SR - en Sequrity
SR - en Sequrity
SR - en Sequrity
If you find any evidence of the suspicious opening of received cartons or you are not sure how it has been packed,
contact your sales representative.
Indicates a potentially hazardous situation which, if not avoided, could result in death, serious
injury, or serious damage, or fire in the equipment or surrounding objects.
Indicates a potentially hazardous situation which, if not avoided, could result in minor or
moderate injury, partial damage to the equipment or surrounding objects, or loss of data.
Indicates information to which you should pay attention when operating the equipment.
Describes handy information that is useful to know when operating the equipment.
References describing items related to what you are currently doing. See these references as
required.
Preface 3
Options
For available options, see the reference below:
Information About Equipment - Information About Equipment - Options
Trademarks
For trademarks, refer to the Safety Information.
4 Preface
CONTENTS
Preface................................................................................................................................................. 3
How to read this manual ............................................................................................................................................ 3
Chapter 4 APPENDIX
List of target events for monitoring and logs to be sent to the Syslog server ............................................ 26
CC Certification obtained version list .................................................................................................... 28
Combination of the SYS version and the firmware .................................................................................................. 31
CONTENTS 5
6 CONTENTS
1. THE HIGH SECURITY MODE
Precautions on Using the High Security Mode .......................................................................8
Confirmation of the mode .....................................................................................................................................9
Operational conditions........................................................................................................................................10
Precautions on Using the High Security Mode
0.
This operation mode protects customers’ important information against unauthorized access to the equipment and
leakage.
The following are the security functions when you operate the equipment complying with CC Certification.
User Authentication Setting function
Role Management function
Log collecting and browsing function
Communication function with TLS1.2
Integrity Check function
Management functions such as:
Log, Passwords, User, Password Policy, Date & Time, Auto Clear, Session Timer, Enable/disable of TLS
ISO/IEC15408 Certificate has been or will be obtained for the equipment (with the fax unit installed and IPv4 used)
which has the combination of the OS and browser below and has been being operated in Japanese or English.
PP Identifier: HCD-PP
OS: Windows 10
Browser: Microsoft Edge
MFP: e-STUDIO2020AC/2520AC/2021AC/2521AC*
e-STUDIO2525AC/3025AC/3525AC/4525AC/5525AC/6525AC*
e-STUDIO2528A/3028A/3528A/4528A/5528A/6528A*
e-STUDIO6526AC/6527AC/7527AC*
e-STUDIO6529A/7529A/9029A*
* Certification pending (as of Jan. 2024)
To operate the equipment complying with CC Certification under the high security mode, configurations according to
the use environment, such as protocol encryption setting and setting for the connection only to the authorized server
or client PC, are required.
Pay attention that if the conditions given in this manual are not met, you may not be able to operate the equipment
complying with CC Certification.
For details of each security function and how to set the related items, see the reference below:
TopAccess
After your service technician has performed the change of the settings of this equipment, confirm that is
displayed on the touch panel.
Moreover, by referring to the initial value list, confirm that the settings have been made correctly.
P.19 “Initial value list”
Operational conditions
Follow the operating guidance above, otherwise your confidential information will not be protected from
leakage or unauthorized access to this equipment.
Be sure to set [MFP Local Authentication] for [Authentication Method] in the [User Management] screen. If
[Windows Domain Authentication] or [LDAP Authentication] is set for user authentication, the equipment will
not be covered by CC Certification.
In order to maintain the security status complying with CC Certification, when a self-signed certificate is
created, use “RSA2048” for Public Key and “SHA256”, “SHA384” or “SHA512” for Signature Algorithm.
Manually select [FULL] and perform the integrity check at the time of installation and during use periodically.
* For details of the integrity check, see the reference below:
User Functions - SETTING ITEMS (Admin) - Security - Performing the integrity check
Do not change the communication settings of the equipment from the initial values. Communication via a
network can be protected by TLS if no such changes are made.
The automatic log-in function in the client software which comes with this equipment is not available. Be sure
to enter the user name and password when using client software.
Any data sent to this equipment, such as a Fax and Internet Fax printed or received from a printer driver*, can
be outputted only when a user with the printing privilege is logged in.
* Use IPP SSL/TLS to communicate with this equipment.
When IPP printing is performed, use the port created by entering “https://[IP address]:[SSL/TLS port number]/
Print” into the URL field.
(e.g.: https://192.168.1.2:631/Print)
* For details, see the reference below:
Installation - INSTALLING PRINTER DRIVERS FOR WINDOWS - Other Installations - IPP printing
When importing the data such as address book, be sure to use the data exported from this equipment.
Do not use any applications which need a setting change of the [ODCA] sub menu in the [Setup] menu on the
Do not enable [Use Password Authentication for Print Job] when printing is performed from this equipment
with any of these printer drivers; Universal Printer 2, Universal PS3.
The Integrity Check function is automatically performed at the startup of this equipment. When “Call For
Service” appears, contact your service technician.
In order to operate this equipment under the high security mode, a Syslog server which supports TLS1.2 is
necessary.
Printing, copying, scanning and fax transmission/reception are subject to an access restriction by means of a
user authentication function. All users can confirm the lists of jobs in processing and in waiting. However, as for
the list of fax reception jobs, only users whose role is Administrator or FaxOperator can confirm it.
Corresponding to the role privilege of users, they can operate outputting, deletion, pause or change orders of
jobs. When the role of the users is Administrator or User, they can create jobs. When the role of the users is
FaxOperator, they can create, output and delete fax transmission/reception jobs. However, as for fax
transmission jobs, the users can output and delete only their account jobs. When the role of the users is User,
jobs, they can output and delete only their account jobs. When the role of the users is Administrator, they can
delete, pause and change the order of all jobs in waiting. However, if the role of the users is AccountManager or
AddressBookRemoteOperator, outputting, deleting, pausing or changing orders of printing, copying or fax jobs
is not available.
Use the encrypted PDF format when saving or sending a file and the encryption level shall be 128 bit AES.
Specify a reliable remote PC for the saving destination of the scan data.
Do not use MFP LOCAL since no password can be set.
Administrators must regularly export and store the logs.
Do not enable [Auto] of Email Direct Printing.
Be sure to reboot the equipment when CA certification is uploaded or removed.
An administrator should explain to users that the high security mode is operating in this equipment as well as
the following items so that they will keep to them appropriately.
Printing should be performed by using the printer driver settings of IPP print.
Specify a reliable remote PC for the saving destination of the scan data.
Do not use any local folder of this equipment.
An administrator should always confirm that communication with the Syslog server is being connected.
When disposing of an MFP, be sure to contact your service technicians to erase the data in the internal storage
device completely.
In the high security mode, a password, tentatively assigned by an administrator to allow a user access, is treated as a
temporary one. To use the equipment, you need to register your password after accessing it with the temporary one.
The security level is insufficient if you continue to use the temporary password. Register your password as soon as
possible.
When an administrator resets users’ passwords, they must be so notified and prompted to change them to ones of
their own choosing.
To prevent user information exported from an equipment from being altered, it is hashed. If you change the password
for the exported user information, plain text is used for the password.
14 Temporary Password
Hold (Fax)
0.
In the high security mode, when an email to which a Fax, Internet Fax or image is received, it is not automatically
output. These jobs are stored in the [Hold (Fax)] queue and only a user having the [Fax Received Print] privilege can
print the job.
You can display the preview of the fax image received on the touch panel before printing the fax. For details, see the
UNIQUE FUNCTIONS
reference below:
Fax - USING THE FAX UNIT (BASIC OPERATION) - Receiving a Fax - Reception mode - Displaying the preview of
a received fax
If a job is in the [Hold (Fax)] queue, the Memory Rx lamp blinks.
Hold (Fax) 15
2.UNIQUE FUNCTIONS
Select the desired job or [Select All], and then press [Print].
4
The job that has been output is deleted from the [Hold (Fax)] queue.
16 Hold (Fax)
3. THE INITIAL VALUES
Precautions on the Initial Values........................................................................................18
Logging in .............................................................................................................................................................18
Initial value list .....................................................................................................................................................19
Precautions on the Initial Values
0.
To securely operate the equipment, the initial and selectable values in the equipment under the high security mode
may differ from those under the normal security mode. This manual only explains about the initial values and setting
items which are different from those under the normal security mode.
To operate equipment complying with CC Certification, be sure to change the initial values for the high security mode
listed in this chapter following the instructions described in the remarks column at the start of use and keep them
unchanged.
For the initial and setting values in the normal security mode, see the references below:
TopAccess
User Functions
To reset all settings by performing “Initialization” of this equipment, back up the setting of this equipment and
customers’ data before initializing. For details, see the reference below:
Information About Equipment - Information About Equipment - How to back up the data
Logging in
The [User Management] and [Administration] in TopAccess are displayed by logging in as a user with the
administrator privilege. Open TopAccess, click “Login” on the top right, and then enter the user name and
password to log in.
Be sure to log in the [Admin] tab in the [User Function] mode of the equipment as a user with the Administrator
privilege.
TopAccess:
[Administration]
[Setup] Menu
[General] Sub Menu
[Security] Menu
[Authentication] Sub Menu
The following information will be sent to a Syslog server. Success or failure of the event can be confirmed by means of
the Result field.
Registration date
Internal log memory date
Code
Message
User name
Domain name
26 List of target events for monitoring and logs to be sent to the Syslog server
4.APPENDIX
APPENDIX
Auto logout time 7182 OK Edited Device Setting
Registration of the 7160 OK Added new contact
address book
Change of the 7166 OK Edited Address Book
address book
Deletion of the 7170 OK Removed a contact
address book
Network setting 7183 OK Edited Network Setting
Modification of the user Changing of the role information 717B OK Updated group information :
group which is a part of Group information modified
the role
Change of the time Correction of the time 718A OK Edited Date & Time Setting
Session consolidation TLS session consolidation failure 80C1 NG Failed to establish the TLS
failure session (bad record mac)
80C5 NG Failed to establish the TLS
session (handshake failure)
Use of the management Management of the software 7100 OK Successfully updated Copier
functions Firmware
As for “End of jobs”, if any codes other than the listed one appear, “NG” will be indicated in the Result field.
List of target events for monitoring and logs to be sent to the Syslog server 27
CC Certification obtained version list
0.
The following table shows the combination of the CC Certification obtained version, operator’s manual and options
for each model. Be sure to confirm the identification number of the operator’s manual and the information described
on the equipment and the packing carton.
APPENDIX
Installation OME210032B0
Print OME210034B0
TopAccess OME210036B0
Frequently Asked OME210030B0 V5.0 or
Questions V6.0 *1
Troubleshooting OME210006B0
High Security Mode OME210040D0
Preparation of Paper OME210004B0
Information About OME210016C0
Equipment
Specifications OME210038C0
Fax OME210022B0
Information to our OMM210083E0 For the U.S.A.: GD-1370NA-N*2
customers For Europe: GD-1370EU *2
e-STUDIO7527AC Series, Basic Operation OME210012B0
e-STUDIO9029A Series (Quick Start Guide)
Safety Information OME210014B0
Copy OME210018B0
Scan OME210020B0
User Functions OME210028B0
Installation OME210032B0
Print OME210034B0
TopAccess OME210036B0
V5.0 *1
Frequently Asked OME210030B0
Questions
Troubleshooting OME21001000
High Security Mode OME210040D0
Preparation of Paper OME21000800
Information About OME210016C0
Equipment
Specifications OME210038C0
Fax OME210022B0
*1 For details about the combination of the SYS version and the firmware, see the reference below:
P.31 “Combination of the SYS version and the firmware”
*2 Be sure to confirm that the model name of the FAX unit is “GD-1370NA-N” or “GD-1370EU” by performing list printing by means of selecting
[User Functions -User-] > [Admin] > [List/Report] > [List] > [Function] from the control panel.
For details about the difference of the SYS version, refer to Information to our customers.
SYS V5.0
APPENDIX
e-STUDIO2525A e-STUDIO4525A e-STUDIO2528A/
e-STUDIO2020A e-STUDIO2021A
Firmware C/3025AC/ C/5525AC/ 3028A/3528A/
C/2520AC C/2521AC
3525AC 6525AC 4528A
SYSTEM TS20SF0W1801 TS20SF0W1801 TS20SF0W1801 TS20SF0W1801 TS20SF0W1801
FIRMWARE
SYSTEM TS20SD0W1801 TS20SD0W1801 TS20SD0W1801 TS20SD0W1801 TS20SD0W1801
SOFTWARE
ENGINE TK160MWW61 TK240MWW02 TK162MWW61 TK166MWW61 TK170MWW61
FIRMWARE
SCANNER TK160SLGWW15 TK160SLGWW15 TK160SLGWW15 TK160SLGWW15 TK160SLGWW15
FIRMWARE
FAX1 FIRMWARE H625TA13 H625TA13 H625TA13 H625TA13 H625TA13
e-STUDIO6526A
e-STUDIO5528A/ e-STUDIO6529A/
Firmware C/6527AC/
6528A 7529A/9029A
7527AC
SYSTEM TS20SF0W1801 TS20SF0W1801 TS20SF0W1801
FIRMWARE
SYSTEM TS20SD0W1801 TS20SD0W1801 TS20SD0W1801
SOFTWARE
ENGINE TK174MWW61 TK180MWW06 TK183MWW06
FIRMWARE
SCANNER TK160SLGWW15 TK160SLGWW15 TK160SLGWW15
FIRMWARE
FAX1 FIRMWARE H625TA13 H625TA13 H625TA13
SYS V6.0
e-STUDIO2525A e-STUDIO4525A
e-STUDIO2020A
Firmware C/3025AC/ C/5525AC/
C/2520AC
3525AC 6525AC
SYSTEM TS20SF0W1801 TS20SF0W1801 TS20SF0W1801
FIRMWARE
SYSTEM TS20SD0W1801 TS20SD0W1801 TS20SD0W1801
SOFTWARE
ENGINE TK160MWW61 TK162MWW61 TK166MWW61
FIRMWARE
SCANNER TK160SLGWW15 TK160SLGWW15 TK160SLGWW15
FIRMWARE
FAX1 FIRMWARE H625TA13 H625TA13 H625TA13