
and Discovery features. In addition to the HelpDesk role, they have been given an assignment to
another role named ExtendedHelp. These two users now have access to additional features beyond
those needed by the normal helpdesk staff. HP Web Jetadmin uses the least restrictive permissions in
its user/roles feature. A user can access any feature that is enabled in a role that has been assigned
to that user.
Diagnostics can be used to observe the privileges granted to any user that has a user/role assignment
(Figure 6). To access the diagnostics feature, go to Application Management > User Security >
Diagnostics. To display the diagnostic information for a user, specify the User name and Domain, and
then click View Roles.
Manage the role permissions and user assignments
As already noted, user/role assignments, role permissions, and even local/domain user groups can
be edited and changed. When managing these items, keep the following rules in mind:
• As users have role permission changes applied to them, the display interface does not change to
reflect (hide) the feature access changes until the next time the user logs in to the application.
• As users have role permission changes applied to them, access to restricted features are blocked
and the users receives an access denied message from the application in areas where feature
restrictions have been implemented.
• Scheduled tasks implemented by users with role permission changes or authorization removals
remain intact and are not affected by user/role or permission changes.
HTTPS and Secure Sockets Layer (SSL)
HP Web Jetadmin administrators can
enable the Secure Sockets Layer (SSL)
protocol on HP Web Jetadmin. This
forces browser communication to the
more secure HTTPS protocol. The
administrator enables SSL from the
console or host running the application.
A notice occurs when users try to enable
this feature from a remote client
(Figure 7).
Prior to HP Web Jetadmin 10, SSL was enabled by default and the primary client interface went
through a web browser. SSL is not enabled by default on HP Web Jetadmin 10.x for the following
reasons:
• HP Web Jetadmin 10.x does not use a web browser as a primary application interface.
• The HTTP service in HP Web Jetadmin 10.x provides minimal or limited functionality and is not
core to the client/server communication. Microsoft .NET Remoting provides data encryption and
user authentication.
• Self-signed certificates cannot be used unless all the clients have the appropriate Certificate
Authority (CA) installed.
In some environments, SSL is required every time an HTTP interface or service is used for
communication. The administrator can enable and enforce t SSL. When SSL is enforced, it provides
an industry-accepted protocol for both authentication and encryption of HTTP communication. A host
that requests access to the HP Web Jetadmin ClickOnce client download is assured that the system
hosting HP Web Jetadmin is authentic and that communication between the two systems is encrypted.
—Certificates notice
Commenti su questo manuale