WorkCentre 7220-7225 Information Assurance Disclosure PaperVer. 1.0, January 2013 Page 35 of 613.3. System Accounts3.3.1. PrintingThe device may be set up to connect to a print queue maintained on a remote print server. The login name andpassword are sent to the print server in clear text. IPSec should be used to secure this channel.3.3.2. Network ScanningNetwork Scanning may require the device to log into a server. The instances where the device logs into a server aredetailed in the following table. Users may also need to authenticate for scanning. This authentication is detailed insubsequent sections.3.3.2.1. Device log onScanning feature Device behaviorScan to File, Public Template The device logs in to the scan repository as set up by the SA in theProperties tab on the WebUI.The credentials may be the user’scredentials or system credentials.Scan to E-mail, I-Fax The device logs into an LDAP Server as set up by the SA in User Tools. Itwill log into the Server when a user is authenticated and the device isconfigured for Remote Authorization or Personalization is enabled, andwhen the user attempts to access LDAP based scan-to-email addressbooks. At the time the LDAP server must be accessed, the device will loginto (bind to)_ the LDAP server.The device uses a simple bind to the LDAP server unless the device wasable to obtain a TGS for the LDAP server from the Kerberos Servier. Inthis case a SASL (GSSAPI) bind is performed.. A network username andpassword may be assigned to the device. The device logs in as a normaluser, with read only privileges. User credentials may be used ifconfigured by the SA for this authentication step.The device then logs into the SMTP server as set up by the SA in theProperties tab on the WebUI.The credentials may be the user’scredentials or system credentials.Scan to Fax Server The device logs in to the Fax Server as set up by the SA from theProperties tab on the WebUI. The credentials may be the user’scredentials or system credentials.Please note that when the device logs into any server the device username and password are sent over the network inclear text unless:• SSL has been enabled• IPSec has been configured to encrypt the traffic• The device is logging into an SMB Server in which case the credentials are hashed.• The device is using NTLM to login to the SMTP server (the device negotiates the most secure authenticationmethod that both the device and server support).• The LDAP server is being accessed via SASL.3.3.2.2. Scan Template ManagementThis is a web service that allows the SA to manage templates stored in a remote template pool. The connection tothe remote pool can be secured with SSL.