background image

Secure Installation and Operation of Your WorkCentre™ 
7755/7765/7775 

 

Purpose and Audience 

This

 

document provides information on the secure installation and operation of a WorkCentre™ 7755/7765/7775 

Multifunction System. All customers, but particularly those concerned with secure installation and operation of these machines, 
should follow these guidelines. 

Overview 

This document lists some important customer information and guidelines that will ensure that your WorkCentre 
7755/7765/7775 Multifunction System is operated and maintained in a secure manner.   

Background 

The WorkCentre 7755/7765/7775 Multifunction System is currently undergoing Common Criteria evaluation. The information 
provided here is consistent with the security functional claims made in the Security Target. Upon completion of the evaluation, 
the Security Target will be available from the Common Criteria Certified Product website 
(http://www.commoncriteriaportal.org/products.html) list of evaluated products, from the Xerox security website 
(http://www.xerox.com/information-security/common-criteria-certified/enus.html ), or from your Xerox representative. 

1.

 

Please follow the guidelines below for secure installation, setup and operation of the evaluated configuration

1

 for a 

WorkCentre 7755/7765/7775 Multifunction System: 

a).

 

The security functions in the evaluated configuration that should be set up by the System Administrator are: 

 

Immediate Image Overwrite 

 

On Demand Image Overwrite 

 

Disk Encryption 

 

IP Filtering  

 

Audit Log 

 

SSL (for protection of management data) 

 

IPSec 

 

SNMP v3 

 

Trusted Certificate Authorities 

 

Local, Remote or CAC/PIV Authentication 

 

Local Authorization and Personalization 

 

802.1x Device Authentication 

 

Session Inactivity Timeout 

System Administrator login is required when accessing the security features via the Web User Interface (Web UI) or when 
implementing the guidelines and recommendations specified in this document. To log in to the Web UI as an authenticated 
System Administrator, follow the instructions under “Accessing CentreWare IS” located on page 17 in the System 
Administration Guide (SAG)

2

.  

To log in to the Local User Interface (Local UI) as an authenticated System Administrator, follow the “System Administrator 
Access at the Control Panel” instructions located on page 15 in the SAG. 

Follow the instructions located in the SAG in Chapter 4, Security to set up these security functions except as noted in the 
items below. Note that whenever the SAG

 

requires that the System Administrator provide an IPv4 address, IPv6 address or 

port number the values should be those that pertain to the particular device being configured.

 

b).

 

The following services are also considered part of the evaluated configuration and should be enabled when needed by the 
System Administrator - Copy, Embedded Fax, Scan to E-mail, Workflow Scanning, Scan to Mailbox and Internet Fax. 

The following services are to be disabled as part of the evaluated configuration - Network Accounting, Copy/Print Store and 
Reprint (may also called “Save for Reprint”/“Reprint Saved Jobs”) and the Extensible Interface Platform (may also called 
“Extensible Services” or “Custom Services”). 

                     

TP

1

 The term “evaluated configuration” will be used throughout this document to refer to the configuration of the WorkCentre 7755/7765/7775 that 

is currently undergoing Common Criteria evaluation. 

2

Xerox

®

®

 WorkCentre  7755/7765/7775 System Administrator Guide, Version 1.0, September 2009 

Содержание WORKCENTRE 7755

Страница 1: ...Version 1 0 May 2 2011 Secure Installation and Operation of Your WorkCentre 7755 7765 7775...

Страница 2: ...thentication Local Authorization and Personalization 802 1x Device Authentication Session Inactivity Timeout System Administrator login is required when accessing the security features via the Web Use...

Страница 3: ...will overwrite all image data including data stored by the Reprint Save Job feature and data stored in Embedded Fax dial directories and mailboxes Please follow the Overwriting Image Data instruction...

Страница 4: ...software reset be initiated by the System Administrator from either the Local UI or the Web UI and be allowed to complete otherwise the Local UI may become unavailable If the Local UI does become unav...

Страница 5: ...the Completed Job Log for this job will read Job could not be sent as a connection to the server could not be established l To be consistent with the evaluated configuration protocol choices for remot...

Страница 6: ...r The IPSec New Actions keying method defaults to Internet Key Exchange IKE If Manual Keying is selected the IPSec security option defaults to ESP the Security Parameter Index IN defaults to 256 the S...

Страница 7: ...ed Local UI inactivity timer setting After saving the changes the Timers screen will be redisplayed w The Saved Jobs for Reprint feature should be disabled to be consistent with the evaluated configur...

Страница 8: ...AG Make sure that the Enable button is selected Local Polling should be disabled in the evaluated configuration To disable Local Polling from the Local UI follow the instructions for Steps 1 2 and 5 u...

Страница 9: ...e to the SA10 Xerox recommends that the Self Assigned Address option from the Web UI IP Internet Protocol page be disabled unless either APIPA is used or Apple Rendezvous Bonjour support is required 1...

Страница 10: ...r Interface These windows provide standard machine services or job management capability Embedded Fax Batch Send Confirmation Allows a user to either send an Embedded Fax job to a remote destination i...

Страница 11: ...erties tab content menu Sleep Mode Settings Allows the System Administrator to set the Network Controller sleep mode settings Is accessible by selecting the Properties tab and then selecting General S...

Страница 12: ...Is accessible by typing http IP Address diagnostics barcodeSpaceToggle php DHCP v6 Allows the System Administrator to choose which compliance option will be followed when DHCP v6 is used Is accessibl...

Страница 13: ...y Web User Interface page Exit from Sleep Mode Automatically informs the user when the Network Controller is in Sleep Mode at the time the user attempts to make a change to current settings on a Web U...

Отзывы: