HP 635n HP Jetdirect Print Server Administrator's Guide - Page 101

SNMP, SNMP v3, Encrypt All Web Communication, Con Medium

Page 101 highlights

Internet Printing Protocol (IPP) use, other non-secure communications (HTTP) are redirected to HTTPS. Redirection of your browser to use HTTPS may be transparent depending on your browser's capabilities. By factory default, unlike prior HP Jetdirect print servers, HP Jetdirect 635n print servers are configured to require HTTPS only. Although not recommended, you may choose to accept both HTTPS and HTTP communications that are not secure by disabling (clearing) the Encrypt All Web Communication checkbox. To support the use of HTTPS communications, a Jetdirect certificate must be installed. A factorydefault, self-signed certificate is preinstalled for initial use. Click the Configure button to update the preinstalled certificate, or to install a new one. For more information, see Configuring Certificates. The minimum encryption strength that will be allowed must be specified when using a Jetdirect certificate. You may select Low (default), Medium, or High encryption strength. For example, selecting Low will allow medium or high encryption levels to be used whereas selecting High will only allow high encryption levels. For each encryption strength, ciphers are specified to identify the weakest cipher allowed. NOTE Cipher suites support different levels of encryption strength. The cipher suites currently supported for encryption and decryption are DES (Data Encryption Standard, 56-bit), RC4 (40-bit or 128-bit), and 3DES (168-bit). SNMP Use this tab to enable or disable SNMP v1, v2c and v3 agents on the print server, depending on the print server model. For a description of SNMP selections, see Table 4-11 SNMP Settings. SNMP v3 Full-featured HP Jetdirect print servers include an SNMP v3 (Simple Network Management Protocol, version 3) agent, for enhanced SNMP security. The SNMP v3 agent employs a User-based Security Model for SNMP v3 (RFC 2574), which features user-authentication and data privacy through encryption. The SNMP v3 agent is enabled when an initial SNMP v3 account on the print server is created. Once the account is created, any SNMP management application, if properly configured, can access or disable the account. CAUTION If you use HP Web Jetadmin to manage your devices, you should use HP Web Jetadmin to seamlessly configure SNMP v3 and other security settings on the print server. Using the embedded Web server to create the SNMP v3 account will erase any existing SNMP v3 accounts. In addition, the SNMP v3 account information will need to be implemented on the SNMP management application. You may create the initial account by specifying the HMAC-MD5 authentication and CBC-DES data privacy encryption keys used by your SNMP v3 management application. ENWW Networking Tab 91

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194

Internet Printing Protocol (IPP) use, other non-secure communications (HTTP) are redirected to
HTTPS. Redirection of your browser to use HTTPS may be transparent depending on your browser's
capabilities.
By factory default, unlike prior HP Jetdirect print servers, HP Jetdirect 635n print servers are
configured to require HTTPS only.
Although not recommended, you may choose to accept both HTTPS and HTTP communications that
are not secure by disabling (clearing) the
Encrypt All Web Communication
checkbox.
To support the use of HTTPS communications, a Jetdirect certificate must be installed. A factory-
default, self-signed certificate is preinstalled for initial use. Click the
Configure
button to update the
preinstalled certificate, or to install a new one. For more information, see
Configuring
Certificates
.
The minimum encryption strength that will be allowed must be specified when using a Jetdirect
certificate. You may select
Low
(default),
Medium
, or
High
encryption strength. For example,
selecting
Low
will allow medium or high encryption levels to be used whereas selecting
High
will
only allow high encryption levels.
For each encryption strength, ciphers are specified to identify the weakest cipher allowed.
NOTE
Cipher suites support different levels of encryption strength. The cipher suites
currently supported for encryption and decryption are DES (Data Encryption Standard, 56-bit),
RC4 (40-bit or 128-bit), and 3DES (168-bit).
SNMP
Use this tab to enable or disable SNMP v1, v2c and v3 agents on the print server, depending on the
print server model. For a description of SNMP selections, see
Table
4-11
SNMP
Settings
.
SNMP v3
Full-featured HP Jetdirect print servers include an SNMP v3 (Simple Network Management Protocol,
version 3) agent, for enhanced SNMP security. The SNMP v3 agent employs a User-based Security
Model for SNMP v3 (RFC 2574), which features user-authentication and data privacy through
encryption.
The SNMP v3 agent is enabled when an initial SNMP v3 account on the print server is created. Once
the account is created, any SNMP management application, if properly configured, can access or
disable the account.
CAUTION
If you use HP Web Jetadmin to manage your devices, you should use HP Web
Jetadmin to seamlessly configure SNMP v3 and other security settings on the print server.
Using the embedded Web server to create the SNMP v3 account will erase any existing
SNMP v3 accounts. In addition, the SNMP v3 account information will need to be
implemented on the SNMP management application.
You may create the initial account by specifying the HMAC-MD5 authentication and CBC-DES data
privacy encryption keys used by your SNMP v3 management application.
ENWW
Networking Tab
91