π ProvisionersΒΆ
See also
Please check out the official documentation to learn more about configuring step-ca provisioners.
Initial provisionersΒΆ
When the CA is initialised the first time, two provisioners will be created:
Provisioner |
Type |
Usage |
|
JWK |
Manually issue certificates via |
|
ACME |
Automatically issue certificates via ACME protocol. |
Note
The ${CA_PROVISIONER} can be specified during the initial setup (see π Configuration).
Additional provisionersΒΆ
Additional provisioners can be created via the step ca provisioner add CLI command in the ca container.
Example CLI command inside the ca container
# Create random password.
openssl rand -base64 32 >passwords/{name}
# Create new provisioner for client certificates.
step ca provisioner add {name} \
--type=JWK \
--create --password-file=passwords/{name} \
--x509-max-dur={duration} \
--x509-default-dur={duration} \
--x509-template={template}
Example CLI command on the Docker host via docker exec
# Create random password.
docker exec ca sh -c 'openssl rand -base64 32 >passwords/{name}'
# Create new provisioner for client certificates.
docker exec ca step ca provisioner add {name} \
--type=JWK \
--create --password-file=passwords/{name} \
--x509-max-dur={duration} \
--x509-default-dur={duration} \
--x509-template={template}
Note
The relative paths (e.g. passwords/{name}) work, because the containerβs working directory is /ca, which is also the STEPPATH.
Tip
The provisioner name should be alphanumeric.
The duration should use the minutes (e.g.
15m), or hours (e.g.24h) format.The template can be retrieved from Templates.
TemplatesΒΆ
The Docker image provides 2 generic templates.
Both pass through the requested subject & SANs, and set the digitalSignature key usage.
They only differ in the extended key usage:
Template |
Extended key usage |
Usage |
|---|---|---|
|
|
Server certificates (also for server-to-server mTLS) |
|
|
Client certificates (e.g. for users) |
Hint
To use a template for the acme provisioner, update it inside the ca container:
step ca provisioner update acme --x509-template=/templates/serverAuth.tpl