HP LaserJet, HP PageWide - Secure by Default Initiative (white paper)

8
Settings Defaults
The following tables contain the Secure by Default settings current and updated defaults.
Security Setting
FutureSmart 4.5 Defaults
SNMPv1/v2
Enable SNMPv1/v2 Read-Write access
Enable SNMPv1/v2 Read-only access
PJL/PS File Access
Enabled
Disabled
PJL Device Access Commands
Enabled
Disabled
TLS Ciphersuites containing RC4 and 3DES
Active (enabled)
Available (not enabled)
TLS version 1.0 / 1.1
Enabled
Disabled (beginning with FutureSmart 4.7.2)
Security Feature
Default
Can be
disabled
Affected Technologies
Cross-Site Request
Forgery Prevention
Enabled
Yes
Print solutions from specific vendors may need to disable setting until compliant.
MPS and customer scripting tools may need to temporarily disable CSRF to execute.
HP Connection
Inspector
Enabled
Yes
None
Administrative
Password Min Length
and Complexity
Enabled
Yes
Defaults may need to be changed to accommodate existing passwords used for print
solutions and fleet tools.
Account Lockout
Enabled
Yes
Defaults may need to be changed to accommodate WJA.