You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Hyperledger Fabric本地MicroFab环境PKCS8私钥格式错误求助

解决MicroFab接口获取的PKCS8私钥格式错误问题

问题背景

基于本地IBM MicroFab区块链网络构建Hyperledger Fabric项目时,调用/ak/api/v1/components接口获取身份连接信息,因私钥格式处理不当,出现malformed plain PKCS8 private key(code:001)错误,需正确处理接口返回的私钥与证书格式。

报错信息

malformed plain PKCS8 private key(code:001)

接口返回JSON示例

[
  {
    "id": "p0000admin",
    "display_name": "p0000 Admin",
    "type": "identity",
    "cert": "LS0tLS.....0tLS0tCg==",
    "private_key": "LS0t....FIEtFWS0tLS0tCg==",
    "ca": "LS0tL....LS0tCg==",
    "msp_id": "p0000MSP",
    "wallet": "p0000",
    "hide": false
  }
]

当前处理代码

const identityLabel = `p${userid} Admin`;
const identity = {
    credentials: {
        certificate: `-----BEGIN CERTIFICATE-----\n${rawcertificate}\n-----END CERTIFICATE-----\n`,
        privateKey: `-----BEGIN PRIVATE KEY-----\n${rawprivatekey}\n-----END PRIVATE KEY-----\n`,
    },
    mspId: `p${userid}MSP`,
    type: 'X.509',
};

完整错误栈

error: [crypto_ecdsa_aes]: createKeyFromRaw - Failed to parse key from PEM:  message=malformed plain PKCS8 private key(code:001), stack=Error: malformed plain PKCS8 private key(code:001)
    at Object.parsePlainPrivatePKCS8Hex (/home/tylr/Documents/IEEE/next-energychain/node_modules/jsrsasign/lib/jsrsasign.js:238:5296)
    at Object.getKeyFromPlainPrivatePKCS8Hex (/home/tylr/Documents/IEEE/next-energychain/node_modules/jsrsasign/lib/jsrsasign.js:238:6073)
    at Object.getKeyFromPlainPrivatePKCS8PEM (/home/tylr/Documents/IEEE/next-energychain/node_modules/jsrsasign/lib/jsrsasign.js:238:5975)
    at KEYUTIL.getKey (/home/tylr/Documents/IEEE/next-energychain/node_modules/jsrsasign/lib/jsrsasign.js:238:11905)
    at CryptoSuite_ECDSA_AES.createKeyFromRaw (/home/tylr/Documents/IEEE/next-energychain/node_modules/fabric-common/lib/impl/CryptoSuite_ECDSA_AES.js:132:18)
    at X509Provider.getUserContext (/home/tylr/Documents/IEEE/next-energychain/node_modules/fabric-network/lib/impl/wallet/x509identity.js:61:46)
    at Gateway.connect (/home/tylr/Documents/IEEE/next-energychain/node_modules/fabric-network/lib/gateway.js:257:41)
    at process.processTicksAndRejections (node:internal/process/task_queues:95:5)
    at async evaluateTransaction (webpack-internal:///(api)/./hyperledger/api-EvaluateTransaction.js:82:9)
API failed to fetch: Error: Failed to parse key from PEM: Error: malformed plain PKCS8 private key(code:001)
    at CryptoSuite_ECDSA_AES.createKeyFromRaw (/home/tylr/Documents/IEEE/next-energychain/node_modules/fabric-common/lib/impl/CryptoSuite_ECDSA_AES.js:135:10)
    at X509Provider.getUserContext (/home/tylr/Documents/IEEE/next-energychain/node_modules/fabric-network/lib/impl/wallet/x509identity.js:61:46)
    at Gateway.connect (/home/tylr/Documents/IEEE/next-energychain/node_modules/fabric-network/lib/gateway.js:257:41)
    at process.processTicksAndRejections (node:internal/process/task_queues:95:5)
    at async evaluateTransaction (webpack-internal:///(api)/./hyperledger/api-EvaluateTransaction.js:82:9)

解决方案

MicroFab接口返回的cert和private_key字段是完整PEM文件的Base64编码,而非原始的PEM内容片段。直接手动添加头部尾部会导致格式重复,引发解析错误。正确处理步骤如下:

  1. 对接口返回的cert和private_key进行Base64解码,得到原始的PEM格式字符串(已包含正确的头部、换行和尾部)
  2. 将解码后的字符串直接作为证书和私钥的值

修改后的代码

const microfabjson = await fetch('http://console.127.0.0.1.nip.io:8081/ak/api/v1/components', { 
    headers: {
      'Accept': 'application/json',
      'Path': '/',
    }
  })
  .then(response => response.json())

const identity_json = microfabjson.filter(obj=> obj.type == "identity" && obj.id == `p${userid}admin`)[0];
// 对证书和私钥进行Base64解码
const decodedCertificate = Buffer.from(identity_json.cert, 'base64').toString('utf8');
const decodedPrivateKey = Buffer.from(identity_json.private_key, 'base64').toString('utf8');

const identityLabel = `p${userid} Admin`;
const identity = {
    credentials: {
        certificate: decodedCertificate,
        privateKey: decodedPrivateKey,
    },
    mspId: identity_json.msp_id,
    type: 'X.509',
};

关键说明

  • 接口返回的LS0t...Cg==格式字符串是完整PEM文件的Base64编码,解码后会自动包含-----BEGIN CERTIFICATE-----、换行符和-----END CERTIFICATE-----等正确格式
  • 无需手动拼接头部尾部,避免重复格式导致解析失败

内容的提问来源于stack exchange,提问作者user19643115

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.20 03:05:29