Home / Support / Oracle Cloud Marketplace / step-ca
In Oracle reviewA hardened, CVE-patched virtual machine image running step-ca 0.30 — Smallstep's open-source online certificate authority — on Oracle Linux 9: your own private CA for service-to-service TLS, mutual TLS and automated certificate renewal inside your VCN.
| Status | Submitted for Oracle certification review |
|---|---|
| Version | 0.30.2 |
| Platform | Oracle Linux 9 |
| Ports open in the host firewall | SSH (22/tcp), 9000/tcp |
| Category | Security |
| Upstream licence | Apache-2.0 |
| Pricing | Pay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab |
This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.
After launch:
ssh opc@PUBLIC_IPsudo systemctl status step-ca-firstboot step-casudo cat /root/.step-ca_default_credentialsThe encrypted CA keys and their passwords live only in /etc/step-ca/secrets as root-only files; systemd hands step-ca the key password at start.
sudo step ca certificate svc.internal svc.crt svc.key --ca-url https://127.0.0.1:9000 --root /etc/step-ca/certs/root_ca.crt --provisioner admin --provisioner-password-file /etc/step-ca/secrets/provisioner-password
sudo step ca health --ca-url https://127.0.0.1:9000 --root /etc/step-ca/certs/root_ca.crtsudo sed -i 's/"address": "127.0.0.1:9000"/"address": ":9000"/' /etc/step-ca/config/ca.json && sudo systemctl restart step-caPort 9000 is already permitted in the host firewall. Restrict it in your VCN security list to the clients that need certificates; never expose the CA to the internet.
step ca bootstrap --ca-url https://PRIVATE_IP:9000 --fingerprint CA_FINGERPRINT
step ca certificate HOSTNAME HOSTNAME.crt HOSTNAME.key --provisioner adminRenew before it expires with: step ca renew HOSTNAME.crt HOSTNAME.key
sudo step ca provisioner remove acme --ca-config /etc/step-ca/config/ca.json --ca-url https://127.0.0.1:9000 --root /etc/step-ca/certs/root_ca.crt && sudo systemctl restart step-casudo dnf -y updatestep-ca and the step CLI are installed from the upstream releases and are refreshed by launching a newer image version of this listing.
Email support@dcassociatesgroup.com (response within 1 business day) or use the
contact form. Include the listing name, your OCI region, the instance OCID and the
output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.