Hyperledger Fabric本地MicroFab环境PKCS8私钥格式错误求助
解决MicroFab接口获取的PKCS8私钥格式错误问题
问题背景
基于本地IBM MicroFab区块链网络构建Hyperledger Fabric项目时,调用/ak/api/v1/components接口获取身份连接信息,因私钥格式处理不当,出现malformed plain PKCS8 private key(code:001)错误,需正确处理接口返回的私钥与证书格式。
报错信息
malformed plain PKCS8 private key(code:001)
接口返回JSON示例
[ { "id": "p0000admin", "display_name": "p0000 Admin", "type": "identity", "cert": "LS0tLS.....0tLS0tCg==", "private_key": "LS0t....FIEtFWS0tLS0tCg==", "ca": "LS0tL....LS0tCg==", "msp_id": "p0000MSP", "wallet": "p0000", "hide": false } ]
当前处理代码
const identityLabel = `p${userid} Admin`; const identity = { credentials: { certificate: `-----BEGIN CERTIFICATE-----\n${rawcertificate}\n-----END CERTIFICATE-----\n`, privateKey: `-----BEGIN PRIVATE KEY-----\n${rawprivatekey}\n-----END PRIVATE KEY-----\n`, }, mspId: `p${userid}MSP`, type: 'X.509', };
完整错误栈
error: [crypto_ecdsa_aes]: createKeyFromRaw - Failed to parse key from PEM: message=malformed plain PKCS8 private key(code:001), stack=Error: malformed plain PKCS8 private key(code:001) at Object.parsePlainPrivatePKCS8Hex (/home/tylr/Documents/IEEE/next-energychain/node_modules/jsrsasign/lib/jsrsasign.js:238:5296) at Object.getKeyFromPlainPrivatePKCS8Hex (/home/tylr/Documents/IEEE/next-energychain/node_modules/jsrsasign/lib/jsrsasign.js:238:6073) at Object.getKeyFromPlainPrivatePKCS8PEM (/home/tylr/Documents/IEEE/next-energychain/node_modules/jsrsasign/lib/jsrsasign.js:238:5975) at KEYUTIL.getKey (/home/tylr/Documents/IEEE/next-energychain/node_modules/jsrsasign/lib/jsrsasign.js:238:11905) at CryptoSuite_ECDSA_AES.createKeyFromRaw (/home/tylr/Documents/IEEE/next-energychain/node_modules/fabric-common/lib/impl/CryptoSuite_ECDSA_AES.js:132:18) at X509Provider.getUserContext (/home/tylr/Documents/IEEE/next-energychain/node_modules/fabric-network/lib/impl/wallet/x509identity.js:61:46) at Gateway.connect (/home/tylr/Documents/IEEE/next-energychain/node_modules/fabric-network/lib/gateway.js:257:41) at process.processTicksAndRejections (node:internal/process/task_queues:95:5) at async evaluateTransaction (webpack-internal:///(api)/./hyperledger/api-EvaluateTransaction.js:82:9) API failed to fetch: Error: Failed to parse key from PEM: Error: malformed plain PKCS8 private key(code:001) at CryptoSuite_ECDSA_AES.createKeyFromRaw (/home/tylr/Documents/IEEE/next-energychain/node_modules/fabric-common/lib/impl/CryptoSuite_ECDSA_AES.js:135:10) at X509Provider.getUserContext (/home/tylr/Documents/IEEE/next-energychain/node_modules/fabric-network/lib/impl/wallet/x509identity.js:61:46) at Gateway.connect (/home/tylr/Documents/IEEE/next-energychain/node_modules/fabric-network/lib/gateway.js:257:41) at process.processTicksAndRejections (node:internal/process/task_queues:95:5) at async evaluateTransaction (webpack-internal:///(api)/./hyperledger/api-EvaluateTransaction.js:82:9)
解决方案
MicroFab接口返回的cert和private_key字段是完整PEM文件的Base64编码,而非原始的PEM内容片段。直接手动添加头部尾部会导致格式重复,引发解析错误。正确处理步骤如下:
- 对接口返回的
cert和private_key进行Base64解码,得到原始的PEM格式字符串(已包含正确的头部、换行和尾部) - 将解码后的字符串直接作为证书和私钥的值
修改后的代码
const microfabjson = await fetch('http://console.127.0.0.1.nip.io:8081/ak/api/v1/components', { headers: { 'Accept': 'application/json', 'Path': '/', } }) .then(response => response.json()) const identity_json = microfabjson.filter(obj=> obj.type == "identity" && obj.id == `p${userid}admin`)[0]; // 对证书和私钥进行Base64解码 const decodedCertificate = Buffer.from(identity_json.cert, 'base64').toString('utf8'); const decodedPrivateKey = Buffer.from(identity_json.private_key, 'base64').toString('utf8'); const identityLabel = `p${userid} Admin`; const identity = { credentials: { certificate: decodedCertificate, privateKey: decodedPrivateKey, }, mspId: identity_json.msp_id, type: 'X.509', };
关键说明
- 接口返回的
LS0t...Cg==格式字符串是完整PEM文件的Base64编码,解码后会自动包含-----BEGIN CERTIFICATE-----、换行符和-----END CERTIFICATE-----等正确格式 - 无需手动拼接头部尾部,避免重复格式导致解析失败
内容的提问来源于stack exchange,提问作者user19643115
相关产品推荐
相关产品推荐

