<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: NiFi Authentication with LDAP in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/NiFi-Authentication-with-LDAP/m-p/352783#M236597</link>
    <description>&lt;P&gt;where location crods previded ?&lt;/P&gt;</description>
    <pubDate>Wed, 21 Sep 2022 03:32:46 GMT</pubDate>
    <dc:creator>myzard</dc:creator>
    <dc:date>2022-09-21T03:32:46Z</dc:date>
    <item>
      <title>NiFi Authentication with LDAP</title>
      <link>https://community.cloudera.com/t5/Support-Questions/NiFi-Authentication-with-LDAP/m-p/299272#M219601</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to secure NiFi using LDAP configuration. I followed blog by&amp;nbsp;&lt;A href="https://mintopsblog.com/2017/11/01/apache-nifi-configuration/" target="_self"&gt;mintops&lt;/A&gt;&amp;nbsp;and &lt;A href="https://pierrevillard.com/2017/01/24/integration-of-nifi-with-ldap/&amp;nbsp;" target="_self"&gt;pvillard&lt;/A&gt; articles for reference. I am running NiFi on windows (not in cluster configuration). I am able to get to the login screen, but then I am getting an error on logging in ( The supplied username and password are invalid)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="error.JPG" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/28185i3BB767D9A7FAD2BF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="error.JPG" alt="error.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I followed most instructions as mentioned in the blog by &lt;A href="https://mintopsblog.com/2017/11/01/apache-nifi-configuration/" target="_self"&gt;mintops&lt;/A&gt;. Can someone help me in the direction, on what might be the problem?&lt;/P&gt;&lt;P&gt;&lt;U&gt;PS&lt;/U&gt;: NiFi version and toolkit versions -1.8.0.&lt;/P&gt;&lt;P&gt;I haven't created certificates, just the configs needed to update in Keystore and truststore passwords by the toolkit.&lt;/P&gt;&lt;P&gt;The LDAP configurations were already being used in another program, so that is also not the issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;login-identity-provider.xml&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="login-identity-provider.JPG" style="width: 784px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/28186i9BC076273CC21896/image-size/large?v=v2&amp;amp;px=999" role="button" title="login-identity-provider.JPG" alt="login-identity-provider.JPG" /&gt;&lt;/span&gt;&lt;U&gt;authorizers.xml&lt;/U&gt;:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="authorizers.JPG" style="width: 629px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/28187i02CBA3236C2239D8/image-size/large?v=v2&amp;amp;px=999" role="button" title="authorizers.JPG" alt="authorizers.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;nifi.properties&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="nifi-properties.JPG" style="width: 546px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/28188iCEF44FF5AB082CB6/image-size/large?v=v2&amp;amp;px=999" role="button" title="nifi-properties.JPG" alt="nifi-properties.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35454"&gt;@MattWho&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/36106"&gt;@bbende&lt;/a&gt;&amp;nbsp;Can you help me out in this regard&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 15:07:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/NiFi-Authentication-with-LDAP/m-p/299272#M219601</guid>
      <dc:creator>sgk</dc:creator>
      <dc:date>2020-07-07T15:07:38Z</dc:date>
    </item>
    <item>
      <title>Re: NiFi Authentication with LDAP</title>
      <link>https://community.cloudera.com/t5/Support-Questions/NiFi-Authentication-with-LDAP/m-p/299319#M219625</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/51806"&gt;@sgk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The error you are seeing has nothing to do with authorization at this point.&amp;nbsp; It is throwing an error during authentication of your user. So your focus at this point is on your ldap-provider configuration since it is handling the authentication of your user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"The Supplied Username or Password are not valid" indicates that the LDAP search resulted in no returns or the password used was wrong.&lt;BR /&gt;&lt;BR /&gt;Observations:&lt;BR /&gt;1. Are you using ldap or Active Directory (AD). I see you have set "User Search Filter" to "sAMAccountName={0}".&amp;nbsp; sAMAccountName is more commonly seen in AD and not LDAP.&amp;nbsp; Did you try using the ldapsearch command from a terminal window on your NiFI server to make sure you can return a listing for your user using this search filter?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ldapsearch -x -H ldap://&amp;lt;ldap-hostname/IP&amp;gt;:&amp;lt;ldap-port&amp;gt; -D "&amp;lt;Manager DN&amp;gt;" -w "&amp;lt;Manager password&amp;gt;" -b "&amp;lt;user search base&amp;gt;" "sAMAccountName=&amp;lt;username&amp;gt;"&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;2. Not that this has anything to do with successful authentication, but I see you have set "Identity Strategy" to "USE_DN" which then uses the users full DN from ldap to identify that user during authorization actions following successful authorization. If you set this to "USE_USERNAME", the user string type at login will be used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Also has nothing to do with authentication, but I see you are using "CN=localhost, OU=NiFi" as your "node identity 1" value.&amp;nbsp; Using localhost in your node certificates is not advisable. This should be set to unique value.&amp;nbsp; Also keep in mind that the keystore used by NiFi must meet the following minimum requirements:&lt;BR /&gt;- Contain only 1 "PrivateKeyEntry"&lt;BR /&gt;- The "PrivateKeyEntry" must support both clientAuth and serverAuth ExtendedKeyUsage (EKU).&lt;BR /&gt;- The "PrivateKeyEntry" must contain at least 1 SubjectAlternativeName (SAN) that matches the hostname of the server on which the certificate is being used.&lt;BR /&gt;&lt;BR /&gt;Hope this information helps you progress with your authentication and then authorization setup in NiFi.&lt;BR /&gt;Matt&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 13:09:19 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/NiFi-Authentication-with-LDAP/m-p/299319#M219625</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2020-07-08T13:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: NiFi Authentication with LDAP</title>
      <link>https://community.cloudera.com/t5/Support-Questions/NiFi-Authentication-with-LDAP/m-p/299494#M219699</link>
      <description>&lt;P&gt;Thanks, you were spot-on about the issue, turned out the creds provided to me were incorrect. And thanks for the suggestions as well.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2020 07:03:22 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/NiFi-Authentication-with-LDAP/m-p/299494#M219699</guid>
      <dc:creator>sgk</dc:creator>
      <dc:date>2020-07-10T07:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: NiFi Authentication with LDAP</title>
      <link>https://community.cloudera.com/t5/Support-Questions/NiFi-Authentication-with-LDAP/m-p/352783#M236597</link>
      <description>&lt;P&gt;where location crods previded ?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 03:32:46 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/NiFi-Authentication-with-LDAP/m-p/352783#M236597</guid>
      <dc:creator>myzard</dc:creator>
      <dc:date>2022-09-21T03:32:46Z</dc:date>
    </item>
  </channel>
</rss>

