Where Does step-ca Store Config and Certs?
step-ca keeps authority config in ~/.step with certs and keys under the authority fingerprint folder.
Last updated
step-ca stores authority state in a .step folder in the running user home. The config folder holds ca.json with provisioners and DNS names. Issued certificates and keys accumulate under the authority fingerprint directory.
Password files for encrypted keys sit beside the config and deserve strict permissions. Back up the whole .step tree with the password to restore the authority. Losing the keys means reissuing every certificate.
Where step-ca stores this, by platform
~/.step
ca.json config plus certs under the fingerprint folder. Password files sit beside them chmod 600. Back up the tree to preserve the authority.
Frequently asked questions
How do I back up a step-ca authority?
Copy ~/.step with the service stopped including password files. The keys inside sign every certificate. Losing them forces full reissuance.
Where does step store client certs?
Wherever step CLI writes them on issue, commonly the current folder or named paths. Authority keys stay server side in .step. Client defaults differ per command.
Notice an outdated path? Let us know.