Ross ROSS = Recommend OSS · open-source software intelligence for agents

smallstep/certificates

🛡️ A private certificate authority (X.509 & SSH) & ACME server for secure automated certificate management, so you can use TLS everywhere & SSO for SSH. observed · 2026-08-28

github.com/smallstep/certificates · homepage · Go · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

91/100

  • Activity 99
  • Release rhythm 75
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 29.0
  • age_days: 2862
  • days_rel: 164
  • days_push: 9
  • n_releases_24m: 11

Full methodology

Adoption not part of the score

8779 stars · 580 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

step-ca is an online private certificate authority (X.509 and SSH) and ACME server for secure, automated certificate management in DevOps environments. It issues TLS and SSH certificates with SSO and cloud identity integrations, enabling TLS everywhere and certificate-based SSH authentication.

Use cases

  • run a private certificate authority for internal TLS certificates
  • issue HTTPS certificates for dev, staging, and internal services that work in browsers
  • automate certificate issuance and renewal with an ACME server
  • issue short-lived SSH certificates with single sign-on instead of managing authorized_keys
  • issue TLS certificates for Kubernetes pods, containers, VMs, and database connections
  • replace static API keys and SSH keys with short-lived certificates
  • set up certificate-based mTLS authentication between services

When to choose

  • you need a self-hosted private CA for internal TLS without paying public CAs
  • you want automated, short-lived certificate lifecycle management via ACME
  • you want SSH certificate authentication tied to an identity provider
  • you need RFC5280 and CA/Browser Forum compliant certificates for browsers and clients

When to avoid

  • you need multiple certificate authorities, CRL/OCSP active revocation, or high-volume HA CA features
  • you need SCEP/NDES, device attestation with TPM/Secure Enclave, or MDM integrations - these are in Smallstep's commercial product
  • you want a web admin UI or ACME External Account Binding
  • you just need certificates from a public CA for public websites - use Let's Encrypt directly

Facets

service · maturity active

security cryptography http-server api-framework auth deployment security networking self-hosted infrastructure-as-code windows self-hosted go cli certificate-authority pki x509 ssh-certificates acme-server tls step-ca zero-trust short-lived-certificates devops linux macos docker kubernetes

6 sources

Member repositories

RepositoryRoleHealth v2
smallstep/certificatesmain91

For agents

markdown · JSON · MCP: product_card(name="smallstep/certificates")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem