bevel-operator-fabric icon indicating copy to clipboard operation
bevel-operator-fabric copied to clipboard

Command for revoking an identity missing

Open koh-osug opened this issue 1 year ago • 1 comments
trafficstars

What happened?

I use:

kubectl hlf ca register
kubectl hlf ca enroll

to create a new client. The client can interact with the chaincode. Now I have to revoke this created identity. The command is missing.

What did you expect to happen?

That I can run something like:

kubectl hlf ca revoke

How can we reproduce it (as minimally and precisely as possible)?

kubectl hlf ca register ... kubectl hlf ca enroll ...

Anything else we need to know?

kubectl hlf identity delete does not seem to do what I want and cannot find data.

Logging into the CA container and trying to run gives:

fabric-ca-client identity list 2023/12/12 21:55:04 [ERROR] Enrollment check failed: either because 'x509 enrollment information does not exist - certFile: /var/hyperledger/fabric-ca/msp/signcerts/cert.pem keyFile: /var/hyperledger/fabric-ca/msp/keystore/key.pem' or 'Idemix enrollment information does not exist'

Kubernetes version

v1.27.5-gke.200

koh-osug avatar Dec 12 '23 21:12 koh-osug

Even after revoking from CA, you need to add it crl in channel to stop accepting txns signed from that identity.

adityajoshi12 avatar May 18 '24 09:05 adityajoshi12