We are pleased to announce the release of EJBCA Community Edition 9.6, the latest version of our open-source PKI software.
This release adds new capabilities for teams preparing their PKI for post-quantum cryptography, along with improvements that make EJBCA easier to automate, integrate, and administer. Highlights include ML-DSA composite certificate support, new REST API capabilities, expanded OAuth support, and user interface improvements.
Release highlights include
- ML-DSA composite certificate support: Issue certificates using composite keys that combine a classical cryptographic key, such as RSA, ECDSA, or EdDSA, with a quantum-safe ML-DSA key.
- More PKI workflows through the REST API: Automate approval workflows through the REST API and export a CA Certificate Signing Request (CSR) for signing by an external CA. CA activation approval is not supported through the REST API.
- Expanded OAuth support: Configure a set of valid hostnames to support redirects and authentication across multiple hostnames, with built-in support for Auth0 as a Trusted OAuth (OpenID Connect) provider.
- User interface improvements: Updates across several administration pages improve layout, navigation, and consistency.
- Updated recommended environment: Java 21 is now the recommended Java runtime environment for EJBCA 9.6, with WildFly 39 as the recommended application server.
Important change for HSM Crypto Token users
As of EJBCA 9.6, all use of HSM Crypto Tokens requires EJBCA Enterprise Edition.
If you are running an earlier version of EJBCA Community Edition with HSM Crypto Tokens configured, you will need to either migrate to EJBCA Enterprise Edition or delete those HSM Crypto Tokens before upgrading to EJBCA Community Edition 9.6.
For more information