> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Generate the intermediate CA key

> Generate the nonexportable RSA-3072 intermediate CA key in CryptoHub with step-kms-plugin.

Generate the online intermediate CA key directly in the Smallstep service key store. The command returns only the public key.

## Review the key policy

The Smallstep service pins these attributes:

| Setting | Value | Reason |
| - | - | - |
| Algorithm | RSA | Matches the validated certificate-signing route |
| Size | 3072 bits | Matches the validated key size |
| Protection | TRUSTED | Keeps the key encrypted under the HSM-protected key hierarchy |
| Usages | Sign and Verify | Restricts the key to the certificate-signing usage class |
| Extractable | No | Prevents private-key export |

The template forces Sign/Verify because step-kms-plugin can request a broader RSA template than a TRUSTED key accepts.

## Generate the key

Load the endpoint variables:

```shell title="Shell" theme={null}
source /etc/step-ca/cryptohub.env
export CHLIBS_CONFIG
```

Confirm that `STEP_INTERMEDIATE_KEY` contains both the hexadecimal `id` and the `object` label. These values identify the same key in every later command.

Generate the key:

```shell title="Shell" theme={null}
step kms create \
  --kty RSA \
  --size 3072 \
  --kms "$STEP_KMS_URI" \
  "$STEP_INTERMEDIATE_KEY" \
  > /tmp/smallstep-intermediate-public.pem
```

The command prints or writes a PEM public key beginning with:

```text title="Expected result" theme={null}
-----BEGIN PUBLIC KEY-----
```

No private-key file appears on the step-ca host.

## Confirm the key is reusable

Retrieve the public key again:

```shell title="Shell" theme={null}
step kms key \
  --kms "$STEP_KMS_URI" \
  "$STEP_INTERMEDIATE_KEY" \
  > /tmp/smallstep-intermediate-public-check.pem

cmp \
  /tmp/smallstep-intermediate-public.pem \
  /tmp/smallstep-intermediate-public-check.pem
```

`cmp` produces no output and exits with status 0 when both commands resolved the same CryptoHub key.

<Warning>
  Do not rerun `step kms create` with the same ID and label after the key exists. Use `step kms key` to retrieve its public key. To rotate the intermediate, choose a new ID and label and follow a planned CA rotation procedure.
</Warning>
