This Document Pertains To The Following Machines:: Toshiba America Business Solutions Inc. June 2010 Version 1.0
This Document Pertains To The Following Machines:: Toshiba America Business Solutions Inc. June 2010 Version 1.0
HDD security is part of the Is Data Safe and Is Disposal Secure? segments of the Toshiba Security Vulnerability Assessment Program. Following is a description of Basic, Enhanced and Optimal Security states for Toshiba MFDs as they apply to 1) MFPs at installation, 2) MFPs already in place at customer locations and 3) MFPs leaving the customers possession.
June 2010
Version 1.0
Table of Contents
(1) Installation of New Toshiba MFPs .................................................................3
Basic Security: Secure Encryption ..................................................................................................... 3 Enhanced Security: Data Overwrite ................................................................................................... 4 Optimal Security: Enhanced Encryption and Data Overwrite Kit ....................................................... 5 Verification of Security Function ........................................................................................................ 6
Secure Encryption
1) Turn on the machine while pressing the 0 and 8 keys. Release them after you hear a beep. 2) Key in code 9379 and press START. 3) Key in a value of 1 and press ENTER. 4) Key in code 690 and press START. 5) Press ENTER the display will say WAIT. When the process is finished REBOOT THE MACHINE will appear. 6) Press the Power button to turn off the machine. 7) Turn on the machine while pressing the 1 and * keys. Release them after you hear a beep. 8) Key in code 100 and press START and initialize the FAX Setup. 9) Key in code 102 and press START and initialize the FAX image data. 10) Press the Power button to turn off the machine.
How to test to see if the function is activated: when the machine is in the ready condition, press the counter button on the control panel. On the touch screen above the counter information on the right hand side, you will see a small lock symbol. This indicates encryption is activated.
Page 3
Data Overwrite
1) With the machine off, insert GP-1070 USB Data Overwrite dongle into the USB connector on the machine. 2) Turn on the machine while pressing the 0 and 8 keys. Release them after you hear a beep. 3) Key in code 3840 and press START. 4) The Data overwrite enabler is displayed under the license name. 5) Touch the Data overwrite enabler message displayed on the touch screen. The background will change color indicating it is selected. 6) Press the INSTALL button on the touch screen. 7) When the Data overwrite enabler license is successfully transferred to the machine a message will be displayed saying Registration Succeeded. 8) Press the Power button to turn off the machine. 9) Tape the GP-1070 USB Data Overwrite dongle to the back of the machine for future use. Remember the license key can only be moved back to the original installing dongle.
How to test to see if the function is activated: Press the START button to make a copy, you will see a message in the lower left hand corner of the touch screen that says printing. Shortly after the message disappears, you will see another message saying erasing data. This indicates the data overwrite kit is installed and working properly.
Page 4
Page 5
How to test to see if the Secure Encryption is activated: when the machine is in the ready condition, press the counter button on the control panel. On the touch screen above the counter information on the right hand side, you will see a small lock symbol. This indicated encryption is activated.
How to test to see if the Data Overwrite is activated: Press the START button to make a copy. You will see a message in the lower left hand corner of the touch screen that says printing. Shortly after the message disappears, you will see another message saying erasing data. This indicates the data overwrite kit is installed and working properly.
Page 6
Please read this section carefully as all the processes require backing up the customers data before proceeding with any of the security levels.
Outline
Back-up HDD User Data Print Function List For Maintenance Print Function List HDD Forced Cleaning Reinstalling firmware Installing security option (s) Reset HDD User Data Reset Function List For Maintenance Reset Function List Verify Operation IMPORTANT This section requires a USB key with the latest firmware on it for the model(s) you will be working on. The firmware can be obtained from the Tech-To-Go section of FYI. The firmware always has the latest instructions for installation.
Page 7
Back up HDD Ask the user (machine administrator) to back up the data in the HDD. Refer to the table below for the type of data, availability and method of backup.
Type of data in HDD Availability Backup method Archive them in the e-Filing of TopAccess. As for the backup in Box data, all data (selectable by the box) can be backed up / restored in one go by using e-Filing Backup/ Restore Utility. Back them up in the Administrator menu of TopAccess. Export them in Administrator menu of TopAccess. Export them in the Administrator menu of TopAccess. (Import cannot be performed.) Copy them to the client computer via the network. (The data which have been copied to the client computer cannot be copied to the shared folder.) Export role information on the TopAccess menus. [User Management] tab > [User Confirm/Create/Modify] > [Role Information] Finish printing them after the paper supply and the jam release, etc. (The data cannot be kept.) If any jobs are left, print them. (The data cannot be backed up.) Print them. (The data cannot be backed up.) Print them. (The data cannot be backed up.)
Available
F-code information, Template registration information, Address book data Department management data Log data (Print, Scan, FAX (Transmission/Reception) Data in the shared folder (Scanned data, Saved data of copy / FAX transmission)
Available
Role information
Available
Print waiting data (Copying data and FAX reception data that are waiting to be printed due to the paper run-out and jam, etc.) Print job (Private print data, Schedule print data) FAX saved data (Confidential / Bulletin board data) Registration data for FAX transmission (Delayed transmission / Recovery transmission)
Not available
Page 8
Backing up data
The administrator can create backup files of the address book, mailboxes and templates that are stored in the hard disk of this equipment. These data must be backed up in the cases such as the updating of system software or the replacement of the hard disk.
Before backing up the data, confirm that there is no print job, no scan job, and no fax job. The backup files cannot be created if there are any jobs that have been processed. If backing up the data takes a long time, perform backing up the data after the equipment turns into the Sleep/Auto Shut Off mode. The password for the template will be displayed as texts in the backup file. Keep the backup file carefully when backing up the template data.
1 2
Access TopAccess in the administrator mode. Click the [Maintenance] menu and [Backup] submenu.
If you previously created a backup file, the backup file link and information are displayed in each area. You can click the link to save the previous backup file.
Click [Create New File] for the data that you want to back up, or click [Create New File] in the [Combined Backup] section to create a backup file of all data.
Page 9
The backup file will be created and the backup file name and file size will be displayed.
Right-click the [File Name] link and select [Save Target As].
Select the file location and select [All Files] in the [Save as type] box.
It is recommended to save the backup file as it is named. If you change the file name, the equipment cannot restore the data from the backup files. The file name of each backup data must be the following name: - Address Book: BACKUP_ADDR<date>.tbf - MailBoxes: BACKUP_MBOX<date>.enc - Template: BACKUP_TEMP<date>.enc - Combined Backup: BACKUP_ALL<date>.enc
Click [Save].
The backup file is saved in the selected location.
Page 10
Print out FUNCTION LIST FOR MAINTENANCE (1) (2) (3) Press the [USER FUNCTIONS] button and then the [USER] button. Press the [LIST] button. Key in [*] [#] [*] [*] [3] [3] and then press the [START] button. The FUNCTION LIST FOR MAINTENANCE is printed out.
Print out FUNCTION list (1) (2) (3) Press the [USER FUNCTIONS] button. Press the [ADMIN] button, enter the password, and then press the [ENTER] button. Press the [LIST/REPORT] button and then the [LIST] button.
(4) Press the [FUNCTION] button. The FUNCTION list is printed out. Note: Explain the procedure to the user (machine administrator) and ask him/her to enter his/her password.
Page 11
Page 12
22) Key in code 3841 and press START. 23) The Data overwrite enabler is displayed under the license name. 24) Touch the Data overwrite enabler message displayed on the touch screen. The background will change color indicating it is selected. 25) Press the MOVE button on the touch screen. 26) When the Data overwrite enabler license is successfully transferred from the machine a message will be displayed saying Moving the License Succeeded. Press return to continue. 27) Key in code 9379 and press START. 28) Key in a value of 1 and press ENTER. 29) Key in code 690 and press START. 30) Press ENTER and the display will say WAIT. When the process is finished REBOOT THE MACHINE will appear. 31) Press the Power button to turn off the machine. 32) With machine off remove the GP-1070 USB Data Overwrite dongle from the machine. 33) Install the USB key and turn on the machine while pressing the 9 and 4 keys. Release them after you hear a beep. 34) Select (1) OS Update and (2) HDD SYS Update firmware options and press START. When the firmware has completed updating it will display Update Completed. 35) Press the Power button to turn off the machine. 36) Turn on the machine while pressing the 0 and 8 keys. Release them after you hear a beep. 37) Key in code 947 and press START and initialize the firmware. 38) Press the Power button to turn off the machine and remove USB key.
How to test to see if the function is activated: when the machine is in the ready condition, press the counter button on the control panel. On the touch screen above the counter information on the right hand side, you will see a small lock symbol. This indicates encryption is activated.
Page 13
Data Overwrite
1) With machine off, insert GP-1070 USB Data Overwrite dongle into the USB connector on the machine. 2) Turn on the machine while pressing the 0 and 8 keys. Release them after you hear a beep. 3) Key in code 3840 and press START. 4) The Data overwrite enabler is displayed under the license name. 5) Touch the Data overwrite enabler message displayed on the touch screen. The background will change color indicating it is selected. 6) Press the INSTALL button on the touch screen. 7) When the Data overwrite enabler license is successfully transferred to the machine a message will be displayed saying Registration Succeeded then press the RETURN button on the touch screen. 8) Key in code 1426 and press START. 9) The touch screen will display the following message Are You Sure . 10) On the touch screen touch INITIALIZE. 11) The machine will display the following message HDD ERASE RUNNING and display how much of the HDD has been erased as a percentage( ie.. 12%). DO NOT turn off the machine until this percentage reaches 100% and the machine stops and displays the following message HDD ERASE [OK] . The HDD has now been erased to a minimum of DOD 522022-M standards 12) Use the Power switch to turn off the machine. 13) Turn on the machine while pressing the Clear and 3 keys. Release them after you hear a beep. 14) Press the 3 key (All Partition Delete and create loader partition) and press START A message will be displayed first saying Initializing HDD table then Initialization Completed. 15) Press the Power button to turn off the machine and remove the GP-1070. 16) Insert a USB key with the appropriate machine firmware into the USB slot on the machine. 17) Turn on the machine while pressing the 9 and 4 keys. Release them after you hear a beep. 18) Select all of the firmware options and press START. When the firmware has completed updating it will display Update Completed. 19) Press the Power button to turn off the machine and remove the USB key. 20) Turn on the machine while pressing the 0 and 8 keys. Release them after you hear a beep. 21) Key in code 947 and press START and initialize the firmware. 22) Key in code 690 and press START. 23) Press ENTER the display will say WAIT. When the process is finished REBOOT THE MACHINE will appear. 24) Press the Power button to turn off the machine.
Page 14
25) Tape the GP-1070 USB Data Overwrite dongle to the back of the machine for future use. Remember the license key can only be moved back to the original installing dongle.
How to test to see if the function is activated: Press the START button to make a copy. You will see a message in the lower left hand corner of the touch screen that says printing. Shortly after the message disappears, you will see another message saying erasing data. This indicates the data overwrite kit is installed and working properly.
Page 15
Page 16
25) Press ENTER the display will say WAIT. When the process is finished a message will say REBOOT THE MACHINE will appear. 26) Use the Power switch to turn off the machine. 27) With machine off remove the GP-1070 USB Data Overwrite dongle from the machine. 28) Tape the GP-1070 USB Data Overwrite dongle to the back of the machine for future use. Remember the license key can only be moved back to the original installing dongle.
How to test to see if the function is activated: when the machine is in the ready condition, press the counter button on the control panel. On the touch screen above the counter information on the right hand side you will see a small lock symbol. This indicated encryption is activated. Press the START button to make a copy. You will see a message in the lower left hand corner of the touch screen that says printing. Shortly after the message disappears, you will see another message saying erasing data. This indicates the data overwrite kit is installed and working properly.
Page 17
How to test to see if the Secure Encryption is activated: when the machine is in the ready condition, press the counter button on the control panel. On the touch screen above the counter information on the right hand side, you will see a small lock symbol. This indicated encryption is activated.
How to test to see if the Data Overwrite is activated: Press the START button to make a copy. You will see a message in the lower left hand corner of the touch screen that says printing. Shortly after the message disappears, you will see another message saying erasing data. This indicates the data overwrite kit is installed and working properly.
Page 18
[F] Reset users setting items and restore data/information Ask the user (machine administrator) to reset the users setting items and to restore data or information. Refer to the following for the reset and restore:
Items to reset/restore Printer driver F-code information, Template registering information, Address book data Department management data Image data in the e-Filing Role information Method Upload them in the Administrator menu of TopAccess. Restore them in the Administrator menu of TopAccess. Import them in the Administrator menu of TopAccess. Restore them in the e-Filing of the TopAccess. Import role information on the TopAccess menus. [User Management] tab > [User Confirm/Create/Modify] > [Role Information]
When the SSL is enabled, perform the setting of the following items again with Create selfcertificate of TopAccess. Country Name State or Province Name Locality Name Organization Name Organizational Unit Name Common Name Email Address
When wireless LAN is used, perform the setting again on the LCD panel. (only when security with a certificate is used) Also, upload the following certificate file with Install Certificate for Wireless LAN of TopAccess. CA certificate User certificate
Page 19
When restoring the data from the backup file, the same template number settings and mailbox settings are overwritten.
Before restoring the data from backup files, confirm that there is no print job, no scan job, and no fax job. The backup files cannot be restored if there are any jobs that have been processed. If restoring the data takes a long time, restore the data after the equipment turns into the Sleep/Auto Shut Off mode.
1 2
Access TopAccess in the administrator mode. Click the [Maintenance] menu and [Restore] submenu.
Click [Browse] in the data section that you want to restore, or click [Browse] in the [Combined Restore] section to restore all data from a backup file of all data.
Page 20
The file version and device name of the selected backup file will be displayed.
If the backup file name is not the name as shown below, the equipment cannot restore the data from the backup files. - Address Book: BACKUP_ADDR<date>.tbf - MailBoxes: BACKUP_MBOX<date>.enc - Template: BACKUP_TEMP<date>.enc - Combined Backup: BACKUP_ALL<date>.enc
Click [Upload].
Select the check box of data that you uploaded a backup file and click [Restore].
The restore process begins. This procedure may take several minutes.
Page 21
Reset FUNCTION LIST FOR MAINTENANCE (1) Print out the FUNCTION LIST FOR MAINTENANCE list after the formatting. P.4-12 "[B] Print out FUNCTION LIST FOR MAINTENANCE" While pressing [1] and [3] simultaneously, turn the power ON. (Function Mode) Compare the lists which were printed before and after the formatting to check the setting items having the different setting values. Set the value which was set before the formatting Turn the power OFF. Turn the power OFF.
(2) (3)
(4)
Reset FUNCTION list Reset the fax function by referring to the function list that was printed out in [C] Print out function list. (1) (2) (3) Press the [USER FUNCTIONS] button. Press the [ADMIN] button, enter the password, and then press the [ENTER] button. Press the [FAX] button and then the [TERMINAL ID] button to set each item.
(4) Press the [INITIAL SETUP] button to set each item. Note: Explain to the user (machine administrator) about the next operation and ask him/her to enter his/her password.
Page 22
IMPORTANT This section requires a USB key with the latest firmware on it for the model(s) you will be working on. The firmware can be obtained from the Tech-To-Go section of FYI. The firmware always has the latest instructions for installation.
Basic Security Remove original HDD and give to Customer, install new HDD, Clean SRAM and FAX
1) Turn on the machine while pressing the Clear and 3 keys. Release them after you hear a beep. 2) Press the 4 key (SRAM DATA FORMAT) and press START. 3) A message will be displayed on the touch screen saying SRAM DATA FORMAT COMPLETED. 4) Press the Power button to turn off the machine. 5) Turn on the machine while pressing the 0 and 8 keys. Release them after you hear a beep. 6) The touch screen will display a message saying SRAM ERROR DOES NOT INITIALIZE and display a list of machine versions below it. The USA machines are called NAD and is next to number 1. 7) Press the number 1 on the 10 key pad and press the START button. 8) The machine will display on the touch screen ARE YOU SURE and you will press the INTERRUPT button on the control panel. 9) The machine will automatically return to the 08 test mode. 10) Key in code 692 and press START and calibrate the touch screen. 11) Key in code 693 and press START and initialize the NIC. 12) Key in code 995 and press START and ENTER the machine serial number located on the back of the machine. 13) Key in code 690 and press START and initialize the HDD. 14) Press the Power button to turn off the machine. 15) Turn on the machine while pressing the 1 and * keys. Release them after you hear a beep. 16) Key in code 100 and press START and initialize the FAX Setup. 17) Key in code 102 and press START and initialize the FAX image data. 18) Press the Power button to turn off the machine.
Page 23
19) Remove the existing machine HDD and give it to the customer. Please record the machine Serial Number and the HDD Serial Number and have the customer sign a document showing they received it and have taken ownership of the drive. Make sure the document is dated. 20) Install a new HDD into the machine. 21) Turn on the machine while pressing the Clear and 3 keys. Release them after you hear a beep. 22) Press the 3 key (All Partition Delete and create loader partition) and press START A message will be displayed first saying Initializing HDD table then Initialization Completed. 23) Press the Power button to turn off the machine. 24) Insert a USB key with the appropriate machine firmware into the USB slot on the machine. 25) Turn on the machine while pressing the 9 and 4 keys. Release them after you hear a beep. 26) Select all of the firmware options and press START. When the firmware has completed updating it will display Update Completed 27) Press the Power button to turn off the machine. 28) Turn on the machine while pressing the 0 and 8 keys. Release them after you hear a beep. 29) Key in code 947 and press START and initialize the firmware. 30) Key in code 690 and press START. 31) On the touch screen press INITIALIZE. 32) The touch screen will display WAIT. Once the HDD is properly formatted the touch screen will display REBOOT THE MACHINE. 33) Press the Power button to turn off the. 34) Remove any network or phone cables from the machine and using the Power Switch to turn on the machine. 35) After the machine comes to ready, make a copy to ensure the machine is functioning properly. 36) Use the Power button to turn off the machine then turn off the Power Switch.
Page 24
Page 25
25) Turn on the machine while pressing the 0 and 8 keys. Release them after you hear a beep. 26) The touch screen will display a message saying SRAM ERROR DOES NOT INITIALIZE and display a list of machine versions below it. The USA machines are called NAD and is next to number 1. 27) Press the number 1 on the 10 key pad and press the START button. 28) The machine will display on the touch screen ARE YOU SURE and you will press the INTERRUPT button on the control panel. 29) The machine will automatically return to the 08 test mode. 30) Key in code 692 and press START and calibrate the touch screen. 31) Key in code 693 and press START and initialize the NIC. 32) Key in code 995 and press START and ENTER the machine serial number located on the back of the machine. 33) Key in code 690 and press START and initialize the HDD. 34) Press the Power button to turn off the machine. 35) Turn on the machine while pressing the 1 and * keys. Release them after you hear a beep. 36) Key in code 100 and press START and initialize the FAX Setup. 37) Key in code 102 and press START and initialize the FAX image data. 38) Press the Power button to turn off the machine. 39) Remove any network or phone cables from the machine and using the Power Switch to turn on the machine. 40) After the machine comes to ready, make a copy to ensure the machine is functioning properly. 41) Use the Power button to turn off the machine then turn off the Power Switch.
Page 26
Optimal Security Data Overwrite Kit, Clean SRAM and FAX and return cleaned original HDD to the customer
1) Turn on the machine while pressing the 0 and 8 keys. Release them after you hear a beep. 2) Key in code 1426 and press START. 3) The touch screen will display the following message Are You Sure. 4) On the touch screen touch INITIALIZE. 5) The machine will display the following message HDD ERASE RUNNING and display how much of the HDD has been erased as a percentage( ie.. 12%). DO NOT turn off the machine until this percentage reaches 100% and the machine stops and displays the following message HDD ERASE RUNNING. The HDD has now been erased to a minimum of DOD 522022-M standards. 6) Use the Power switch to turn off the machine. 7) Remove the existing machine HDD and give it to the customer. Please record the machine Serial Number and the HDD Serial Number and have the customer sign a document showing they received it and have taken ownership of the drive. Make sure the document is dated. 8) Install a new HDD into the machine. 9) Turn on the machine while pressing the Clear and 3 keys. Release them after you hear a beep. 10) Press the 3 key (All Partition Delete and create loader partition) and press START A message will be displayed first saying Initializing HDD table then Initialization Completed. 11) Press the Power button to turn off the machine. 12) Insert a USB key with the appropriate machine firmware into the USB slot on the machine. 13) Turn on the machine while pressing the 9 and 4 keys. Release them after you hear a beep. 14) Select all of the firmware options and press START. When the firmware has completed updating it will display Update Completed 15) Press the Power button to turn off the machine and remove the USB key. 16) Turn on the machine while pressing the 0 and 8 keys. Release them after you hear a beep. 17) Key in code 947 and press START and initialize the firmware. 18) Key in code 690 and press START. 19) On the touch screen press INITIALIZE. 20) The touch screen will display WAIT. Once the HDD is properly formatted the touch screen will display REBOOT THE MACHINE. 21) Press the Power button to turn off the machine. 22) Turn on the machine while pressing the Clear and 3 keys. Release them after you hear a beep. 23) Press the 4 key (SRAM DATA FORMAT) and press START. 24) A message will be displayed on the touch screen saying SRAM DATA FORMAT COMPLETED.
Page 27
25) Press the Power button to turn off the machine. 26) Turn on the machine while pressing the 0 and 8 keys. Release them after you hear a beep. 27) The touch screen will display a message saying SRAM ERROR DOES NOT INITIALIZE and display a list of machine versions below it. The USA machines are called NAD and is next to number 1. 28) Press the number 1 on the 10 key pad and press the START button. 29) The machine will display on the touch screen ARE YOU SURE and you will press the INTERRUPT button on the control panel. 30) The machine will automatically return to the 08 test mode. 31) Key in code 692 and press START and calibrate the touch screen. 32) Key in code 693 and press START and initialize the NIC. 33) Key in code 995 and press START and ENTER the machine serial number located on the back of the machine. 34) Key in code 690 and press START and initialize the HDD. 35) Press the Power button to turn off the machine. 36) Turn on the machine while pressing the 1 and * keys. Release them after you hear a beep. 37) Key in code 100 and press START and initialize the FAX. 38) Key in code 102 and press START and initialize the FAX. 39) Press the Power button to turn off the machine. 40) Remove any network or phone cables from the machine and using the Power Switch to turn on the machine. 41) After the machine comes to ready, make a copy to ensure the machine is functioning properly. 42) Use the Power button to turn off the machine then turn off the Power Switch.
Page 28
Note:
If you have questions about any of the procedures you can refer to the appropriate Service Handbook and or the installation instruction included with each option. The latest handbooks and installation instructions can be found on the Tech-To-Go section of FYI.
Version 1.0
Page 29