You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Fabric最新版本first-network中CA服务器启动及SSL验证错误求助

Solutions to Your Hyperledger Fabric & Composer Deployment Issues

Let's work through your two problems step by step to get your multi-org network up and running smoothly.

1. Fixing the Missing -a Parameter in byfn.sh

The -a parameter you're trying to use likely doesn't exist in your version of the byfn.sh script—this is a common version mismatch issue.

For Hyperledger Fabric 1.4 (the version compatible with Hyperledger Composer), the correct flag to enable Certificate Authorities (CAs) when starting the network is -ca, not -a.

To start your first-network with CAs enabled, run these commands:

./byfn.sh down
./byfn.sh up -s couchdb -ca

This will spin up the CA servers for both organizations as expected, aligning with the Composer multi-org tutorial.

2. Resolving SSL Certificate Verification Failure During composer network install

The SSL handshake error you're seeing happens when Composer can't validate the peer's TLS certificate, usually due to mismatched configurations or incorrect certificate paths. Here's how to fix it:

Step 1: Recreate Your PeerAdmin Card

Your existing PeerAdmin@byfn-network-org1 card probably has incorrect certificate references or network settings. Delete it and create a fresh one:

# Delete the old card
composer card delete -c PeerAdmin@byfn-network-org1

# Create a new card with correct certificate paths
# Replace <PRIVATE_KEY_FILE> with the actual _sk file in your crypto-config directory
composer card create -p connection-org1.json -u PeerAdmin \
  -c crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp/signcerts/Admin@org1.example.com-cert.pem \
  -k crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp/keystore/<PRIVATE_KEY_FILE> \
  -r PeerAdmin -r ChannelAdmin

# Import the new card
composer card import -f PeerAdmin@byfn-network-org1.card

You can find the private key file by listing the keystore directory:

ls crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp/keystore/

It will be a file ending in _sk.

Step 2: Correct the connection-org1.json Profile

Ensure your connection profile has the right TLS settings and peer address:

  • Open connection-org1.json and check the peers section for peer0.org1.example.com:
    "peers": {
        "peer0.org1.example.com": {
            "url": "grpcs://localhost:7051",
            "tlsCACerts": {
                "path": "crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt"
            },
            "grpcOptions": {
                "ssl-target-name-override": "peer0.org1.example.com"
            }
        }
    }
    
    The ssl-target-name-override must exactly match the Common Name (CN) in the peer's TLS certificate, which is peer0.org1.example.com for the default first-network.

Step 3: Update Your Local Hosts File

Fabric uses domain names in certificates, so your machine needs to resolve these domains to localhost. Edit /etc/hosts (Linux/macOS) or C:\Windows\System32\drivers\etc\hosts (Windows) and add these lines:

127.0.0.1 peer0.org1.example.com peer0.org2.example.com orderer.example.com ca.org1.example.com ca.org2.example.com

Step 4: Verify Fabric Container Status

Make sure all required containers are running without errors:

docker ps

If any containers are restarting or not running, tear down and restart the network:

./byfn.sh down
./byfn.sh up -s couchdb -ca

Step 5: Retry the Network Install

Once all the above steps are done, run the install command again:

composer network install --card PeerAdmin@byfn-network-org1 --archiveFile trade-network.bna

内容的提问来源于stack exchange,提问作者Mallesh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 07:19:32