Simplifies creating and managing a private PKI and issuing short-lived TLS certificates for internal services.
Install
mkdir -p .claude/skills/step-ca && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/11459" && unzip -o skill.zip -d .claude/skills/step-ca && rm skill.zipInstalls to .claude/skills/step-ca
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Run a private certificate authority with step-ca. Use when a user asks to issue internal TLS certificates, set up mTLS between services, create a private PKI, or manage certificates for internal infrastructure.Key capabilities
- →Run a private certificate authority
- →Issue internal TLS certificates
- →Set up mTLS between services
- →Manage certificates for internal infrastructure
- →Automate certificate renewal
How it works
The skill initializes a private CA, then issues and manages TLS certificates for internal services, supporting auto-renewal.
Inputs & outputs
When to use step-ca
- →Set up a private PKI
- →Issue internal TLS certificates
- →Configure mTLS between microservices
- →Automate certificate renewal
About this skill
step-ca (Smallstep)
Overview
step-ca is a private certificate authority for issuing TLS certificates to internal services. Automated certificate issuance, renewal, and revocation — like Let's Encrypt but for private infrastructure.
Instructions
Step 1: Initialize CA
brew install step
step ca init --name "Internal CA" --dns localhost --address :443 --provisioner admin
Step 2: Issue Certificates
step-ca $(step path)/config/ca.json # start CA server
step ca certificate api.internal api.crt api.key # issue cert
Step 3: Auto-Renewal
step ca renew --daemon api.crt api.key # auto-renews before expiry
Step 4: mTLS Between Services
// server.ts — Node.js server with mutual TLS
import https from 'https'
import fs from 'fs'
const server = https.createServer({
cert: fs.readFileSync('server.crt'),
key: fs.readFileSync('server.key'),
ca: fs.readFileSync('root_ca.crt'),
requestCert: true, // require client certificate
rejectUnauthorized: true,
}, (req, res) => {
const clientCN = req.socket.getPeerCertificate().subject.CN
res.end('Hello ' + clientCN)
})
Guidelines
- Use step-ca for internal services, Let's Encrypt for public-facing.
- Short-lived certs (24h) with auto-renewal are more secure than long-lived ones.
- ACME protocol support — works with Certbot, Caddy.
- Integrates with Kubernetes cert-manager for automatic pod certificates.
When not to use it
- →When issuing certificates for public-facing services
Prerequisites
Limitations
- →It is for internal services only.
- →It is not for public-facing services.
How it compares
This workflow provides an automated, private certificate authority for internal infrastructure, unlike manual certificate management or public CAs.
Compared to similar skills
step-ca side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| step-ca (this skill) | 0 | 3mo | Review | Intermediate |
| opnsense | 0 | 2mo | No flags | Intermediate |
| azure-infra-review | 0 | 4mo | No flags | Intermediate |
| infra-architect | 0 | 1mo | Review | Advanced |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by TerminalSkills
View all by TerminalSkills →You might also like
opnsense
MylesLandais
OPNsense firewall + router for the SecretCon lab, deployed as a Proxmox VM in front of vmbr1
azure-infra-review
aldelar
Reviews Bicep modules, azure.yaml, and infrastructure changes for the KB Agent project. Checks naming, RBAC, module wiring, and doc sync. Use when working on infra/ or reviewing infrastructure PRs.
infra-architect
k1lgor
|
secrets-management
wshobson
Implement secure secrets management for CI/CD pipelines using Vault, AWS Secrets Manager, or native platform solutions. Use when handling sensitive credentials, rotating secrets, or securing CI/CD environments.
container-security-testing
Ed1s0nZ
容器安全测试的专业技能和方法论
secure-storage
gabriellpequeno
>