- Sign data from an OpenSSL command task.
- Authenticate Ansible’s SSH connection plugin to a managed host.
Generate the CryptoHub key
1
Set the client-library configuration path and open the endpoint-provided
manager:Initialize the module and log in with the endpoint UserPass password.
2
Generate an RSA-2048 key named
ansible_rsa_privatekey.The template creates the key as TRUSTED with Sign and Verify usages. Both
procedures below use this single RSA usage class.3
Install OpenSC, export the public key, and convert it to PEM:The PEM file contains only the public key. The private key remains in
CryptoHub.
Sign data from a playbook
1
Read the PKCS #11 token label from the endpoint configuration:Use the returned label for
<token-label> in the next step.2
Create
sign.yml:3
Run the playbook:The Verify the signature task reports
ok, the assertion reports
All assertions passed, and the play recap reports failed=0.Authenticate Ansible SSH with the CryptoHub key
Ansible Core 2.12 and later provides theansible_ssh_pkcs11_provider connection option. The plugin uses sshpass to
supply the PKCS #11 PIN through a protected input pipe.
1
Install
sshpass and convert the public key to OpenSSH format:sshpass -V must report version 1.06 or later.2
Add
ansible-public.ssh to the target account’s
~/.ssh/authorized_keys.The target account now trusts the public half of the CryptoHub key.3
Create a protected variable file. The command reads the endpoint UserPass
password without echoing it and JSON-encodes the value as valid YAML:Encrypt this variable with Ansible Vault or supply it from your approved
controller credential store when your policy requires encrypted secrets at
rest.
4
Create Do not add
inventory.ini. Replace <target-host> and <target-user>:IdentitiesOnly=yes. That option prevents OpenSSH from trying keys
enumerated through the PKCS #11 provider.5
Create
ssh.yml:6
Set Set this variable in the controller shell, not the playbook
CHLIBS_CONFIG in the controller shell and run the playbook:environment:
block. The Ansible environment keyword applies to remote tasks, not the SSH
connection plugin.A successful run prints the target hostname and reports unreachable=0 and
failed=0.Troubleshoot the validation
No configuration file found: exportCHLIBS_CONFIGin the process that loads the module.operation not supported for this keytypefromopenssl dgst: confirm thatOPENSSL_CONFloadspkcs11-provider1.2.0 instead of the Ubuntu 24.04 distribution’s 0.3 provider.to use pkcs11_provider you must specify a password/pin: load the endpoint UserPass password from the protected Ansible variable source.Permission denied (publickey)after OpenSSH enumerates the matching key: confirm that the public key is inauthorized_keysand removeIdentitiesOnly=yesfrom the SSH arguments.

