step-ca
step-ca from Smallstep is an open-source private certificate authority and ACME server that issues X.509 and SSH certificates for automated DevOps workflows.
- GitHub stars
- 8.9k
- Last commit
- 3 days ago
- Latest release
- v0.30.2
- Licence
- Apache-2.0
- Self-hosted
- Yes

step-ca, published as smallstep/certificates, is an online private certificate authority built for automated certificate management in DevOps environments. It is the server counterpart to the step command-line tool, and both are maintained by Smallstep Labs.
It can issue HTTPS server and client certificates trusted by browsers, as well as TLS certificates for virtual machines, containers, APIs, database connections and Kubernetes pods. It also issues SSH certificates: users can obtain them with single sign-on tokens, and hosts can obtain them using cloud instance identity documents. As an ACME server it supports the popular challenge types, and a Go wrapper and the step CLI help with scripting.
step-ca is written in Go and released under Apache-2.0. It is tuned for a two-tier PKI, and the README points teams that need multiple authorities, active revocation through CRL or OCSP, device attestation or a web admin UI to Smallstep's separate commercial product.
Key features
- Private certificate authority for X.509
- SSH certificates for users and hosts
- ACME server with common challenge types
- TLS certificates for containers and Kubernetes pods
- Single sign-on token exchange for SSH access
- Go wrapper and step CLI automation
Pricing: Open source under Apache-2.0; Smallstep also sells a separate commercial CA product with additional features.
