Re: Starting Fabric-CA without providing any root certificate

Jean-Gaël Dominé <jgdomine@...>


This is a tricky thing. I had the same issue and it took me a while to figure out the issue.

This is definitely not mandatory to provide the root certificate and the private key to the CA because it will generate them if needed.
BUT (and that's where your issue lies) the provided fabric-ca image was packaged with already a root certificate and a private key... I suppose you always see that issued everything right?

The workaround I found was to delete these two files before starting the CA so that it creates them.
I did it like this:
rm -Rf /etc/hyperledger/fabric-ca-server

Pretty ugly but at least all my CAs use the CN I was defining :)

Hope this helps


