# ejbca

Source: https://startwithidentity.com/vendors/pki/ejbca/
Last updated: 2026-07-03
License: content by Start with Identity. Cite the source URL.

---

## Overview
EJBCA is one of the most widely used enterprise PKI and certificate authority platforms, originally open source from PrimeKey and now part of Keyfactor. It issues and manages digital certificates for people, devices, and workloads at scale.

## What it is good at
EJBCA is a mature, standards-rich CA supporting a broad range of protocols and use cases, from TLS to device and IoT identity, with flexible deployment as software, appliance, or SaaS. Its open-source heritage and configurability make it a default for organizations that want to run their own certificate authority.

## Where it falls short
Running a CA is real operational work, and EJBCA's depth carries a learning curve. Teams wanting only lightweight, automated TLS issuance may prefer simpler ACME-first tools.

## Pricing
Open-source community edition plus commercial enterprise licensing and support from Keyfactor.

## Best for, and who should look elsewhere
Choose EJBCA to operate a flexible, standards-rich enterprise CA. Look elsewhere for a fully managed CA or a developer-first ACME tool (see [Smallstep](https://startwithidentity.com/vendors/pki/smallstep/)).

## Bottom line
A battle-tested enterprise CA with unmatched deployment flexibility, best for organizations running their own PKI.
