Page 3 - Contents
Contents Overview and first steps...............................................................................5 Overview...................................................................................................................................................5 Using this guide................
Page 5 - Overview and first steps; Overview; Using this guide; Supported devices
Overview and first steps Overview This guide describes how to configure a supported Lexmark TM multifunction printer (MFP) to reach Common Criteria Evaluation Assurance Level 2 (EAL 2). It is critical that you carefully follow the instructions in this guide, as failure to do so may result in a devic...
Page 6 - Operating environment; Verifying physical interfaces and installed firmware
Operating environment The instructions provided in this guide are based on the following assumptions and objectives: • The MFP is installed in a cooperative, nonhostile environment that is physically secure or monitored and providesprotection from unauthorized access to MFP external interfaces. • Th...
Page 8 - Disabling the USB buffer
3 Verify that the MFP is in Configuration mode by locating the Exit Config Menu icon in the lower right corner of the touch screen. 4 Scroll through the configuration menus to locate the Disk Encryption menu selection. 5 Touch Disk Encryption > Enable . Warning: Enabling disk encryption will eras...
Page 9 - Installing the minimum configuration; Configuring the device; Configuration checklist
Installing the minimum configuration You can achieve an evaluated configuration on a non-networked (standalone) device in just a few steps. For thisconfiguration, all tasks are performed at the device, using the touch screen. Configuring the device Configuration checklist This checklist outlines the...
Page 10 - Creating user accounts
3 Retype the password, and then touch Done to save the new password and return to the Edit Backup Password screen. 4 Set Use Backup Password to On . 5 Touch Submit . Creating user accounts Creating internal (device) accounts for use with the evaluated configuration involves not only assigning a user...
Page 11 - Creating security templates
Group name Type of user group would be selected for Authenticated_Users • Administrators permitted to access all device functions • Administrators permitted to use device functions and access the Reportsmenu • Administrators permitted to use device functions and access theSecurity menu • Non ‑ admin...
Page 12 - Controlling access to device functions
3 Type a unique name to identify the template. Use a descriptive name, such as ”Administrator_Only” or“Authenticated_Users,” and then touch Done . 4 On the Authentication Setup screen, select the internal accounts building block, and then touch Done . 5 On the Authorization Setup screen, select the ...
Page 14 - Disabling home screen icons
Access control Level of protection Held Jobs Access Disabled Use Profiles Authenticated users only Change Language from Home Screen Authenticated users only Cancel Jobs at the Device Administrator access only PictBridge Printing Not applicable—USB port disabled Solution 1 Authenticated users only No...
Page 15 - Administering the device; Using the Embedded Web Server; Accessing the EWS; Printing a network setup page; Settings for network-connected devices; Creating and modifying digital certificates
Administering the device This chapter describes how to configure additional settings and functions that may be available on your device. Using the Embedded Web Server Many settings can be configured using either the Embedded Web Server (EWS) or the touch screen. Accessing the EWS 1 Type the device I...
Page 17 - Setting up IPSec
The contents of the file should be in the following format: -----BEGIN CERTIFICATE----- MIIE1jCCA76gAwIBAgIQY6sV0KL3tIhBtlr4gHG85zANBgkqhkiG9w0BAQUFADBs … l3DTbPe0mnIbTq0iWqKEaVne1vvaDt52iSpEQyevwgUcHD16rFy+sOnCaQ== -----END CERTIFICATE----- • Download Signing Request —Download or save the signing r...
Page 18 - Disabling the AppleTalk protocol; Shutting down port access
Disabling the AppleTalk protocol IP is the only network protocol permitted under this evaluation. The AppleTalk protocol must be disabled. Using the EWS Note: For information about accessing the EWS, see “Using the Embedded Web Server” on page 15. 1 From the Embedded Web Server, click Settings > ...
Page 19 - Other settings and functions; Kerberos
3 Click Submit . Other settings and functions Network Time Protocol Use Network Time Protocol (NTP) to automatically sync MFP date and time settings with a trusted clock so that Kerberosrequests and audit log events will be accurately time ‑ stamped. Note: If your network uses DHCP, then verify that...
Page 20 - Security audit logging
3 Under Simple Kerberos Setup, for KDC Address, type the IP address or host name of the KDC (Key DistributionCenter) IP. 4 For KDC Port, type the number of the port used by the Kerberos server. 5 For Realm, type the realm used by the Kerberos server. Note: The Realm entry must be typed in all upperc...
Page 24 - Fax
6 If you want to receive responses to messages sent from the MFP (in case of failed or bounced messages), thenprovide a Reply Address. 7 Set Use SSL to Disabled , Negotiate or Required to specify whether e-mail will be sent using an encrypted link. 8 If the SMTP server requires user credentials, the...
Page 25 - Configuring security reset jumper behavior; User access; Creating user accounts through the EWS
Setting up a fax storage location (optional) 1 Turn off the MFP using the power switch. 2 Simultaneously press and hold the 2 and 6 keys on the numeric keypad while turning the MFP back on. It takes approximately a minute to boot into the Configuration menu. Once the MFP is ready, the touch screen d...
Page 27 - Configuring LDAP+GSSAPI
5 Click Settings > Security > Security Setup > Internal Accounts . 6 Click Add an Internal Account , and then provide the information needed for each account: • Account Name —Type the user's account name (example: “Jack Smith”). • User ID —Type an ID for the account (example: “jsmith”). • P...
Page 30 - Configuring Common Access Card access
Configuring Common Access Card access A set of Public Key Infrastructure (PKI) embedded applications comes installed on the MFP. These applications provide for additional functionality, including the use of Smart Cards such as the Department of Defense Common Access Card(CAC). For more information o...
Page 32 - Creating security templates using the EWS
Creating security templates using the EWS A security template is assigned to each device function to control which users are permitted to access that function.At a minimum, you must create two security templates: one for "Administrator_Only" and one for"Authenticated_Users." If there...
Page 33 - Configuring PKI Held Jobs
Notes: • Clicking Delete List from the Manage Security Templates screen will delete all security templates on the MFP, regardless of which one is selected. To delete an individual security template, select it from the list, and thenclick Delete Entry . • You can delete a security template only if it...
Page 34 - Controlling access to device functions using the EWS
• Verify Job Expiration —This can be set to Off , Same as Confidential Print , or one of four intervals ranging from one hour to one week. • Repeat Job Expiration —This can be set to Off , Same as Confidential Print , or one of four intervals ranging from one hour to one week. 8 Under Advanced Setti...
Page 37 - Troubleshooting; Login issues; “Unsupported USB Device” error message; PKI A; Login screen does not appear when a Smart Card is inserted
Troubleshooting Login issues “Unsupported USB Device” error message M AKE SURE A SUPPORTED S MART C ARD READER IS ATTACHED Only the OmniKey reader that came with the printer is supported. Remove the unsupported reader and attach theOmniKey reader. The printer home screen fails to return to a locked ...
Page 41 - LDAP issues; LDAP lookups take a long time and then fail
LDAP issues LDAP lookups take a long time and then fail This issue can occur during login (at “Getting User Info”) or during address book searches. Try one or more of thefollowing: M AKE SURE P ORT 389 ( NON ‑ SSL) AND P ORT 636 (SSL) ARE NOT BLOCKED BY A FIREWALL The printer uses these ports to com...
Page 42 - Held Jobs/Print Release Lite issues; “You are not authorized to use this feature” Held Jobs error message
Held Jobs/Print Release Lite issues “You are not authorized to use this feature” Held Jobs error message A DD THE USER TO THE APPROPRIATE A CTIVE D IRECTORY GROUP If user authorization is enabled for Held Jobs, then add the user to an Active Directory group that is included in theauthorization list ...
Page 44 - Appendix A: Using the touch screen; Understanding the home screen; Using the on
Appendix A: Using the touch screen Understanding the home screen The screen located on the front of the MFP is touch ‑ sensitive and can be used to access device functions and navigate settings and configuration menus. The home screen looks similar to this (yours may contain additional icons): @ Sta...
Page 47 - Appendix C: Description of access controls; Access controls
Appendix C: Description of access controls Access controls Depending on the device type and installed options, some access controls (referred to on some devices as FunctionAccess Controls) may not be available for your printer. Administrative Menus Function access control What it does Configuration ...
Page 50 - Appendix D: Using Common Access Cards; Using a Common Access Card to access the printer
Appendix D: Using Common Access Cards Using a Common Access Card to access the printer 1 Insert your Common Access Card into the card reader attached to the printer. 2 When prompted, enter your PIN using the keypad that appears on the touch screen, and then touch Next . It may take a moment for the ...
Page 51 - Notices; LEXMARK SOFTWARE LICENSE AGREEMENT
Notices LEXMARK SOFTWARE LICENSE AGREEMENT PLEASE READ CAREFULLY BEFORE INSTALLING AND/OR USING THIS SOFTWARE: This Software License Agreement("License Agreement") is a legal agreement between you (either an individual or a single entity) and LexmarkInternational, Inc. ("Lexmark") th...
Page 54 - Index
Index A access controls list of 47setting at the device 12using the EWS to set 34 acronyms 46AppleTalk disabling 18 assumptions 6audit logging configuring 20 authentication token 30 B backup password using the touch screen to enable 9 before configuring the device verifying firmware 6verifying physi...