Supported Algorithms

This page provides a high-level overview of algorithm support across the logical layers involved in EJBCA certificate signing. Detailed information about enrollment protocols, Certificate Authority (CA) types, and Hardware Security Module (HSM) support is documented in their respective documentation sections.

This overview is intended as a reference and may not always reflect the latest changes to individual features or components. In case of inconsistencies, the feature-specific or component-specific documentation is considered authoritative.

Supported Algorithms for Certificate Signing

EJBCA supports the following key algorithms, signature algorithms, and key specifications for certificate signing.

Note that HSM support depends on vendor implementation, firmware capabilities, and operational mode. Confirm with your HSM supplier that the required algorithms are supported in your target configuration, including FIPS mode where applicable. Operating an HSM in FIPS mode may impose additional restrictions, such as disallowing SHA1-based signature algorithms.

Key Algorithm / Key Specification

Signature Algorithm

Enrollment Protocol

CA Type

HSM Support

RSA (RSASSA-PKCS1_v1.5 and RSASSA-PSS)

Keys up to and including 8192 bits.


SHA1withRSA

ACME, EST, CMP, SCEP,
REST Interface, Web Service Interface

X509 CA, CVC CA, SSH CA

Supported Hardware Security Modules (HSMs)

SHA224withRSA

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA, SSH CA

SHA256withRSA

ACME, EST, CMP, SCEP,
REST Interface, Web Service Interface

X509 CA, CVC CA, SSH CA

SHA384withRSA

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA, SSH CA

SHA512withRSA

ACME, EST, CMP, SCEP,
REST Interface, Web Service Interface

X509 CA, SSH CA

SHA1withRSAandMGF1

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA, CVC CA, SSH CA

SHA224withRSAandMGF1

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA, SSH CA

SHA256withRSAandMGF1

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA, CVC CA, SSH CA

SHA384withRSAandMGF1

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA, SSH CA

SHA512withRSAandMGF1

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA, SSH CA

ECDSA

Algorithm with named curves.

SHA1withECDSA

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA, CVC CA, SSH CA

Supported Hardware Security Modules (HSMs)

SHA224withECDSA

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA, CVC CA

SHA256withECDSA

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA, CVC CA

SHA384withECDSA

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA, CVC CA

SHA512withECDSA

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA, CVC CA

EdDSA

Ed25519

Ed25519

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA, SSH CA

Supported Hardware Security Modules (HSMs)

Ed448

Ed448

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA, SSH CA

ML-DSA

ML-DSA-44

ML-DSA-44

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

  • AWS Key Management Service (KMS)

  • Entrust nShield Connect 5c

  • Fortanix Data Security Manager (DSM)

  • Thales Luna 7

  • Thales TCT

  • Securosys Primus HSM and CloudHSM Service

  • Utimaco u.trust Anchor

ML-DSA-65

ML-DSA-65

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

ML-DSA-87

ML-DSA-87

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

ML-DSA

ML-DSA-EXTERNAL-MU

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

  • AWS Key Management Service (KMS)

  • Thales Luna 7

  • Utimaco u.trust Anchor

ML-DSA Composite

ML-DSA-44 & RSA 2048

MLDSA44-RSA2048-PSS-SHA256

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

  • AWS Key Management Service (KMS)

  • Entrust nShield Connect 5c

  • Fortanix Data Security Manager (DSM)

  • Thales Luna 7

  • Thales TCT

  • Securosys Primus HSM and CloudHSM Service

  • Utimaco u.trust Anchor

ML-DSA-44 & ECDSA

MLDSA44-ECDSA-P256-SHA256

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

ML-DSA-44 & Ed25519

MLDSA44-Ed25519-SHA512

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

ML-DSA-65 & RSA 3072

MLDSA65-RSA3072-PSS-SHA512

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

ML-DSA-65 & RSA 4096

MLDSA65-RSA4096-PSS-SHA512

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

ML-DSA-65 & ECDSA

MLDSA65-ECDSA-P256-SHA512

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

ML-DSA-65 & ECDSA

MLDSA65-ECDSA-P384-SHA512

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

ML-DSA-65 & ECDSA

MLDSA65-ECDSA-brainpoolP256r1-SHA512

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

ML-DSA-65 & Ed25519

MLDSA65-Ed25519-SHA512

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

ML-DSA-87 & RSA 3072

MLDSA87-RSA3072-PSS-SHA512

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

ML-DSA-87 & RSA 4096

MLDSA87-RSA4096-PSS-SHA512

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

ML-DSA-87 & ECDSA

MLDSA87-ECDSA-P384-SHA512

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

ML-DSA-87 & ECDSA

MLDSA87-ECDSA-P521-SHA512

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

ML-DSA-87 & ECDSA

MLDSA87-ECDSA-brainpoolP384r1-SHA512

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

ML-DSA-87 & Ed448

MLDSA87-Ed448-SHAKE256

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

SLH-DSA

SLH-DSA

SLH-DSA-SHA2-128F

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

  • Securosys Primus HSM and CloudHSM Service

SLH-DSA

SLH-DSA-SHA2-128S

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

SLH-DSA

SLH-DSA-SHA2-192F

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

SLH-DSA

SLH-DSA-SHA2-192S

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

SLH-DSA

SLH-DSA-SHA2-256F

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

SLH-DSA

SLH-DSA-SHA2-256S

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

SLH-DSA

SLH-DSA-SHAKE-128F

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

SLH-DSA

SLH-DSA-SHAKE-128S

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

SLH-DSA

SLH-DSA-SHAKE-192F

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

SLH-DSA

SLH-DSA-SHAKE-192S

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

SLH-DSA

SLH-DSA-SHAKE-256F

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA

SLH-DSA

SLH-DSA-SHAKE-256S

ACME, EST, CMP,
REST Interface, Web Service Interface

X509 CA