πŸ”‘ ProvisionersΒΆ

See also

Please check out the official documentation to learn more about configuring step-ca provisioners.

Initial provisionersΒΆ

When the CA is initialised the first time, two provisioners will be created:

Provisioner

Type

Usage

${CA_PROVISIONER}

JWK

Manually issue certificates via step CLI.

acme

ACME

Automatically issue certificates via ACME protocol.

Note

The ${CA_PROVISIONER} can be specified during the initial setup (see 🎚 Configuration).

Additional provisionersΒΆ

Additional provisioners can be created via the step ca provisioner add CLI command in the ca container.

Example CLI command inside the ca container
# Create random password.
openssl rand -base64 32 >passwords/{name}

# Create new provisioner for client certificates.
step ca provisioner add {name} \
    --type=JWK \
    --create --password-file=passwords/{name} \
    --x509-max-dur={duration} \
    --x509-default-dur={duration} \
    --x509-template={template}
Example CLI command on the Docker host via docker exec
# Create random password.
docker exec ca sh -c 'openssl rand -base64 32 >passwords/{name}'

# Create new provisioner for client certificates.
docker exec ca step ca provisioner add {name} \
    --type=JWK \
    --create --password-file=passwords/{name} \
    --x509-max-dur={duration} \
    --x509-default-dur={duration} \
    --x509-template={template}

Note

The relative paths (e.g. passwords/{name}) work, because the container’s working directory is /ca, which is also the STEPPATH.

Tip

  • The provisioner name should be alphanumeric.

  • The duration should use the minutes (e.g. 15m), or hours (e.g. 24h) format.

  • The template can be retrieved from Templates.

TemplatesΒΆ

The Docker image provides 2 generic templates. Both pass through the requested subject & SANs, and set the digitalSignature key usage. They only differ in the extended key usage:

Template

Extended key usage

Usage

/templates/serverAuth.tpl

serverAuth, clientAuth

Server certificates (also for server-to-server mTLS)

/templates/clientAuth.tpl

clientAuth

Client certificates (e.g. for users)

Hint

To use a template for the acme provisioner, update it inside the ca container:

step ca provisioner update acme --x509-template=/templates/serverAuth.tpl