This VA instance requires an EJBCA Certificate Authority Instance to fully function.
EJBCA PKI for Enterprises - A powerful and flexible certificate issuance and management system to issue and enable full life-cycle control of digital certificates. This instance is a EJBCA Validation Authority (VA) instance with OCSP and CRL functionality. This instance is not a Certificate Authority. Please choose one of the full instances if you need a Certificate Authority. This instance is designed to be peered with another EJBCA Enterprise CA instance for a fully separated certificate authority hierarchy. It can be paired with any EJBCA Enterprise Instance of equal version whether it be a cloud, PKI Appliance or on-prem software installation.
You must have an existing keypair to be able to access the admin UI of this instance once configured. You will be asked for the username of that keypair and the public certificate of the CA that issued it during the installation of this node.
EJBCA includes support for CloudHSM, and has introduced support for the ACME protocol as well as a REST API. Please visit the EJBCA Enterprise Cloud documentation for a CloudHSM integration guide. This instance includes Standard Support but is functionally identical to the Premium Support listing.
A VA server that can resepond for multiple CAs and levels of CAs, build a complete infrastructure (or several) within one instance of EJBCA.
Full OCSP and CRL functionality through peer connections to an EJBCA Enterprise CA host
Support all common PKI Architectures, as well as many uncommon. Store keys in CloudHSM, AWS KMS, in a PKCS11 connected HSM, or in the database (for demo).
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 30 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
EJBCA Enterprise Cloud Validation Authority (VA) - Premium Support
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pay by the hour for the compute instance that runs your Validation Authority (VA), plus premium support. Each dimension maps to a specific AWS EC2 instance size, so pricing scales with the compute capacity you choose. You pick one instance type to match your workload. Smaller instances handle lighter demand; larger instances add more CPU and memory. There is no long-term commitment — billing follows usage hours. The VA instance peers with a separate EJBCA CA instance to keep certificate validation functions on their own hardware.
Top-of-mind questions for buyers
What determines which instance dimension I should choose for my Validation Authority?
Each dimension maps to an AWS EC2 instance size with set CPU and memory. Larger instances hold more compute for higher certificate validation demand. You match the instance type to your expected workload and can scale up on-demand as needs grow.
Am I charged when the Validation Authority instance is stopped or idle?
Hourly software charges follow running time, so you pay per hour the instance runs. A fully stopped instance does not accrue hourly software charges. Underlying AWS storage fees may still apply while the instance is stopped. There is no long-term commitment.
Does the hourly price include premium support, and what does that cover?
Yes. This listing bundles premium support with the hourly instance charge. Keyfactor offers 24×7 expert support for EJBCA Cloud deployments. You pay one hourly rate tied to your chosen instance size, and support comes with it. No separate support fee applies.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Product Support:
To register with Keyfactor Support, please send an email to marketplace-support@keyfactor.com and note that you are an AWS customer. Please note that Keyfactor Support has no other way to identify you as a Keyfactor customer unless you first contact us at marketplace-support@keyfactor.com. You will then be asked to fill out a questionnaire so that we can identify you in our system. Please do not expect a response from support without completing this process first.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Full Online Certificate Status Protocol (OCSP) and Certificate Revocation List (CRL) functionality through peer connections to an EJBCA Enterprise CA host
Hardware Security Module Integration
Support for storing cryptographic keys in CloudHSM, AWS KMS, PKCS11-connected HSM, or database storage options
Multi-CA Validation
Validation Authority server capable of responding for multiple Certificate Authorities and hierarchical CA levels within a single instance
API and Protocol Support
Support for ACME protocol and REST API for certificate management and automation
PKI Architecture Flexibility
Support for common and uncommon Public Key Infrastructure architectures with ability to build complete infrastructure hierarchies
Hardware Security Module Integration
FIPS 140-2 Level 3 validated Cloud HSMs utilized for securing Certificate Authority keys with high availability
Post-Quantum Cryptography Support
Support for NIST-standardized PQC encryption algorithms including Dilithium, SPHINCS+, and Falcon for quantum-resistant certificate issuance
Certificate Lifecycle Management Automation
Integrated end-to-end certificate lifecycle management automation for provisioning and management of private and public certificates from centralized console
Access Control and Key Management
M of N control mechanism enforced for all Certificate Authority related operations with strict access and security policies
Certificate Status Verification
Online Certificate Status Protocol (OCSP) support for certificate status verification and revocation checking
Key Lifecycle Management
Supports comprehensive key and certificate lifecycle management including key storage, generation, rotation, distribution, and usage policies.
Cryptographic Algorithm Support
Implements FIPS 140-3 validated encryption libraries, Covercrypt for post-quantum resistance with access policy support, and Findex for search encryption capabilities.
Public Key Infrastructure Integration
Provides seamless integration with external Public Key Infrastructure systems for managing keys and certificates beyond organizational boundaries.
On-the-Fly Encryption and Decryption
Delivers real-time encryption and decryption key operations for protecting sensitive data including workspace, research and development data, HR information, and electronic communications.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.