
step-ca
Summary
step-ca is an online Certificate Authority for managing X.509 and SSH certificates with automated issuance and renewal. It issues X.509 certificates for TLS, mutual TLS authentication, document signing, and authentication, as well as SSH certificates for users and hosts. Provisioners can authorize issuance through ACME challenges, OIDC tokens, cloud instance identity documents, and short-lived JWK tokens. Templates can customize names and identifiers, restrict domains or key sizes, and create longer certificate chains. For signing-key protection, step-ca integrates with cloud key-management services, HSMs, TPM 2.0, and YubiKey PIV. Its designed architecture uses an offline root CA and a configured intermediate CA to issue end-entity certificates. Installation options include macOS, Windows, Linux, Kubernetes, and Docker. The open-source software is free, with community support through Discord and dedicated support contracts available from Smallstep. Documented limitations include limited active revocation, no certificate history or metrics, and no ACME External Account Binding.
Who it is for
step-ca is positioned for DevOps teams managing certificates for VMs, containers, APIs, databases, Kubernetes workloads, and people. It may suit teams building a private CA with automated certificate workflows.
What is good
- Issues both X.509 and SSH certificates.
- Supports automated issuance and renewal.
- Integrates with HSMs and cloud key-management services.
- Offers installation options for macOS, Windows, Linux, Kubernetes, and Docker.
- Free and open source.
What to know first
- Active revocation is limited.
- No certificate history or metrics.
- No ACME External Account Binding.
- Open-source support is community-provided.
Everything Xiaomi review
step-ca: the full review
step-ca provides a free private certificate authority with automation, identity-based provisioners, and multiple key-protection integrations. Its documented gaps include limited active revocation and missing certificate history and metrics, so check those limitations against your requirements.
step-ca is a self-hosted private certificate authority for teams automating certificate use across infrastructure and people. It suits DevOps groups that can manage their own PKI and want a free, flexible issuing service. Its strongest case is broad X.509 and SSH coverage; its weaker fit is any environment that depends on active revocation or certificate-history reporting.
Overview
Its two-tier design keeps an offline root CA separate from the configured intermediate that issues end-entity certificates. That is a sensible foundation for routine automated issuance, but the free plan allows one configured intermediate, which constrains teams that need several independent issuing authorities.
step-ca issues X.509 certificates for TLS, mutual TLS, document signing and authentication, alongside SSH certificates for users and hosts. Single sign-on can provide short-lived SSH user certificates. It also automates issuance, renewal and passive revocation for clients, servers and Kubernetes workloads. The distinction between passive and active revocation matters: teams with demanding certificate-response workflows should not assume this replaces a fuller revocation system.
Key features
Provisioners authorize certificate issuance through ACME challenges, OIDC tokens, cloud instance identity documents from AWS, GCP and Azure, or short-lived JWK tokens. This range gives infrastructure teams several ways to tie issuance to existing identity and deployment processes rather than relying on a single credential model.
Templates can add custom SANs or OIDs, restrict domains or key sizes, and create longer certificate chains. Those controls are useful when certificate policy varies by workload, but step-ca still lacks certificate history and metrics, leaving teams without those built-in views for auditing issuance or monitoring activity.
For signing-key protection, integrations include Google Cloud KMS, AWS KMS, Azure Key Vault, PKCS#11 HSMs, TPM 2.0 and YubiKey PIV. The wider ecosystem covers ACME, SCEP, OIDC, cloud identity, Kubernetes cert-manager, Nebula and Envoy SDS. Configurable database backends include Badger, BoltDB, MySQL and PostgreSQL. The project also documents no dynamic SCEP and no ACME External Account Binding, and has limited legacy-protocol and device-attestation options; organizations relying on those specific capabilities should consider another fit.
Pricing
step-ca (open source): 0.00 USD per free. The plan includes one configured intermediate CA, an offline root CA and authority-wide issuance policies. It is a strong starting point for teams comfortable operating open-source infrastructure, with no paid tier or per-seat, quota, trial or renewal terms stated for this plan. It does not include Certificate Transparency integration or ACME EAB. Community support is provided through Discord; dedicated support contracts are available from Smallstep.
Platforms
step-ca supports API, Linux, macOS, Windows and self-hosted deployment. Official installation routes cover macOS Homebrew, Windows Winget or Scoop, Linux packages and binaries, Kubernetes and Docker. Its hybrid deployment model suits teams placing certificate services alongside their infrastructure, while the range of install paths supports both conventional hosts and containerized environments.
Who it's for
DevOps teams managing private certificates for VMs, containers, APIs, databases, Kubernetes pods and people are the clearest audience. It is particularly appropriate when automated issuance and renewal, cloud identity provisioners, and protected CA signing keys matter more than built-in history or metrics. Teams needing active revocation, extensive legacy protocol support, device attestation, dynamic SCEP or ACME EAB should assess those gaps before adopting it.
Pros and cons
- Pros: Free open-source plan combines X.509 and SSH issuance with automation across clients, servers and Kubernetes workloads.
- Pros: Multiple identity provisioners and KMS, HSM, TPM and YubiKey integrations support varied infrastructure and key-protection needs.
- Pros: Templates and configurable databases offer useful policy and deployment flexibility.
- Cons: One configured intermediate CA limits the free plan for organizations needing multiple issuing authorities.
- Cons: Limited active revocation and no certificate history or metrics weaken response and operational visibility.
- Cons: No Certificate Transparency integration or ACME EAB, alongside limited legacy-protocol and device-attestation options.
Alternatives
Public Key Infrastructure Software is the broader category to browse if step-ca's operating model or feature gaps do not match your needs.
SecureW2 Cloud NAC is a paid alternative with Android, iOS, web and desktop platform coverage; choose it if you want to compare a product sold through a quote process that asks about solution type, organization type and device count.
XiPKI is another free, open-source option with API, Linux, macOS and self-hosted platform support; consider it if you want to evaluate a different open-source PKI project.
EZCA suits buyers seeking a paid service with a free trial and a stated Basic plan at 200.00 USD per month, described as FIPS 140-3 Level 2 HSM-backed CAs.
Entrust Certificate Manager is a paid alternative for readers considering another certificate-management provider.
KeyTalk CKMS is worth comparing for readers considering paid key-management software with a free trial and a stated S/MIME on-premise plan at 5.00 EUR per month per user.
HashiCorp Nomad offers a freemium option; consider it if you are comparing certificate-related needs alongside a product with self-managed and customizable enterprise plans.
Keyfactor Platform is a paid alternative with a free trial; its certificate lifecycle automation plan states no per-certificate fees and a deployment tested for more than 500 million certificates.
SSL.com Certificate Lifecycle Management is another freemium option to compare for API and web use.
Verdict
Choose step-ca if your team wants a free, self-hosted private CA that automates X.509 and SSH issuance and can integrate with existing identity and key-protection systems. Its focused two-tier model and broad integration range are compelling for infrastructure automation. Look elsewhere if active revocation, certificate history, metrics, multiple configured intermediates or the missing protocol features are central requirements.
step-ca plans and pricing
All plansCompared on public key infrastructure software
- Free plan
- Yessmallstep.com
- Deployment model
- hybridsmallstep.com
- ACME support
- Yessmallstep.com
- SCEP support
- Yessmallstep.com
- HSM integration
- Yessmallstep.com
- Certificate profiles
- Yessmallstep.com
Facts
- Purpose
- step-ca is an online Certificate Authority for secure, automated X.509 and SSH certificate management.smallstep.com · 30 Sept 2026
- X.509 certificates
- It issues X.509 certificates for TLS, mutual TLS authentication, document signing and X.509 authentication.smallstep.com · 30 Sept 2026
- SSH certificates
- It issues SSH certificates to users and hosts and can provide short-lived SSH user certificates through single sign-on.smallstep.com · 30 Sept 2026
- Provisioners
- Provisioners can authorize issuance through ACME challenge responses, OIDC tokens, AWS/GCP/Azure instance identity documents and short-lived JWK tokens.smallstep.com · 30 Sept 2026
- Certificate automation
- step-ca supports automated certificate issuance, renewal and passive revocation for clients, servers and Kubernetes workloads.smallstep.com · 30 Sept 2026
- Templates
- X.509 and SSH templates can add custom SANs or OIDs, restrict domains or key sizes and create longer certificate chains.smallstep.com · 30 Sept 2026
- Key protection
- It integrates with Google Cloud KMS, AWS KMS, Azure Key Vault, PKCS#11 HSMs, TPM 2.0 and YubiKey PIV for CA signing-key protection.smallstep.com · 30 Sept 2026
- Integrations
- The integration ecosystem includes ACME, SCEP, OIDC, AWS/GCP/Azure cloud identity, Kubernetes cert-manager, Nebula and Envoy SDS.smallstep.com · 30 Sept 2026
- Databases
- Its configurable database backends include Badger, BoltDB, MySQL and PostgreSQL.smallstep.com · 30 Sept 2026
- Installation
- Official installation options cover macOS Homebrew, Windows Winget or Scoop, Linux packages and binaries, Kubernetes and Docker.smallstep.com · 30 Sept 2026
- Architecture
- step-ca is designed around a two-tier PKI with one offline root CA and one configured intermediate CA issuing end-entity certificates.smallstep.com · 30 Sept 2026
- Limitations
- The project documents limited active revocation, limited legacy-protocol and device-attestation options, no certificate history or metrics, no dynamic SCEP and no ACME External Account Binding.smallstep.com · 30 Sept 2026
- Support
- Open-source step-ca support is provided by the user community through Discord, with dedicated support contracts available from Smallstep.support.smallstep.com · 30 Sept 2026
- Target users
- The project is positioned for DevOps teams that need a private CA for certificates used by VMs, containers, APIs, databases, Kubernetes pods and people.github.com · 30 Sept 2026
Best step-ca alternatives
See all 12Where it ranks on Everything Xiaomi
Is step-ca yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- smallstep.com/docs/step-ca/· checked 30 Sept 2026
- smallstep.com/docs/step-ca/cryptographic-protection/· checked 30 Sept 2026
- smallstep.com/docs/step-ca/integrations/· checked 30 Sept 2026
- smallstep.com/docs/step-ca/configuration/· checked 30 Sept 2026
- smallstep.com/docs/step-ca/installation/· checked 30 Sept 2026
- support.smallstep.com/en/articles/8471361· checked 30 Sept 2026
- github.com/smallstep/certificates· checked 30 Sept 2026

