About step-ca
step-ca, published as smallstep/certificates, is an online private certificate authority built for automated certificate management in DevOps environments. It is the server counterpart to the step command-line tool, and both are maintained by Smallstep Labs.
It can issue HTTPS server and client certificates trusted by browsers, as well as TLS certificates for virtual machines, containers, APIs, database connections and Kubernetes pods. It also issues SSH certificates: users can obtain them with single sign-on tokens, and hosts can obtain them using cloud instance identity documents. As an ACME server it supports the popular challenge types, and a Go wrapper and the step CLI help with scripting.
step-ca is written in Go and released under Apache-2.0. It is tuned for a two-tier PKI, and the README points teams that need multiple authorities, active revocation through CRL or OCSP, device attestation or a web admin UI to Smallstep's separate commercial product.
Key features
- Private certificate authority for X.509
- SSH certificates for users and hosts
- ACME server with common challenge types
- TLS certificates for containers and Kubernetes pods
- Single sign-on token exchange for SSH access
- Go wrapper and step CLI automation
Good fit for
- →Running an internal PKI for TLS
- →Replacing static SSH keys with certificates
- Built with
- Go
- Tags
- certificate-authority
- pki
- acme
- tls
- x509
- ssh
- security
- go
step-ca: questions and answers
- What is step-ca used for?
- step-ca from Smallstep is an open-source private certificate authority and ACME server that issues X.509 and SSH certificates for automated DevOps workflows. It is a good fit for running an internal PKI for TLS and replacing static SSH keys with certificates.
- Is step-ca open source?
- Yes. step-ca is open source under the Apache-2.0 licence. Its source code is on GitHub at smallstep/certificates and is written mainly in Go.
- Is step-ca free?
- Yes. step-ca is open source, so the software itself is free to use.
- Can I self-host step-ca?
- Yes. step-ca can be self-hosted on your own server or infrastructure.
- What is step-ca an alternative to?
- step-ca is an open-source alternative to Entrust, DigiCert, Sectigo and GlobalSign. Other open-source alternatives to DigiCert include Lego, acme.sh and Certbot.
- Is step-ca actively maintained?
- Yes. The most recent commit to step-ca was on 29 September 2026, and the latest release is v0.30.2, published on 23 March 2026. The project has 8.9k stars on GitHub.
Open-source alternatives to step-ca
See all
Lego
Security
Let's Encrypt/ACME client and library written in Go
MITvs DigiCert★ 9.9k
acme.sh
Security
A pure Unix shell script ACME client for SSL / TLS certificate automation
GPL-3.0vs DigiCert★ 48k
Certbot
Security
Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTP
OSSvs DigiCert★ 33k
Certimate
Security
ssl tls https ssl-certificate ssl-certificates ssl-cert https-certificate https-certificat
MITvs Sectigo★ 9.3k
OpenBao
Security
OpenBao is a software solution to manage, store, and distribute sensitive data including s
MPL-2.0vs AWS Secrets Manager★ 8.3k
Certd
Security
开源SSL证书管理工具;全自动证书申请、更新、续期;通配符证书,泛域名证书申请;证书自动化部署到阿里云、腾讯云、主机、群晖、宝塔;https证书,pfx证书,der证书,TLS证书
AGPL-3.0vs Sectigo★ 5k
SaaS alternatives to step-ca
See all
Entrust
Security
Identity security provider with MFA, PKI, identity verification and payments security
SaaS
DigiCert
Security
Certificate authority and digital trust provider for TLS and PKI
SaaS
Sectigo
Security
Certificate authority offering TLS certificates and certificate lifecycle management
SaaS
GlobalSign
Security
Certificate authority and digital identity provider
SaaS
Keyfactor
Security
Machine identity and PKI management platform
SaaS
AttackerView
Security
Security auditor that shows what an attacker can see on your website
SaaS

