background image

 

 

 

I. 

Secure Installation and Set-up in the Evaluated Configuration

 

To set up the machines in the evaluated configuration, follow the guidelines below: 

a.  Make sure that the following system software releases along with patch 905956v2

4

 

are installed on the device: 

 

WorkCentre 3655/3655i: 073.060.075.34540 

 

WorkCentre 5845/5855/5865/5865i/5875/5875i/5890/5890i: 073.190.075.34540 

 

WorkCentre 5945/5945i//5955/5955i: 073.091.075.34540 

 

WorkCentre 6655/6655i: 073.110.075.34540 

 

WorkCentre 7220/7220i/7225/7225i: 073.030.075.34540 

 

WorkCentre 7830/7830i/7835/7835i: 073.010.075.34540 

 

WorkCentre 7845/7845i/7855/7855i: 073.040.075.34540 

 

WorkCentre 7970/7970i: 073.200.075.34540 

b.  Set up and configure the following security protocols and functions in the evaluated configuration: 

 

Immediate Image Overwrite 

 

On Demand Image Overwrite 

 

Data Encryption 

 

FIPS 140-2 Mode 

 

IP Filtering  

 

Audit Log 

 

Security Certificates, Transport Layer Security (TLS)/Secure Sockets Layer (SSL) and HTTPS 

 

IPSec 

 

Local, Remote or Smart Card Authentication 

 

Local or Remote Authorization  

 

User Permissions 

 

Personalization 

 

802.1x Device Authentication 

 

Session Inactivity Timeout 

 

USB Port Security 

 

SFTP Filing 

 

Embedded Fax Secure Receive  

 

Secure Print 

 

Hold All Jobs 

 

McAfee

®

 Embedded Control  

 

Erase Customer Data 

System Administrator login is required when accessing the security features via the Web User Interface (Web UI) 
or when implementing the guidelines and recommendations specified in this document. To log in to the Web UI as 
an authenticated System Ad

ministrator, follow the instructions under “Accessing CentreWare Information Services 

as  a  System  Administrator

”  under  “Accessing  Administration  and  Configuration  Settings”  in  Section  2  of  the 

applicable System Administration Guide (SAG)

5

.  

To log in to the Local User Interface (denoted hereafter in this document as the Control Panel) as an authenticated 
System  Administrator,  follow 

“Accessing  the  Control  Panel  as  a  System  Administrator”  under  “Accessing 

Administration and Configuration Settings” in Section 2 of the SAG. 

                     

4

 Links to each of the system software mentioned above, along with the applicable installation instructions, can be found at 

http://www.support.xerox.com/support/enus.html

 by searching for the products listed above with the ‘I’ designation (e.g., WorkCentre 3655i) 

and then selecting the ‘Drivers & Downloads’ link; 

the link to the 905956v2

 

patch can be found at 

http://www.support.xerox.com/support/CK_PROD_DOWN/file-download/enus.html?contentId=134478

  

 .  

5

Xerox

®

 WorkCentre

®

 3655/3655i Multifunction Printer 2016 Xerox

®

 ConnectKey

®

 Technology System Administrator Guide, Version 1.3, 

February 2016; Xerox

®

 WorkCentre

®

 5800/5800i Multifunction Printer 2016 Xerox

®

 ConnectKey

®

 Technology System Administrator Guide, 

Version 1.3, February 2016; Xerox

®

 WorkCentre

®

 5945/5945i/5955/5955i Multifunction Printer 2016 Xerox

®

 ConnectKey

®

 Technology System 

Administrator Guide, Version 1.3, February 2016; Xerox

®

 WorkCentre

®

 6655/6655i Multifunction Printer 2016 Xerox

®

 ConnectKey

®

 Technology 

System Administrator Guide, Version 1.3, February 2016; Xerox

®

 WorkCentre

®

 7220/7220i/7225/7225i Multifunction Printer 2016 Xerox

®

 

ConnectKey

®

 Technology System Administrator Guide, Version 1.3, February 2016; Xerox

®

 WorkCentre

®

 7800/7800i Multifunction Printer 

2016 Xerox

®

 ConnectKey

®

 Technology System Administrator Guide, Version 1.3, February 2016; Xerox

®

 WorkCentre

®

 7970/7970i 

Multifunction Printer 2016 Xerox

®

 ConnectKey

®

 Technology System Administrator Guide, Version 1.3, February 2016.  

Summary of Contents for WorkCentre 3655

Page 1: ...ntre 5845 5855 5865 5865i 5875 5875i 5890 5890i WorkCentre 5945 5945i 5955 5955i WorkCentre 6655 6655i WorkCentre 7220 7220i 7225 7225i WorkCentre 7830 7830i 7835 7835i 7845 7845i 7855 7855i WorkCentr...

Page 2: ...from the Common Criteria Certified Product website http www commoncriteriaportal org products html list of evaluated products from the Xerox security website http www xerox com information security c...

Page 3: ...Accessing Administration and Configuration Settings in Section 2 of the applicable System Administration Guide SAG 5 To log in to the Local User Interface denoted hereafter in this document as the Con...

Page 4: ...ructions in Section 4 of the SAG Set up unique user accounts with appropriate privileges on the device for all users who require access to the device by following the User Database instructions in Sec...

Page 5: ...ed certificate is installed by default on the device If a CA certificate is desired a Certificate Signing Request CSR will have to be sent to a Certificate Authority to obtain the CA Certificate befor...

Page 6: ...number for the Audit Log Server Enter the directory path to the filename where the transferred Audit Log is to be stored Enter the login name and password to access the Audit Log server Either schedu...

Page 7: ...re print job only the submitter of a held print job can release the job and only the System Administrator can delete any print job 16 802 1x Device Authentication Enable and configure 802 1x device au...

Page 8: ...ption and signing Workflow Scanning Scan to Mailbox Scan to USB Print from USB Print from Mailbox NTP SMB Filing When setting up the device to be in the evaluated configuration perform the following s...

Page 9: ...Fax in Section 8 of the SAG Makes sure the Delete on Print option is selected for Received Documents The Local Polling option and embedded fax mailboxes should not be set up or used at any time Remot...

Page 10: ...encryption and signing of Scan to Email jobs by following the instructions for Configuring Email Encryption Settings and Configuring Email Signing Settings respectively under Configuring Email Securit...

Page 11: ...0 of the SAG II Secure Acceptance Secure acceptance once device delivery and installation is completed should be done by Printing out a Configuration Report from the Web UI by following the Printing t...

Page 12: ...age will persist until an On Demand Image overwrite is initiated by the System Administrator In the case that the copy controller is reset at the same time a copy job is being processed by the device...

Page 13: ...certificate should be uploaded to the device so the device can verify the certificate provided by the remote repository When an SSL certificate for a remote SSL repository fails its validation checks...

Page 14: ...rvice calls for example through appropriate signage in order to discourage unauthorized physical attacks such as attempts to remove the internal hard disk drive s Ensure that office personnel are made...

Page 15: ...vice Allows the user to pause an active copy print workflow scanning scan to email Internet Fax or Embedded Fax job while it is being processed Is accessible by selecting the Stop machine hard button...

Page 16: ...Filter guess algorithm will use a strict or loose interpretation Is accessible by typing http IP Address diagnostics postScriptTokens php Web Services IP Lockout Reset Allows the System Administrator...

Page 17: ...t be displayed for a device in the evaluated configuration Scan Image Compression Allows the System Administrator to manage the asymmetric sub sampling options of scan image processing Is accessible b...

Page 18: ...m the Web User Interface with no user login and authentication required Site Map Provides the user with hyperlink pointers to each Web User Interface screen organized by Web UI tab Is accessible by se...

Page 19: ...oss of business profits or special damages even if Xerox Corporation has been advised of the possibility of such damages Some states do not allow the exclusion or limitation of liability for consequen...

Reviews:

Related manuals for WorkCentre 3655