Project reference ↗

Hyperledger Fabric CA is the identity-issuing service for a Fabric network. It registers participants and supplies the certificates that clients, administrators and nodes use to prove who they are. It is useful when operating the network's own certificate-authority infrastructure rather than just running application peers. Those signing keys and trust relationships are durable network identity: replacing a failed container must not accidentally create a different authority that existing participants do not trust.

Deployment and operating notes

Fabric CA’s current deployment guide distinguishes TLS, organization and intermediate certificate authorities and provides production planning guidance. The historical chart packages only part of that identity infrastructure. A fresh CA pod with a newly generated root is not an equivalent replacement for an existing organization’s trust anchor.

Inventory CA certificates, private keys or HSM references, registry database, affiliations, enrollment policies and revocation configuration. Preserve the materials required to restore the same CA identity, with access controls appropriate to signing keys. Check server and client compatibility and the documented database upgrade path before changing images. Rehearse enrollment, reenrollment, revocation and certificate-chain validation against a non-production organization. Coordinate root or intermediate rotation with channel MSP and client trust updates rather than treating it as a chart rollout. Maintain a recovery method that does not depend on the failed Kubernetes cluster. No current maintained successor chart or tested CA upgrade is implied by linking the application’s official documentation.

Historical upstream link check · 2026-10-09

The recorded upstream address responded successfully (HTTP 200) on 2026-10-09. Link availability does not certify the historical installation instructions or current security support.

Source for this check ↗

Website availability is separate from project, chart and image support. Use the current guidance and primary sources on this page to assess the distribution.

The original record

Historical Kubedex content

Original publication: 2018-09-12T06:22:35+00:00. Preserved for context. Commands, versions, prices and results below reflect the original research.

Hyperledger Fabric CA is a Certificate Authority node for the Hyperledger Fabric permissioned blockchain framework. The Hyperledger Fabric CA can be installed as either a Root CA, or an intermediate CA (by pointing to a parent CA, which can itself be a Root CA or an intermediate).

This CA can then be used to register and enroll identities for clients, admins, and nodes of the Hyperledger Fabric network.
The Hyperledger Fabric CA is a Certificate Authority (CA) for Hyperledger Fabric.

It provides features such as:

  • Registration of identities, or connects to LDAP as the user registry
  • issuance of Enrollment Certificates (ECerts)
  • certificate renewal and revocation

Overview:

There are two ways of interacting with a Hyperledger Fabric CA server: via the Hyperledger Fabric CA client or through one of the Fabric SDKs. All communication to the Hyperledger Fabric CA server is via REST APIs. See fabric-ca/swagger/swagger-fabric-ca.json for the swagger documentation for these REST APIs. You may view this documentation via the http://editor2.swagger.io online editor.

The Hyperledger Fabric CA client or SDK may connect to a server in a cluster of Hyperledger Fabric CA servers. This is illustrated in the top right section of the diagram. The client routes to an HA Proxy endpoint which load balances traffic to one of the fabric-ca-server cluster members.

All Hyperledger Fabric CA servers in a cluster share the same database for keeping track of identities and certificates. If LDAP is configured, the identity information is kept in LDAP rather than the database.

A server may contain multiple CAs. Each CA is either a root CA or an intermediate CA. Each intermediate CA has a parent CA which is either a root CA or another intermediate CA.

Prerequisites

  • Kubernetes 1.9+
  • PV provisioner support in the underlying infrastructure.
  • A running PostgreSQL Chart to host the Hyperledger Fabric CA data, in a database defined under the settings db.database.

The post Hlf-Ca appeared first on kubedex.com.

Sources & further reading

  1. Fabric CA production deployment guide
  2. Fabric CA user and upgrade guide
  3. Recovered historical source

Spotted something that needs another look?

Help improve this page →