background image

Common Criteria

Installation supplement and administrator

guide

April 2010

www.lexmark.com

Lexmark and Lexmark with diamond design are trademarks of Lexmark International, Inc., registered in the United States and/or other countries.

All other trademarks are the property of their respective owners.

© 2010 Lexmark International, Inc.

All rights reserved.
740 West New Circle Road
Lexington, Kentucky 40550

3060008-002

Summary of Contents for X651

Page 1: ...exmark with diamond design are trademarks of Lexmark International Inc registered in the United States and or other countries All other trademarks are the property of their respective owners 2010 Lexm...

Page 2: ...ernational Inc Bldg 004 2 CSC 740 New Circle Road NW Lexington KY 40550 References in this publication to products programs or services do not imply that the manufacturer intends to make these availab...

Page 3: ...g user accounts 10 Creating security templates 12 Controlling access to device functions 12 Disabling home screen icons 14 Administering the device 15 Using the Embedded Web Server 15 Settings for net...

Page 4: ...d within the required time error message 41 User s Realm was not found in the Kerberos Configuration file error message 41 Realm on the card was not found in the Kerberos Configuration File error mess...

Page 5: ...bedded Web Server EWS or the device touch screen Where applicable instructions for both methods are included For information about physically setting up the MFP or using device features see the UserGu...

Page 6: ...MFP on using the power switch 3 From the home screen touch Menus Reports Menu Settings Page Several pages of device information will print 4 Under Installed Features verify that no Download Emulator...

Page 7: ...nd hold the 2 and 6 keys on the numeric keypad while turning the device back on It takes approximately a minute to boot into the Configuration menu Once the MFP is fully powered up the touch screen sh...

Page 8: ...er off the device during the encryption process Doing so may result in loss of data Note Disk encryption can take several hours to complete 8 To finish press Back and then Exit Config Menu The MFP wil...

Page 9: ...t access to device functions 5 Disable home screen icons Configuring disk wiping Note Not all devices have a hard disk installed This section applies only to devices containing a hard disk Disk wiping...

Page 10: ...unts General Settings Groups for Internal Accounts 2 On the Groups for Internal Accounts screen select Add Entry 3 For the Name type Administrator_Only 4 Touch Next to save this group and return to th...

Page 11: ...ser s account name example Jack Smith and then touch Next 5 Type a user ID for the account example jsmith and then touch Next 6 Type a password for the account and then touch Next Passwords must Conta...

Page 12: ...in use can be modified 1 From the home screen touch Menus Security Edit Security Setups Edit Security Templates 2 To remove all security templates select Delete List 3 To remove an individual security...

Page 13: ...rmware Updates Not applicable USB port disabled Flash Drive Print Not applicable USB port disabled Flash Drive Scan Not applicable USB port disabled FTP Function Any valid setting Held Jobs Access Dis...

Page 14: ...u Remotely Not applicable all remote access disabled Solution 1 Authenticated users Note When eSF applications are configured Solution 1 controls access to Held Jobs Solutions 2 10 Administrator acces...

Page 15: ...r 1 From the home screen touch Menus Network Ports Standard Network STD NET SETUP TCP IP 2 From TCP IP scroll to locate Enable HTTP Server 3 Set Enable HTTP Server to Yes and then touch Submit 4 Again...

Page 16: ...d for SSL support in LDAP Each certificate must be in a separate PEM cer file Setting certificate defaults The values entered here will be present in all new certificates generated in the Certificate...

Page 17: ...the certificate Country Name Type the country location for the company or organization issuing the certificate 2 character maximum Province Name Type the name of the province where the company or org...

Page 18: ...he power switch Setting up IPSec IPSecencryptsIPpacketsastheyaretransmittedoverthenetworkbetweendevices Itdoesnothandleauthentication or restrict access 1 From the EWS click Settings Security IPSec No...

Page 19: ...he home screen touch Menus Network Ports Standard Network STD NET SETUP b From the Std Network Setup screen select AppleTalk Activate Note It might be necessary to scroll down to find the AppleTalk se...

Page 20: ...urity TCP IP Port Access 2 Clear the following check boxes TCP 21 FTP UDP 69 TFTP TCP 79 FINGER TCP 80 HTTP UDP 161 SNMP TCP 443 HTTPS TCP 631 IPP TCP 5000 XML TCP 5001 IPDS TCP 6110 UDP6110 TCP6100 T...

Page 21: ...nable Authentication to On 5 Touch Submit Kerberos IfyouwillbeusingLDAP GSSAPIorCommonAccessCardstocontroluseraccesstotheMFP youmustfirstconfigure Kerberos Using the EWS 1 From the EWS click Settings...

Page 22: ...be configured or adjusted using the touch screen 1 From the home screen touch Menus Security Edit Security Setups Edit Building Blocks Simple Kerberos Setup 2 From the Simple Kerberos Setup screen sel...

Page 23: ...ne endings choose LF n CR r or CRLF r n to specify how line endings will be handled in the log file depending on the operating system in which the file will be parsed or viewed Select Digitally sign e...

Page 24: ...if you want the MFP to add a digital signature to E mail alerts 13 Touch Submit Note In order to use E mail alerts you must also configure SMTP settings For information about SMTP settings see E mail...

Page 25: ...following settings Server must be blank Login must be blank Password must be blank Path must be Base file name image must be blank Web Link must be blank 3 Touch Back and then touch Back again to retu...

Page 26: ...ave finished using the EWS 2 Under Fax Receive Settings click Holding Faxes 3 Set Held Fax Mode to Always On 4 Click Submit to save changes and return to Settings 5 Under Fax Send Settings clear the D...

Page 27: ...MFP will power on reset and then return to normal operating mode Configuring security reset jumper behavior The security reset jumper is a hardware jumper located on the motherboard that can be used t...

Page 28: ...color_user Marketing Copy Color Printing fax_user Office Marketing Fax Function WhencreatinginternalaccountsinScenario1 youwouldselectthegroupthatcorrespondstotheuser sdepartment Scenario 2 Creating...

Page 29: ...he account should belong Hold down the Ctrl key to select multiple groups for the account 7 Click Submit Configuring LDAP GSSAPI On networks running Active Directory you can use LDAP GSSAPI to take ad...

Page 30: ...vice Credentials optional MFP Kerberos Username Type the distinguished name of the print server s MFP Password Type the Kerberos password for the print server s Search specific object classes optional...

Page 31: ...print server s MFP Password The Kerberos password for the print server s Touch Submit to save settings and return to General Information 7 From the General Information Screen select Search Specific O...

Page 32: ...ation provides the login screen and authentication mechanism and supports user authorization to the MFP and its functions 1 From the EWS click Settings Embedded Solutions 2 Under Installed Solutions s...

Page 33: ...nfigure the following Responder URL The IP address or hostname of an OCSP responder repeater along with the port being used usually 80 The correct format is http ip_address port_number http 255 255 25...

Page 34: ...select a method for authenticating users This list will be populated with the authentication building blocks that have been configured on the MFP internal accounts LDAP GSSAPI and or PKI Authenticatio...

Page 35: ...ew Current Value 5 For Access Control select Solution specific access control 1 6 Select from the following Release Options to determine how users will be able to release print jobs Release Method Sel...

Page 36: ...authorization Any valid setting Can be any valid setting available for a function at the discretion of the administrator Disabled Disables access to a function for all users and administrators Not ap...

Page 37: ...mote access disabled PictBridge Printing Not applicable USB port disabled PJL Device Setting Changes Disabled Release Held Faxes Administrator access only Remote Certificate Management Not applicable...

Page 38: ...cess Control Level of protection Supplies Menu Remotely Not applicable all remote access disabled Use Profiles Authenticated users Web Import Export Settings Not applicable all remote access disabled...

Page 39: ...alled but not running select the check box next to the application name and then click Start If the authentication token does not appear in the list of installed solutions contact the Lexmark Solution...

Page 40: ...nfigure 2 If the Simple Kerberos Setup has been configured in PKI Authentication clear the Use Device Kerberos Setup check box and then click Apply 3 If a Kerberos configuration file is needed a From...

Page 41: ...eros Configuration file error message This error occurs during manual login and indicates the Windows Domain is not specified in the Kerberos settings 1 From the Embedded Web Server click Settings Emb...

Page 42: ...iscellaneous Security Settings Login Restrictions 2 Increase the time in seconds of the Panel Login Timeout LDAP Issues LDAP lookups take a long time and then may or may not work This normally occurs...

Page 43: ...r click Settings Network Ports Address Book Setup 2 Verify or adjust the following settings Server Port Should be 636 Use SSL TLS Select SSL TLS LDAP Certificate Verification Select Never 3 Click Subm...

Page 44: ...anual login is used to set the userid userid LDAP Lookup The userid is retrieved from Active Directory 3 Click Apply to save any needed changes There are no jobs available for USER error message PKI A...

Page 45: ...tion menus for the device Note Access to device menus may be restricted to administrators only Using the on screen keyboard Some device settings require one or more alphanumeric entries such as server...

Page 46: ...number you need to capitalize or shift select To turn on caps lock touch the up arrow A with the lock symbol and then continue typing Uppercase Shift will remain engaged until you touch the lock key a...

Page 47: ...Hypertext Transfer Protocol IP Internet Protocol IPSec Internet Protocol Security IPv4 Internet Protocol Version 4 IPv6 Internet Protocol Version 6 KDC Key Distribution Center LDAP Lightweight Directo...

Page 48: ...ngs menu in the Embedded Web Server Create Profiles Controls the ability to create new profiles E mail Function Controls access to the Scan to Email function eSF Configuration Controls access to the c...

Page 49: ...xes Remote Certificate Management When disabled it is no longer possible to manage certificates using remote management tools Certificate Management is limited to the operations available from the pri...

Page 50: ...panel Supplies Menu Remotely Protects access to the Supplies menu from the Embedded Web Server User Profiles Controls access to Profiles such as scanning shortcuts workflows or eSF applications Web Im...

Page 51: ...the MFP 1 Insert your Common Access Card into the card reader attached to the MFP Note The appearance of your MFP including the location of the card reader may vary 2 When prompted use the number pad...

Page 52: ...fter your logon credentials have been validated the MFP will return to the home screen Note The MFP home screen may contain different icons than the one shown here For more information about using the...

Page 53: ...ITATION OF WARRANTIES EXCEPT AS PROVIDED IN THIS LICENSE AGREEMENT AND TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW LEXMARK AND ITS SUPPLIERS PROVIDE THE SOFTWARE PROGRAM AS IS AND HEREBY DISCLAI...

Page 54: ...ecessary for the legitimate Use of the Software Program 7 ADDITIONAL SOFTWARE This License Agreement applies to updates or supplements to the original Software Program provided by Lexmark unless Lexma...

Page 55: ...ftware clause at DFARS 252 227 7013 and in similar FAR provisions or any equivalent agency regulation or contract clause 15 CONSENT TO USE OF DATA You agree that Lexmark its affiliates and agents may...

Page 56: ...F fax forwarding 26 fax settings Driver to fax 26 fax forwarding 26 held faxes 26 fax storage 26 firmware verifying 6 function access using the EWS to restrict 36 using the touch screen to restrict 12...

Page 57: ...not installed 40 home screen does not lock 39 jobs not being held at printer 44 jobs print immediately 44 KDCandMFPclocksoutofsync 40 KDC did not respond within the required time 41 Kerberos file not...

Page 58: ...www lexmark com...

Reviews: