background image

 

 

1.

 

All  passwords  entered  on  the  Control  Panel  for  authentication  purposes  will  be  obfuscated  by  ‘*’s.  All  passwords 

entered  on  the  WebUI  for  authentication  purposes  will  also  be  obfuscated,  but  the  character  that  does  the 

obfuscation will depend on the web browser used. This applies to all the models covered by these guidelines. 

2.

 

The System Administrator does not have to configure or perform any actions to utilize the random number generation 

needed for key generation and for the encryption algorithms the products covered by these guidelines use for the 

security features described in I. and III.  

4

 

Change the SNMPv1/v2c public/private community strings from their default string names to random un-guessable 

string names of at least 8 characters in length. 

5

 

Customers should sign up for the RSS

5

 subscription service available via the Xerox Security Web Site (Security@Xerox) 

at 

www.xerox.com/security

 that permits customers to view the latest Xerox Product Security Information and receive 

timely reporting of security information about Xerox products, including the latest security patches. 

6

 

Customers who encounter or suspect software problems  should immediately contact  the Xerox Customer Support 

Center  to  report  the  suspected  problem  and  initiate  the  SPAR  (Software  Problem  Action  Request)

6

  process  for 

addressing problems found by Xerox customers.   

Customers who required specialized changes to support unique workflows in their environment may request specific changes 

to normal behavior. Xerox will supply these SPAR releases to the specific customers requesting the change. Please note that 

in general enabling a specialized customer-specific feature will take the system out of the evaluated configuration. 

Contact 

For additional information or clarification on any of the product information given here, contact Xerox support. 

The information in this document is subject to change without notice. 

 

 

                                                                    

5

 Really Simple Syndication – A lightweight XML format for distributing news headlines and other content on the Web. Details for signing up for 

this RSS Service are provided in the 

Security@Xerox RSS Subscription Service guide 

posted on the Security@Xerox site at

 

http://www.xerox.com/go/xrx/template/009.jsp?view=Feature&ed_name=RSS_Security_at_Xerox&Xcntry=USA&Xlang=en_US

.  

6

 A SPAR is the software problem report form used internally within Xerox to document customer-reported software problems found in products 

in the field.

 

Summary of Contents for VersaLink

Page 1: ...Version 1 0 July 10 2017 Secure Installation and Operation Xerox VersaLink Multifunction and Single Function Printer...

Page 2: ...rights reserved Xerox and Xerox and Design and VersaLink are trademarks of Xerox Corporation in the United States and or other countries BR22046 Other company trademarks are also acknowledged Documen...

Page 3: ...Web Server Interface denoted hereafter as the Web UI follow the instructions under Accessing the Embedded Web Server as a System Administrator under Accessing Administration and Configuration Settings...

Page 4: ...tting the Network Login Method instructions in Section 4 of the SAG to set up an Authentication Server For the most secure network authentication the preferred authentication types are Kerberos or LDA...

Page 5: ...can be installed on the device follow the instructions for Creating a Certificate Signing Request under Security Certificates in Section 4 of the SAG to create the CSR If desired certificate path val...

Page 6: ...ession Inactivity Timeout Enable the session inactivity timers termination of an inactive session from the Web UI by following the instructions for Setting System Timeouts in Section 4 of the SAG The...

Page 7: ...setting Fax Forwarding in Configuring the Fax Settings at the Control Panel under Configuring General Settings and Policies 4 Scan to Email Set the domain filtering to limit the domains to which Scan...

Page 8: ...llowing internal customer policies and procedures required to evaluate and install devices in your environment III Secure Operation of Device Services Functions a Change the following passcodes on a r...

Page 9: ...riate training on how to use the device in a secure manner before being assigned user accounts to access the device j Users experiencing problems logging in to the device using the Web UI only on a pa...

Page 10: ...nter or suspect software problems should immediately contact the Xerox Customer Support Center to report the suspected problem and initiate the SPAR Software Problem Action Request 6 process for addre...

Reviews: