Composer Rest Server中不存网卡时,如何用证书单独签名交易?
Great question! I’ve dealt with this exact use case while working with Hyperledger Composer Rest Server, so let me break down the step-by-step solution for you.
The core idea here is to enable TLS client authentication + multi-user mode on the Composer Rest Server. This lets clients pass their certificates directly with each request, so the server uses that certificate to sign transactions without needing to store it in a wallet beforehand.
1. Start the Composer Rest Server with TLS Client Authentication
First, you need to launch the Rest Server with TLS enabled and configured to require client certificates for authentication. This ensures every request carries the client's identity certificate, which the server uses for transaction signing.
Here's a sample startup command:
composer-rest-server -c admin@your-network -t true -s true -o true -k ./server-key.pem -c ./server-cert.pem -r true
Let’s break down the key parameters:
-t true: Enables TLS for secure communication-s true: Forces client certificate authentication-o true: Enables CORS (optional, but useful if you’re calling from a frontend)-k/-c: Paths to the Rest Server’s own private key and certificate-r true: Enables multi-user mode (critical, as this maps each client’s certificate to a unique network identity)
2. Pass Certificates When Making Client Requests
When calling the Rest Server API, your client needs to attach its own private key and public certificate with every request. Here’s how to do this with common tools:
Using curl:
curl -X POST \ https://your-rest-server-url:3000/api/YourTransactionType \ -H 'Content-Type: application/json' \ -d '{"assetId": "asset123", "newValue": "updated"}' \ --key ./client-private-key.pem \ --cert ./client-public-cert.pem
Using Node.js with axios:
const axios = require('axios'); const https = require('https'); const fs = require('fs'); // Load client certificate and key const clientKey = fs.readFileSync('./client-private-key.pem'); const clientCert = fs.readFileSync('./client-public-cert.pem'); // Configure HTTPS agent to use client certs const httpsAgent = new https.Agent({ key: clientKey, cert: clientCert, rejectUnauthorized: false // Disable only for testing; validate server certs in production }); // Send transaction request axios.post('https://your-rest-server-url:3000/api/YourTransactionType', { assetId: "asset123", newValue: "updated" }, { httpsAgent }) .then(res => console.log('Transaction submitted:', res.data)) .catch(err => console.error('Error:', err));
3. How the Server Handles Signing
Once TLS client auth is enabled, the Rest Server automatically extracts the client’s certificate from the request. It uses this certificate to authenticate the client’s identity against the Hyperledger Fabric network, then signs the transaction using that identity—no need to pre-store the certificate in the server’s wallet.
4. Switching Certificates On-the-Fly
To use a different certificate for signing transactions at any time, simply swap out the client key and certificate files in your request. Each certificate maps to a unique registered identity in the Fabric network, so the server will automatically use the new identity for that specific request.
Important: Make sure every client certificate you use has already been registered and enrolled with your Hyperledger Fabric network. Unregistered certificates will fail to authenticate and sign transactions.
内容的提问来源于stack exchange,提问作者user9040429

