Fabric-ca: server init函数——获取bccsp

1 生成BCCSP实例

初始化此CA的加密层(BCCSP)

ca.csp, err = util.InitBCCSP(&ca.Config.CSP, "", ca.HomeDir)

方法代码

// InitBCCSP initializes BCCSP
func InitBCCSP(optsPtr **factory.FactoryOpts, mspDir, homeDir string) (bccsp.BCCSP, error) {
   err := ConfigureBCCSP(optsPtr, mspDir, homeDir)
   if err != nil {
      return nil, err
   }
   csp, err := GetBCCSP(*optsPtr, homeDir)
   if err != nil {
      return nil, err
   }
   return csp, nil
}

ConfigureBCCSP方法的参数

ConfigureBCCSP方法作用: 配置keystore的目录,以及获取目录的绝对路径

GetBCCSP方法:

func GetBCCSP(opts *factory.FactoryOpts, homeDir string) (bccsp.BCCSP, error) {

   // Get BCCSP from the opts
   csp, err := factory.GetBCCSPFromOpts(opts)
   if err != nil {
      return nil, errors.WithMessage(err, "Failed to get BCCSP with opts")
   }
   return csp, nil
}

 

 

 

GetBCCSPFromOpts方法:

// GetBCCSPFromOpts returns a BCCSP created according to the options passed in input.
func GetBCCSPFromOpts(config *FactoryOpts) (bccsp.BCCSP, error) {
   var f BCCSPFactory
   switch config.ProviderName {
   case "SW":
      f = &SWFactory{}
   case "PLUGIN":
      f = &PluginFactory{}
   default:
      return nil, errors.Errorf("Could not find BCCSP, no '%s' provider", config.ProviderName)
   }

   csp, err := f.Get(config)
   if err != nil {
      return nil, errors.Wrapf(err, "Could not initialize BCCSP %s", f.Name())
   }
   return csp, nil
}

SW 是指基于软件的bccsp; f是SWFactory的实例,f.Get(config)方法获取csp 加密服务提供者; 此时返回的还是bccsp.BCCSP实例

Get方法

func (f *SWFactory) Get(config *FactoryOpts) (bccsp.BCCSP, error) {
   // Validate arguments
   if config == nil || config.SwOpts == nil {
      return nil, errors.New("Invalid config. It must not be nil.")
   }

   swOpts := config.SwOpts

   var ks bccsp.KeyStore
   if swOpts.Ephemeral == true {
      ks = sw.NewDummyKeyStore()
   } else if swOpts.FileKeystore != nil {
      fks, err := sw.NewFileBasedKeyStore(nil, swOpts.FileKeystore.KeyStorePath, false)
      if err != nil {
         return nil, errors.Wrapf(err, "Failed to initialize software key store")
      }
      ks = fks
   } else if swOpts.InmemKeystore != nil {
      ks = sw.NewInMemoryKeyStore()
   } else {
      // Default to ephemeral key store
      ks = sw.NewDummyKeyStore()
   }

   return sw.NewWithParams(swOpts.SecLevel, swOpts.HashFamily, ks)
}

 

sw.NewWithParams(swOpts.SecLevel, swOpts.HashFamily, ks)方法

func NewWithParams(securityLevel int, hashFamily string, keyStore bccsp.KeyStore) (bccsp.BCCSP, error) {
	// Init config
	conf := &config{}
	err := conf.setSecurityLevel(securityLevel, hashFamily)
	if err != nil {
		return nil, errors.Wrapf(err, "Failed initializing configuration at [%v,%v]", securityLevel, hashFamily)
	}

	swbccsp, err := New(keyStore)
	if err != nil {
		return nil, err
	}

	// Notice that errors are ignored here because some test will fail if one
	// of the following call fails.

	// Set the Encryptors
	swbccsp.AddWrapper(reflect.TypeOf(&aesPrivateKey{}), &aescbcpkcs7Encryptor{})

	// Set the Decryptors
	swbccsp.AddWrapper(reflect.TypeOf(&aesPrivateKey{}), &aescbcpkcs7Decryptor{})
    
    .......

    return swbccsp,nil
}

New方法:

func New(keyStore bccsp.KeyStore) (*CSP, error) {
	if keyStore == nil {
		return nil, errors.Errorf("Invalid bccsp.KeyStore instance. It must be different from nil.")
	}

	encryptors := make(map[reflect.Type]Encryptor)
	decryptors := make(map[reflect.Type]Decryptor)
	signers := make(map[reflect.Type]Signer)
	verifiers := make(map[reflect.Type]Verifier)
	hashers := make(map[reflect.Type]Hasher)
	keyGenerators := make(map[reflect.Type]KeyGenerator)
	keyDerivers := make(map[reflect.Type]KeyDeriver)
	keyImporters := make(map[reflect.Type]KeyImporter)

	csp := &CSP{keyStore,
		keyGenerators, keyDerivers, keyImporters, encryptors,
		decryptors, signers, verifiers, hashers}

	return csp, nil
}

 

在加上上面的其他包装器,sw.CSP实例构造完成。

方法要求返回的是bccsp.BCCSP接口实例,但是具体的接口实现是 sw.CSP

 

 

 

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值