ca.json for the HSM container.
Create the CA password file
Create one protected password file for the software root and JWK provisioner:Shell
Initialize the software CA
Replace<CA-NAME> with a descriptive CA name and <CA-DNS-NAME> with the DNS name clients use for step-ca.
Shell
ca.json.
At this stage, both CA keys are software keys. The next section replaces the online intermediate.
Issue the CryptoHub-backed intermediate certificate
Load the CryptoHub variables:Shell
Shell
intermediate_ca_cryptohub.crt.
Confirm the key binding
Compare the public key in CryptoHub with the public key in the new certificate:Shell
cmp produces no output. OpenSSL prints the intermediate certificate path followed by OK.
Only after both checks pass, install the new certificate and remove the superseded software intermediate key:
Shell
Configure the PKCS #11 KMS
Rewrite the host paths for the container and add the KMS configuration:Shell
Validate the CA configuration
Verify the non-secret path and KMS fields:Shell
kms.type set to pkcs11, the CryptoHub key URI, and /home/step/.step/ paths that exist inside the container.
