Skip to content

108.4 Manage printers and printing

Weight: 2

Candidates should be able to manage print queues and user print jobs using CUPS and the LPD compatibility interface.

Objectives

  • Basic CUPS configuration (for local and remote printers).
  • Manage user print queues.
  • Troubleshoot general printing problems.
  • Add and remove jobs from configured printer queues.

Terms

CUPS configuration files, tools and utilities, /etc/cups/, lpd legacy interface (lpr, lprm, lpq)

How printing works with CUPS

Almost every Linux distribution prints with CUPS, the Common Unix Printing System. Its daemon is cupsd. When you print a file, this is what happens:

  user: lpr report.txt
        |
        v
  cupsd spools the job  --->  job gets a number, a queue (printer) and a document name
        |
        v
  filters turn the file into a format the printer understands
        |
        v
  the formatted file is sent to the printer

Installing and starting CUPS

Desktop installations usually have CUPS already. On a minimal system, install it. On Red Hat based systems you must also start the service yourself:

$ sudo apt install cups                         # Debian
$ sudo dnf install cups                         # Fedora / Red Hat
$ sudo systemctl start cups.service
$ systemctl status cups.service
● cups.service - CUPS Scheduler
     Loaded: loaded (/lib/systemd/system/cups.service; enabled; preset: enabled)
     Active: active (running) since Sun 2023-07-16 13:50:20 EDT; 27s ago
   Main PID: 2366 (cupsd)
     Status: "Scheduler is running..."
     CGroup: /system.slice/cups.service
             └─2366 /usr/sbin/cupsd -l

Installing CUPS pulls in many packages (filters, drivers, Ghostscript, fonts), because it must handle printers from many vendors. You can manage CUPS in three ways: a web interface, GUI tools of your desktop, and command line tools.

Configuration files and logs

CUPS keeps its configuration in /etc/cups/:

# ls /etc/cups/
cups-browsed.conf  cups-files.conf  ppd            raw.convs  snmp.conf  subscriptions.conf
cupsd.conf         interfaces       printers.conf  raw.types  ssl

The files you must know:

File What it holds
/etc/cups/cupsd.conf settings of the CUPS service itself: who can reach which queue, the web interface on or off, the log level
/etc/cups/printers.conf every printer and its queue, each in a <Printer>...</Printer> block. Written by cupsd, do not edit it while CUPS is running
/etc/cups/ppd/ a directory of PPD (PostScript Printer Description) files. Each .ppd is a plain text file that describes what a printer can do
/etc/printcap the legacy file of the old LPD (Line Printer Daemon), one printer per line. CUPS still creates it for compatibility, often as a link to /run/cups/printcap

cupsd.conf looks a lot like an Apache web server configuration. A short part of it:

# /etc/cups/cupsd.conf
LogLevel warn                                   # "debug" when troubleshooting
ErrorPolicy retry-job                           # default error policy for printers
Listen localhost:631                            # only accept connections from this machine
Listen /run/cups/cups.sock
Browsing Yes                                    # show shared printers on the local network
DefaultAuthType Basic
WebInterface Yes                                # enable the web interface

<Location />                                    # who may reach the server
  Order allow,deny
</Location>

<Location /admin/conf>                          # who may read the configuration files
  AuthType Default
  Require user @SYSTEM
  Order allow,deny
</Location>

printers.conf is what the web interface and GUI tools actually edit:

# cat /etc/cups/printers.conf
# Printer configuration file for CUPS v2.4.2
# Written by cupsd
# DO NOT EDIT THIS FILE WHEN CUPSD IS RUNNING
<Printer MyPrinter>
Info My Printer
Location other room
MakeModel HP DesignJet 600 pcl, 1.0
DeviceURI http://thatprinter:631/ipp/
State Idle
Accepting Yes
Shared Yes
ErrorPolicy retry-job
</Printer>

Logs are the first place to look when printing fails. They are in /var/log/cups/:

Log Records
access_log access to the web interface and actions taken there, like printer management
page_log print jobs sent to the queues
error_log failed print jobs and other errors

The web interface

If cupsd.conf has WebInterface Yes, open http://localhost:631 (or the server's IP address on port 631) in a browser. To turn the web interface off: stop CUPS, change it to WebInterface No, and start CUPS again.

The main tabs:

Tab Use
Home the CUPS version and help for users, administrators and developers
Administration add and manage printers and classes, see all jobs, change server settings (sharing, remote administration)
Classes groups of printers with their own rules, for example all printers on one floor, or a page limit. None exist until an admin creates them
Jobs search and list print jobs
Printers all printers and their status, taken from printers.conf
Help the installed CUPS documentation

By default any user can look at printers and queues, but changes need an administrator to log in. That is set by a <Limit> block in cupsd.conf:

# All administration operations require an administrator to authenticate...
<Limit CUPS-Add-Modify-Printer CUPS-Delete-Printer CUPS-Add-Modify-Class CUPS-Delete-Class CUPS-Set-Default>
  AuthType Default
  Require user @SYSTEM
  Order deny,allow
</Limit>
Line Meaning
AuthType Default ask for a basic login when the action needs admin rights
Require user @SYSTEM the user must be an administrator. Use @groupname for members of a group, or a list of users like Require user carol, tim
Order deny,allow deny by default, unless the user (or group member) is authenticated

So to let the members of a printer_admin group add, modify and delete printers:

<Limit CUPS-Add-Modify-Printer CUPS-Delete-Printer CUPS-Set-Default>
  AuthType Default
  Require user @printer_admin
  Order deny,allow
</Limit>

Adding a printer

In the web interface:

  1. Go to Administration, click Add Printer.
  2. Choose how the printer is connected: a local port, or a network printer (CUPS also tries to find printers on the network).
  3. Give it a name, description and location (like "front desk"), and tick the box if you want to share it on the network.
  4. Choose the make and model, so CUPS can find the best driver and PPD file in its local database. Or upload the PPD file from the manufacturer.
  5. Set the default options (page size, resolution). The printer is installed.

Adding a printer is usually just picking it from a dropdown, since CUPS ships most common drivers.

GNOME and KDE have their own printer tools too, but on a server that many users print to, the CUPS web interface is often the best tool.

On the command line, use lpadmin (as root):

$ sudo lpadmin -p ENVY-4510 -L "office" -v socket://192.168.150.25 -m everywhere
Option Meaning
-p the printer (queue) name users will see
-L the location, optional but useful when you have many printers
-v the device URI: where CUPS sends the finished job. Here a network printer at that IP address
-m the model, which decides the PPD file. everywhere lets CUPS ask the printer itself and choose automatically

CUPS is moving away from drivers to IPP (Internet Printing Protocol), which does the same job as a driver. IPP, like the web interface, uses TCP port 631. The old lpinfo command (deprecated) shows which PPD files are installed for a model:

$ lpinfo --make-and-model "HP Envy 4510" -m
hplip:0/ppd/hplip/HP/hp-envy_4510_series-hpijs.ppd HP Envy 4510 Series hpijs, 3.17.10
drv:///hpcups.crv/hp-envy_4510_series.ppd HP Envy 4510 Series, hpcups 3.17.10
everywhere IPP Everywhere

Set the default printer with lpoptions -d:

$ lpoptions -d ENVY-4510

Managing printers with lpadmin

$ sudo lpadmin -p FRONT-DESK -o printer-is-shared=true          # share it on the network
$ sudo lpadmin -p FRONT-DESK -u allow:carol,frank,grace         # only these users may print
$ sudo lpadmin -p FRONT-DESK -u deny:dave                       # everyone except dave
$ sudo lpadmin -p FRONT-DESK -u deny:@sales,@marketing          # groups start with @
$ sudo lpadmin -p FRONT-DESK -o printer-error-policy=abort-job  # what to do on an error

The error policies are:

Policy On an error
abort-job throw the job away
retry-job try the job again later
retry-current-job try the job again right away
stop-printer stop the printer immediately

Printing files

Desktop programs print with a menu or Ctrl+P. Without a desktop, use the legacy LPD commands. lpr ("line printer remote") sends a file to the default printer:

$ lpr report.txt

Which printers exist, and which is the default? Ask lpstat: -p lists printers and -d shows the default:

$ lpstat -p -d
printer FRONT-DESK is idle.  enabled since Mon 03 Aug 2020 10:33:07 AM EDT
printer PostScript_oc0303387803 disabled since Sat 07 Mar 2020 08:33:11 PM EST -
        reason unknown
printer ENVY-4510 is idle.  enabled since Fri 31 Jul 2020 10:08:31 AM EDT
system default destination: ENVY-4510

Use -P to pick another printer:

$ lpr -P FRONT-DESK report.txt
$ lpr -PApple-Dot-Matrix for_print.txt          # the old style, no space, also works

Change how a page is printed with -o options:

Option Effect
landscape rotate the page 90 degrees (same as orientation-requested=4)
two-sided-long-edge print on both sides, portrait
two-sided-short-edge print on both sides, landscape
media=A4 paper size: A4, Letter, Legal, DL, COM10 and more
collate=true keep the pages of each copy in order
page-ranges=5-7,9,15 only print pages 5, 6, 7, 9 and 15
fit-to-page scale the document to fit the paper
outputorder=reverse print from the last page (normal starts at page one)

-#N prints N copies:

$ lpr -P ACCOUNTING-LASERJET -o landscape -o media=A4 -o two-sided-short-edge finance-report.pdf
$ lpr -#7 -o collate=true status-report.pdf

The System V style command lp works too, with some different options: -d chooses the printer and -n the number of copies:

$ lp -d ACCOUNTING-LASERJET -n 7 -o collate=true status-report.pdf

Managing print jobs

The four legacy LPD commands are easy to remember by their last letters. On Debian they may need the cups-bsd package:

Command Use
lpr print a file (remote)
lpq show the queue and its jobs
lprm remove a job from the queue
lpc control and troubleshoot printers

lpq shows the jobs. -a shows all printers, and -P one printer (in the old style there is no space after -P):

$ lpq -PApple-Dot-Matrix
Apple-Dot-Matrix is ready and printing
Rank    Owner   Job     File(s)                Total Size
active  nagato  1       Untitled Document 1    7168 bytes
1st     nagato  2       Untitled1              2048 bytes
2nd     nagato  3       for_print.txt          1024 bytes

lpstat -o shows the queues too. Each job ID starts with the queue name:

$ lpstat -o
ACCOUNTING-LASERJET-4   carol   19456   Wed 05 Aug 2020 04:29:44 PM EDT

lprm removes a job by its ID. A single dash - removes all jobs in the queue. Only root can remove other people's jobs:

$ lprm 2                                        # remove job 2
$ lprm -                                        # remove all jobs
$ lprm -PApple-Dot-Matrix -                     # remove all jobs on this printer (lprm -Pprinter -)

The CUPS command cancel does the same job. With no argument it cancels your current job, or give it the job ID with the printer name:

$ cancel
$ cancel ACCOUNTING-LASERJET-20

lpmove moves a job to another queue, for example when a printer stops working. It usually needs root:

$ sudo lpmove ACCOUNTING-LASERJET-20 FRONT-DESK

Troubleshooting: queuing and printing

lpc status shows two important states of a printer:

$ lpc status
Apple-Dot-Matrix:
    printer is on device 'ipp' speed -1
    queuing is enabled
    printing is enabled
    2 entries
    daemon present
  • queuing is enabled: the queue accepts new jobs. If it is disabled, users cannot even send jobs.
  • printing is enabled: the printer really prints on paper. It becomes disabled when the printer is out of ink or paper, or has a paper jam.

Four commands control these states. Each needs the printer name, and -r adds a reason:

Command Effect
cupsaccept the queue accepts new jobs
cupsreject the queue rejects new jobs
cupsenable printing on paper is enabled
cupsdisable printing on paper is stopped, jobs still wait in the queue
$ cupsdisable Apple-Dot-Matrix -r "need more paper"
$ lpc status
Apple-Dot-Matrix:
    printer is on device 'ipp' speed -1
    queuing is enabled
    printing is disabled
    2 entries
    daemon present

Jobs keep arriving while the paper is refilled, and cupsenable Apple-Dot-Matrix prints them all afterwards.

Removing a printer

First list the printers and how they are connected with lpstat -v, then reject new jobs with a reason, then delete it with lpadmin -x:

$ lpstat -v
device for FRONT-DESK: socket://192.168.150.24
device for ENVY-4510: socket://192.168.150.25
$ sudo cupsreject -r "Printer to be removed" FRONT-DESK
$ sudo lpadmin -x FRONT-DESK

Summary

Printing on Linux means CUPS, the Common Unix Printing System, whose cupsd daemon listens on port 631, spools each job, runs it through filters and sends it to the printer. Its configuration is in /etc/cups/: cupsd.conf (Apache-like, with Listen, Browsing, WebInterface, <Location> and <Limit> blocks), printers.conf (written by cupsd, never edited while it runs), the ppd/ printer descriptions, and the legacy /etc/printcap; the logs access_log, page_log and error_log are in /var/log/cups/. I normally manage it in the web interface at localhost:631, or with lpadmin (-p name, -v device URI, -m everywhere, -u allow: or deny:, -x to delete), and set the default with lpoptions -d. Users print with the LPD legacy command lpr (-P printer, -o options, -# copies) or lp, and I see queues with lpq or lpstat, remove jobs with lprm (-P printer -, with a single -, clears the queue) or cancel, and move them with lpmove. Troubleshooting turns on two ideas: lpc status shows whether the queue is accepting jobs and whether the printer is printing (ink on paper), which I control with cupsaccept/cupsreject and cupsenable/cupsdisable, so I can hold jobs while a printer is jammed and release them later.