Hyperledger Fabric多Consenter加入通道时重复节点错误排查
问题原因排查
错误提示duplicate consenter的核心原因是configtx.yaml中所有EtcdRaft Consenter节点的ClientTLSCert和ServerTLSCert都配置成了同一个TLS CA根证书,而非每个Orderer节点自身的TLS签名证书。Fabric通过证书唯一识别Consenter节点,所有节点使用相同证书会被判定为同一个节点,因此多节点配置时触发重复检测错误。
解决方法
1. 修正configtx.yaml的Consenter配置
找到OrdererDefaults.EtcdRaft.Consenters和Profiles.ChannelUsingRaft.Orderer.EtcdRaft.Consenters部分,将每个节点的ClientTLSCert和ServerTLSCert替换为对应Orderer自己的TLS签名证书路径(通常在msp/signcerts目录下)。
修改后的示例片段:
EtcdRaft: Consenters: - Host: orderer1-org Port: 7050 ClientTLSCert: ca-tls/orderer1-org/msp/signcerts/cert.pem ServerTLSCert: ca-tls/orderer1-org/msp/signcerts/cert.pem - Host: orderer2-org Port: 7050 ClientTLSCert: ca-tls/orderer2-org/msp/signcerts/cert.pem ServerTLSCert: ca-tls/orderer2-org/msp/signcerts/cert.pem - Host: orderer3-org Port: 7050 ClientTLSCert: ca-tls/orderer3-org/msp/signcerts/cert.pem ServerTLSCert: ca-tls/orderer3-org/msp/signcerts/cert.pem
注:
Profiles下的对应配置也需要同步修改,保持和OrdererDefaults一致。
2. 重新生成通道创世块
删除旧的创世块文件,使用修正后的configtx.yaml重新生成:
configtxgen -profile ChannelUsingRaft -outputBlock /tmp/hyperledger/fabric-ca/crypto/mychannel.block -channelID mychannel
3. 重新执行通道加入命令
使用新生成的创世块,依次对每个Orderer节点执行osnadmin channel join命令(注意替换每个命令中的-o参数为对应Orderer的admin地址):
# 加入orderer1 osnadmin channel join --channelID mychannel --config-block /tmp/hyperledger/fabric-ca/crypto/mychannel.block -o orderer1-org:10443 \ --ca-file /path/crypto/ca-tls/tls-root-cert/tls-ca-cert.pem --client-cert /path/crypto/ca-tls/osnadmin1-org/msp/signcerts/cert.pem --client-key /path/crypto/ca-tls/osnadmin1-org/msp/keystore/key.pem # 加入orderer2 osnadmin channel join --channelID mychannel --config-block /tmp/hyperledger/fabric-ca/crypto/mychannel.block -o orderer2-org:10443 \ --ca-file /path/crypto/ca-tls/tls-root-cert/tls-ca-cert.pem --client-cert /path/crypto/ca-tls/osnadmin2-org/msp/signcerts/cert.pem --client-key /path/crypto/ca-tls/osnadmin2-org/msp/keystore/key.pem # 加入orderer3 osnadmin channel join --channelID mychannel --config-block /tmp/hyperledger/fabric-ca/crypto/mychannel.block -o orderer3-org:10443 \ --ca-file /path/crypto/ca-tls/tls-root-cert/tls-ca-cert.pem --client-cert /path/crypto/ca-tls/osnadmin3-org/msp/signcerts/cert.pem --client-key /path/crypto/ca-tls/osnadmin3-org/msp/keystore/key.pem
内容的提问来源于stack exchange,提问作者Ivan
相关产品推荐
相关产品推荐

