3.2 KiB
Janus
Generate passwords:
mkdir -p /tmp/janus-step-ca-bootstrap && chmod 700 /tmp/janus-step-ca-bootstrap && cd /tmp/janus-step-ca-bootstrap && umask 077 && openssl rand -base64 48 > ca_password.txt && openssl rand -base64 48 > admin_jwk_password.txt
Bootstrap CA materials with SSH enabled:
STEPPATH=/tmp/janus-step-ca-bootstrap/step step ca init --name Janus --dns janus.john-stream.com --dns 192.168.1.244 --address :443 --provisioner admin --password-file /tmp/janus-step-ca-bootstrap/ca_password.txt --provisioner-password-file /tmp/janus-step-ca-bootstrap/admin_jwk_password.txt --ssh --deployment-type standalone --with-ca-url https://janus.john-stream.com
Insert generated runtime CA material into modules/hosts/janus/secrets.yaml under janus:
/tmp/janus-step-ca-bootstrap/ca_password.txt->ca_password/tmp/janus-step-ca-bootstrap/step/secrets/intermediate_ca_key->intermediate_ca_key/tmp/janus-step-ca-bootstrap/step/secrets/ssh_host_ca_key->ssh_host_ca_key/tmp/janus-step-ca-bootstrap/step/secrets/ssh_user_ca_key->ssh_user_ca_key/tmp/janus-step-ca-bootstrap/step/config/ca.json->admin_provisioner_encrypted_key(copyauthority.provisioners[].encryptedKeyfor theadminJWK provisioner)
If you are only validating wiring first, admin_provisioner_encrypted_key can be an encrypted placeholder and replaced later.
If rotating provisioner password, also set:
/tmp/janus-step-ca-bootstrap/admin_jwk_password.txt->janus.admin_jwkinkeys/secrets.yaml
Secret source-of-truth after this split:
modules/hosts/janus/secrets.yaml: Janus runtime CA secrets (ca_password,intermediate_ca_key,ssh_host_ca_key,ssh_user_ca_key,admin_provisioner_encrypted_key)keys/secrets.yaml: shared Janus provisioner secret (janus.admin_jwk) consumed bystep-ssh-hostacross hosts
Then update public artifacts in repo from generated output:
modules/hosts/janus/root_ca.crtfrom/tmp/janus-step-ca-bootstrap/step/certs/root_ca.crtmodules/hosts/janus/intermediate_ca.crtfrom/tmp/janus-step-ca-bootstrap/step/certs/intermediate_ca.crt(public certificate; intentionally committed, not stored in SOPS)modules/hosts/janus/fingerprintfrom:step certificate fingerprint /tmp/janus-step-ca-bootstrap/step/certs/root_ca.crtmodules/hosts/janus/ssh_user_ca_key.pubfrom/tmp/janus-step-ca-bootstrap/step/certs/ssh_user_ca_key.pub
Back up the root CA key offline
The root CA private key is not deployed and is never needed by the running CA.
It is only used to sign/rotate intermediates. Store it offline (e.g. 1Password)
before wiping the bootstrap directory, otherwise intermediate rotation becomes
impossible and any future rotation forces a full root rotation (redistributing
root_ca.crt + fingerprint to every client).
Back up, then wipe the bootstrap material:
/tmp/janus-step-ca-bootstrap/step/secrets/root_ca_key-> offline secret store/tmp/janus-step-ca-bootstrap/ca_password.txt-> offline secret store (root/intermediate key password)
shred -u /tmp/janus-step-ca-bootstrap/step/secrets/root_ca_key 2>/dev/null || true
rm -rf /tmp/janus-step-ca-bootstrap