7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

step-ca

Open source

step-ca from Smallstep is an open-source private certificate authority and ACME server that issues X.509 and SSH certificates for automated DevOps workflows.

smallstep.com
step-ca homepage screenshot
GitHub stars
8.9k
Last commit
3 days ago
Repository age
7 years
Version
v0.30.2
Licence
Apache-2.0
Self-hosted
Yes

About step-ca

step-ca, published as smallstep/certificates, is an online private certificate authority built for automated certificate management in DevOps environments. It is the server counterpart to the step command-line tool, and both are maintained by Smallstep Labs.

It can issue HTTPS server and client certificates trusted by browsers, as well as TLS certificates for virtual machines, containers, APIs, database connections and Kubernetes pods. It also issues SSH certificates: users can obtain them with single sign-on tokens, and hosts can obtain them using cloud instance identity documents. As an ACME server it supports the popular challenge types, and a Go wrapper and the step CLI help with scripting.

step-ca is written in Go and released under Apache-2.0. It is tuned for a two-tier PKI, and the README points teams that need multiple authorities, active revocation through CRL or OCSP, device attestation or a web admin UI to Smallstep's separate commercial product.

Key features

  • Private certificate authority for X.509
  • SSH certificates for users and hosts
  • ACME server with common challenge types
  • TLS certificates for containers and Kubernetes pods
  • Single sign-on token exchange for SSH access
  • Go wrapper and step CLI automation

Good fit for

  • →Running an internal PKI for TLS
  • →Replacing static SSH keys with certificates
Built with
Go
Tags
certificate-authority
pki
acme
tls
x509
ssh
security
go

step-ca: questions and answers

What is step-ca used for?
step-ca from Smallstep is an open-source private certificate authority and ACME server that issues X.509 and SSH certificates for automated DevOps workflows. It is a good fit for running an internal PKI for TLS and replacing static SSH keys with certificates.
Is step-ca open source?
Yes. step-ca is open source under the Apache-2.0 licence. Its source code is on GitHub at smallstep/certificates and is written mainly in Go.
Is step-ca free?
Yes. step-ca is open source, so the software itself is free to use.
Can I self-host step-ca?
Yes. step-ca can be self-hosted on your own server or infrastructure.
What is step-ca an alternative to?
step-ca is an open-source alternative to Entrust, DigiCert, Sectigo and GlobalSign. Other open-source alternatives to DigiCert include Lego, acme.sh and Certbot.
Is step-ca actively maintained?
Yes. The most recent commit to step-ca was on 29 September 2026, and the latest release is v0.30.2, published on 23 March 2026. The project has 8.9k stars on GitHub.

Open-source alternatives to step-ca

See all

SaaS alternatives to step-ca

See all