<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: How to display a NiFi login window for http web browser in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/How-to-display-a-NiFi-login-window-for-http-web-browser/m-p/138381#M101012</link>
    <description>&lt;P&gt;If that's the case, then why does Ambari have a login page without https? Sometimes it's useful to setup the login first, then add a security layer. It helps with troubleshooting and not having a login for Ambari (for example) would be confusing! So why is this any different?&lt;/P&gt;</description>
    <pubDate>Thu, 29 Nov 2018 03:55:37 GMT</pubDate>
    <dc:creator>jpetro416</dc:creator>
    <dc:date>2018-11-29T03:55:37Z</dc:date>
    <item>
      <title>How to display a NiFi login window for http web browser</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-display-a-NiFi-login-window-for-http-web-browser/m-p/138374#M101005</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Wanted to display the log in window for apache nifi http server. Can anyone please let me know the setting to display the log in window for http instead of https. &lt;/P&gt;</description>
      <pubDate>Sun, 05 Mar 2017 22:37:17 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-display-a-NiFi-login-window-for-http-web-browser/m-p/138374#M101005</guid>
      <dc:creator>ayaskant19</dc:creator>
      <dc:date>2017-03-05T22:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to display a NiFi login window for http web browser</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-display-a-NiFi-login-window-for-http-web-browser/m-p/138375#M101006</link>
      <description>&lt;P&gt;The same question was already answered twice:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.hortonworks.com/questions/87146/how-can-we-pop-up-log-in-window-asking-user-id-and.html" target="_blank"&gt;https://community.hortonworks.com/questions/87146/how-can-we-pop-up-log-in-window-asking-user-id-and.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.hortonworks.com/questions/87122/how-can-we-pop-up-the-log-in-window-while-accessin.html" target="_blank"&gt;https://community.hortonworks.com/questions/87122/how-can-we-pop-up-the-log-in-window-while-accessin.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;To clarify you can not login over "http", only via "https". It would not be secure to send your LDAP credentials from the browser to the NiFi server over unencrypted http.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 05:10:21 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-display-a-NiFi-login-window-for-http-web-browser/m-p/138375#M101006</guid>
      <dc:creator>bbende</dc:creator>
      <dc:date>2017-03-07T05:10:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to display a NiFi login window for http web browser</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-display-a-NiFi-login-window-for-http-web-browser/m-p/138376#M101007</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/16310/ayaskant19.html" nodeid="16310"&gt;@Ayaskant Das&lt;/A&gt;&lt;P&gt;@Joe Petro&lt;/P&gt;&lt;P&gt;NiFi must be secured to run over HTTPS using a server certificates (loaded into a keystore) and a truststore before you can enable some form of user authentication.

You can create your own keystore and truststore using the below procedure:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.hortonworks.com/articles/17293/how-to-create-user-generated-keys-for-securing-nif.html" target="_blank"&gt;https://community.hortonworks.com/articles/17293/how-to-create-user-generated-keys-for-securing-nif.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Note: If you are going to be using LDAP or Kerberos for user authentication, you can skip the last part of the above procedure about generating a user SSL certificate to load in your browser.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 05:12:40 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-display-a-NiFi-login-window-for-http-web-browser/m-p/138376#M101007</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2017-03-07T05:12:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to display a NiFi login window for http web browser</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-display-a-NiFi-login-window-for-http-web-browser/m-p/138377#M101008</link>
      <description>&lt;P&gt;Thanks, I don't understand why NiFi wouldn't have a default login page for an admin user. It seems strange that no user login is required on http and can only be done via https. Every other HDP component has at least a basic UI login. &lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 03:50:45 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-display-a-NiFi-login-window-for-http-web-browser/m-p/138377#M101008</guid>
      <dc:creator>jpetro416</dc:creator>
      <dc:date>2017-03-09T03:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to display a NiFi login window for http web browser</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-display-a-NiFi-login-window-for-http-web-browser/m-p/138378#M101009</link>
      <description>&lt;P&gt;A default login page for an admin user served over HTTP provides the illusion of security -- &lt;EM&gt;security theater&lt;/EM&gt; -- but does absolutely nothing to improve the security of the system while adding obstacles to ease of use. &lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 07:17:54 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-display-a-NiFi-login-window-for-http-web-browser/m-p/138378#M101009</guid>
      <dc:creator>alopresto</dc:creator>
      <dc:date>2017-03-09T07:17:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to display a NiFi login window for http web browser</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-display-a-NiFi-login-window-for-http-web-browser/m-p/138379#M101010</link>
      <description>&lt;P&gt;That is true, but some times such an option can be good for a little access control and avoiding not seriously harmfull but unwanted activities on the server.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Nov 2018 00:37:51 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-display-a-NiFi-login-window-for-http-web-browser/m-p/138379#M101010</guid>
      <dc:creator>siddpande</dc:creator>
      <dc:date>2018-11-24T00:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to display a NiFi login window for http web browser</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-display-a-NiFi-login-window-for-http-web-browser/m-p/138380#M101011</link>
      <description>&lt;P&gt;We fundamentally disagree on the utility and value of that feature. Providing a login page which does not secure the transmission of sensitive credentials against trivial intercept and can be bypassed easily does not provide sufficient value and leads to a number of problems:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Users will assume it is secure and not change it from the default/configure stronger login options such as LDAP/Kerberos/client certificate authentication. We make a conscious effort not to offer weak security options as defaults because many users are unaware and will not change them&lt;/LI&gt;&lt;LI&gt;Users will not be aware that the credentials can be intercepted and stolen (these credentials may be reused from other applications and pose a large threat)&lt;/LI&gt;&lt;LI&gt;Users will not be aware that the login page can be bypassed (HTTP traffic can be monitored, and any credentials or tokens (NiFi is stateless, so it does not use session identifiers) can be intercepted and reused)&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;For these reasons, NiFi does not offer an option for authentication or authorization controls over plaintext HTTP. HTTPS &lt;EM&gt;must&lt;/EM&gt; be configured to enable those mechanisms to avoid a false sense of security and prevent user/admin complacency. &lt;/P&gt;</description>
      <pubDate>Wed, 28 Nov 2018 02:54:58 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-display-a-NiFi-login-window-for-http-web-browser/m-p/138380#M101011</guid>
      <dc:creator>alopresto</dc:creator>
      <dc:date>2018-11-28T02:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to display a NiFi login window for http web browser</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-display-a-NiFi-login-window-for-http-web-browser/m-p/138381#M101012</link>
      <description>&lt;P&gt;If that's the case, then why does Ambari have a login page without https? Sometimes it's useful to setup the login first, then add a security layer. It helps with troubleshooting and not having a login for Ambari (for example) would be confusing! So why is this any different?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2018 03:55:37 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-display-a-NiFi-login-window-for-http-web-browser/m-p/138381#M101012</guid>
      <dc:creator>jpetro416</dc:creator>
      <dc:date>2018-11-29T03:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to display a NiFi login window for http web browser</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-display-a-NiFi-login-window-for-http-web-browser/m-p/138382#M101013</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/13322/jpetro416.html" nodeid="13322" target="_blank"&gt;@Joe P&lt;/A&gt; I cannot reply to your comment for some reason, so I'm putting my response here. &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="94407-screen-shot-2018-11-28-at-121109-pm.png" style="width: 1708px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/21912i13F6B4D6769C1A71/image-size/medium?v=v2&amp;amp;px=400" role="button" title="94407-screen-shot-2018-11-28-at-121109-pm.png" alt="94407-screen-shot-2018-11-28-at-121109-pm.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I do not set the security policy for Ambari or any other Apache project. Every project evaluates security differently and makes decisions to reach a balance they find acceptable. &lt;/P&gt;&lt;P&gt;I am only one member of the NiFi community as well, but our community has agreed on this policy for NiFi. We invite all community members and users to contribute ideas and engage in discussion on design decisions. You are welcome to request the changes you want, but I will say that the previous discussion around that obviously went in this direction and I don't see any new information in your position than was previously discussed. &lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 08:37:34 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-display-a-NiFi-login-window-for-http-web-browser/m-p/138382#M101013</guid>
      <dc:creator>alopresto</dc:creator>
      <dc:date>2019-08-19T08:37:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to display a NiFi login window for http web browser</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-display-a-NiFi-login-window-for-http-web-browser/m-p/138383#M101014</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/13322/jpetro416.html" nodeid="13322"&gt;@Joe P&lt;/A&gt; did you set up https  i.e. did you enable SSL on the server?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2019 19:43:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-display-a-NiFi-login-window-for-http-web-browser/m-p/138383#M101014</guid>
      <dc:creator>sriramhadoop27</dc:creator>
      <dc:date>2019-02-12T19:43:38Z</dc:date>
    </item>
  </channel>
</rss>

