ConnectKey WorkCentre Product Enhancements Read Me-R20-04
ConnectKey WorkCentre Product Enhancements Read Me-R20-04
WorkCentre® Product
Enhancement Read Me
Description of new features and enhancements to the products specified below.
i
Contents
ii
6. CERTIFICATE DOESN'T UPDATE AFTER IP ADDRESS RENEWAL. .............................................................................. 5
7. PRINTER UNABLE TO RESOLVE SMTP HOST NAME VIA DNS WITH SERVER 2012 OR 2016 .................................... 5
8. ENABLEMENT FOR POP3 OVER SECURED CONNECTION (TLS). ................................................................................ 5
9. HIDE NETWORK TROUBLESHOOTING ........................................................................................................................... 7
Firmware 073.xxx.008.05210 March 2018 ................................................................................. 8
1. DEVICE BEHAVIOR IMPROVEMENTS ............................................................................................................................. 8
2. XEROX DROPBOX APP BLANK SCREEN ....................................................................................................................... 8
Firmware 073.xxx.247.32400 December 2017 ........................................................................... 8
1. XEROX DROPBOX APP BLANK SCREEN ....................................................................................................................... 8
2. DEVICE BEHAVIOR IMPROVEMENTS ............................................................................................................................. 8
Firmware 073.xxx.197.28500 October 2017............................................................................... 8
1. PIV CARD SUPPORT ......................................................................................................................................................... 8
2. SIMPLIFIED CHINESE LANGUAGE SUPPORT ................................................................................................................ 8
3. XEROX® LOCKDOWN SECURITY SOLUTION / HEALTHCARE LOCKDOWN SOLUTION........................................... 10
4. LONG MEDIA SOLUTION ................................................................................................................................................ 12
Firmware 073.xxx.177.14300 June 2017...................................................................................13
1. CLONING WEB SERVICE ................................................................................................................................................ 13
2. EIP AUTHENTICATION .................................................................................................................................................... 13
3. DISABLE PRINT SUBMISSION OF CLONE FILES ......................................................................................................... 13
5. DISABLE SNMP SETS ..................................................................................................................................................... 13
6. XML CONFIGURATION REPORT .................................................................................................................................... 13
7. ABILITY TO HIDE USERNAME FOR SECURITY REASONS .......................................................................................... 13
8. DUPLEX COLOR SCANNING OPTIONS ......................................................................................................................... 14
9. NETWORK TROUBLESHOOTING LOG .......................................................................................................................... 14
Firmware 073.xxx.147.07400 March 2017 ................................................................................16
1. INTER JOB OFFSET DISABLEMENT .................................................................................................................................. 16
Firmware 073.xxx.136.34300 December 2016 ..........................................................................17
1. IMPROVE HOLD ALL JOBS SECURITY WHEN LOGGING OUT ........................................................................................ 17
2. PAUSE SYSTEM TIMER WHILE PRINTING ........................................................................................................................ 17
Firmware 073.xxx.106.26100 September 2016 .........................................................................17
1. CUSTOM ADMINISTRATOR SOLUTION ............................................................................................................................. 17
Firmware 073.xxx.086.15410 June 2016...................................................................................19
1. BILLING METER READ EMAIL SETUP ............................................................................................................................... 19
Firmware 073.xxx.066.08210 April 2016 ...................................................................................21
1. WAKE ON SWIPE ................................................................................................................................................................ 21
2. SCAN TO DESTINATION SETUP TEST BUTTON ............................................................................................................... 22
iii
Firmware 075.xxx.010.12010 May 2020
1. Blackboard Card Reader PS4101
Blackboard Card Reader PS4101 USB Smartcard Reader is supported in this release.
• The issue with "Delete All print jobs at Power On" has been corrected.
1
2. Additional Smart Cards Supported
Giesecke & Devrient SmartCafe Expert v7.0 144K DI smart card with CAC 2.7.6 Applet (STOPGAP)
Giesecke & Devrient Sm@rtCafe Expert v7.0 144K DI smart card with PIV Applet is now supported.
IDEMIA Cosmo v8 (NEATS) smart card (NEATS) Smartcard Support
SHAC support for SafeNet SC650 v4.1 (3v) Smartcard. The SHAC middleware support is provided
for SafeNet SC650 card, ATR: 3b ff 14 00 ff 81 31 fe 45 80 25 a0 00 00 00 56 57 53 43 36 35 30 04
01 3d with the following requirements:
• Email signing and encryption are not supported
• FIPS must be disabled
• Feature Installation Key must be installed:
o Install Key: 227334773923
o Uninstall Key: 227434773923
• A Cherry TC-1100 Card Reader must be connected. (This is the recommended Reader)
2
Firmware 073.xxx.019.13010 May 2019
1. EIP ability to request LDAP user attributes to include in user session data.
Added the EIP ability to request sAMAccountName & userPrincipalName from LDAP as part of
the xrxSessionGetSessionInfo() call in the Session Web service to include in the user session
data.
This method allows a client to retrieve information about the currently logged in user. It returns a
block of XML data that is defined by the SessionInfoSchema.xsd. An optional parameter can be
passed in to request a list of LDAP attributes from the MFD.
Note: Other LDAP values may become available in the future, but for now only
sAMAccountName & userPrincipalName are available.
Note: For the GetSessionInformation request to return info for sAMAccountName &
userPrincipalName the following must be true on the MFD being used:
• The EIP version must be 4.1.4+ or 3.5.7+ (EIP 3.7.X not supported)
• LDAP must be configured on the MFD
• LDAP must be the Login Method on the MFD
• An LDAP user must be logged in at the MFD
.
2. Enablement of Cherry ST-1144 Smartcard Reader
Cherry ST-1144 USB Smartcard Readers are supported in this release.
3
the feature is hidden until it is activated by purchase of the kit and installation of a Feature
Installation Key (FIK).
The Xerox® Lockdown Security Solution permanently enhances certain security aspects of the
Xerox® WorkCentre® Devices by encrypting the hard drive, overwriting hard drive data
immediately after use, preventing jobs from being stored on or printed from USB devices,
recording who has used the device and how they used it and providing additional controls
designed to protect specific Xerox® networked and non-networked devices against malicious
attacks.
Refer to description in Firmware 073.xxx.197.2850 October 2017 for more details.
Note: Either FIPS or Email Signing must be disabled to send Email successfully.
4
If any email signing with these new cards is required, a Xerox technician will be needed to upgrade
the device.
2. Message stating device in energy saver mode after card swipe
Fixed an intermittent issue of UI message stating device in energy saver mode after authentication
card swipe. A power cycle was required to clear this message.
3. Device freezes when waking up from power saver mode
Fixed an issue of device lock ups when waking up. A power cycle was required to revive the device.
7. Printer unable to resolve SMTP host name via DNS with Server 2012 or 2016
Fixed an issue in scan to email when the smtp server was set as Host, the device could not resolve
to the IP.
5
2. Go to Properties>Connectivity>Setup
3. Select Edit for POP3.
4. Check the Pop3 Over Secure Connection (TLS) checkbox and notice that the Validate
Server Certificate checkbox is automatically checked, and the POP3 Server port value
has defaulted to Port 995.
Note: A port value of 995 is not permitted with an unsecure connection. It is recommended to
upload Trusted Root /Intermediate certificates to the device for certificate validation.
5. Enter your POP3 Server IPv4 Address or Host Name.
6. Enter Login Name and Password.
7. Enter password again under Retype password and check the Select to save new
password checkbox.
8. Select Save
6
9. Hide Network Troubleshooting
Overview: These WorkCentre Devices have added the ability to permanently remove the Network
Troubleshooting feature.
Note: This will permanently remove the Network Troubleshooting feature from the device.
There are two methods to remove this feature from the device.
The first method is a button called Permanently Remove this Function on the Network Troubleshooting
page. This will allow an Administrator to remove the feature. The button is located on the WebUI under
Properties, Security, Logs, Network Troubleshooting page. Below is an image of the page.
The second method is to install a Feature Installation Key (FIK) on the WebUI under Properties, General
Setup, Feature Installation. Then select Enter Installation Key.
The FIK key for permanently removing the Network Troubleshooting feature is 468854198391
7
Firmware 073.xxx.008.05210 March 2018
1. Device Behavior Improvements
Various improvements have been made in the areas of:
• A fix was added to mitigate the UI screen displaying login screen when authentication is not
enabled.
• Large PDF printing has been improved to reduce occurrences of fault codes displayed.
• PDL switching over port 9100 is now more robust.
This release adds support for the following additional Gemalto IDPrime PIV
(Personal Identify Verification) format SmartCards:
• Gemalto TOP DL - protiva PIV applet V1.55
• Gemalto TOP DL V2 – protiva PIV applet V1.55
The ConnectKey® WorkCentre® 7855 XOM devices will be able to support Simplified Chinese language
via either of the following two modes:
• Set Simplified Chinese as the default language/keyboard: The default language/keyboard on the
device can be set to Simplified Chinese via the user interface Language/Keyboard setting. This
setting is accessible to an Admin via: Machine Status > Device Settings > General > Language/
Keyboard Selection. Setting the default language to Simplified Chinese will also set printed reports
and banner sheets to appear in this language.
8
Note: A user can change the current session display language and keyboard to any other language
via the ‘Language’ Hard button on the control panel.
• Select Simplified Chinese language/keyboard for current session only: The default
language/keyboard can be set to any other language and a User can select the Language hard
button on the console to select Simplified Chinese for their current session only. Enabling Simplified
Chinese via the Language button will only last until the user interface session timeout or user logout
at which point the device will revert to the default language configured by the Admin. This mode of
operation does not affect printed reports and banner sheets.
9
3. Xerox® Lockdown Security Solution / Healthcare Lockdown Solution
The Xerox® Lockdown Security Solution was previously known as Xerox ® Healthcare Lockdown Solution,
initially introduced with Firmware 073.xxx.197.2850 October 2017.
Note: The Xerox® Lockdown Security Solution kit part number 301K33790 can be ordered by contacting
your Xerox® account representative.
Installation of this release enables a device Administrator to install the purchasable Xerox ® Lockdown
Security Solution on a device. While the Solution content is contained in this release, the feature is
hidden until it is activated by purchase of the kit and installation of a Feature Installation Key (FIK).
The Xerox® Lockdown Security Solution permanently enhances certain security aspects of the Xerox ®
WorkCentre® Devices by encrypting the hard drive, overwriting hard drive data immediately after use,
preventing jobs from being stored on or printed from USB devices, recording who has used the device
and how they used it and providing additional controls designed to protect specific Xerox ® networked and
non-networked devices against malicious attacks.
10
How the Xerox® Lockdown Security Solution Works:
The Lockdown Security Solution performs the following functions:
“Locks-down” a set of security settings on the printer as the name implies, making them unchangeable to
anyone including the system administrator and raises the bar on printer security. The security settings
that Xerox® Lockdown Security Solution permanently controls:
a. User Data Encryption is enabled which AES encrypts all partitions of the hard drive that may contain
customer data.
b. Immediate Job Overwrite is enabled which deletes and overwrites disk sectors that temporarily
contained electronic image data conforming to NIST Special Publication 800-88 Rev1.
c. Scheduled Disk Overwrite is enabled on a daily basis at a time that is selectable. This deletes and
overwrites every sector of any partitions of the hard drive that may contain customer data.
d. McAfee® Embedded Control is set to Enhanced Security (or McAfee® Integrity Control™ if this
option has been purchased) to protect against threats to confidential data by use of whitelisting
technology that allows only approved files to run.
e. Audit Log is set to record information about who has used the device and how they have used it, as
well as the chronology to help track the events that have occurred.
f. Print from USB is disabled preventing the printing of any files that are stored on a USB Flash Drive
from the USB port on the printer control panel.
g. Scan to USB is disabled preventing scanning of a document and storing the scanned file on a USB
drive.
• Monitors these security settings on a daily basis to ensure that they have not been changed
maliciously.
• Restores any of these settings automatically back to the compliant state if the Monitor found any to be
non-compliant.
• Reports the compliance state of the machine via email and/or printed reports:
Once the Feature Installation Key is installed, a Lockdown control panel is made available and added to
the list of Security functions for the MFP via both Embedded Web Server and Local UI.
The Administrator can determine the time of day the Monitor will run, the frequency of printed and /or
emailed confirmation reports, set the action text that appears on the printed confirmation reports that
directs the user where to deliver the printed reports and perform Monitor “Check Now” and Error
Simulation” to test the operation.
11
4. Long Media Solution
New system policy to influence how the scanner handles “long” media when it is unable to identify the
page size.
This setting can be found under:
General Setup > Paper Management > Required Paper Policies / Default Legal Size. Systems primarily
being used to scan or copy 8.5 x 13.4” will want to set this new policy to use 8.5 x 13.4” as the default
legal [scan] size.
Note: There are limitations with both the trays and the scanner in regards to being able to differentiate
the new 8.5 x 13.4” size from sizes slightly smaller (e.g. 8.5 x 13”) or slightly larger (e.g. 8.5 x 14”).
There may still be use cases that require the target tray or size be manually specified by the user in order
to ensure the system copies to the desired size media.
12
Firmware 073.xxx.177.14300 June 2017
CentreWare Web will deliver compatible software for this ConnectKey solution that will Import, export and
manage clone files. CWW and ConnectKey will authenticate Network Users and verify User is in
appropriate Active Directory Group for device administration. CWW will schedule and push clone files to
individual and multiple Xerox devices with the user’s Network User ID and clone file description.
2. EIP Authentication
For EIP web service calls requiring administrator credentials, these ConnectKey devices will now add the
ability to authenticate the credentials against the Device Configuration for Network Authentication and for
the Device Administrator privileges. The authentication could be network (LDAP, Kerberos or SMB), or
the device user database, or ‘admin’.
13
8. Duplex Color Scanning Options
The single pass duplex scanner, on the WorkCentre® 7845/55 & 7970 may lead to inaccurate color
detection at low resolutions. New options to enable the scanner to scan at 600x600dpi are available. This
will allow for optimal color detection, but could negatively impact scanning performance.
• Select fastest scanning speed means that the device will scan at 600x300 whenever the user
selects 300dpi or lower
• Select best auto-color detection accuracy means the device will scan at 600x600 whenever the
user programs a job for 300dpi or lower with duplex scanning and auto-color selected, as well.
• Select best auto-color detection accuracy and color image quality means the device will scan at
600x600 whenever the user programs a job for 300dpi or lower with duplex scanning and auto-color
or fill color selected, as well.
Why an SA would change this: If they use accounting and account for mono scans differently than color
scans, they would want to change this setting. However, we expect most users will not notice a change in
system behavior if this setting is changed.
This new feature allows a device administrator to capture network communications directed to the device.
This feature is disabled by default, and only captures communications between the device and another
network node. It does not capture broadcast information or communications between other devices.
Additionally it can be limited to specific protocols. Note this data may contain authentication credentials or
other sensitive information. The feature enables administrators to analyze network traffic which can help
diagnose communications problems.
14
The Capability can be accessed through the Properties> Security> Logs> Network Troubleshooting OR
under Support> Troubleshooting> Network Troubleshooting tabs as shown below.
Note: File size of the Network Trace capture is limited to 10 MB.
Settings:
1. Settings shown above include setting the number of hours of capturing the trace from 1 to 48
hours.
2. Start Session Now begins the process of capturing network packet data.
3. Clear Session can be selected to clear the trace data and start a trace over.
4. Stop Session can be selected to stop a trace at a point in time but save the existing trace data.
5. Download Log Now can be selected to download the existing log file.
6. Maximum packet size can be customized, default is 1514 bytes
7. Customize Captured Port Filters can be selected to limit the trace selection to select Protocol,
Ports or limit to a specific Destination IP Address as shown below.
8. Be sure to select Save before beginning data capture.
9. Encrypted communications will not be decrypted in the log.
10. Downloaded file has .pcap extension,
11. Default All can be selected to return the Customize Capture Port Filters to their Default values.
15
Each Protocol can be edited to customize protocol name or select a specific port.
Additional custom protocols can be added.
This adds the ability to disable job offset (the offset between jobs). A new setting was added to CWIS
that controls Job Offset for all jobs independent of submission methods (e.g. Xerox Global Print Driver,
LPR, and CWIS).
This feature will now allow the ability to print jobs to the MFD as a single aligned stack on the output tray.
In CWIS, the Admin must navigate to Properties/Printing/General/ and set the Offsetting Between Jobs
feature to “No Offset Between Jobs” on the MFD.
Note: When submitting a print job through the print driver, to disable offsetting between sets, the user
must go to Printer Properties/Advanced/Offset Output and change the setting to No Offset.
16
Firmware 073.xxx.136.34300 December 2016
1. Improve Hold All Jobs Security When Logging Out
There is a new feature in Hold All Jobs which can prevent jobs from printing when the job owner is not
logged in. This policy builds on the current Hold All Jobs feature and applies to a specific user’s print jobs.
This new feature can automatically delete any in progress or pending print jobs if the job owner logs out
of the device. This can reduce the likelihood that jobs might be accessible to anyone other than the job
owner.
Enablement is done in CWIS. Go to Properties >Services >Printing>Hold All Jobs >When Users Logout
Occurs:
• Delete all jobs in queue
• Continue to print all jobs in queue
Example: If the policy is set to delete, when the User logs out any job printing or pending in the queue
belonging the logged out User will be deleted.
Hold All Jobs Enablement needs to be set to Hold Jobs in a Private Queue
A new feature that allows the printing to pause the system timer while a job is printing. This feature
prevents the User’s session from timing out during log print jobs. While a job is printing the system timer
will not be active. Once the job has finished printing, the system timer will start again.
This release enables a new level of Administrator called Custom Administrator. The Administrator can
create a Custom Administrator role, assign users to the role and select from a list of 21 permissible
features that the Custom Admin has permission to modify.
Custom Administrators rights are determined by the Admin. The Custom Admin is allowed to
create/manage logged-in user roles, but they cannot create/modify roles with Admin permissions or
device management roles.
Note:
• Custom Administrators permissions are determined by the Admin.
• Administration of the Custom Admin role can only be performed via CWIS.
• A Custom Admin is allowed to create/manage logged-in user roles, but they cannot create/modify
roles with Admin permissions or device management roles.
17
• Creating a Custom Admin role will delete the default “Logged-in user” Role if no other custom roles
have been previously created. See section 4 below to re-create the default “Logged-in user” Role
Note: The Custom Admin role Administration can only be performed via CWIS.
Note: Creating a Custom Admin role will delete the default “Logged-in user” Role if no other custom roles
have been previously created. See section 4 below.
18
Firmware 073.xxx.086.15410 June 2016
1. Billing Meter Read Email Setup
ConnectKey® WorkCentre® device Admins will be able to set and submit billing meter reports from the
device with an option of scheduled or manual email submission.
Note: Email feature is required and must be configured on the device to use this feature and you must
select Apply once all recipients and groups are created or the information will be lost when going to
another screen in CWIS.
Go to Properties> Alert Notification> Email Alerts and enter the email address you want the device to
send the report to. Individual recipient groups can be created and recipient group preferences can be
selected.
19
To Schedule or manually submit the billing meter report you must select Edit under Actions for Email
billing meters for manual submission.
20
Firmware 073.xxx.066.08210 April 2016
1. Wake on Swipe
The RFID Integrated Card Reader Alternative Power Retrofit Kit 497K18900 for WorkCentre® 78xx and
79xx products equipped with RFID Integrated Card Reader Kits that was previously announced is
currently unavailable. See caveats below as a result.
The “Wake on Swipe” capability introduces the ability to control the USB ports power state in sleep mode
giving the administrator the ability to separately set the front or rear USB ports as either 'powered' or 'not
powered' while in sleep mode. The 'powered' setting enables USB accessories connected to the USB
ports to function when the device goes to sleep such as:
21
Caveats:
• If adding a USB hub to the device, the device must be awake when the hub is plugged in to operate
properly.
• WorkCentre 78xx and 79xx: Front USB port power control is not currently supported on WorkCentre
78xx or 79xx. Kits that use the front USB port such as Xerox Integrated/Programmable RFID Reader
Kits do not support Wake on Swipe on this product.
Workarounds:
• Press Energy-Saver key on the keyboard to wake MFD, wait for MFD to wake, swipe card and login.
(replacing the workaround to the current caveat)
• CSE utilize the NVM switch to turn “Energy Saver off”
• CSE or admin set the “Sleep and Wake up at Scheduled time” to: Wake up before anyone arrives at
the work place, Sleep after everyone has left the work place.
• Install external RFID card reader that plugs into the rear USB port instead of Xerox Integrated /
Programmable RFID Reader Kit which uses the front USB port.
The Scan Destination Setup Test Button feature saves the Administrator time by providing the ability to
test, and then receive troubleshooting assistance while setting up scan destinations.
Prior to this feature enhancement the Administrator would set up the device but was unable to test it in
CWIS, leading to service/support calls. The Destination Test Button is available once the file destination
settings are entered and then selected.
Caveat: If using IPV6 addresses, the Scan Destination Test available on the Embedded
Web Server will incorrectly fail its Ping test even though the IPv6 address works in an actual scan if all
other settings are correct. For Scan Destination Test purposes please use either the hostname or an
IPV4 address.
© 2017 Xerox Corporation. All rights reserved. Xerox ® and Xerox and Design®, ConnectKey®
CentreWare® and WorkCentre® are trademarks of Xerox Corporation in the United States and/or other
countries. BR22808
Other company trademarks are also acknowledged.
22
Document Version: 1.0 (January 2018).
23