background image

Secure Installation and Operation of Your ColorQube™ 8700/8900 

 

Purpose and Audience 

This

 

document  provides  information  on  the  secure  installation  and  operation  of  a  ColorQube™  8700/8900  Multifunction 

System. All customers, but particularly those concerned with secure installation and operation of these machines, should follow 
these guidelines. 

Overview 

This document lists some important customer information and guidelines that will ensure that your machine is operated and 
maintained in a secure manner.   

Background 

This product is currently undergoing Common Criteria evaluation. The information provided here is consistent with the security 
functional claims made in the Security Target

1

. Upon completion of the evaluation, the Security Target will be available from 

the  Common  Criteria  Certified  Product  website  (http://www.commoncriteriaportal.org/products.html)  list  of  evaluated 
products, from the Xerox security website (http://www.xerox.com/information-security/common-criteria-certified/enus.html ), or 
from your Xerox representative. 

1.

 

Please follow the guidelines below for secure installation, setup and operation of the evaluated 

[XC1]

configuration

2

a).

 

The security functions in the evaluated configuration that should be set up by the System Administrator are: 

 

Immediate Image Overwrite 

 

On Demand Image Overwrite 

 

Disk Encryption 

 

FIPS 140-2 Encryption 

 

IP Filtering  

 

Audit Log 

 

SSL 

 

IPSec 

 

Local, Remote or Smart Card Authentication 

 

Local Authorization and Personalization 

 

802.1x Device Authentication 

 

Session Inactivity Timeout 

System Administrator login is required when accessing the security features via the Web User Interface (Web UI) or when 
implementing the guidelines and recommendations specified in this document. To log in to the Web UI as an authenticated 
System Administrator, follow the instructions under “Initial Setup in CentreWare Information Services” located on page 19 
in the System Administration Guide (SAG)

3

.  

To log in to the Local User Interface (Local UI) as an authenticated System Administrator, follow the “System Administrator 
Access at the Control Panel” instructions located on page 18 in the SAG. 

Follow the instructions located in the SAG in Chapter 4, Security to set up these security functions except as noted in the 
items below. Note that whenever the SAG

 

requires that the System Administrator provide an IPv4 address, IPv6 address or 

port number the values should be those that pertain to the particular device being configured.

 

b).

 

The following services are also considered part of the evaluated configuration and should be enabled when needed by the 
System  Administrator  -  Copy,  Embedded  Fax,  Fax  Forwarding  on  Receive  (for  received  Embedded  Faxes),  Scan  to  E-mail, 
Workflow Scanning, Scan to Mailbox, Scan to USB, Print from USB and Print from Mailbox. 

Secure acceptance, once device delivery and installation is completed, should be done by:  

 

Printing out a Configuration Report by following the “Configuration Report” instructions located on page 17 of the SAG. 

 

Comparing  the  software/firmware  versions  listed  on  the  Configuration  Report  with  the  Evaluated  Software/Firmware 
versions listed in Table 2 of the Security Target, latest version issued and make sure that they are the same in all cases.  

c).

 

Change the Administrator password as soon as possible. Reset the Tools password periodically.   

 (1) Set the Administrator password to a minimum length of eight alphanumeric characters, (2) change the Administrator 
password  once  a  month  and  (3)  ensure  that  all  passwords  are  strong  passwords  (e.g.,    passwords  use  a  combination  of 
alphanumeric and non-alphanumeric characters; passwords don’t use common names or phrases, etc.).  

                     

1

 Xerox ColorQube™ 8700/8900 Security Target, Latest Version issued 

2

 The term “evaluated configuration” will be used throughout this document to refer to the configuration of the machine that is currently 

undergoing Common Criteria evaluation. 

3

Xerox

 ColorQube

 8700 / 8900 System Administrator Guide, Version 1.0: February 2012 

Содержание ColorQube 8700

Страница 1: ...Version 1 1 Sep 21 2012 Secure Installation and Operation of Your ColorQube 8700 8900 ...

Страница 2: ...on page 19 in the System Administration Guide SAG 3 To log in to the Local User Interface Local UI as an authenticated System Administrator follow the System Administrator Access at the Control Panel instructions located on page 18 in the SAG Follow the instructions located in the SAG in Chapter 4 Security to set up these security functions except as noted in the items below Note that whenever the...

Страница 3: ...le h In the evaluated configuration only the System Administrator should have the ability to delete a job From the Local UI follow the instructions for Setting Job Deletion Options at the Control Panel on page 198 of the SAG to set job deletion to System Administrator Only From the WebUI set the permission for Delete Jobs under the Job Status Pathway to Not Allowed for all roles defined other than...

Страница 4: ...emand Image Overwrite request the confirmation sheet must have printed The Embedded Fax card must have the correct software version and must be properly configured When invoked from the Web UI the status of the completed On Demand Image Overwrite will not appear on the Local UI but can be ascertained from the On Demand Overwrite Confirmation Report that is printed after the Network Controller rebo...

Страница 5: ...trator should ensure that SSL is enabled as discussed in Step 3 under Configuring LDAP Server Optional Information on page 47 in the SAG Make sure that Enable SSL under SSL is selected s To be consistent with the evaluated configuration the device should be set for local authorization Remote authorization was not evaluated since that function is performed external to the system Choose the authoriz...

Страница 6: ...ore scanned documents only in private folders To set the scan policies for the Scan to Mailbox feature follow the instructions under Setting Scan Policies starting on page 126 of the SAG Public folders are not allowed in the evaluated configuration The scan policies should therefore be set as follows Deselect Allow Scanning to Default Public Folder Deselect Require per Job password to public folde...

Страница 7: ...ion mm The following features and protocols are not included in the evaluation Reprint from Saved Job SMart eSolutions Custom Services Extensible Interface Platform or EIP Network Accounting and Auxiliary Access Internet Fax Use of Embedded Fax mailboxes NTP Direct USB Printing AppleTalk and Novell protocols SFTP Web Services 2 The System Administrator should change the SNMPv1 v2c public private c...

Страница 8: ...unts to access the device 15 The following windows are available to any authenticated and authorized user from the Local User Interface These windows provide standard machine services or job management capability Embedded Fax Batch Send Confirmation Allows a user to either send an Embedded Fax job to a remote destination immediately or include the job as part of a batch of Embedded Fax jobs sent t...

Страница 9: ...typing http IP Address diagnostics hideotherqueuesbutton php Secure Print Alphanumeric PIN Allows the System Administrator to set the secure print PIN to be alphanumeric characters instead of just digits Is accessible by typing either http IP Address diagnostics index dhtml and then selecting Secure Print Alphanumeric PIN from the Diagnostics Content Menu or by typing http IP Address diagnostics s...

Страница 10: ...M NTLM versions Is accessible by typing http IP Address diagnostics NTLMSecurity php Custom Size Allowed Allows the System Administrator to allow custom size paper to be used for print jobs Is accessible by typing http IP Address diagnostics customSizeAllowed php Copies Per Page Print Setting Allows the System Administrator to permit the use of the copies per page setting for print jobs Is accessi...

Страница 11: ...n general enabling a specialized customer specific feature will take the system out of the evaluated configuration Contact For additional information or clarification on any of the product information given here contact Xerox support Disclaimer The information provided in this Xerox Product Response is provided as is without warranty of any kind Xerox Corporation disclaims all warranties either ex...

Отзывы: