> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Start step-ca

> Start the pinned PKCS #11-capable step-ca HSM container with its online intermediate key held in CryptoHub.

Start the online CA from the pinned HSM image. Bind-mount the CA state and endpoint files instead of copying either credential set into the image.

## Load the runtime variables

```shell title="Shell" theme={null}
export STEPPATH=/var/lib/smallstep/.step
export CA_PASSWORD_FILE=/var/lib/smallstep/ca-password.txt
source /etc/step-ca/cryptohub.env

STEP_CA_GROUP_ID=$(getent group step-ca | cut -d: -f3)
test -n "$STEP_CA_GROUP_ID"
```

The final command exits with status 0 when the endpoint-file group exists.

## Start the container

```shell title="Shell" theme={null}
sudo docker run -d \
  --name stepca \
  -p 9000:9000 \
  --user "$(id -u):$(id -g)" \
  --group-add "$STEP_CA_GROUP_ID" \
  -e CHLIBS_CONFIG=/opt/futurex/cryptohub.json \
  -e STEPPATH=/home/step/.step \
  -v "$STEPPATH:/home/step/.step" \
  -v "$CA_PASSWORD_FILE:/home/step/ca-password.txt:ro" \
  -v /opt/futurex:/opt/futurex:ro \
  -v /var/log/futurex:/var/log/futurex \
  --entrypoint /usr/local/bin/step-ca \
  smallstep/step-ca:0.30.2-hsm \
  --password-file /home/step/ca-password.txt \
  /home/step/.step/config/ca.json
```

Docker prints the new container ID.

The command keeps the endpoint directory read-only, exposes the CA on port 9000, and grants the container only the supplementary group needed to read the endpoint files and append to the FxChlibs log.

<Note>
  The command does not pass a PKCS #11 PIN or endpoint password. FxChlibs reads the protected UserPass credential from the bind-mounted `cryptohub.json`.
</Note>

## Verify startup

Check the container state and CA health:

```shell title="Shell" theme={null}
sudo docker ps --filter name=stepca

curl --fail --silent \
  --cacert "$STEPPATH/certs/root_ca.crt" \
  https://localhost:9000/health | jq .
```

The health response is:

```json title="Expected result" theme={null}
{
  "status": "ok"
}
```

Inspect the startup log:

```shell title="Shell" theme={null}
sudo docker logs --tail 50 stepca
```

The log includes these messages:

```text title="Expected result" theme={null}
Building new tls configuration using step-ca x509 Signer Interface
Serving HTTPS on :9000 ...
```

Confirm that FxChlibs reached the intermediate key:

```shell title="Shell" theme={null}
sudo grep -E 'C_SignInit|C_SignFinal' \
  /var/log/futurex/smallstep-chlibs.log | tail
```

The output includes successful sign initialization and finalization calls. Continue to [Validate the integration](/Integrations/CryptoHub-7.3/Certificate_Authority/Smallstep_step-ca/Validate_the_integration) to issue a leaf certificate.
