Adding a new organization to a Hyperledger Fabric channel uptated from 1.4 to 2.2

Viewed 119

We are trying to add a new org to the channel by following these steps:

  1. Generate crypto materials for newOrg
  2. Generate newOrg-specific configuration materials
  3. Fetch the latest config block from orderer, trim it down and convert it to JSON
  4. Add newOrg-specific configuration materials to the JSON
  5. Convert original JSON and newly edited JSON to protobuf format
  6. Compute difference between the new and original block (.pb files)
  7. Convert it to JSON format and add back header
  8. Convert it to protobuf format
  9. Sign transaction by old Org
  10. Update channel
  11. Join new Org to the channel

configtx.yaml:

Organizations:
  - &Org2
    # DefaultOrg defines the organization which is used in the sampleconfig
    # of the fabric.git development environment
    Name: Org2
    # ID to load the MSP definition as
    ID: Org2MSP
    MSPDir: ./../crypto-config/peerOrganizations/newOrg.com/msp
    Policies:
      Readers:
        Type: Signature
        Rule: "OR('newOrgMSP.admin', 'newOrgMSP.peer', 'newOrgMSP.client')"
      Writers:
        Type: Signature
        Rule: "OR('newOrgMSP.admin', 'newOrgMSP.client')"
      Admins:
        Type: Signature
        Rule: "OR('newOrgMSP.admin')"
      Endorsement:
        Type: Signature
        Rule: "OR('newOrgMSP.peer')"
# Anchor peers
AnchorPeers:
  - Host: peer0.newOrg.com
    Port: 8052
  - Host: peer1.newOrg.com
    Port: 8053

This is the channel config.json after the process:

{
    "data":{
       "data":[
          {
             "payload":{
                "data":{
                   "config":{
                      "channel_group":{
                         "groups":{
                            "Application":{
                               "groups":{
                                  "newOrgMSP":{
                                     "groups":{
                                        
                                     },
                                     "mod_policy":"Admins",
                                     "policies":{
                                        "Admins":{
                                           "mod_policy":"Admins",
                                           "policy":{
                                              "type":1,
                                              "value":{
                                                 "identities":[
                                                    {
                                                       "principal":{
                                                          "msp_identifier":"newOrgMSP",
                                                          "role":"ADMIN"
                                                       },
                                                       "principal_classification":"ROLE"
                                                    }
                                                 ],
                                                 "rule":{
                                                    "n_out_of":{
                                                       "n":1,
                                                       "rules":[
                                                          {
                                                             "signed_by":0
                                                          }
                                                       ]
                                                    }
                                                 },
                                                 "version":0
                                              }
                                           },
                                           "version":"0"
                                        },
                                        "Endorsement":{
                                           "mod_policy":"Admins",
                                           "policy":{
                                              "type":1,
                                              "value":{
                                                 "identities":[
                                                    {
                                                       "principal":{
                                                          "msp_identifier":"newOrgMSP",
                                                          "role":"PEER"
                                                       },
                                                       "principal_classification":"ROLE"
                                                    }
                                                 ],
                                                 "rule":{
                                                    "n_out_of":{
                                                       "n":1,
                                                       "rules":[
                                                          {
                                                             "signed_by":0
                                                          }
                                                       ]
                                                    }
                                                 },
                                                 "version":0
                                              }
                                           },
                                           "version":"0"
                                        },
                                        "Readers":{
                                           "mod_policy":"Admins",
                                           "policy":{
                                              "type":1,
                                              "value":{
                                                 "identities":[
                                                    {
                                                       "principal":{
                                                          "msp_identifier":"newOrgMSP",
                                                          "role":"ADMIN"
                                                       },
                                                       "principal_classification":"ROLE"
                                                    },
                                                    {
                                                       "principal":{
                                                          "msp_identifier":"newOrgMSP",
                                                          "role":"PEER"
                                                       },
                                                       "principal_classification":"ROLE"
                                                    },
                                                    {
                                                       "principal":{
                                                          "msp_identifier":"newOrgMSP",
                                                          "role":"CLIENT"
                                                       },
                                                       "principal_classification":"ROLE"
                                                    }
                                                 ],
                                                 "rule":{
                                                    "n_out_of":{
                                                       "n":1,
                                                       "rules":[
                                                          {
                                                             "signed_by":0
                                                          },
                                                          {
                                                             "signed_by":1
                                                          },
                                                          {
                                                             "signed_by":2
                                                          }
                                                       ]
                                                    }
                                                 },
                                                 "version":0
                                              }
                                           },
                                           "version":"0"
                                        },
                                        "Writers":{
                                           "mod_policy":"Admins",
                                           "policy":{
                                              "type":1,
                                              "value":{
                                                 "identities":[
                                                    {
                                                       "principal":{
                                                          "msp_identifier":"newOrgMSP",
                                                          "role":"ADMIN"
                                                       },
                                                       "principal_classification":"ROLE"
                                                    },
                                                    {
                                                       "principal":{
                                                          "msp_identifier":"newOrgMSP",
                                                          "role":"CLIENT"
                                                       },
                                                       "principal_classification":"ROLE"
                                                    }
                                                 ],
                                                 "rule":{
                                                    "n_out_of":{
                                                       "n":1,
                                                       "rules":[
                                                          {
                                                             "signed_by":0
                                                          },
                                                          {
                                                             "signed_by":1
                                                          }
                                                       ]
                                                    }
                                                 },
                                                 "version":0
                                              }
                                           },
                                           "version":"0"
                                        }
                                     },
                                     "values":{
                                        "MSP":{
                                           "mod_policy":"Admins",
                                           "value":{
                                              "config":{
                                                 "admins":[
                                                    
                                                 ],
                                                 "crypto_config":{
                                                    "identity_identifier_hash_function":"SHA256",
                                                    "signature_hash_family":"SHA2"
                                                 },
                                                 "fabric_node_ous":{
                                                    "admin_ou_identifier":{
                                                       "certificate":"",
                                                       "organizational_unit_identifier":"admin"
                                                    },
                                                    "client_ou_identifier":{
                                                       "certificate":"",
                                                       "organizational_unit_identifier":"client"
                                                    },
                                                    "enable":true,
                                                    "orderer_ou_identifier":{
                                                       "certificate":"",
                                                       "organizational_unit_identifier":"orderer"
                                                    },
                                                    "peer_ou_identifier":{
                                                       "certificate":"",
                                                       "organizational_unit_identifier":"peer"
                                                    }
                                                 },
                                                 "intermediate_certs":[
                                                    
                                                 ],
                                                 "name":"newOrgMSP",
                                                 "organizational_unit_identifiers":[
                                                    
                                                 ],
                                                 "revocation_list":[
                                                    
                                                 ],
                                                 "root_certs":[
                                                    ""
                                                 ],
                                                 "signing_identity":null,
                                                 "tls_intermediate_certs":[
                                                    
                                                 ],
                                                 "tls_root_certs":[
                                                    ""
                                                 ]
                                              },
                                              "type":0
                                           },
                                           "version":"0"
                                        }
                                     },
                                     "version":"0"
                                  },
                                  "oldOrgMSP":{
                                     "groups":{
                                        
                                     },
                                     "mod_policy":"Admins",
                                     "policies":{
                                        "Admins":{
                                           "mod_policy":"Admins",
                                           "policy":{
                                              "type":1,
                                              "value":{
                      

But in the last step I get this error:

2021-06-16 07:47:02.908 UTC [channelCmd] InitCmdFactory -> INFO 001 Endorser and orderer connections initialized
2021-06-16 07:47:02.910 UTC [cli.common] readBlock -> INFO 002 Expect block, but got status: &{FORBIDDEN}

Error: can't read the block: &{FORBIDDEN}

And on orderer logs:

Client 172.28.0.16:55310 is not authorized: implicit policy evaluation failed - 0 sub-policies wer
e satisfied, but this policy requires 1 of the 'Readers' sub-policies to be satisfied: permission denied

Thank you.

0 Answers
Related