Current Compatibility Matrix - Keyfactor Products

The tables below show compatibility between supported Keyfactor Command releases and supported Keyfactor products, including gateways, platforms, and orchestrators. Versions that are no longer supported are not included.

In the tables below, each row represents the version of the product shown in the matrix. Columns indicate supported Keyfactor Command release streams.

Table 1: Compatibility Matrix Legend

Symbol Definition
All functionality is fully supported
Functionality is not supported
OAuth functionality introduced in Windows Enrollment Gateway (EJBCA CAs) version 24.1 requires Keyfactor Command version 24.1 or higher.

EJBCA Native Support

EJBCA Enterprise is a commercial public key infrastructure (PKI) platform and certificate authority that integrates directly with Keyfactor Command. This matrix shows compatibility between Keyfactor Command release streams and EJBCA native integration versions.

Table 2: Compatibility Matrix - Keyfactor Command and EJBCA

EJBCA Versions Command 26.x Command 25.x Command 24.x
9.6.x
9.5.x
9.4.x
9.3.5 - 9.3.8
9.3.4
9.3.0 - 9.3.3

Windows Enrollment Gateway (EJBCA CAs)

The Windows Enrollment Gateway supports management of digital certificates in an EJBCA CA hosted in a cloud-based environment. This matrix shows compatibility between Keyfactor Command release streams and Windows Enrollment Gateway.

Table 3: Compatibility Matrix - Keyfactor Command and Windows Enrollment Gateway

Gateway Versions Command 26.x Command 25.x Command 24.x
26.x
25.x
24.x

AnyCAGateway REST

The AnyCAGateway REST enables Keyfactor Command to communicate with supported third-party certificate authorities through a modern REST-based gateway. This matrix shows compatibility between Keyfactor Command release streams and AnyCAGateway REST versions.

Table 4: Compatibility Matrix - Keyfactor Command and AnyCAGateway REST

Gateway Versions Command 26.x Command 25.3 - 25.5 Command 25.1-25.2 Command 24.x
26.x
25.5
25.1 - 25.4
24.4
24.2
24.1

CA Connector Client versions 25.5 and later require AnyCAGateway REST versions 25.5 and later.

AnyCAGateway DCOM

The AnyCAGateway DCOM enables Keyfactor Command to communicate with supported third-party certificate authorities through the legacy DCOM-based gateway.

AnyCAGateway DCOM versions 24.1.x and later are supported with Keyfactor Command 24.x and later.

Windows Cloud Gateway (Microsoft CAs)

The Keyfactor Cloud Gateway supports management of digital certificates in a Microsoft CA hosted in a cloud-based environment managed by Keyfactor. Windows Cloud Gateway versions are independent of Keyfactor Command releases. There are no version-based compatibility restrictions between the two.

Universal Orchestrator

The Keyfactor Universal Orchestrator automates certificate lifecycle operations across systems and applications.

Universal Orchestrator versions 24.x through 25.x are supported with Keyfactor Command versions 24.x through 26.21, however orchestrator pools are not be available for Universal Orchestrators earlier than version 26.2.1.

Universal Orchestrator versions 26.2.1 and later require Keyfactor Command v26.2.1 or later, due to the introduction of orchestrator pools.

Important:  If you are upgrading a Universal Orchestrator to version 26.2.1 or later, you must upgrade Keyfactor Command to version 26.2.1 or later first.

Before upgrading a Universal Orchestrator, review the orchestrator upgrade information.

SSH Orchestrator

The SSH Orchestrator automates certificate lifecycle operations on SSH-enabled systems. This matrix shows compatibility between Keyfactor Command release streams and SSH Orchestrator versions.

Table 5: Compatibility Matrix - Keyfactor Command and SSH Orchestrator

Orchestrator Versions Command 26.x Command 25.x Command 24.x
2.0.0
1.0.1

Windows Orchestrator

The Keyfactor Windows Orchestrator was deprecated as of Keyfactor Command version 11. Customers must migrate to the Keyfactor Universal Orchestrator, with the appropriate custom extension, publicly available at:

CA Connector Client

The CA Connector Client enables Keyfactor Command to communicate with certificate authorities that are not directly accessible, including HTTPS-based CAs and Active Directory forests across trust boundaries.

CA Connector Client versions 24.4 and later are supported with Keyfactor Command 24.x and later.

CA Connector Client versions 25.5 and later require AnyCAGateway REST versions 25.5 and later.

Keyfactor ACME

Keyfactor ACME provides an ACME-compliant interface for automated certificate enrollment and renewal. This matrix shows compatibility between Keyfactor Command release streams and Keyfactor ACME versions.

Table 6: Compatibility Matrix - Keyfactor Command and Keyfactor ACME

Keyfactor

ACME Versions

Command 26.x Command 25.x Command 24.x
26.x
25.x
24.x
2.4.1