EJBCA Validation Authority
The EJBCA Validation Authority (VA) software component enables certificate validation using OCSP or CRLs.
Real-time certificate validation
Features of EJBCA Validation Authority
Validation is conveniently performed with PrimeKey’s open source EJBCA Validation Authority (VA). The EJBCA VA offers several advantages through its use of both an OCSP Responder and a Certificate and CRL distribution feature.
The most comprehensive VA solution
The mainstay of any Validation Authority is the Online Certificate Status Protocol (OCSP) responder. Through the VA, clients can instantly request the revocation status of individual certificates, without the need to download the full Certificate Revocation List (CRL). Meanwhile, CRLs and CA certificate distribution are also available.
No vendor lock-in
The EJBCA VA can provide certificate revocation services to any PKI, including EJBCA. It is developed on the same flexible and robust platform as EJBCA but packaged as a stand-alone component. The EJBCA VA smoothly accommodates every organization’s requirement.
Enterprise scalability
EJBCA Validation Authority has support for the leading Hardware Security Modules (HSMs) and allows easy and reliable clustering. This ensures linear scalability. It is even possible to shut down a node for maintenance, while other nodes continue to answer requests. The EJBCA Validation Authority contains a built-in monitoring facility, ensuring that the responder is functioning properly at all times. High performance is ensured; more than 500 requests per second can be achieved on a single server.
Security by design
The Common Criteria-certified platform offers highly configurable audit and transaction logging, a built-in health check used for load balancing and monitoring, and configurable requirements for signed requests, authorized signers, and so on. When there is a need to keep the CA in an enclosed environment with limited access and the VA in a DMZ or even publicly, secure communication can be ensured by using the EJBCA Peers Systems protocol, which is based on mutually authenticated TLS.
EJBCA deployment options
To account for the unique business challenges of your organization, including security, budget and the availability of internal resources, PrimeKey offers a combination of deployment options to suit your needs today and allow you to grow flexibly over time.
Software Appliance
Deploy your PKI in your own data center using your native virtualization resources. Select the HSM and the appliance model that best suit your needs.
Hardware Appliance
Select the EJBCA Hardware Appliance when you are looking for an on-premises PKI-in-a-box solution. EJBCA Hardware Appliance is a hardened, high-performance server that comes with the complete hardware and software stack and an HSM.
EJBCA Cloud
Enjoy rapid deployment with PKI in a public cloud, with no hardware to purchase and maintain or any upfront software license costs. Our cloud-based PKI solutions are available in AWS and Azure.
EJBCA Software as a Service
If you are looking for a fully hosted and managed PKI solution, then EJBCA SaaS is your choice. It helps limit deployment risks and increase your speed to market.
Do you need a hybrid deployment?
Do you want to combine on-premises and cloud? Or do you need help to find the best deployment option for your use case? See our documentation on hybrid PKI deployments or get in touch with us.
More information
See the links for more information on EJBCA Validation Authority and related products.
Contact us
Fill in your contact information below and we will get in touch with you.