Do I need smallstep-ca or just smallstep-cli #1787
Replies: 2 comments
-
|
Ended up following the guide here: https://blog.xentoo.info/2021/09/12/running-a-pki-using-smallstep-certificates-with-docker Am getting an error that I cannot trace down though when trying to issue a cert for a host:
If anyone can decipher the above, I'd be happy to get some pointers. |
Beta Was this translation helpful? Give feedback.
-
|
The
Clients can get certificate by running the Or you can do the entire operation — generate and sign a CSR all at once — using the We designed Hope this helps! |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
I've finally decided to do something about the huge number of internal sites and devices that use self signed certs. I'm looking for a simple CA that I can pass CSRs to, get them signed, grab the cert and install. I've used a combo of OpenSSL for generating CSRs and Windows CA Server to sign them for years through work so just looking for a simpler setup for home.
I assumed I needed smallstep-ca which I plan to run via docker so thats set up and running as per the below. * I realise we're not supposed to be setting passwords as env variables. I'm jut trying to get it working for now.
Then I've read here that smallstep-ca is not required to run a CA: https://smallstep.com/docs/step-cli/#introduction-to-step
Examples that don't require step-ca
Create and work with X.509 certificates](https://smallstep.com/docs/step-cli/basic-crypto-operations/#create-and-work-with-x509-certificates)
https://smallstep.com/docs/step-cli/basic-crypto-operations/#create-a-certificate-authority
You can use it to create certificate signing requests (CSRs), sign CSRs, create self-signed certificates (e.g., a root certificate authority), create leaf or intermediate CA certificates, validate and inspect certificates, renew certificates, generate certificate bundles, and to key-wrap private keys.
So the first question I have is which should I be running? Experience tells me that I will definitely need a CA as that's how I've worked for years.
Second question is, assuming I'm going the CA Server route via docker, once i have it running, how do I submit a CSR for signing? I'm finding mixed resources and none of them seem to offer a simple set of steps to submit a CSR and get the resulting certificate.
Thanks for any advice you can offer!
Beta Was this translation helpful? Give feedback.
All reactions