Skip to main content
Create a software root, replace the initial software intermediate with the CryptoHub-backed key, and update ca.json for the HSM container.

Create the CA password file

Create one protected password file for the software root and JWK provisioner:
Shell
The file contains one password line and is readable only by its owner.
Protect this password with the same controls as the software root key. Losing both the password and a recoverable backup of the root prevents future intermediate renewal.

Initialize the software CA

Replace <CA-NAME> with a descriptive CA name and <CA-DNS-NAME> with the DNS name clients use for step-ca.
Shell
The command reports paths for the root certificate, root private key, intermediate certificate, database, and ca.json. At this stage, both CA keys are software keys. The next section replaces the online intermediate.

Issue the CryptoHub-backed intermediate certificate

Load the CryptoHub variables:
Shell
Issue an intermediate certificate whose public key comes from CryptoHub:
Shell
The command reports that it saved intermediate_ca_cryptohub.crt.

Confirm the key binding

Compare the public key in CryptoHub with the public key in the new certificate:
Shell
cmp produces no output. OpenSSL prints the intermediate certificate path followed by OK. Only after both checks pass, install the new certificate and remove the superseded software intermediate key:
Shell
The encrypted root key remains on disk. The online intermediate private key exists only in CryptoHub.

Configure the PKCS #11 KMS

Rewrite the host paths for the container and add the KMS configuration:
Shell

Validate the CA configuration

Verify the non-secret path and KMS fields:
Shell
The output shows kms.type set to pkcs11, the CryptoHub key URI, and /home/step/.step/ paths that exist inside the container.