HP 635n HP Jetdirect Print Servers - HP Jetdirect and SSL/TLS - Page 95

Which HP Jetdirect Products Support SSL/TLS?, Summary - firmware download

Page 95 highlights

physical user interface) and is probably stored right next to the digital certificate. In short, an analysis of the non-volatile storage of your embedded device may reveal more information than you want. When deploying certificates to embedded devices, there are several questions that you should ask the vendor: • Can the private keys be exported? • Can exporting private keys be prevented? • Is the private key password protected? • How is the password protected in non-volatile storage? • How is the digital certificate protected in non-volatile storage? • Does the embedded device meet any security standards regarding the handling of security information like passwords or digital certificates? • Can this information be securely erased when I no longer need the embedded device? Anytime you are deploying digital certificates to embedded devices, you need to be sure that you know the answers to these questions. When an embedded device leaves your physical possession, due to a hardware failure, warranty failure, theft, or simply selling them as used, the non-volatile storage may be able to be accessed and some information about your PKI or network could become available. The worse case is that the digital certificate could be obtained from a device no longer used and that digital certificate may be used to attack your network. Which HP Jetdirect Products Support SSL/TLS? HP Jetdirect has supported SSL/TLS for a long time. It is actually easier to answer this question in the negative. Here is a list of devices that are popular but do not support SSL/TLS • Any external parallel port print server does not support SSL/TLS. Common products are the 170X, 300X, 500X, and 510X. The firmware versions are X.08.XX or lower. • Any MIO products. The firmware versions are X.08.XX or lower. • The 600n series of EIO print servers - such as the J3113A 10/100. The firmware versions are X.08.XX or lower. • Value based products like the 175X (external USB) or the 200m (LIO). • The Embedded Jetdirect in value based products such as the CP4005n and HP Color LaserJet 3600n Here are some popular HP Jetdirect products that do support SSL/TLS. This is not a comprehensive list and, as always, be sure to upgrade your Jetdirect to the latest firmware available for the best experience (http://www.hp.com/go/wja_firmware). • EIO print servers 610n, 615n, 620n, 625n, 630n, 635n with the latest firmware. • External USB print server en3700 • Embedded Jetdirect products with the Jetdirect product number J7949E, J7982E, J7991E, J7997E, J7974E, and J7992E. You can get the product number of Embedded Jetdirect devices through Web Jetadmin or via the HP Download Manager. Summary Well, you've made it to the end. Hopefully, you've learned a lot about SSL/TLS and how it works on HP Jetdirect. Most importantly, know that when someone says their communication is secure because it uses SSL/TLS, you'll know that there are many more questions to ask before any actual statement about security can be made. Hope you enjoyed it! 95

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95

95
physical user interface) and is probably stored right next to the digital certificate.
In short, an analysis
of the non-volatile storage of your embedded device may reveal more information than you want.
When deploying certificates to embedded devices, there are several questions that you should ask the
vendor:
Can the private keys be exported?
Can exporting private keys be prevented?
Is the private key password protected?
How is the password protected in non-volatile storage?
How is the digital certificate protected in non-volatile storage?
Does the embedded device meet any security standards regarding the handling of security
information like passwords or digital certificates?
Can this information be securely erased when I no longer need the embedded device?
Anytime you are deploying digital certificates to embedded devices, you need to be sure that you
know the answers to these questions.
When an embedded device leaves your physical possession,
due to a hardware failure, warranty failure, theft, or simply selling them as used, the non-volatile
storage may be able to be accessed and some information about your PKI or network could become
available.
The worse case is that the digital certificate could be obtained from a device no longer
used and that digital certificate may be used to attack your network.
Which HP Jetdirect Products Support SSL/TLS?
HP Jetdirect has supported SSL/TLS for a long time.
It is actually easier to answer this question in the
negative.
Here is a list of devices that are popular but do
not
support SSL/TLS
Any external parallel port print server does not support SSL/TLS.
Common products are the
170X, 300X, 500X, and 510X.
The firmware versions are X.08.XX or lower.
Any MIO products. The firmware versions are X.08.XX or lower.
The 600n series of EIO print servers – such as the J3113A 10/100.
The firmware versions
are X.08.XX or lower.
Value based products like the 175X (external USB) or the 200m (LIO).
The Embedded Jetdirect in value based products such as the CP4005n and HP Color LaserJet
3600n
Here are some popular HP Jetdirect products that do support SSL/TLS.
This is not a comprehensive
list
and, as always, be sure to upgrade your Jetdirect to the latest firmware available for the best
experience (
).
EIO print servers 610n, 615n, 620n, 625n, 630n, 635n with the latest firmware.
External USB print server en3700
Embedded Jetdirect products with the Jetdirect product number J7949E, J7982E, J7991E,
J7997E, J7974E, and J7992E.
You can get the product number of Embedded Jetdirect
devices through Web Jetadmin or via the HP Download Manager.
Summary
Well, you’ve made it to the end.
Hopefully, you’ve learned a lot about SSL/TLS and how it works on
HP Jetdirect.
Most importantly, know that when someone says their communication is secure because
it uses SSL/TLS, you’ll know that there are many more questions to ask before any actual statement
about security can be made.
Hope you enjoyed it!