
Security Manager isn’t remediating or downloading firmware to the device, it is merely reading the
device’s firmware version and comparing it with device’s latest version from the following file over an
HTTPS connection: https://ftp.hp.com/pub/networking/software/pfirmware/pfirmware.glf.
If the current device’s firmware version does not match with the latest in the pfirmware.glf file, then an
assessment failure is shown.
There are three options to choose from to dictate how Security Manager will compare the firmware
versions: File, Web (hp.com), and Best Possible. Web (hp.com) provides the best accuracy as a real
time query is made to the ftp location to ensure the most recent data is being read. However, this
accuracy involves a query outside the company firewall, which may not be desired or possible on the
server. File allows for manually downloading the pfirmware.glf file at any desired frequency from
any client with web access, then the file can be uploaded into Security Manager to be used for
comparisons in assessments. This eliminates Security Manager having to query outside the firewall as
it will merely read from the file that is uploaded, but accuracy will only be as good as how recently
the file was uploaded. Best Possible combines both techniques, Security Manager attempts to gather
the most recent pfirmware.glf file from the web, but falls back on an earlier downloaded firmware
index file or can use the user provided pfirmware.glf file in the case of web connectivity not
available.
The frequency or threshold in which Security Manager queries the web for the pfirmware.glf file is set
to be every 24 hours by default. That means Security Manager will use what has previously been
downloaded for up to 24 hours before it will query the web again for a more current file. The
threshold can be changed if desired in the following file:
C:\Program Files (x86)\HP JetAdvantage Security Manager\HPSM_Service.exe.config
Change the following to define the threshold. Default is 24 hours:
<add key="firmwareIndexUpdateThreshold" value="24:0:0" />
Check for Latest Jetdirect Firmware
This item is used to determine if the Jetdirect device in the printer/MFP is currently at the latest
firmware version. The latest firmware on device ensures that device is better protected from security
threats.
Security Manager is using an index file at the following location that HP Web Jetadmin also uses to
determine the most recent firmware versions available for Jetdirect devices:
ftp.hp.com/pub/networking/software/jetdirect/firmware
Comentarios a estos manuales