background image

 

 

4

 

For the purposes of the evaluation, the maximum validity of digital certificates was set to 180 days.  

 

If a self-signed certificate is to be used the generic Xerox root CA certificate should be downloaded from the device and 
installed in the certificate store of the user's browser. 

n).

 

HTTPS  is  enabled  in  the  evaluated  configuration.  To  enable  secure  HTTPS  follow  the  instructions  in  Steps  6  and  7  under 
‘Configuring HTTP Settings in CentreWare Internet Services” on page 50 of the SAG. 

o).

 

When utilizing Secure Sockets Layer (SSL) for secure scanning: 

 

SSL should be enabled and used for secure transmission of scan jobs. 

 

When  storing  scanned  images  to  a  remote  repository  using  an  https:  connection,  a  Trusted  Certificate  Authority 
certificate should be uploaded to the device so the device can verify the certificate provided by the remote repository. 

 

When an SSL certificate for  a remote SSL repository fails its validation checks the associated scan job will be deleted 
and not transferred to the remote SSL repository. The System Administrator should be aware that in this case the job 
status  reported  in  the  Completed  Job  Log  for  this  job  will  read:  “Job  could  not  be  sent  as  a  connection  to  the  server 
could not be established”. 

p).

 

To  be  consistent  with  the  evaluated  configuration,  the  HTTPS  protocol  should  be  used  to  send  scan  jobs  to  a  remote  IT 
product.  

q).

 

SNMPv3  cannot  be  enabled  until  SSL  (Secure  Sockets  Layer)  and  HTTPS  (SSL)  are  enabled  on  the  machine.  To  enable 
SNMPv3  follow  the  instructions  starting  on  page  35  of  the  SAG.  The  System  Administrator  should  be  aware  that  in 
configuring SNMPv3 there is the  option  of resetting both the  Privacy and  Authentication passwords back to their default 
values.  This  option  should  only  be  used  if  necessary  since  if  the  default  passwords  are  not  known  no  one  will  be  able  to 
access the SNMP administrator account

4

r).

 

To  be  consistent  with  the  evaluated  configuration,  protocol  choices  for  remote  authentication  should  be  limited  to 
[

Kerberos  (Solaris)

],  [

Kerberos  (Windows)

]  or  [

LDAP

].

 

The  device  supports  other  protocol  options.

 

Choose  the  protocol 

option that best suits your needs. The System  Administrator should be aware, however, that remote authentication using 
Kerberos will not work with Windows Server 2003.  

In  the  case  of  LDAP/LDAPS  the  System  Administrator  should  ensure  that  SSL  is  enabled  as  discussed  in  Step  3  under 
“Configuring LDAP Server Optional Information” on page 47 in the SAG. Make sure that [

Enable SSL

] under SSL is selected. 

s).

 

To be consistent  with the evaluated configuration, the  device should be  set  for local  authorization. Remote authorization 
was not evaluated since that function is performed external to the system.

 

Choose the authorization option that best suits 

your needs. 

t).

 

As part of the evaluated configuration, encryption of transmitted and stored data by the device must meet the FIPS 140-2 
Standard. To enable the use of encryption in “FIPS 140 mode” and check for compliance of certificates stored on the device 
to the FIPS 140-2 Standard follow the instructions on page 76 of the SAG.  

u).

 

In viewing the Audit Log the System Administrator should note the following: 

 

Deletion of a file from Reprint Saved Job folders or deletion of a Reprint Saved Job folder itself is recorded in the Audit 
Log.  

 

Deletion of a print or scan job or deletion of a scan-to-mailbox job from its scan-to-mailbox folder may not be recorded 
in the Audit Log.   

 

Extraneous  process  termination  events  (Event  50)  may  be  recorded  in  the  Audit  Log  when  the  device  is  rebooted  or 
upon  a  Power  Down  /  Power  Up.  Extraneous  security  certificate  completion  status  (Created/Uploaded/Downloaded) 
events (Event 38) may also be recorded. 

v).

 

The System  Administrator should download and review  the  Audit Log  on a daily basis.  The machine will  send a  warning 
email when the audit log is filled to 90% (i.e., 13,500) of the 15,000 maximum allowable number of entries, and repeated 
thereafter at 15,000 entries until the Audit Log is downloaded. 

 

In downloading the Audit Log the System Administrator should ensure that Audit Log records are protected after they have 
been exported to an external trusted IT product and that the exported records are only accessible by authorized individuals. 

 

w).

 

Be careful not to create an IP Filtering rule that rejects incoming TCP traffic from all addresses with source port set to 80; 
this will disable the Web UI. Also, the System Administrator should configure IP filtering so that traffic to open ports from 

                     

4

The SNMP administrator account is strictly for the purposes of accessing and modifying the MIB objects via SNMP; it is separate from the System 

Administrator “admin” user account or user accounts given SA privileges by the System Administrator “admin” user. The administrator account can 
not perform any System Administrator functions.   

Содержание ColorQube 8700

Страница 1: ...Version 1 1 Sep 21 2012 Secure Installation and Operation of Your ColorQube 8700 8900 ...

Страница 2: ...on page 19 in the System Administration Guide SAG 3 To log in to the Local User Interface Local UI as an authenticated System Administrator follow the System Administrator Access at the Control Panel instructions located on page 18 in the SAG Follow the instructions located in the SAG in Chapter 4 Security to set up these security functions except as noted in the items below Note that whenever the...

Страница 3: ...le h In the evaluated configuration only the System Administrator should have the ability to delete a job From the Local UI follow the instructions for Setting Job Deletion Options at the Control Panel on page 198 of the SAG to set job deletion to System Administrator Only From the WebUI set the permission for Delete Jobs under the Job Status Pathway to Not Allowed for all roles defined other than...

Страница 4: ...emand Image Overwrite request the confirmation sheet must have printed The Embedded Fax card must have the correct software version and must be properly configured When invoked from the Web UI the status of the completed On Demand Image Overwrite will not appear on the Local UI but can be ascertained from the On Demand Overwrite Confirmation Report that is printed after the Network Controller rebo...

Страница 5: ...trator should ensure that SSL is enabled as discussed in Step 3 under Configuring LDAP Server Optional Information on page 47 in the SAG Make sure that Enable SSL under SSL is selected s To be consistent with the evaluated configuration the device should be set for local authorization Remote authorization was not evaluated since that function is performed external to the system Choose the authoriz...

Страница 6: ...ore scanned documents only in private folders To set the scan policies for the Scan to Mailbox feature follow the instructions under Setting Scan Policies starting on page 126 of the SAG Public folders are not allowed in the evaluated configuration The scan policies should therefore be set as follows Deselect Allow Scanning to Default Public Folder Deselect Require per Job password to public folde...

Страница 7: ...ion mm The following features and protocols are not included in the evaluation Reprint from Saved Job SMart eSolutions Custom Services Extensible Interface Platform or EIP Network Accounting and Auxiliary Access Internet Fax Use of Embedded Fax mailboxes NTP Direct USB Printing AppleTalk and Novell protocols SFTP Web Services 2 The System Administrator should change the SNMPv1 v2c public private c...

Страница 8: ...unts to access the device 15 The following windows are available to any authenticated and authorized user from the Local User Interface These windows provide standard machine services or job management capability Embedded Fax Batch Send Confirmation Allows a user to either send an Embedded Fax job to a remote destination immediately or include the job as part of a batch of Embedded Fax jobs sent t...

Страница 9: ...typing http IP Address diagnostics hideotherqueuesbutton php Secure Print Alphanumeric PIN Allows the System Administrator to set the secure print PIN to be alphanumeric characters instead of just digits Is accessible by typing either http IP Address diagnostics index dhtml and then selecting Secure Print Alphanumeric PIN from the Diagnostics Content Menu or by typing http IP Address diagnostics s...

Страница 10: ...M NTLM versions Is accessible by typing http IP Address diagnostics NTLMSecurity php Custom Size Allowed Allows the System Administrator to allow custom size paper to be used for print jobs Is accessible by typing http IP Address diagnostics customSizeAllowed php Copies Per Page Print Setting Allows the System Administrator to permit the use of the copies per page setting for print jobs Is accessi...

Страница 11: ...n general enabling a specialized customer specific feature will take the system out of the evaluated configuration Contact For additional information or clarification on any of the product information given here contact Xerox support Disclaimer The information provided in this Xerox Product Response is provided as is without warranty of any kind Xerox Corporation disclaims all warranties either ex...

Отзывы: