Certificate Authorities
Available

Smallstep Integration

TigerTrust integrates with Smallstep step-ca for modern private PKI management. Leverage Smallstep for zero-trust certificate management with TigerTrust automation and monitoring.

Key Features

step-ca Integration
ACME Protocol
OIDC Provisioners
SSH Certificates
Short-Lived Certs
Device Attestation
Cloud Hosted
Self-Hosted

Benefits

Modern PKI with Smallstep and TigerTrust
Zero-trust certificate management
Multiple provisioner support
SSH certificate automation
Enhanced visibility and compliance
Use cases

What teams build with this integration

Common scenarios platform, security, and SRE teams solve after connecting Smallstep.

01Scenario

Zero-trust infrastructure

02Scenario

SSH certificate management

03Scenario

Service mesh certificates

04Scenario

DevOps certificate automation

Smallstep Integration with TigerTrust

TigerTrust integrates with Smallstep step-ca for modern, zero-trust private PKI management.

Why Smallstep?

Smallstep provides modern PKI:

  • Zero Trust: Short-lived certificates
  • Multiple Provisioners: ACME, OIDC, JWK, and more
  • SSH Certificates: X.509 and SSH from one CA
  • Modern Design: Built for cloud-native

Integration Configuration

Configure Smallstep with:

  • CA URL and root certificate
  • Provisioner type (ACME, OIDC, JWK, etc.)
  • Auto-renewal settings at percentage of lifetime
  • Default and maximum certificate duration

Provisioner Support

ProvisionerDescription
ACMEStandard ACME protocol
OIDCOAuth/OIDC identity federation
JWKJSON Web Key authentication
X5CX.509 certificate authentication
K8sSAKubernetes ServiceAccount tokens
SSHPOPSSH Proof-of-Possession
CloudCloud instance identity (AWS, GCP, Azure)

Certificate Issuance

ACME Provisioner: Standard ACME protocol with DNS-01 challenges.

OIDC Provisioner: OAuth/OIDC-based issuance using identity providers like Google.

SSH Certificates

Smallstep SSH certificate support:

  • Host certificates with principal configuration
  • User certificates with claims-based principals
  • Configurable certificate duration

Kubernetes Integration

cert-manager Issuer: Use Smallstep as a cert-manager StepClusterIssuer for native Kubernetes certificate management.

Short-Lived Certificates

Configure automated rotation:

  • Default duration (e.g., 1 hour)
  • Maximum duration (e.g., 24 hours)
  • Auto-renewal at threshold (e.g., 66% of lifetime)

Getting Started

  1. Deploy step-ca: Self-hosted or Smallstep hosted
  2. Configure Provisioners: Set up ACME, OIDC, etc.
  3. Add Integration: Configure Smallstep in TigerTrust
  4. Enable Automation: Start certificate management
  5. Monitor: Track certificates and renewals

TigerTrust's Smallstep integration enables zero-trust infrastructure with modern PKI practices and comprehensive visibility.

Getting Started

1

Deploy or configure Smallstep step-ca

2

Set up provisioners (ACME, OIDC, JWK)

3

Configure TigerTrust integration

4

Enable certificate policies

5

Set up monitoring

Ready to Integrate Smallstep?

Get started with TigerTrust and automate your certificate lifecycle management today.