> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Validate the integration

> Issue and independently verify a leaf certificate, restart step-ca, and repeat issuance with the CryptoHub-backed intermediate key.

Issue a leaf certificate, verify its chain independently, restart the CA, and repeat the operation. This proves that step-ca uses the CryptoHub intermediate during normal issuance and after process restart.

## Confirm CA health

```shell title="Shell" theme={null}
export STEPPATH=/var/lib/smallstep/.step
export CA_PASSWORD_FILE=/var/lib/smallstep/ca-password.txt

curl --fail --silent \
  --cacert "$STEPPATH/certs/root_ca.crt" \
  https://localhost:9000/health | jq -e '.status == "ok"'
```

The command prints `true` and exits with status 0.

## Issue the first leaf certificate

```shell title="Shell" theme={null}
mkdir -p /var/lib/smallstep/issued

step ca certificate \
  service.example.com \
  /var/lib/smallstep/issued/service.crt \
  /var/lib/smallstep/issued/service.key \
  --provisioner admin \
  --provisioner-password-file "$CA_PASSWORD_FILE" \
  --ca-url https://localhost:9000 \
  --root "$STEPPATH/certs/root_ca.crt" \
  --not-after 24h \
  --force
```

The command reports that it saved the certificate and private key. The leaf private key belongs to the requesting service; it is separate from both CA keys.

Inspect the issuer and verify the chain:

```shell title="Shell" theme={null}
openssl x509 \
  -in /var/lib/smallstep/issued/service.crt \
  -noout -subject -issuer

openssl verify \
  -CAfile "$STEPPATH/certs/root_ca.crt" \
  -untrusted "$STEPPATH/certs/intermediate_ca.crt" \
  /var/lib/smallstep/issued/service.crt
```

The issuer is `CryptoHub Smallstep Intermediate CA`. OpenSSL prints:

```text title="Expected result" theme={null}
/var/lib/smallstep/issued/service.crt: OK
```

## Confirm the CryptoHub signing operation

```shell title="Shell" theme={null}
sudo grep -E 'C_SignInit|C_SignFinal' \
  /var/log/futurex/smallstep-chlibs.log | tail -8
```

The output includes `C_SignInit` and `C_SignFinal` calls from the issuance window.

Confirm that the superseded software intermediate key is absent:

```shell title="Shell" theme={null}
test ! -e "$STEPPATH/secrets/intermediate_ca_key"
```

The command exits with status 0. The root key remains encrypted on disk, while the active intermediate private key remains in CryptoHub.

## Restart and repeat issuance

```shell title="Shell" theme={null}
sudo docker restart stepca

for attempt in $(seq 1 30); do
  if curl --fail --silent \
    --cacert "$STEPPATH/certs/root_ca.crt" \
    https://localhost:9000/health | jq -e '.status == "ok"' >/dev/null; then
    break
  fi
  sleep 2
done

step ca certificate \
  service-after-restart.example.com \
  /var/lib/smallstep/issued/service-after-restart.crt \
  /var/lib/smallstep/issued/service-after-restart.key \
  --provisioner admin \
  --provisioner-password-file "$CA_PASSWORD_FILE" \
  --ca-url https://localhost:9000 \
  --root "$STEPPATH/certs/root_ca.crt" \
  --not-after 24h \
  --force

openssl verify \
  -CAfile "$STEPPATH/certs/root_ca.crt" \
  -untrusted "$STEPPATH/certs/intermediate_ca.crt" \
  /var/lib/smallstep/issued/service-after-restart.crt
```

OpenSSL prints the second certificate path followed by `OK`. A second pair of `C_SignInit` and `C_SignFinal` calls appears in the FxChlibs log.

The integration is complete when both certificates verify and the CA remains healthy after restart.
