Skip to main content
Generate the online intermediate CA key directly in the Smallstep service key store. The command returns only the public key.

Review the key policy

The Smallstep service pins these attributes: The template forces Sign/Verify because step-kms-plugin can request a broader RSA template than a TRUSTED key accepts.

Generate the key

Load the endpoint variables:
Shell
Confirm that STEP_INTERMEDIATE_KEY contains both the hexadecimal id and the object label. These values identify the same key in every later command. Generate the key:
Shell
The command prints or writes a PEM public key beginning with:
Expected result
No private-key file appears on the step-ca host.

Confirm the key is reusable

Retrieve the public key again:
Shell
cmp produces no output and exits with status 0 when both commands resolved the same CryptoHub key.
Do not rerun step kms create with the same ID and label after the key exists. Use step kms key to retrieve its public key. To rotate the intermediate, choose a new ID and label and follow a planned CA rotation procedure.