<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Integrate NIFI , NIFI Registry in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Integrate-NIFI-NIFI-Registry/m-p/300892#M220423</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/54111"&gt;@sunile_manjee&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;cluster A NIfi &amp;amp; Registry are managed by Ranger, working well.&lt;/P&gt;&lt;P&gt;hence I added cluster B nifi node cert to cluster A Ranger user and then added to Registry policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;clusterB nifi user logs:&lt;/P&gt;&lt;P&gt;2020-08-04 21:40:37,824 INFO [NiFi Web Server-333] o.a.n.w.s.NiFiAuthenticationFilter Authentication success for divya&lt;BR /&gt;2020-08-04 21:40:37,833 INFO [NiFi Web Server-333] o.a.n.w.a.config.NiFiCoreExceptionMapper org.apache.nifi.web.NiFiCoreException: Unable to obtain listing of buckets: javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path validation failed: java.security.cert.CertPathValidatorException: Path does not chain with any of the trust anchors. Returning Conflict response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NIFI GUI exception:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DivyaKaki_0-1596577319783.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/28471i3948F379086ADB7F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DivyaKaki_0-1596577319783.png" alt="DivyaKaki_0-1596577319783.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any advice&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Aug 2020 21:44:11 GMT</pubDate>
    <dc:creator>DivyaKaki</dc:creator>
    <dc:date>2020-08-04T21:44:11Z</dc:date>
    <item>
      <title>Integrate NIFI , NIFI Registry</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Integrate-NIFI-NIFI-Registry/m-p/300882#M220419</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I have HDF 3.4 cluster A with nifi and nifi registry integrated, cluster B with NIFI. both are tls/ssl secured. now I'm trying to use the cluster A NIFI registry for NIFI running on cluster B.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;noticing below error when trying to version a flow from cluster B NIFI&amp;nbsp; integrated with cluster A registry&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DivyaKaki_0-1596559594694.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/28469i5A92E9D6362BC6A5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DivyaKaki_0-1596559594694.png" alt="DivyaKaki_0-1596559594694.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have added cluster B nifi node cert to registry users list but still same error&lt;/P&gt;&lt;DIV class="td-data-table-cell"&gt;&lt;DIV class="ellipsis"&gt;CN=its-nifi-node-dev-nifipoc1-01, OU=NIFI&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/52489"&gt;@alim&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35454"&gt;@MattWho&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/54111"&gt;@sunile_manjee&lt;/a&gt;&amp;nbsp;please advice&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 16:52:31 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Integrate-NIFI-NIFI-Registry/m-p/300882#M220419</guid>
      <dc:creator>DivyaKaki</dc:creator>
      <dc:date>2020-08-04T16:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate NIFI , NIFI Registry</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Integrate-NIFI-NIFI-Registry/m-p/300884#M220421</link>
      <description>Do you have the ssl context service setup properly?&lt;BR /&gt;</description>
      <pubDate>Tue, 04 Aug 2020 17:31:45 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Integrate-NIFI-NIFI-Registry/m-p/300884#M220421</guid>
      <dc:creator>sunile_manjee</dc:creator>
      <dc:date>2020-08-04T17:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate NIFI , NIFI Registry</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Integrate-NIFI-NIFI-Registry/m-p/300892#M220423</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/54111"&gt;@sunile_manjee&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;cluster A NIfi &amp;amp; Registry are managed by Ranger, working well.&lt;/P&gt;&lt;P&gt;hence I added cluster B nifi node cert to cluster A Ranger user and then added to Registry policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;clusterB nifi user logs:&lt;/P&gt;&lt;P&gt;2020-08-04 21:40:37,824 INFO [NiFi Web Server-333] o.a.n.w.s.NiFiAuthenticationFilter Authentication success for divya&lt;BR /&gt;2020-08-04 21:40:37,833 INFO [NiFi Web Server-333] o.a.n.w.a.config.NiFiCoreExceptionMapper org.apache.nifi.web.NiFiCoreException: Unable to obtain listing of buckets: javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path validation failed: java.security.cert.CertPathValidatorException: Path does not chain with any of the trust anchors. Returning Conflict response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NIFI GUI exception:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DivyaKaki_0-1596577319783.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/28471i3948F379086ADB7F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DivyaKaki_0-1596577319783.png" alt="DivyaKaki_0-1596577319783.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any advice&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 21:44:11 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Integrate-NIFI-NIFI-Registry/m-p/300892#M220423</guid>
      <dc:creator>DivyaKaki</dc:creator>
      <dc:date>2020-08-04T21:44:11Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate NIFI , NIFI Registry</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Integrate-NIFI-NIFI-Registry/m-p/300898#M220427</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/54111"&gt;@sunile_manjee&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have generated certs for bothe cluster nifi, nifi registrty using below commands&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do i need to add jks from cluster A nifi to cluster B registry&lt;/P&gt;&lt;P&gt;sh /usr/hdf/current/nifi-toolkit/bin/tls-toolkit.sh standalone -B&amp;nbsp; myTokenTouse -C 'CN=nifiadmin, OU=NIFI' -n 'nifi-pb-amb-01.its-streaming,nifi-pb-nifi-01.its-streaming,nifi-pb-nifi-02.its-streaming,nifi-pb-nifi-03.its-streaming,nifi-pb-nreg-01.its-streaming'&amp;nbsp; --nifiDnPrefix 'CN=' --nifiDnSuffix ', OU=NIFI' -o /data/nifi_certs/ -K myTokenTouse -P myTokenTouse -S myTokenTouse&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 04:43:16 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Integrate-NIFI-NIFI-Registry/m-p/300898#M220427</guid>
      <dc:creator>DivyaKaki</dc:creator>
      <dc:date>2020-08-05T04:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate NIFI , NIFI Registry</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Integrate-NIFI-NIFI-Registry/m-p/301511#M220719</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/73471"&gt;@DivyaKaki&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The exception implies that the complete trust chain does not exist to facilitate a successful mutual TLS handshake between this NiFI and the target NiFi-Registry.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NiFi uses the keystore and truststore configured in its nifi.properties and NiFi-Registry uses the keystore and truststore configured in its nifi-registry.properties files.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Openssl can be used to public certificates for the complete trust chain:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;openssl s_client -connect &amp;lt;nifi-registry-hostname&amp;gt;:&amp;lt;port&amp;gt; -showcerts&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;openssl s_client -connect &amp;lt;nifi-hostname&amp;gt;:&amp;lt;port&amp;gt; -showcerts&lt;/LI-CODE&gt;&lt;P&gt;for each public cert you will see:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;-----BEGIN CERTIFICATE-----
MIIESjCCAzKgAwIBAgINAeO0mqGNiqmBJWlQuDANBgkqhkiG9w0BAQsFADBMMSAw
HgYDVQQLExdHbG9iYWxTaWduIFJvb3QgQ0EgLSBSMjETMBEGA1UEChMKR2xvYmFs
U2lnbjETMBEGA1UEAxMKR2xvYmFsU2lnbjAeFw0xNzA2MTUwMDAwNDJaFw0yMTEy
MTUwMDAwNDJaMEIxCzAJBgNVBAYTAlVTMR4wHAYDVQQKExVHb29nbGUgVHJ1c3Qg
U2VydmljZXMxEzARBgNVBAMTCkdUUyBDQSAxTzEwggEiMA0GCSqGSIb3DQEBAQUA
A4IBDwAwggEKAoIBAQDQGM9F1IvN05zkQO9+tN1pIRvJzzyOTHW5DzEZhD2ePCnv
UA0Qk28FgICfKqC9EksC4T2fWBYk/jCfC3R3VZMdS/dN4ZKCEPZRrAzDsiKUDzRr
mBBJ5wudgzndIMYcLe/RGGFl5yODIKgjEv/SJH/UL+dEaltN11BmsK+eQmMF++Ac
xGNhr59qM/9il71I2dN8FGfcddwuaej4bXhp0LcQBbjxMcI7JP0aM3T4I+DsaxmK
FsbjzaTNC9uzpFlgOIg7rR25xoynUxv8vNmkq7zdPGHXkxWY7oG9j+JkRyBABk7X
rJfoucBZEqFJJSPk7XA0LKW0Y3z5oz2D0c1tJKwHAgMBAAGjggEzMIIBLzAOBgNV
HQ8BAf8EBAMCAYYwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMBIGA1Ud
EwEB/wQIMAYBAf8CAQAwHQYDVR0OBBYEFJjR+G4Q68+b7GCfGJAboOt9Cf0rMB8G
A1UdIwQYMBaAFJviB1dnHB7AagbeWbSaLd/cGYYuMDUGCCsGAQUFBwEBBCkwJzAl
BggrBgEFBQcwAYYZaHR0cDovL29jc3AucGtpLmdvb2cvZ3NyMjAyBgNVHR8EKzAp
MCegJaAjhiFodHRwOi8vY3JsLnBraS5nb29nL2dzcjIvZ3NyMi5jcmwwPwYDVR0g
BDgwNjA0BgZngQwBAgIwKjAoBggrBgEFBQcCARYcaHR0cHM6Ly9wa2kuZ29vZy9y
ZXBvc2l0b3J5LzANBgkqhkiG9w0BAQsFAAOCAQEAGoA+Nnn78y6pRjd9XlQWNa7H
TgiZ/r3RNGkmUmYHPQq6Scti9PEajvwRT2iWTHQr02fesqOqBY2ETUwgZQ+lltoN
FvhsO9tvBCOIazpswWC9aJ9xju4tWDQH8NVU6YZZ/XteDSGU9YzJqPjY8q3MDxrz
mqepBCf5o8mw/wJ4a2G6xzUr6Fb6T8McDO22PLRL6u3M4Tzs3A2M1j6bykJYi8wW
IRdAvKLWZu/axBVbzYmqmwkm5zLSDW5nIAJbELCQCZwMH56t2Dvqofxs6BBcCFIZ
USpxu6x6td0V7SvJCCosirSmIatj/9dSSVDQibet8q/7UK4v4ZUN80atnZz1yg==
-----END CERTIFICATE-----&lt;/LI-CODE&gt;&lt;P&gt;Above is just example public cert from openssl command against google.com:443&lt;BR /&gt;&lt;BR /&gt;You will need to make sure that every certificate in the chain when run agains NiFi UI is added to the truststore on NiFi-Registry and vice versa.&lt;BR /&gt;&lt;BR /&gt;You'll need to restart NiFi and NiFi-Registry before changes to your keystore or truststore files will be read in.&lt;BR /&gt;&lt;BR /&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2020 13:37:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Integrate-NIFI-NIFI-Registry/m-p/301511#M220719</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2020-08-14T13:37:52Z</dc:date>
    </item>
  </channel>
</rss>

