Hyperledger Fabric示例网络创建通道时私钥加载失败问题求助
解决Hyperledger Fabric创建通道时的私钥加载错误
你遇到的这个Failed loading private key错误,核心问题是peer节点找不到指定路径下的完整私钥文件——报错里的文件名明显被截断了,和keystore目录里的真实私钥文件名不匹配。下面是几个直接有效的解决步骤:
先确认私钥文件的真实名称
先进入报错提示的私钥目录,查看完整的文件名:cd /opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp/keystore ls -l你会发现Fabric自动生成的私钥是一串很长的完整字符串,后缀带
_sk,而报错里的文件名只显示了一部分,这就是加载失败的原因。用环境变量自动匹配私钥,避免手动输入长文件名
不用费劲手动复制完整文件名,直接用命令自动识别并赋值:export PRIVATE_KEY=$(ls /opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp/keystore/*_sk)这条命令会自动抓取keystore目录下所有以
_sk结尾的私钥文件(Fabric生成的私钥默认都是这个后缀),并把路径存入PRIVATE_KEY变量。替换私钥路径后重新执行创建通道命令
把你原来创建通道命令里--keyfile后面的截断路径,换成上面的环境变量。比如原来的命令如果是:peer channel create -o orderer.example.com:7050 -c mychannel -f ./channel-artifacts/channel.tx --tls true --cafile /opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/ordererOrganizations/example.com/orderers/orderer.example.com/msp/tlscacerts/tlsca.example.com-cert.pem --keyfile /opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp/keystore/ec1f4a4699b91d9e6010e30aea31c0d1ba60f4e1787b84a5e03bb7aafc730...修改后变成:
peer channel create -o orderer.example.com:7050 -c mychannel -f ./channel-artifacts/channel.tx --tls true --cafile /opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/ordererOrganizations/example.com/orderers/orderer.example.com/msp/tlscacerts/tlsca.example.com-cert.pem --keyfile $PRIVATE_KEY额外排查:确认加密材料完整性
如果上面的方法还是不行,可能是生成加密材料时出了问题。可以重新运行cryptogen命令生成完整的加密文件:cryptogen generate --config=./crypto-config.yaml生成后再检查keystore和signcerts目录是否都有对应的文件。
内容的提问来源于stack exchange,提问作者Prasadh Kannan
相关产品推荐
相关产品推荐

