Files
Notebook/content/netlab/sécurité/stepca.en.md
Damien f49c0f45dd Add bilingual French/English support with Hugo multilingual config
Configure Hugo multilingual mode (fr default, en secondary) with
Hextra's language-switch menu entry, and translate all existing
content pages to English using Hugo's per-file language suffix
convention (.en.md alongside .fr.md).
2026-07-18 09:48:18 +02:00

9.0 KiB

title, date, weight, cascade
title date weight cascade
Self-Hosted Certificate Manager 2024-08-01T20:00:00+02:00 2
type
docs

🔗 Sources

🤖 About Step-CA

Step-CA is a clever toolset developed by Smallstep, a company specializing in secure identity management and certificate automation. 🚀
Its mission? To simplify setting up and managing your own certificate authorities (CAs) with ease and security!

Key Features

  1. Certificate Authority Management 🔑
    Easily configure and manage your own CAs. Create root and intermediate CAs, issue certificates, and handle revocations like a pro.

  2. Secure Key Management 🛡️
    Follows best practices for securely storing and managing keys, ensuring your cryptographic keys stay protected from unauthorized access.

  3. Automation and Scalability ⚙️
    Ideal for small to large-scale deployments. Take advantage of APIs and integrations that automate certificate issuance, renewal, and revocation for a smooth lifecycle.

  4. Enhanced Security 🔒
    Through the use of modern cryptographic algorithms and protocols, Step-CA supports industry-standard X.509 certificates, providing robust encryption and digital signatures.

  5. Infrastructure Integration 🌐
    Integrates seamlessly with your existing tools and systems. Supports various authentication methods such as username/password, MFA, and external identity providers.

  6. Auditability and Compliance 📜
    With comprehensive logging and auditing capabilities, you can track certificate activity and meet compliance requirements with ease.

  7. Developer-Friendly APIs 👩‍💻👨‍💻
    APIs and SDKs designed for developers make it easy to integrate certificate management into your applications and custom workflows.

In short: Step-CA by Smallstep is designed to make certificate authority management both fun and hassle-free. Thanks to its secure, scalable, and user-friendly features, you can easily manage your certificates' lifecycle while protecting your infrastructure!

🚀 Installation

🔧 Binary Installation

1. Step CLI

wget https://dl.step.sm/gh-release/cli/docs-cli-install/v0.24.3/step-cli_0.24.3_amd64.deb
sudo dpkg -i step-cli_0.24.3_amd64.deb

2. Step-CA

wget https://dl.step.sm/gh-release/certificates/docs-ca-install/v0.24.1/step-ca_0.24.1_amd64.deb
sudo dpkg -i step-ca_0.24.1_amd64.deb

3. Creating a Dedicated User

adduser adminCA

Configuration

$ step ca init --password-file=password.txt
✔ Deployment type: Standalone
What would you like to name your new PKI?
✔ (e.g. Smallstep) : Lab
✔ (e.g. ca.example.com[,10.1.2.3,etc.]) : ca.lab.loc, localhost, 192.168.1.101
What IP and port will your new CA bind to? (:443 will bind to 0.0.0.0:443). 1.101
✔ (e.g. :443 or 127.0.0.1:443) : :443
What would you like to name the CA's first provisioner?
✔ (e.g. you@smallstep.com) : contact@lab.loc
Choose a password for your CA keys and the first provisioner.
✔ [leave empty and we will generate one] : 

Generating root certificate... done! 🎉  
Generating intermediate certificate... done! 🎊

✔ Root certificate: /home/adminCA/.step/certs/root_ca.crt  
✔ Root private key: /home/adminCA/.step/secrets/root_ca_key  
✔ Root fingerprint: 7d754397c6897aa87d21e33c64daad7be087dc6fe18bf04627848ae1c8e26a4f  
✔ Intermediate certificate: /home/adminCA/.step/certs/intermediate_ca.crt  
✔ Intermediate private key: /home/adminCA/.step/secrets/intermediate_ca_key  
✔ Database folder: /home/adminCA/.step/db  
✔ Default configuration: /home/adminCA/.step/config/defaults.json  
✔ Certificate Authority configuration: /home/adminCA/.step/config/ca.json  

Your PKI is ready to go. To generate certificates for individual services, see `step help ca`.

💌 **FEEDBACK**  
The step utility is not instrumented for usage statistics. It does not contact a central server. Your feedback is, however, extremely valuable! Please consider writing to feedback@smallstep.com, joining GitHub Discussions, or joining us on Discord at [https://u.step.sm/discord](https://u.step.sm/discord).

Start Step-CA:

step-ca .step/config/ca.json

Enable ACME

$ step ca provisioner add acme --type ACME
✔ CA Configuration: /home/adminCA/.step/config/ca.json

Success! Your `step-ca` configuration has been updated. To pick up the new configuration, send a SIGHUP (kill -1 <pid>) or restart the step-ca process. 🎉

Running Step-CA as a systemd Service

Create a file:

vim /etc/systemd/system/step-ca.service

Paste in the following:

[Unit]
Description=step-ca
After=syslog.target network.target

[Service]
User=adminCA
Group=adminCA
ExecStart=/bin/sh -c '/bin/step-ca /home/adminCA/.step/config/ca.json --password-file=/home/step/.step/pwd >> /var/log/step-ca/output.log 2>&1'
Type=simple
Restart=on-failure
RestartSec=10

[Install]
WantedBy=multi-user.target

Create the log directory:

mkdir -p /var/log/step-ca
chown -R adminCA:adminCA /var/log/step-ca

Reload the systemd daemon:

systemctl daemon-reload
systemctl start step-ca.service

🐳 Docker Installation

docker run -it -v step:/home/step \
    -p 9000:9000 \
    -e "DOCKER_STEPCA_INIT_NAME=Lab" \
    -e "DOCKER_STEPCA_INIT_DNS_NAMES=caserver.lab.loc,localhost,192.168.1.101" \
    -e "DOCKER_STEPCA_INIT_REMOTE_MANAGEMENT=true" \
    -e "DOCKER_STEPCA_INIT_ACME=true" \
    smallstep/step-ca

🔑 Accessing the CA from Another Client

[!NOTE] Adjust the port based on your installation:

  • Binary: port 443
  • Docker: port 9000

Install the Step CLI:

wget https://dl.step.sm/gh-release/cli/docs-cli-install/v0.24.3/step-cli_0.24.3_amd64.deb
sudo dpkg -i step-cli_0.24.3_amd64.deb

Initialize your CA:

step ca bootstrap --ca-url https://caserver.lab.loc:$PORT/ --fingerprint 685059c30eb305db5272a7a199a2b5823624d55c732121ac65c06b0915d3c887

[!TIP] To get the fingerprint, simply run:

step certificate fingerprint $(step path)/certs/root_ca.crt

For Docker, check the container logs.

Example output:

admin@User:~$ step ca bootstrap --ca-url https://caserver.lab.loc:$PORT --fingerprint 685059c30eb305db5272a7a199a2b5823624d55c732121ac65c06b0915d3c887
The root certificate has been saved in /home/admin/.step/certs/root_ca.crt.
The authority configuration has been saved in /home/admin/.step/config/defaults.json.

Install the certificate:

step certificate install $(step path)/certs/root_ca.crt

[!TIP] Installation on Debian:

  • Copy the individual CRT files (PEM format) into /usr/local/share/ca-certificates/
  • The files must be owned by root:root with 644 permissions
  • Make sure the ca-certificates package is installed (if not, install it)
  • Then, run as root:
# /usr/sbin/update-ca-certificates

All certificates will be consolidated into: /etc/ssl/certs/ca-certificates.crt


📝 Obtaining a Certificate

admin@User:~$ step ca certificate nas.lab.loc srv.crt srv.key
✔ Provisioner: contact@lab.loc (JWK) [kid: chyGkrZqp-BGSHUZ8v3jsPipegt2JLcC7y6RPq4OOkU]
Please enter the password to decrypt the provisioner key:
✔ CA: https://caserver.lab.loc:443
✔ Certificate: srv.crt
✔ Private Key: srv.key

[!TIP] To perform a health check:

curl https://caserver.lab.loc:443/health -k

You may need to customize the ca.json file to increase the minimum certificate validity duration. Here's the directory structure:

.
|-- certs
|   |-- intermediate_ca.crt
|   `-- root_ca.crt
|-- config
|   |-- ca.json
|   `-- defaults.json
|-- db
|   |-- 000000.vlog
|   |-- 000020.sst
|   |-- KEYREGISTRY
|   |-- LOCK
|   `-- MANIFEST
|-- secrets
|   |-- intermediate_ca_key
|   |-- password
|   `-- root_ca_key
`-- templates

Example ca.json file:

{
    "root": "/home/step/certs/root_ca.crt",
    "federatedRoots": null,
    "crt": "/home/step/certs/intermediate_ca.crt",
    "key": "/home/step/secrets/intermediate_ca_key",
    "address": ":9000",
    "insecureAddress": "",
    "dnsNames": [
        "caserver.lab.loc",
        "caserver",
        "localhost",
        "192.168.1.200"
    ],
    "logger": {
        "format": "text"
    },
    "db": {
        "type": "badgerv2",
        "dataSource": "/home/step/db",
        "badgerFileLoadingMode": ""
    },
    "authority": {
        "enableAdmin": true,
        "claims": {
            "maxTLSCertDuration": "4380h"
        }
    },
    "tls": {
        "cipherSuites": [
            "TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256",
            "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256"
        ],
        "minVersion": 1.2,
        "maxVersion": 1.3,
        "renegotiation": false
    }
}