HP JetAdvantage Security Manager 10 Device E-LTU Bedienungsanleitung Seite 1

Stöbern Sie online oder laden Sie Bedienungsanleitung nach Nein HP JetAdvantage Security Manager 10 Device E-LTU herunter. Using Microsoft SQL Server with HP Web Jetadmin Benutzerhandbuch

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 31
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 0
HP JETADVANTAGE SECURITY MANAGER
Certificate Management
CONTENTS
Overview ............................................................................................................................. 2
What is a Certificate? ............................................................................................................ 2
Certificate Use Cases ............................................................................................................. 2
Self-Signed Certificates ........................................................................................................... 2
Identity Certificates ................................................................................................................ 4
CA Certificates ...................................................................................................................... 5
Certificate Authorities (CA) ...................................................................................................... 5
Creating a Certificate Request Using EWS ................................................................................ 6
Using Security Manager to Manage Identity Certificates.............................................................. 7
Certificate Authority Access Details .......................................................................................... 8
Certificate Authority Template Access ....................................................................................... 9
Certificate Revocation Lists .................................................................................................... 14
General CRL Knowledge ................................................................................................... 14
Certificate Revocation ....................................................................................................... 15
CRL Distribution Point (CDP) ............................................................................................... 16
Security Manager Certificate Policy Settings ............................................................................ 18
Certificate Assessment Detail ................................................................................................. 21
Initial Certificate Assessment .............................................................................................. 21
Initial Certificate Remediation ............................................................................................. 22
Subsequent Certificate Assessment & Remediation ................................................................. 23
Security Manager Assessment Behavior (CRL) ....................................................................... 23
Using Security Manager to Manage CA Certificates ................................................................. 27
Troubleshooting Certificate Remediations ................................................................................ 29
Summary ............................................................................................................................ 31
Seitenansicht 0
1 2 3 4 5 6 ... 30 31

Inhaltsverzeichnis

Seite 1 - Certificate Management

HP JETADVANTAGE SECURITY MANAGER Certificate Management CONTENTS Overview ...

Seite 2 - SELF-SIGNED CERTIFICATES

This template must be created at the Certificate Authority and customized for printer certificate generation. Relative to HP printers, identity cert

Seite 3

Under the Request Handling tab, Signature and encryption should be selected as the Purpose. Allow private key to be exported can be selected

Seite 4 - IDENTITY CERTIFICATES

As is the case when granting the Security Manager server “machine” access to the designated certificate authority, Security Manager access to the ne

Seite 5 - CERTIFICATE AUTHORITIES (CA)

Enter the name of the Security Manager server requiring template access (hp-print-mgmt), then select OK. Granting the Security Manager server both R

Seite 6

Now that template configuration is complete, a final step is required to complete the template access process. The new template must be enabled fo

Seite 7

To support a variety of scenarios, Microsoft Active Directory Certificate Services (AD CS) supports industry-standard methods of certificate revo

Seite 8

then Revoke Certificate. Once a reason for revocation is provided and the certificate has been revoked, it is moved from the Issued Certificates q

Seite 9 - TEMPLATE ACCESS

CDP repositories can either be an LDAP or HTTP location. This example shows CDP configuration if CRL access is to occur via HTTP. The CDP informa

Seite 10

SECURITY MANAGER CERTIFICATE POLICY SETTINGS The image below provides a graphic representation of the configurable identity certificate settings fou

Seite 11

private key. Why select HP Security Manager as the CSR source? When HP Security Manager is selected as the CSR source, stronger encryption algorith

Seite 12

OVERVIEW Digital certificates are a primary foundation of security providing authentication and encryption between two nodes. HP printers use certif

Seite 13

discovered. If there is a hostname reference of an Security Manager device in the database, Security Manager will generate the request (CSR) with th

Seite 14 - CERTIFICATE REVOCATION LISTS

select the desired key length. More selections are available when HP Security Manager is selected as the CSR source. 15. Certificate Request Signa

Seite 15 - Certificate Revocation

This recommendation report shows a failed assessment of the device with the self-signed certificate. Explanation as follows: 1. Common Name Mismat

Seite 16 - CRL Distribution Point

1. Security Manager will assess the device based upon the Identity Certificate policy editor settings and determine if remediation is necessary. 2.

Seite 17

to the next publishing of the CRL, Security Manager won’t attempt CRL access. The CDP information was gleaned from the certificate when it was issue

Seite 18

4. If an assessment is performed before the next CRL update, Security Manager will not access the CRL to check for certificate revocation. If an

Seite 19

5. Security Manager now possesses revocation knowledge of the certificate it installed on the device. If Security Manager attempts to access the

Seite 20

device. The following image shows completion of this task and evidence of a new certificate based on the new serial number. USING SECURITY MANAGER

Seite 21

Newer HP devices such as the HP LaserJet M604/605/606, HP Color LaserJet MFP M577, HP Color LaserJet M552, and others began to unify the location of

Seite 22

NOTE: For devices that do not support this unification of Jetdirect and device CA certificates and still place the Jetdirect CA certificate on the

Seite 23

The Jetdirect certificate (identity certificate) on the device has two roles: to provide encryption of the data stream and to provide authentication

Seite 24

client and server, may be preventing traffic from reaching the server on TCP port 135. The client may be unable to reach the server at all due to a

Seite 25

7. If workstations are also having issues auto-enrolling for certificates, then the standard troubleshooting steps for resolving RPC Server Unavaila

Seite 26

certificate from one of the devices and using a tool such as Web Jetadmin to install it on the affected devices in one easy step. Since self-signed

Seite 27 - CERTIFICATES

CA CERTIFICATES HP Jetdirect can store an Identity certificate and a CA (Certificate Authority) certificate. The CA certificate tells Jetdirect whic

Seite 28

Directory service. When you install an enterprise root CA, it uses Group Policy to propagate its certificate to the Trusted Root Certification Autho

Seite 29

The form itself can take time to complete and is prone to error especially when completing many times over. The Common Name will be either an

Seite 30 - has Read permissions. Make

 Security Manager incorporates the certificate management solution into the standard assess and remediate lifecycle. Not a separate add-on or plug-

Seite 31 - SUMMARY

Next, with Authenticated Users highlighted, select the Security tab, click Add. Select Object Type, then select Computers. Select OK and enter t

Kommentare zu diesen Handbüchern

Keine Kommentare