Installing Security Certificate via GPO - which format to use

This is on a Windows 2008 R2 Active Directory with Windows 7 clients. I want to push out a Security Certificate via GPO. Which format should i use? I have .pem .der and .p7b. Thanks.
criskritAsked:
Who is Participating?

Improve company productivity with a Business Account.Sign Up

x
 
cristiantmConnect With a Mentor Commented:
It is not a recognized windows *extension*. One thing is the extension, that gives windows a hint of what is inside. Another is the *format*.

DER is the ANS.1 data encoded in binary. PEM is a base64 encoded version this data with some headers. And p7b is a PKCS#7 certificate bundle.

You can rename the ".pem" files to .crt, .cer, and even .der, and Windows will recognize them as a certificate. And when windows opens it, it will interpret it if it is PEM or DER encoded.

Regarding which one is recommended:

A PEM certificate will be DER converted by the system before its ANS.1 data is interpreted. So you probably would better serve them already DER encoded. But really, this base conversion is not that costly so you may use any of it.

But PEM only is relevant when you need to transport it for some reason using only printable chars. Its not the case so really there is no need to use it, but not a problem if you use it too.
0
 
Mohammed KhawajaManager - Infrastructure:  Information TechnologyCommented:
I recommend using .pem
0
 
criskritAuthor Commented:
.pem doesn't seem to be a windows format. Won't this be a problem? the GPO seems to read it fine.
0
 
criskritAuthor Commented:
Great, thanks for the detailed explanation. :-)
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.