如何修改Ansible脚本使生成的SSH密钥兼容Java 8和Java 17?
解决Ansible生成SSH密钥兼容Java 8和Java 17的问题
问题核心是你当前用cipher: auto生成的私钥默认采用AES-256加密,而Java 8对这种加密格式的私钥存在兼容性问题。要让密钥同时兼容两个Java版本,只需修改Ansible脚本中私钥生成的加密算法为Triple DES(DES-EDE3),对应OpenSSL中的des3 cipher。
修改后的完整Ansible脚本
--- - name: Generate SSH key with passphrase and set permissions hosts: localhost connection: local vars: ssh_private_key_filepath: "{{ ssh_private_key_filepath }}" ssh_public_key_filepath: "{{ ssh_public_key_filepath }}" ssh_passphrase: "{{ ssh_passphrase }}" tasks: - name: Generate private key with Triple DES encryption (compatible with Java 8/17) community.crypto.openssl_privatekey: path: "{{ ssh_private_key_filepath }}" type: RSA size: 4096 passphrase: "{{ ssh_passphrase }}" cipher: des3 # 替换原auto配置,指定用Triple DES加密 state: present force: false register: private_key - name: Generate public key community.crypto.openssl_publickey: path: "{{ ssh_public_key_filepath }}" privatekey_path: "{{ ssh_private_key_filepath }}" privatekey_passphrase: "{{ ssh_passphrase }}" state: present force: false format: "OpenSSH" when: private_key.changed - name: Set permissions for private key file: path: "{{ ssh_private_key_filepath }}" mode: '400' - name: Set permissions for public key file: path: "{{ ssh_public_key_filepath }}" mode: '600'
关键说明
cipher: des3:明确指定使用Triple DES加密私钥,这是Java 8原生支持的算法,同时完全兼容Java 17- 若已生成过AES-256加密的旧密钥,需将
force: false改为force: true(或手动删除旧密钥文件),否则Ansible不会重新生成密钥 - 保持密钥权限设置不变,SSH对私钥权限(400)和公钥权限(600)的要求是硬性标准,否则会导致密钥无法使用
内容的提问来源于stack exchange,提问作者Nish
相关产品推荐
相关产品推荐

