
Credentials Store
The concept of a Credentials Store is not new to HP Web Jetadmin. Older versions of HP Web Jetadmin stored
credentials onto the devices as they were used and congured. This feature keeps HP Web Jetadmin users from
having to provide a credential every time a device is congured that requires one.
The Credentials Store is a portion of the HP Web Jetadmin database that securely encrypts and stores device
credentials when ever a correct credential value is authenticated at the device. These values are stored on a per
credential and per device basis.
Here is a list of HP device credentials used by HP Web Jetadmin:
●
EWS Password: Blocks unauthorized access to the device-embedded HTTP interface. It is also synchronized
with the HP Jetdirect telnet password.
●
File System Password: Protects the printer disk and other storage facilities from unauthorized access.
●
SNMPv3 Credentials: Consists of user name, passphrase1, and passphrase2 which are all used when
SNMPv3 is enabled. This version of SNMP secures and authenticates communication between
management applications like HP Web Jetadmin and the device. This protocol is used when strong security
is required.
●
SNMP Set Community Name: A grouping mechanism for SNMPv1/v2 used as a security mechanism by
many customers. Device conguration is not possible without knowledge of the Set name value. The Set
name value traverses the network in clear text and can be “snied” by eavesdroppers.
●
SNMP Get Community Name: Sometimes used to prevent device discovery from other HP Web Jetadmin
installations. Devices only respond to Get packets that have the correct value. The Get name value
traverses the network in clear text and can be “snied” by eavesdroppers.
Two actions cause the value of any credential to be stored:
●
Conguration: The credential becomes stored once it has been congured onto the device.
●
Use: The credential value, when used successfully, becomes stored.
HP Web Jetadmin reuses stored credentials any time it encounters the requirement for them. When conguring
a device that has had a credential stored, you are not required to re-enter the credential into HP Web Jetadmin.
The application uses the credential in the background. In fact, you are not even required to know the credential
because HP Web Jetadmin is using stored values.
Credentials Delegation
With credentials stored in the Credentials Store, HP Web Jetadmin can apply them transparently any time the
need arises. This is known as credentials delegation. While conguring devices, you do not have to remember or
even know the credential to perform the conguration. You just need access to HP Web Jetadmin and device
conguration features. Characteristics of credentials delegation are:
●
Only one or a few device administrators know the device credentials.
●
Some HP Web Jetadmin users are allowed conguration access to the devices via Roles and User Security.
●
Users can be added or removed from this delegation through Roles and User Security (User Security
on page 278).
●
Other HP Web Jetadmin users can be restricted from device conguration.
●
Knowledge about device passwords is required before you can change any password value.
Credentials delegation is used to allow conguration of devices without having to share the credential “secrets”
across a large distribution. Stas can control and congure devices while administrators control and congure
ENWW Shared Conguration Options for all Views 53
Commentaires sur ces manuels