Xerox® Security Guide for Light Production Mono Class Products
6 Identification, Authentication, and Authorization
Legacy and D-Series® Copier/Printer products offer a range of authentication and authorization options to
support various environments.
Single Factor authentication is supported locally on the product or via external network authentication
servers (e.g. LDAP, Kerberos, ADS). Multi Factor authentication is supported by addition of card reader
hardware. (Where ease of access is desired, open access and simple user identification modes also
exist, however these are not recommended for secure environments.)
In all modes, product administrator accounts always require authentication. This cannot be disabled.
A flexible RBAC (Role Based Access Control) security model supports granular to assign of user
permissions. Once a user has been authenticated, the product grants (or denies) user permissions
based upon the role(s) they have been assigned to. Pre-defined roles that may be used or custom roles
may be created as desired.
Authentication
Legacy and D-Series® Copier/Printer devices support the following authentication mode:
Local Authentication
Network Authentication
Smart Card Authentication (CAC, PIV, SIPR, .Net)
Convenience Authentication
Service Technician Authentication
Local Authentication
The local user database stores user credential information. The printer uses this information for local
authentication and authorization, and for Xerox ® Standard Accounting. When you configure local
authentication, the printer checks the credentials that a user provides against the information in the user
database. When you configure local authorization, the printer checks the user database to determine
which features the user is allowed access.
Note: User names and passwords stored in the user database are not transmitted over the network
Password Policy
The following password attributes can be configured:
Legacy Printers
Legacy Copier/Printers D-Series® Copier/Printers
4110, 4112/4127, 4590
EPS
4110, 4112/4127, 4590
D95/D110/D125/D136
Password Policy
Minimum Length
1
1
1
Maximum Length
63
63
63
Password cannot contain User Name
Supported
Supported
Supported
Password complexity options (in addition
to alphabetic characters)
Require a number
Require a number
Require a number