Bring Entrust EASM under Jellyfish management 

Jellyfish EASM Migration enables organisations to bring an Entrust Authority Security Manager (EASM) PKI under Jellyfish management while keeping current services operational. usCA-EASM and or the client-side tool Jellyfish EASM Migration connect through Entrust CA Gateway (CAGW) and synchronise certificate authorities, issued certificates, and revocations into Jellyfish. 

Entrust EASM is a legacy Windows CA. It continues to issue, but it is not a modern certificate lifecycle platform. Policy, enrolment, validation, and reporting sit outside Security Manager, and the CA depends on a tightly coupled Windows stack. 

Jellyfish is Cogito Group's enterprise PKI platform. Jellyfish CA provides HSM-backed issuance, high availability, and native enrolment. The wider platform adds certificate lifecycle management, identity, reporting, analytical insights, Cog VA validation, automation, and much more. 

Keep EASM running while you modernise 

  • EASM continues to issue 
  • Jellyfish CA is introduced as the enterprise CA 
  • Jellyfish keeps both environments aligned 
  • Your team migrates at a controlled pace 

Jellyfish acts as the central management and synchronisation layer across the transition. Operators gain a unified view of certificate and revocation state while EASM continues to serve existing workloads through CAGW. Automation end points can move over days, weeks, or months rather than in a single change. 

A migration model built for enterprise reality 

Enterprise PKI is not isolated. Certificate Authorities are connected to identity platforms, applications, network services, and smartcards. Jellyfish EASM Migration brings an established Entrust CA under enterprise management without replacing every integration at once. 

Business Benefits 

Lower migration risk 

EASM is not switched off before Jellyfish is introduced. Existing issuing, CRL publication, and CAGW-facing integrations continue while Jellyfish synchronises the environment. 

Keep your HSM-backed CA with you in Jellyfish CA 

EASM keys live in the Entrust connected HSM. Jellyfish connects to this HSM with native Jellyfish crypto integration, a tight approach for a long-lived production PKI. Historical certificates stay visible in Jellyfish while new issuance moves to Jellyfish CA at a pace the business can absorb. 

Centralised PKI visibility 

Jellyfish is a single pane of glass for PKI operations: certificate visibility, CA management, lifecycle data, and operational reporting. This includes certificates that EASM already issued. 

Operational Outcomes 

With Jellyfish EASM Migration, organisations can: 

  • Maintain continuity of EASM and CAGW services 
  • Synchronise issued certificates and revocations into Jellyfish 
  • Map Entrust CAs and certificate types into Jellyfish CAs and templates 
  • Use Jellyfish certificate lifecycle management immediately, before issuance is cut over 
  • Retire EASM when the organisation is ready 
  • Use enterprise scalable Jellyfish Cog VA validation authority for CRL and OCSP 

Simplified migration strategy 

Follow these steps in order. EASM remains in service until you choose to cut over. 

Deploy beside CAGW 

Run usCA-EASM in the Jellyfish mesh when CAGW is reachable, or install the jellyfish-easm-migration tool on a host next to CAGW. The tool uploads to Jellyfish over the REST API. Jellyfish needs access to the Entrust EASM CAGW server. 

Scan and synchronise 

The tool authenticates to CAGW with an mTLS client certificate, maps CAGW CA identifiers to Jellyfish CAs, then performs a bulk load of issued certificates and revocations, followed by incremental scheduled updates from a persisted watermark. 

Introduce Jellyfish CA signing 

Stand up Jellyfish CA with HSM-backed keys as the enterprise issuing CA. New enrolment can move to Jellyfish while EASM remains the source of historical certificates. 

Transition validation services 

Update CRL and OCSP paths so validation services point to Cog VA. Cog VA reflects revocations from EASM, via synchronisation, and from Jellyfish CA. 

Migrate integrations progressively 

Move enrolment services and applications across as required. ACME, SCEP, EST, CMP, and Auto-enrol can land on Jellyfish without a single cut-over of every relying party. 

An established Entrust CA and an industry-standard PKI 

Entrust EASM is a capable issuing CA with years of operational history. It is not, on its own, an enterprise certificate lifecycle platform. 

Jellyfish is Cogito Group's industry-standard, enterprise-grade PKI platform. Jellyfish CA provides full certificate authority, certificate lifecycle, and key management, with HSM-backed operations, high availability, enrolment services, and Cog VA validation.