You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用IBP创建的Hyperledger Fabric 2.5.3网络注册用户时遇Authorization failure(错误码71)问题求助

Fixing "Authorization failure" (code:71) when registering users in Hyperledger Fabric 2.5.3 (IBP-created network)

Let’s break down why you’re hitting this authorization error when calling caClient.register()—even though your admin can enroll and submit transactions, registering users requires specific permissions and configuration checks that are easy to miss with IBP-setup networks.

Common Causes & Fixes

1. Your admin lacks registrar permissions

Just enrolling an admin doesn’t automatically give it the right to register other users. In Fabric CA, the identity needs the hf.Registrar.Roles attribute to register clients, peers, etc.

  • Check in IBP: Go to your CA node in the IBP console, navigate to the Identities tab, find your admin user, and inspect its attributes. Ensure hf.Registrar.Roles is present and includes client (or * for all roles).
  • Fix: If the attribute is missing, either:
    • Re-enroll using the CA’s bootstrap admin (the default admin account created when you spun up the CA via IBP—this one has full registrar permissions by default), or
    • Edit your existing admin’s attributes in IBP to add hf.Registrar.Roles: client.

2. Missing affiliation in the registration request

IBP-configured CAs typically enforce affiliation constraints (tied to your network’s organizations/ departments). Omitting the affiliation can trigger authorization failures even if your admin has permissions.

  • Adjust your code: Add the affiliation parameter matching your network’s structure (e.g., org1 or org1.department1—check IBP’s CA settings for valid affiliations):
    const secret = await caClient.register(
      {
        enrollmentID: "user",
        role: "client",
        affiliation: "org1" // Replace with your valid affiliation
      },
      adminUser
    );
    

3. Verify CA client and admin identity validity

Double-check that your caClient is pointing to the correct CA endpoint (match the grpcs/grpc URL from IBP’s CA connection profile) and that adminUser is a fully enrolled identity (not just a username/password).

  • Quick debug: Print the admin’s identity details to confirm:
    console.log("Admin MSP ID:", adminUser.getIdentity().getMspId());
    console.log("Admin Attributes:", adminUser.getIdentity().getAttributes());
    
    Ensure the MSP ID matches your organization’s MSP, and attributes include the registrar permissions mentioned earlier.

4. Strict CA registration policies

IBP lets you define custom registration policies for your CA. If the policy blocks your admin from registering client users, you’ll get this error.

  • Check in IBP: Go to your CA node, select the Policies tab, and review the Registration Policy. Ensure there’s no hf.Registrar.Deny rule targeting your admin, and that hf.Registrar.Allow rules permit registering client roles.

Final Notes

If you’re using the official Fabric sample code, remember that IBP networks often have stricter defaults than local test networks—don’t skip checking affiliation and attribute permissions. Start with the bootstrap admin first to rule out permission issues, then adjust your custom admin’s attributes as needed.

内容的提问来源于stack exchange,提问作者Carlos Daniel Ospina Salazar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 14:12:54