<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: NIFI SAML Error in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/NIFI-SAML-Error/m-p/337235#M232535</link>
    <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/11191"&gt;@araujo&lt;/a&gt;,&lt;BR /&gt;In our authorizers.xml, we have below mentioned entry:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;userGroupProvider&amp;gt;&lt;BR /&gt;&amp;lt;identifier&amp;gt;file-user-group-provider&amp;lt;/identifier&amp;gt;&lt;BR /&gt;&amp;lt;class&amp;gt;org.apache.nifi.authorization.FileUserGroupProvider&amp;lt;/class&amp;gt;&lt;BR /&gt;&amp;lt;property name="Users File"&amp;gt;./conf/users.xml&amp;lt;/property&amp;gt;&lt;BR /&gt;&amp;lt;property name="Legacy Authorized Users File"&amp;gt;&amp;lt;/property&amp;gt;&lt;BR /&gt;&amp;lt;property name="Initial User Identity 1"&amp;gt;xxxx@xxx.com&amp;lt;/property&amp;gt;&lt;BR /&gt;&amp;lt;property name="Initial User Identity 2"&amp;gt;servernode1 XXXXXX&amp;lt;/property&amp;gt;&lt;BR /&gt;&amp;lt;property name="Initial User Identity 3"&amp;gt;servernode2 XXXXXX&amp;lt;/property&amp;gt;&lt;BR /&gt;&amp;lt;property name="Initial User Identity 4"&amp;gt;servernode3 XXXXXX&amp;lt;/property&amp;gt;&lt;BR /&gt;&amp;lt;/userGroupProvider&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;accessPolicyProvider&amp;gt;&lt;BR /&gt;&amp;lt;identifier&amp;gt;file-access-policy-provider&amp;lt;/identifier&amp;gt;&lt;BR /&gt;&amp;lt;class&amp;gt;org.apache.nifi.authorization.FileAccessPolicyProvider&amp;lt;/class&amp;gt;&lt;BR /&gt;&amp;lt;property name="User Group Provider"&amp;gt;file-user-group-provider&amp;lt;/property&amp;gt;&lt;BR /&gt;&amp;lt;property name="Authorizations File"&amp;gt;./conf/authorizations.xml&amp;lt;/property&amp;gt;&lt;BR /&gt;&amp;lt;property name="Initial Admin Identity"&amp;gt;xxxxxxxx@xxx.com&amp;lt;/property&amp;gt;&lt;BR /&gt;&amp;lt;property name="Legacy Authorized Users File"&amp;gt;&amp;lt;/property&amp;gt;&lt;BR /&gt;&amp;lt;property name="Node Identity 1"&amp;gt;servernode1 XXXXXX&amp;lt;/property&amp;gt;&lt;BR /&gt;&amp;lt;property name="Node Identity 2"&amp;gt;servernode2 xxxxxx&amp;lt;/property&amp;gt;&lt;BR /&gt;&amp;lt;property name="Node Identity 3"&amp;gt;servernode3 xxxxx&amp;lt;/property&amp;gt;&lt;BR /&gt;&amp;lt;property name="Node Group"&amp;gt;&amp;lt;/property&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;/accessPolicyProvider&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;authorizer&amp;gt;&lt;BR /&gt;&amp;lt;identifier&amp;gt;managed-authorizer&amp;lt;/identifier&amp;gt;&lt;BR /&gt;&amp;lt;class&amp;gt;org.apache.nifi.authorization.StandardManagedAuthorizer&amp;lt;/class&amp;gt;&lt;BR /&gt;&amp;lt;property name="Access Policy Provider"&amp;gt;file-access-policy-provider&amp;lt;/property&amp;gt;&lt;BR /&gt;&amp;lt;/authorizer&amp;gt;&lt;BR /&gt;###############################################################&lt;BR /&gt;&lt;SPAN&gt;nifi-app.log&lt;/SPAN&gt;&lt;BR /&gt;###########################&lt;BR /&gt;Server node 1:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2022-02-28 10:42:37,897 ERROR [NiFi Web Server-162] o.apache.nifi.web.api.SAMLAccessResource The RelayState value returned by the SAML IDP does not match the stored state. Unable to continue login process.&lt;BR /&gt;&lt;BR /&gt;##########################&lt;BR /&gt;&lt;/SPAN&gt;Server node 2:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2022-02-28 10:42:27,550 WARN [NiFi Web Server-151] o.apache.nifi.web.api.SAMLAccessResource The login request identifier was not found in the request. Unable to continue.&lt;BR /&gt;&lt;BR /&gt;########################&lt;BR /&gt;&lt;/SPAN&gt;Server node 3: This is the node where we see the SAML request Logs:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2022-02-28 10:42:28,269 DEBUG [NiFi Web Server-217] org.apache.velocity.loader ResourceManager: found /templates/saml2-post-binding.vm with loader org.apache.velocity.runtime.resource.loader.ClasspathResourceLoader&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2022-02-28 10:42:28,270 DEBUG [NiFi Web Server-217] org.apache.velocity.loader ResourceManager: found /templates/add-html-head-content.vm with loader org.apache.velocity.runtime.resource.loader.ClasspathResourceLoader&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2022-02-28 10:42:28,271 DEBUG [NiFi Web Server-217] org.apache.velocity.loader ResourceManager: found /templates/add-html-body-content.vm with loader org.apache.velocity.runtime.resource.loader.ClasspathResourceLoader&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2022-02-28 10:42:28,273 DEBUG [NiFi Web Server-217] PROTOCOL_MESSAGE&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;lt;saml2p:AuthnRequest&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;AssertionConsumerServiceURL="&lt;A href="https://xxxxxxxx/nifi-api/access/saml/login/consumer" target="_blank"&gt;https://xxxxxxxx/nifi-api/access/saml/login/consumer&lt;/A&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Destination="xxxxxxxxx"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;ForceAuthn="false" ID="xxxxx"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;IsPassive="false" IssueInstant="2022-02-28T10:42:28.261Z"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Version="2.0" xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&amp;lt;saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"&amp;gt;xxxxxxx&amp;lt;/saml2:Issuer&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;lt;/saml2p:AuthnRequest&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Feb 2022 10:52:09 GMT</pubDate>
    <dc:creator>Abhishek27Apple</dc:creator>
    <dc:date>2022-02-28T10:52:09Z</dc:date>
  </channel>
</rss>

