EJBCA PKI for Enterprises - A powerful and flexible certificate issuance and management system to issue and enable full life-cycle control of digital certificate and Certificate (CA), Registration (RA) and Validation Authorities (VA); enabling multiple use cases and standards compliance.
EJBCA PKI for Enterprises - A powerful and flexible certificate issuance and management system to issue and enable full life-cycle control of digital certificate and Certificate (CA), Registration (RA) and Validation Authorities (VA); enabling multiple use cases and standards compliance. EJBCA now includes support for CloudHSM and AWS KMS, has introduced support for the ACME protocol and has a REST API. Please visit the EJBCA Enterprise Cloud documentation for CloudHSM and AWS KMS integration guides. This instance includes Standard Standard Support but is functionally identical to the Premium listing.
Version 2.0 and above now feature a web based configuration wizard so options to install directly into an RDS database or even have the ManagementCA keys be generated directly into CloudHSM can be chosen.
Multiple CAs and levels of CAs, build a complete infrastructure (or several) within one instance of EJBCA.
Unlimited number of Root CAs and SubCAs. Request cross certificates and bridge certificates from other CAs and Bridge CAs. Issue cross certificates to other CAs.
Support all common PKI Architectures, as well as many uncommon. Store keys in CloudHSM, AWS KMS, in a PKCS11 connected HSM, or in the database (for demo).
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 30 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pay by the hour for the EC2 instance size you run, with no long-term commitment. Each dimension maps to a specific instance type, so your rate depends on the compute size you choose. Smaller instances like t3.medium suit lighter workloads, while larger ones like m7a.2xlarge and c5n.4xlarge handle heavier demand. This Standard Support listing bundles vendor support with the software. You scale by selecting or switching instance sizes as your certificate volume grows, paying only for the hours each instance runs.
Top-of-mind questions for buyers
What does the hourly rate cover, and what else might I pay separately?
The hourly rate covers the EJBCA Enterprise Cloud software plus Standard Support for the running instance. You also pay standard AWS infrastructure charges, such as compute and storage, on top. You keep control over your own PKI configuration and can connect your choice of key storage service separately.
Am I charged when an instance is stopped or powered off?
Software charges meter running hours only. A fully stopped instance stops accruing the hourly software rate. You may still pay underlying AWS storage fees for a stopped instance, but the EJBCA software billing tracks active running time per instance.
How do I scale as my certificate volume grows?
You choose an instance size that fits your workload and can move to a larger type as demand rises. Deployments start around 2,500 active certificates and scale to millions. You can also run your PKI on a single instance or cluster nodes across regions.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Product Support:
To register with Keyfactor Support, please send an email to marketplace-support@keyfactor.com and note that you are an AWS customer. Please note that Keyfactor Support has no other way to identify you as a Keyfactor customer unless you first contact us at marketplace-support@keyfactor.com. You will then be asked to fill out a questionnaire so that we can identify you in our system. Please do not expect a response from support without completing this process first.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Support for multiple Certificate Authorities (CAs) and hierarchical CA levels with unlimited Root CAs and SubCAs, enabling cross-certificate and bridge certificate issuance between CAs.
Key Management and Storage
Support for storing cryptographic keys in CloudHSM, AWS KMS, PKCS11-connected HSM, or database, with web-based configuration wizard for key generation options.
Protocol and API Support
Support for ACME protocol and REST API for certificate issuance and management operations.
PKI Authority Functions
Implementation of Certificate Authority (CA), Registration Authority (RA), and Validation Authority (VA) functions within a single instance.
Certificate Lifecycle Management
Full lifecycle control of digital certificates from issuance through management and revocation across multiple use cases and standards compliance scenarios.
Hardware Security Module Integration
FIPS 140-2 Level 3 validated Cloud HSMs utilized for securing Certificate Authority keys with high availability
Post-Quantum Cryptography Support
Support for NIST-standardized PQC encryption algorithms including Dilithium, SPHINCS+, and Falcon for quantum-resistant certificate issuance
Certificate Lifecycle Management Automation
Integrated end-to-end certificate lifecycle management automation for provisioning and management of private and public certificates from centralized console
Access Control and Key Management
M of N control mechanism enforced for all Certificate Authority related operations with strict access and security policies
Certificate Status Verification
Online Certificate Status Protocol (OCSP) support for certificate status verification and revocation checking
Key Lifecycle Management
Supports comprehensive key and certificate lifecycle management including key storage, generation, rotation, distribution, and usage policies.
Cryptographic Algorithm Support
Implements FIPS 140-3 validated encryption libraries, Covercrypt for post-quantum resistance with access policy support, and Findex for search encryption capabilities.
Public Key Infrastructure Integration
Provides seamless integration with external Public Key Infrastructure systems for managing keys and certificates beyond organizational boundaries.
On-the-Fly Encryption and Decryption
Delivers real-time encryption and decryption key operations for protecting sensitive data including workspace, research and development data, HR information, and electronic communications.
Simplicity and Efficiency in Certificate Management
Reviewed on Dec 11, 2025
Review provided by G2
What do you like best about the product?
I really like the simplicity of Keyfactor EJBCA®. It is very easy to understand, manage, and configure. There is a large amount of manuals available to set up the service, whether with a container or directly from the source code, and it was quite easy for us to modify the code without any problem.
What do you dislike about the product?
The most complicated issue that is causing us some friction now would be the disconnection with the HSM services. I understand it's due to the type of library, the PKCS11, used for this type of connection, but it's what could cause us some trouble at the moment. We need to be vigilant; if the connection drops, reestablish it and restart WildFly if we have a token disconnection.
What problems is the product solving and how is that benefiting you?
Keyfactor EJBCA® has simplified setting up a PKI quickly and easily, meeting the required standards in Chile. The documentation is clear, facilitating the administration, configuration, and modification of the software according to our needs.
David T. K.
Powerful PKI toolset, with a steep step-up to get value
Reviewed on Oct 07, 2025
Review provided by G2
What do you like best about the product?
EJBCA offers a wealth of capabilities, enabling virtually all workflows for enrolling, managing, and distributing certificates. EJBCA often implements leading-edge features ahead of other PKI toolkits, enabling early access to capabilities.
What do you dislike about the product?
Implementing EJBCA is challenging, when using the straightforward software distribution methods. I know this can be remedied when using virtual appliances on either a virtualization platform or containers platform.
What problems is the product solving and how is that benefiting you?
We anticipate EJBCA solving hands-off certificate enrollment/renewal, as well as enabling us to offer quantum-safe certificates to early adopters.
Computer & Network Security
Good overall product
Reviewed on Oct 07, 2025
Review provided by G2
What do you like best about the product?
you can create multiple CAs in one machine.
What do you dislike about the product?
RA web UX/UI needs to be improved as it is hard sometimes to know exactly what to do
What problems is the product solving and how is that benefiting you?
security and ease of use
Alston Bejo P.
User Experience and Onboarding
Reviewed on Sep 21, 2025
Review provided by G2
What do you like best about the product?
Keyfactor EJBCA is built with a comprehensive REST API. This is crucial for a PKI management tool like Keyfactor Command, as it allows for programmatic and automated lifecycle management of certificates. Instead of manual certificate requests, the API enables Keyfactor Command to enroll, renew, and revoke certificates on a massive scale, which is the entire purpose of a streamlined PKI management system.
What do you dislike about the product?
The platform is incredibly powerful, but the sheer number of features and the complex UI make it feel like a tool for PKI experts, not for general IT administrators. A smoother onboarding process or more intuitive UI similar to keyfactor command for handling common tasks would be a massive improvement
What problems is the product solving and how is that benefiting you?
while the POC may have hit a snag, the underlying architecture of Keyfactor EJBCA is what makes it a premier choice for integration with a PKI management tool.
Telecommunications
Consistently Reliable and Flexible PKI Platform
Reviewed on Sep 12, 2025
Review provided by G2
What do you like best about the product?
"What I like best about Keyfactor EJBCA is its reliability and flexibility. It fully meets our security and compliance requirements, and over the years it has consistently proven to be a stable and dependable solution. In addition, the support team has always provided prompt and precise feedback whenever needed."
What do you dislike about the product?
"Overall, there is not much to dislike about Keyfactor EJBCA. The documentation could be even more comprehensive in some advanced areas, but the support team has always been very responsive and helpful in clarifying any doubts."
What problems is the product solving and how is that benefiting you?
Keyfactor EJBCA is helping us manage our public key infrastructure reliably and securely. It ensures compliance with our security requirements, simplifies certificate management, and gives us the confidence that our systems are protected.