68.1 Ensure 'Require Ipps Policy' is set to 'Enabled'

Information

This policy setting determines whether communication with printers using the Microsoft Internet Printing Protocol (IPP) Class Driver uses IPPS. IPPS uses TLS for secure communication.

The recommended state for this setting is: Enabled.

To prevent interception or tampering with printer data, IPPS encrypts all communication between the client and the printer.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled.

Printers\Require Ipps Policy

Impact:

IPP printers which use self-signed or locally issued certificates will be affected and may not function properly. Any attempts to install non-compliant IPP printers will fail and generate an event in the Application log.

Warning: It is recommended that all printers are assessed, and if they meet the requirements, then enable this policy.

See Also

https://workbench.cisecurity.org/benchmarks/27282

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8

Plugin: Windows

Control ID: d3b24551b64c7b89026fac9b896c32bd54cb1a220433f65e7f252efbdc7147d0