Konica Minolta bizhub C35 User Manual

Konica Minolta bizhub C35 User Manual

Security operations user guide
Hide thumbs Also See for bizhub C35:
Table of Contents

Advertisement

User's Guide [Security Operations]
2010. 10
Ver. 1.00

Advertisement

Table of Contents
loading

Summary of Contents for Konica Minolta bizhub C35

  • Page 1 User’s Guide [Security Operations] 2010. 10 Ver. 1.00...
  • Page 2: Table Of Contents

    Setting the Overwrite All Data......................2-22 2.9.2 Setting the SSD Low-level Format....................2-25 2.9.3 Setting the Restore All ........................2-26 2.10 SSL Setting Function ........................2-27 2.10.1 Device Certificate Setting ........................ 2-27 2.10.2 SSL Setting ............................2-29 2.10.3 Removing a Certificate........................2-30 bizhub C35 Contents-1...
  • Page 3 Accessing from PageScope Data Administrator ................4-2 4.1.2 Setting the user authentication method..................... 4-4 4.1.3 Changing the authentication mode....................4-6 4.1.4 Making the user settings........................4-9 4.1.5 Setting the IC card information......................4-10 TWAIN driver..........................4-12 Accessing from the TWAIN driver....................4-12 bizhub C35 Contents-2...
  • Page 4: Security

    Security...
  • Page 5: Introduction

    This User's Guide contains the operating procedures and precautions to be used when using the security functions offered by the bizhub C35 machine. To ensure the best possible performance and effective use of the machine, read this manual thoroughly before using the security functions. The Administrator of the ma- chine should keep this manual for ready reference.
  • Page 6: Installation Checklist

    Administrator of the machine. The copy should be kept at the corre- sponding Service Representative for filing. Product Name Company Name User Division Name Person in charge Customer (Administrator of Machine) Service Representative bizhub C35...
  • Page 7: Security Functions

    The machine is restarted <User Authentication Mode> User Authentication mode is successful. The machine is restarted <Secured Job> Authentication of Secured Job is successful. The machine is restarted <SNMP Password (auth-password, priv-password)> Authentication of SNMP is successful. The machine is restarted bizhub C35...
  • Page 8: Data To Be Protected

    Secured Job files and ID & Print files, take necessary anti-sniffing measures, including installation of cryptographic communications equipment or a sniffing detector. If the HDD is stolen, data is protected by the HDD encryption function, however, the HDD encryption function is not governed by authentication by the ISO15408. bizhub C35...
  • Page 9: Precautions For Operation Control

    The administrator of the machine and the server administrator are required to apply patches to, or perform account control for, this machine and the user information control system connected to the office LAN in which the machine is installed to ensure operation control that achieves appropriate access control. bizhub C35...
  • Page 10: Security Function Operation Setting Operating Requirements

    IC card. The person responsible within the organization that uses the machine should prohibit the user from transferring or lending the IC card to any third person and make sure that the user reports any lost IC card. bizhub C35...
  • Page 11: Miscellaneous

    Internet Explorer or other type of web browser, "SSL v3" or "TLS v1" should be used, not "SSL v2," for the SSL setting. PageScope Direct Print cannot be used if the Enhanced Security Mode is set to [ON]. bizhub C35...
  • Page 12: Encrypting Communications

    Click "Certificate Error" to display the certificate. Then, click "Install Certificate" to install the certificate. Display the physical stores. Then, deploy the certificate, which has earlier been exported, in "Local Computer" of "Trusted Root Certification Authorities" to thereby import the certificate. bizhub C35...
  • Page 13: Items Of Data Cleared By Data Erase Function

    Machine setting data Deletes the machine setting data Restore All Trusted channel setting data Deletes the trusted channel setting data Restore All External server identification Deletes the external server identification Overwrite All Data setting data setting data bizhub C35 1-10...
  • Page 14: Hdd Format

    For details of items of data to be cleared by [Restore All], see page 1-10. The execution of [Restore All] will turn [OFF] the Enhanced Security Mode. So, it must be turned [ON] again. For details of settings, see page 2-5. bizhub C35 1-11...
  • Page 15: Administrator Operations

    Administrator Operations...
  • Page 16: Accessing The Admin Settings

    Do not leave the machine with the setting screen of Admin Settings left shown on the display. If it is absolutely necessary to leave the machine, be sure first to log off from the Admin Settings. Press the [Utility/Counter] key. Touch [↓]. Touch [Admin Settings]. bizhub C35...
  • Page 17 When the power switch is turned off, then on again, wait at least 10 seconds to turn it on after turn- ing it off. This interval is necessary to ensure that the machine functions properly. Press the [Reset] key to log off from the Admin Settings. bizhub C35...
  • Page 18 When the power switch is turned off, then on again, wait at least 10 seconds to turn it on after turn- ing it off. This interval is necessary to ensure that the machine functions properly. Click [Log out]. This allows you to log off from the Admin Mode. bizhub C35...
  • Page 19: Enhancing The Security Function

    For details of the Password Rules, see page 1-8. Turning ON the Enhanced Security Mode does not enable the ID & Print function. Enable the function man- ually to protect image files. For details of the ID & Print function, see page 2-12. bizhub C35...
  • Page 20 The Enhanced Security Mode is set to [OFF], if the Administrator of the machine executes any of the following functions. Set the Enhanced Security Mode to [ON] again. [All] is executed of [HDD Format]. [Overwrite All Data] is executed. [SSD Low-level Format] is executed. [Restore All] is executed. [Restore Network] is executed. [Restore System] is executed. bizhub C35...
  • Page 21: Setting The Enhanced Security Mode

    Call the Admin Settings on the display from the control panel. Touch [↓]. Touch [Security Settings]. Touch [Enhanced Security Mode]. Select [ON] to enable the Enhanced Security Mode and touch [OK]. Touch [OK], then the machine restarts automatically. bizhub C35...
  • Page 22 For details of the necessary settings, see page 2-5. % If the Enhanced Security Mode is properly set to [ON], a key icon appears at the portion enclosed by a red frame of the screen, indicating that the machine is in the Enhanced Security Mode. bizhub C35...
  • Page 23: Setting The Authentication Method

    Do not leave the machine with the Admin Mode setting screen left shown on the display. If it is abso- lutely necessary to leave the machine, be sure first to log off from the Admin Mode. Start PageScope Web Connection and access the Admin Mode. Click the [Security] tab. bizhub C35...
  • Page 24 % If the IC card function is to be used, it is necessary to register user IC card information in the ma- chine. For details, see page 2-18. Click [Apply]. bizhub C35 2-10...
  • Page 25 Setting the Authentication Method If [External Server] is selected, click [External Server List] from [Authentication] menu. Click [Edit]. Select [Active Directory] and click [Next]. Make the necessary settings. Click [Apply]. bizhub C35 2-11...
  • Page 26: Id & Print Setting Function

    % If [Enable] is set, the document is stored as ID & Print file even if [Print] is selected on the printer driver side. % Even if [Disable] is set, the document is stored as ID & Print file if [ID & Print] is selected on the printer driver side. Click [Apply]. bizhub C35 2-12...
  • Page 27: Auto Reset Function

    Do not leave the machine with the setting screen of Admin Settings left shown on the display. If it is absolutely necessary to leave the machine, be sure first to log off from the Admin Settings. Call the Admin Settings on the display from the control panel. Touch [Machine Settings]. Touch [↓]. Touch [Auto Reset Settings]. bizhub C35 2-13...
  • Page 28 Select [ON] and touch [OK]. % If no operations are performed for 1 min. even with Auto Reset set to [OFF], the function is activated to cause the user to log off from the mode automatically. Touch [Auto Reset]. bizhub C35 2-14...
  • Page 29 Enter the period of time (1 min. to 9 min.) after which Auto Reset is activated using [-]/[+] key. % The time for Auto Reset can be set to a value between 1 min. and 9 min., variable in 1-min. incre- ments. Touch [OK]. bizhub C35 2-15...
  • Page 30: User Setting Function

    If a user has been registered, promptly notify the user in question of the registration and have him or her change the password. Start PageScope Web Connection and access the Admin Mode. Click the [Security] tab and [User List]. bizhub C35 2-16...
  • Page 31 % To delete a previously registered user, click [Delete] in step 3. Check the contents of registration on the confirmation screen and click [OK] if the user is to be deleted. If a user is deleted, the image files owned by that specific user are deleted. bizhub C35 2-17...
  • Page 32: Ic Card Information Setting Function

    Do not leave the machine with the setting screen of Admin Settings left shown on the display. If it is absolutely necessary to leave the machine, be sure first to log off from the Admin Settings. Call the Admin Settings on the display from the control panel. Touch [Authentication Setting]. Touch [Card Authentication]. bizhub C35 2-18...
  • Page 33 % To delete a previously registered IC card information, touch [Delete]. Select [Yes] and touch [OK] on the confirmation screen that will appear. Place the IC card on the IC card reader and touch [OK]. Touch [Close]. bizhub C35 2-19...
  • Page 34: Changing The Administrator Password

    Enter the new 8-digit Administrator Password from the keyboard or keypad. % Press the [C] key to clear all characters. % Touch [Delete] to delete the last character entered. % Touch [↑] to show the upper case screen. bizhub C35 2-20...
  • Page 35 Administrator Password. For details of the Password Rules, see page 1-8. % If the entered Administrator Password does not match, a message that tells that the Administrator Password does not match appears. Enter the correct Administrator Password. bizhub C35 2-21...
  • Page 36: Erasing Data When The Machine Is To Be Discarded Or Use Of A Leased Machine Is Terminated

    Do not leave the machine with the setting screen of Admin Settings left shown on the display. If it is absolutely necessary to leave the machine, be sure first to log off from the Admin Settings. For details of items that are cleared, see page 1-10. bizhub C35 2-22...
  • Page 37 Erasing data when the machine is to be discarded or use of a leased machine is terminated Call the Security Settings screen on the display from the control panel. Touch [HDD Settings]. Touch [Overwrite All Data]. Touch [Mode]. Select the desired mode. bizhub C35 2-23...
  • Page 38 % Do not turn off the power switch of the machine during execution of Overwrite All Data. If the power switch is inadvertently turned off during the execution of Overwrite All Data and the machine, as a result, fails to recognize the HDD or develops other fault, contact your Service Representative. bizhub C35 2-24...
  • Page 39: Setting The Ssd Low-Level Format

    % Do not turn off the power switch of the machine during execution of SSD Low-level Format. If the power switch is inadvertently turned off during the execution of SSD Low-level Format and the ma- chine, as a result, develops a fault, contact your Service Representative. bizhub C35 2-25...
  • Page 40: Setting The Restore All

    % Do not turn off the power switch of the machine during execution of Restore All. If the power switch is inadvertently turned off during the execution of Restore All and the machine, as a result, develops a fault, contact your Service Representative. bizhub C35 2-26...
  • Page 41: Ssl Setting Function

    Enhanced Security Mode. The Administrator of the machine should register a new certificate before the validity of the old certificate expires. Start PageScope Web Connection and access the Admin Mode. Click the [Security] tab and [PKI Settings]. Click [New Registration]. Select [Create a Self-signed Certificate] and click [Next]. bizhub C35 2-27...
  • Page 42 2.10 SSL Setting Function Make the necessary settings. % Settings are all cleared if [Apply] is clicked with data entered for each item not meeting the require- ments. Click [Apply]. The certificate can now be registered. bizhub C35 2-28...
  • Page 43: Ssl Setting

    Click the [Security] tab and [SSL/TLS Settings] from [PKI Settings] menu. Set "Encryption Strength" and click [Apply]. % For encryption strength, select the strong "AES-256, 3DES." % In the Enhanced Security Mode, the setting cannot be changed to one containing strength lower than AES/3DES. bizhub C35 2-29...
  • Page 44: Removing A Certificate

    Admin Mode. In the Enhanced Security Mode, no certificates can be removed. Start PageScope Web Connection and access the Admin Mode. Click the [Security] tab and [PKI Settings]. Click [Edit]. Select [Delete a Certificate] and click [Next]. bizhub C35 2-30...
  • Page 45 2.10 SSL Setting Function Click [OK]. bizhub C35 2-31...
  • Page 46: Snmp Setting Function

    % If the entered auth-password or priv-password does not meet the requirements of the Password Rules, a message that tells that the entered auth-password or priv-password cannot be used ap- pears. Enter the correct auth-password or priv-password. For details of the Password Rules, see page 1-8. bizhub C35 2-32...
  • Page 47: Snmp Access Authentication Function

    1.3.6.1.4.1.18334.1.1.2.1.5.7.1.1.1.3.1 BOOT Protocol use setting 1.3.6.1.4.1.18334.1.1.2.1.5.7.1.1.1.6.1 BOOT Protocol Type 1.3.6.1.4.1.18334.1.1.2.1.5.7.1.1.1.7.1 DNS server address setting 1.3.6.1.4.1.18334.1.1.2.1.5.7.1.2.1.3.1.1 SMTP server address setting 1.3.6.1.4.1.18334.1.1.2.1.5.7.13.1.1.3.1 NetWare setting Print Server Name 1.3.6.1.4.1.18334.1.1.2.1.5.8.3.1.3.1.1 Printer Name 1.3.6.1.4.1.18334.1.1.2.1.5.8.5.1.3.1.1 AppleTalk Printer Name Setting 1.3.6.1.4.1.18334.1.1.2.1.5.9.2.1.3.1.1 NetBIOS setting 1.3.6.1.4.1.18334.1.1.2.1.5.10.1.1.4.1 bizhub C35 2-33...
  • Page 48: Accessing The Scan To Hdd File

    A list appears showing image files saved in the HDD. To back up (download) a file, click [Copy] of the file in question. % If [Delete] is selected, a confirmation message appears. Click [OK] to delete the specified file. bizhub C35 2-34...
  • Page 49 2.12 Accessing the Scan to HDD file Select [Save] to back up (download) the image file in the PC. % The backed up (downloaded) file is not deleted from the machine. bizhub C35 2-35...
  • Page 50: Tcp/Ip Setting Function

    Admin Mode. Start PageScope Web Connection and access the Admin Mode. Click the [Network] tab and [DNS Settings] from [TCP/IP Settings] menu. Enter the address in the DNS Server box. Make the necessary settings. Click [Apply]. bizhub C35 2-36...
  • Page 51: Netware Setting Function

    Admin Mode. Start PageScope Web Connection and access the Admin Mode. Click the [Network] tab and [Netware Settings]. Make the necessary settings. Click [Apply]. bizhub C35 2-37...
  • Page 52: Smb Setting Function

    Admin Mode. Start PageScope Web Connection and access the Admin Mode. Click the [Network] tab and [SMB Settings]. Make the necessary settings. Click [Apply]. bizhub C35 2-38...
  • Page 53: Appletalk Setting Function

    Admin Mode. Start PageScope Web Connection and access the Admin Mode. Click the [Network] tab and [AppleTalk Settings]. Make the necessary settings. Click [Apply]. bizhub C35 2-39...
  • Page 54: E-Mail Setting Function

    Admin Mode. Start PageScope Web Connection and access the Admin Mode. Click the [Network] tab and [E-mail TX (SMTP)] from [E-mail Settings] menu. Make the necessary settings. Click [Apply]. bizhub C35 2-40...
  • Page 55: User Operations

    User Operations...
  • Page 56: User Authentication Function

    Authentication using the IC card is enabled only when [Device] is selected. Authentication using the IC card is disabled, if it is performed from a device other than this machine, such as printing from PageScope Web Connection or printer driver. bizhub C35...
  • Page 57: Performing User Authentication (Authentication Through Entry Of The User Name And User Password)

    In this case, log onto the machine through the ordinary procedure, select the desired file from [ID & Print] and have it printed. For details of how to access the ID & Print file, see page 3-14. Touch [Direct Input]. bizhub C35...
  • Page 58 % Press the [C] key to clear all characters. % Touch [Delete] to delete the last character entered. % Touch [↑] to show the upper case screen. % Touch [!#?/] to show the symbol screen. Touch [OK]. Touch [OK]. Touch [Password]. bizhub C35...
  • Page 59 Prints only the ID & Print file of the corresponding user. The user op- eration mode screen is not called to the screen. [Access Basic Screen] Only the ordinary login procedure is applicable and no ID & Print files are printed. bizhub C35...
  • Page 60 % If the ID & Print file is not saved even with the ID & Print function set, you log on to the machine through the ordinary procedure regardless of whether [Begin Printing] or [Access Basic Screen] is selected. Press the [Access] key to log off. bizhub C35...
  • Page 61: Performing User Authentication (Identification Through The Ic Card)

    % If the ID & Print file is not saved even with the ID & Print function set, you log on to the machine through the ordinary procedure regardless of whether [Begin Printing] or [Access Basic Screen] is selected. Press the [Access] key to log off. bizhub C35...
  • Page 62: Performing User Authentication (Authentication Through The Ic Card + User Password)

    In this case, log onto the machine through the ordinary procedure, select the desired file from [ID & Print] and have it printed. For details of how to access the ID & Print file, see page 3-14. Place the IC card on the IC card reader. Touch [Password]. bizhub C35...
  • Page 63 Prints only the ID & Print file of the corresponding user. The user op- eration mode screen is not called to the screen. [Access Basic Screen] Only the ordinary login procedure is applicable and no ID & Print files are printed. bizhub C35...
  • Page 64 % If the ID & Print file is not saved even with the ID & Print function set, you log on to the machine through the ordinary procedure regardless of whether [Begin Printing] or [Access Basic Screen] is selected. Press the [Access] key to log off. bizhub C35 3-10...
  • Page 65 When the power switch is turned off, then on again, wait at least 10 seconds to turn it on after turn- ing it off. This interval is necessary to ensure that the machine functions properly. Click [Log out] to log off from the user operation mode. bizhub C35 3-11...
  • Page 66: Id & Print Function

    Connection is also saved as an ID & Print file. 3.2.1 Registering ID & Print files Click [Properties] in the Print dialog box to show the Printing Preference window. Click the [Basic] tab. Select [ID & Print] in [Job Retention]. Click [Authentication/Account Track]. bizhub C35 3-12...
  • Page 67 When the power switch is turned off, then on again, wait at least 10 seconds to turn it on after turn- ing it off. This interval is necessary to ensure that the machine functions properly. Print the document. bizhub C35 3-13...
  • Page 68: Accessing The Id & Print File

    Do not leave the machine while you are in the user operation mode. If it is absolutely necessary to leave the machine, be sure first to log off from the user operation mode. Log on to the user operation mode through User Authentication from the control panel. Touch [USB/HDD]. Touch [ID & Print]. Touch [Login User]. bizhub C35 3-14...
  • Page 69 ID & Print Function Select the desired ID & Print file and touch [Print]. % The ID & Print file is automatically deleted as soon as the printing is normally terminated. bizhub C35 3-15...
  • Page 70: Change Password Function

    Log on to the user operation mode through User Authentication from the PageScope Web Connection. Click the [System] tab and [Authentication]. Enter the currently registered User Password and a new User Password. Then, to make sure that you have entered the correct new password, enter the new User Password once again. bizhub C35 3-16...
  • Page 71 User Password. For details of the Password Rules, see page 1-8. % If the entered User Password in the "New Password" box and "Retype New Password" box does not match, a message that tells that the User Password does not match appears. Enter the correct User Password. bizhub C35 3-17...
  • Page 72: Secured Job Function

    Select [Secured Job (Encryption)] in [Job Retention]. % If the Enhanced Security mode is turned ON, select "Secured Job (Encryption)". Selection of "Se- cured Job" does not result in the print data being saved in the machine. Click [User Settings]. bizhub C35 3-18...
  • Page 73 When the power switch is turned off, then on again, wait at least 10 seconds to turn it on after turn- ing it off. This interval is necessary to ensure that the machine functions properly. Print the document. bizhub C35 3-19...
  • Page 74: Accessing The Secured Job File

    Log on to the user operation mode through User Authentication from the control panel. Touch [USB/HDD]. Touch [Proof Print]. Select the user name and touch [OK]. % The name of the user of the PC from which the Secured Job file has been sent appears. bizhub C35 3-20...
  • Page 75 % Press the [C] key to clear all characters. % Touch [Delete] to delete the last character entered. % Touch [↑] to show the upper case screen. % Touch [!#?/] to show the symbol screen. Touch [OK]. bizhub C35 3-21...
  • Page 76 Check the details of the file and touch [OK]. % Touch [Cancel] to go back to the screen of step 5. % The Secured Job file is automatically deleted as soon as the printing is normally terminated. bizhub C35 3-22...
  • Page 77: Scan To Hdd Function

    Log on to the user operation mode through User Authentication from the control panel. Touch [Scan to Folder]. Touch [Direct Input] tab and touch [HDD]. bizhub C35 3-23...
  • Page 78 Touch [Save Document]. Select the destination to which the file is to be saved and touch [OK] or [Start]. % The image file stored in [Personal] is protected. Select [Personal] whenever saving a highly confi- dential file. bizhub C35 3-24...
  • Page 79: Accessing The Image File

    Log on to the user operation mode through User Authentication from the control panel. Touch [Scan to Folder]. Touch [Direct Input] tab and touch [HDD]. Touch [File Document]. bizhub C35 3-25...
  • Page 80 Scan to HDD Function A list of documents saved will appear. % To delete image file, select the specific document and press [Delete]. bizhub C35 3-26...
  • Page 81 Click [Copy] of the desired file. % If [Delete] is selected, a confirmation message appears. Click [OK] to delete the specified file. Select [Open] or [Save] to execute the desired function. % The downloaded file is not deleted from the machine. bizhub C35 3-27...
  • Page 82: Application Software

    Application Software...
  • Page 83: Pagescope Data Administrator

    Do not leave the site while you are gaining access to the machine through PageScope Data Adminis- trator. If it is absolutely necessary to leave the site, be sure first to log off from the PageScope Data Administrator. Start the PageScope Data Administrator. Select this machine from Device List and click [Authentication Settings/Address Settings]. bizhub C35...
  • Page 84 When the power switch is turned off, then on again, wait at least 10 seconds to turn it on after turn- ing it off. This interval is necessary to ensure that the machine functions properly. Check the data displayed on the SSL certificate check screen and click [Yes]. bizhub C35...
  • Page 85: Setting The User Authentication Method

    If it is absolutely necessary to leave the site, be sure first to log off from the PageScope Data Administrator. Access the machine through [Authentication Settings/Address Settings] mode of PageScope Data Ad- ministrator. Click [Authentication settings]. Click [User authentication]. bizhub C35...
  • Page 86 % If there is a job being executed or a reserved job (timer TX, fax redial waiting, etc.) in the machine, the machine displays a message that tells that the write operation has not been successful because of a device lock error. Click [OK] and wait for some while before attempting to execute [Export to the device] again. bizhub C35...
  • Page 87: Changing The Authentication Mode

    If it is absolutely necessary to leave the site, be sure first to log off from the PageScope Data Administrator. Access the machine through [Authentication Settings/Address Settings] mode of PageScope Data Ad- ministrator. Click [Authentication settings]. From [Edit] on the tool bar, select [Authentication] and click [Change authentication mode]. Click [Next]. bizhub C35...
  • Page 88 % If there is a job being executed or a reserved job (timer TX, fax redial waiting, etc.) in the machine, the machine displays a message that tells that the write operation has not been successful because of a device lock error. Click [OK] and wait for some while before attempting to execute [Export to the device] again. bizhub C35...
  • Page 89 % If [User Authentication and Account Track] is selected in step 5, [Synchronize] is set for "Synchro- nize user authentication and account track." If you want user authentication not synchronized with account track, click to deselect [Synchronize user authentication and account track] and execute [Export to the device] once again. bizhub C35...
  • Page 90: Making The User Settings

    Click [OK] and wait for some while before attempting to execute [Export to the device] again. % If a previously registered user is deleted in step 4, the image files owned by that specific user are deleted. bizhub C35...
  • Page 91: Setting The Ic Card Information

    Access the machine through [Authentication Settings/Address Settings] mode of PageScope Data Ad- ministrator. Click the Authentication settings expand button. Select [User authentication settings] and click [Add]. Click [OK]. Enter the user name and password, and select the [IC card authentication] tab. bizhub C35 4-10...
  • Page 92 Click [OK]. % If the user IC card information is registered through [Input the card ID directly], the user must be associated with the card through the Admin Settings of the machine. For more details, see page 2-18. bizhub C35 4-11...
  • Page 93: Twain Driver

    TWAIN driver. Start the image processing application. From the [File] menu, click [Read], and then select [KONICA MINOLTA bizhub C35 TWAIN Ver.1]. Select the "Login as the Registered user" radio button and enter the User Name and the 8-to-64-digit User Password.
  • Page 94 http://konicaminolta.com Copyright A121-9301B-00 2010...

Table of Contents