Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ The script will:
- Help you choose a JWK provisioner on your CA to link your RA to
- Create RA configuration files in `/etc/step-ca`
- Create a `step` user and group
- Add a systemd service called `step-ca.service`
- Add a systemd service called `step-ca.service`, with a drop-in file at `/etc/systemd/system/step-ca.service.d/local.conf` that sets the `step-ca` command line. To change `step-ca` flags, edit the drop-in file.
- Enable and start `step-ca.service`
- Export a `STEPPATH` variable in `/root/.bash_profile`

Expand Down
1 change: 0 additions & 1 deletion step-ca/acme-basics.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -159,7 +159,6 @@ Finalizing Order .. done!
✔ Private Key: example.key
```


## Next steps

- Start tailoring `step-ca` to your infrastructure. See [Provisioners](./provisioners.mdx), [Production Considerations](./certificate-authority-server-production.mdx), and our [Configuration Guide](./configuration.mdx).
Expand Down
15 changes: 14 additions & 1 deletion step-ca/certificate-authority-server-production.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,7 @@ safely and securely in a production environment.
- [High Availability](#high-availability)
- [Proxying `step-ca` traffic](#proxying-step-ca-traffic)
- [Exposing `step-ca` to the internet](#exposing-step-ca-to-the-internet)
- [Using an alternative DNS resolver](#using-an-alternative-dns-resolver)
- [Certificate Lifecycle Management](#certificate-lifecycle-management)
- [Automate Certificate Renewal](#automate-x509-certificate-lifecycle-management)
- [Certificate Revocation](#certificate-revocation)
Expand Down Expand Up @@ -649,7 +650,6 @@ When connecting an ACME provisioner to the internet, you will need to take preca
echo https://ca.example.com/acme/$PROVISIONER_NAME/directory
}
```


### Alternative: Use federation

Expand All @@ -659,6 +659,19 @@ there's no need to expose your CA to the internet.

Use [multiple autonomous federated CAs](../tutorials/pki-trust-model-federation.mdx) instead.

## Using an alternative DNS resolver

By default, `step-ca` uses the system DNS resolver to look up `dns-01` challenge records.
In a split-horizon DNS environment, the internal resolver may not see the `TXT` records that your ACME client creates at a public DNS provider.
To send DNS queries to a different resolver, start `step-ca` with the `--resolver` flag:

```shell
step-ca --resolver 1.1.1.1 $(step path)/config/ca.json
```

The flag applies to all DNS queries that `step-ca` makes, including `http-01` and `tls-alpn-01` validation and outbound connections to an upstream CA or to webhook servers.


## Certificate lifecycle management

### Automate X.509 certificate lifecycle management
Expand Down
Loading