September 2026
The EJBCA team is pleased to announce the release of EJBCA 9.7.
This version includes improvements and corrections across SCEP, EST, Certificate Revocation List (CRL) publishing, Certification Authority Authorization (CAA), Intune, the REST API, and ConfigDump. It also includes updates to Hardware Security Module (HSM) support, WildFly, and Bouncy Castle.
For available deployment types and associated versions, refer to Supported Versions.
Highlights
Support for WildFly 41
EJBCA 9.7 introduces support for WildFly 41. For more information about software requirements, see Installation Prerequisites.
Note: Due to the WildFly 41 upgrade in the EJBCA container, all multi-node EJBCA 9.7 deployments must use sticky sessions when deployed with a load balancer in front of the EJBCA instances, as described in High Availability and Clustering.
Before upgrading a multi-node deployment, confirm that your load balancer is configured for sticky sessions.
REST API Improvements
Approvals for CA Activation
Approval for CA activation can now be performed through the REST API.
New ca_type Attribute in GET /v1/ca Response
The GET /ejbca/ejbca-rest-api/v1/ca endpoint has been enhanced to include the CA type in the response.
Bouncy Castle Upgrade
Bouncy Castle has been upgraded to version 1.86. For information about the latest Bouncy Castle releases, refer to the Bouncy Castle Release Notes.
dnsjava Upgrade
dnsjava has been upgraded to version 3.6.5.
Support for MPIC Lambda 1.8.0
EJBCA's Multi-Perspective Issuance Corroboration (MPIC) implementation has been tested against, and now supports, MPIC Lambda version 1.8.0 (Open MPIC API Specification 3.9.0). For more information, see MPIC Validator.
Thales Luna HSM High Availability Support
EJBCA 9.7 Container Set deployments support mounting a custom Chrystoki.conf file for Thales Luna HSMs, which enables high availability (HA) mode. For more information, refer to Thales Luna Integration in Kubernetes.
Announcements
Correction to EJBCA 9.6.2 Release Notes
The EJBCA 9.6.2 release notes incorrectly stated that accounturi validation over MPIC was implemented. This functionality is pending the implementation of corresponding functionality in Open MPIC.
Deprecation of AJP Listener Support
As of EJBCA 9.7, support for the Apache JServ Protocol (AJP) listener is deprecated and will be removed in a future release. This follows WildFly's deprecation of the ajp-listener in the Undertow subsystem.
While the AJP listener remains supported for now, it is strongly recommended to migrate to HTTP proxying, which provides the same functionality with proper TLS and mutual authentication support. This deprecation is recorded in the EJBCA Deprecation Timeline, which tracks deprecation and removal versions across EJBCA releases.
Deprecation of C-ITS Support
As of EJBCA 9.7, support for acting as an Enrollment Authority (EA) in a C-ITS PKI is deprecated. Support for C-ITS is planned for removal in EJBCA 9.8, targeted for Q4 2026. This deprecation is recorded in the EJBCA Deprecation Timeline.
Upgrade Information
Review the EJBCA Upgrade Notes for important upgrade information. For upgrade instructions and information on upgrade paths, see Upgrading EJBCA.
Change Log: Resolved Issues
The following lists implemented improvements and fixed issues in EJBCA 9.7.
Issues Resolved in 9.7.0
Released September 2026
New Features
ECA-15289 PKCS11v3.3 External-mu-ML-DSA support, with Securosys Primus PKCS11 and Entrust nShield 5c
Improvements
ECA-13158 Allow forbidding issuance of wildcard certificates using tls-alpn-01
ECA-14643 Add Helm support to mount custom Chrystoki.conf in Luna to allow HA mode
ECA-14802 REST API Approvals - CA Activation
ECA-15052 Update MPIC Lambda to 1.8.0
ECA-15064 Upgrade the EJBCA container to use WildFly 41.0.1
ECA-15091 Implement JsonDateSerializer in a thread safe way
ECA-15291 Upgrade to BC 1.86
ECA-15169 Upgrade dnsjava to 3.6.5
ECA-15186 Add ca_type attribute to the GET /v1/ca REST response
ECA-15193 Document limitation of SCEP GetCRL not working in “Use separate keys for SCEP decryption” mode
ECA-15228 Update SoftHSM version in Helm Chart
ECA-15240 Upgrade P11NG to version 0.30.2 or later to improve Thales detection check.
ECA-15286 Fix and deprecate AJP
ECA-15187 Upgrade cvc-cert to 1.7.0
ECA-15241 Documentation: limitations for Generate CRL on Revocation
ECA-15352 Deprecate C-ITS support
Bug Fixes
ECA-12752 CMP Response Protection does not refresh available values when in RA Mode
ECA-14536 Handle SAN URI string the same way for end entity creation and update.
ECA-14632 Admin Web - View End Entity - Incorrectly presented SSH related fields
ECA-14840 Intune service incorrectly reports revocations as errors.
ECA-14842 Transaction issue with keystore creation from RA web
ECA-14879 End entity setstatus endpoint quietly disables batch generation
ECA-14985 Values are missing when importing certificate profiles to EJBCA
ECA-15069 DoS vulnerability in PostgreSQL JDBC driver in container, need to upgrade to 42.7.11 or later
ECA-15093 IssuerDN input for REST keyrecover isn't normalized
ECA-15098 Certificate profiles with Any CA inaccessible
ECA-15100 SCEP CA Mode - End Entity Status Reset to NEW with Single Active Certificate Constraint
ECA-15122 Downloaded openAPI.json for EJBCA REST API changes
ECA-15134 Fix description label for the ACME configuration DNS resolver
ECA-15165 Missing commons-codec dependency in ejbca-ejb-cli
ECA-15177 v1/ca returns null expiration date for SSH CA's
ECA-15180 Cryptotokens lib not updated in .classpath file for v 4.1.0
ECA-15182 Fix missing information in SCEP unknown CA error
ECA-15188 Certificate profile with Any CA is not visible to not root user
ECA-15199 Fix issue with issuevmc tag
ECA-15200 getcrl auth bypass
ECA-15203 AWS KMS token with Service Account Role authentication fails after running for several hours
ECA-15217 AcmeEndPoint accesses profiles locally when using MPIC, which does not work with peer connections
ECA-15224 Wrong name Partitioned CRL
ECA-15226 EST Client Mode Username Extraction for DN\(whole subjectDN\) does not work
ECA-15227 Regression: CertificateProfile field USE_MS_OBJECTSID_SECURITY_EXTENSION is not upgraded anymore
ECA-15235 Ed448 on nShield does not work
ECA-15236 Remove ML-KEM as an available signature algorithm
ECA-15247 End entity profiles are imported but not visible
ECA-15257 Change maxlength for URI inputs in CA page
ECA-15293 RA UI edit EE have all keystore types that EE profile does not allow