<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Nifi-Registry OIDC in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Registry-OIDC/m-p/365795#M239396</link>
    <description>&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/100472"&gt;@RRosa&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;That particular exceptions seems to point an issue with the ldap-provider configuration in your nifi-registry possible related to the manager DN property not being set.&lt;BR /&gt;Would need to see your nifi-registry.properties and authorizers.xml to provide more context around the above exception.&lt;BR /&gt;&lt;BR /&gt;Yes, OIDC is supported in NiFi-Registry 1.19.1.&amp;nbsp; When access in a secured (TLS/SSL Enabled) NiFi-Registry, the UI is displayed as the "anonymous" user.&amp;nbsp; Only "public" buckets will be visible.&amp;nbsp; In order to login via OIDC, you would need to click on the login via OIDC link in the UI.&lt;BR /&gt;&lt;BR /&gt;OIDC properties:&lt;BR /&gt;nifi.registry.security.user.oidc.discovery.url=&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;nifi.registry.security.user.oidc.connect.timeout=5 secs&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;nifi.registry.security.user.oidc.read.timeout=5 secs&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;nifi.registry.security.user.oidc.client.id=&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;nifi.registry.security.user.oidc.client.secret=&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;nifi.registry.security.user.oidc.preferred.jwsalgorithm=&lt;BR /&gt;nifi.registry.security.user.oidc.additional.scopes=&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;nifi.registry.security.user.oidc.claim.identifying.user=&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic"&gt;If you found that the provided solution(s) assisted you with your query, please take a moment to login and click&lt;/FONT&gt;&amp;nbsp;&lt;FONT face="arial black,avant garde" color="#FF0000"&gt;Accept as Solution&amp;nbsp;&lt;/FONT&gt;&lt;FONT face="batang,apple gothic" color="#000000"&gt;below each response that helped.&lt;BR /&gt;&lt;BR /&gt;Thank you,&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic" color="#000000"&gt;Matt&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 09 Mar 2023 20:54:46 GMT</pubDate>
    <dc:creator>MattWho</dc:creator>
    <dc:date>2023-03-09T20:54:46Z</dc:date>
    <item>
      <title>Nifi-Registry OIDC</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Registry-OIDC/m-p/365791#M239392</link>
      <description>&lt;P&gt;How to configure OIDC authentication in nifi-registry 1.19.1?&lt;BR /&gt;When configuring secure access ssl + oidc does not display the UI when trying to access. In the log I don't see errors just warnings, one of them is this:&lt;BR /&gt;o.s.l.core.support.AbstractContextSource Property 'userDn' not set - anonymous context will be used for read-write operations&lt;/P&gt;&lt;P&gt;Is it possible to access this version through OIDC?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 19:46:45 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-Registry-OIDC/m-p/365791#M239392</guid>
      <dc:creator>RRosa</dc:creator>
      <dc:date>2023-03-09T19:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi-Registry OIDC</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Registry-OIDC/m-p/365795#M239396</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/100472"&gt;@RRosa&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;That particular exceptions seems to point an issue with the ldap-provider configuration in your nifi-registry possible related to the manager DN property not being set.&lt;BR /&gt;Would need to see your nifi-registry.properties and authorizers.xml to provide more context around the above exception.&lt;BR /&gt;&lt;BR /&gt;Yes, OIDC is supported in NiFi-Registry 1.19.1.&amp;nbsp; When access in a secured (TLS/SSL Enabled) NiFi-Registry, the UI is displayed as the "anonymous" user.&amp;nbsp; Only "public" buckets will be visible.&amp;nbsp; In order to login via OIDC, you would need to click on the login via OIDC link in the UI.&lt;BR /&gt;&lt;BR /&gt;OIDC properties:&lt;BR /&gt;nifi.registry.security.user.oidc.discovery.url=&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;nifi.registry.security.user.oidc.connect.timeout=5 secs&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;nifi.registry.security.user.oidc.read.timeout=5 secs&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;nifi.registry.security.user.oidc.client.id=&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;nifi.registry.security.user.oidc.client.secret=&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;nifi.registry.security.user.oidc.preferred.jwsalgorithm=&lt;BR /&gt;nifi.registry.security.user.oidc.additional.scopes=&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;nifi.registry.security.user.oidc.claim.identifying.user=&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic"&gt;If you found that the provided solution(s) assisted you with your query, please take a moment to login and click&lt;/FONT&gt;&amp;nbsp;&lt;FONT face="arial black,avant garde" color="#FF0000"&gt;Accept as Solution&amp;nbsp;&lt;/FONT&gt;&lt;FONT face="batang,apple gothic" color="#000000"&gt;below each response that helped.&lt;BR /&gt;&lt;BR /&gt;Thank you,&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic" color="#000000"&gt;Matt&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 20:54:46 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-Registry-OIDC/m-p/365795#M239396</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2023-03-09T20:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi-Registry OIDC</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Registry-OIDC/m-p/380741#M244148</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35454"&gt;@MattWho&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I managed to enable OIDC based authentication for Nifi - registry. However there are tow challenges post login.&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; After login via OIDC the user does have the necessary permissions. Getting the following message in the logs.&lt;BR /&gt;"Property 'userDn' not set - anonymous context will be used for read-write operations"&lt;BR /&gt;&lt;BR /&gt;2. While trying to logout getting the following message in the browser:&lt;BR /&gt;&lt;SPAN&gt;"The 'post_logout_redirect_uri' parameter must be a Logout redirect URI in the client app settings:..."&lt;BR /&gt;&lt;BR /&gt;Could you please let me know if there additional setting to address the above issues&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 02:56:30 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-Registry-OIDC/m-p/380741#M244148</guid>
      <dc:creator>teriyatha</dc:creator>
      <dc:date>2023-12-13T02:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi-Registry OIDC</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Registry-OIDC/m-p/394473#M248725</link>
      <description>&lt;P&gt;Set the nifi-registry security INITIAL_ADMIN_IDENTITY value to your admin email address.&lt;BR /&gt;From the nifi-registry using oidc, login using the admin email address. And you will see all permissions in the nifi-registry page...&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Oct 2024 09:30:10 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-Registry-OIDC/m-p/394473#M248725</guid>
      <dc:creator>archie</dc:creator>
      <dc:date>2024-10-03T09:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi-Registry OIDC</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Registry-OIDC/m-p/398350#M250165</link>
      <description>&lt;P&gt;It works fine&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/118020"&gt;@archie&lt;/a&gt;&amp;nbsp;!&lt;BR /&gt;Thanks!&lt;BR /&gt;&lt;BR /&gt;This is my following snipped docker-compose code:&lt;BR /&gt;&lt;BR /&gt;nifi-registry:&lt;BR /&gt;image: apache/nifi-registry:1.23.2&lt;BR /&gt;container_name: nifi-registry&lt;BR /&gt;hostname: nifi-registry&lt;BR /&gt;restart: "no"&lt;BR /&gt;ports:&lt;BR /&gt;- 18443:18443&lt;BR /&gt;volumes:&lt;BR /&gt;- ./nifi/certs/localhost:/opt/certs&lt;BR /&gt;environment:&lt;BR /&gt;TZ: America/Sao_Paulo&lt;BR /&gt;NIFI_REGISTRY_WEB_HTTPS_PORT: 18443&lt;BR /&gt;AUTH: oidc&lt;BR /&gt;KEYSTORE_PATH: /opt/certs/keystore.jks&lt;BR /&gt;KEYSTORE_TYPE: JKS&lt;BR /&gt;KEYSTORE_PASSWORD: changeit&lt;BR /&gt;TRUSTSTORE_PATH: /opt/certs/truststore.jks&lt;BR /&gt;TRUSTSTORE_PASSWORD: changeit&lt;BR /&gt;TRUSTSTORE_TYPE: JKS&lt;BR /&gt;INITIAL_ADMIN_IDENTITY: test@test.com&lt;BR /&gt;NIFI_REGISTRY_SECURITY_USER_OIDC_DISCOVERY_URL: http://&amp;lt;LOCAL_KEYCLOAK_IP&amp;gt;:8080/realms/TEST/.well-known/openid-configuration&lt;BR /&gt;NIFI_REGISTRY_SECURITY_USER_OIDC_CONNECT_TIMEOUT: 10000&lt;BR /&gt;NIFI_REGISTRY_SECURITY_USER_OIDC_READ_TIMEOUT: 10000&lt;BR /&gt;NIFI_REGISTRY_SECURITY_USER_OIDC_CLIENT_ID: nifi&lt;BR /&gt;NIFI_REGISTRY_SECURITY_USER_OIDC_CLIENT_SECRET: &amp;lt;CLIENT_SECRET&amp;gt;&lt;BR /&gt;NIFI_REGISTRY_SECURITY_USER_OIDC_PREFERRED_JWSALGORITHM: RS256&lt;BR /&gt;NIFI_REGISTRY_SECURITY_USER_OIDC_ADDITIONAL_SCOPES: openid,email,profile&lt;BR /&gt;NIFI_REGISTRY_SECURITY_USER_OIDC_CLAIM_IDENTIFYING_USER: preferred_username&lt;BR /&gt;networks:&lt;BR /&gt;- test-net&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2024 21:33:14 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-Registry-OIDC/m-p/398350#M250165</guid>
      <dc:creator>marcelo225</dc:creator>
      <dc:date>2024-12-03T21:33:14Z</dc:date>
    </item>
  </channel>
</rss>

