<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Securing NiFi - Cannot see UI in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Securing-NiFi-Cannot-see-UI/m-p/283258#M210542</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/71309"&gt;@frassis&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The error message you have encountered indicates and issue with the certificates you are using to secure your NiFi nodes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;javax.net.ssl.SSLPeerUnverifiedException: Hostname &amp;lt;my_fqdn_is_here&amp;gt; not verified: certificate: sha256/716mOuXyoAKqzNrXrNnG2ozHXwN8WWJsVxzWzfQzpNV= DN: CN=xxx-xxxx-xxxx.xxx.xxx.net, OU=XXXXXXXXX XXXXXX, O=XXXXX, L=XXXXXX, ST=XXXXXX XXXXX, C=CA subjectAltNames: [] &lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;Jetty no longer uses the DN to verify hostnames and now requires that the certificates include at least 1 Subject Alternative Name (SAN) entry that matches the hostname of the server on which it is being used.&lt;BR /&gt;&lt;BR /&gt;As you can see from the ERROR output, it indicates you have no SAN entries in your cert.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;subjectAltNames: []&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You will need to generate new certificates and keystores for your NiFi nodes.&lt;BR /&gt;When doing so keep in mind the following:&lt;BR /&gt;1. Keystore may contain ONLY 1 PrivateKeyEntry&lt;BR /&gt;2. The PrivateKeyEntry MUST support both "clientAuth" and "serverAuth"&lt;BR /&gt;3. The PrivateKeyEntry MUST contain at least 1 SAN entry matching the hostname of the server where keystore will be used.&lt;BR /&gt;4. The Keystore and Key passwords must be the same. Or no key password set.&lt;BR /&gt;&lt;BR /&gt;Thank you,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
    <pubDate>Mon, 18 Nov 2019 13:49:19 GMT</pubDate>
    <dc:creator>MattWho</dc:creator>
    <dc:date>2019-11-18T13:49:19Z</dc:date>
    <item>
      <title>Securing NiFi - Cannot see UI</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Securing-NiFi-Cannot-see-UI/m-p/283129#M210447</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have been struggling for the past 3 weeks trying to secure a cluster.&lt;/P&gt;
&lt;P&gt;We have 3 nodes. They were working ok in a cluster (but not secured).&lt;/P&gt;
&lt;P&gt;When trying to secure those (and following the guide suggested here), we came across the following message when trying to access the UI:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;javax.net.ssl.SSLPeerUnverifiedException: Hostname &amp;lt;my_fqdn_is_here&amp;gt; not verified: certificate: sha256/716mOuXyoAKqzNrXrNnG2ozHXwN8WWJsVxzWzfQzpNV= DN: CN=xxx-xxxx-xxxx.xxx.xxx.net, OU=XXXXXXXXX XXXXXX, O=XXXXX, L=XXXXXX, ST=XXXXXX XXXXX, C=CA subjectAltNames: []&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We've been going over and over the configs and nothing seems to point to the right direction.&lt;BR /&gt;&lt;BR /&gt;Would anyone point us to at least the right direction?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2019 23:09:05 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Securing-NiFi-Cannot-see-UI/m-p/283129#M210447</guid>
      <dc:creator>frassis</dc:creator>
      <dc:date>2019-11-15T23:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: Securing NiFi - Cannot see UI</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Securing-NiFi-Cannot-see-UI/m-p/283137#M210454</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/71309"&gt;@frassis&lt;/a&gt;&amp;nbsp;You wrote that you were "&lt;SPAN&gt;&amp;nbsp;following the guide suggested here", but there was no indication as to what guide you were actually following. Did you perhaps forget the hyperlink?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2019 23:12:31 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Securing-NiFi-Cannot-see-UI/m-p/283137#M210454</guid>
      <dc:creator>ask_bill_brooks</dc:creator>
      <dc:date>2019-11-15T23:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: Securing NiFi - Cannot see UI</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Securing-NiFi-Cannot-see-UI/m-p/283258#M210542</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/71309"&gt;@frassis&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The error message you have encountered indicates and issue with the certificates you are using to secure your NiFi nodes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;javax.net.ssl.SSLPeerUnverifiedException: Hostname &amp;lt;my_fqdn_is_here&amp;gt; not verified: certificate: sha256/716mOuXyoAKqzNrXrNnG2ozHXwN8WWJsVxzWzfQzpNV= DN: CN=xxx-xxxx-xxxx.xxx.xxx.net, OU=XXXXXXXXX XXXXXX, O=XXXXX, L=XXXXXX, ST=XXXXXX XXXXX, C=CA subjectAltNames: [] &lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;Jetty no longer uses the DN to verify hostnames and now requires that the certificates include at least 1 Subject Alternative Name (SAN) entry that matches the hostname of the server on which it is being used.&lt;BR /&gt;&lt;BR /&gt;As you can see from the ERROR output, it indicates you have no SAN entries in your cert.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;subjectAltNames: []&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You will need to generate new certificates and keystores for your NiFi nodes.&lt;BR /&gt;When doing so keep in mind the following:&lt;BR /&gt;1. Keystore may contain ONLY 1 PrivateKeyEntry&lt;BR /&gt;2. The PrivateKeyEntry MUST support both "clientAuth" and "serverAuth"&lt;BR /&gt;3. The PrivateKeyEntry MUST contain at least 1 SAN entry matching the hostname of the server where keystore will be used.&lt;BR /&gt;4. The Keystore and Key passwords must be the same. Or no key password set.&lt;BR /&gt;&lt;BR /&gt;Thank you,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2019 13:49:19 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Securing-NiFi-Cannot-see-UI/m-p/283258#M210542</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2019-11-18T13:49:19Z</dc:date>
    </item>
    <item>
      <title>Re: Securing NiFi - Cannot see UI</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Securing-NiFi-Cannot-see-UI/m-p/283408#M210647</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35454"&gt;@MattWho&lt;/a&gt;, thank you very much for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Quick question, how do you determine if the&amp;nbsp;&lt;SPAN&gt;PrivateKeyEntry supports both?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;The PrivateKeyEntry MUST support both "clientAuth" and "serverAuth""?&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I don't see this when i use keytool -v&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 19:34:04 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Securing-NiFi-Cannot-see-UI/m-p/283408#M210647</guid>
      <dc:creator>gdizzz</dc:creator>
      <dc:date>2019-11-19T19:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: Securing NiFi - Cannot see UI</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Securing-NiFi-Cannot-see-UI/m-p/284560#M211295</link>
      <description>&lt;P&gt;Thanks Matt,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With new certs, like you mentioned, we were able to make it work.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2019 19:19:40 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Securing-NiFi-Cannot-see-UI/m-p/284560#M211295</guid>
      <dc:creator>frassis</dc:creator>
      <dc:date>2019-12-02T19:19:40Z</dc:date>
    </item>
  </channel>
</rss>

