You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Bash脚本通过EOF执行yubikey-luks-enroll时卡住问题求助

解决Yubikey-LUKS自动化注册卡住的问题

问题原因

yubikey-luks-enroll为了安全性,不会从标准输入(stdin)读取密码,而是直接打开终端设备(/dev/tty)获取用户输入。你用here document(<<-EOF)传递的内容会被写入stdin,但命令根本不读取这个通道,所以会一直卡在等待终端输入的状态。

解决方案:使用Expect工具自动化交互

Expect是专门处理交互式命令行工具的程序,能模拟用户手动输入的操作,完美适配这类需要终端交互的密码输入场景。

步骤1:安装Expect

sudo apt install expect

步骤2:编写Expect脚本

创建一个名为enroll_yubikey.exp的脚本,内容如下:

#!/usr/bin/expect -f

# 从命令行参数获取变量
set PART [lindex $argv 0]
set DISKPWD [lindex $argv 1]
set PWD1 [lindex $argv 2]
set PWD2 [lindex $argv 3]

# 启动目标命令
spawn sudo yubikey-luks-enroll -d $PART -s 7

# 匹配提示并发送密码
expect "Enter Yubikey challenge password:"
send "$PWD1\r"

expect "Re-enter Yubikey challenge password:"
send "$PWD2\r"

expect "Enter existing LUKS password:"
send "$DISKPWD\r"

# 等待命令执行完成
expect eof

步骤3:执行脚本

  1. 给脚本添加执行权限:
chmod +x enroll_yubikey.exp
  1. 运行脚本,替换对应参数:
./enroll_yubikey.exp /dev/sda3 "你的LUKS分区密码" "Yubikey挑战密码1" "Yubikey挑战密码2"

替代方案:Bash内嵌Expect代码

如果你不想单独维护Expect脚本,可以把逻辑直接嵌入Bash脚本中:

#!/bin/bash
PART="$1"
DISKPWD="$2"
PWD1="$3"
PWD2="$4"

expect << EOF
spawn sudo yubikey-luks-enroll -d $PART -s 7
expect "Enter Yubikey challenge password:"
send "$PWD1\r"
expect "Re-enter Yubikey challenge password:"
send "$PWD2\r"
expect "Enter existing LUKS password:"
send "$DISKPWD\r"
expect eof
EOF

保存为enroll_yubikey.sh,赋予执行权限后即可运行。

注意事项

  • 密码作为命令行参数传递时,会在系统进程列表中短暂可见,若对安全性要求极高,可修改脚本从加密文件或环境变量读取密码。
  • 确保运行脚本时Yubikey已插入设备且被系统正常识别。

内容的提问来源于stack exchange,提问作者133U

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 00:05:32