9.7 9.6.2 9.6 9.5 9.4.2 9.3.6 9.3.5 9.3.4 9.3.3 9.3.2
9.7 9.6.2 9.6 9.5 9.4.2 9.3.6 9.3.5 9.3.4 9.3.3 9.3.2

EJBCA 9.7 Release Notes

September 2026

The EJBCA team is pleased to announce the release of EJBCA 9.7.

This version includes improvements and corrections across SCEP, EST, Certificate Revocation List (CRL) publishing, Certification Authority Authorization (CAA), Intune, the REST API, and ConfigDump. It also includes updates to Hardware Security Module (HSM) support, WildFly, and Bouncy Castle.

For available deployment types and associated versions, refer to Supported Versions.

Highlights

Support for WildFly 41

EJBCA 9.7 introduces support for WildFly 41. For more information about software requirements, see Installation Prerequisites.

Note: Due to the WildFly 41 upgrade in the EJBCA container, all multi-node EJBCA 9.7 deployments must use sticky sessions when deployed with a load balancer in front of the EJBCA instances, as described in High Availability and Clustering.

Before upgrading a multi-node deployment, confirm that your load balancer is configured for sticky sessions.

REST API Improvements

Approvals for CA Activation

Approval for CA activation can now be performed through the REST API.

New ca_type Attribute in GET /v1/ca Response

The GET /ejbca/ejbca-rest-api/v1/ca endpoint has been enhanced to include the CA type in the response.

Bouncy Castle Upgrade

Bouncy Castle has been upgraded to version 1.86. For information about the latest Bouncy Castle releases, refer to the Bouncy Castle Release Notes.

dnsjava Upgrade

dnsjava has been upgraded to version 3.6.5.

Support for MPIC Lambda 1.8.0

EJBCA's Multi-Perspective Issuance Corroboration (MPIC) implementation has been tested against, and now supports, MPIC Lambda version 1.8.0 (Open MPIC API Specification 3.9.0). For more information, see MPIC Validator.

Thales Luna HSM High Availability Support

EJBCA 9.7 Container Set deployments support mounting a custom Chrystoki.conf file for Thales Luna HSMs, which enables high availability (HA) mode. For more information, refer to Thales Luna Integration in Kubernetes.

Announcements

Correction to EJBCA 9.6.2 Release Notes

The EJBCA 9.6.2 release notes incorrectly stated that accounturi validation over MPIC was implemented. This functionality is pending the implementation of corresponding functionality in Open MPIC.

Deprecation of AJP Listener Support

As of EJBCA 9.7, support for the Apache JServ Protocol (AJP) listener is deprecated and will be removed in a future release. This follows WildFly's deprecation of the ajp-listener in the Undertow subsystem.

While the AJP listener remains supported for now, it is strongly recommended to migrate to HTTP proxying, which provides the same functionality with proper TLS and mutual authentication support. This deprecation is recorded in the EJBCA Deprecation Timeline, which tracks deprecation and removal versions across EJBCA releases.

Deprecation of C-ITS Support

As of EJBCA 9.7, support for acting as an Enrollment Authority (EA) in a C-ITS PKI is deprecated. Support for C-ITS is planned for removal in EJBCA 9.8, targeted for Q4 2026. This deprecation is recorded in the EJBCA Deprecation Timeline.

Upgrade Information

Review the EJBCA Upgrade Notes for important upgrade information. For upgrade instructions and information on upgrade paths, see Upgrading EJBCA.

Change Log: Resolved Issues

The following lists implemented improvements and fixed issues in EJBCA 9.7.

Issues Resolved in 9.7.0

Released September 2026

New Features

ECA-15289 PKCS11v3.3 External-mu-ML-DSA support, with Securosys Primus PKCS11 and Entrust nShield 5c

Improvements

ECA-13158 Allow forbidding issuance of wildcard certificates using tls-alpn-01

ECA-14643 Add Helm support to mount custom Chrystoki.conf in Luna to allow HA mode

ECA-14802 REST API Approvals - CA Activation

ECA-15052 Update MPIC Lambda to 1.8.0

ECA-15064 Upgrade the EJBCA container to use WildFly 41.0.1

ECA-15091 Implement JsonDateSerializer in a thread safe way

ECA-15291 Upgrade to BC 1.86

ECA-15169 Upgrade dnsjava to 3.6.5

ECA-15186 Add ca_type attribute to the GET /v1/ca REST response

ECA-15193 Document limitation of SCEP GetCRL not working in “Use separate keys for SCEP decryption” mode

ECA-15228 Update SoftHSM version in Helm Chart

ECA-15240 Upgrade P11NG to version 0.30.2 or later to improve Thales detection check.

ECA-15286 Fix and deprecate AJP

ECA-15187 Upgrade cvc-cert to 1.7.0

ECA-15241 Documentation: limitations for Generate CRL on Revocation

ECA-15352 Deprecate C-ITS support

Bug Fixes

ECA-12752 CMP Response Protection does not refresh available values when in RA Mode

ECA-14536 Handle SAN URI string the same way for end entity creation and update.

ECA-14632 Admin Web - View End Entity - Incorrectly presented SSH related fields

ECA-14840 Intune service incorrectly reports revocations as errors.

ECA-14842 Transaction issue with keystore creation from RA web

ECA-14879 End entity setstatus endpoint quietly disables batch generation

ECA-14985 Values are missing when importing certificate profiles to EJBCA

ECA-15069 DoS vulnerability in PostgreSQL JDBC driver in container, need to upgrade to 42.7.11 or later

ECA-15093 IssuerDN input for REST keyrecover isn't normalized

ECA-15098 Certificate profiles with Any CA inaccessible

ECA-15100 SCEP CA Mode - End Entity Status Reset to NEW with Single Active Certificate Constraint

ECA-15122 Downloaded openAPI.json for EJBCA REST API changes

ECA-15134 Fix description label for the ACME configuration DNS resolver

ECA-15165 Missing commons-codec dependency in ejbca-ejb-cli

ECA-15177 v1/ca returns null expiration date for SSH CA's

ECA-15180 Cryptotokens lib not updated in .classpath file for v 4.1.0

ECA-15182 Fix missing information in SCEP unknown CA error

ECA-15188 Certificate profile with Any CA is not visible to not root user

ECA-15199 Fix issue with issuevmc tag

ECA-15200 getcrl auth bypass

ECA-15203 AWS KMS token with Service Account Role authentication fails after running for several hours

ECA-15217 AcmeEndPoint accesses profiles locally when using MPIC, which does not work with peer connections

ECA-15224 Wrong name Partitioned CRL

ECA-15226 EST Client Mode Username Extraction for DN\(whole subjectDN\) does not work

ECA-15227 Regression: CertificateProfile field USE_MS_OBJECTSID_SECURITY_EXTENSION is not upgraded anymore

ECA-15235 Ed448 on nShield does not work

ECA-15236 Remove ML-KEM as an available signature algorithm

ECA-15247 End entity profiles are imported but not visible

ECA-15257 Change maxlength for URI inputs in CA page

ECA-15293 RA UI edit EE have all keystore types that EE profile does not allow