Supported versions
Use the following validated versions:
Pin the versioned HSM image instead of the moving
smallstep/step-ca:hsm tag. A moving tag can change the CA, operating-system libraries, or plugin behavior without a configuration change.
CryptoHub access
Obtain access to CryptoHub under dual control. The administrator workflow must allow you to:- Deploy and manage the Smallstep step-ca service.
- Create a Linux OpenSSL 3.x client endpoint.
- Download the endpoint ZIP once. The ZIP contains the application credential and TLS material.
Linux host
Prepare a Linux x86-64 host with:- Root or
sudoaccess, because the endpoint files require protected system locations. - Docker Engine, because the HSM image supplies the PKCS #11-capable step-ca runtime.
curl,jq, OpenSSL, and OpenSC, because the procedure verifies downloads, parses the endpoint config, and checks PKCS #11 connectivity.- At least 2 GB of available memory and enough storage for the CA database, container image, and audit logs.
Network and TLS
Allow these connections:
Add a TLS-inspection exemption for the CryptoHub connection. TLS interception changes the server certificate chain and prevents the endpoint from validating the appliance.
Verify reachability from the step-ca host:
Shell
<cryptohub-host> with the CryptoHub FQDN. An HTTP response proves that the network path is open; certificate validation may remain incomplete until you install the endpoint CA files.
Protected storage
Prepare protected storage for:- The endpoint ZIP and extracted
cryptohub.json. - The endpoint TLS client key and CA files.
- The encrypted software root key.
- The CA and provisioner password file.

