从客户端调用Fabric Chaincode遇PEM证书错误求助
解决Fabric客户端调用Chaincode时的"PEM encoded certificate is required"错误
你遇到的问题确实和TLS配置不完整有关——既然peer CLI能正常调用,说明Chaincode和网络本身没问题,问题出在客户端代码缺少TLS证书配置,导致无法和启用了TLS的peer节点建立安全连接。
错误原因分析
当Fabric网络的peer节点启用TLS(这是默认安全配置)时,客户端必须提供TLS根证书来验证peer的身份。你的peer CLI能正常工作,大概率是因为调用时加了--tls=false跳过了TLS验证,或者CLI已经通过环境变量/配置文件自动加载了所需证书,但你的Node.js客户端代码完全没配置TLS相关参数,所以触发了这个错误。
具体修复步骤
你需要在客户端连接选项中添加TLS根证书的配置,以下是修改后的代码示例:
'use strict'; const fs = require('fs'); const yaml = require('js-yaml'); const { FileSystemWallet, Gateway } = require('fabric-network'); const CommercialPaper = require('../chaincode/lib/paper'); // A wallet stores a collection of identities for use const wallet = new FileSystemWallet('../identity/user/isabella/wallet'); async function main() { const gateway = new Gateway(); try { const userName = 'User1@org1.bionic.com'; // Load connection profile; will be used to locate a gateway let connectionProfile = yaml.safeLoad(fs.readFileSync('../gateway/networkConnection.yaml', 'utf8') ); // 加载TLS根证书(路径根据你的crypto-config实际位置调整) const tlsRootCert = fs.readFileSync('../crypto-config/peerOrganizations/org1.bionic.com/peers/peer0.org1.bionic.com/tls/ca.crt', 'utf8'); // Set connection options; identity, wallet AND TLS configuration let connectionOptions = { identity: userName, wallet: wallet, discovery: { enabled: false, asLocalhost: true }, // 添加TLS证书配置 tlsInfo: { certificate: tlsRootCert } }; await gateway.connect(connectionProfile, connectionOptions); const network = await gateway.getNetwork('bionicchannel'); // Get addressability to commercial paper contract const contract = await network.getContract('papercontract'); const issueResponse = await contract.submitTransaction( 'issue', 'BionicSoftware', '00001', '2020-05-31', '2020-11-30', '5000000'); console.log('Transaction submitted successfully:', issueResponse.toString()); } catch (error) { console.error('Error processing transaction:', error); process.exit(1); } finally { // 记得断开网关连接 await gateway.disconnect(); } } main();
额外检查点
- 确认TLS证书路径正确:根据你的crypto-config目录结构,调整
fs.readFileSync的路径,确保能读取到peer节点的TLS CA证书。 - 检查
networkConnection.yaml配置:如果connection profile里已经配置了tlsCACerts的路径,确保该路径是客户端能访问到的绝对/相对路径,也可以直接用代码加载证书覆盖配置。 - 测试环境临时方案:如果确实不需要TLS,可在peer节点启动时关闭TLS,或在客户端连接选项中添加
tls: false(不推荐生产环境使用)。
内容的提问来源于stack exchange,提问作者Mike Araya
相关产品推荐
相关产品推荐

