Skip to main content
Validate both supported Ansible paths with one CryptoHub-backed RSA key:
  • Sign data from an OpenSSL command task.
  • Authenticate Ansible’s SSH connection plugin to a managed host.

Generate the CryptoHub key

1
Set the client-library configuration path and open the endpoint-provided manager:
Initialize the module and log in with the endpoint UserPass password.
2
Generate an RSA-2048 key named ansible_rsa_privatekey.The template creates the key as TRUSTED with Sign and Verify usages. Both procedures below use this single RSA usage class.
3
Install OpenSC, export the public key, and convert it to PEM:
The PEM file contains only the public key. The private key remains in CryptoHub.

Sign data from a playbook

1
Read the PKCS #11 token label from the endpoint configuration:
Use the returned label for <token-label> in the next step.
2
Create sign.yml:
3
Run the playbook:
The Verify the signature task reports ok, the assertion reports All assertions passed, and the play recap reports failed=0.

Authenticate Ansible SSH with the CryptoHub key

Ansible Core 2.12 and later provides the ansible_ssh_pkcs11_provider connection option. The plugin uses sshpass to supply the PKCS #11 PIN through a protected input pipe.
1
Install sshpass and convert the public key to OpenSSH format:
sshpass -V must report version 1.06 or later.
2
Add ansible-public.ssh to the target account’s ~/.ssh/authorized_keys.The target account now trusts the public half of the CryptoHub key.
3
Create a protected variable file. The command reads the endpoint UserPass password without echoing it and JSON-encodes the value as valid YAML:
Encrypt this variable with Ansible Vault or supply it from your approved controller credential store when your policy requires encrypted secrets at rest.
4
Create inventory.ini. Replace <target-host> and <target-user>:
Do not add IdentitiesOnly=yes. That option prevents OpenSSH from trying keys enumerated through the PKCS #11 provider.
5
Create ssh.yml:
6
Set CHLIBS_CONFIG in the controller shell and run the playbook:
Set this variable in the controller shell, not the playbook environment: block. The Ansible environment keyword applies to remote tasks, not the SSH connection plugin.A successful run prints the target hostname and reports unreachable=0 and failed=0.

Troubleshoot the validation

  • No configuration file found: export CHLIBS_CONFIG in the process that loads the module.
  • operation not supported for this keytype from openssl dgst: confirm that OPENSSL_CONF loads pkcs11-provider 1.2.0 instead of the Ubuntu 24.04 distribution’s 0.3 provider.
  • to use pkcs11_provider you must specify a password/pin: load the endpoint UserPass password from the protected Ansible variable source.
  • Permission denied (publickey) after OpenSSH enumerates the matching key: confirm that the public key is in authorized_keys and remove IdentitiesOnly=yes from the SSH arguments.