Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / step-ca

In Oracle review

DCA Hardened Private Certificate Authority for step-ca — Support & Quick Start

A hardened, CVE-patched virtual machine image running step-ca 0.30 — Smallstep's open-source online certificate authority — on Oracle Linux 9: your own private CA for service-to-service TLS, mutual TLS and automated certificate renewal inside your VCN.

Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusSubmitted for Oracle certification review
Version0.30.2
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 9000/tcp
CategorySecurity
Upstream licenceApache-2.0
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@PUBLIC_IP
  2. First boot creates a root and intermediate CA unique to this instance, then starts step-ca on 127.0.0.1:9000 as the unprivileged step user. Check both units:
    sudo systemctl status step-ca-firstboot step-ca
  3. Read the root fingerprint, provisioner name and password-file path (root only):
    sudo cat /root/.step-ca_default_credentials

    The encrypted CA keys and their passwords live only in /etc/step-ca/secrets as root-only files; systemd hands step-ca the key password at start.

  4. Issue a test certificate on this host (24-hour lifetime by default) and check the CA:
    sudo step ca certificate svc.internal svc.crt svc.key --ca-url https://127.0.0.1:9000 --root /etc/step-ca/certs/root_ca.crt --provisioner admin --provisioner-password-file /etc/step-ca/secrets/provisioner-password
    sudo step ca health --ca-url https://127.0.0.1:9000 --root /etc/step-ca/certs/root_ca.crt
  5. To serve clients in your VCN, move the listener off loopback and restart:
    sudo sed -i 's/"address": "127.0.0.1:9000"/"address": ":9000"/' /etc/step-ca/config/ca.json && sudo systemctl restart step-ca

    Port 9000 is already permitted in the host firewall. Restrict it in your VCN security list to the clients that need certificates; never expose the CA to the internet.

  6. On each client, install the step CLI, trust this CA by its fingerprint, then request a certificate (enter the provisioner password when prompted):
    step ca bootstrap --ca-url https://PRIVATE_IP:9000 --fingerprint CA_FINGERPRINT
    step ca certificate HOSTNAME HOSTNAME.crt HOSTNAME.key --provisioner admin

    Renew before it expires with: step ca renew HOSTNAME.crt HOSTNAME.key

  7. An ACME provisioner (directory https://PRIVATE_IP:9000/acme/acme/directory) serves ACME clients such as certbot that prove control of a name. To remove it:
    sudo step ca provisioner remove acme --ca-config /etc/step-ca/config/ca.json --ca-url https://127.0.0.1:9000 --root /etc/step-ca/certs/root_ca.crt && sudo systemctl restart step-ca
  8. Back up /etc/step-ca (encrypted keys, passwords, configuration) and /var/lib/step-ca (certificate database) to secure storage off the instance; keep a copy of the root key offline. The image is CVE-patched at build time; apply OS updates with:
    sudo dnf -y update

step-ca and the step CLI are installed from the upstream releases and are refreshed by launching a newer image version of this listing.

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.