CNG v3 certificates overview - Configuration Manager (2024)

  • Article

Configuration Manager supports Cryptography: Next Generation (CNG) certificates. Configuration Manager clients can use a PKI client authentication certificate with the private key generated and stored in a CNG Key Storage Provider (KSP). With KSP support, Configuration Manager clients support hardware-based private keys, such as a TPM KSP for PKI client authentication certificates.

Supported scenarios

You can use Cryptography API: Next Generation (CNG) v3 certificate templates for the following scenarios:

  • Client registration and communication with an HTTPS management point
  • Software distribution and application deployment with an HTTPS distribution point
  • OS deployment
  • Client messaging SDK (with latest update) and ISV Proxy
  • Cloud management gateway (CMG) configuration
  • User-targeted available applications in Software Center

Also use CNG v3 certificates for the following HTTPS-enabled server roles:

  • Management point
  • Distribution point
  • Software update point
  • State migration point
  • Certificate registration point, including the NDES server with the Configuration Manager policy module

Note

CNG is backward compatible with Crypto API (CAPI). CAPI certificates continue to be supported even when CNG support is enabled on the client.

Unsupported scenarios

The following scenarios currently aren't supported:

  • The following server roles aren't operational when installed in HTTPS mode with a CNG v3 certificate bound to the web site in Internet Information Services (IIS):

    • Enrollment point
    • Enrollment proxy point

To use CNG certificates

To use CNG v3 certificates, your certification authority (CA) needs to provide CNG certificate templates for target machines. Template details vary according to the scenario; however, the following properties are required:

  • Compatibility tab

    • Certificate Authority must be Windows Server 2008 or later. (Windows Server 2012 is recommended.)

    • Certificate recipient must be Windows Vista/Server 2008 or later. (Windows 8/Windows Server 2012 is recommended.)

  • Cryptography tab

    • Provider Category must be Key Storage Provider. (required)

    • Algorithm name must be RSA. (required)

    • Request must use one of the following providers: must be Microsoft Software Key Storage Provider.

Note

The requirements for your environment or organization may be different. Contact your PKI expert. The important point to consider is a certificate template must use a Key Storage Provider to take advantage of CNG.

For best results, we recommend building the Subject Name from Active Directory information. Use the DNS Name for Subject name format and include the DNS name in the alternate subject name. Otherwise, you must provide this information when the device enrolls into the certificate profile.

CNG v3 certificates overview - Configuration Manager (2024)
Top Articles
Quantified Strategies - Backtesting, Historical Data-Driven Trading, Technical Indicators - Quantified Strategies
Blog: Flexibility is the New Standard for Cash Cassettes
Dainty Rascal Io
Canya 7 Drawer Dresser
CLI Book 3: Cisco Secure Firewall ASA VPN CLI Configuration Guide, 9.22 - General VPN Parameters [Cisco Secure Firewall ASA]
Affidea ExpressCare - Affidea Ireland
Craigslist Mexico Cancun
Steve Strange - From Punk To New Romantic
Call of Duty: NEXT Event Intel, How to Watch, and Tune In Rewards
Graveguard Set Bloodborne
Nichole Monskey
Craigslist Cars Nwi
Spartanburg County Detention Facility - Annex I
Rainfall Map Oklahoma
Conan Exiles Colored Crystal
Nba Rotogrinders Starting Lineups
Lancasterfire Live Incidents
EASYfelt Plafondeiland
Doublelist Paducah Ky
Mj Nails Derby Ct
Myql Loan Login
Die 8 Rollen einer Führungskraft
Delete Verizon Cloud
Visit the UK as a Standard Visitor
Core Relief Texas
Angel del Villar Net Worth | Wife
Busted! 29 New Arrests in Portsmouth, Ohio – 03/27/22 Scioto County Mugshots
Indiana Jones 5 Showtimes Near Jamaica Multiplex Cinemas
RFK Jr., in Glendale, says he's under investigation for 'collecting a whale specimen'
Federal Student Aid
John F Slater Funeral Home Brentwood
Gwu Apps
Tal 3L Zeus Replacement Lid
Best Restaurants In Blacksburg
Craigslist Gigs Wichita Ks
Jail View Sumter
This 85-year-old mom co-signed her daughter's student loan years ago. Now she fears the lender may take her house
Jasgotgass2
Stewartville Star Obituaries
The Conners Season 5 Wiki
Miami Vice turns 40: A look back at the iconic series
Ethan Cutkosky co*ck
Woody Folsom Overflow Inventory
Autozone Battery Hold Down
Vagicaine Walgreens
2294141287
Kaamel Hasaun Wikipedia
Dying Light Mother's Day Roof
The top 10 takeaways from the Harris-Trump presidential debate
Deshuesadero El Pulpo
Edt National Board
Shad Base Elevator
Latest Posts
Article information

Author: Fr. Dewey Fisher

Last Updated:

Views: 6023

Rating: 4.1 / 5 (42 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Fr. Dewey Fisher

Birthday: 1993-03-26

Address: 917 Hyun Views, Rogahnmouth, KY 91013-8827

Phone: +5938540192553

Job: Administration Developer

Hobby: Embroidery, Horseback riding, Juggling, Urban exploration, Skiing, Cycling, Handball

Introduction: My name is Fr. Dewey Fisher, I am a powerful, open, faithful, combative, spotless, faithful, fair person who loves writing and wants to share my knowledge and understanding with you.