<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Nifi login error ( when ldap login is applied ) in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Nifi-login-error-when-ldap-login-is-applied/m-p/352372#M236503</link>
    <description>&lt;P&gt;Matt , the next steps mitigate the problem , but not its solution&lt;BR /&gt;&lt;BR /&gt;Step 1&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="noekmc_0-1663273060870.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/35578i2DC4F827572DE8A4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="noekmc_0-1663273060870.png" alt="noekmc_0-1663273060870.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Step 2 show the problem&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="noekmc_1-1663273113790.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/35579i14F774818D4A1148/image-size/medium?v=v2&amp;amp;px=400" role="button" title="noekmc_1-1663273113790.png" alt="noekmc_1-1663273113790.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Step 3 Select" log out " option&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="noekmc_2-1663273156635.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/35580iDD69161C6B5808DC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="noekmc_2-1663273156635.png" alt="noekmc_2-1663273156635.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="noekmc_3-1663273182957.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/35581i24794812CF5B4B43/image-size/medium?v=v2&amp;amp;px=400" role="button" title="noekmc_3-1663273182957.png" alt="noekmc_3-1663273182957.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Step 4 : in the Url delete "logout-complete" and add "login"&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="noekmc_4-1663273282243.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/35582iF2FEC460B91E8469/image-size/medium?v=v2&amp;amp;px=400" role="button" title="noekmc_4-1663273282243.png" alt="noekmc_4-1663273282243.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="noekmc_5-1663273340591.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/35583i34F58D3A077E1888/image-size/medium?v=v2&amp;amp;px=400" role="button" title="noekmc_5-1663273340591.png" alt="noekmc_5-1663273340591.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Do you know why this behavior occurs?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Regards!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 15 Sep 2022 20:29:04 GMT</pubDate>
    <dc:creator>noekmc</dc:creator>
    <dc:date>2022-09-15T20:29:04Z</dc:date>
    <item>
      <title>Nifi login error ( when ldap login is applied )</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-login-error-when-ldap-login-is-applied/m-p/352350#M236496</link>
      <description>&lt;P&gt;Hi Guys ,i have a problem with Nifi login &amp;nbsp; please can´t help me ?&lt;BR /&gt;&lt;BR /&gt;this problem start when open the web interface of Nifi later config ldap login&amp;nbsp; .Present the next message&amp;nbsp;&lt;BR /&gt;has been attached imagen .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="noekmc_0-1663253765063.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/35575i7FDF7E95878C6721/image-size/medium?v=v2&amp;amp;px=400" role="button" title="noekmc_0-1663253765063.png" alt="noekmc_0-1663253765063.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;for fix the problem -&amp;gt; select log out&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;is there any other solution ?&lt;BR /&gt;&lt;BR /&gt;Regards!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 07:50:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-login-error-when-ldap-login-is-applied/m-p/352350#M236496</guid>
      <dc:creator>noekmc</dc:creator>
      <dc:date>2026-04-21T07:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi login error ( when ldap login is applied )</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-login-error-when-ldap-login-is-applied/m-p/352361#M236500</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/99719"&gt;@noekmc&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;The UI you are seeing is telling you that your ldap user credentials have successfully been authenticated; however, your user identity is not authorized within NiFi to "view the UI".&lt;BR /&gt;&lt;A href="https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html#access-policies" target="_self"&gt;NiFi Access Policies&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The ldap-provider configured in the login-identity-providers.xml handles the authentication process.&lt;BR /&gt;The configuration within the authorizers.xml handles the authorizing of those authenticated user identities.&lt;BR /&gt;You can tail the nifi-user.log&amp;nbsp; while you login to see that your user identity that is resulting from your successful authentication.&amp;nbsp; You will also then see the not authorized log output with the missing access policy.&lt;BR /&gt;&lt;BR /&gt;The following section of the Apache Documentation can help setting up authorization for the first time:&lt;BR /&gt;&lt;A href="https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html#multi-tenant-authorization" target="_self"&gt;multi-tenant-authorization&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If you were to share the log lines from your nifi-user.log specific to your login attempt along with the contents of your authorizers.xml file, it may be easier to provide guidance on your setup.&amp;nbsp; The multi-tenant-authorization setup in the authorizers.xml has many configuration options and providers to choose from.&amp;nbsp; The very basic setup would use a managed-provider that uses the file-access-policy-provider and file-user-group-provider.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic"&gt;If you found that the provided solution(s) assisted you with your query, please take a moment to login and click&lt;/FONT&gt;&amp;nbsp;&lt;FONT face="arial black,avant garde" color="#FF0000"&gt;Accept as Solution&amp;nbsp;&lt;/FONT&gt;&lt;FONT face="batang,apple gothic" color="#000000"&gt;below each response that helped.&lt;BR /&gt;&lt;BR /&gt;Thank you,&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic" color="#000000"&gt;Matt&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2022 19:40:40 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-login-error-when-ldap-login-is-applied/m-p/352361#M236500</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2022-09-15T19:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi login error ( when ldap login is applied )</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-login-error-when-ldap-login-is-applied/m-p/352372#M236503</link>
      <description>&lt;P&gt;Matt , the next steps mitigate the problem , but not its solution&lt;BR /&gt;&lt;BR /&gt;Step 1&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="noekmc_0-1663273060870.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/35578i2DC4F827572DE8A4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="noekmc_0-1663273060870.png" alt="noekmc_0-1663273060870.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Step 2 show the problem&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="noekmc_1-1663273113790.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/35579i14F774818D4A1148/image-size/medium?v=v2&amp;amp;px=400" role="button" title="noekmc_1-1663273113790.png" alt="noekmc_1-1663273113790.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Step 3 Select" log out " option&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="noekmc_2-1663273156635.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/35580iDD69161C6B5808DC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="noekmc_2-1663273156635.png" alt="noekmc_2-1663273156635.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="noekmc_3-1663273182957.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/35581i24794812CF5B4B43/image-size/medium?v=v2&amp;amp;px=400" role="button" title="noekmc_3-1663273182957.png" alt="noekmc_3-1663273182957.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Step 4 : in the Url delete "logout-complete" and add "login"&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="noekmc_4-1663273282243.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/35582iF2FEC460B91E8469/image-size/medium?v=v2&amp;amp;px=400" role="button" title="noekmc_4-1663273282243.png" alt="noekmc_4-1663273282243.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="noekmc_5-1663273340591.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/35583i34F58D3A077E1888/image-size/medium?v=v2&amp;amp;px=400" role="button" title="noekmc_5-1663273340591.png" alt="noekmc_5-1663273340591.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Do you know why this behavior occurs?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Regards!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2022 20:29:04 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-login-error-when-ldap-login-is-applied/m-p/352372#M236503</guid>
      <dc:creator>noekmc</dc:creator>
      <dc:date>2022-09-15T20:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi login error ( when ldap login is applied )</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-login-error-when-ldap-login-is-applied/m-p/352440#M236511</link>
      <description>&lt;P&gt;You need to create an initial admin account ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Go to your authorizers.xml file and add your ldap username "cn=xxx,ou=xx,dc=xxx,dc=xxx" in the Initial Admin Identity property, it will create admin user and you will log on to NiFi as admin and create policies for other users&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 07:32:55 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-login-error-when-ldap-login-is-applied/m-p/352440#M236511</guid>
      <dc:creator>AyanF</dc:creator>
      <dc:date>2022-09-16T07:32:55Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi login error ( when ldap login is applied )</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-login-error-when-ldap-login-is-applied/m-p/352500#M236524</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/99719"&gt;@noekmc&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I was not clear that when you accessed the NiFi Web address you were skipping the login window completely.&amp;nbsp; This means that your browser provided and alternative method of client/user authentication.&lt;BR /&gt;&lt;BR /&gt;When you access the NiFi web address, NiFi will always negotiate a mutual TLS handshake. This is necessary because this is how NiFi nodes authenticate with one another.&amp;nbsp; If no other methods of client authentication have been configured, the mutual TLS handshake "Requires" a client certificate.&amp;nbsp; When other methods of authentication are configured&amp;nbsp; in NiFi, the mutual TLS handshake will "WANT" a client certificate.&amp;nbsp; If no client certificate is presented, then NiFi will move on to the next configured authentication method which would spnego.&lt;BR /&gt;&lt;BR /&gt;Spnego based authentication is enabled when the following properties have been configured in the nifi.properties file:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MattWho_0-1663353868838.png" style="width: 694px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/35637iD4D97DFD4DAA365F/image-dimensions/694x160?v=v2" width="694" height="160" role="button" title="MattWho_0-1663353868838.png" alt="MattWho_0-1663353868838.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Make sure these two properties are clear to disable spnego auth challenge to your browser.&lt;BR /&gt;&lt;BR /&gt;If Spnego auth challenge is not successful, NiFi moves on to next auth method such as a configured login provider like the ldap-provider you have setup.&lt;BR /&gt;&lt;BR /&gt;The first step is figuring out which method (TLS client certificate or Spnego) is authenticating your user.&lt;BR /&gt;Typically a browser will prompt you when either if these methods are invoked the first time.&amp;nbsp; If you ack instead of cancel, the browser will remember that choice going forward.&amp;nbsp; For TLS client auth to work, your browser must have a client certificate loaded in to it that your NiFi's truststore file is capable of trusting.&lt;BR /&gt;&lt;BR /&gt;For Spengo to work, Spnego must be configured in your browser.&lt;BR /&gt;&lt;BR /&gt;Step one:&lt;BR /&gt;- Open an incognito browser tab (it will not have any retained cookies that would auto use a certificate or spnego) and provide the NiFi UI address.&amp;nbsp; &amp;nbsp;Does it redirect you immediately to the login UI.&amp;nbsp; If so, you now know one of these other methods are being used.&lt;BR /&gt;&lt;BR /&gt;- Clear the two Spnego properties if configured in the nifi.properties file. (if already blank, then we know a TLS certificate is what is being used.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;- Clear browser cache and cookies.&amp;nbsp; Access NiFi UI address, when prompted via browser for certifcate, cancel and you should get redirected to login window.&amp;nbsp; There is not configuration change that can be made in NiFi to stop a browser from doing this.&amp;nbsp; &amp;nbsp;However, your decision to cancel and continue to URL without providing your certifcate should be cached by your browser so it does not ask you each time afterwards.&lt;BR /&gt;&lt;BR /&gt;- Try a different browser.&amp;nbsp; While your certificate maybe loaded in one browser, it may not be loaded in another.&amp;nbsp; Same goes for Spnego, it may not be enabled in all browsers on your client.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic"&gt;If you found that the provided solution(s) assisted you with your query, please take a moment to login and click&lt;/FONT&gt;&amp;nbsp;&lt;FONT face="arial black,avant garde" color="#FF0000"&gt;Accept as Solution&amp;nbsp;&lt;/FONT&gt;&lt;FONT face="batang,apple gothic" color="#000000"&gt;below each response that helped.&lt;BR /&gt;&lt;BR /&gt;Thank you,&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic" color="#000000"&gt;Matt&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 18:56:33 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-login-error-when-ldap-login-is-applied/m-p/352500#M236524</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2022-09-16T18:56:33Z</dc:date>
    </item>
  </channel>
</rss>

