Review the key policy
The Smallstep service pins these attributes:
The template forces Sign/Verify because step-kms-plugin can request a broader RSA template than a TRUSTED key accepts.
Generate the key
Load the endpoint variables:Shell
STEP_INTERMEDIATE_KEY contains both the hexadecimal id and the object label. These values identify the same key in every later command.
Generate the key:
Shell
Expected result
Confirm the key is reusable
Retrieve the public key again:Shell
cmp produces no output and exits with status 0 when both commands resolved the same CryptoHub key.

