Configure certificates

Configure certificates


To update or install a certificate, click Configure to start the certificate management wizard. The screens displayed depend on the type of certificate (HP Jetdirect or CA) and your selections. Certificate configuration screens provides a description of the screens and configuration parameters that are displayed.

HP Jetdirect Print Servers note Configure certificates NOTE:

If you improperly exit Certificates configuration by failing to use the Cancel button, for example, an Operation Failed screen appears. If this occurs, wait approximately two minutes and restart the wizard.

Certificate configuration screens
Certificate Options screen. The options displayed depend on your print server model.

Update Pre-Installed Certificate Update the pre-installed, self-signed certificate. The certificate is overwritten. You can update the following item:

Certificate Validity Period

The browser identifies the certificate as self-signed for each new Web session, which can cause a security alert message. You can bypass this message by adding the certificate to the browser’s certificate store or by disabling browser alerts (not recommended).

Self-signed certificates are not necessarily secure because the certificate owner is merely confirming his own identity instead of verification by a trusted third party. Certificates from a trusted third party are considered more secure.


Create Certificate Request You are prompted for specific device and organizational information in the following screen:

Certificate Information

Use this option when an authentication protocol requires that you install an HP Jetdirect certificate issued by a trusted third party or certificate authority.


Install Certificate Displayed only if there is a pending HP Jetdirect certificate request (to a trusted third party). When the certificate is received, use this option to install it. Once installed, this certificate overwrites the pre-installed certificate. You are prompted for information in the following screen:

Install Certificate

The certificate to be installed must be associated with a previous certificate request generated by the embedded Web server.


Install CA Certificate (Full-featured print servers only) Displayed when you click Configure to install a CA certificate required for selected authentication protocols. You are prompted for information in the following screen:

Install Certificate


Import Certificate and Private Key Import a previously acquired and known certificate as the HP Jetdirect certificate. If you import a certificate, the currently installed certificate is overwritten. You are prompted for information in the following screen:

Import Certificate and Private Key

 

Export Certificate and Private Key Export the HP Jetdirect certificate currently installed on the print server for use on other print servers. You are prompted for information in the following screen:

Export the HP Jetdirect certificate and private key

 

Delete CA Certificate (Full-featured print servers only) Remove the CA certificate installed on the HP Jetdirect print server. Displayed when a CA certificate for EAP authentication is installed.
HP Jetdirect Print Servers caution Configure certificates CAUTION:

If the CA Certificate is deleted, EAP authentication is disabled and network access is denied.

The CA Certificate is also removed on a cold-reset of the print server, where factory-default settings are restored.

Certificate Validity screen. Specify how long the HP Jetdirect self-signed certificate is valid.
 

Displays only when a self-signed certificate is pre-installed and you click Edit Settings to update the validity period. It specifies the current coordinated universal time (UTC).

Validity Start Date Calculated from the PC’s clock settings.

Validity Period Number of days (1 to 3650) that the certificate is valid, starting from the Validity Start Date. A valid entry (1 to 3650) is required. The default is 5 years.

Certificate Information screen. Enter information for requesting a certificate from a Certificate Authority.
 

Common Name (Required) For HP Jetdirect print servers, specify the FQDN or a valid IP address for the device.

Examples

Domain Name: myprinter.mydepartment.mycompany.com

IP address: 192.168.2.116

The Common Name is used to uniquely identify the device. For HP Jetdirect print servers using EAP authentication, some authentication servers can require configuration with the Common Name as specified on the certificate.

If the default IP address 192.0.0.192 is set on the HP Jetdirect print server, it is probably invalid for your network. Do not use this default address to identify your device.

 

Organization (Required) Specify the full legal name for your company.
 

Organizational Unit (Optional) Specify your department, division, or other subgroup of your organization.
 

City/Locality (Required) Enter the city or locality in which your organization is located.
 

State/Province (Required for all countries/regions) Must contain at least three characters.
 

Country/Region Two-character ISO 3166 country/region code. For example, use gb Great Britain or us for USA (required).
Install Certificate or Install CA Certificate screens.
Use the Install Certificate screen to install an HP Jetdirect certificate. (The Install Certificate option is not presented if there is no pending request.)
Use the Install CA Certificate screen to install a trusted certificate authority (CA) certificate for use during EAP authentication. (Full-featured print servers only.)
 

Install a privacy enhanced mail (PEM/Base64) encoded certificate.

To install a certificate, specify the name and path of the file that contains the certificate. Or, click Browse to browse your system for the file.

Click Finish to complete the installation.

To install a certificate, it must be associated with a pending certificate request by the embedded Web server.

Import Certificate and Private Key screen. Import an HP Jetdirect certificate and private key.

Import an HP Jetdirect certificate and private key. When imported, the existing certificate and private key are overwritten.

The file format must be PKCS#12 encoded (.pfx).

To import a certificate and private key, specify the name and path of the file that contains the certificate and private key. Or, click Browse to browse your system for the file. Then enter the password that was used to encrypt the private key.

Click Finish to complete the installation.

Export the HP Jetdirect certificate and private key screen. Export the installed HP Jetdirect certificate and private key to a file.
 

To export a certificate and private key, enter a password to use to encrypt the private key. Enter the password again to confirm it. Then click Save As to save the certificate and private key in a file on your system. The file format is PKCS#12 encoded (.pfx).
HP Jetdirect Print Servers Configure certificates