Simplifies creating and managing a private PKI and issuing short-lived TLS certificates for internal services.

Install

mkdir -p .claude/skills/step-ca && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/11459" && unzip -o skill.zip -d .claude/skills/step-ca && rm skill.zip

Installs to .claude/skills/step-ca

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Run a private certificate authority with step-ca. Use when a user asks to issue internal TLS certificates, set up mTLS between services, create a private PKI, or manage certificates for internal infrastructure.
210 chars✓ has a “when” trigger
Intermediate

Key capabilities

  • Run a private certificate authority
  • Issue internal TLS certificates
  • Set up mTLS between services
  • Manage certificates for internal infrastructure
  • Automate certificate renewal

How it works

The skill initializes a private CA, then issues and manages TLS certificates for internal services, supporting auto-renewal.

Inputs & outputs

You give it
a certificate signing request for an internal service
You get back
a signed TLS certificate and key

When to use step-ca

  • Set up a private PKI
  • Issue internal TLS certificates
  • Configure mTLS between microservices
  • Automate certificate renewal

About this skill

step-ca (Smallstep)

Overview

step-ca is a private certificate authority for issuing TLS certificates to internal services. Automated certificate issuance, renewal, and revocation — like Let's Encrypt but for private infrastructure.

Instructions

Step 1: Initialize CA

brew install step
step ca init --name "Internal CA" --dns localhost --address :443 --provisioner admin

Step 2: Issue Certificates

step-ca $(step path)/config/ca.json    # start CA server
step ca certificate api.internal api.crt api.key    # issue cert

Step 3: Auto-Renewal

step ca renew --daemon api.crt api.key    # auto-renews before expiry

Step 4: mTLS Between Services

// server.ts — Node.js server with mutual TLS
import https from 'https'
import fs from 'fs'

const server = https.createServer({
  cert: fs.readFileSync('server.crt'),
  key: fs.readFileSync('server.key'),
  ca: fs.readFileSync('root_ca.crt'),
  requestCert: true,          // require client certificate
  rejectUnauthorized: true,
}, (req, res) => {
  const clientCN = req.socket.getPeerCertificate().subject.CN
  res.end('Hello ' + clientCN)
})

Guidelines

  • Use step-ca for internal services, Let's Encrypt for public-facing.
  • Short-lived certs (24h) with auto-renewal are more secure than long-lived ones.
  • ACME protocol support — works with Certbot, Caddy.
  • Integrates with Kubernetes cert-manager for automatic pod certificates.

When not to use it

  • When issuing certificates for public-facing services

Prerequisites

step

Limitations

  • It is for internal services only.
  • It is not for public-facing services.

How it compares

This workflow provides an automated, private certificate authority for internal infrastructure, unlike manual certificate management or public CAs.

Compared to similar skills

step-ca side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
step-ca (this skill)03moReviewIntermediate
opnsense02moNo flagsIntermediate
azure-infra-review04moNo flagsIntermediate
infra-architect01moReviewAdvanced

Try saying

Example prompts that trigger this skill in your AI assistant.

Search skills

Search the agent skills registry