Skip to content

Difference between "step ca roots" and "step ca federation"? #1836

Answered by hslatman
rwv37 asked this question in Q&A
Discussion options

You must be logged in to vote

@rwv37 I agree that look very similar, and I can imagine putting the "other CAs to be federated" under the roots might work for some use cases, so I think it's mainly to explicitly designate they're used for the specific purpose of federation. The roots that are configured are used in several places in the CA (e.g. for bootstrapping trust, used as trusted client CA certificate, etc), whereas the certificates configured as federated are used only to be able to distribute them to clients and servers in need of those trust bundles (in addition to the single root CA they would usually need). The release blog post explains it with an example of a web server that adds the federated roots as tru…

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@hslatman
Comment options

Answer selected by rwv37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants