> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Deploy the service

> Deploy the Smallstep step-ca ClientApplication service and its CryptoHub key store.

Deploy the Smallstep service before creating its endpoint. The service owns the key store that holds the intermediate CA key.

<Steps>
  <Step>
    Log in to CryptoHub under dual control.

    Dual control authorizes the service and endpoint workflow with the same administrator context used for other managed integrations.
  </Step>

  <Step>
    Open **Services**, select **Smallstep step-ca**, and select **\[ Deploy ]**.

    The service tile identifies the CryptoHub Client Library PKCS #11 integration. Do not select a legacy Futurex PKCS #11 service.
  </Step>

  <Step>
    Set **Service Name** to a name that identifies this CA, then keep **Service Category** set to **Certificate Authority**.

    Select **\[ Next ]**.
  </Step>

  <Step>
    Review **Authorized Resources**. Add only the roles that must administer this CA service, then select **\[ Next ]**.
  </Step>

  <Step>
    Keep the endpoint authentication mechanism set to **UserPass**, then select **\[ Deploy ]**.

    UserPass is the validated noninteractive authentication method for the direct PKCS #11 route. CryptoHub creates the service, its key store, and the endpoint role.
  </Step>
</Steps>

<Check>
  CryptoHub opens the deployed service and shows a **step-ca** endpoint type. The service key store is available before the first key-generation command runs.
</Check>
