Skip to content

CA Capability Matrix

This page provides a comprehensive comparison of capabilities across all supported Certificate Authority integrations in SSL-CLM v2.


CapabilityMicrosoft AD CSSmallstep CAACME / Let’s EncryptEJBCAAWS Private CAGoogle CAS
Enroll✓✓✓✓✓✓
Renew✓✓✓✓✓✓
Revoke✓✓✓✓✓✓
Template Discovery✓——✓——
Template Selection✓——✓✓ (via ARN)—
Inventory Sync✓✓—✓✓✓
Health Check✓✓✓✓✓✓
Wildcard Certs✓✓✓ (DNS-01 only)✓✓✓
SAN Support✓✓✓✓✓✓
Custom ValidityTemplate-based✓90 days (fixed)Profile-based✓✓
Auto-Renewal✓✓✓✓✓✓

CAType IDRuntimeAgent RequiredProtocol
Microsoft AD CSMSCAAgentYesWinRM / certutil
Smallstep CASTEPCABackendNoREST API + JWK tokens
ACME / Let’s EncryptACMEBackendNoACME (RFC 8555)
EJBCAEJBCABackendNoREST API + mTLS
AWS Private CAACMPCABackendNoAWS SDK
Google CASGOOGLE_CASBackendNoGoogle Cloud API

CAPrimary AuthCredentials Required
Microsoft AD CSDomain/Kerberos (via Agent)Domain-joined agent, optional ADCS username/password
Smallstep CAJWK ProvisionerJWK private key (EC P-256), provisioner name, key ID
ACME / Let’s EncryptACME Account KeyDirectory URL, account email, optional EAB (KID + HMAC)
EJBCAMutual TLSClient certificate + key, CA name, profile names
AWS Private CAIAM CredentialsAccess Key ID, Secret Access Key, CA ARN, region
Google CASService AccountService account JSON, project ID, location, CA pool ID

CADomain ValidationHow It Works
Microsoft AD CSTemplate-basedCA enforces template constraints; no domain validation
Smallstep CAProvisioner-basedJWK token authorizes issuance; no external validation
ACME / Let’s EncryptChallenge-basedDNS-01, HTTP-01, or TLS-ALPN-01 challenges
EJBCAProfile-basedEnd entity profile constraints; optional approval
AWS Private CAIAM PolicyAWS IAM policies control who can issue
Google CASIAM PolicyGCP IAM policies control who can issue

CARSAECDSAEd25519Min Key Size
Microsoft AD CS✓✓—Template-defined
Smallstep CA✓✓✓Provisioner-defined
ACME / Let’s Encrypt✓✓—2048 (RSA)
EJBCA✓✓✓Profile-defined
AWS Private CA✓✓—2048 (RSA)
Google CAS✓✓—2048 (RSA)

CADefault ValidityConfigurableMaximum
Microsoft AD CSTemplate-definedPer templateUp to CA validity
Smallstep CAProvisioner-defined✓Configurable
ACME / Let’s Encrypt90 daysNo90 days
EJBCAProfile-definedPer profileUp to CA validity
AWS Private CAConfigurable✓Up to CA validity
Google CASConfigurable✓Up to CA validity

Use CaseRecommended CA
Enterprise Windows environment with ADMicrosoft AD CS
Internal microservices / DevOpsSmallstep CA
Public-facing websites (free, automated)Let’s Encrypt (ACME)
Enterprise PKI with complex profilesEJBCA
AWS-native workloadsAWS Private CA
GCP-native workloadsGoogle CAS
Multi-cloud or hybridSmallstep CA or EJBCA
IoT / embedded devicesEJBCA or Smallstep CA
Short-lived certificates (< 24h)Smallstep CA

CALicense Model
Microsoft AD CSIncluded with Windows Server (Enterprise CAL)
Smallstep CAOpen source (community) or commercial (Smallstep)
Let’s EncryptFree
ZeroSSLFree tier + paid plans
EJBCAOpen source (community) or commercial (Keyfactor)
AWS Private CAPer-certificate pricing ($0.75/cert/month for general certs)
Google CASPer-certificate pricing (DevOps tier: $0.10/cert, Enterprise: $2-3/cert)