<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: LDAP Integration (ldap-provider) Issue in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/LDAP-Integration-ldap-provider-Issue/m-p/303438#M221550</link>
    <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;I solved the problem.&lt;/P&gt;</description>
    <pubDate>Sun, 27 Sep 2020 19:43:13 GMT</pubDate>
    <dc:creator>Muhyid</dc:creator>
    <dc:date>2020-09-27T19:43:13Z</dc:date>
    <item>
      <title>LDAP Integration (ldap-provider) Issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-Integration-ldap-provider-Issue/m-p/301544#M220731</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;I am encountering issue with LDAP integration.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;I have completed LDAP (ldap-provider) and Certificate configurations according to documentation.&lt;/LI&gt;&lt;LI&gt;I added IU certificate in NiFi (keystore, truststore etc.) and configured other pieces of the MS AD LDAP integration (authorizers.xml, login-identity-providers.xml and nifi.properties).&lt;/LI&gt;&lt;LI&gt;I logged on NiFi from HTTPS UI with initial admin (admin1) and assigned the policies one of the LDAP users (nifiadmin) which is located on MS AD LDAP.&lt;/LI&gt;&lt;LI&gt;I checked LDAP user (nifiadmin) from NiFi UI it is exist in the NiFi. It seems Ok. I added all screenshots (nifi_policies.jpg) about that.&lt;/LI&gt;&lt;LI&gt;When I try to login initial admin (admin1) there is no error:&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;nifi-user.log:&lt;/P&gt;&lt;P&gt;2020-08-13 10:46:43,544 INFO [main] o.a.n.a.FileUserGroupProvider Users/Groups file loaded at Thu Aug 13 10:46:43 MSK 2020&lt;/P&gt;&lt;P&gt;2020-08-13 10:46:43,684 INFO [main] o.a.n.a.FileAccessPolicyProvider Authorizations file loaded at Thu Aug 13 10:46:43 MSK 2020&lt;/P&gt;&lt;P&gt;2020-08-13 11:21:28,051 INFO [NiFi Web Server-22] o.a.n.w.s.NiFiAuthenticationFilter Attempting request for (&amp;lt;JWT token&amp;gt;) GET &lt;A href="https://nifiportal.abc.example.com/nifi-api/flow/current-user" target="_blank" rel="noopener"&gt;https://nifiportal.abc.example.com/nifi-api/flow/current-user&lt;/A&gt; (source ip: 10.0.2.15)&lt;/P&gt;&lt;P&gt;2020-08-13 11:21:28,062 INFO [NiFi Web Server-22] o.a.n.w.s.NiFiAuthenticationFilter Authentication success for admin1&lt;/P&gt;&lt;P&gt;2020-08-13 11:21:28,167 INFO [NiFi Web Server-118] o.a.n.w.s.NiFiAuthenticationFilter Attempting request for (&amp;lt;JWT token&amp;gt;) GET &lt;A href="https://nifiportal.abc.example.com/nifi-api/flow/client-id" target="_blank" rel="noopener"&gt;https://nifiportal.abc.example.com/nifi-api/flow/client-id&lt;/A&gt; (source ip: 10.0.2.15)&lt;/P&gt;&lt;P&gt;2020-08-13 11:21:28,170 INFO [NiFi Web Server-118] o.a.n.w.s.NiFiAuthenticationFilter Authentication success for admin1&lt;/P&gt;&lt;P&gt;2020-08-13 11:21:28,170 INFO [NiFi Web Server-22] o.a.n.w.s.NiFiAuthenticationFilter Attempting request for (&amp;lt;JWT token&amp;gt;) GET &lt;A href="https://nifiportal.abc.example.com/nifi-api/flow/config" target="_blank" rel="noopener"&gt;https://nifiportal.abc.example.com/nifi-api/flow/config&lt;/A&gt; (source ip: 10.0.2.15)&lt;/P&gt;&lt;P&gt;2020-08-13 11:21:28,179 INFO [NiFi Web Server-22] o.a.n.w.s.NiFiAuthenticationFilter Authentication success for admin1&lt;/P&gt;&lt;P&gt;2020-08-13 11:21:28,206 INFO [NiFi Web Server-118] o.a.n.w.s.NiFiAuthenticationFilter Attempting request for (&amp;lt;JWT token&amp;gt;) GET &lt;A href="https://nifiportal.abc.example.com/nifi-api/flow/banners" target="_blank" rel="noopener"&gt;https://nifiportal.abc.example.com/nifi-api/flow/banners&lt;/A&gt; (source ip: 10.0.2.15)&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 6. But, when I try to login with LDAP User (nifiadmin) who was already assigned NiFi UI access by me I am getting permission error. I added all screenshots (nifi_policies.jpg) about that:&lt;/P&gt;&lt;P&gt;nifi-user.log:&lt;/P&gt;&lt;P&gt;2020-08-13 11:51:52,255 INFO [NiFi Web Server-16] o.a.n.w.s.NiFiAuthenticationFilter Attempting request for (&amp;lt;JWT token&amp;gt;) GET &lt;A href="https://nifiportal.abc.example.com/nifi-api/flow/current-user" target="_blank" rel="noopener"&gt;https://nifiportal.abc.example.com/nifi-api/flow/current-user&lt;/A&gt; (source ip: 10.0.2.15)&lt;/P&gt;&lt;P&gt;2020-08-13 11:51:52,258 INFO [NiFi Web Server-16] o.a.n.w.s.NiFiAuthenticationFilter Authentication success for nifiadmin&lt;/P&gt;&lt;P&gt;2020-08-13 11:51:52,260 INFO [NiFi Web Server-16] o.a.n.w.a.c.AccessDeniedExceptionMapper identity[nifiadmin], groups[] does not have permission to access the requested resource. Unknown user with identity 'nifiadmin'. Returning Forbidden response.&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 7. When I check the nifi-app.log there is no error:&lt;/P&gt;&lt;P&gt;nifi-app.log:&lt;/P&gt;&lt;P&gt;2020-08-13 10:46:52,310 INFO [main] o.e.jetty.util.ssl.SslContextFactory x509=X509@1b8354aa(fa3f2599-3d3b-43c9-9e7a-ea26375d4470,h=[nifiportal.abc.example.com],w=[]) for SslContextFactory@378a5302[provider=null,keyStore=file:///C:/nifi/certificates/private-keystore1,trus&lt;/P&gt;&lt;P&gt;tStore=file:///C:/nifi/certificates/public-keystore1]&lt;/P&gt;&lt;P&gt;2020-08-13 10:46:52,325 INFO [main] o.eclipse.jetty.server.AbstractConnector Started ServerConnector@2794eab6{SSL,[ssl, http/1.1]}{nifiportal.abc.example.com:443}&lt;/P&gt;&lt;P&gt;2020-08-13 10:46:52,325 INFO [main] org.eclipse.jetty.server.Server Started @31030ms&lt;/P&gt;&lt;P&gt;2020-08-13 10:46:52,419 INFO [main] org.apache.nifi.nar.NarAutoLoader Starting NAR Auto-Loader for directory .\extensions ...&lt;/P&gt;&lt;P&gt;2020-08-13 10:46:52,419 INFO [main] org.apache.nifi.nar.NarAutoLoader NAR Auto-Loader started&lt;/P&gt;&lt;P&gt;2020-08-13 10:46:52,419 INFO [main] org.apache.nifi.web.server.JettyServer NiFi has started. The UI is available at the following URLs:&lt;/P&gt;&lt;P&gt;2020-08-13 10:46:52,419 INFO [main] org.apache.nifi.web.server.JettyServer &lt;A href="https://nifiportal.abc.example.com:443/nifi" target="_blank" rel="noopener"&gt;https://nifiportal.abc.example.com:443/nifi&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 8. What I did for solving the problem&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I deleted user.xml and authorizations.xml several times. Nifi creates automatically them but problem is still continue.&lt;/LI&gt;&lt;LI&gt;I tried different kind of the configurations in the related files (authorizers.xml, login-identity-providers.xml and nifi.properties). But no change&lt;/LI&gt;&lt;LI&gt;I also tried another LDAP user than nifiadmin (admin2) but there is no any solution for ldap user login issue&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I added all configuration files (authorizations, authorizers, login-identity-providers, nifi.properties and users) with jpeg format. I also added screenshots (nifi_policies.jpg) about access and user policies.&lt;/P&gt;&lt;P&gt;My environment details are below:&lt;BR /&gt;Apache NiFi 1.11.3 (single, not cluster)&lt;BR /&gt;Windows Server 2016&lt;BR /&gt;Java JRE 1.8.0_251 (64 Bit)&lt;/P&gt;&lt;P&gt;MS Active Directory 2016 for LDAP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any comment or idea?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="nifi_policies" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/28628i8706FAA3A8D9581F/image-size/large?v=v2&amp;amp;px=999" role="button" title="nifi_policies.jpg" alt="nifi_policies" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;nifi_policies&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="authorizations.xml" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/28629i233DA9ADB06AC964/image-size/large?v=v2&amp;amp;px=999" role="button" title="authorizations.JPG" alt="authorizations.xml" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;authorizations.xml&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="authorizers-1.xml" style="width: 850px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/28630i6515DD29545E6731/image-size/large?v=v2&amp;amp;px=999" role="button" title="authorizers-1.JPG" alt="authorizers-1.xml" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;authorizers-1.xml&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="authorizers-2.xml" style="width: 937px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/28631iB634AB3EF7DF6834/image-size/large?v=v2&amp;amp;px=999" role="button" title="authorizers-2.JPG" alt="authorizers-2.xml" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;authorizers-2.xml&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="authorizers-3.xml" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/28632i421F180230C6EC93/image-size/large?v=v2&amp;amp;px=999" role="button" title="authorizers-3.JPG" alt="authorizers-3.xml" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;authorizers-3.xml&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="login-identity-providers.xml" style="width: 952px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/28633i3D443403C9FE4080/image-size/large?v=v2&amp;amp;px=999" role="button" title="login-identity-providers.JPG" alt="login-identity-providers.xml" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;login-identity-providers.xml&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="nifi.properties" style="width: 699px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/28634iDE9795AD064C8AD7/image-size/large?v=v2&amp;amp;px=999" role="button" title="nifi.properties.JPG" alt="nifi.properties" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;nifi.properties&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="users.xml" style="width: 693px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/28635i6C07FBC8A48F7E1C/image-size/large?v=v2&amp;amp;px=999" role="button" title="users.JPG" alt="users.xml" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;users.xml&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Aug 2020 14:51:44 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-Integration-ldap-provider-Issue/m-p/301544#M220731</guid>
      <dc:creator>Muhyid</dc:creator>
      <dc:date>2020-08-15T14:51:44Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Integration (ldap-provider) Issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-Integration-ldap-provider-Issue/m-p/303438#M221550</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;I solved the problem.&lt;/P&gt;</description>
      <pubDate>Sun, 27 Sep 2020 19:43:13 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-Integration-ldap-provider-Issue/m-p/303438#M221550</guid>
      <dc:creator>Muhyid</dc:creator>
      <dc:date>2020-09-27T19:43:13Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Integration (ldap-provider) Issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-Integration-ldap-provider-Issue/m-p/303473#M221565</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/79448"&gt;@Muhyid&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;SPAN data-sheets-value="{&amp;quot;1&amp;quot;:2,&amp;quot;2&amp;quot;:&amp;quot;I'm happy to see you resolved your issue. Please mark the appropriate reply as the solution, as it will make it easier for others to find the answer in the future.&amp;quot;}" data-sheets-userformat="{&amp;quot;2&amp;quot;:15297,&amp;quot;3&amp;quot;:{&amp;quot;1&amp;quot;:0},&amp;quot;9&amp;quot;:0,&amp;quot;10&amp;quot;:1,&amp;quot;11&amp;quot;:4,&amp;quot;12&amp;quot;:0,&amp;quot;14&amp;quot;:{&amp;quot;1&amp;quot;:2,&amp;quot;2&amp;quot;:0},&amp;quot;15&amp;quot;:&amp;quot;Arial&amp;quot;,&amp;quot;16&amp;quot;:11}"&gt;I'm happy to see you resolved your issue. Can you please provide the details of the solution?&amp;nbsp;It will make it easier for others to find the answer in the future.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:44:53 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-Integration-ldap-provider-Issue/m-p/303473#M221565</guid>
      <dc:creator>VidyaSargur</dc:creator>
      <dc:date>2020-09-28T09:44:53Z</dc:date>
    </item>
  </channel>
</rss>

