Intermediate CA certificate bootstrap support by LeeFred3042U · Pull Request #2680 · smallstep/certificates · GitHub
Skip to content

Intermediate CA certificate bootstrap support#2680

Open
LeeFred3042U wants to merge 1 commit into
smallstep:masterfrom
LeeFred3042U:feat/bootstrap-intermediate-ca
Open

Intermediate CA certificate bootstrap support#2680
LeeFred3042U wants to merge 1 commit into
smallstep:masterfrom
LeeFred3042U:feat/bootstrap-intermediate-ca

Conversation

@LeeFred3042U

Copy link
Copy Markdown

Extend step ca bootstrap --install to support installing intermediate CA certificates in addition to root certificates.

Fixes #2391

Name of feature:

Intermediate CA certificate bootstrap support

Pain or issue this feature alleviates:

It's a nice to have featur, Win cannot resolve the full certificate chain when only the root CA is installed, causing the certificate viewer to show an incomplete chain, installing the intermediate CA certificate resolves this

Why is this important to the project (if not answered above):

Is there documentation on how to use this feature? If so, where?

No additional documentation required since, the existing step ca bootstrap --fingerprint --install command works the same way, now accepting intermediate CA fingerprints in addition to root CA fingerprints

In what environments or workflows is this feature supported?

Any environment using step ca bootstrap with a custom PKI which is useful on Win where CryptoAPI does not perform AIA chasing during local certificate inspection

In what environments or workflows is this feature explicitly NOT supported (if any)?

Team-based bootstrap, --team flag: fingerprint-based bootstrap only

Supporting links/other PRs/issues:

💔Thank you!

Extend `step ca bootstrap --install` to support installing intermediate CA certificates in addition to root certificates.

Fixes smallstep#2391
@CLAassistant

CLAassistant commented May 14, 2026

Copy link
Copy Markdown

@CLAassistant

Copy link
Copy Markdown

@github-actions github-actions Bot added the needs triage Waiting for discussion / prioritization by team label May 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs triage Waiting for discussion / prioritization by team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Allow step-cli to bootstrap the intermediate_ca certificate

3 participants