Fabric最新版本first-network中CA服务器启动及SSL验证错误求助
Let's work through your two problems step by step to get your multi-org network up and running smoothly.
1. Fixing the Missing -a Parameter in byfn.sh
The -a parameter you're trying to use likely doesn't exist in your version of the byfn.sh script—this is a common version mismatch issue.
For Hyperledger Fabric 1.4 (the version compatible with Hyperledger Composer), the correct flag to enable Certificate Authorities (CAs) when starting the network is -ca, not -a.
To start your first-network with CAs enabled, run these commands:
./byfn.sh down ./byfn.sh up -s couchdb -ca
This will spin up the CA servers for both organizations as expected, aligning with the Composer multi-org tutorial.
2. Resolving SSL Certificate Verification Failure During composer network install
The SSL handshake error you're seeing happens when Composer can't validate the peer's TLS certificate, usually due to mismatched configurations or incorrect certificate paths. Here's how to fix it:
Step 1: Recreate Your PeerAdmin Card
Your existing PeerAdmin@byfn-network-org1 card probably has incorrect certificate references or network settings. Delete it and create a fresh one:
# Delete the old card composer card delete -c PeerAdmin@byfn-network-org1 # Create a new card with correct certificate paths # Replace <PRIVATE_KEY_FILE> with the actual _sk file in your crypto-config directory composer card create -p connection-org1.json -u PeerAdmin \ -c crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp/signcerts/Admin@org1.example.com-cert.pem \ -k crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp/keystore/<PRIVATE_KEY_FILE> \ -r PeerAdmin -r ChannelAdmin # Import the new card composer card import -f PeerAdmin@byfn-network-org1.card
You can find the private key file by listing the keystore directory:
ls crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp/keystore/
It will be a file ending in _sk.
Step 2: Correct the connection-org1.json Profile
Ensure your connection profile has the right TLS settings and peer address:
- Open
connection-org1.jsonand check thepeerssection forpeer0.org1.example.com:
The"peers": { "peer0.org1.example.com": { "url": "grpcs://localhost:7051", "tlsCACerts": { "path": "crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt" }, "grpcOptions": { "ssl-target-name-override": "peer0.org1.example.com" } } }ssl-target-name-overridemust exactly match the Common Name (CN) in the peer's TLS certificate, which ispeer0.org1.example.comfor the default first-network.
Step 3: Update Your Local Hosts File
Fabric uses domain names in certificates, so your machine needs to resolve these domains to localhost. Edit /etc/hosts (Linux/macOS) or C:\Windows\System32\drivers\etc\hosts (Windows) and add these lines:
127.0.0.1 peer0.org1.example.com peer0.org2.example.com orderer.example.com ca.org1.example.com ca.org2.example.com
Step 4: Verify Fabric Container Status
Make sure all required containers are running without errors:
docker ps
If any containers are restarting or not running, tear down and restart the network:
./byfn.sh down ./byfn.sh up -s couchdb -ca
Step 5: Retry the Network Install
Once all the above steps are done, run the install command again:
composer network install --card PeerAdmin@byfn-network-org1 --archiveFile trade-network.bna
内容的提问来源于stack exchange,提问作者Mallesh

