• ×
    Information
    Windows update impacting certain printer icons and names. Microsoft is working on a solution.
    Click here to learn more
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Windows update impacting certain printer icons and names. Microsoft is working on a solution.
    Click here to learn more
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Do you need the WPS PIN to connect your printer? Click here for tips and tricks!
Common problems for Connectivity Issues
We would like to share some of the most frequently asked questions about Printer Wi-Fi, Connectivity Issues and Offline Status. Check out this link: HP printer is offline or unavailable.
HP Recommended

Hello,

 

I created a csr using HP printer Embedded Web Server (EWS), I try to create a CA certificate (Comodo SSL), but I need to valid it an email like "Admin@HPICxxxxx.home" or CNAME (DNS) but EWS is on LAN (not internet) ?

Do you know a way to create a p12 certificate ?

 

Thanks

3 REPLIES 3
HP Recommended

Hi @pol2020,

 

Welcome to HP Support Community.

Thank you for posting your query, I will be glad to help you.

 

It sounds like you're trying to replace the self-signed certificate used by your HP printer's Embedded Web Server (EWS) with a CA-signed SSL certificate. The challenge you're facing with email or DNS validation is common when the device is on a local network (LAN) and not accessible from the internet. Here are the steps you can follow to obtain a signed certificate and create a P12 file:

 

Generate CSR and Private Key: It seems you've already done this part using your HP EWS. Make sure you have both the CSR and the corresponding private key saved, as you'll need them later.

Choose a Certificate Authority (CA): Since you mentioned Comodo SSL, you can proceed with them or any other CA that offers domain validation SSL certificates. Domain validation typically requires proving control over the domain via DNS, email, or HTTP validation.

DNS Validation on Local Network: If your printer is on a LAN and does not have a publicly accessible DNS record, you might face difficulties using DNS validation in the standard way. One approach is to:

  • Configure a local DNS server or modify your local hosts file to resolve a domain name to your printer’s IP address. However, note that this local setup won't be recognized by external CAs for domain validation purposes.
  • A more practical approach would be to use a subdomain of a domain you own (e.g., printer.yourdomain.com) and create a DNS A record pointing to an external IP, then use port forwarding on your router to redirect traffic to your printer's internal IP during the validation process.

I hope this helps.

 

Take care and have a good day.

 

Please mark this post as “Accepted Solution” if the issue is resolved and if you feel this reply was helpful click “Yes”.

 

Rachel571

HP Support

Rachel571
I am an HP Employee

HP Recommended

Thanks, I have changed "Host Name" an "Domain Name" in EWS > Network > Network settings > Identification, I validate the certificate using Email method, I imported the certicate (*.cer) in EWS > Security > Certificate Managment > Import successfully.

but when I try to connect to "https://192.168.1.49", I have always the  Chrome browser warning : "certificate is not trusted" ?

My certificate is for a DNS and not an IP address ?

HP Recommended

Hi @pol2020,

 

Thank you for your response, 

 

It seems like you've correctly replaced the self-signed certificate with a signed one and updated the host and domain names in the EWS settings. However, the warning you're seeing in Chrome indicates that the certificate is still not being recognized as trusted.

 

Certificates are typically issued for domain names (e.g., example.com) rather than IP addresses (e.g., 192.168.1.49). This is because the certificate is used to verify the identity of the server hosting the website or service, and domain names provide a more human-readable and flexible way to do this compared to IP addresses.

 

To resolve this issue, you should obtain a certificate that is issued for the domain name associated with your server (e.g., myserver.example.com) rather than the IP address. Once you have the correct certificate, you can install it in the EWS settings, and when users access your server using the domain name (e.g., https://myserver.example.com), they should no longer see the certificate warning in their browsers. 

 

I hope this helps.

 

Take care and have a good day.

 

Please click “Accepted Solution” if you feel my post solved your issue, it will help others find the solution. Click the “Kudos/Thumbs Up" on the bottom right to say “Thanks” for helping!

 

Alden4

HP Support

I am an HP Employee.
† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.