Zum Inhalt springen
  • Blog
  • Cookie Policy (EU)
  • Datenschutzerklärung
  • EBF Docs
  • Onboarder Source and Target
  • Test
  • EBF product documentation

    Find help using and administering EBF applications

    EBF Print

    • Release Notes
    • 01. Getting Started
    • 02. Architecture and Workflow
    • 03. Requirements
    • 04. Initial Installation
    • 05. Configuration
    • 06. Contact
    View Categories
    • Home
    • EBF Docs
    • EBF Print

    03. Requirements

    3 min read

    Firewall

    The system must be accessible via the Internet to allow printing, the following table contains the required open ports for the respective components:

    Source System  Source Port  Target System  Target Target Port  Protocol
    Mobile Devices Internet 8443 Load Balancer Internet 8443 IPPS
    Load Balancer Internet 8443 Print Proxy DMZ 8443 IPPS
    Print Proxy DMZ 8631 Print Server DMZ 8631 IPP
    Print Server DMZ 515 Printserver Solution Intranet 515 LPD
    Print Proxy DMZ 443 EMM System (API-Component) DMZ 443 HTTPS
    Print Proxy DMZ 8443 Print Proxy Admin Portal Intranet 8443 HTTPS

    Appliance

    The solution can be installed using an appliance. EBF provides ISO images used to carry out the application installation and can be provided by EBF for download over the Internet. Alternatively, installation into an existing systems can be achieved with a JAR file installation provided on request at EBF.

    The appliances are usually virtual machines (from VMware or other VM providers) and are based on CentOS 7 x64 Linux distribution.

    The following specifications for the virtual machines are recommended:

    Hardware Recommendation
    CPU min. 4 Cores
    RAM min. 4GB (8GB if on one machine)
    HDD min. 50GB

    A high availability (HA) solution can be achieved by integrating a load balancer with round-robin load distribution within the active proxies and the downstream print server systems.

    Secured Connection

    Certificate

    To secure communication appropriate SSL certificates are required, ideally issued to the server names and in an iOS-compatible format. Depending on the implementation, these certificates must be stored directly in the server systems or on the load balancer system (SSL offloading)

    Requirements for trusted certificates in iOS 13 and macOS 10.15

    Technical users and roles

    EBF Print requires the following technical users with the following rights/roles in the following systems:

    System  User  Rights/Roles
    EBF Print Server root Root access within the LINUX appliance to configure the Print Server
    EBF Print Proxy root Root access within the LINUX appliance to configure the Print Server
    UEM System Print Admin API access from Print Proxy to UEM System to read user/device data
    UEM System Print Admin Device Management: View Device/View Device Details
    UEM System Print Admin User Management: View User

    Admin Roles MobileIron

    Required Admin Roles in MobileIron are:

    • Device Management: View device page, device details
    • Label Management: Manage Label
    • User Management: View User
    • Configuration Management:
      • Manage configuration
      • Apply and remove configuration label
    • Other Roles: API

    Admin Permissions Intune

    For Intune an admin needs to create an Azure Application ID in the Azure portal and assign several Graph-API permissions to this App. All App permissions must be of type “Application permission”.

    This App-ID will then be used in the configuration of the Print Proxy.

    Required API permission for EBF Print using MS Intune are:

    • DeviceManagementManagedDevices.Read.All
    • Directory.Read.All
    • User.Read.All

    Admin Permissions for Workspace One

    An API user to connect EBF Print to a Workspace One instance must have the following permissions:

    • REST API Devices Read
    • REST API Organizational Units Read
    • REST API Smart Groups Read
    • REST API Groups Read
    • REST API Users Read
    • User Details View

    Find below an example file with the needed permissions, that can be imported into Workspace One:
    Workspace One Example

    Was this article useful?

    Still stuck? How can we help?

    How can we help?

    Updated on 9. Juli 2024
    02. Architecture and Workflow04. Initial Installation
    Table of Contents
    • Firewall
    • Appliance
    • Secured Connection
    • Technical users and roles
      • Admin Roles MobileIron
      • Admin Permissions Intune
      • Admin Permissions for Workspace One
    Linkedin-in Phone
    Workplace Management
    • UEM Solutions
    • Migrations
    • Services
    Modern Work Tools
    • Sync Contacts
    • Hybrid Data Management
    • Secure Mobile Printing
    • eSIM Management
    • App Management
    IT Security
    • IAM
    • Modern Threat Defense
    • Cyber Risk Management
    • Secure Development
    • Zero Trust
    • Security Check
    AI Solutions
    • AI Consulting
    • AI Development
    Company
    • About Us
    • References
    • Partners
    • Sustainability
    • Careers
    • Trends
    © 2026 EBF-EDV Beratung Föllmer GmbH
    • Privacy Policy
    • GTC
    • EULA
    • Imprint
    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Immer aktiv
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Optionen verwalten
    • Dienste verwalten
    • Verwalten von {vendor_count}-Lieferanten
    • Lese mehr über diese Zwecke
    View preferences
    • {title}
    • {title}
    • {title}
    EBF Status Check