在GitHub Actions中自动输入yes确认EasyRSA证书签名请求
当前在GitHub Actions搭建EasyRSA证书生成CI/CD流水线时,执行build-client-full命令触发交互确认提示,导致流水线自动执行失败,报错内容如下:
You are about to sign the following certificate.
Please check over the details shown below for accuracy. Note that this request
has not been cryptographically verified. Please be sure it came from a trusted
source or that you have verified the request checksum with the sender.Request subject, to be signed as a client certificate for 825 days:
subject=
commonName = joni.lehtoType the word 'yes' to continue, or any other input to abort.
Confirm request details:Notice
Aborting without confirmation.
当前使用的YAML步骤配置:
- name: Creating Client Certificate and key run: | sudo su - cd easyrsa3 yes | ./easyrsa --passout=file:pki/file.txt build-client-full ${{ github.event.inputs.username }}
解决方案
EasyRSA自带非交互模式参数,直接在命令中添加--batch并指定nopass即可跳过所有交互确认:
修改后的YAML配置:
- name: Creating Client Certificate and key run: | cd easyrsa3 ./easyrsa --batch --passout=file:pki/file.txt build-client-full ${{ github.event.inputs.username }} nopass
参数说明
--batch:强制EasyRSA以非交互模式运行,自动确认所有需要手动输入的步骤(包括签名确认环节)nopass:指定生成的客户端证书不设置密码,避免额外的密码输入交互- 移除
sudo su -:该命令会切换到root用户并重置工作目录,可能导致找不到easyrsa3路径,建议直接在当前环境执行命令
内容的提问来源于stack exchange,提问作者learner

