You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求助:Ansible对接InCommon/Sectigo ACME配置EAB及无挑战证书

使用Ansible结合Sectigo/InCommon ACME服务(带EAB和无挑战)的问题

我正在编写可运行的Ansible Playbook,希望通过ACME协议、InCommon/Sectigo的**外部账户绑定(EAB)**以及「无挑战」选项生成SSL证书,但始终无法成功。很多网站(包括厂商)都声称该方案可行,但没有提供可用的示例。

根据Ansible官方文档:

目前ACME模块仅由开发者针对Let's Encrypt、Buypass、ZeroSSL及Pebble测试服务器完成测试。我们收到社区反馈,这些模块也可用于InCommon的Sectigo ACME服务。若您在其他ACME服务器上遇到问题……

我参考了Ansible Galaxy上的acme_certificate和acme_account模块文档。

请问有没有人成功使用Ansible Playbook结合community.crypto.acme*模块,与Sectigo/InCommon ACME服务交互,提交CSR并生成SSL证书?

核心障碍:EAB集成问题

1. acme_certificate模块不支持EAB参数

调用community.crypto.acme_certificate时使用external_account_binding参数会直接报错,提示该参数不被支持,错误信息如下:

"msg": "Unsupported parameters for (community.crypto.acme_certificate) module: external_account_binding. Supported parameters include: account_email, account_key_content, account_key_passphrase, account_key_src, account_uri, acme_directory, acme_version, agreement, chain_dest, challenge, csr, csr_content, data, deactivate_authzs, dest, force, fullchain_dest, modify_account, remaining_days, request_timeout, retrieve_all_alternates, select_chain, select_crypto_backend, terms_agreed, validate_certs (account_key, cert, chain, fullchain, src)."

2. acme_account模块的账户密钥获取困惑

只有community.crypto.acme_account模块支持EAB,但该模块的account_key_content参数要求传入「ACME账户RSA或椭圆曲线密钥内容」。我在Sectigo的ACME账户GUI中找不到这个密钥,也没有资料说明如何获取或生成它。尝试传入待生成证书的私钥,执行时报错:

TASK [Get Account URI] *********************************************************
fatal: [localhost]: FAILED! => {"changed": false, "msg": "Account does not exist or is deactivated.", "other": {}}

我的非工作Playbook代码

- name: Get Account URI
  community.crypto.acme_account:
    account_key_content: "{{ cert_privatekey }}"
    acme_directory: "{{ acme_url }}"
    acme_version: "{{ acme_version }}"
    allow_creation: false
    state: present
    external_account_binding:
      alg: HS256
      key: "{{ acme_hmac_key }}"
      kid: "{{ acme_account_id }}"
  register: the_account_uri

# DEBUG: Output the_account_uri?
- name: Output the_account_uri?
  ansible.builtin.debug:
    msg: "{{ the_account_uri }}"


- name: Create a challenge for sample.com using a account key file
  community.crypto.acme_certificate:
    account_key_content: "{{ cert_privatekey }}"
    csr_content: "{{ cert_csr }}"
    account_email: "{{ acme_account_email }}"
    acme_version: "{{ acme_version }}"
    acme_directory: "{{ acme_url }}"
    remaining_days: "{{ cert_term_length }}"
    dest: "/var/tmp/{{ cert_filename }}"
    challenge: no challenge
  register: acme_no_challenge
  no_log: false

# DEBUG: Output challenge?
- name: Output challenge?
  ansible.builtin.debug:
    msg: "{{ acme_no_challenge }}"

- name: Retrieve the cert and intermediate certificate
  community.crypto.acme_certificate:
    account_key_content: "{{ cert_privatekey }}"
    csr_content: "{{ cert_csr }}"
    account_email: "{{ acme_account_email }}"
    acme_version: "{{ acme_version }}"
    challenge: no challenge
    data: "{{ acme_no_challenge }}"
    acme_directory: "{{ acme_url }}"
    remaining_days: "{{ cert_term_length }}"
    dest: "/var/tmp/{{ cert_filename }}"
    chain_dest: "{{ chain_filename }}"
    fullchain_dest: "{{ full_chain_filename }}"
  when: acme_no_challenge is changed
  no_log: false

内容的提问来源于stack exchange,提问作者jewettg

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 09:15:27