使用PKCS7 RSA加密传递Puppet令牌时遇“输入过大”错误求助
Puppet Hiera-Eyaml PKCS7解密报错:input too large for RSA cipher 的解决方案
问题场景
单台服务器部署两台虚拟机(Puppet Master和Agent),采用PKCS7 RSA加密方式通过控制仓库的.eyaml文件存储加密令牌。此前流程正常,近期执行r10k deploy environment production -pv同步代码后,Master端执行puppet agent -t --no-noop成功,但Agent端执行相同命令时触发以下错误:
Info: Using environment 'production' Info: Retrieving pluginfacts Info: Retrieving plugin Info: Loading facts Error: Could not retrieve catalog from remote server: Error 500 on SERVER: Server Error: hiera-eyaml backend error decrypting ENC[PKCS7,<Encyption here>Sc=] when looking up letsencrypt::plugin::dns_cloudflare::api_token in /etc/puppetlabs/code/environments/production/data/secrets/nodes/example.example.com.eyaml. Error was input too large for RSA cipher. on node example.example.com
解决方案
1. 排查加密值长度超限问题
RSA加密存在明文长度限制:2048位RSA密钥的最大可加密明文长度约为245字节(UTF-8编码),若加密的令牌长度超过该阈值,会触发input too large for RSA cipher错误。
- 验证方式:提取待加密的明文令牌,通过
echo -n "你的令牌内容" | wc -c计算字节数,确认是否超过密钥对应的长度限制。 - 修复操作:
- 若令牌过长,使用hiera-eyaml默认流程重新加密(无需手动指定密钥参数),工具会自动采用「对称加密令牌 + RSA加密对称密钥」的方式规避长度限制:
/opt/puppetlabs/puppet/bin/eyaml encrypt -l 'letsencrypt::plugin::dns_cloudflare::api_token' -s '你的长令牌内容' - 将新生成的加密串替换
.eyaml文件中的旧值,重新同步代码后测试。
- 若令牌过长,使用hiera-eyaml默认流程重新加密(无需手动指定密钥参数),工具会自动采用「对称加密令牌 + RSA加密对称密钥」的方式规避长度限制:
2. 验证密钥文件与加密串的一致性
尽管Master端执行正常,仍需确认以下内容:
- 密钥完整性:对比Master上
/etc/puppetlabs/puppet/eyaml/下的公私钥与此前正常运行时的备份,若有变更则恢复原密钥文件。 - 加密串有效性:重新加密令牌并替换
.eyaml中的旧值,避免加密过程中因参数错误生成无效加密串。同时检查加密串格式,确保无多余空格、换行或截断(比如错误信息中的<Encyption here>需替换为完整的加密内容)。 - 密钥权限:验证puppet用户可读取密钥文件:
若无法读取,重新设置权限:su - puppet -c 'cat /etc/puppetlabs/puppet/eyaml/private_key.pkcs7.pem'chown -R puppet:puppet /etc/puppetlabs/puppet/eyaml chmod -R 0500 /etc/puppetlabs/puppet/eyaml chmod 0400 /etc/puppetlabs/puppet/eyaml/*.pem
3. 检查hiera-eyaml配置与版本
- 版本兼容性:查看Master上的hiera-eyaml版本,对比此前正常运行时的版本:
若版本更新后出现问题,可尝试回退至旧版本,或按照新版本要求重新加密令牌。/opt/puppetlabs/puppet/bin/gem list hiera-eyaml - 配置正确性:检查
/etc/puppetlabs/puppet/hiera.yaml中的eyaml后端配置,确保密钥路径正确:--- version: 5 defaults: datadir: data data_hash: yaml_data hierarchy: - name: "Per-node secrets" lookup_key: eyaml_lookup_key paths: - "secrets/nodes/%{trusted.certname}.eyaml" options: pkcs7_private_key: /etc/puppetlabs/puppet/eyaml/private_key.pkcs7.pem pkcs7_public_key: /etc/puppetlabs/puppet/eyaml/public_key.pkcs7.pem
4. 确认r10k部署的文件状态
执行r10k deploy environment production -pv后,验证控制仓库中的.eyaml文件已正确同步至Master的/etc/puppetlabs/code/environments/production/data/secrets/nodes/目录,且内容与本地仓库完全一致,无篡改或格式错误。
内容的提问来源于stack exchange,提问作者Callum McCrorie
相关产品推荐
相关产品推荐

