<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: LDAP Authentication Issue in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233934#M195755</link>
    <description>&lt;P&gt;@Wynner ,&lt;/P&gt;&lt;P&gt;Sorry , i missed it..Thanks a lot..&lt;/P&gt;&lt;P&gt;now i am getting &lt;/P&gt;&lt;P&gt;insufficient permissions error ..let me check in my user..&lt;/P&gt;&lt;BR /&gt;&lt;IMG src="https://community.cloudera.com/t5/image/serverpage/image-id/7710iB8322259B0FE33E7/image-size/large?v=1.0&amp;amp;px=999" border="0" alt="ldap1.png" title="ldap1.png" /&gt;</description>
    <pubDate>Wed, 30 Aug 2017 01:37:22 GMT</pubDate>
    <dc:creator>saikrishna_tara</dc:creator>
    <dc:date>2017-08-30T01:37:22Z</dc:date>
    <item>
      <title>LDAP Authentication Issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233925#M195746</link>
      <description>&lt;P&gt;Hi,I am trying to configure LDAP authentication to our NiFi instance, I am using SIMPLE authentication strategy , with the below settings.&lt;/P&gt;&lt;P&gt; &amp;lt;provider&amp;gt;
        &amp;lt;identifier&amp;gt;ldap-provider&amp;lt;/identifier&amp;gt;&lt;/P&gt;&lt;P&gt;
        &amp;lt;class&amp;gt;org.apache.nifi.ldap.LdapProvider&amp;lt;/class&amp;gt;&lt;/P&gt;&lt;P&gt;
        &amp;lt;property name="Authentication Strategy"&amp;gt;SIMPLE&amp;lt;/property&amp;gt; &lt;/P&gt;&lt;P&gt;        &amp;lt;property name="Manager DN"&amp;gt;CN=admintarapare,OU=Admins,OU=Users and Groups,OU=GC AMS,OU=AMS,OU=Organizations,DC=mycompany,DC=com&amp;gt;&amp;lt;/property&amp;gt;&lt;/P&gt;&lt;P&gt;
        &amp;lt;property name="Manager Password"&amp;gt;mypwd&amp;gt;&amp;lt;/property&amp;gt; &lt;/P&gt;&lt;P&gt;        &amp;lt;property name="TLS - Keystore"&amp;gt;&amp;lt;/property&amp;gt; &lt;/P&gt;&lt;P&gt;        &amp;lt;property name="TLS - Keystore Password"&amp;gt;&amp;lt;/property&amp;gt; &lt;/P&gt;&lt;P&gt;        &amp;lt;property name="TLS - Keystore Type"&amp;gt;&amp;lt;/property&amp;gt; &lt;/P&gt;&lt;P&gt;        &amp;lt;property name="TLS - Truststore"&amp;gt;&amp;lt;/property&amp;gt;&lt;/P&gt;&lt;P&gt;
        &amp;lt;property name="TLS - Truststore Password"&amp;gt;&amp;lt;/property&amp;gt;&lt;/P&gt;&lt;P&gt;
        &amp;lt;property name="TLS - Truststore Type"&amp;gt;&amp;lt;/property&amp;gt; &lt;/P&gt;&lt;P&gt;        &amp;lt;property name="TLS - Client Auth"&amp;gt;&amp;lt;/property&amp;gt; &lt;/P&gt;&lt;P&gt;        &amp;lt;property name="TLS - Protocol"&amp;gt;&amp;lt;/property&amp;gt; &lt;/P&gt;&lt;P&gt;        &amp;lt;property name="TLS - Shutdown Gracefully"&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;/property&amp;gt;
        &amp;lt;property name="Referral Strategy"&amp;gt;FOLLOW&amp;lt;/property&amp;gt; &lt;/P&gt;&lt;P&gt;        &amp;lt;property name="Connect Timeout"&amp;gt;10 secs&amp;lt;/property&amp;gt; &lt;/P&gt;&lt;P&gt;        &amp;lt;property name="Read Timeout"&amp;gt;10 secs&amp;lt;/property&amp;gt; &lt;/P&gt;&lt;P&gt;        &amp;lt;property name="Url"&amp;gt;ldap://ourserver:389&amp;lt;/property&amp;gt; &lt;/P&gt;&lt;P&gt;        &amp;lt;property name="User Search Base"&amp;gt;OU=Admins,OU=Users and Groups,OU=GC AMS,OU=AMS,OU=Organizations,DC=mycompany,DC=com&amp;gt;&amp;lt;/property&amp;gt; &lt;/P&gt;&lt;P&gt;        &amp;lt;property name="User Search Filter"&amp;gt;sAMAccountName={0}&amp;lt;/property&amp;gt; &lt;/P&gt;&lt;P&gt;        &amp;lt;property name="Identity Strategy"&amp;gt;USE_DN&amp;lt;/property&amp;gt;
        &amp;lt;property name="Authentication Expiration"&amp;gt;12 hours&amp;lt;/property&amp;gt;
    &amp;lt;/provider&amp;gt;&lt;/P&gt;&lt;P&gt;i am not getting any exception in the nifi-app.log, but getting this in nifi-user.log &lt;/P&gt;&lt;P&gt;o.a.n.w.a.c.IllegalArgumentExceptionMapper java.lang.IllegalArgumentException: The supplied username and password are not valid.. Returning Bad Request response.&lt;/P&gt;&lt;P&gt;I am using this user admintarapare(which i used in my Manager CN) to login and i know the pwd is correct and i used LDP on my server to verify its connecting to the LDAP server.&lt;/P&gt;&lt;P&gt;Any idea on what i am doing wrong here.?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sai&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 04:08:33 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233925#M195746</guid>
      <dc:creator>saikrishna_tara</dc:creator>
      <dc:date>2017-08-29T04:08:33Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication Issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233926#M195747</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/11732/saikrishnatarapareddy.html" nodeid="11732"&gt;@Saikrishna Tarapareddy&lt;/A&gt;&lt;P&gt;Try changing the User Search Filter from sAMAccountName={0}  to (sAMAccountName={0})&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 00:38:02 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233926#M195747</guid>
      <dc:creator>Wynner</dc:creator>
      <dc:date>2017-08-30T00:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication Issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233927#M195748</link>
      <description>&lt;P&gt;@wynner ,&lt;/P&gt;&lt;P&gt;I am getting the same error after changing sAMAccountName={0} to (sAMAccountName={0})&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 00:52:56 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233927#M195748</guid>
      <dc:creator>saikrishna_tara</dc:creator>
      <dc:date>2017-08-30T00:52:56Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication Issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233928#M195749</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/11732/saikrishnatarapareddy.html" nodeid="11732"&gt;@Saikrishna Tarapareddy&lt;/A&gt;&lt;P&gt;Just to be sure. Did you restart NiFi after making the change?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 00:56:13 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233928#M195749</guid>
      <dc:creator>Wynner</dc:creator>
      <dc:date>2017-08-30T00:56:13Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication Issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233929#M195750</link>
      <description>&lt;P&gt;@Wynner ,&lt;/P&gt;&lt;P&gt;Yes , i did.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 01:01:37 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233929#M195750</guid>
      <dc:creator>saikrishna_tara</dc:creator>
      <dc:date>2017-08-30T01:01:37Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication Issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233930#M195751</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/11732/saikrishnatarapareddy.html" nodeid="11732"&gt;@Saikrishna Tarapareddy&lt;/A&gt;&lt;P&gt;Another just to be sure, you have an extra character at the end of a couple of the properties.&lt;/P&gt;&lt;P&gt;This property appears to have an extra character&lt;/P&gt;&lt;P&gt;Manager DN&lt;/P&gt;&lt;P&gt;CN=admintarapare,OU=Admins,OU=Users and Groups,OU=GC AMS,OU=AMS,OU=Organizations,DC=mycompany,DC=com&amp;gt;&lt;/P&gt;&lt;P&gt;and this property also&lt;/P&gt;&lt;P&gt;User Search Base&lt;/P&gt;&lt;P&gt;OU=Admins,OU=Users and Groups,OU=GC AMS,OU=AMS,OU=Organizations,DC=mycompany,DC=com&amp;gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 01:09:11 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233930#M195751</guid>
      <dc:creator>Wynner</dc:creator>
      <dc:date>2017-08-30T01:09:11Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication Issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233931#M195752</link>
      <description>&lt;P&gt;@Wynner,&lt;/P&gt;&lt;P&gt;i do not have any extra chars , i just double checked..&lt;/P&gt;&lt;P&gt;&amp;lt;property name="Manager DN"&amp;gt;CN=admintarapa,OU=Admins,OU=Users and Groups,OU=GC AMS,OU=AMS,OU=Organizations,DC=mycomp,DC=com&amp;gt;&amp;lt;/property&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;lt;property name="User Search Base"&amp;gt;OU=Admins,OU=Users and Groups,OU=GC AMS,OU=AMS,OU=Organizations,DC=mycomp,DC=com&amp;gt;&amp;lt;/property&amp;gt;&lt;/P&gt;&lt;P&gt;One interesting thing is , i tried with wrong password for my manager DN in the login-identity-providers.xml file , even then i get the same error. &lt;/P&gt;&lt;P&gt;o.a.n.w.a.c.IllegalArgumentExceptionMapper java.lang.IllegalArgumentException: The supplied username and password are not valid.. Returning Bad Request response.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sai&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 01:20:33 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233931#M195752</guid>
      <dc:creator>saikrishna_tara</dc:creator>
      <dc:date>2017-08-30T01:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication Issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233932#M195753</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/11732/saikrishnatarapareddy.html" nodeid="11732"&gt;@Saikrishna Tarapareddy&lt;/A&gt;
&lt;/P&gt;&lt;P&gt;There is an extra character at the end of both of those properties.&lt;/P&gt;&lt;P&gt;"&amp;gt;" this is the extra character, on the end of your value.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 01:27:19 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233932#M195753</guid>
      <dc:creator>Wynner</dc:creator>
      <dc:date>2017-08-30T01:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication Issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233933#M195754</link>
      <description>&lt;P&gt;If your password has any unique characters such as "&lt;STRONG&gt;&amp;amp;"  &lt;/STRONG&gt;it will break the XML&lt;/P&gt;&lt;P&gt;The fix for this example would be changing the &lt;STRONG&gt;&amp;amp; &lt;/STRONG&gt;to:&lt;STRONG&gt; &lt;/STRONG&gt;"&lt;STRONG&gt;&amp;amp; amp;&lt;/STRONG&gt;"  without the space (this website will not show the correct value).&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 01:28:00 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233933#M195754</guid>
      <dc:creator>jpetro416</dc:creator>
      <dc:date>2017-08-30T01:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication Issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233934#M195755</link>
      <description>&lt;P&gt;@Wynner ,&lt;/P&gt;&lt;P&gt;Sorry , i missed it..Thanks a lot..&lt;/P&gt;&lt;P&gt;now i am getting &lt;/P&gt;&lt;P&gt;insufficient permissions error ..let me check in my user..&lt;/P&gt;&lt;BR /&gt;&lt;IMG src="https://community.cloudera.com/t5/image/serverpage/image-id/7710iB8322259B0FE33E7/image-size/large?v=1.0&amp;amp;px=999" border="0" alt="ldap1.png" title="ldap1.png" /&gt;</description>
      <pubDate>Wed, 30 Aug 2017 01:37:22 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233934#M195755</guid>
      <dc:creator>saikrishna_tara</dc:creator>
      <dc:date>2017-08-30T01:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication Issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233935#M195756</link>
      <description>&lt;P&gt;@Wynner, &lt;/P&gt;&lt;P&gt;its working now .&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Sai&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 02:15:14 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233935#M195756</guid>
      <dc:creator>saikrishna_tara</dc:creator>
      <dc:date>2017-08-30T02:15:14Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication Issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233936#M195757</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/286/dwynne.html" nodeid="286"&gt;@Wynner&lt;/A&gt; ,&lt;/P&gt;&lt;P&gt;i have another issue..while i was able to LDAP authenticate successfully using same OU values.&lt;/P&gt;&lt;P&gt;It is failing to authenticate when my Manager DN's OU is different than Users.&lt;/P&gt;&lt;P&gt;As per our company rule they create service accounts differently to regular user accounts. and we want to use service account as Initial Admin and Manager as shown below..&lt;/P&gt;&lt;P&gt;Only way i could solve this is by&lt;/P&gt;&lt;P&gt;1. In login-identity-providers.xml have Manager DN and User Search Base's OU same.&lt;/P&gt;&lt;P&gt;in my case (ou=Generic-Users,ou=Users and Groups,ou=NPPC AMS,ou=AMS,ou=Organizations,dc=mycomp,dc=com) &lt;/P&gt;&lt;P&gt;2. Start NiFi and log in as Initial Admin . &lt;/P&gt;&lt;P&gt;3. from NiFi UI , create an user with my users DN  like (OU=US-StLouis-HQ,OU=Users and Groups,OU=NPPC AMS,OU=AMS,OU=Organizations,DC=mycomp,DC=com)  , this is how general users DN looks.&lt;/P&gt;&lt;P&gt;4. in login-identity-providers.xml change the user search base to match with step 3 &lt;/P&gt;&lt;P&gt;5. restart NiFi &lt;/P&gt;&lt;P&gt;6. Login as user&lt;/P&gt;&lt;P&gt;Managers DN:&lt;/P&gt;&lt;P&gt;&amp;lt;property name="Manager DN"&amp;gt;cn=nifiadmin,ou=Generic-Users,ou=Users and Groups,ou=NPPC AMS,ou=AMS,ou=Organizations,dc=mycomp,dc=com&amp;lt;/property&amp;gt;&lt;/P&gt;&lt;P&gt;User Search base:&lt;/P&gt;&lt;P&gt;&amp;lt;property name="User Search Base"&amp;gt;OU=US-StLouis-HQ,OU=Users and Groups,OU=NPPC AMS,OU=AMS,OU=Organizations,DC=mycomp,DC=com&amp;lt;/property&amp;gt;&lt;/P&gt;&lt;P&gt;Is there a better way.? this way i will have to go back and forth when i have to add a new user or grant an user with create user policy and use that user to create new users instead of initial admin.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sai&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 01:44:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233936#M195757</guid>
      <dc:creator>saikrishna_tara</dc:creator>
      <dc:date>2017-08-31T01:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication Issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233937#M195758</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/11732/saikrishnatarapareddy.html" nodeid="11732"&gt;@Saikrishna Tarapareddy&lt;/A&gt;&lt;P&gt;This should be a different question, not a continuation of your first question.&lt;/P&gt;&lt;P&gt;Because, now you are asking about authorization, not authentication.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 02:03:46 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233937#M195758</guid>
      <dc:creator>Wynner</dc:creator>
      <dc:date>2017-08-31T02:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication Issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233938#M195759</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/11732/saikrishnatarapareddy.html" nodeid="11732"&gt;@Saikrishna Tarapareddy&lt;/A&gt; &lt;/P&gt;&lt;P&gt;Look at this article, it should help you:  &lt;A href="https://community.hortonworks.com/articles/85306/how-to-simplify-user-management-in-nifi-through-us.html"&gt;User management in NiFi through identity mapping patterns&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 04:12:05 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-Authentication-Issue/m-p/233938#M195759</guid>
      <dc:creator>Wynner</dc:creator>
      <dc:date>2017-08-31T04:12:05Z</dc:date>
    </item>
  </channel>
</rss>

