See below the new features in the CA Gateway version running on PKI Hub 1.4.0.

Support for renewing Sectigo-issued certificates (ATEAM-18908)

This release adds support for issuing certificates issued by a Sectigo CA.

See Enrollments endpoint for considerations on renewing Sectigo-issued certificates.

EJBCA support (ATEAM-18931)

This release adds support for Integrating an EJBCA CA.

Entrust CA support for post-quantum cryptography algorithms (PKI-42161)

This release adds support for Entrust CA post-quantum cryptography (PQC) algorithms. Specifically, when Integrating an Entrust CA, CA Gateway supports the following algorithms.

  • Module-Lattice-based Digital Signature Algorithm (ML-DSA)
  • Module-Lattice-based Key Encapsulation Mechanism (ML-KEM)

DigiCert certificate validity is set in days instead of years (ATEAM-19254)

The following DigiCert CA Profile Properties have been updated so that their values are now expressed in days rather than years:

  • Order Validity (days)
  • Certificate Validity (days)

When upgrading an installation that is already integrated with DigiCert, this new feature requires the ATEAM-19297 workaround described in the Known issues in CA Gateway for PKI Hub 1.4.0.