Page 1
Version 1.1 Sep 21, 2012 Secure Installation and Operation of Your ColorQube™ 8700/8900...
Page 2
. Upon completion of the evaluation, the Security Target will be available from the Common Criteria Certified Product website (http://www.commoncriteriaportal.org/products.html) list of evaluated products, from the Xerox security website (http://www.xerox.com/information-security/common-criteria-certified/enus.html ), or from your Xerox representative. 1. Please follow the guidelines below for secure installation, setup and operation of the evaluated...
Page 3
Follow the “Specifying Password Requirements” instructions on page 61 in the SAG to set the minimum and maximum user authentication password lengths. e). Xerox recommends the following passcodes be changed on a regular basis, chosen to be as random as possible and set to the indicated minimum lengths: Smart Card or CAC passcode –...
Page 4
• There are no active processes that access the hard disk drive(s). No user is logged into a session via network accounting, Xerox Standard Accounting, or the internal auditron, or • into a session accessing a directory on the hard disk drive(s) After a power on of the machine all subsystems must be properly synced and, if printing of Configuration Reports is •...
Page 5
• • If a self-signed certificate is to be used the generic Xerox root CA certificate should be downloaded from the device and installed in the certificate store of the user's browser. n). HTTPS is enabled in the evaluated configuration. To enable secure HTTPS follow the instructions in Steps 6 and 7 under ‘Configuring HTTP Settings in CentreWare Internet Services”...
Page 6
Passcodes for Scan-to-Mailbox mailboxes should be selected to be as random as possible and should be changed on a regular basis, consistent with applicable internal policies and procedures. Xerox recommends that the minimum length of a password assigned to a private Scan to Mailbox folder be 8 alphanumeric characters.
Page 7
RSS Service are provided in the Security@Xerox RSS Subscription Service guide posted on the Security@Xerox site at http://www.xerox.com/go/xrx/template/009.jsp?view=Feature&ed_name=RSS_Security_at_Xerox&Xcntry=USA&Xlang=en_US. A SPAR is the software problem report form used internally within Xerox to document customer-reported software problems found in products in the field.
Page 8
9. If IPv6 is disabled and then a software upgrade is performed by a Xerox Service Technician using an AltBoot, IPv6 will be disabled even though both the Local UI and Web UI show that IPv6 is enabled. IPv6 can be enabled again via the Web UI by first disabling and then re-enabling it.
Page 9
Binary Printing Support - Allows the device to accept printing jobs that are identified as binary files. Is accessible by typing http://{IP Address}/diagnostics/binaryAllow.php. • XSA Reports with User IDs - Allows the device to generate Xerox Standard Accounting reports with User IDs. Is accessible by typing http://{IP Address}/diagnostics/enableUserID.php. •...
Page 10
Job Queue Limit - Allows the System Administrator to set the maximum number of jobs that can be listed in the device’s • job queues. Is accessible by typing http://{IP Address}/diagnostics/jobLimit.php. Barcode Space Character Interpretation - Allows the System Administrator to choose how the device renders space •...
Page 11
Xerox Product Response including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Xerox Corporation has been advised of the possibility of such damages. Some states do no allow the exclusion or limitation of liability for consequential damages so the foregoing limitation may not apply.
Need help?
Do you have a question about the ColorQube 8700 and is the answer not in the manual?
Questions and answers