求助:Ansible对接InCommon/Sectigo ACME配置EAB及无挑战证书
使用Ansible结合Sectigo/InCommon ACME服务(带EAB和无挑战)的问题
我正在编写可运行的Ansible Playbook,希望通过ACME协议、InCommon/Sectigo的**外部账户绑定(EAB)**以及「无挑战」选项生成SSL证书,但始终无法成功。很多网站(包括厂商)都声称该方案可行,但没有提供可用的示例。
根据Ansible官方文档:
目前ACME模块仅由开发者针对Let's Encrypt、Buypass、ZeroSSL及Pebble测试服务器完成测试。我们收到社区反馈,这些模块也可用于InCommon的Sectigo ACME服务。若您在其他ACME服务器上遇到问题……
我参考了Ansible Galaxy上的acme_certificate和acme_account模块文档。
请问有没有人成功使用Ansible Playbook结合community.crypto.acme*模块,与Sectigo/InCommon ACME服务交互,提交CSR并生成SSL证书?
核心障碍:EAB集成问题
1. acme_certificate模块不支持EAB参数
调用community.crypto.acme_certificate时使用external_account_binding参数会直接报错,提示该参数不被支持,错误信息如下:
"msg": "Unsupported parameters for (community.crypto.acme_certificate) module: external_account_binding. Supported parameters include: account_email, account_key_content, account_key_passphrase, account_key_src, account_uri, acme_directory, acme_version, agreement, chain_dest, challenge, csr, csr_content, data, deactivate_authzs, dest, force, fullchain_dest, modify_account, remaining_days, request_timeout, retrieve_all_alternates, select_chain, select_crypto_backend, terms_agreed, validate_certs (account_key, cert, chain, fullchain, src)."
2. acme_account模块的账户密钥获取困惑
只有community.crypto.acme_account模块支持EAB,但该模块的account_key_content参数要求传入「ACME账户RSA或椭圆曲线密钥内容」。我在Sectigo的ACME账户GUI中找不到这个密钥,也没有资料说明如何获取或生成它。尝试传入待生成证书的私钥,执行时报错:
TASK [Get Account URI] ********************************************************* fatal: [localhost]: FAILED! => {"changed": false, "msg": "Account does not exist or is deactivated.", "other": {}}
我的非工作Playbook代码
- name: Get Account URI community.crypto.acme_account: account_key_content: "{{ cert_privatekey }}" acme_directory: "{{ acme_url }}" acme_version: "{{ acme_version }}" allow_creation: false state: present external_account_binding: alg: HS256 key: "{{ acme_hmac_key }}" kid: "{{ acme_account_id }}" register: the_account_uri # DEBUG: Output the_account_uri? - name: Output the_account_uri? ansible.builtin.debug: msg: "{{ the_account_uri }}" - name: Create a challenge for sample.com using a account key file community.crypto.acme_certificate: account_key_content: "{{ cert_privatekey }}" csr_content: "{{ cert_csr }}" account_email: "{{ acme_account_email }}" acme_version: "{{ acme_version }}" acme_directory: "{{ acme_url }}" remaining_days: "{{ cert_term_length }}" dest: "/var/tmp/{{ cert_filename }}" challenge: no challenge register: acme_no_challenge no_log: false # DEBUG: Output challenge? - name: Output challenge? ansible.builtin.debug: msg: "{{ acme_no_challenge }}" - name: Retrieve the cert and intermediate certificate community.crypto.acme_certificate: account_key_content: "{{ cert_privatekey }}" csr_content: "{{ cert_csr }}" account_email: "{{ acme_account_email }}" acme_version: "{{ acme_version }}" challenge: no challenge data: "{{ acme_no_challenge }}" acme_directory: "{{ acme_url }}" remaining_days: "{{ cert_term_length }}" dest: "/var/tmp/{{ cert_filename }}" chain_dest: "{{ chain_filename }}" fullchain_dest: "{{ full_chain_filename }}" when: acme_no_challenge is changed no_log: false
内容的提问来源于stack exchange,提问作者jewettg
相关产品推荐
相关产品推荐

