Bring Entrust EASM under Jellyfish management
Jellyfish EASM Migration enables organisations to bring an Entrust Authority Security Manager (EASM) PKI under Jellyfish management while keeping current services operational. usCA-EASM and or the client-side tool Jellyfish EASM Migration connect through Entrust CA Gateway (CAGW) and synchronise certificate authorities, issued certificates, and revocations into Jellyfish.
Entrust EASM is a legacy Windows CA. It continues to issue, but it is not a modern certificate lifecycle platform. Policy, enrolment, validation, and reporting sit outside Security Manager, and the CA depends on a tightly coupled Windows stack.
Jellyfish is Cogito Group's enterprise PKI platform. Jellyfish CA provides HSM-backed issuance, high availability, and native enrolment. The wider platform adds certificate lifecycle management, identity, reporting, analytical insights, Cog VA validation, automation, and much more.
Keep EASM running while you modernise
- EASM continues to issue
- Jellyfish CA is introduced as the enterprise CA
- Jellyfish keeps both environments aligned
- Your team migrates at a controlled pace
Jellyfish acts as the central management and synchronisation layer across the transition. Operators gain a unified view of certificate and revocation state while EASM continues to serve existing workloads through CAGW. Automation end points can move over days, weeks, or months rather than in a single change.
A migration model built for enterprise reality
Enterprise PKI is not isolated. Certificate Authorities are connected to identity platforms, applications, network services, and smartcards. Jellyfish EASM Migration brings an established Entrust CA under enterprise management without replacing every integration at once.
Business Benefits
Lower migration risk
EASM is not switched off before Jellyfish is introduced. Existing issuing, CRL publication, and CAGW-facing integrations continue while Jellyfish synchronises the environment.
Keep your HSM-backed CA with you in Jellyfish CA
EASM keys live in the Entrust connected HSM. Jellyfish connects to this HSM with native Jellyfish crypto integration, a tight approach for a long-lived production PKI. Historical certificates stay visible in Jellyfish while new issuance moves to Jellyfish CA at a pace the business can absorb.
Centralised PKI visibility
Jellyfish is a single pane of glass for PKI operations: certificate visibility, CA management, lifecycle data, and operational reporting. This includes certificates that EASM already issued.
Operational Outcomes
With Jellyfish EASM Migration, organisations can:
- Maintain continuity of EASM and CAGW services
- Synchronise issued certificates and revocations into Jellyfish
- Map Entrust CAs and certificate types into Jellyfish CAs and templates
- Use Jellyfish certificate lifecycle management immediately, before issuance is cut over
- Retire EASM when the organisation is ready
- Use enterprise scalable Jellyfish Cog VA validation authority for CRL and OCSP
Simplified migration strategy
Follow these steps in order. EASM remains in service until you choose to cut over.
Deploy beside CAGW
Run usCA-EASM in the Jellyfish mesh when CAGW is reachable, or install the jellyfish-easm-migration tool on a host next to CAGW. The tool uploads to Jellyfish over the REST API. Jellyfish needs access to the Entrust EASM CAGW server.
Scan and synchronise
The tool authenticates to CAGW with an mTLS client certificate, maps CAGW CA identifiers to Jellyfish CAs, then performs a bulk load of issued certificates and revocations, followed by incremental scheduled updates from a persisted watermark.
Introduce Jellyfish CA signing
Stand up Jellyfish CA with HSM-backed keys as the enterprise issuing CA. New enrolment can move to Jellyfish while EASM remains the source of historical certificates.
Transition validation services
Update CRL and OCSP paths so validation services point to Cog VA. Cog VA reflects revocations from EASM, via synchronisation, and from Jellyfish CA.
Migrate integrations progressively
Move enrolment services and applications across as required. ACME, SCEP, EST, CMP, and Auto-enrol can land on Jellyfish without a single cut-over of every relying party.
An established Entrust CA and an industry-standard PKI
Entrust EASM is a capable issuing CA with years of operational history. It is not, on its own, an enterprise certificate lifecycle platform.
Jellyfish is Cogito Group's industry-standard, enterprise-grade PKI platform. Jellyfish CA provides full certificate authority, certificate lifecycle, and key management, with HSM-backed operations, high availability, enrolment services, and Cog VA validation.