Oki ES9466 MFP Programming manual

MULTIFUNCTIONAL DIGITAL COLOR SYSTEMS
High Security Mode
Management Guide
ES9466 MFP/ES9476 MFP

© 2016 Oki Data Corporation All rights reserved Under the copyright laws, this manual cannot be reproduced in any form
without prior written permission of Oki Data.

Preface 3
Preface
Thank you for purchasing Oki Multifunctional Digital Systems or Multifunctional Digital Color Systems.
This manual explains about the conditions and settings for using the Multifunctional Digital Systems which complies
with IEEE Std 2600.1TM-2009.
Read this manual carefully before using your Multifunctional Digital Systems under the high security mode. For the
security precautions on operating the equipment complying with IEEE Std 2600.1TM-2009, refer to “Security
Precautions” in the “Safety Information”.
Keep this manual within easy reach and use it to maintain the equipment complying with IEEE Std 2600.1TM-2009.
If you find any evidence of the suspicious opening of received cartons or you are not sure how it has been packed,
contact your sales representative.
How to read this manual
Symbols in this manual
In this manual, some important items are described with the symbols shown below. Be sure to read these items
before using this equipment.
Target audience for this manual
This is the manual for equipment administrators. It is not necessary for general users to read this manual.
Optional equipment
For the available options, refer to the Quick Start Guide.
Trademarks
For trademarks, refer to the Safety Information.
Indicates a potentially hazardous situation which, if not avoided, could result in death, serious
injury, or serious damage, or fire in the equipment or surrounding objects.
Indicates a potentially hazardous situation which, if not avoided, may result in minor or
moderate injury, partial damage to the equipment or surrounding objects, or loss of data.
Indicates information to which you should pay attention when operating the equipment.
Describes handy information that is useful to know when operating the equipment.
Pages describing items related to what you are currently doing. See these pages as required.

4 Preface

CONTENTS 5
CONTENTS
Preface................................................................................................................................................. 3
How to read this manual ............................................................................................................................................ 3
Chapter 1 The High Security Mode
Precautions on Using the High Security Mode .......................................................................................... 8
Confirmation of the mode ........................................................................................................................................... 9
Operational conditions.............................................................................................................................................. 10
Chapter 2 UNIQUE FUNCTIONS
Temporary Password .......................................................................................................................... 14
Conditions when a temporary password is used ..................................................................................................... 14
Operation by a user when a temporary password is used....................................................................................... 14
Hold (Fax)........................................................................................................................................... 15
Chapter 3 THE INITIAL VALUES
Precautions on the Initial Values .......................................................................................................... 18
Logging in................................................................................................................................................................... 18
Initial value list........................................................................................................................................................... 19

6 CONTENTS

1.The High Security Mode
Precautions on Using the High Security Mode .......................................................................8
Confirmation of the mode .....................................................................................................................................9
Operational conditions........................................................................................................................................10

8 Precautions on Using the High Security Mode
0.Precautions on Using the High Security Mode
This operation mode protects customers’ important information against unauthorized access to the equipment and
leakage.
The following are the security functions when you operate the equipment complying with IEEE Std 2600.1TM-2009.
User Authentication Setting function
Role Management function
Log collecting and browsing function
Overwriting function of the specified data in HDD when jobs are completed or the power is turned ON
Communication function with TLS
Integrity Check function
Management functions such as:
Log, Passwords, User, Password Policy, Date & Time, Auto Clear, Session Timer, Enable/disable of TLS
We have applied for ISO/IEC 15408 certification for the environment where the following equipment is operating in
Japanese or English mode and connected to a PC running Windows 7 with Internet Explorer version 9.0.
MFP: ES9466 MFP/ES9476 MFP*
* Certification pending (as of April, 2016)
To operate the equipment complying with IEEE Std 2600.1TM-2009 under the high security mode, configurations
according to the use environment, such as protocol encryption setting and setting for the connection only to the
authorized server or client PC, are required.
Pay attention that if the conditions given in this manual are not met, you may not be able to operate the equipment
complying with IEEE Std 2600.1TM-2009.
For details of each security function and how to set the related items, refer to the TopAccess Guide.

1.The High Security Mode
Precautions on Using the High Security Mode 9
The High Security Mode
Confirmation of the mode
When this equipment is operated under the high security mode, is displayed on the touch panel of the
equipment.
The HDD inside the equipment which is operated under the high security mode is encrypted. Moreover, the Data
Overwrite Option (GP-1070) is installed in such equipment.
To confirm that each function is operating, check the display at the top right of the [Counter] screen on the touch
panel of the equipment.
When the Data Overwrite Enabler is installed, the hard disk space temporarily used during the job process will be
used for another job after the data are overwritten when the user is logging out.
The HDD is encrypted. The icon is displayed.
The HDD has been encrypted if this equipment is operated under
the high security mode.
The Data Overwrite Enabler is operating
properly. The icon showing that the Data Overwrite Enabler is correctly
operating is displayed.
The version of the system which is running is displayed. (SYS V1.0)

1.The High Security Mode
10 Precautions on Using the High Security Mode
Operational conditions
Follow the operating guidance above, otherwise your confidential information will not be protected from
leakage or unauthorized access to this equipment.
Be sure to set [MFP Local Authentication] for [Authentication Method] in the [User Management] screen. If
[Windows Domain Authentication] or [LDAP Authentication] is set for user authentication, the equipment will
not be covered by IEEE Std 2600.1TM-2009.
Manually select [FULL] and perform the integrity check at the time of installation and during use periodically.
* For details of the integrity check, refer to the MFP Management Guide.
Do not change the communication settings of the equipment from the initial values. Communication via a
network can be protected by TLS if no such changes are made.
In any of the following cases, contact your service technician.
If the icon showing that the HDD is encrypted ( ) is not displayed.
If the icon showing that the Data Overwrite Enabler is operating properly ( ) is not displayed.
The displayed system version differs from the actual one.
In the High Security Mode, the following functions cannot be used.
Interrupt copy
Network Fax
AddressBook Viewer
File Downloader
TWAIN Driver
e-Filing BackUp/Restore Utility
Scheduled printing
Storing to e-Filing from a printer driver*
* The function can be selected; however, an error occurs and the job is deleted. As a result, printing is not performed. When a job is deleted, it is recorded
in the error log. Confirm it in the [Logs] tab on TopAccess or [Job Status] - [Log] - [Print] in the equipment.
Disabling log authentication
The automatic log-in function in the client software which comes with this equipment is not available. Be sure
to enter the user name and password when using client software.
Any data sent to this equipment, such as a Fax and Internet Fax printed or received from a printer driver*, can
be outputted only when a user with the printing privilege is logged in.
* Use IPP SSL to communicate with this equipment.

1.The High Security Mode
Precautions on Using the High Security Mode 11
The High Security Mode
When IPP printing is performed, use the port created by entering “https://[IP address]:[SSL port number]/
Print” into the URL field.
(e.g.: https://192.168.1.2:443/Print)
* For details, refer to [IPP printing] under [Installing Printer Drivers for Windows] - [Other Installations] in the Software Installation Guide.
When importing the data such as address book, be sure to use the data exported from this equipment.
Do not use any applications which need a setting change of the [ODCA] sub menu in the [Setup] menu on the
[Administration] tab under TopAccess.
Do not enable [Use Password Authentication for Print Job] when printing is performed from this equipment
with any of these printer drivers; PCL Printer, PS Printer and XPS Printer.
To operate this equipment securely, be sure to set the following items:
Perform the setting correctly referring to Initial value list (P.19).
Use the encrypted PDF format when saving or sending a file and the encryption level shall be 128 bit AES.
Specify a reliable remote PC for the saving destination of the scan data.
Do not use PUBLIC BOX in e-Filing since no password can be set.
Do not use MFP LOCAL since no password can be set.
Administrators must regularly export and store the logs.
An administrator should explain to users that the high security mode is operating in this equipment as well as
the following items so that they will keep to them appropriately.
Printing should be performed by using the printer driver settings of IPP print.
Specify a reliable remote PC for the saving destination of the scan data.
Do not use a shared folder in e-Filing.
Do not use any local folder of this equipment.
When disposing of an MFP, be sure to contact your service technicians to erase the data in the HDD completely.

1.The High Security Mode
12 Precautions on Using the High Security Mode

2.UNIQUE FUNCTIONS
Temporary Password........................................................................................................14
Conditions when a temporary password is used ...............................................................................................14
Operation by a user when a temporary password is used.................................................................................14
Hold (Fax)........................................................................................................................15

14 Temporary Password
0.Temporary Password
In the high security mode, a password, tentatively assigned by an administrator to allow a user access, is treated as a
temporary one. To use the equipment, you need to register your password after accessing it with the temporary one.
The security level is insufficient if you continue to use the temporary password. Register your password as soon as
possible.
Conditions when a temporary password is used
A user temporary password is used in the following cases:
For the first time to log in to the equipment after being registered by an administrator.
When an administrator resets the user’s password.
When the user information password imported by an administrator is plain text.
When an administrator resets users' passwords, they must be so notified and prompted to change them to ones of
their own choosing.
To prevent user information exported from an equipment from being altered, it is hashed. If you change the password
for the exported user information, plain text is used for the password.
Operation by a user when a temporary password is used
If your password can be registered when accessing.
Registering your password on the control panel
Enter the user name and a temporary password in the User Authentication menu. When you press [OK] in the
confirmation screen for the temporary password, the password entry screen appears. Enter the temporary
password in [Old Password]. Enter your new password in [New Password] and [Retype New Password], and then
press [OK]. The new password is registered and you can log in to the equipment.
Registering your password in TopAccess
When you access the equipment from TopAccess, the log-in screen appears. Enter the user name and a temporary
password in the log-in screen, and then press [Login]. When the registration screen appears, enter your new
password in [New Password] and [Retype New Password], and then press [Save]. The new password is registered
and you can log in to TopAccess.
If you cannot register a new password when accessing the equipment.
In the following utilities, an error occurs when you try to log in to the equipment with a temporary password.
Therefore a new password cannot be registered either. Before using these utilities, register a new password on the
control panel or in TopAccess.
Remote Scan driver
e-Filing Web Utility

UNIQUE FUNCTIONS
Hold (Fax) 15
0.Hold (Fax)
In the high security mode, when an email to which a Fax, Internet Fax or image is received, it is not automatically
output. These jobs are stored in the [Hold (Fax)] queue and only a user having the [Fax Received Print] privilege can
print the job.
If a job is in the [Hold (Fax)] queue, the DATA IN MEMORY lamp blinks.
Printing a job in the Hold (Fax) queue
1
Log in to the equipment as a user having the [Fax Received Print] privilege.
2
Press [Print Mode] on the home menu screen.
3
Select [Hold (Fax)].
All jobs in the [Hold (Fax)] queue are displayed.
4
Select the desired job or [Select All], and then press [Print].
The job that has been output is deleted from the [Hold (Fax)] queue.

2.UNIQUE FUNCTIONS
16 Hold (Fax)

3.THE INITIAL VALUES
Precautions on the Initial Values........................................................................................18
Logging in.............................................................................................................................................................18
Initial value list.....................................................................................................................................................19

18 Precautions on the Initial Values
0.Precautions on the Initial Values
To securely operate the equipment, the initial and selectable values in the equipment under the high security mode
may differ from those under the normal security mode. This manual only explains about the initial values and setting
items which are different from those under the normal security mode.
To operate equipment complying with IEEE Std 2600.1TM-2009, be sure to change the initial values for the high
security mode listed in this chapter following the instructions described in the remarks column at the start of use and
keep them unchanged.
For the initial and setting values in the normal security mode, refer to the TopAccess Guide and MFP Management
Guide.
To reset all settings by performing “Initialization” of this equipment, back up the setting of this equipment and
customers’ data before initializing. For details, refer to the TopAccess Guide and MFP Management Guide.
Logging in
The [User Management] and [Administration] tabs in TopAccess are displayed by logging in as a user with the
administrator privilege. Open TopAccess, click “Login” on the top right, and then enter the user name and
password to log in.
Be sure to log in the [Admin] tab in the [Setting] mode of the equipment as a user with the Administrator privilege.

3.THE INITIAL VALUES
Precautions on the Initial Values 19
THE INITIAL VALUES
Initial value list
Home screen:
[Setting -User-] Menu
[Admin] Tab
[List/Report] Menu
[Report Setting] Menu
* It is not possible to operate the above menus from TopAccess.
TopAccess:
[Administration] Tab
[Setup] Menu
[General] Sub Menu
* The value can be changed in the [ADMIN] tab in the [Setting -User-] mode in the touch panel of the equipment.
Item Initial value for the high
security mode Remarks
[COMM. Report]
Memory Tx OFF Do not change the setting to “ON”.
Item Initial value for the high
security mode Remarks
Device Information
USB Direct Print Disable
Functions
Save as FTP Disable
Save to USB Media Disable
Save as SMB Disable
Save as Netware Disable
Network iFax Disable
Network Fax Disable
Web Services Scan Disable
Twain Scanning Disable
Restriction on Address Book Operation by administrator / AddressbookRemoteOperator
Can be operated by Administrator /
AddressbookRemoteOperator only
Power Save
Auto Clear * 45 Seconds The initial value is the same as in the Normal
Security Mode; however, OFF cannot be selected.

3.THE INITIAL VALUES
20 Precautions on the Initial Values
[Network] Sub Menu
* The value can be changed in the [ADMIN] tab in the [Setting -User-] mode in the touch panel of the equipment.
Item Initial value for the high
security mode Remarks
SMB
SMB Server Protocol Disable
HTTP
Enable SSL* Enable
WSD
Enable SSL Enable
Web Services Print Disable
Web Services Scan Disable
SMTP Server
Enable SMTP Server Disable
FTP Server
Enable FTP Server Disable
Enable SSL Enable
SMTP Client
Enable SSL Verify with imported CA
certification(s)
The secure setting is “Verify with imported CA
certification(s)” or “Accept all certificates
without CA”.
Authentication AUTO Be sure to confirm that one of “CRAM-MD5”,
“Digest-MD5”, “Kerberos” or “NTLM (IWA)” is
applied to your use environment.
POP3 Client
Enable SSL Verify with imported CA
certification(s)
FTP Client
SSL Setting Verify with imported CA
certification(s)
Bonjour
Enable Bonjour Disable
SNMP
Enable SNMP V1/V2 Disable
Enable SNMP V3 Enable
SLP
Enable SLP Disable
Syslog Setting
Enable SSL Verify with imported CA
certification(s)
Other manuals for ES9466 MFP
5
This manual suits for next models
1
Table of contents
Other Oki All In One Printer manuals

Oki
Oki ES5473 User manual

Oki
Oki CX 1145 MFP Parts list manual

Oki
Oki Teriostar LP-1030 User manual

Oki
Oki MC860 MFP Quick start guide

Oki
Oki MB460MFP Quick start guide

Oki
Oki B2520 User manual

Oki
Oki C9800hdn Parts list manual

Oki
Oki MC770x User manual

Oki
Oki MB780 User manual

Oki
Oki MC560 MFP CX2032 User manual