This VA instance requires an EJBCA Certificate Authority Instance to fully function.
EJBCA PKI for Enterprises - A powerful and flexible certificate issuance and management system to issue and enable full life-cycle control of digital certificates. This instance is a EJBCA Validation Authority (VA) instance with OCSP and CRL functionality. This instance is not a Certificate Authority. Please choose one of the full instances if you need a Certificate Authority. This instance is designed to be peered with another EJBCA Enterprise CA instance for a fully separated certificate authority hierarchy. It can be paired with any EJBCA Enterprise Instance of equal version whether it be a cloud, PKI Appliance or on-prem software installation.
You must have an existing keypair to be able to access the admin UI of this instance once configured. You will be asked for the username of that keypair and the public certificate of the CA that issued it during the installation of this node.
EJBCA includes support for CloudHSM and AWS KMS, and has introduced support for the ACME protocol as well as a REST API. Please visit the EJBCA Enterprise Cloud documentation for a CloudHSM integration guide. This instance includes Standard Support but is functionally identical to the Premium Support listing.
A VA server that can respond for multiple CAs and levels of CAs, build a complete infrastructure (or several) within one instance of EJBCA.
Full OCSP and CRL functionality through peer connections to an EJBCA Enterprise CA host.
Support all common PKI Architectures, as well as many uncommon. Store keys in CloudHSM, AWS KMS, in a PKCS11 connected HSM, or in the database (for demo).
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 30 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
EJBCA Enterprise Cloud Validation Authority (VA) - Standard Support
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pay by the hour for the EC2 instance size you run this Validation Authority on. The 18 options map to AWS instance types across the t2, t3, t3a, c5, m3, and m5a families. Larger instances offer more compute, so hourly rates rise with size. There is no long-term commitment. You pick one instance size that fits your workload, then scale up or down by switching sizes as demand changes. Billing is usage-based, so you only pay for the hours the instance runs.
Top-of-mind questions for buyers
What is a Validation Authority instance, and why run it separately from the CA?
A Validation Authority (VA) answers certificate status checks, confirming whether certificates are still valid. You run it on its own EC2 instance, peered with a separate Certificate Authority instance. This separation keeps signing and validation functions on distinct servers within your PKI hierarchy.
Am I charged when the EC2 instance is stopped or powered off?
The software charge meters running hours only. A fully stopped instance stops accruing the hourly software fee. Underlying AWS storage tied to the stopped instance may still incur separate AWS charges, but the listing itself bills per hour the instance runs.
If I outgrow my chosen instance size, do I upgrade automatically or manually?
You choose one instance size that fits your workload. Scaling is manual: you switch to a different instance type when demand changes. There is no automatic tier jump. The new size then bills at its own hourly rate for the hours it runs.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Product Support:
To register with Keyfactor Support, please send an email to marketplace-support@keyfactor.com and note that you are an AWS customer. Please note that Keyfactor Support has no other way to identify you as a Keyfactor customer unless you first contact us at marketplace-support@keyfactor.com. You will then be asked to fill out a questionnaire so that we can identify you in our system. Please do not expect a response from support without completing this process first.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Full Online Certificate Status Protocol (OCSP) and Certificate Revocation List (CRL) functionality through peer connections to an EJBCA Enterprise Certificate Authority host.
Hardware Security Module Integration
Support for key storage in AWS CloudHSM, AWS KMS, PKCS11-connected Hardware Security Modules, or database storage.
Multi-CA Validation
Validation Authority server capable of responding for multiple Certificate Authorities and hierarchical levels, enabling complete PKI infrastructure within a single instance.
ACME Protocol Support
Support for Automated Certificate Management Environment (ACME) protocol for certificate issuance and lifecycle management.
REST API Access
REST API interface for programmatic access to certificate management and validation functions.
Hardware Security Module Integration
FIPS 140-2 Level 3 validated Cloud HSMs utilized for securing Certificate Authority keys with high availability
Post-Quantum Cryptography Support
Support for NIST-standardized PQC encryption algorithms including Dilithium, SPHINCS+, and Falcon for quantum-resistant certificate issuance
Certificate Lifecycle Management Automation
Integrated end-to-end certificate lifecycle management automation for provisioning and management of private and public certificates from centralized console
Access Control and Key Management
M of N control mechanism enforced for all Certificate Authority related operations with strict access and security policies
Certificate Status Verification
Online Certificate Status Protocol (OCSP) support for certificate status verification and revocation checking
Key Lifecycle Management
Supports comprehensive key and certificate lifecycle management including key storage, generation, rotation, distribution, and usage policies.
Cryptographic Algorithm Support
Implements FIPS 140-3 validated encryption libraries, Covercrypt for post-quantum resistance with access policy support, and Findex for search encryption capabilities.
Public Key Infrastructure Integration
Provides seamless integration with external Public Key Infrastructure systems for managing keys and certificates beyond organizational boundaries.
On-the-Fly Encryption and Decryption
Delivers real-time encryption and decryption key operations for protecting sensitive data including workspace, research and development data, HR information, and electronic communications.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.