You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何修改Ansible脚本使生成的SSH密钥兼容Java 8和Java 17?

解决Ansible生成SSH密钥兼容Java 8和Java 17的问题

问题核心是你当前用cipher: auto生成的私钥默认采用AES-256加密,而Java 8对这种加密格式的私钥存在兼容性问题。要让密钥同时兼容两个Java版本,只需修改Ansible脚本中私钥生成的加密算法为Triple DES(DES-EDE3),对应OpenSSL中的des3 cipher。

修改后的完整Ansible脚本

---
- name: Generate SSH key with passphrase and set permissions
  hosts: localhost
  connection: local
  vars:
    ssh_private_key_filepath: "{{ ssh_private_key_filepath }}"
    ssh_public_key_filepath: "{{ ssh_public_key_filepath }}"
    ssh_passphrase: "{{ ssh_passphrase }}"
  tasks:
    - name: Generate private key with Triple DES encryption (compatible with Java 8/17)
      community.crypto.openssl_privatekey:
        path: "{{ ssh_private_key_filepath }}"
        type: RSA
        size: 4096
        passphrase: "{{ ssh_passphrase }}"
        cipher: des3  # 替换原auto配置,指定用Triple DES加密
        state: present
        force: false
      register: private_key

    - name: Generate public key
      community.crypto.openssl_publickey:
        path: "{{ ssh_public_key_filepath }}"
        privatekey_path: "{{ ssh_private_key_filepath }}"
        privatekey_passphrase: "{{ ssh_passphrase }}"
        state: present
        force: false
        format: "OpenSSH"
      when: private_key.changed

    - name: Set permissions for private key
      file:
        path: "{{ ssh_private_key_filepath }}"
        mode: '400'

    - name: Set permissions for public key
      file:
        path: "{{ ssh_public_key_filepath }}"
        mode: '600'

关键说明

  • cipher: des3:明确指定使用Triple DES加密私钥,这是Java 8原生支持的算法,同时完全兼容Java 17
  • 若已生成过AES-256加密的旧密钥,需将force: false改为force: true(或手动删除旧密钥文件),否则Ansible不会重新生成密钥
  • 保持密钥权限设置不变,SSH对私钥权限(400)和公钥权限(600)的要求是硬性标准,否则会导致密钥无法使用

内容的提问来源于stack exchange,提问作者Nish

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 19:07:26