Hi QZ Industries,
I am currently evaluating the deployment options for QZ Tray within our organization and would appreciate your insights regarding the server mode configuration.
While the server mode offers centralized management, I have several concerns from a security standpoint that I would like to clarify:
Given these considerations, I would like to understand whether server mode is truly recommended over deploying QZ Tray individually on each client workstation.
Any documentation or best practices you could share would be greatly appreciated.
Best regards,
Boris Royer
CISO
Hôpital Saint Joseph Marseille
Hi QZ Industries,
I am currently evaluating the deployment options for QZ Tray within our organization and would appreciate your insights regarding the server mode configuration.
While the server mode offers centralized management, I have several concerns from a security standpoint that I would like to clarify:
- Printer rights bypass: Server mode allow users to circumvent local printer access controls
- Print traceability: Is there a mechanism to log and audit print requests centrally?
- Lateral movement risks: Exposing the print server increase the attack surface for lateral movement within the network
- Single point of failure: If the QZ Tray service crashes, it does block all printing operations across clients
Given these considerations, I would like to understand whether server mode is truly recommended over deploying QZ Tray individually on each client workstation.
I mean that in server mode the "user context" used is the one of the account executing QZ Tray. So it has to e an account with print priviledges (windows rights) on all our printers, whereas if QZ Tray is installed on users computers it will use only the printers visible by the user connected.
Ok for the print traceability, I understand, and you're right for the lateral movement my concern was just to compare local and server mode in OUR implementation ; In local mode the exposition is limited whereas in server mode the port is exposed with a global authentication which can be considered as sufficient in OUR local network furthermore protected by nac.
I will file an enhancement as proposed to know if a windows authentication, or a computer certificate based authentication can be considered.
I retain the fact as you say it may be in our case a best slution to install QZ Tray on each PC.
if my questions may have appeared negatives in part because of my english, but that was not the goal.
--
You received this message because you are subscribed to the Google Groups "qz-print" group.
To unsubscribe from this group and stop receiving emails from it, send an email to qz-print+u...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/qz-print/74b4500f-6432-409e-aaf2-45b4c9268246n%40googlegroups.com.