fabric-node-sdk TLS配置

fabric-node-sdk中开启TLS的代码,以及peer和orderer的YAML网络配置。

更多区块链技术与应用分类:

区块链应用    区块链开发

以太坊 | Fabric | BCOS | 密码技术 | 共识算法 | 比特币其他链

通证经济传统金融场景 | 去中心化金融 | 防伪溯源 | 数据共享 | 可信存证

fabric-node-sdk中开启TLS的代码如下

let order1ServerCert = fs.readFileSync(path.join(__dirname, './crypto-config/ordererOrganizations/trace.com/users/Admin@trace.com/msp/tlscacerts/tlsca.trace.com-cert.pem'));
let order1Peer0ClientKey = fs.readFileSync(path.join(__dirname, './crypto-config/ordererOrganizations/trace.com/users/Admin@trace.com/tls/client.key'));
let order1Peer0ClientCert = fs.readFileSync(path.join(__dirname, './crypto-config/ordererOrganizations/trace.com/users/Admin@trace.com/tls/client.crt'));
 
let org1Peer0ServerCert = fs.readFileSync(path.join(__dirname, './crypto-config/peerOrganizations/org1.trace.com/tlsca/tlsca.org1.trace.com-cert.pem'));
let org1Peer0ClientKey = fs.readFileSync(path.join(__dirname, './crypto-config/peerOrganizations/org1.trace.com/users/Admin@org1.trace.com/tls/client.key'));
let org1Peer0ClientCert = fs.readFileSync(path.join(__dirname, './crypto-config/peerOrganizations/org1.trace.com/users/Admin@org1.trace.com/tls/client.crt'));
 
var order1Options = {
'pem': Buffer.from(order1ServerCert).toString(),
'clientKey': Buffer.from(order1Peer0ClientKey).toString(),
'clientCert': Buffer.from(order1Peer0ClientCert).toString(),
'ssl-target-name-override':"orderer1.trace.com"
};
 
var org1Peer0Options = {
'pem': Buffer.from(org1Peer0ServerCert).toString(),
'clientKey': Buffer.from(org1Peer0ClientKey).toString(),
'clientCert': Buffer.from(org1Peer0ClientCert).toString(),
'ssl-target-name-override':"peer0.org1.trace.com"
};
 
var order1 = client.newOrderer('grpcs://172.27.83.137:7050',order1Options);
var org1Peer0 = client.newPeer('grpcs://172.27.83.137:7051',org1Peer0Options);

在newPeer或newOrderer的后面参数中,要加ssl-target-name-override参数(容器名称),否则不能识别到相应节点无法与相应容器通信,产生错误:error: [Remote.js]: Error: Failed to connect before the deadline URL:grpcs://172.27.83.137:7051。

fabric网络配置(peer和orderer):

orderer:
- ORDERER_GENERAL_TLS_ENABLED=true
- ORDERER_GENERAL_TLS_PRIVATEKEY=/var/hyperledger/orderer/tls/server.key
- ORDERER_GENERAL_TLS_CERTIFICATE=/var/hyperledger/orderer/tls/server.crt
- ORDERER_GENERAL_TLS_ROOTCAS=[/var/hyperledger/orderer/tls/ca.crt]
- ORDERER_GENERAL_TLS_CLIENTAUTHREQUIRED=true
- ORDERER_GENERAL_TLS_CLIENTROOTCAS=/var/hyperledger/ordererclient/tls/ca.crt
 
peer:
- CORE_PEER_TLS_ENABLED=true
- CORE_PEER_TLS_CERT_FILE=/etc/hyperledger/fabric/tls/server.crt
- CORE_PEER_TLS_KEY_FILE=/etc/hyperledger/fabric/tls/server.key
- CORE_PEER_TLS_ROOTCERT_FILE=/etc/hyperledger/fabric/tls/ca.crt
- CORE_PEER_TLS_CLIENTAUTHREQUIRED=true
- CORE_PEER_TLS_CLIENTROOTCAS_FILES=/etc/hyperledger/client/tls/ca.crt
- CORE_PEER_TLS_CLIENTCERT_FILE=/etc/hyperledger/client/tls/client.crt
- CORE_PEER_TLS_CLIENTKEY_FILE=/etc/hyperledger/client/tls/client.key

原文链接:fabric-node-sdk TLS配置 

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值