Skip to main content
Create one endpoint for each step-ca host. The downloaded ZIP contains the module, configuration, credential, and TLS files that bind the host to the deployed service.
Treat the endpoint ZIP as a credential. Store it outside source control and remove unprotected copies after installing the endpoint.
1
Open the deployed Smallstep service and select Endpoints.
2
Select [ Add endpoint ], then select the step-ca endpoint type.
3
Enter an Endpoint Name that identifies the CA host.Keep Authentication Type set to UserPass.
4
Select Linux OpenSSL 3.x as the platform.This platform supplies the Linux FxChlibs module used by the validated x86-64 container route.
5
Set Device Address to the CryptoHub FQDN that the CA host uses, then create the endpoint.
6
Download the endpoint ZIP and move it to the step-ca host through an approved secure transfer method.
Confirm that the ZIP contains at least these files:
The generated cryptohub.json names the deployed service and enables TLS verification. Do not replace it with a sample configuration from another service.