Entrust to EJBCA Migration
Project Description
The engagement
Unsung partnered with the Head of Trust Services within a large public sector organisation to execute the re-platforming of 20 Root Certificate Authorities from an end-of-life vendor platform (Entrust) to a modern, strategically aligned platform (EJBCA). This migration represented a critical infrastructure modernisation initiative driven by evolving technical requirements that the legacy platform could no longer adequately support.
The migration was necessitated by emerging organisational requirements for automated certificate enrolment capabilities via industry-standard SCEP and ACME interfaces. These automation protocols were essential to support modern DevOps workflows, CI/CD pipelines, and autoscaling compute infrastructure that formed the foundation of the organisation's cloud transformation strategy.
Why the legacy platform could no longer serve
The existing platform had served the organisation reliably for a considerable period, and the decision to migrate was not a reflection on its historic performance. It was a reflection of a change in what the organisation needed a certificate authority to do. A platform designed around managed, human-mediated certificate issuance cannot readily support an estate where infrastructure provisions itself and applications request their own credentials as part of a deployment pipeline. Approaching end of life compounded the position, introducing support and assurance exposure alongside the functional gap.
Root certificate authorities are also the most consequential component of any trust hierarchy. Every certificate the organisation relied upon chained back to them, and every system that validated a certificate depended on those roots being present, correct and trusted. Twenty of them, supporting an enterprise-scale estate, is a substantial migration by any measure.
Why standards-based enrolment was the driver
SCEP and ACME are not simply convenient interfaces; they are what allows certificate issuance to become part of an automated build rather than a request raised against a team. Where infrastructure scales automatically, or where deployment pipelines create and destroy environments many times a day, certificates must be obtained and renewed by the systems that need them, at the moment they need them, without a person in the path. A platform that cannot expose those interfaces places a manual step inside an otherwise automated process, and that step becomes the limiting factor on the whole pipeline.
The organisation's cloud transformation strategy therefore made the enrolment gap a strategic constraint rather than an operational inconvenience. Certificate issuance was on the critical path for the wider programme, which is what moved the migration from a technology refresh that could be scheduled at leisure to an enabling activity with a defined dependency behind it.
The constraint that shaped the engagement
The requirement was to migrate without operational impact to business services. That constraint did more to shape the delivery approach than any other factor. It ruled out approaches that would have required consuming systems to be reconfigured or trust stores to be updated at scale, since each of those would have introduced risk and coordination overhead across a large and diverse estate. It placed the emphasis instead on achieving exact parity between the legacy and target platforms, so that downstream systems would continue to validate trust chains without being aware that anything had changed beneath them.
Outcomes & Deliverables
Unsung successfully delivered a complex platform migration that achieved all client objectives whilst maintaining seamless business operations:
- Successfully migrated all 20 Entrust Root Certificate Authorities to the EJBCA platform with zero operational impact to business services.
- Achieved substantial reduction in business-as-usual operational costs and licensing expenditure through platform consolidation.
- Delivered comprehensive governance documentation aligned to the client's assurance frameworks and regulatory compliance requirements.
The engagement was run through Unsung's structured delivery framework, adapted for migration work, with formal review gates between phases and full governance documentation maintained throughout.
Discovery and due diligence
The engagement began with detailed due diligence across all twenty root certificate authorities: their configuration, the certificate structures they issued, their key material and protection arrangements, and the systems that depended upon them. Migration engagements succeed or fail on the completeness of this phase. A dependency identified during discovery is a planning consideration; the same dependency identified during cutover is an incident. Requirements were baselined in an approved Statement of Requirements, and project governance established through a delivery plan, communications plan and RAID log.
Design and migration methodology
Design work addressed both the target platform architecture and, critically, the migration method itself. With no vendor-supported migration path available, developing a documented, repeatable and verifiable method was a design deliverable in its own right rather than an operational detail. The High-Level Design covered technical, operational and business change dimensions, supported by low-level configuration detail and a decisions log recording the rationale for each significant choice. A build readiness review confirmed design maturity before build commenced.
Build, configuration and proving the method
The target platform was built and configured, including the certificate authority estate itself, hardware security module integration, and the operational management layer covering access control, monitoring, auditing, alerting and reporting. Key ceremony activity was conducted under formal witnessed procedure appropriate to the assurance level of root key material. The migration method was proven in a controlled environment before being applied to production, so that the production activity executed a rehearsed procedure rather than a theoretical one.
Testing and validation
Testing focused on the property that mattered most: that certificate structures on the target platform were an exact match for those on the source, and that trust chains continued to validate correctly for consuming systems. Testing was executed against documented test scripts under an agreed test plan defining scope, roles, defect categorisation and exit criteria, with defects tracked to resolution and results consolidated into a test report and service acceptance checklist.
Cutover, governance documentation and handover
Cutover was executed against a rehearsed plan with defined rollback positions. Governance documentation was produced to align with the client's assurance frameworks and regulatory compliance requirements, giving the organisation the evidence base to demonstrate that the new platform met its obligations. Handover included runbooks and playbooks for the operations team, operational readiness and service acceptance reviews, and a structured transition of outstanding risks, actions, issues and dependencies to the client.
The commercial outcome
Consolidating twenty root certificate authorities onto a single modern platform produced a substantial reduction in both business-as-usual operational cost and licensing expenditure. The saving came from two directions. Licensing consolidated onto one platform rather than being carried across an end-of-life estate, and the operational effort required to maintain twenty separately administered authorities reduced considerably once they were managed consistently within a single environment.
The automation capability delivered a further operational return that is harder to express as a line item but is frequently larger: certificate issuance and renewal that previously consumed skilled staff time moved to standards-based enrolment, releasing that capacity and removing a category of expiry-related incident that manual processes make almost inevitable at scale.
Challenges
The engagement presented several significant technical challenges that required deep PKI expertise and innovative problem-solving to overcome successfully.
A migration the vendor considered unfeasible
The migration constituted a technically complex process that the vendor deemed unfeasible. Developing a repeatable, reliable migration methodology in the absence of vendor guidance required Unsung's consultants to leverage deep understanding of certificate authority architecture and cryptographic operations.
Working without a supported path means working without documentation, without a support arrangement to fall back on and without precedent to reassure stakeholders. Unsung's response was to make the method itself the deliverable: to develop it from first principles based on how certificate authorities structure and protect key material, to document it precisely, and to prove it repeatedly under controlled conditions until it could be executed against production with confidence. Repeatability was essential given that the procedure had to be applied twenty times.
Achieving exact certificate structure parity
Ensuring precise certificate structure parity between the legacy and target platforms was critical to maintain seamless trust chain validation by downstream consuming systems. Unsung successfully addressed these challenges through rigorous project structure and robust delivery governance frameworks.
Certificate validation is unforgiving of small discrepancies. Differences in encoding, extension handling or naming that appear immaterial on inspection can cause a consuming system to reject a chain outright, and in a large estate those failures surface unevenly, in the systems with the strictest validation logic, often some time after the change that caused them. Parity therefore had to be verified rather than assumed, which is why validation of certificate structure formed the core of the testing phase.
Delivering change to a live, enterprise-scale trust hierarchy
Root certificate authorities cannot be taken offline for the convenience of a migration, and the organisation could not accept operational impact to business services. Managing this required rigorous project structure: clear sequencing, defined rollback positions at each stage, active RAID management with named owners, and delivery governance that gave stakeholders visibility of progress and risk throughout. The absence of operational impact was an outcome of that discipline rather than an incidental result.
Sustaining confidence through the programme
A migration the vendor had described as unfeasible required stakeholders to extend trust to an approach with no external validation behind it. Maintaining that confidence over the life of the engagement depended on visible governance: regular reporting against plan, an actively managed RAID log, and evidence produced at each stage rather than assurance offered in place of it. Confidence built this way is durable, because it rests on demonstrated progress rather than on the credibility of the claim.
Technologies Used
Related Services
Learn more about our PKI consultancy, certificate lifecycle management.

