EJBCA
EJBCA Integration
Section titled “EJBCA Integration”Integrate EJBCA with SSL-CLM to:
- Issue certificates using certificate profiles and end entity profiles
- Renew certificates
- Revoke certificates
- Discover certificate templates/profiles
- Sync certificate inventory
EJBCA integrates directly via its REST API with mutual TLS authentication. No agent is required.
Architecture
Section titled “Architecture”SSL-CLM Platform││ (HTTPS + mTLS client certificate)▼EJBCA Server (REST API)│▼Certificate AuthorityPrerequisites
Section titled “Prerequisites”- EJBCA instance (Community or Enterprise) with REST API enabled
- Client certificate and key for mTLS authentication to EJBCA
- Network access from SSL-CLM backend to EJBCA REST API
- Certificate profile and end entity profile configured in EJBCA
Step 1 — Prepare EJBCA
Section titled “Step 1 — Prepare EJBCA”Enable REST API
Section titled “Enable REST API”Ensure the EJBCA REST API is accessible:
https://ejbca.internal.corp/ejbca/ejbca-rest-apiCreate Client Certificate
Section titled “Create Client Certificate”Generate or issue a client certificate that EJBCA will trust for API authentication. This certificate must be in a role with appropriate permissions (RA Administrator or similar).
Note Certificate Profile and End Entity Profile
Section titled “Note Certificate Profile and End Entity Profile”You will need:
- CA Name — The CA within EJBCA to issue from
- Certificate Profile Name — Defines key constraints, extensions, and validity
- End Entity Profile Name — Defines allowed subject fields and request parameters
Step 2 — Create Certificate Authority in SSL-CLM
Section titled “Step 2 — Create Certificate Authority in SSL-CLM”- Navigate to Infrastructure → Certificate Authorities
- Click + Add CA
- Select EJBCA from the type cards
- Fill in the configuration:
| Field | Description | Example |
|---|---|---|
| Name | Friendly name | EJBCA Production |
| Base URL | EJBCA REST API endpoint | https://ejbca.internal.corp/ejbca/ejbca-rest-api |
| Client Certificate | PEM-encoded client cert for mTLS | (paste or upload) |
| Client Key | PEM-encoded private key for mTLS | (paste or upload, stored encrypted) |
| CA Name | Target CA name within EJBCA | MyOrg-SubCA |
| Certificate Profile | Certificate profile name | TLSServer |
| End Entity Profile | End entity profile name | TLSServerEndEntity |
| Discovery Interval | Hours between inventory syncs | 24 |
- Click Test Connection to verify
- Click Save
Step 3 — Load Templates
Section titled “Step 3 — Load Templates”After saving, click Load Templates on the CA detail page.
SSL-CLM will query EJBCA’s API and discover:
- Available certificate profiles
- End entity profiles
- Key constraints per profile
- Validity settings
These templates appear in the enrollment workflow when users select this CA.
Step 4 — Issue Certificates
Section titled “Step 4 — Issue Certificates”- Navigate to Certificates → + New Certificate
- Select Issue from CA
- Choose the EJBCA CA
- Select the desired template/profile (if multiple are available)
- Fill in subject and SAN details
- Submit
SSL-CLM will:
- Generate a CSR
- Call EJBCA’s certificate enrollment REST endpoint
- Provide the CSR, profile names, and subject data
- Receive the issued certificate
- Store it in inventory
Step 5 — Revoke Certificates
Section titled “Step 5 — Revoke Certificates”When revocation is requested:
- SSL-CLM calls EJBCA’s revocation endpoint with the certificate serial number
- EJBCA revokes the certificate and updates its CRL
- SSL-CLM updates the certificate status to REVOKED
- Next inventory sync confirms revocation
Supported Operations
Section titled “Supported Operations”| Operation | API Endpoint | Description |
|---|---|---|
| Enroll | POST /v1/certificate/enrollkeystore | Issue certificate from CSR |
| Revoke | PUT /v1/certificate/{issuer_dn}/{serial}/revoke | Revoke by serial |
| Status | GET /v1/certificate/{issuer_dn}/{serial} | Check certificate status |
| Search | POST /v1/certificate/search | Search issued certificates |
| Profiles | GET /v1/certificate/profiles | List available profiles |
Troubleshooting
Section titled “Troubleshooting”| Issue | Possible Cause | Resolution |
|---|---|---|
| Connection refused | REST API not enabled or wrong URL | Verify EJBCA REST API is running and accessible |
| 403 Forbidden | Client cert not in authorized role | Check EJBCA role assignments for the client cert |
| mTLS handshake failure | Wrong client cert or CA mismatch | Verify client cert is trusted by EJBCA’s TLS config |
| Profile not found | Name mismatch | Check exact profile name in EJBCA admin UI |
| Enrollment rejected | End entity profile constraints violated | Verify subject fields match profile requirements |
Security Considerations
Section titled “Security Considerations”- Store the mTLS client private key securely (SSL-CLM encrypts it in vault)
- Use a dedicated client certificate for SSL-CLM — don’t share with other systems
- Restrict the EJBCA role to minimum required permissions
- Enable TLS 1.2+ on the EJBCA REST API
- Rotate the client certificate periodically