> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Install Smallstep and the HSM image

> Install step CLI 0.30.6 and step-kms-plugin 0.17.0, then pull the pinned PKCS #11-capable step-ca 0.30.2 HSM image.

Install the host bootstrap tools and the pinned HSM container image. The host uses `step` and `step-kms-plugin` to initialize the CA; the container runs the online CA.

## Install operating-system packages

```shell title="Shell" theme={null}
sudo apt-get update
sudo apt-get install -y ca-certificates curl docker.io jq opensc openssl
sudo systemctl enable --now docker
```

Confirm that Docker is running:

```shell title="Shell" theme={null}
sudo docker info >/dev/null
```

The command exits with status 0 when the Docker daemon is ready.

## Install step CLI 0.30.6

```shell title="Shell" theme={null}
curl -fL \
  https://github.com/smallstep/cli/releases/download/v0.30.6/step_linux_amd64.tar.gz \
  -o /tmp/step-cli.tgz
rm -rf /tmp/step-cli
mkdir -p /tmp/step-cli
tar -xzf /tmp/step-cli.tgz -C /tmp/step-cli
sudo install -m 0755 \
  "$(find /tmp/step-cli -type f -name step | head -1)" \
  /usr/local/bin/step
step version
```

The output includes `Smallstep CLI/0.30.6`.

## Install step-kms-plugin 0.17.0

```shell title="Shell" theme={null}
curl -fL \
  https://github.com/smallstep/step-kms-plugin/releases/download/v0.17.0/step-kms-plugin_0.17.0_linux_amd64.tar.gz \
  -o /tmp/step-kms-plugin.tgz
rm -rf /tmp/step-kms-plugin
mkdir -p /tmp/step-kms-plugin
tar -xzf /tmp/step-kms-plugin.tgz -C /tmp/step-kms-plugin
sudo install -m 0755 \
  "$(find /tmp/step-kms-plugin -type f -name step-kms-plugin | head -1)" \
  /usr/local/bin/step-kms-plugin
step-kms-plugin version
```

The output includes `step-kms-plugin/0.17.0`.

## Pull the HSM image

```shell title="Shell" theme={null}
sudo docker pull smallstep/step-ca:0.30.2-hsm
sudo docker run --rm \
  --entrypoint /usr/local/bin/step-ca \
  smallstep/step-ca:0.30.2-hsm version
```

The second command reports `Smallstep CA/0.30.2`.

<Warning>
  Do not substitute `smallstep/step-ca:0.30.2` or an ordinary step-ca package. The `-hsm` image is the CGO-enabled build that supports a native PKCS #11 module.
</Warning>

## Register the plugin for the CA workspace

Create the CA workspace and plugin link:

```shell title="Shell" theme={null}
export STEPPATH=/var/lib/smallstep/.step
sudo install -d -m 0750 -o "$USER" -g "$(id -gn)" \
  /var/lib/smallstep "$STEPPATH" "$STEPPATH/plugins"
ln -sf /usr/local/bin/step-kms-plugin \
  "$STEPPATH/plugins/step-kms-plugin"
```

Confirm that step discovers the plugin:

```shell title="Shell" theme={null}
STEPPATH=/var/lib/smallstep/.step step kms help >/dev/null
```

The command exits with status 0 when the KMS commands are available.
