HP Enterprise printers and scanners - Imaging and Printing Security Best Practices (white paper)

Figure 64: Enable TFTP Configuration File use by selecting check box.
HP & 3
rd
Party Solutions
Most of the recommendations in the next chapter of this checklist can be implemented without having a negative impact on HP &
3
rd
party solutions you may utilize in your environment without causing them to fail. However, there are some settings that have
been known to cause problems. When setting up a solution in your environment you want to test the following:
Disabling EWS remote access (port 80, port 443 etc.)
Disabling Command load and execute
If your previously working solution no longer works revert to your original settings, or if you are unable to get your solution
working enable them if disabled by default. The reason for this is many solutions require specific ports to communicate with the
printer and may need to load a piece of their solution on boot of the print device.
Also, be sure you do not implement a Secure Storage Erase as a disk cleaning practice. This type of erase will wipe everything off
your existing hard drive including any HP or 3
rd
party solution you have installed.
There are two suggestions in the next chapter that should only be implemented after a solution has been installed. They are:
Configure a PJL password
Disable PJL file system access
Once installed, you can test whether implementing these recommendation impacts your solution. If your solution is impacted, skip
these recommendations in the next chapter. If you choose to implement these recommendations a solution needs to be updated,
you will need to re-enable PJL file system access and set the PJL password to blank to install the solution. After the upgrade you
will need to test if the new version of the solution is adversely affected.
Note:
This setting disables configuration from the MFP EWS. It also disables all EWS-related settings from Web Jetadmin (they will
disappear from Web Jetadmin menus). With this setting configured, the only way to make changes to the EWS settings again is to
re-enable them using Web Jetadmin. Always remember to disable EWS Config after making changes.