部署Hyperledger Composer多组织Fabric时遇SSL握手错误求助
Hey there, let's work through this SSL handshake error you're facing while deploying your Composer business network to a multi-organization Hyperledger Fabric setup. This is a common snag, so here are targeted fixes to get you back on track:
Double-check certificate paths and permissions
Make sure your Composer connection profile (connection.json) points to the correct, valid certificates for your peers, orderers, and user identities. These paths often get messed up when copying files between multi-org setups. Also, verify file permissions:- Set certificates to
chmod 644(read-only for all) - Set private keys to
chmod 600(read/write only for your user)
You can quickly validate paths by runningcat <path-to-cert>to confirm the file exists and has valid certificate content.
- Set certificates to
Match SSL target name overrides to certificate CNs
In yourconnection.json, every peer and orderer entry has ansslTargetNameOverridefield. This value must exactly match the Common Name (CN) in the corresponding node's SSL certificate. For example, if your peer's certificate has a CN ofpeer0.org1.example.com, yoursslTargetNameOverrideneeds to be identical—typos here are a frequent culprit for handshake failures.Confirm Fabric nodes are using consistent SSL settings
Ensure your Fabric peers and orderers are configured to use SSL if your connection profile specifiesgrpcsorhttpsendpoints. Conversely, if your nodes aren't using SSL, switch your connection profile to usegrpcorhttpinstead. Check node logs (e.g.,docker logs peer0.org1.example.com) to confirm SSL certificates loaded without errors on startup.Refresh your Fabric environment
Sometimes stale certificates or cached connections cause issues. Stop all Fabric containers completely with:docker-compose down -vThen restart the network:
docker-compose up -dIf you're running a Composer REST server or other client processes, restart those too to ensure they pick up the latest certificate and network state.
Validate CA certificate validity
Use OpenSSL to inspect your CA certificates and ensure they're active and match what your Fabric nodes are using:openssl x509 -in <path-to-ca-cert> -text -nooutCheck the expiration date and CN to confirm there's no mismatch or expired certificate causing the handshake failure.
If none of these fix the issue, enable debug logging for Fabric by setting this environment variable before running your Composer install command:
export FABRIC_LOGGING_SPEC=debug
The detailed logs will help pinpoint exactly where the SSL handshake is breaking down.
内容的提问来源于stack exchange,提问作者Simon Mullaney

