<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Nifi Registry + openid ? in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Registry-openid/m-p/290769#M215086</link>
    <description>&lt;P&gt;Hi, is there a way to login to NiFi registry via openid (ej google)?&lt;/P&gt;&lt;P&gt;I'm thinking of how I can secure the instance without a domain like in NiFi&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Sun, 01 Mar 2020 22:14:16 GMT</pubDate>
    <dc:creator>Alexandros</dc:creator>
    <dc:date>2020-03-01T22:14:16Z</dc:date>
    <item>
      <title>Nifi Registry + openid ?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Registry-openid/m-p/290769#M215086</link>
      <description>&lt;P&gt;Hi, is there a way to login to NiFi registry via openid (ej google)?&lt;/P&gt;&lt;P&gt;I'm thinking of how I can secure the instance without a domain like in NiFi&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 01 Mar 2020 22:14:16 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-Registry-openid/m-p/290769#M215086</guid>
      <dc:creator>Alexandros</dc:creator>
      <dc:date>2020-03-01T22:14:16Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi Registry + openid ?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Registry-openid/m-p/290935#M215202</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/70892"&gt;@Alexandros&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Securing NiFi and NiFi-registry will always require TLS certificates.&amp;nbsp; There are then numerous options for authentication in to those secured sevices.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Both NiFi and NiFi Registry both offer:&lt;BR /&gt;&lt;BR /&gt;1. User based certificate authentication.&amp;nbsp; You would need to create a user certificate for each user who will access NiFi or NiFi-registry&lt;BR /&gt;2. Spnego - This requires that you have a KDC and your users have Spnego enabled in their browser&lt;BR /&gt;3. LDAP/AD user authentication.&amp;nbsp; You would need to have your own LDAP/AD setup which you can use to authenticate your users.&lt;BR /&gt;4. kerberos login provider.&amp;nbsp; This would require you to setup your own KDC as well.&lt;BR /&gt;&lt;BR /&gt;NiFi also supports OpenID connect compatible service based authentication; however, the same is not offered in NiFi-Registry.&amp;nbsp; The jira for adding OpenID connect capability to NiFi-Registry is still open here:&lt;BR /&gt;&lt;A href="https://issues.apache.org/jira/browse/NIFIREG-313" target="_blank"&gt;https://issues.apache.org/jira/browse/NIFIREG-313&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;So based on options above and depending on the number of users you want to give access to, your best options are either by issuing each of your users a user/client certificate or setting up a simple LDAP server or KDC server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 22:02:45 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-Registry-openid/m-p/290935#M215202</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2020-03-03T22:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi Registry + openid ?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Registry-openid/m-p/339842#M233193</link>
      <description>&lt;P&gt;By checking the status of&amp;nbsp;&lt;A href="https://issues.apache.org/jira/browse/NIFIREG-313," target="_blank"&gt;https://issues.apache.org/jira/browse/NIFIREG-313,&lt;/A&gt;&amp;nbsp;it seems that the feature of authenticating using OIDC for nifi registry is already resolved as of 9/14/2020.&lt;BR /&gt;&lt;BR /&gt;But In nifi registry admin guide at&amp;nbsp;&lt;A href="https://nifi.apache.org/docs/nifi-registry-docs/index.html," target="_blank"&gt;https://nifi.apache.org/docs/nifi-registry-docs/index.html,&lt;/A&gt;&amp;nbsp;it still mentions that only LDAP and Kerberos are supported. Is the document up-to-date?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 15:35:47 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-Registry-openid/m-p/339842#M233193</guid>
      <dc:creator>myuintelli2021</dc:creator>
      <dc:date>2022-03-28T15:35:47Z</dc:date>
    </item>
  </channel>
</rss>

