<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: How to use InvokeHTTP without SSL verification in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/How-to-use-InvokeHTTP-without-SSL-verification/m-p/305654#M222534</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/82585"&gt;@vatodorov19&lt;/a&gt;&amp;nbsp; &amp;nbsp;If the service you are connecting too is https,&amp;nbsp; there is no way to use invokeHttp without SSL Verification.&amp;nbsp; &amp;nbsp;If the remote host is using a publicly signed cert, try using cacerts in your java location before trying to make keystores and truststores.&amp;nbsp; &amp;nbsp;If you do make keystores and truststores from the service's public or self signed certs you will need to make sure those certs are generated following best practices. For example: using a real hostname for the service and make sure you connect to the same hostname, not an ip or "resilient.localdomain".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this answer resolves your issue or allows you to move forward, please choose to ACCEPT this solution and close this topic. If you have further dialogue on this topic please comment here or feel free to private message me. If you have new questions related to your Use Case please create separate topic and feel free to tag me in your post.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Steven&lt;/P&gt;</description>
    <pubDate>Mon, 09 Nov 2020 12:40:11 GMT</pubDate>
    <dc:creator>stevenmatison</dc:creator>
    <dc:date>2020-11-09T12:40:11Z</dc:date>
    <item>
      <title>How to use InvokeHTTP without SSL verification</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-use-InvokeHTTP-without-SSL-verification/m-p/305497#M222469</link>
      <description>&lt;P&gt;How can I use InvokeHTTP without SSL verification? I followed this article on how to import the public certificate but that cert is not CA-signed, and InvokeHTTP doesn't work. Below is the error I get.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cloudera.com/t5/Support-Questions/Is-it-possible-to-provide-options-to-InvokeHTTP-nifi/m-p/236239" target="_blank"&gt;https://community.cloudera.com/t5/Support-Questions/Is-it-possible-to-provide-options-to-InvokeHTTP-nifi/m-p/236239&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vatodorov19_1-1604603238416.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/29376i441F530AF8386F4B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vatodorov19_1-1604603238416.png" alt="vatodorov19_1-1604603238416.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In InvokeHTTP, I'm using the StandardSSLContextService with the following configs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vatodorov19_2-1604603342053.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/29377iA9CED0AA50E4EA32/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vatodorov19_2-1604603342053.png" alt="vatodorov19_2-1604603342053.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Valentin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2020 19:09:33 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-use-InvokeHTTP-without-SSL-verification/m-p/305497#M222469</guid>
      <dc:creator>vatodorov19</dc:creator>
      <dc:date>2020-11-05T19:09:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to use InvokeHTTP without SSL verification</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-use-InvokeHTTP-without-SSL-verification/m-p/305654#M222534</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/82585"&gt;@vatodorov19&lt;/a&gt;&amp;nbsp; &amp;nbsp;If the service you are connecting too is https,&amp;nbsp; there is no way to use invokeHttp without SSL Verification.&amp;nbsp; &amp;nbsp;If the remote host is using a publicly signed cert, try using cacerts in your java location before trying to make keystores and truststores.&amp;nbsp; &amp;nbsp;If you do make keystores and truststores from the service's public or self signed certs you will need to make sure those certs are generated following best practices. For example: using a real hostname for the service and make sure you connect to the same hostname, not an ip or "resilient.localdomain".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this answer resolves your issue or allows you to move forward, please choose to ACCEPT this solution and close this topic. If you have further dialogue on this topic please comment here or feel free to private message me. If you have new questions related to your Use Case please create separate topic and feel free to tag me in your post.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Steven&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 12:40:11 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-use-InvokeHTTP-without-SSL-verification/m-p/305654#M222534</guid>
      <dc:creator>stevenmatison</dc:creator>
      <dc:date>2020-11-09T12:40:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to use InvokeHTTP without SSL verification</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-use-InvokeHTTP-without-SSL-verification/m-p/305847#M222580</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/60150"&gt;@stevenmatison&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Is there a plan to add a feature to InvokeHTTP to access hosts with a self-signed cert? It is very common for organizations to deploy internal hosts with localhost.localdomain certs, that are only accessible by the IP.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2020 14:55:14 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-use-InvokeHTTP-without-SSL-verification/m-p/305847#M222580</guid>
      <dc:creator>vatodorov19</dc:creator>
      <dc:date>2020-11-12T14:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to use InvokeHTTP without SSL verification</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-use-InvokeHTTP-without-SSL-verification/m-p/305854#M222581</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/82585"&gt;@vatodorov19&lt;/a&gt;&amp;nbsp; &amp;nbsp;I have used tons of self signed certs and not had issues.&amp;nbsp; &amp;nbsp;Maybe you need to just adjust the method to create the self signed certs and/or the keystore and truststores based on known working nifi samples.&amp;nbsp; &amp;nbsp;SSL, Certs, Keystores, Versions, and SSL Context Services each are all very finicky so getting them right can be as easy as a config change, or adjustment in the commands to kick of cert/keystore creations.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2020 16:12:57 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-use-InvokeHTTP-without-SSL-verification/m-p/305854#M222581</guid>
      <dc:creator>stevenmatison</dc:creator>
      <dc:date>2020-11-12T16:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to use InvokeHTTP without SSL verification</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-use-InvokeHTTP-without-SSL-verification/m-p/345660#M234598</link>
      <description>&lt;P&gt;I have used invokeHTTP in 1.12 version without SSL cert and works fine, however new version 1.16 doesn't. Any settings available to ignore?. Ex: I connect to SQL server with JDBCConnection with property&amp;nbsp;trustServerCertificate=true; post which it works without certifcates.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 08:23:35 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-use-InvokeHTTP-without-SSL-verification/m-p/345660#M234598</guid>
      <dc:creator>Althotta</dc:creator>
      <dc:date>2022-06-15T08:23:35Z</dc:date>
    </item>
  </channel>
</rss>

