ADCS templates compatibility question


hello,

    have general question, hope can answered before start transition new version of windows.  domain controllers are windows 2012 r2, , of our client computers may going windows 10 here shortly.  in preparation certificate templates being updated, removing older templates.  question arose in compatibility of certificates under certificate recipient there nothing windows 10.  windows 8.1 / 2012 r2 template work windows 10, or update needed adcs server?

thanks 


michael r. mastro ii

there foreward compatibility certificate templates. when new certificate template released, supported os (the template released with) , further (newer) os versions. is:

certificate template version min supported ca min supported client max supported client
version 1 windows 2000 server windows 2000 windows 10
version 2 windows server 2003 enterprise windows xp windows 10
version 3 windows server 2008 enterprise windows vista windows 10
version 4 windows server 2012 windows 8 windows 10

the table outlines defined certificate templates , minumum , maximum supperted os version , minimum ca version. max supported client windows 10 (at point, windows server vnext well). safely can use version 2 certificate templates needs. not recommend use version 3 , version 4 templates, use new key storage provider not supported .net. means, certificates issued based on version 3 , 4 not work in adfs, entire system center product line (configmgr, opsmgr, dpm, etc.) , many other applications. i'm not usre if exchange server supports v3 templates, may not either.


vadims podāns, aka powershell cryptoguy
weblog: www.sysadmins.lv
powershell pki module: pspki.codeplex.com
check out new: ssl certificate verifier
check out new: powershell file checksum integrity verifier tool.



Windows Server  >  Security



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file