LICENSEWARE

Keyfactor EJBCA and SignServer licensing

This article is about how Keyfactor licenses EJBCA and SignServer: the open-source Community editions under the GNU LGPL, the commercial Enterprise editions, the EJBCA Software Appliance licence file, EJBCA Cloud and the EJBCA SaaS contract options. It is not legal advice.

On This Page

EJBCA is a certificate authority (CA) software project, and SignServer is a server-side framework for digital signatures. Both started as open-source projects and Keyfactor sponsors both. Each therefore has two licensing faces: an open-source Community edition that anyone can download and use under the GNU Lesser General Public License, and commercial Enterprise editions sold by Keyfactor.[1][2] A software asset manager needs to establish which edition is running, because the licence terms, the support position and the evidence of entitlement differ.

EJBCA Community and the LGPL

The EJBCA site states that EJBCA Community Edition is an open-source project sponsored by Keyfactor, first released in 2001, and “released under LGPL V2.1 (or later)”. The page also says the software depends on third-party components under licences such as Apache 2.0, LGPL 2.1, BSD, MIT and EPL, and points to a lib folder in the project repository for the complete list.[1] The LICENSE file in the Keyfactor/ejbca-ce repository is the GNU Lesser General Public License Version 2.1, February 1999.[3] The LGPL permits use, modification and redistribution subject to its conditions, which concern chiefly the library’s own source and how it is linked into other programs; see GNU GPL, LGPL and AGPL obligations for a general treatment. Catalog proof: EJBCA Community is released under LGPL v2.1 or later; EJBCA LICENSE file is the GNU LGPL version 2.1.

Keyfactor’s own comparison is explicit that the open-source licence is not the whole commercial question. EJBCA Community Edition is “intended for learning, testing, and prototyping” and allows users to explore PKI concepts, validate integrations and evaluate core functionality in non-production environments.[4] The page says Community is not intended for production use because bug fixes and security updates arrive on a delayed release cycle compared with the Enterprise Edition, and because enterprise-grade capabilities, including advanced high availability, HSM support, compliance features and SLAs, are not included.[4] The product documentation says Community is not designed or supported for production use and recommends Enterprise for PKI that supports business-critical systems or critical infrastructure.[5] Catalog proof: EJBCA Community is not intended for production use; EJBCA Community lacks enterprise HA, HSM support, compliance features and SLAs; EJBCA Enterprise is recommended for production and business-critical PKI.

Edition differences visible in documentation

The library manifest lists every library used in EJBCA with its licence and has a column marking libraries available only in the Enterprise edition. The page says libraries marked Enterprise are only available in EJBCA Enterprise.[6] Comparing a deployed build with the manifest is one way to tell which edition an installation carries. The documentation’s deployment table assigns the Docker deployments to Community, Kubernetes deployments with Helm to Community with limited functionality or Enterprise, and a Preconfigured Test Drive and the cloud trial to Enterprise.[5] Catalog proof: Some EJBCA libraries are Enterprise Edition only.

EJBCA Enterprise delivery forms

Keyfactor’s comparison page distinguishes EJBCA Community from “EJBCA Enterprise” and “EJBCA Cloud”, with the latter offering “Free 30-day trial on AWS or Azure marketplaces” with Enterprise edition functionality, and Enterprise offering advanced PKI functionality, multiple deployment options and a support agreement with SLA.[4] Deployment forms include container, Helm and source builds, the software and hardware appliance, EJBCA Cloud on AWS and Azure, and EJBCA SaaS.[4] Catalog proof: EJBCA Enterprise; EJBCA Cloud; EJBCA Cloud offers a free 30-day trial.

EJBCA Software Appliance licence

The EJBCA Software Appliance is based on EJBCA Enterprise and is offered in model tiers: Starter (models A and B), Professional (C to E), Scale (F to H) and Enterprise (I and J). The documented active certificate capacity is 2,500 to 10,000 for Starter, 25,000 to 100,000 for Professional, 150,000 to 500,000 for Scale and 1 million to 2.5 million or more for Enterprise.[7]

To use the EJBCA application in the appliance the customer must upload the licence provided by Keyfactor. EJBCA can only start if a valid licence has been uploaded; an update without one stops the service but loses no data or key material.[8] EJBCA and the EJBCA LRA do not start if no licence is available or the uploaded licence has expired beyond the grace period. A warning appears in the web configuration 60 days before expiry, and the software remains functional for up to 90 days after the licence expires, with a red warning, before it shuts down.[8] The licence screen shows the product name and version, licence ID, customer name, issued and expiry dates and a feature table. In that table the number of active EJBCA Active Certificates is compared with the maximum number of certificates permitted by the purchased licence, the status showing the number of active certificates and then the number of valid ones. A 12-hour control interval checks validity, a warning is shown when the licence is invalid or more certificates exist than the licence allows, and only one licence can be active at a time.[8] Catalog proof: EJBCA appliance stops without a valid licence file; EJBCA appliance licence has a 90-day grace period after expiry; Active certificate count is compared with the licensed maximum; Appliance models are sized by active certificate capacity.

EJBCA SaaS

EJBCA SaaS is a hosted PKI in Keyfactor’s environment, subscribed to through a marketplace. It comes in contract sizes and options. The Entry Level option, for small production workloads and enterprise test or lab environments, has a 99.9% SLA, capacity for 2500 active and 10,000 total certificates and one region and availability zone. The Available Upon Request option, for enterprise and manufacturing workloads, offers up to a 99.99% SLA, multi-region options and capacity up to billions of certificates.[9]

On AWS Marketplace, EJBCA SaaS is a contract-based subscription chosen by duration and size. The durations are 1, 12, 24 and 36 months, and each longer duration gives a larger discount. The customer can allow AWS to renew automatically for the same duration. Sizes are described as XS, S and M, backed either by AWS KMS or by CloudHSM, with different cores, memory and database capacity. AWS bills the full contract duration when the contract is created. A customer may select a higher option at any time, with the difference billed, but cannot select a cheaper option until the current contract expires.[10] For capacity planning that means the contract size is a floor for the duration, while growth is billed pro rata. Catalog proof: EJBCA SaaS Entry Level capacity is 2500 active and 10,000 total certificates; AWS SaaS contract durations are 1, 12, 24 or 36 months; AWS SaaS size can be raised but not lowered during the contract.

SignServer

SignServer is described as a flexible, server-side framework for digital signatures. It supports code signing, document signing, time-stamping and ePassports, hosts multiple signers, organizations and users in one instance, and keeps signing keys on the server side, preferably in an HSM.[11] The SignServer site says the Community edition is an open-source project sponsored by Keyfactor and “released under LGPL V2.1 (or later)”, first released in 2005, with third-party components under Apache 2.0, LGPL 2.1, BSD, MIT, EPL and other licences.[2] The about page adds that the first version was released by PrimeKey in 2005 and that the Enterprise edition was developed and released in 2012; Community is available as prebuilt binaries, containers or source code.[12] Catalog proof: SignServer Community is released under LGPL v2.1 or later.

The documentation sets out the edition split. SignServer Enterprise “offers the security hardening, automation, scalability, and professional support required in production”, and some advanced features in the reference are available only in the Enterprise Edition, as indicated by an Enterprise label. SignServer Community “is open-source and provides a core set of capabilities for evaluation and testing.”[11] The about page adds that organizations should move to Enterprise when their signing service needs SLAs, security and audit-proof configurations, or a deployment option such as a hardware or software appliance, SaaS or cloud, and that a 30-day free trial is available on the AWS and Azure marketplaces.[12] Catalog proof: SignServer Community is for evaluation and testing; Some SignServer features are Enterprise Edition only; SignServer Enterprise offers appliance, SaaS and cloud deployments with SLAs.

Counting practice

  • Inventory each EJBCA and SignServer instance by edition, and by delivery form: container, source build, appliance, cloud or SaaS.
  • For Community instances, record the LGPL obligations that apply to any redistribution or modification, and record whether the instance is in production, which Keyfactor says Community is not designed for.
  • For appliances, keep the licence file, its expiry and the active certificate maximum, and compare the count shown on the licence screen with the capacity of the purchased model.
  • For SaaS, record the contract duration, size and renewal setting, and remember that AWS allows upsizing but not downsizing during the term.
  • For all commercial editions, the EULA and Order Form set renewal, reporting and excess use; see Keyfactor End User License Agreement and Order Forms.

Out of scope

This article does not cover the licences of each third-party library bundled with EJBCA or SignServer, which are listed in the library manifest and the projects’ lib folders. It does not cover the EJBCA Azure Marketplace plan details, the PQC Lab test drive, or Keyfactor’s PKI as a Service marketing pages, which returned no text content to automated requests. The terms of the commercial agreement are in the EULA article.

References

  1. Licenses - EJBCAEJBCA Community released under LGPL V2.1 (or later). Undated.Retrieved 2026-10-08.
  2. Licenses - SignServerSignServer Community released under LGPL V2.1 (or later). Undated.Retrieved 2026-10-08.
  3. ejbca-ce/LICENSE at mainGNU Lesser General Public License Version 2.1, February 1999.Retrieved 2026-10-08.
  4. EJBCA Community vs EnterpriseProse differences between Community, Cloud and Enterprise. Undated.Retrieved 2026-10-08.
  5. Get Started with EJBCADeployment options; Community versus Enterprise. Undated.Retrieved 2026-10-08.
  6. Library Manifest (EJBCA)Enterprise Edition Only column. Undated.Retrieved 2026-10-08.
  7. EJBCA Software Appliance Model SpecificationsModel tiers and active certificate capacity. Undated.Retrieved 2026-10-08.
  8. Settings: License Management (EJBCA Software Appliance)Licence file, grace period and Active Certificates. Undated.Retrieved 2026-10-08.
  9. Contract Subscription Options (EJBCA SaaS)Entry Level capacity and options. Undated.Retrieved 2026-10-08.
  10. Subscribe to EJBCA SaaS in AWSContract durations and upgrade rule. Undated.Retrieved 2026-10-08.
  11. Introduction (SignServer)Enterprise and Community editions. Undated.Retrieved 2026-10-08.
  12. About SignServer: Open Source Signing SoftwareCommunity and Enterprise editions; trial. Undated.Retrieved 2026-10-08.

See also

Catalog Rows Cited

18Rules2SKUs4Metrics4Programs

Esc