ADCS templates compatibility question
hello,
have general question, hope can answered before start transition new version of windows. domain controllers are windows 2012 r2, , of our client computers may going windows 10 here shortly. in preparation certificate templates being updated, removing older templates. question arose in compatibility of certificates under certificate recipient there nothing windows 10. windows 8.1 / 2012 r2 template work windows 10, or update needed adcs server?
thanks
michael r. mastro ii
there foreward compatibility certificate templates. when new certificate template released, supported os (the template released with) , further (newer) os versions. is:
| certificate template version | min supported ca | min supported client | max supported client |
|---|---|---|---|
| version 1 | windows 2000 server | windows 2000 | windows 10 |
| version 2 | windows server 2003 enterprise | windows xp | windows 10 |
| version 3 | windows server 2008 enterprise | windows vista | windows 10 |
| version 4 | windows server 2012 | windows 8 | windows 10 |
the table outlines defined certificate templates , minumum , maximum supperted os version , minimum ca version. max supported client windows 10 (at point, windows server vnext well). safely can use version 2 certificate templates needs. not recommend use version 3 , version 4 templates, use new key storage provider not supported .net. means, certificates issued based on version 3 , 4 not work in adfs, entire system center product line (configmgr, opsmgr, dpm, etc.) , many other applications. i'm not usre if exchange server supports v3 templates, may not either.
vadims podāns, aka powershell cryptoguy
weblog: www.sysadmins.lv
powershell pki module: pspki.codeplex.com
check out new: ssl certificate verifier
check out new: powershell file checksum integrity verifier tool.
Windows Server > Security
Comments
Post a Comment