【问题标题】:Copy the ssl certificate from a server to a host in ansible将ssl证书从服务器复制到ansible中的主机
【发布时间】:2021-09-27 02:10:48
【问题描述】:

我正在尝试将本地容器注册表的证书复制到具有 ansible 版本 2.9.6 的 Docker 主机。注册表由其他人管理,但在我们的本地网络中。

使用 shell 我会这样做:

openssl s_client -showcerts -connect registry.example:443 < /dev/null 2> /dev/null | openssl x509 -outform PEM > ca.crt

到目前为止,我在 community.crypto 模块上为 ansible ans 设法获得了证书:

- name: get certificate from registry
  community.crypto.get_certificate:
    host: "{{ registry_url }}"
    port: "{{ registry_port }}"
  delegate_to: localhost
  become: no
  register: cert

这类似于 shell 替代方案的前半部分。我还没有弄清楚如何完成后半部分的工作,即使用从服务器接收到的内容创建证书。

我尝试使用community.crypto.x509_certificate,但我无法让它表现得像下面的shell示例中的openssl_client。

openssl x509 -outform PEM -in server_content_file -text -out ca.crt

有没有办法使用 community.crypto 模块或以任何其他方式使用 ansible 来做到这一点?

【问题讨论】:

    标签: ansible ssl-certificate ansible-galaxy


    【解决方案1】:

    您没有追求的一个选项是在 Ansible 中运行 openssl 命令。以下示例假设您已将 remotehost 变量设置为例如registry.example:

    - hosts: localhost
      gather_facts: false
      tasks:
        - name: get remote certificate
          command: openssl s_client -showcerts -connect {{ remotehost }}
          register: remotecert
    
        - name: extract certificate
          command: openssl x509 -outform PEM
          args:
            stdin: "{{ remotecert.stdout }}"
          register: remotex509
    
        - name: write ca.crt
          copy:
            dest: ./ca.crt
            content: "{{ remotex509.stdout }}"
    

    虽然粒度不那么细,但您当然可以将所有内容组合起来 放入单个 shell 脚本中:

    - hosts: localhost
      gather_facts: false
      tasks:
        - name: get remote certificate
          shell: >-
            openssl s_client -showcerts -connect {{ remotehost }} |
            openssl x509 -outform PEM > ca.crt
          args:
            creates: ca.crt
          register: remotecert
    

    creates 参数将导致任务被跳过,如果目标 文件 (ca.crt) 已存在。

    【讨论】:

    • 感谢您的回答。这就像一个魅力。我想我太专注于使用加密模块了。
    猜你喜欢
    • 2021-01-15
    • 1970-01-01
    • 2020-10-30
    • 1970-01-01
    • 2021-06-23
    • 2019-03-09
    • 1970-01-01
    • 2014-11-07
    • 1970-01-01
    相关资源
    最近更新 更多