Konica Minolta C300i bizhub C360i/C300i/C250i Security Operations User Manual - Page 36

action]: Any of [Protected], [Allow], and [Deny] [Cancel]

Page 36 highlights

2.4 Setting IPsec 2 device, confirm that a new certificate has been issued. See bizhub C360i/C300i/C250i User's Guide, Ver. 1.00 AA2J-9598BA-00 for more information. Use [Enable IPsec] in the settings below. Setting item [IPsec] [Default action] [Certificate Verification Level Settings] IPsec Policy Setting value [ON] [Deny] • Expiration Date: ON (default) • Key Usage: OFF (default) • Chain: ON • Expiration Date Confirmation: OFF (default) [action]: Any of [Protected], [Allow], and [Deny] ([Cancel] cannot be used.) NOTICE Do not use an device certificate that is electronically signed by MD5, as an increased risk results of data to be protected being tampered with or leaked. With FIPS enabled, only SHA-256 can be used for the digital signature certificate. Turning off the main power switch results in discarding IKE SA (shared secret key for IKE) that is stored in the memory managed by this machine as well as the shared key managed by each SA (key generated by converting the pre-shared key used for IPsec). To eliminate the risk of the data to be protected being tampered with or leaked, refer to the recommended ciphers list disclosed by, for example, NIST and CRYPTREC and use the appropriate cryptographic technique. Use the following browsers to ensure safety. Use of any of the following browsers achieves communication that ensures confidentiality of the image data transmitted and received. Microsoft Internet Explorer - 10/11 Mozilla Firefox - 20 or later Microsoft Internet Explorer 11 is used for the ISO15408 evaluation for this machine. 0 The control panel and the Web Connection can be used for this setting. 0 For the procedure to access the administrator mode, see page 2-2. 0 Do not leave the machine with the setting screen of administrator mode left shown on the display. If it is absolutely necessary to leave the machine, be sure first to log off from the administrator mode. 1 Call the administrator mode. 2 Tap [Network] - [TCP/IP Setting] - [IPsec]. 3 Select [IPsec Setting], and tap [OK]. 4 Make the necessary settings. % Tap [Cancel] or [

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106

bizhub C360i/C300i/C250i/C036DNi/C030DNi/C025DNi
2-16
2.4
Setting IPsec
2
device, confirm that a new certificate has been issued. See bizhub C360i/C300i/C250i User’s Guide, Ver.
1.00 AA2J-9598BA-00 for more information.
Use [Enable IPsec] in the settings below.
NOTICE
Do not use an device certificate that is electronically signed by MD5, as an increased risk results of data to be
protected being tampered with or leaked.
With FIPS enabled, only SHA-256 can be used for the digital signature certificate.
Turning off the
main power switch
results in discarding IKE SA (shared secret key for IKE) that is stored in
the memory managed by this machine as well as the shared key managed by each SA (key generated by con-
verting the pre-shared key used for IPsec).
To eliminate the risk of the data to be protected being tampered with or leaked, refer to the recommended
ciphers list disclosed by, for example, NIST and CRYPTREC and use the appropriate cryptographic tech-
nique.
Use the following browsers to ensure safety. Use of any of the following browsers achieves communication
that ensures confidentiality of the image data transmitted and received.
Microsoft Internet Explorer
-
10/11
Mozilla Firefox
-
20 or later
Microsoft Internet Explorer 11 is used for the ISO15408 evaluation for this machine.
0
The control panel and the
Web Connection
can be used for this setting.
0
For the procedure to access the administrator mode, see page 2-2.
0
Do not leave the machine with the setting screen of administrator mode left shown on the display. If it
is absolutely necessary to leave the machine, be sure first to log off from the administrator mode.
1
Call the administrator mode.
2
Tap [Network] - [TCP/IP Setting] - [IPsec].
3
Select [IPsec Setting], and tap [OK].
4
Make the necessary settings.
%
Tap [Cancel] or [<] to go back to the previous screen.
5
Select [Enable IPsec], and tap [OK].
6
Make the necessary settings.
%
Tap [OK] or [Cancel] to go back to the previous screen.
7
Select [Communication Check], and tap [OK].
8
Make the necessary settings.
%
Tap [Back] to go back to the previous screen.
9
Tap [OK].
Setting item
Setting value
[IPsec]
[ON]
[Default action]
[Deny]
[Certificate Verification Level Settings]
Expiration Date: ON (default)
Key Usage: OFF (default)
Chain: ON
Expiration Date Confirmation: OFF (default)
IPsec Policy
[action]: Any of [Protected], [Allow], and [Deny] ([Cancel]
cannot be used.)