manualshive.com logo in svg
background image

Secure Installation and Operation of Your ColorQube™ 
9201/9202/9203 

 

Purpose and Audience 

This

 

document provides information on the secure installation and operation of a ColorQube™ 9201/9202/9203 Multifunction 

System. All customers, but particularly those concerned with secure installation and operation of these machines, should follow 
these guidelines. 

Overview 

This  document  lists  some  important  customer  information  and  guidelines  that  will  ensure  that  your  ColorQube 
9201/9202/9203 Multifunction System is operated and maintained in a secure manner.   

Background 

The ColorQube 9201/9202/9203 Multifunction System is currently undergoing Common Criteria evaluation. The information 
provided here is consistent with the security functional claims made in the Security Target. Upon completion of the evaluation, 
the 

Security 

Target 

will 

be 

available 

from 

the 

Common 

Criteria 

Certified 

Product 

website 

(http://www.commoncriteriaportal.org/products.html)  list  of  evaluated  products,  from  the  Xerox  security  website 
(http://www.xerox.com/information-security/common-criteria-certified/enus.html ), or from your Xerox representative. 

1.

 

Please  follow  the  guidelines  below  for  secure  installation,  setup  and  operation  of  the  evaluated  configuration

1

  for  a 

ColorQube 9201/9202/9203 Multifunction System: 

a).

 

The security functions in the evaluated configuration that should be set up by the System Administrator are: 

 

Immediate Image Overwrite 

 

On Demand Image Overwrite 

 

Disk Encryption 

 

IP Filtering  

 

Audit Log 

 

SSL (for protection of management data) 

 

IPSec 

 

SNMP v3 

 

Trusted Certificate Authorities 

 

Local, Remote or CAC/PIV Authentication 

 

Local Authorization and Personalization 

 

802.1x Device Authentication 

 

Session Inactivity Timeout 

System Administrator login is required when accessing the security features via the Web User Interface (Web UI) or when 
implementing the guidelines and recommendations specified in this document. To log in to the Web UI as an authenticated 
System  Administrator,  follow  the  instructions  under  “CentreWare  Internet  Services”  located  on  page  2-6  in  the  System 
Administration Guide (SAG)

2

.  

To log in to the Local User Interface (Local UI) as an authenticated System Administrator, follow the “Administrator Access” 
instructions located on page 2-4 in the SAG. 

Follow the instructions located in the SAG in Chapter 8, Security to set up these security functions except as noted in the 
items below. Note that whenever the SAG

 

requires that the System Administrator provide an IPv4 address, IPv6 address or 

port number the values should be those that pertain to the particular device being configured.

 

b).

 

The following services are also considered part of the evaluated configuration and should be enabled when needed by the 
System Administrator - Copy, Embedded Fax, Scan to E-mail, Workflow Scanning, Scan to Mailbox and Internet Fax. 

c).

 

Secure acceptance of a ColorQube 9201/9202/9203, once device delivery and installation is completed, should be done by:  

 

Printing out a Configuration Report by following the “How to Print a Configuration Report” instructions located on page 
3-2 of the SAG. 

 

Comparing  the  software/firmware  versions  listed  on  the  Configuration  Report  with  the  Evaluated  Software/Firmware 
versions listed in Table 2 of the Xerox ColorQube™ 9201/9202/9203 Multifunction Systems Security Target, Version 1.0 
and make sure that they are the same in all cases.  

d).

 

Change the Administrator password as soon as possible. Reset the Tools password periodically.   

                     

1

 The term “evaluated configuration” will be used throughout this document to refer to the configuration of the ColorQube™ 9201/9202/9203 

Multifunction System that is currently undergoing Common Criteria evaluation. 

2

ColorQube™ 9201/9202/9203 System Administration Guide, Document Version : 1.0 (05/09) 

Содержание ColorQube 9201

Страница 1: ...Version 1 3 March 21 2012 Secure Installation and Operation of Your ColorQube 9201 9202 9203...

Страница 2: ...ity features via the Web User Interface Web UI or when implementing the guidelines and recommendations specified in this document To log in to the Web UI as an authenticated System Administrator follo...

Страница 3: ...mage Overwrite security features which comes installed on the device must be properly configured and enabled Please follow the Immediate Image Overwrite instructions starting on page 8 17 in the SAG a...

Страница 4: ...d on the Local UI may not reflect Daylight Savings Time If an On Demand Image Overwrite is successfully completed the completion finish time shown on the printed On Demand Overwrite Confirmation Repor...

Страница 5: ...Reprint Saved Job folders or deletion of a Reprint Saved Job folder itself is recorded in the Audit Log Deletion of a print or scan job or deletion of a scan to mailbox job from its scan to mailbox fo...

Страница 6: ...rox recommends that if SNMP is enabled SNMPv3 should be used SNMPv3 can be set up by following the instructions statrting on page 5 10 of the SAG SNMPv3 cannot be enabled until SSL Secure Sockets Laye...

Страница 7: ...e evaluation assumes that after normal business hours Fax Forwarding on Receive is enabled and secure receive is disabled The Mailbox and Polling Policy should be set to delete received faxes when the...

Страница 8: ...a secondary IPv4 address may be utilized The System Administrator selects whether the primary IPv4 address will be obtained statically or dynamically via DHCP from the IP Internet Protocol page on the...

Страница 9: ...oad either a basic or an enhanced level of network log information and a separate screen will provide information on the completion status of the download Downloaded network logs are always encrypted...

Страница 10: ...ewed will be displayed There is also a TOC contents list of all Web UI help pages to the left of each help page scrolling through the content list and selecting the desired page will also cause the ap...

Страница 11: ...yping http IP Address diagnostics postScriptTokens php Web Services IP Lockout Reset Allows the System Administrator to clear the Web Services IP Address Lockout cache Is accessible by typing http IP...

Страница 12: ...20 The following pages are available from the Web User Interface with no user login and authentication required Site Map Provides the user with hyperlink pointers to each Web User Interface screen or...

Отзывы: