<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Nifi Integration with Ranger Not Working in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217332#M179241</link>
    <description>&lt;P&gt;&lt;A href="https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html" target="_blank"&gt;https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;NiFi even provides a toolkit you can use to create your own certificates/keystores for each of your NiFi nodes.&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
    <pubDate>Fri, 08 Jun 2018 23:25:21 GMT</pubDate>
    <dc:creator>MattWho</dc:creator>
    <dc:date>2018-06-08T23:25:21Z</dc:date>
    <item>
      <title>Nifi Integration with Ranger Not Working</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217321#M179230</link>
      <description>&lt;P&gt;HI All,&lt;/P&gt;&lt;P&gt;In our cluster NIFI is SSL enabled. Ranger is not SSL enabled. Both NIFI and Ranger are integrated with AD/LDAP.&lt;/P&gt;&lt;P&gt;Before enabling NIFI plugin in Ranger, our AD/LDAP users are able to see NIFI UI.&lt;/P&gt;&lt;P&gt;But after enabling NIFI plugin in Ranger, our AD/LDAP users are not able to see NIFI UI.&lt;/P&gt;&lt;P&gt;We are getting following message on NIFI screen:&lt;/P&gt;&lt;PRE&gt;Insufficient Permissions
   
Untrusted proxy CN=*.test.com, OU=NIFI&lt;/PRE&gt;&lt;P&gt;nifi-user.log shows Authentication success but Untrusted proxy  error as follows:&lt;/P&gt;&lt;PRE&gt;2018-06-07 07:00:13,447 INFO [NiFi Web Server-19] o.a.n.w.s.NiFiAuthenticationFilter Attempting request for (&amp;lt;JWT token&amp;gt;) GET &lt;A href="https://usdf24v0075.test.com:9091/nifi-api/flow/current-user" target="_blank"&gt;https://usdf24v0075.test.com:9091/nifi-api/flow/current-user&lt;/A&gt; (source ip: 10.23.118.51)
2018-06-07 07:00:13,449 INFO [NiFi Web Server-19] o.a.n.w.s.NiFiAuthenticationFilter Authentication success for test-user
2018-06-07 07:00:13,612 INFO [NiFi Web Server-18] o.a.n.w.s.NiFiAuthenticationFilter Attempting request for (&amp;lt;test-user&amp;gt;&amp;lt;CN=*.test.com, OU=NIFI&amp;gt;) GET &lt;A href="https://usdf24v0075.test.com:9091/nifi-api/flow/current-user" target="_blank"&gt;https://usdf24v0075.test.com:9091/nifi-api/flow/current-user&lt;/A&gt; (source ip: 10.23.132.140)
2018-06-07 07:00:13,615 WARN [NiFi Web Server-18] o.a.n.w.s.NiFiAuthenticationFilter Rejecting access to web api: Untrusted proxy CN=*.test.com, OU=NIFI

&lt;/PRE&gt;&lt;P&gt;I have also deleted authorizers.xml and users.xml file from NIFI node and restarted NIFI as well.&lt;/P&gt;&lt;P&gt;How to resolve it.?&lt;/P&gt;&lt;P&gt;Please suggest.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 15:11:21 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217321#M179230</guid>
      <dc:creator>bkandalkar</dc:creator>
      <dc:date>2018-06-07T15:11:21Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi Integration with Ranger Not Working</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217322#M179231</link>
      <description>&lt;P&gt;Hi &lt;A rel="user" href="https://community.cloudera.com/users/29224/kandalkarbhushan.html" nodeid="29224"&gt;@Bhushan Kandalkar&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Have you added Ranger policies to let users see the UI : &lt;A href="https://docs.hortonworks.com/HDPDocuments/HDF3/HDF-3.1.2/bk_security/content/policies-to-view-nifi.html" target="_blank"&gt;https://docs.hortonworks.com/HDPDocuments/HDF3/HDF-3.1.2/bk_security/content/policies-to-view-nifi.html&lt;/A&gt; ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 15:15:44 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217322#M179231</guid>
      <dc:creator>ahadjidj</dc:creator>
      <dc:date>2018-06-07T15:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi Integration with Ranger Not Working</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217323#M179232</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/2056/ahadjidj.html" nodeid="2056"&gt;@Abdelkrim Hadjidj&lt;/A&gt; &lt;/P&gt;&lt;P&gt;Yes, I have added Ranger policies for user to see UI. Still getting same exception.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 15:28:44 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217323#M179232</guid>
      <dc:creator>bkandalkar</dc:creator>
      <dc:date>2018-06-07T15:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi Integration with Ranger Not Working</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217324#M179233</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/29224/kandalkarbhushan.html" nodeid="29224"&gt;@Bhushan Kandalka&lt;/A&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;Once the Ranger plugin is enabled, the authorizations.xml file is no longer used to determine what authorizations both users and Nifi nodes have.  &lt;/P&gt;&lt;P&gt;In a NiFi cluster each node must be authorized to act as a proxy so that requests made by users logged in to any one of the nodes's UIs can be replicated to the other nodes.&lt;/P&gt;&lt;P&gt;This means that you will need to set an authorization policy in Ranger that authorizes "CN=*.test.com, OU=NIFI" against the "/proxy" policy.&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 20:43:00 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217324#M179233</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2018-06-07T20:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi Integration with Ranger Not Working</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217325#M179234</link>
      <description>&lt;P&gt;What about proxy ? as you can see in the provided link &lt;/P&gt;&lt;P&gt;To allow users to view the NiFi UI, create the following policies for each host:&lt;/P&gt;&lt;UL&gt;
&lt;LI&gt;/flow – read&lt;/LI&gt;&lt;LI&gt;/proxy – read/write&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 07 Jun 2018 21:02:02 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217325#M179234</guid>
      <dc:creator>ahadjidj</dc:creator>
      <dc:date>2018-06-07T21:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi Integration with Ranger Not Working</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217326#M179235</link>
      <description>&lt;P&gt;&lt;A href="https://community.hortonworks.com/questions/196475/nifi-integration-with-ranger-not-working.html?childToView=196478#"&gt;@Matt Clarke&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Do I need to create "CN=*.&lt;A href="http://test.com/"&gt;test.com&lt;/A&gt;, OU=NIFI" user with password in Ranger and need to add "/proxy" policy for it? &lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 21:05:41 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217326#M179235</guid>
      <dc:creator>bkandalkar</dc:creator>
      <dc:date>2018-06-07T21:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi Integration with Ranger Not Working</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217327#M179236</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/29224/kandalkarbhushan.html" nodeid="29224"&gt;@Bhushan Kandalkar&lt;/A&gt;&lt;/P&gt;&lt;P&gt;That is correct.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 21:10:24 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217327#M179236</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2018-06-07T21:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi Integration with Ranger Not Working</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217328#M179237</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/525/mclarke.html" nodeid="525"&gt;@Matt Clarke&lt;/A&gt; &lt;/P&gt;&lt;P&gt;While adding "CN=*.&lt;A href="http://test.com/"&gt;test.com&lt;/A&gt;, OU=NIFI" user in Ranger its giving invalid username error. How to resolve it?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 21:30:15 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217328#M179237</guid>
      <dc:creator>bkandalkar</dc:creator>
      <dc:date>2018-06-07T21:30:15Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi Integration with Ranger Not Working</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217329#M179238</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/29224/kandalkarbhushan.html" nodeid="29224"&gt;@Bhushan Kandalkar&lt;/A&gt; &lt;/P&gt;&lt;P&gt;I was afraid of that.  Ranger does not allow wildcards in the user names.&lt;/P&gt;&lt;P&gt;From a security standpoint it is generally a bad idea to create a server certificate that uses wildcards.&lt;/P&gt;&lt;P&gt;In order to use Ranger as your authorizer, you are going to need to create new NiFi node certificates/keystores that do not use wildcards in the "Owner" DN.&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;This means you will have a unique keystore for each of your NiFi nodes (which is a security best practice).  You will then need to authorize each of those nodes with /proxy.&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 22:18:31 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217329#M179238</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2018-06-07T22:18:31Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi Integration with Ranger Not Working</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217330#M179239</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/525/mclarke.html" nodeid="525"&gt;@Matt Clarke&lt;/A&gt; &lt;/P&gt;&lt;P&gt;Could you please provide link about how to configure SSL for NIFI which have a unique keystore for each of your NiFi nodes and which authorizes using Ranger.It will be great if you provide that link.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 23:03:26 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217330#M179239</guid>
      <dc:creator>bkandalkar</dc:creator>
      <dc:date>2018-06-07T23:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi Integration with Ranger Not Working</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217331#M179240</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/29224/kandalkarbhushan.html" nodeid="29224"&gt;@Bhushan Kandalkar&lt;/A&gt;&lt;P&gt;Here a step by step doc : &lt;A href="https://community.hortonworks.com/articles/886/securing-nifi-step-by-step.html" target="_blank"&gt;https://community.hortonworks.com/articles/886/securing-nifi-step-by-step.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;And this the official doc : &lt;A href="https://docs.hortonworks.com/HDPDocuments/HDF3/HDF-3.1.1/bk_security/content/enabling-ssl-without-ca.html" target="_blank"&gt;https://docs.hortonworks.com/HDPDocuments/HDF3/HDF-3.1.1/bk_security/content/enabling-ssl-without-ca.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jun 2018 02:08:31 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217331#M179240</guid>
      <dc:creator>ahadjidj</dc:creator>
      <dc:date>2018-06-08T02:08:31Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi Integration with Ranger Not Working</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217332#M179241</link>
      <description>&lt;P&gt;&lt;A href="https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html" target="_blank"&gt;https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;NiFi even provides a toolkit you can use to create your own certificates/keystores for each of your NiFi nodes.&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jun 2018 23:25:21 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-Integration-with-Ranger-Not-Working/m-p/217332#M179241</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2018-06-08T23:25:21Z</dc:date>
    </item>
  </channel>
</rss>

