Smallstep step-cli对接Google/GitHub OIDC配置器时'exec step oauth'失败
Smallstep step-ca v0.29.0 Google/GitHub OIDC认证报错排查
环境信息
- 运行系统:Ubuntu(Windows Subsystem for Linux 环境)
- 安装来源:Smallstep官方APT仓库
- 版本:step-ca v0.29.0、step-cli v0.29.0
- CA状态:本地运行,健康检查与配置器端点正常,
step ca provisioner list可正常列出配置器
CA配置(ca.json中的OIDC配置器)
{ "type": "OIDC", "name": "google", "clientID": "<my-google-client-id>", "clientSecret": "<my-google-client-secret>", "claims": { "enableSSHCA": true } }, { "type": "OIDC", "name": "github", "clientID": "<my-github-client-id>", "clientSecret": "<my-github-client-secret>", "claims": { "enableSSHCA": true } }
问题现象
执行以下命令时出现报错:
命令1
step ssh certificate <user> id_ecdsa_google --provisioner google
命令2
step ca token <user> --provisioner google --ca-url https://localhost:9000 --root /etc/step-ca/certs/root_ca.crt
错误输出(两种命令对应类似错误)
✔ Provisioner: github (OIDC) [client: <ID>] use a valid provider: google or github error generating OIDC token: exec "step oauth" failed
或
✔ Provisioner: google (OIDC) [client: <ID>] use a valid provider: google or github error generating OIDC token: exec "step oauth" failed
补充信息
- 此前使用Azure AD(Entra)OIDC配置器的相同流程可正常工作
- 系统中无单独
step-oauth二进制文件,step oauth子命令可用(执行step help oauth显示正常) - CA运行在WSL用户环境中,怀疑可能影响OIDC浏览器跳转或网络连通性
疑问
- 该错误的具体原因是什么?
- 在step-cli v0.29中使用Google/GitHub OIDC是否需要额外依赖、配置或临时解决方案?
- 是否为当前版本(v0.29.0)的已知Bug?
求相关建议或经验分享。
内容的提问来源于stack exchange,提问作者Peter
相关产品推荐
相关产品推荐

