We are trying to add a new org to the channel by following these steps:
- Generate crypto materials for newOrg
- Generate newOrg-specific configuration materials
- Fetch the latest config block from orderer, trim it down and convert it to JSON
- Add newOrg-specific configuration materials to the JSON
- Convert original JSON and newly edited JSON to protobuf format
- Compute difference between the new and original block (.pb files)
- Convert it to JSON format and add back header
- Convert it to protobuf format
- Sign transaction by old Org
- Update channel
- Join new Org to the channel
configtx.yaml:
Organizations:
- &Org2
# DefaultOrg defines the organization which is used in the sampleconfig
# of the fabric.git development environment
Name: Org2
# ID to load the MSP definition as
ID: Org2MSP
MSPDir: ./../crypto-config/peerOrganizations/newOrg.com/msp
Policies:
Readers:
Type: Signature
Rule: "OR('newOrgMSP.admin', 'newOrgMSP.peer', 'newOrgMSP.client')"
Writers:
Type: Signature
Rule: "OR('newOrgMSP.admin', 'newOrgMSP.client')"
Admins:
Type: Signature
Rule: "OR('newOrgMSP.admin')"
Endorsement:
Type: Signature
Rule: "OR('newOrgMSP.peer')"
# Anchor peers
AnchorPeers:
- Host: peer0.newOrg.com
Port: 8052
- Host: peer1.newOrg.com
Port: 8053
This is the channel config.json after the process:
{
"data":{
"data":[
{
"payload":{
"data":{
"config":{
"channel_group":{
"groups":{
"Application":{
"groups":{
"newOrgMSP":{
"groups":{
},
"mod_policy":"Admins",
"policies":{
"Admins":{
"mod_policy":"Admins",
"policy":{
"type":1,
"value":{
"identities":[
{
"principal":{
"msp_identifier":"newOrgMSP",
"role":"ADMIN"
},
"principal_classification":"ROLE"
}
],
"rule":{
"n_out_of":{
"n":1,
"rules":[
{
"signed_by":0
}
]
}
},
"version":0
}
},
"version":"0"
},
"Endorsement":{
"mod_policy":"Admins",
"policy":{
"type":1,
"value":{
"identities":[
{
"principal":{
"msp_identifier":"newOrgMSP",
"role":"PEER"
},
"principal_classification":"ROLE"
}
],
"rule":{
"n_out_of":{
"n":1,
"rules":[
{
"signed_by":0
}
]
}
},
"version":0
}
},
"version":"0"
},
"Readers":{
"mod_policy":"Admins",
"policy":{
"type":1,
"value":{
"identities":[
{
"principal":{
"msp_identifier":"newOrgMSP",
"role":"ADMIN"
},
"principal_classification":"ROLE"
},
{
"principal":{
"msp_identifier":"newOrgMSP",
"role":"PEER"
},
"principal_classification":"ROLE"
},
{
"principal":{
"msp_identifier":"newOrgMSP",
"role":"CLIENT"
},
"principal_classification":"ROLE"
}
],
"rule":{
"n_out_of":{
"n":1,
"rules":[
{
"signed_by":0
},
{
"signed_by":1
},
{
"signed_by":2
}
]
}
},
"version":0
}
},
"version":"0"
},
"Writers":{
"mod_policy":"Admins",
"policy":{
"type":1,
"value":{
"identities":[
{
"principal":{
"msp_identifier":"newOrgMSP",
"role":"ADMIN"
},
"principal_classification":"ROLE"
},
{
"principal":{
"msp_identifier":"newOrgMSP",
"role":"CLIENT"
},
"principal_classification":"ROLE"
}
],
"rule":{
"n_out_of":{
"n":1,
"rules":[
{
"signed_by":0
},
{
"signed_by":1
}
]
}
},
"version":0
}
},
"version":"0"
}
},
"values":{
"MSP":{
"mod_policy":"Admins",
"value":{
"config":{
"admins":[
],
"crypto_config":{
"identity_identifier_hash_function":"SHA256",
"signature_hash_family":"SHA2"
},
"fabric_node_ous":{
"admin_ou_identifier":{
"certificate":"",
"organizational_unit_identifier":"admin"
},
"client_ou_identifier":{
"certificate":"",
"organizational_unit_identifier":"client"
},
"enable":true,
"orderer_ou_identifier":{
"certificate":"",
"organizational_unit_identifier":"orderer"
},
"peer_ou_identifier":{
"certificate":"",
"organizational_unit_identifier":"peer"
}
},
"intermediate_certs":[
],
"name":"newOrgMSP",
"organizational_unit_identifiers":[
],
"revocation_list":[
],
"root_certs":[
""
],
"signing_identity":null,
"tls_intermediate_certs":[
],
"tls_root_certs":[
""
]
},
"type":0
},
"version":"0"
}
},
"version":"0"
},
"oldOrgMSP":{
"groups":{
},
"mod_policy":"Admins",
"policies":{
"Admins":{
"mod_policy":"Admins",
"policy":{
"type":1,
"value":{
But in the last step I get this error:
2021-06-16 07:47:02.908 UTC [channelCmd] InitCmdFactory -> INFO 001 Endorser and orderer connections initialized
2021-06-16 07:47:02.910 UTC [cli.common] readBlock -> INFO 002 Expect block, but got status: &{FORBIDDEN}
Error: can't read the block: &{FORBIDDEN}
And on orderer logs:
Client 172.28.0.16:55310 is not authorized: implicit policy evaluation failed - 0 sub-policies wer
e satisfied, but this policy requires 1 of the 'Readers' sub-policies to be satisfied: permission denied
Thank you.