Skip to content

EJBCA

Integrate EJBCA with SSL-CLM to:

  • Issue certificates using certificate profiles and end entity profiles
  • Renew certificates
  • Revoke certificates
  • Discover certificate templates/profiles
  • Sync certificate inventory

EJBCA integrates directly via its REST API with mutual TLS authentication. No agent is required.


SSL-CLM Platform
│
│ (HTTPS + mTLS client certificate)
▼
EJBCA Server (REST API)
│
▼
Certificate Authority

  • EJBCA instance (Community or Enterprise) with REST API enabled
  • Client certificate and key for mTLS authentication to EJBCA
  • Network access from SSL-CLM backend to EJBCA REST API
  • Certificate profile and end entity profile configured in EJBCA

Ensure the EJBCA REST API is accessible:

https://ejbca.internal.corp/ejbca/ejbca-rest-api

Generate or issue a client certificate that EJBCA will trust for API authentication. This certificate must be in a role with appropriate permissions (RA Administrator or similar).

Note Certificate Profile and End Entity Profile

Section titled “Note Certificate Profile and End Entity Profile”

You will need:

  • CA Name — The CA within EJBCA to issue from
  • Certificate Profile Name — Defines key constraints, extensions, and validity
  • End Entity Profile Name — Defines allowed subject fields and request parameters

Step 2 — Create Certificate Authority in SSL-CLM

Section titled “Step 2 — Create Certificate Authority in SSL-CLM”
  1. Navigate to Infrastructure → Certificate Authorities
  2. Click + Add CA
  3. Select EJBCA from the type cards
  4. Fill in the configuration:
FieldDescriptionExample
NameFriendly nameEJBCA Production
Base URLEJBCA REST API endpointhttps://ejbca.internal.corp/ejbca/ejbca-rest-api
Client CertificatePEM-encoded client cert for mTLS(paste or upload)
Client KeyPEM-encoded private key for mTLS(paste or upload, stored encrypted)
CA NameTarget CA name within EJBCAMyOrg-SubCA
Certificate ProfileCertificate profile nameTLSServer
End Entity ProfileEnd entity profile nameTLSServerEndEntity
Discovery IntervalHours between inventory syncs24
  1. Click Test Connection to verify
  2. Click Save

After saving, click Load Templates on the CA detail page.

SSL-CLM will query EJBCA’s API and discover:

  • Available certificate profiles
  • End entity profiles
  • Key constraints per profile
  • Validity settings

These templates appear in the enrollment workflow when users select this CA.


  1. Navigate to Certificates → + New Certificate
  2. Select Issue from CA
  3. Choose the EJBCA CA
  4. Select the desired template/profile (if multiple are available)
  5. Fill in subject and SAN details
  6. Submit

SSL-CLM will:

  1. Generate a CSR
  2. Call EJBCA’s certificate enrollment REST endpoint
  3. Provide the CSR, profile names, and subject data
  4. Receive the issued certificate
  5. Store it in inventory

When revocation is requested:

  1. SSL-CLM calls EJBCA’s revocation endpoint with the certificate serial number
  2. EJBCA revokes the certificate and updates its CRL
  3. SSL-CLM updates the certificate status to REVOKED
  4. Next inventory sync confirms revocation

OperationAPI EndpointDescription
EnrollPOST /v1/certificate/enrollkeystoreIssue certificate from CSR
RevokePUT /v1/certificate/{issuer_dn}/{serial}/revokeRevoke by serial
StatusGET /v1/certificate/{issuer_dn}/{serial}Check certificate status
SearchPOST /v1/certificate/searchSearch issued certificates
ProfilesGET /v1/certificate/profilesList available profiles

IssuePossible CauseResolution
Connection refusedREST API not enabled or wrong URLVerify EJBCA REST API is running and accessible
403 ForbiddenClient cert not in authorized roleCheck EJBCA role assignments for the client cert
mTLS handshake failureWrong client cert or CA mismatchVerify client cert is trusted by EJBCA’s TLS config
Profile not foundName mismatchCheck exact profile name in EJBCA admin UI
Enrollment rejectedEnd entity profile constraints violatedVerify subject fields match profile requirements

  • Store the mTLS client private key securely (SSL-CLM encrypts it in vault)
  • Use a dedicated client certificate for SSL-CLM — don’t share with other systems
  • Restrict the EJBCA role to minimum required permissions
  • Enable TLS 1.2+ on the EJBCA REST API
  • Rotate the client certificate periodically