step-ca is an online Certificate Authority for automating the management of X.509 and SSH certificates. It issues X.509 certificates for TLS, mutual TLS, document signing, and authentication, as well as SSH certificates for users and hosts. Provisioners can authorize issuance using ACME challenge responses, OIDC tokens, cloud instance identity documents, or short-lived JWK tokens. The software supports automated issuance and renewal, along with passive revocation, for clients, servers, and Kubernetes workloads. Templates can customize names and identifiers, constrain domains or key sizes, and form longer certificate chains. For protecting CA signing keys, step-ca integrates with cloud key-management services, PKCS#11 HSMs, TPM 2.0, and YubiKey PIV. Its architecture uses an offline root CA and a configured intermediate CA to issue end-entity certificates. Installation choices include macOS, Windows, Linux, Kubernetes, and Docker. The open-source software is free, with community support through Discord and dedicated support contracts available from Smallstep. Documented gaps include limited active revocation, no certificate history or metrics, and no ACME External Account Binding.
Who it is for
step-ca is positioned for DevOps teams that need a private CA for certificates used by VMs, containers, APIs, databases, Kubernetes pods, and people. It may suit teams automating both X.509 and SSH certificate issuance.
What is good
- Automates certificate issuance and renewal.
- Supports X.509 and SSH certificates.
- Integrates with cloud key-management services and HSMs.
- Installation options include Linux, Kubernetes, and Docker.
What to know first
- Active revocation is limited.
- No certificate history or metrics.
- No ACME External Account Binding.
Freedom251 review
step-ca: the full review
step-ca offers a free, open-source route to automated private certificate issuance, with integrations for multiple identity and key-protection systems. Teams should assess its documented revocation and monitoring gaps before adopting it.
step-ca is a private certificate authority for automating X.509 and SSH certificates. It is best suited to DevOps teams managing certificates for infrastructure and people. Its free, integration-rich issuing service is compelling, but limited active revocation and a single-intermediate plan constrain where it fits.
Overview
step-ca uses a two-tier PKI: an offline root anchors trust, while a configured intermediate issues end-entity certificates. Keeping the root offline supports a clear separation between trust and routine issuance; the open-source plan’s single intermediate, however, will not suit teams that need multiple issuing authorities.
It covers X.509 certificates for TLS, mutual TLS, document signing and authentication, plus SSH certificates for users and hosts. Single sign-on can provide short-lived SSH user certificates. Automation handles issuance, renewal and passive revocation for clients, servers and Kubernetes workloads. That passive-revocation scope is not a substitute for robust active revocation, and the absence of certificate history and metrics leaves less operational visibility than some teams may require.
Key features
Provisioners authorize issuance through ACME challenges, OIDC tokens, AWS, GCP or Azure instance identity documents, and short-lived JWK tokens. This gives teams options for tying certificate requests to existing identity flows rather than relying on a single enrollment method.
X.509 and SSH templates can add custom SANs or OIDs, restrict domains or key sizes, and create longer certificate chains. These controls are useful for organizations with specific issuance policies, while authority-wide policies provide another layer of control in the open-source plan.
For signing-key protection, step-ca integrates with Google Cloud KMS, AWS KMS, Azure Key Vault, PKCS#11 HSMs, TPM 2.0 and YubiKey PIV. Its wider ecosystem includes SCEP, Kubernetes cert-manager, Nebula and Envoy SDS, alongside ACME and OIDC. Configurable database choices—Badger, BoltDB, MySQL and PostgreSQL—let operators select a backend suited to their deployment.
The project documents limits that matter in more demanding environments: legacy-protocol and device-attestation options are limited, SCEP is not dynamic, and ACME External Account Binding is unavailable. Teams that depend on those specific capabilities should compare alternatives before adopting it.
Pricing
step-ca (open source)
0.00 USD per free. The plan includes a single configured intermediate CA, an offline root CA and authority-wide issuance policies. It has no Certificate Transparency integration and no ACME EAB, in addition to the project’s limitations around active revocation, certificate history and metrics. The free plan is a strong fit for teams able to operate their own CA and accept those constraints. Open-source support comes from the user community through Discord; dedicated support contracts are available from Smallstep.
Platforms
step-ca supports API use and Linux, macOS and Windows, with self-hosted and hybrid deployment. Official installation options include Homebrew on macOS, Winget or Scoop on Windows, Linux packages and binaries, Kubernetes and Docker. Those deployment paths give infrastructure teams flexibility, but also leave them responsible for running the CA.
Who it's for
DevOps teams issuing private certificates for VMs, containers, APIs, databases, Kubernetes pods and people are the clearest match. Its range of provisioners, key-protection integrations and database backends can accommodate varied infrastructure. It is a weaker choice for organizations that require richer active-revocation workflows, certificate history or metrics, or need multiple configured intermediates on the free plan.
Pros and cons
- Pros: Free open-source issuance covers both X.509 and SSH, including short-lived SSH user certificates through single sign-on.
- Pros: Multiple identity, cloud KMS, HSM and platform integrations give operators options for enrollment and signing-key protection.
- Pros: Templates and authority-wide policies provide controls for certificate contents and issuance.
- Cons: The open-source plan permits only one configured intermediate CA.
- Cons: Limited active revocation and no certificate history or metrics make it less suitable for teams needing stronger response and monitoring capabilities.
- Cons: No ACME EAB, no dynamic SCEP and limited legacy-protocol and device-attestation options may rule it out for specific environments.
Alternatives
For a broader comparison, see Public Key Infrastructure Software.
- XiPKI is another free, open-source option for teams comparing private CA software.
- SecureW2 Cloud NAC is a paid alternative with a quote-based price and support across mobile, desktop, web and API platforms.
- KeyTalk CKMS is a paid option with a free trial and an S/MIME on-premise plan at 5.00 EUR per month, billed per user per month, for up to 250 participants.
- Entrust Certificate Manager is a paid alternative with pricing discussed through Entrust.
- HashiCorp Nomad offers a free plan as well as paid plans with custom pricing.
- DigiCert Private CA uses subscription licensing, with soft limits and overages.
- Keyfactor Platform is a paid alternative with a free trial and no per-certificate fees.
- SSL.com Certificate Lifecycle Management is a freemium alternative without a free plan.
Verdict
Choose step-ca if your DevOps team wants a free, self-hosted authority for automated X.509 and SSH issuance and can work within one configured intermediate. Its breadth of identity and key-protection integrations is the main draw. Look elsewhere if active revocation, certificate history or metrics are essential to your certificate operations.
step-ca plans and pricing
All plansCompared on public key infrastructure software
- Free plan
- Yes
- Deployment model
- hybrid
- ACME support
- Yes
- SCEP support
- Yes
- HSM integration
- Yes
- Certificate profiles
- Yes


