To display: [Utility] - [Administrator] - [Security] - [PKI Settings]
Make settings to enable SSL communication using the certificate of this machine.
To display: [Utility] - [Administrator] - [Security] - [PKI Settings] - [Enable SSL Version]
Select a login mode to enable SSL communication. Also, specify the range of the SSL version to be used.
Setting | Description |
---|---|
[Mode using SSL/TLS] | Select a login mode to establish SSL communications (default: [None]).
|
[Encryption Strength] | Displays the SSL encryption strength (AES-256 only). |
[SSL/TLS Version Setting] | Select the target SSL version respectively from [Minimum] and [Maximum]. |
To display: [Utility] - [Administrator] - [Security] - [PKI Settings] - [Protocol Setting]
If there are multiple certificates on this machine, you can use the certificates properly according to the purpose (protocol).
Specify the desired protocol in the protocol list, select [Edit], and select the target certificate.
Protocol | Application |
---|---|
[SSL]: [HTTP Server] | If this machine is used as an http server, it encrypts transmission from a client to the machine. For example, it is used for the following application.
|
[SSL]: [E-mail TX (SMTP)] | If this machine is used as an SMTP client, it submits a certificate of the machine according to a request from the E-mail server (SMTP). |
[SSL]: [E-mail RX (POP)] | If this machine is used as an POP client, it submits a certificate of the machine according to a request from the E-mail server (POP). |
[SSL]: [TCP Socket] | If this machine is used as a TCP Socket client, it submits a certificate of the machine according to a request by the TCP Socket server. |
[SSL]: [LDAP] | If this machine is used as an LDAP client, it submits a certificate of the machine according to a request by the LDAP server. |
[SSL]: [WebDAV Client] | If this machine is used as a WebDAV client, it submits a certificate of the machine according to a request by the WebDAV server. |
[SSL]: [OpenAPI] | If this machine is used as an OpenAPI server, it encrypts transmission from an OpenAPI client to the machine. |
[SSL]: [Web Service] | If this machine is used as a Web service server, it encrypts transmission from a client to the machine. This option is used when your Windows computer accesses the machine via HTTPS. |
[SSL]: [IPsec] | Used to activate IPsec communication on this machine. |
[SSL]: [Remote Panel] | When the screen of this machine is operated remotely with the dedicated software, it is used for the following applications:
|
[IEEE802.1X] | If this machine is used as an IEEE802.1X authentication client, it is used for the following applications:
|
To display: [Utility] - [Administrator] - [Security] - [Restrict User Access]
Configure settings to restrict change or deletion operations for users.
Setting | Description |
---|---|
[Biometric/IC Card Information Registration] | When allowing the user to register or when deleting the user’s biometric or IC card information, set this option to ON (default: OFF). |
[Synchronize User Authentication / Account Track By User] | When allowing the user to change the setting for synchronization between user authentication and account track, set this option to ON (default: ON). This setting is displayed when [Synchronize User Authentication / Account Track] is set to [Synchronize by User] in [Utility] - [Administrator] - [User Auth/Account Track] - [Authentication Method]. |
[Changing job priority] | Select whether to allow the user to change the job priority order (default: [Allow]). |
[Delete other user jobs] | Select whether to allow another user to delete a job (default: [Restrict]). |
To display: [Utility] - [Administrator] - [Security] - [Administrator Password Setting]
Change the administrator password of this machine (using up to 64 single-byte characters). Be sure to remember the changed password so that you do not forget it.
To display: [Utility] - [Administrator] - [Security] - [Admin. Password Change Permission Sett.]
Specify whether to allow a change of the administrator password for each function.
Setting | Description |
---|---|
[Allow password change] | When allowing the user to change the administrator password, set this option to ON (default: ON). |
[Function] | Specify the functions for which the administrator password can be changed.
|
To display: [Utility] - [Administrator] - [Security] - [Administrator Security Levels]
From those items that are set up by the administrator, select levels at which users are authorized to change settings (default: [Restrict]).
Configure the settings you have opened up to users in [Utility].
Setting | Description |
---|---|
[Level 1] | Open up the following settings to the users.
|
[Level 2] | Open up the following settings to the users.
|
[Restrict] | The settings are not opened up to users. |
To display: [Utility] - [Administrator] - [Security] - [Security Details]
Restricts functions that are related to authentication operations and data management to enhance security.
To display: [Utility] - [Administrator] - [Security] - [Security Details] - [Password Rules]
To enable the password rules, set the rule level.
Regardless of which rule level you set, rules are applied to the number of characters and character types that can be used in the password.
Setting | Description |
---|---|
[Password Rules] | When enabling the Password Rules, select the rule level (default: [Disable]). Setting to [Complexity 1] applies the following rules to the password to be specified in this machine.
Setting to [Complexity 2] applies the following rules to the password to be specified in this machine.
|
[Set Minimum Password Length] | If necessary, change the minimum number of password characters (default: [15] characters). |
[Prohibited words] | Register words you want to prohibit use of when specifying a password. The banned words can be registered when [Complexity 2] is selected in [Password Rules]. |
The password rules are applied to:
Administrator Password
User Password
Account Password
WebDAV Server Password
SNMP Password
Remote panel server password
Encryption Passphrase
To display: [Utility] - [Administrator] - [Security] - [Security Details] - [Authentication attack detection]
Configure settings to detect signs of unauthorized accesses to this machine in an environment where user authentication is installed.
Setting | Description |
---|---|
[Password attack detection] | When enabling detection against password attacks, set this option to ON (default: OFF).
|
[Detection for authentication access attacks] | When enabling detection against authentication access attacks, set this option to ON (default: OFF).
|
To display: [Utility] - [Administrator] - [Security] - [Security Details] - [Prohibit Functions]
Define the severity of penalties applied if an incorrect password is entered during the authentication process.
Setting | Description |
---|---|
[Prohibit Functions] | Select the severity of penalties applied if an incorrect password is entered during the authentication process (default: [Mode1]).
|
[No. of Tries] | When [Mode2] is selected in [Prohibit Functions], specify the number of password entry failures that occurred until authentication operation is restricted. |
[Release] | Select an item to be released from Access Lock during authentication failure. |
[Release Time Settings] | If necessary, change the time that elapses before an access lock state in the Administrator Setting mode is canceled (default: [5] min.). If a predetermined time has elapsed after the machine was restarted, an access lock state is canceled. |
To display: [Utility] - [Administrator] - [Security] - [Security Details] - [Print Data Capture]
When allowing the user to capture print data received on this machine, set this option to ON (default: ON).
The captured data is used in order that the service engineer analyzes printer failures. For details, contact your service representative.
To display: [Utility] - [Administrator] - [Security] - [Security Details] - [Personal Data Security Settings]
Set whether to hide the personal information included in job information, MIB, and notification information.
Setting | Description |
---|---|
[Job History] | Configure settings to display personal information of the job history screen.
|
[Current Job] | Configure settings to display personal information of the active job screen.
|
[Hide Personal Information] | When displaying the file name of MIB information, set this option to OFF (default: ON). |
[Withhold Personal Information] | When displaying the user name in the penalty lock notification information, set this option to OFF (default: OFF). |
To display: [Utility] - [Administrator] - [Security] - [Security Details] - [Initialize]
Initializes the settings in [Job History], [Network Settings], and [Enhanced Server Information].
Select items you want to initialize, then tap [OK].
To display: [Utility] - [Administrator] - [Security] - [Security Details] - [Web browser contents access]
When using the application associated with the Web browser function of this machine, select whether to allow an access to the contents saved in the storage device of this machine via the Web browser (default: [Allow]).
To display: [Utility] - [Administrator] - [Security] - [Security Details] - [Export Debug Log]
When allowing the user to retrieve debug information saved in the storage device of this machine, set this option to ON (default: OFF).
To display: [Utility] - [Administrator] - [Security] - [Security Details] - [Remote Service setting]
When allowing the use of the remote services, set [Allow remote service setting] to ON (default: OFF).
To display: [Utility] - [Administrator] - [Security] - [Security Details] - [Web browser setting change]
Specify the type of the user who can change the user data setting of the Web browser (default: [Administrator only]).
Selecting [Administrator + User] allows you to configure the following Web browser settings using the registered user's privileges.
Home page
Start up
Web data (Cookie, Web Storage, or Indexed Database)
Authentication information
To display: [Utility] - [Administrator] - [Security] - [Security Details] - [Maintenance Mode Access]
Select whether to permit your service representative to change the settings of this machine without administrator authentication (default: [Restrict]).
To display: [Utility] - [Administrator] - [Security] - [Security Details] - [Write the Configuration from USB]
When allowing the user to change the settings of this machine by loading the configuration file saved in a USB flash drive, set this option to ON (default: ON).
To display: [Utility] - [Administrator] - [Security] - [Security Details] - [Storage data backup]
When allowing our service representative to back up or restore the storage on this machine, set this option to ON (default: OFF).
To display: [Utility] - [Administrator] - [Security] - [Quick Security Setting]
Summarizes settings to enhance the security of this machine. We recommend that you change settings in order to use this machine more securely.
Setting | Description |
---|---|
[Quick IP Filtering] | When using the quick IP filtering function, select the method to specify the IP address for which access is restricted. [Synchronize IP Address] is specified by default. In some areas, [No Filtering] is specified by default. |
[Administrator Password Setting] | Change the administrator password of this machine (using up to 64 single-byte characters). Be sure to remember the changed password so that you do not forget it. This setting is displayed when SSL communication is enabled in Web Connection. |
[Password Rules] | When enabling the Password Rules, select the rule level (default: [Disable]). |
[Web Conn.setting] | When using Web Connection, set this option to ON (default: ON). |
[Security Warning Display Setting] | To display the security warning screen if the administrator password remains set to the default or if password rules are not satisfied, set this option to ON. ON is specified by default. In some areas, OFF is specified by default. |
[USB flash drive function settings] | Specify whether to permit a function that requires the USB Port.
|
To display: [Utility] - [Administrator] - [Security] - [USB port connection permission setting]
Specify whether to permit a function that requires the USB Port.
Setting | Description |
---|---|
[Set All] | Select whether to restrict all the functions using the USB Port, or configure a setting for each function (default: [Detail Setting]). |
If [Detail Setting] is selected in [Set All], configure the following settings.
Setting | Description |
---|---|
[Authentication Device] | When allowing a connection with the Authentication Unit, select [Allow] (default: [Allow]). |
[External Keyboard] | When allowing the user to connect an external keyboard, set this option to ON (default: ON). |
[USB flash drive (User)] | Specify whether to allow the use of USB memory for functions to be used by the user (default: [ON]).
|
[USB flash drive (Administrator)] | Specify whether to allow the use of USB memory for functions to be used by the administrator (default: [ON]).
|
[USB flash drive (Service)] | Specify whether to allow the use of USB memory for functions to be used by the service engineer (default: [ON]).
|
[PC Connect] | Specify whether to enable to print files from a USB-connected computer (default: [ON]).
|
To display: [Utility] - [Administrator] - [Security] - [Enhanced Security Mode]
Select whether to enable the Enhanced Security Mode.
If you enable the Enhanced Security Mode, the various security functions are forcibly configured. This allows you to ensure higher-level security of data management. For details, contact your service representative.
To enable the enhanced security mode, the following settings must have been configured.
Prerequisite settings | Check Job |
---|---|
[User Auth/Account Track] - [Authentication Method] - [User Authentication] | Select an option other than [OFF]. (When external server authentication is used, only Active Directory is available as the server type.) |
[Security] - [Administrator Password Setting] | Set a password complying with password rules. |
[Security] - [Firmware Update (USB) Permission Setting] (with [Password Priority] specified) | Set a password complying with password rules. |
In Web Connection, register the certificate. | For details, refer to Encrypting Communications. |
Service settings | Service settings must be configured by your service representative. For details, contact your service representative. |
If you enable the Enhanced Security Mode, the following settings are forcibly changed.
Setting items in Administrator Settings | Settings to forcibly changed |
---|---|
[User Auth/Account Track] - [Authentication Method] - [Public User Access]* | Set to [Restrict]. |
[User Auth/Account Track] - [User Authentication Setting] - [Administrative Setting] - [User Name List]* | Set to [OFF]. |
[User Auth/Account Track] - [Print without Authentication]* | Set to [Restrict]. |
[User Auth/Account Track] - [User/Account Common Setting] - [Counter Remote Control] | Set to OFF. |
[User Auth/Account Track] - [Simple Authentication setting] - [Simple Authentication setting]* | Set to OFF. |
[Network] - [SNMP Setting] - [SNMP v1/v2c Setting] - [Write Community Name]* | Set to OFF. |
[Network] - [SNMP Setting] - [SNMP v3 Setting]* | [Security Level] for read and write allowed users is set to [auth-password/priv-password]. The Security Level can be changed to [auth-password]. |
[Network] - [TCP Socket Setting] - [Use SSL/TLS] | Set to ON. |
[Network] - [Web Browser Setting] - [Web Browser Setting]* | Set to OFF. |
[Network] - [Remote Panel Settings]* |
|
[Network] - [Machine Update Settings] - [Machine Auto Update Settings]* | This function is not available. |
[Network] - [IWS Settings] - [IWS Settings]* | Set to OFF. |
[Network] - [OpenAPI Setting] - [OpenAPI Setting] - [SSL/Port Settings] | Set to [SSL Only]. |
[System Settings] - [System Connection Setting] - [Mobile Connection Settings] - [Simple Connection Setting]* |
|
[Security] - [Admin. Password Change Permission Sett.] - [Allow password change] | Set to OFF. |
[Security] - [USB port connection permission setting] | Set to [Restrict]. |
[Security] - [FW Update (Network) Perm. Sett.] | Set to OFF. |
[Security] - [Secure Boot Function Set.]* | Set to ON. |
[Security] - [Security Details] - [Password Rules]* | Set to [Complexity 1]. If this option cannot be set to [Complexity 1], the enhanced security mode is not available. |
[Security] - [Security Details] - [Prohibit Functions]* |
|
[Security] - [Security Details] - [Print Data Capture] | Set to OFF. |
[Security] - [Security Details] - [Personal Data Security Settings] - [Hide Personal Information] | Set to ON. |
[Security] - [Security Details] - [Initialize]* | This function is not available. |
[Maintenance] - [Remote Access Setting] - [Import/Export User Data] | Set to OFF. |
[Maintenance] - [Import/Export] in Web Connection | This function is not available. |
[Security] - [PKI Settings] - [Device Certificate Setting] in Web Connection | [Remove a Certificate] is hidden. |
[Security] - [PKI Settings] - [Enable SSL Version]* | [Mode using SSL/TLS]: Set to [Admin. Mode and User Mode]. |
[Security] - [PKI Settings] - [Protocol Setting] | [Protocol 1]: [SSL], [Protocol 2]: The certificate is registered in the [HTTP Server]. |
Remote Diagnosis System | Some functions may be disabled. For details, contact your service representative. |
[Security] - [Security Details] - [Maintenance Mode Access] | Set to [Restrict]. |
To display: [Utility] - [Administrator] - [Security] - [Firmware Update (USB) Permission Setting]
Select the method to allow the service engineer to update firmware using a USB flash drive (default: [USB port connection permission preference setting]).
[Password Priority]: Prompts the user to enter the password. Enter the required password in [Password] (using up to 20 characters). When the entered password matches the password specified here, firmware update is permitted.
[USB port connection permission preference setting]: Follows the Allow or Restrict setting that is selected in [USB flash drive (Service)] - [Firmware Update Parameters] of [Utility] - [Administrator] - [Security] - [USB port connection permission setting].
To display: [Utility] - [Administrator] - [Security] - [Driver Password Encryption Setting]
Change the encryption passphrase to encrypt authentication passwords (such as user and account passwords) when printing data using a printer driver (default: [Use Factory default settings]).
[User-Defined]: Select this option when you want to set your own encryption passphrase. Tap [Encryption Passphrase] and enter the encryption passphrase (up to 20 single-byte characters). Set the same encryption passphrase in the printer driver, too.
[Use Factory default settings]: Uses the encryption passphrase (common key) set on this machine at the time of shipping.
To display: [Utility] - [Administrator] - [Security] - [FIPS Settings]
When enabling the FIPS (Federal Information Processing Standardization) mode, set this option to ON (default: OFF).
FIPS defines security requirements for cryptographic modules. These standards have been adopted by many organizations, including U.S. federal government agencies. Enabling the FIPS Mode makes the functions of the machine conform to the FIPS.
To display: [Utility] - [Administrator] - [Security] - [Job Log Settings]
Configure the settings to obtain job logs.
To display: [Utility] - [Administrator] - [Security] - [Job Log Settings] - [Job Log Usage Set.]
Configure the settings to obtain job logs. After you have changed these settings, the job log is obtained when you restart this machine.
You can check usage, paper usage, operations and job history for each user or account in the job log. For details on how to viewing the output job logs, contact your service representative.
Setting | Description |
---|---|
[Enable Settings] | When obtaining job logs, set this option to ON (default: OFF). |
[Obtain Log Type] | Select whether to obtain job logs for each type.
|
[Transmission Method] | Display the method to send job logs to the server ([Auto (syslog)] only). To configure the log sending setting, select [Job Log Settings] - [syslog TX settings]. |
To display: [Utility] - [Administrator] - [Security] - [Job Log Settings] - [syslog TX settings]
Configure the setting to send job logs to the server, in the syslog format.
Setting | Description |
---|---|
[Communication Protocol] | Select the communication protocol (default: [UDP]). |
[Communication Server Settings] | Enter the IP address or host name of the destination server. |
[Port No.] | If necessary, change the port number (default: [514]). |
[Log format] | Select the log format (default: [Standard]). |
To display: [Utility] - [Administrator] - [Security] - [OpenAPI Certification Management Setting]
Specify a restriction code to prevent an OpenAPI connection application from being registered on this machine.
For details, contact your service representative.
To display: [Utility] - [Administrator] - [Security] - [FW Update (Network) Perm. Sett.]
Select whether to allow the firmware update via the network (default: [Allow]).
To display: [Utility] - [Administrator] - [Security] - [Secure Boot Function Set.]
Select whether to enable the secure boot function (default: OFF).