Keyfactor licensing is the set of terms under which Keyfactor, Inc. sells and distributes its public key infrastructure (PKI) and certificate management software. Three lines matter to a software asset manager. Keyfactor Command is licensed by component, and for many customers by a count of “actioned” certificates. EJBCA is a certificate authority available as an open-source Community edition and as commercial Enterprise software, appliance, cloud and software-as-a-service forms. SignServer is a server-side signing framework with the same Community and Enterprise split.[1][2][3] Commercial purchases are made under an End User License Agreement (EULA) and an Order Form that states the licence metrics and fees.[4]
Product lines
| Product | How it is licensed | Deeper article |
|---|---|---|
| Keyfactor Command | By component, through a signed .cmslicense file; an Actioned Certificates count or a Site-License with no cap[1] | Keyfactor Command licensing and actioned certificates |
| EJBCA Community | Open source under the GNU Lesser General Public License v2.1 or later; not intended for production[5][2] | EJBCA and SignServer licensing |
| EJBCA Enterprise, Software Appliance, Cloud and SaaS | Commercial; appliance licence file with an active certificate maximum; SaaS contracts by duration and size[6][7] | same |
| SignServer Community | Open source under the LGPL v2.1 or later; core capabilities for evaluation and testing[8][3] | same |
| SignServer Enterprise | Commercial edition with support and production features[3] | same |
| Contract terms | EULA and Order Form[4] | Keyfactor End User License Agreement and Order Forms |
The catalog rows behind these are Keyfactor Command, EJBCA Community, EJBCA Enterprise, EJBCA SaaS, EJBCA Software Appliance, SignServer Community and SignServer Enterprise.
Keyfactor does not publish a price list in the cited documents, so the catalog holds no list prices.
Commercial contract
The EULA is made between Keyfactor, Inc., a Delaware corporation, and the customer, effective from the date of the initial Order Form. It grants a “revocable, non-exclusive, non-transferable, limited license” to use the software and documentation for internal business purposes during the applicable Subscription Term.[4] The grant is subject to payment and to the license metrics set out on the Order Form, and the Order Form takes precedence over the EULA in a conflict.[4] Catalog proof: EULA licence is revocable, limited and for the Subscription Term; Order Form takes precedence over the EULA.
The EULA gives Keyfactor a usage-reporting right for software it does not host. On request, no more than once a calendar quarter, the customer sends a report of monthly usage for the prior 12 months in accordance with the Order Form’s license metrics, and any use beyond the licence is invoiced at Keyfactor’s then current list price.[4] Orders renew automatically for the stated period, or one year if none is stated, unless either party gives 60 days’ written notice. On renewal, unless the pricing is designated one-time, multi-year per-unit pricing increases by 3% annually on a compounded basis, and a one-year renewal is priced at an 8% increase over the prior term.[4] Catalog proof: Quarterly usage report on request for non-hosted Software; Renewal uplift is 3% a year for multi-year and 8% for one-year subscriptions.
How use is counted
Keyfactor documents several measures, depending on the product:
- Actioned certificates in Keyfactor Command: certificates that were requested through Command, revoked in the past week, carry metadata, sit in a managed certificate store, hold a private key stored in Command, or belong to a collection used by an expiration alert or workflow. They are counted once each, every day at 2:00 am UTC by default.[1]
- Active certificates in the EJBCA Software Appliance: the number of active certificates is compared with the maximum in the licence file.[6]
- Active and total certificate capacity in EJBCA SaaS, such as 2500 active and 10,000 total for the Entry Level option.[9]
- Order Form metrics for other software, which the EULA illustrates as licences or instances used, environments, certificates issued or managed, and endpoints monitored or managed.[4]
Enforcement differs by product. Exceeding the actioned certificate count in Command raises a warning alert and does not interrupt functionality, while the EJBCA appliance stops running without a valid licence file after a 90-day grace period following expiry.[1][6] A software asset manager should therefore expect commercial exposure for Command to arise from the usage report and renewal process rather than from a technical stop. Catalog proof: Exceeding the actioned certificate count only raises a warning; EJBCA appliance licence has a 90-day grace period after expiry.
Open-source and commercial editions
EJBCA Community and SignServer Community are open-source projects sponsored by Keyfactor, released under the LGPL version 2.1 or later; the licence file in the ejbca-ce repository is the GNU Lesser General Public License Version 2.1 of February 1999.[5][8][10] Keyfactor describes EJBCA Community as intended for learning, testing and prototyping in non-production environments, with security updates delivered on a delayed cycle and no advanced high availability, HSM support, compliance features or SLAs.[2] The Enterprise editions add support, hardening and deployment options.[11][3] The LGPL grants the use rights that an open-source licence grants; the support and production features come from a commercial agreement. An estate that runs the Community edition in production has no commercial entitlement to those, and the vendor’s own guidance is that it is not designed or supported for that use. Catalog proof: EJBCA Community is released under LGPL v2.1 or later; EJBCA Community is not intended for production use.
Deployment and purchasing routes
Enterprise PKI is offered as software, as an appliance built on EJBCA Enterprise, from the AWS or Azure marketplaces as EJBCA Cloud with a free 30-day trial, and as a hosted EJBCA SaaS contract.[12][2][7] SignServer Enterprise can be deployed as software or hardware appliances and on AWS or Azure.[13] When a customer buys through a Keyfactor-authorized reseller, it pays the reseller under its contract with the reseller.[4] Hardware is provided under a separate Hardware Addendum, and professional services under their own terms, each incorporated by reference.[4]
Out of scope
This article does not cover Keyfactor’s privacy policy, service level agreement or professional services terms, the Hardware Addendum text. Keyfactor marketing pages for PKI as a Service did not return text content to automated requests, so the hosted PKI offering is described only through the EJBCA SaaS documentation.