
●
Upload CA Certicate conguration option: Certicates must not be signed by using MD5 or earlier
(MD2 or MD4).
●
Mgmt Protocol conguration option: The SSL 3.0 or earlier protocol must not be enabled.
HP Web Jetadmin does not report the exact reason for the failure. However, if you enable FIPS-140 mode
by using the device HP Embedded Web Server (EWS), the EWS does report the exact reason for the failure.
The FIPS-140 mode setting is available in the EWS from the Networking tab > Security link > Settings page.
Enable FIPS on the HP Web Jetadmin server
1. Stop the following services. These services must be stopped in the specied order.
a. HPWSProAdapter
b. HPWJAService
c. mssql$HPWJA
2. Use the following steps to enable FIPS on the HP Web Jetadmin server as a local security policy:
TIP: For more information about the System cryptography setting, see the “System cryptography: Use
FIPS compliant algorithms for encryption, hashing, and signing" security setting eects in Windows XP and in
later versions of Windows document. This document is available from the Microsoft support page.
a. Go to Control Panel > Administrative Tools > Local Security Policy > Local Policies > Security Options.
b. Right-click System cryptography: Use FIPS compliant algorithms for encryption, hashing and signing,
and then select Properties.
c. On the Local Security Setting tab, select the Enabled option, and then click the OK button.
3. Start the following services. These services must be started in the specied order.
a. mssql$HPWJA
b. HPWJAService
c. HPWSProAdapter
4. Use the following steps to verify that HP Web Jetadmin can communicate with all of the devices:
a. In the All Devices list, look for any devices that have Device Communication Error in the Status
column.
b. Verify that you can congure a device by using HP Web Jetadmin.
c. In the All Devices list, right-click a device, and then select Refresh Selection (Full). Verify that the
refresh completed.
If there are any devices that have a status of Device Communication Error or you cannot complete step b or
c, access the device EWS, and then verify the following settings:
●
Click the Networking tab, and then click the Network Settings link. If SNMPv3 is enabled, verify that
the authentication protocol is SHA x and the privacy protocol is AES.
●
Click the Security tab, and then click the Certicate Management link. Select a certicate, and then
click the View Details button. Verify that the self-signed certicate uses a signature algorithm other
than MD5. Repeat this step for each self-signed certicate.
ENWW Enable FIPS on the HP Web Jetadmin Server 29
Kommentare zu diesen Handbüchern