Skip to main content
Issue a leaf certificate, verify its chain independently, restart the CA, and repeat the operation. This proves that step-ca uses the CryptoHub intermediate during normal issuance and after process restart.

Confirm CA health

Shell
The command prints true and exits with status 0.

Issue the first leaf certificate

Shell
The command reports that it saved the certificate and private key. The leaf private key belongs to the requesting service; it is separate from both CA keys. Inspect the issuer and verify the chain:
Shell
The issuer is CryptoHub Smallstep Intermediate CA. OpenSSL prints:
Expected result

Confirm the CryptoHub signing operation

Shell
The output includes C_SignInit and C_SignFinal calls from the issuance window. Confirm that the superseded software intermediate key is absent:
Shell
The command exits with status 0. The root key remains encrypted on disk, while the active intermediate private key remains in CryptoHub.

Restart and repeat issuance

Shell
OpenSSL prints the second certificate path followed by OK. A second pair of C_SignInit and C_SignFinal calls appears in the FxChlibs log. The integration is complete when both certificates verify and the CA remains healthy after restart.