FOG PKI Infrastructure

The three-zone certificate split is not 1.6-exclusive; the same hierarchy exists on 1.5. What 1.6 adds on top of it is storage node coverage, documented certificate paths, and the per-zone bring-your-own-CA and Setup Mode options.

Which version am I on?

Check FOG Configuration → FOG Settings → General → FOG_VERSION in the web UI, or the version string printed at the top of installfog.sh.