HP Web Jetadmin - Security and HP Web Jetadmin
14
Prior to HP Web Jetadmin setting the device credential, the software authenticates the user’s
knowledge of the credential. This is true in both batch and single device modes of password or
credential configuration. Once a password or credential is successfully configured or changed, it is
added to the Credentials Store as an encrypted value.
Credentials delegation
With credentials stored, HP Web Jetadmin can apply them transparently any time the need arises.
HP Web Jetadmin uses these passwords or credentials during live configuration or during automated
background tasks such as scheduled firmware upgrades or configuration. When configuring devices,
users do not have to know the credential to perform the configuration. The user just needs access to
HP Web Jetadmin and device configuration features. This is called credentials delegation.
Credentials delegation is used to allow device configuration without having to share confidential
credential information across a large distribution. Your IT staff can control and configure devices
while IT administrators control and configure passwords. Any user with access to devices and
configuration features has delegated access to the Credential Store.
Credentials settings and global credentials
Controls for adding global multiple try-values for each of the following credential types can be found
under Tools > Options > Application Management >
Credentials, including:
• EWS Password
• File System Password
• SNMPv3 Credentials
• SNMP Set Community Name
• SNMP Get Community Name
Global Credentials are values set by the user and then used by HP Web Jetadmin when a credential is
needed but is not available in the Credentials Store. Multiple values can be set in Global Credentials.
HP Web Jetadmin tries each credential value in the stack until it encounters success. If the Global
Credential value is used by the application and results in success, that value is stored for that device
within the Credentials Store. If success is not achieved, the device is placed in a “credentials needed”
state.
In Tools > Options > Credentials there are options to clear all credentials stored within the application
and to clear Global Credentials:
• Credentials Options > Clear all Credentials removes all device credentials from the Credentials
Store in the HP Web Jetadmin database.
• Credentials Options > Clear all Global Credentials clears all global values stored in each of the
credential types.
Credentials needed
When HP Web Jetadmin is performing an action, such as device configuration, and it encounters a
device with a credential such as SNMP Set Community Name, it follows a specific sequence. The
following is a simplified example of how HP Web Jetadmin attempts to resolve a credential:
1. Check store for credential
• If it exists, attempt config using credential value
• Else, go to Global
• If success, stop
• If fail, go to Global
2. Check Global for credential
• If it exists, attempt config using credential value
• Else, log credential-needed, prompt user if live session