Where Does Smallstep step-ca Store Keys and Certs?
Where Smallstep step-ca keeps keys and database on Linux servers. Full paths are listed below. More below.
Last updated
Smallstep step-ca is private PKI with server storage. The config directory holds provisioners and authority keys. The database holds certificates and fingerprints.
Same config plus database means same authority. Exact paths vary by binary versus Docker installs, often under step paths. Keep root keys offline beside live copies. For moves, stop services first to avoid partial writes. Clients need fresh trust bundles after migration to the new host. Screenshots of settings help when support asks for reproduction steps later.
Where Smallstep CA stores this, by platform
/var/lib/step (config plus database, paths vary by install)
Authority keys and provisioners live in config on your server with certs beside them in database. Back up both together stopped. Keep roots offline too.
Frequently asked questions
How do I migrate step-ca to a new server?
Back up the step-ca config directory with services stopped, then install the same release on the new server before restore. Provisioners follow the config. Mixed releases can refuse old databases, so match versions first. Keep the root keys offline too.
Does step-ca upload private keys?
No. step-ca signs from its local database and files without uploading. The server holds certs, keys, and provisioner configs. Clients hold fingerprints plus short lived certs. Back up the config dir plus database together. One without the other loses trust roots.
Notice an outdated path? Let us know.