Bring Dogtag CA under Jellyfish management
Jellyfish Dogtag Migration enables organisations to bring a Dogtag PKI Certificate Authority under Jellyfish management while keeping current services operational. usCA-Dogtag and the host-side tool Jellyfish Dogtag Migration connect to the Dogtag CA REST API and synchronise certificate authorities, issued certificates, and revocations into Jellyfish.
Dogtag is a capable open-source issuing CA with a profile-driven enrolment model and an LDAP-backed certificate repository. It continues to issue, but it is not a modern enterprise certificate lifecycle platform. Policy, reporting, multi-protocol enrolment, and validation sit outside the CA, and operators work through REST, agent portals, and Directory Server.
Jellyfish is Cogito Group's enterprise PKI platform. Jellyfish CA provides HSM-backed issuance, high availability, and native enrolment. The wider platform adds certificate lifecycle management, identity, reporting, analytical insights, Cog VA validation, automation, and much more.
Keep Dogtag running while you modernise
- Dogtag continues to issue
- Jellyfish CA is introduced as the enterprise CA
- Jellyfish keeps both environments aligned
- Your team migrates at a controlled pace
Jellyfish acts as the central management and synchronisation layer across the transition. Operators gain a unified view of certificate and revocation state while Dogtag continues to serve existing workloads over its REST API. Automation end points can move over days, weeks, or months rather than in a single change.
A migration model built for enterprise reality
Enterprise PKI is not isolated. Certificate Authorities are connected to identity platforms, applications, network services, and smartcards. Jellyfish Dogtag Migration brings an established Dogtag CA under enterprise management without replacing every integration at once.
Business Benefits
Lower migration risk
Dogtag is not switched off before Jellyfish is introduced. Existing issuing, profile-based enrolment, CRL publication, and Directory Server-backed certificate storage continue while Jellyfish synchronises the environment.
Introduce Jellyfish as the Issuing CA
Dogtag remains the issuing CA until you choose otherwise. Jellyfish CA takes on new enrolment as the enterprise path with native lifecycle management and a unified operational picture. Historical certificates stay visible in Jellyfish while issuance moves across at a pace the business can absorb.
Centralised PKI visibility
Jellyfish is a single pane of glass for PKI operations: certificate visibility, CA management, lifecycle data, and operational reporting. This includes certificates that Dogtag already issued.
Operational Outcomes
With Jellyfish Dogtag Migration, organisations can:
- Maintain continuity of Dogtag CA services
- Synchronise issued certificates and revocations into Jellyfish
- Map Dogtag CAs and profiles into Jellyfish CAs and templates
- Use Jellyfish certificate lifecycle management immediately, before issuance is cut over
- Retire Dogtag when the organisation is ready
- Use enterprise scalable Jellyfish Cog VA validation authority for CRL and OCSP
Simplified migration strategy
Follow these steps in order. Dogtag remains in service until you choose to cut over.
Deploy beside Dogtag
Run usCA-Dogtag in the Jellyfish mesh when the Dogtag CA REST endpoint is reachable, or install the jellyfish-dogtag-migration tool on a host next to Dogtag. The tool uploads to Jellyfish over the REST API. Jellyfish needs access to the Dogtag CA HTTPS REST interface, authenticated with an agent or administrator client certificate.
Scan and synchronise
The tool authenticates to Dogtag with mTLS, maps each Dogtag CA subject DN to a Jellyfish CA of the same name, then performs a bulk load of issued certificates and revocations, followed by incremental scheduled updates from a persisted watermark. Jellyfish template names must equal Dogtag profile IDs such as caUserCert.
Introduce Jellyfish CA signing
Stand up Jellyfish CA with HSM-backed keys as the enterprise issuing CA. New enrolment can move to Jellyfish while Dogtag remains the source of historical certificates.
Transition validation services
Update CRL and OCSP paths so validation services point to Cog VA. Cog VA reflects revocations from Dogtag, via synchronisation, and from Jellyfish CA.
Migrate integrations progressively
Move enrolment services and applications across as required. ACME, SCEP, EST, CMP, and Auto-enrol can land on Jellyfish without a single cut-over of every relying party.
An established Dogtag CA and an industry-standard PKI
Dogtag is a capable open-source issuing CA with years of operational use in Red Hat and community PKI estates. It is not, on its own, an enterprise certificate lifecycle platform.
Jellyfish is Cogito Group's industry-standard, enterprise-grade PKI platform. Jellyfish CA provides full certificate authority, certificate lifecycle, and key management, with HSM-backed operations, high availability, enrolment services, and Cog VA validation.