Xerox 701P40211 manual User Account Management, Remote shell internet service

Page 35

System Guide

Security and Network Setup

Remote shell internet service

If you are using the legacy Xerox print command line client (the software is not distributed with this release), you will need to use the remote shell internet service to transfer files to the DocuSP controller. However, if you are not using the print command line client, it is strongly recommended that the remote shell internet service is disabled. When these three questions are answered, all remaining aspects of the "high" security setting are implemented.

disable-security and enable-security scripts

To disable security, run the disable-security script. It restores the system to the state it was before configure-xdss was run.

The enable-security script was designed as a companion to configure-xdss. It configures all of the changes in the “high” security setting, with the exception of the three questions asked by the configure-xdss script (anonymous LP, DigiPath, rsh).

enable-ftp and disable-ftp scripts

These scripts allow for enabling and disabling FTP alone. You must have FTP enabled when using a Continuous Feed system, or DigiPath Production Print and NetAgent.

FTP is also required for the iGen Call For Assistance (CFA) feature. This uses FTP to push IOT logs and a DocuSP outload back to the DocuSP controller.

enable-remote-diagnostics/disable-remote-diagnostics scripts

The enable-remote-diagnostics script re-enables the asppp daemon (asynchronous Point-to-Point Protocol), which is required for modem dial-in. The script also re-enables FTP and telnet because they are used in dialup sessions. All three of these services are disabled when the security setting is "High". The disable script disables them.

User Account Management

The following UNIX accounts are defined during the installation process:

Common Controller

4-11

Image 35
Contents Xerox Document Services Platform Series USA Table of Contents Table of Contents Fonts PrintingFinishing Accounting and Billing TroubleshootingHints and Tips Table of Contents Table of Contents System Guide Viii About this guide ContentsIntroduction Customer Support ConventionsInternet Services Http Gateway Configuration Gateway ConfigurationGateway IPP Gateway ConfigurationType cd /opt/XRXnps/XRXipp Administrator must enable Snmp in License Manager Simple Network Management Protocol Snmp ConfigurationSnmpdebuglog Configuration variablesSnmp MIB Support Printer and job messagesGateway Configuration System Guide Type cd /opt/XRXnps/XRXnwqsgw/bin NDS SetupGateway Configuration System Guide Common Controller Backup Backup and RestoreRestore Backing up a System Restoring a System Type restoreAccess and Security Security and Network SetupChanging the logon level Overview of SecurityXerox responsibility User Password changesRoles and responsibilities DocuSP 3.7 security changes Security SetupUsing the High security setting Security and Network Setup System Guide User level User and File-level changesSendmail daemon secured Multicast routing disabledSolaris file permissions secured OS and host information hiddenNFS port monitor restricted Network parameters secured Executable stacks disabledRemote CDE login disabled DocuSP router capabilities disabledDisabling LP Anonymous Printing Configure-xdss scriptDigiPath and Decomposition Services Xdss script componentsUser Account Management Remote shell internet serviceDisable-security and enable-security scripts Enable-ftp and disable-ftp scriptsPrint command line client from remote systems Other security tips Configure for xrxusrOnline help for security Document and backupSample of inetd.conf file # Syntax for TLI-based Internet services # only on machines acting as boot servers Orstream or dgram #rexd/1 tli rpc/tcp wait root /usr/sbin/ rpc.rexd rpc.rexd How Do I? Answer Quick referenceHow Do I? Answer First In/First Out Fifo Printing Controller settings for limited Fifo scheduling/printingPrinting ‘Enabling Fifo Job Scheduling’ Enable/Disable Fifo Job Scheduling‘No Change Made’ Enabled DisabledSetpclcontrol Utility Ascii and PCL Printing UtilityImpact on DocuSP printers Set lp/lprcopycount utility # ./setVPSoption -2NONVPS Socket Gateway Configuration Utility setVPSoptionPerformance considerations Tiff filesTiff orientation T4 Option Resolution UnitsSupported Tiff tags CompressionTile Width, Tile Length, Tile Offsets, Tile Byte Counts Micr EnablementY Resolution Strip Byte Counts and Strip OffsetsPaper Trays Using VippPrinting hints Printing System Guide Common Controller DocuTech FinishingSubset Finishing Subset Offset Page Level Jog Creating jobs to use subset finishingPCL Offset/Separator/Subset Finishing command Large Capacity ESC&15H Envelope Feed ESC&16H PCL Paper Source CommandMixed Stacking Additional finishing information Finishing System Guide Common Controller Fonts How to choose fontsFonts PostScript Resident Fonts Font download optionResident Fonts System GuideFonts FontsSystem Guide PCL resident fonts Downloaded fonts PCL 5e resident bitmap fontsNon Resident Fonts PostScript fonts Optional or soft fontsFont substitution PCL 5e fonts Accounting exported values Accounting and BillingAccounting Auto exporting accounting logAccounting file fields System Guide Accounting and Billing Bytes Skipped SecondsRead ProcessedAccounting and Billing System Guide Pages Printed Sheets PrintedAccounting and Billing System Guide Billable Events BillingMarket Region Billing Meters for Region Billing MetersDeclared faults TroubleshootingCalling for service Job fault Undeclared faultsPrinter fault Macintosh problems Client problemsWindows problems GUI problems DigiPath problemsFont problems Print Quality problemsAt the # prompt, typesync sync halt and press Enter Inoperable system problemsJob flow problems System Guide Troubleshooting PostScript problems Job Integrity problemsPDL problems Tiff problems Restore password Problems when saving a job Restart DocuSP software without rebootingProductivity and performance problems Statuslog Printing system logsAlljobslog SystemlogPrinting the system logs Epexceptionlog and epprimarylogType sync sync halt Rebooting and restartingPrinting the accounting log Opt/XRXnps/bin/XJDC -option,option... filename Loading XJDC/UnixXjdc Hints and Tips Configuring XJDC/UnixBASIC.JSL Output filesTroubleshooting System Guide General Hints and TipsTime used to transfer PDL Color SystemsGeneral Comments Time used to generate the PDLGateways Time required to print PDLJob submission hints Number of images EthernetVariable data Job submission orderJob RIP Hints Image Quality Skipped Pitches Job Printing HintsPerform a Trace PCI Channel Interface PWB Trace Capture ProcedureExport the trace file to floppy Numerics IndexIndex System Guide INDEX-3 Index INDEX-4 System Guide