for later.

Install the Certificate

Go to the admin screen on the printer, and complete the following steps:

The placement of the configuration options outlined here might vary depending on the printer.

  1. From the right-side navigation near the top, select Settings/Registration.
  2. From the Management Settings section in the left-side navigation, select Security Settings.
  3. In the Security Settings, select Encryption/Key Settings.
  4. Above the list of installed Secure Sockets Layer (SSL) certificates, select Edit, and then select Register CA certificate.
  5. Select Install.
  6. Select Choose File.
  7. Navigate to the certificate that you downloaded from the Admin Console, and select Open.
  8. Ensure that the file's name appears beside the Choose File button, and select Start Installation.
  9. After the CA certificate uploads and installs, the printer should return to the Register CA Certificate screen.
  10. Select the printerlogic-ca-cert.pem certificate from the list, and then select the Register button.
  11. Go to Settings/Registration then Security Settings then Encryption/Key Settings then CA Certificate Settings to confirm that the certificate appears in the list.

General Authentication Options

The authentication options on the TCP / IP printer determine what the CPA shows to the end user. If you use the same authentication options for all printers, you can use the default settings. If you want to set specific methods by printer, you can choose which printer-specific options you want available for setup on individual printers.

Default Settings

For provider-specific attribute mapping, refer to Entra ID (Azure AD) Badge & PIN Attributes, Okta Badge & PIN Attributes, or Google Badge & PIN Attributes.

Cloud IdPs like Entra ID and Okta support badge and PIN authentication. The username and password option is not available.

In the Admin Console, go to Tools then Settings then General, and scroll down to the Identity Provider Settings. Follow the appropriate steps below for your provider.

Users sign in with their network credentials or the same credentials they use to sign in to the device. This method requires no additional setup beyond your Lightweight Directory Access Protocol (LDAP) Identity Sync configuration since it uses the credentials already defined there.

LDAP configurations are not supported in Vasion Automate Fed environments. Select from User ID and Pin or Badge Scan.

To verify this LDAP option:

  1. In the Identity Provider Settings section, select LDAP, and ensure that you correctly configured your LDAP credentials.

    Admin Console showing General settings and Identity Provider Settings section.

  2. Scroll down to CPA Specific Settings section and verify / turn on Enable Username/Password Authentication.

  3. Select Save in the upper-right corner.

CPA Login screen showing Scan Badge icon and fields for User sign-in option.

PIN authentication requires the end user to enter a user ID and PIN at the CPA.

CPA Login screen showing Scan Badge icon and fields for PIN sign-in option.

Badge scan authentication requires the end user to scan a badge, card, or dongle at the CPA. For LDAP, the first time users scan their badge, the CPA prompts them for their network credentials.

CPA Login screen showing Scan Badge icon and fields for PIN sign-in option.

Global Install Credentials, Security, & Single Sign-On (SSO)

In the Control Panel Application section on Tools then Settings then General set global installation credentials if the username and password to access the printer's UI are the same. Installation credentials can be adjusted per printer on the Apps tab or through the CPA Manager.

This section also includes the global Enabled or Disabled settings for SSO. Most of the CPA 2.0 apps support SSO with an IdP. With this functionality, you can choose Provider or Listener mode.

  • In Provider mode you can lock the printer so that a user must authenticate before they can access the printer's control panel.
  • In Listener mode PrinterLogic listens for when another app acting as the SSO provider authenticates a user and passes that user information to the CPA. The user can then select PrinterLogic on the control panel.

To set global installation credentials or turn on SSO:

  1. Go to the Control Panel Application section.
  2. Use the Username and Password fields to set the global installation credentials.

    The credentials must have admin rights to the printer.

  3. Turn SSO on or off using the Enabled and Disabled options.

    Admin Console showing General settings and Control Panel Application section.

  4. Select Save in the upper-right corner.

Configure the Printer's Web Interface Portal

You need the locations of the JAR and license files that you obtained for the next steps.

Log in to the printer's web interface by opening a browser and entering the printer's IP address in the address bar.

Install the Web JAR File

Follow these steps:

  1. From the right-side navigation in Management Tools, select Service Management Service.

    Web interface portal showing Management Tools section.

  2. Select Install MEAP Application from the left-side navigation.
  3. Select the Choose File button for the Application File Path field.
  4. Locate the PrinterLogic Web JAR file, and then select Open.
  5. Select the Choose File button for the License File Path field.
  6. Locate the license file for the current printer's serial number, and then select Open.
  7. For the Operation to Perform field, select Install and Start.
  8. Select the Install button.

Web interface portal showing Install MEAP Application/License section.

Install the Auth JAR File

Follow these steps:

  1. From the right-side navigation in Management Tools, select Service Management Service.

    Web interface portal showing Management Tools section.

  2. Select Enhanced System Application Management from the left-side navigation.

  3. In the Install Enhanced System Application/License section, select the Choose File button for the Enhanced System Application File Path field.

  4. Locate the PrinterLogic Auth JAR file, and then select Open.
  5. Select the Choose File button for the License File Path field.

  6. Locate the license for the current printer's serial number, and then select Open.
  7. For the Operation to Perform field, select Install and Start or Enable.
  8. Select the Install button.
  9. Select Yes.
  10. Select To Portal link at the top.
  11. On the Portal page, select Settings/Registration from the right-side navigation.
  12. Select Restart Device from the left-side navigation.

Web interface portal showing Enhanced System Application Management section.

Install the CPA

These steps are for installing the CPA on a single printer using the printer's Apps tab. To install the CPA on multiple printers at once, refer to CPA Manager.

Follow these steps:

  1. From the Admin Console tree structure, select the printer on which you want to install the CPA.
  2. Select the Apps tab.
  3. From the Manufacturer menu, select the printer manufacturer.

  4. Select the Service Agent that you want to use to install the CPA.
  5. In the Install Embedded Application section, select the Secure Release option.
  6. Select the checkboxes for any additional apps that you want to install:
    1. Copy / Scan Tracking.
    2. QR Code Display.
    3. Scan to Email.

Admin Console showing printer object's Apps tab and expanded Manufacturer menu.

Installation Credentials

If your printers do not share the default username and password, defined on Tools then Settings then General in the Control Panel Application section, to access the printer's UI:

  1. Go to the Apps tab, Credentials to use when installing... section.
  2. Select Use printer-specific administration credentials.
  3. Enter in the printer's username and password.

Admin Console showing printer object's Apps tab and section about credentials.

The credentials must have admin rights to the printer.

CPA Authentication Options

The options below appear depending on what you select in the CPA Authentication settings. Note that authentication features vary depending on the printer manufacturer.

If you use an IdP, the Control Panel Application (CPA) supports only badge and PIN authentication.

For SSO, select from:

  • Disabled: Normal CPA authentication without SSO.
  • Enabled as a Provider: Users authenticate through the CPA screen before accessing apps.
  • Enabled as a Listener: Users authenticate through another SSO provider and the CPA listens in the background and accepts the authorization.

For CPA Authentication, select from the option(s) you enabled in the General Authentication Options section above.

The Extended debug section is more for troubleshooting and contains:

  • Certificates to download the PrinterLogic CA.
  • PrinterLogic Control Panel Application manual install URL.

Admin Console showing printer object's Apps tab and Single Sign On, CPA Authentication, and "Extended debug" sections.

Start the Installation

With your settings in place:

  1. Select Save to start the installation.

Do the following if installation fails:

  1. Note the error message, and check the Printer Apps logs. For more details refer to PrinterLogic Log File Locations.
  2. Review and adjust your configuration to ensure that it meets all requirements.
  3. Select the Try Again button to restart the installation.

Admin Console showing printer object's Apps tab, error message, and Try Again button.

The installation process may trigger a device restart once complete.

Uninstall the CPA

Follow these steps:

  1. In the Admin Console, select the Apps tab for the printer from which you want to remove the CPA.
  2. Deselect the options in the Install Embedded Application section.
  3. Select Save.
  4. After the uninstallation completes, log in to the printer's web interface, and select Service Management Service from the right-side navigation.

    Web interface portal showing Management Tools section.

  5. Select MEAP Application Management from the left-side navigation.
  6. Select Stop for the PrinterLogic app.
  7. Select the PrinterLogic link.

    Web interface portal showing MEAP Application Management section.

  8. In the License Information section, select License Management.

    Web interface portal showing Application/License Information section.

  9. In the Disable License File section, select Disable, and confirm that you want to turn off the license.
  10. Select the Delete button, and confirm that you want to remove the license file.

    Web interface portal showing License Management section.

  11. Navigate back to the MEAP Application Management section.

    Web interface portal showing MEAP Application Management section.

  12. Next to the PrinterLogic app, select Uninstall, and confirm that you want to uninstall the app.
  13. From the left-side navigation in System Management, select Enhanced System Application Management.
  14. In the Login Service section, expand the User Authentication line item.
  15. For the PrinterLogic Auth line item, select Uninstall.

    Web interface portal showing Enhanced System Application Management section.

  16. Select the To Portal link at the top.
  17. On the Portal page, select Settings/Registration from the right-side navigation.
  18. Select Restart Device from the left-side navigation.

After the device restarts, all references of PrinterLogic CPA are removed from the printer.

Troubleshooting Help