You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS AMB HyperLedger Fabric创建通道时策略验证失败求助

AWS Managed Blockchain Hyperledger Fabric创建通道时权限验证失败

问题背景

已在Amazon Managed Blockchain(AMB)上基于HyperLedger Fabric搭建私有网络,完成所有前置配置步骤后,执行创建通道命令时出现权限验证错误。

执行的创建通道命令

[ec2-user@ip-xx-xx-xx-xx ~]$ docker exec cli peer channel create -c mychannel -f /opt/home/mychannel.pb -o orderer.n-xxxxxxxxxxxx.managedblockchain.us-east-1.amazonaws.com:30001 --cafile /opt/home/managedblockchain-tls-chain.pem --tls

错误输出

2025-03-11 14:29:02.157 UTC [channelCmd] InitCmdFactory -> INFO 001 Endorser and orderer connections initialized
Error: got unexpected status: BAD_REQUEST -- error validating channel creation transaction for new channel 'mychannel', could not successfully apply update to template configuration: error authorizing update: error validating DeltaSet: policy for [Group] /Channel/Application not satisfied: implicit policy evaluation failed - 0 sub-policies were satisfied, but this policy requires 1 of the 'Admins' sub-policies to be satisfied

解决方案

该错误根源是通道配置更新未通过/Channel/Application组的Admins策略验证,按以下步骤排查修复:

  • 检查通道配置文件的Admins策略

    1. 将protobuf格式的配置文件转成JSON格式查看:
      docker exec cli configtxlator proto_decode --input /opt/home/mychannel.pb --type common.Config > /opt/home/mychannel_config.json
      
    2. 打开JSON文件,定位到/Channel/Application/Admins节点,确认策略指向的MSP ID是你AMB网络中已创建的组织MSP,且规则为1 of [Admins](符合AMB默认要求)。
  • 确认CLI容器使用管理员身份

    1. 进入CLI容器检查环境变量:
      docker exec -it cli bash
      echo $CORE_PEER_MSPCONFIGPATH
      echo $CORE_PEER_LOCALMSPID
      
    2. 确保CORE_PEER_MSPCONFIGPATH指向组织管理员的MSP目录(如/opt/home/admin-msp),CORE_PEER_LOCALMSPID匹配你的组织MSP ID。若变量错误,重新设置后再执行创建命令:
      export CORE_PEER_MSPCONFIGPATH=/opt/home/admin-msp
      export CORE_PEER_LOCALMSPID="你的组织MSP ID"
      
  • 验证管理员证书有效性
    检查管理员证书是否属于当前组织的管理员身份:

    docker exec cli peer certificate verify -c /opt/home/admin-msp/signcerts/cert.pem -m "你的组织MSP ID"
    

    若证书无效,从AMB控制台重新下载该组织的管理员MSP包,替换CLI容器内对应文件。

  • 确认通道配置文件已正确签名
    若手动生成配置文件,需确保用组织管理员私钥完成签名:

    docker exec cli configtxlator proto_encode --input /opt/home/mychannel_config.json --type common.Config --output /opt/home/mychannel.pb
    docker exec cli peer channel signconfigtx -f /opt/home/mychannel.pb
    

    推荐使用AWS提供的工具生成已签名配置文件,避免手动操作出错。

内容的提问来源于stack exchange,提问作者Vinay Uttekar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 22:47:09