You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Hyperledger Fabric中Cryptogen生成证书文件夹结构含义咨询

Hey there! Let me break down the folder structure generated by cryptogen when running the Hyperledger Fabric Build Your First Network (BYFN) example—understanding this is crucial to grasping how Fabric manages identity, authentication, and network permissions.

Cryptogen Generated Folder Structure Overview

By default, cryptogen outputs all certificates, keys, and MSP (Membership Service Provider) configurations into a root folder named crypto-config. Here’s a deep dive into what each subfolder contains:

1. OrdererOrganizations/

This directory holds all identity credentials for the orderer organization(s) in your network. In BYFN, the default orderer org is example.com, so you’ll see a subfolder example.com/ with these components:

  • ca/: Contains the Certificate Authority (CA) certificate (ca.example.com-cert.pem) and its private key (priv_sk). This CA is responsible for issuing valid certificates for all identities within the orderer organization.
  • orderers/: One subfolder per orderer node (e.g., orderer.example.com/). Each node’s folder includes:
    • msp/: The node’s MSP configuration, with subdirectories like cacerts/ (trusted CA certs), keystore/ (node’s private key), signcerts/ (node’s public signing certificate), and admincerts/ (admin certs for the org).
    • tls/: TLS-specific certificates and keys for secure communication between the orderer and other network entities, including ca.crt (TLS CA cert), server.crt (node’s TLS cert), and server.key (node’s TLS private key).
  • users/: Folders for administrative and regular users of the orderer org (e.g., Admin@example.com/, User1@example.com/). Each user’s folder has msp/ (for identity verification when interacting with the network) and tls/ (for TLS-secured client connections).
  • msp/: A template MSP configuration for the entire orderer organization, including cacerts/, admincerts/, and config.yaml (defines the MSP name and admin identity rules).

2. PeerOrganizations/

This directory houses credentials for peer organizations—BYFN includes two default orgs: org1.example.com and org2.example.com. Each org follows a similar structure to the orderer org:

  • ca/: The peer org’s CA certificate (e.g., ca.org1.example.com-cert.pem) and private key (priv_sk), which issues certificates for peers and users in this organization.
  • peers/: One subfolder per peer node (e.g., peer0.org1.example.com/, peer1.org1.example.com/). Each peer’s folder has:
    • msp/: The peer’s identity configuration, with cacerts/ (trusted CA certs), keystore/ (peer’s private key), signcerts/ (peer’s public signing cert), and admincerts/ (org admin certs).
    • tls/: TLS credentials for secure peer-to-peer and peer-to-orderer communication.
  • users/: Folders for the org’s admin and regular users (e.g., Admin@org1.example.com/, User1@org1.example.com/). These credentials let users submit transactions, query the ledger, and interact with peer nodes securely.
  • msp/: The org-wide MSP template, used to configure peer nodes’ MSP settings across the organization.

Key Subdirectory Deep Dive: msp/

Across all nodes and users, the msp/ folder has consistent critical components:

  • cacerts/: Trusted root CA certificates—used to verify that an identity’s certificate was issued by a trusted authority.
  • keystore/: The private key for the identity, used to sign transactions, proposals, or network messages.
  • signcerts/: The public signing certificate for the identity, which others use to verify signatures made with the corresponding private key.
  • admincerts/: Certificates of users with administrative privileges for the organization—these identities can perform actions like modifying channel configurations.
  • config.yaml: A configuration file that defines the MSP’s name, rules for validating admin identities, and other MSP-specific settings.

Key Subdirectory Deep Dive: tls/

The tls/ folder ensures all network communication is encrypted:

  • ca.crt: The TLS CA certificate, used to validate the authenticity of other TLS certificates in the network.
  • server.crt: The TLS certificate for the node/user, presented during TLS handshake to prove identity.
  • server.key: The private key paired with the TLS certificate, used to encrypt communication sessions.

内容的提问来源于stack exchange,提问作者Skadoosh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:36:22