• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
HP Recommended
HP Color LaserJet Pro MFP M283cdw

Product: HP Color LaserJet Pro MFP M283cdw

Problem: Changing the EWS Network Identification > Configuration Precedence setting causes the printer to stop using an installed custom HTTPS printer certificate and revert to the factory HP self-signed certificate.

I am using a valid CA-signed printer certificate installed through the printer's Embedded Web Server (EWS). The certificate works correctly for HTTPS access and is presented correctly by the printer on TCP port 443.

Steps to reproduce:

  1. Install a custom CA-signed printer certificate under Networking > Certificates.
  2. Verify that the printer presents the custom certificate when accessing the EWS over HTTPS.
  3. Go to Networking > Network Identification.
  4. Change Configuration Precedence. In my case I changed the order from:
    Manual > TFTP > DHCP/BootP > DHCPv6 > Default
    to:
    DHCP/BootP > Manual > TFTP > DHCPv6 > Default
  5. Apply the change. The printer reboots.
  6. After the reboot, access the EWS over HTTPS and inspect the printer certificate.

Actual result:

The previously installed custom certificate is no longer being used. The printer instead presents its factory HP self-signed certificate, with the factory/default NPI hostname as the certificate subject.

Changing Configuration Precedence back to the original factory order and rebooting does not restore the custom certificate. The custom certificate must be imported again.

After re-importing the same custom certificate, the printer again presents it correctly over HTTPS. I verified the certificate actually served on TCP port 443 using OpenSSL, including its issuer, subject, validity period, and Subject Alternative Names.

Expected result:

Changing the Configuration Precedence order should affect only the precedence of network configuration sources such as DHCP/BOOTP, Manual, TFTP, DHCPv6, and Default. It should not remove, deactivate, or replace an independently installed HTTPS printer certificate.

Additional observation:

The HP certificate that becomes active after this change is not newly generated at the time of the configuration change. Its issue date predates the test, which suggests the printer is reverting to or reactivating an existing factory self-signed certificate.

This behavior is reproducible and appears to be an EWS/firmware defect. I would appreciate this being escalated to the LaserJet firmware/EWS engineering team for investigation.

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->