# step-ca config sketch — internal CA for aws-posture Roles Anywhere leaf certs Design ref: `docs/r720-agent-team-design.md` §6.3 (step-ca + Roles Anywhere, D5) and §7 Phase 3. **Not provisioned here.** This is the config + renewal approach for the GPT-4.1 cross-review. step-ca is the small internal CA on the R720 box (Smallstep `step-ca`) whose **root** cert is pinned as the Roles Anywhere trust anchor, and which issues a **short-lived leaf** that the box presents to Roles Anywhere to obtain short-lived read-only STS credentials. **No long-lived AWS key ever lands on the box** — the leaf self-expires and is auto-renewed by a systemd timer. ## Trust chain (one CA, one purpose) ``` step-ca ROOT (offline-ish, long-lived) └── step-ca intermediate (the online signer) └── leaf CN=r720-aws-posture (short-lived, ~24h, auto-renewed) └── presented to AWS IAM Roles Anywhere trust anchor └── AssumeRole -> r720-aws-posture-readonly (1h STS session) ``` The trust anchor pins the **root** cert (`roles-anywhere-config.json` → `sourceData .x509CertificateData`). The role trust policy (`aws-posture-trust-policy.json`) additionally pins the leaf **subject CN** (`r720-aws-posture`) and **issuer CN**, so only this CA's leaf with this exact CN can assume the role. ## `ca.json` (sketch — the single-purpose provisioner) ```jsonc { "root": "/etc/step-ca/certs/root_ca.crt", "crt": "/etc/step-ca/certs/intermediate_ca.crt", "key": "/etc/step-ca/secrets/intermediate_ca_key", "address": "127.0.0.1:8443", // localhost-only; the box is the sole client "dnsNames": ["localhost", "r720.lan"], "authority": { "claims": { "minTLSCertDuration": "5m", "maxTLSCertDuration": "24h", // hard cap: leaves are short-lived "defaultTLSCertDuration": "24h", "disableRenewal": false }, "provisioners": [ { "type": "JWK", "name": "aws-posture", "key": { "use": "sig", "kty": "EC", "crv": "P-256", "alg": "ES256", "kid": "REPLACE", "x": "REPLACE", "y": "REPLACE" }, "encryptedKey": "REPLACE_WITH_ENCRYPTED_PROVISIONER_KEY", "claims": { "maxTLSCertDuration": "24h", "defaultTLSCertDuration": "24h" }, "options": { "x509": { // The provisioner only ever issues this one CN; templating keeps the // subject/issuer fields the Roles Anywhere trust policy pins. "templateData": { "CommonName": "r720-aws-posture" } } } } ] } } ``` Root CA subject CN: **`Sea Haven Internal CA - R720 Roles Anywhere`** (matches the `x509Issuer/CN` condition in `aws-posture-trust-policy.json`). ## Initial bootstrap (one-time, at provisioning) ```bash step ca init \ --name "Sea Haven Internal CA - R720 Roles Anywhere" \ --dns localhost --dns r720.lan --address 127.0.0.1:8443 \ --provisioner aws-posture --deployment-type standalone # Issue the first leaf the box will present to Roles Anywhere: step ca certificate "r720-aws-posture" \ /etc/aws-posture/leaf.crt /etc/aws-posture/leaf.key \ --not-after 24h --provisioner aws-posture ``` `leaf.key` is mode 600, owned by the unattended service user; it never leaves the box. ## Auto-renewal — systemd timer (the leaf self-expires; the timer keeps it fresh) `step-ca` ships `step ca renew`, which no-ops until the cert is within its renewal window. `/etc/systemd/system/aws-posture-cert-renew.service`: ```ini [Unit] Description=Renew r720-aws-posture Roles Anywhere leaf certificate After=network-online.target step-ca.service [Service] Type=oneshot User=aws-posture # --expires-in: renew only when <8h of life remains; idempotent, safe to run hourly. ExecStart=/usr/bin/step ca renew --force --expires-in 8h \ /etc/aws-posture/leaf.crt /etc/aws-posture/leaf.key # step-ca renew rewrites the cert in place; aws_signing_helper reads it fresh each call, # so no service reload is needed. ``` `/etc/systemd/system/aws-posture-cert-renew.timer`: ```ini [Unit] Description=Hourly renewal check for the aws-posture leaf cert [Timer] OnCalendar=hourly RandomizedDelaySec=300 Persistent=true # catch up a renewal missed while the box was off [Install] WantedBy=timers.target ``` Hourly check + 8h renewal window + 24h cert = the leaf is always fresh and a missed window has hours of slack. The timer mirrors the existing secrev launchd/systemd discipline. ## How aws-posture USES the leaf (no AWS key on disk) aws-posture invokes AWS's `aws_signing_helper credential-process`, which signs the Roles Anywhere request with the **leaf** and returns short-lived STS creds on stdout: ```ini # ~/.aws/config (on the box) [profile r720-aws-posture] credential_process = /usr/local/bin/aws_signing_helper credential-process \ --certificate /etc/aws-posture/leaf.crt \ --private-key /etc/aws-posture/leaf.key \ --trust-anchor-arn arn:aws:rolesanywhere:us-east-1:328440206208:trust-anchor/REPLACE \ --profile-arn arn:aws:rolesanywhere:us-east-1:328440206208:profile/REPLACE \ --role-arn arn:aws:iam::328440206208:role/r720-aws-posture-readonly ``` The credentials live only in process memory for the 1h session duration; nothing long-lived is written. This is **strictly stronger than the box's existing long-lived GitHub PAT** (design §6.3): the AWS identity self-expires and rotates without operator action. ## Capacity note (design §6.5) step-ca on a 4GB / 2 vCPU / 40GB box is negligible (a localhost signer + a tiny DB). Re-check disk headroom after Phase 1 per §6.5; snapshot the Hyper-V VM before standing this up per `feedback_ec2_replacement_snapshot`.