Certificate Authorities
Available

Smallstep Integration

TigerTrust integrates with Smallstep step-ca for modern private PKI management. Leverage Smallstep for zero-trust certificate management with TigerTrust automation and monitoring.

Key Features

step-ca Integration
ACME Protocol
OIDC Provisioners
SSH Certificates
Short-Lived Certs
Device Attestation
Cloud Hosted
Self-Hosted

Benefits

Modern PKI with Smallstep and TigerTrust
Zero-trust certificate management
Multiple provisioner support
SSH certificate automation
Enhanced visibility and compliance

Common Use Cases

Zero-trust infrastructure

SSH certificate management

Service mesh certificates

DevOps certificate automation

Smallstep Integration with TigerTrust

TigerTrust integrates with Smallstep step-ca for modern, zero-trust private PKI management.

Why Smallstep?

Smallstep provides modern PKI:

  • Zero Trust: Short-lived certificates
  • Multiple Provisioners: ACME, OIDC, JWK, and more
  • SSH Certificates: X.509 and SSH from one CA
  • Modern Design: Built for cloud-native

Integration Configuration

Configure Smallstep with:

  • CA URL and root certificate
  • Provisioner type (ACME, OIDC, JWK, etc.)
  • Auto-renewal settings at percentage of lifetime
  • Default and maximum certificate duration

Provisioner Support

ProvisionerDescription
ACMEStandard ACME protocol
OIDCOAuth/OIDC identity federation
JWKJSON Web Key authentication
X5CX.509 certificate authentication
K8sSAKubernetes ServiceAccount tokens
SSHPOPSSH Proof-of-Possession
CloudCloud instance identity (AWS, GCP, Azure)

Certificate Issuance

ACME Provisioner: Standard ACME protocol with DNS-01 challenges.

OIDC Provisioner: OAuth/OIDC-based issuance using identity providers like Google.

SSH Certificates

Smallstep SSH certificate support:

  • Host certificates with principal configuration
  • User certificates with claims-based principals
  • Configurable certificate duration

Kubernetes Integration

cert-manager Issuer: Use Smallstep as a cert-manager StepClusterIssuer for native Kubernetes certificate management.

Short-Lived Certificates

Configure automated rotation:

  • Default duration (e.g., 1 hour)
  • Maximum duration (e.g., 24 hours)
  • Auto-renewal at threshold (e.g., 66% of lifetime)

Getting Started

  1. Deploy step-ca: Self-hosted or Smallstep hosted
  2. Configure Provisioners: Set up ACME, OIDC, etc.
  3. Add Integration: Configure Smallstep in TigerTrust
  4. Enable Automation: Start certificate management
  5. Monitor: Track certificates and renewals

TigerTrust's Smallstep integration enables zero-trust infrastructure with modern PKI practices and comprehensive visibility.

Getting Started

1

Deploy or configure Smallstep step-ca

2

Set up provisioners (ACME, OIDC, JWK)

3

Configure TigerTrust integration

4

Enable certificate policies

5

Set up monitoring

Ready to Integrate Smallstep?

Get started with TigerTrust and automate your certificate lifecycle management today.