EJBCA® Software Appliance

With PrimeKey EJBCA Software Appliance, you get the most used PKI in the world, packaged as an easy-to-deploy software appliance and installed within minutes.

Contact us Download Product Sheet

The most used PKI in the world

Feature-complete PKI

EJBCA Software Appliance supports all your public key infrastructure (PKI) use cases and scales with your needs. It offers clustering possibilities and comes in five models, from XS to XL.

Off-the-shelf packaged solution

The self-contained software package runs on your virtualization platform and lets you plug in your existing hardware security module (HSM). 

Rapid deployment within minutes

Easy and fast deployment with a stable package that includes the complete software stack - not only the PKI applications. 

EJBCA Software Appliance user interface

The graphical user interface in EJBCA Software Appliance, makes it easy to deploy and maintain your EJBCA instances. 

Features of EJBCA Software Appliance

EJBCA Software Appliance includes EJBCA Enterprise and offers an easy and cost-efficient way to deploy and maintain an enterprise PKI system. Leverage your virtualization environment and pick the HSM of your choice.


Complete and easy to deploy enterprise PKI solution

EJBCA Software Appliance supports most of your PKI use cases. In a single instance, you can run multiple certificate authorities (CAs), subordinate CAs, registration authorities (RAs) and validation authorities (VAs). In addition, EJBCA Software Appliance comes as a fully tested and complete software technology package. It is delivered in a virtual machine (VM) and you can leverage your existing virtualization environment. 


Easy to maintain and operate

Easy and effective management is the key to a secure and reliable PKI deployment. With EJBCA Software Appliance, updates and upgrades are delivered as complete and tested software packages. Backup and restore routines are robust and simplified to reduce manual errors.


Bring your own HSM

To ensure the protection of private keys, PrimeKey recommends using an HSM. With EJBCA Software Appliance, you can reuse your existing HSM infrastructure. 


Flexible for your use cases

PrimeKey understands that organizations have different needs and business requirements - and that things evolve over time. We therefore offer the EJBCA Software Appliance in five different models ranging from XS to XL. This gives you the possibility to start small and grow with your use cases.

Related resources

About PrimeKey
EJBCA Enterprise
EJBCA Hardware Appliance
EJBCA Software Appliance

EJBCA® Enterprise achieves Common Criteria certification

We are proud to announce that PrimeKey’s EJBCA Enterprise has achieved Common Criteria certification conformant to the Protection Profile for Certification Authorities, a Collaborative Protection Profiles (cPP) approved by the National Information Asso...
enabling security through PKI
On-demand webinar
Corporate PKI
EJBCA Enterprise
EJBCA Hardware Appliance
EJBCA Software Appliance
PKI migration

Webinar: Own your own risks – Modern manufacturers on-prem security journey to the Cloud

Let us demonstrate together with Thales how manufacturing organizations can benefit from robust and securely built PKI implementations. Date: 12 May Time: 11 AM CET Duration: 1 hour Presented by: Paul Hampton, Cyber Security Specialist, Thales Tom...
Android signing schemes, compliance and crypto agility
Tech update
EJBCA Enterprise
EJBCA Hardware Appliance
EJBCA Software Appliance

EJBCA plugin available for Hashicorp Vault

Hashicorp Vault is a popular tool  for encryption services and secrets management. The Vault is available both as open source and Enterprise versions. It can be deployed as a container in any cloud environment. The Vault allows applications  to generate...

Five models optimized for your needs

The EJBCA Software Appliance is available in five different models ranging from an XS model, which is designed to operate as a dedicated root CA, to an XL, which is suited for extremely large PKI deployments.

Extra Small EJBCA Software Appliance

Model Extra Small is the smallest Software Appliance with support for up to 1,000 certificates. This model is ideal for an offline Root CA in a PKI deployment.

Small EJBCA Software Appliance

This is your PKI start environment - EJBCA with everything you need. The Small model supports the operation of multiple, independent PKI hierarchies with one installation, and up to 1 million certificates. 

Medium EJBCA Software Appliance

Start with model Medium if you already know that you need more certificates. This model supports up to 15 million certificates.

Large EJBCA Software Appliance

Model Large can manage even more certificates. If you have one or a couple of use cases that require a high number of certificates, and you soon expect to add additional use cases on top, then you should choose this model. 

Extra Large EJBCA Software Appliance

Model XL is suited for extremely large PKI deployments with the need for more than 100 million certificates. It supports up to 160 million certificates.

Read more on Model Specifications

Stand-alone models

The following stand-alone models are also available, including the Validation Authority and Registration Authority modules and the eIDAS edition. 

EJBCA Registration Authority

The EJBCA RA is an external entity to the Certificate Authority (CA). It is used for registration and enrollment of any type of certificate and adds an additional layer of security around the CA.

Read more

EJBCA Validation Authority

EJBCA Validation Authority (VA) offers real-time certificate validation with OCSP and CRLs.

Read more

eIDAS edition

The software appliance is also available as an eIDAS edition with support for eIDAS approved Common Criteria-certified HSMs.

Read more on Doc

Customer stories from PKI implementations around the globe

communication tower. cell, radio and television antennas on top

EJBCA Enterprise, Telecom

Powering 5G innovation through security, open standards and flexible integration

Attorneys talking

EJBCA Enterprise, Enterprise, Trust Service Provider

Bundesnotarkammer – Innovation and security in German notaries

DGN Customer Story, PrimeKey

EJBCA Enterprise, Enterprise, Trust Service Provider

Securing and enabling German healthcare


Document signing, EJBCA Enterprise, SignServer Enterprise, Timestamping, Trust Service Provider

The Faroe Islands – Creating a Future-Proof National e-ID

vault and businessman

Bank & Finance, EJBCA Enterprise, Trust Service Provider

Bank-Verlag – Launching an eIDAS-compliant trust center for the German banking industry

EJBCA Telecom

EJBCA Enterprise, PKI migration, Trust Service Provider

Swisscom – Becoming eIDAS compliant and migrating from RSA to EJBCA Enterprise

Contact us

Fill in your contact information below and we will get in touch with you.