If blocked by default, you will need to whitelist the following smallstep domains in order for the hosts and bastion hosts to renew certificates with your SAAS CA:


api.smallstep.com
ssh.<your_team>.ca.smallstep.com

additionally if you are running the smallstep host quickstart  to register servers you will need to whitelist:


https://files.smallstep.com/