@terminalskills/step-ca
ARun a private certificate authority with step-ca. Use when a user asks to issue internal TLS certificates, set up mTLS between services, create a private PKI, or manage certificates for internal infrastructure.
Install
agr install @terminalskills/step-ca --target claudeWrites 2 files into .claude/skills/, pinned to git-033987e0.
- .claude/skills/step-ca/SKILL.md
- .claude/skills/step-ca/_scores.json
Document
name: step-ca description: >- Run a private certificate authority with step-ca. Use when a user asks to issue internal TLS certificates, set up mTLS between services, create a private PKI, or manage certificates for internal infrastructure. license: Apache-2.0 compatibility: 'Linux, macOS, Docker' metadata: author: terminal-skills version: 1.0.0 category: devops tags: - step-ca - pki - certificates - mtls - internal-tls
step-ca (Smallstep)
Overview
step-ca is a private certificate authority for issuing TLS certificates to internal services. Automated certificate issuance, renewal, and revocation — like Let's Encrypt but for private infrastructure.
Instructions
Step 1: Initialize CA
brew install step
step ca init --name "Internal CA" --dns localhost --address :443 --provisioner admin
Step 2: Issue Certificates
step-ca $(step path)/config/ca.json # start CA server
step ca certificate api.internal api.crt api.key # issue cert
Step 3: Auto-Renewal
step ca renew --daemon api.crt api.key # auto-renews before expiry
Step 4: mTLS Between Services
// server.ts — Node.js server with mutual TLS
import https from 'https'
import fs from 'fs'
const server = https.createServer({
cert: fs.readFileSync('server.crt'),
key: fs.readFileSync('server.key'),
ca: fs.readFileSync('root_ca.crt'),
requestCert: true, // require client certificate
rejectUnauthorized: true,
}, (req, res) => {
const clientCN = req.socket.getPeerCertificate().subject.CN
res.end('Hello ' + clientCN)
})
Guidelines
- Use step-ca for internal services, Let's Encrypt for public-facing.
- Short-lived certs (24h) with auto-renewal are more secure than long-lived ones.
- ACME protocol support — works with Certbot, Caddy.
- Integrates with Kubernetes cert-manager for automatic pod certificates.
Trustgrade A
- passBody integrity
Whether the stored document is plausibly the kind of file the artifact declares, rather than something fetched by mistake.
- passType matchnot applicable to this artifact type
Whether the artifact is really the kind of thing its metadata claims it is.
- passFreshness
How long since the source repository was last pushed to.
- passPrompt injection
Scans the artifact's own text for instructions aimed at your agent rather than at you.
- passLicense
Whether the source repository declares an SPDX license permissive enough to redistribute.
How the grade is calculated
Each check contributes 0 points when it passes, 1 when it warns, and 2 when it fails. The total maps to a letter:
- Aevery check passed
- Bone warning
- Ctwo warnings
- Dprompt injection or body integrity failed, or three warnings
- Fone of those failed, and something else is wrong
These are automated hygiene checks, not a security audit, and not a dependency or vulnerability scan. A grade of A means nothing was flagged — not that the artifact is safe.
Versions
git-033987e00a272026-07-31