<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: How to set passwords for multiple users in Apache Nifi in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/How-to-set-passwords-for-multiple-users-in-Apache-Nifi/m-p/367116#M239793</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/104274"&gt;@Breezer&lt;/a&gt;&amp;nbsp;Welcome to the Cloudera Community!&lt;BR /&gt;&lt;BR /&gt;To help you get the best possible solution, I have tagged our NiFi experts&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/103151"&gt;@cotopaul&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/80381"&gt;@SAMSAL&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35454"&gt;@MattWho&lt;/a&gt;&amp;nbsp; who may be able to assist you further.&lt;BR /&gt;&lt;BR /&gt;Please keep us updated on your post, and we hope you find a satisfactory solution to your query.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Mar 2023 16:33:37 GMT</pubDate>
    <dc:creator>DianaTorres</dc:creator>
    <dc:date>2023-03-28T16:33:37Z</dc:date>
    <item>
      <title>How to set passwords for multiple users in Apache Nifi</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-set-passwords-for-multiple-users-in-Apache-Nifi/m-p/367110#M239791</link>
      <description>&lt;P&gt;I want to have multiple users in Nifi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't want to use LDAP because I don't have a LDAP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't want to use Kerberos because I don't have a Kerberos.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't want to use Apache Knox because I don't have a Apache Knox.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't want to integrate with the thing because I don't have the thing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just want to have 3 users, each with their own username and password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've gotten to the point where I have three users but I have no idea what password to use for the non-admin users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 15:51:17 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-set-passwords-for-multiple-users-in-Apache-Nifi/m-p/367110#M239791</guid>
      <dc:creator>Breezer</dc:creator>
      <dc:date>2023-03-28T15:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to set passwords for multiple users in Apache Nifi</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-set-passwords-for-multiple-users-in-Apache-Nifi/m-p/367116#M239793</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/104274"&gt;@Breezer&lt;/a&gt;&amp;nbsp;Welcome to the Cloudera Community!&lt;BR /&gt;&lt;BR /&gt;To help you get the best possible solution, I have tagged our NiFi experts&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/103151"&gt;@cotopaul&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/80381"&gt;@SAMSAL&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35454"&gt;@MattWho&lt;/a&gt;&amp;nbsp; who may be able to assist you further.&lt;BR /&gt;&lt;BR /&gt;Please keep us updated on your post, and we hope you find a satisfactory solution to your query.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 16:33:37 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-set-passwords-for-multiple-users-in-Apache-Nifi/m-p/367116#M239793</guid>
      <dc:creator>DianaTorres</dc:creator>
      <dc:date>2023-03-28T16:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to set passwords for multiple users in Apache Nifi</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-set-passwords-for-multiple-users-in-Apache-Nifi/m-p/367341#M239875</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/104274"&gt;@Breezer&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;NiFi was historically never built to manage local users.&amp;nbsp; NiFi provides no mechanism for creating and managing multiple users locally.&lt;BR /&gt;&lt;BR /&gt;That being said, the Apache NiFi community found that many new users to NiFi were simply starting up unsecure NiFi instances on publicly accessible networks and decided to make changes so that by default NiFi would start with out of the box configuration secured over https.&amp;nbsp; &amp;nbsp; This change was released as part of the Apache NiFi 1.14 release and involved the following changes to make this work.&lt;BR /&gt;&lt;BR /&gt;1. NiFi toolkit is used automatically to generate a keystore and truststore using self signed certs to secure NiFi.&lt;BR /&gt;2. A secured NiFi will require users/clients to authenticate and be authorized to interact with the NiFi UI in various ways. This means that out of the box there would need to be an authorizer and a means to define some user that could then be auto authorized to the needed policies.&amp;nbsp; These changes were all part of&amp;nbsp;&lt;A href="https://issues.apache.org/jira/browse/NIFI-8220" target="_blank"&gt;https://issues.apache.org/jira/browse/NIFI-8220&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;The single-user-authorizer and single-user-provider were never intended for use in production as they do not provide granular multi-user level of authentication and authorization (which is what you are looking for).&amp;nbsp; The simply provide for a single user who is authorized to every NiFi policy allowing for a secured environment out of the box.&lt;BR /&gt;&lt;BR /&gt;Since NiFi never has and does not have any intention of managing users locally (creating multiple local users with passwords managed through NiFi UI) in the future, you'll need to utilize one of the other available user authentication methods if you want an environment which supports multiple users with unique authorizations.&amp;nbsp; Those methods are explained here:&lt;BR /&gt;&lt;A href="https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html#user_authentication" target="_blank"&gt;https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html#user_authentication&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I see you don't want to rely on some external authentication provider like ldap, kerbersos, knox, etc. and that is fine.&amp;nbsp; User authentication can also be achieved via a mutual TLS handshake.&amp;nbsp; All this requires is generating a unique user certificate for each of your 3 users.&lt;BR /&gt;&lt;BR /&gt;A basic setup like this would require you to configure your NiFi to use the follwoing:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Authentication:&lt;OL&gt;&lt;LI&gt;Clear the "single-user-provider" for the "nifi.security.user.login.provider" property in the nifi.properties file.&lt;/LI&gt;&lt;LI&gt;Use the NiFi TLS toolkit to generate your certifcates:&amp;nbsp;&lt;A href="https://nifi.apache.org/docs/nifi-docs/html/toolkit-guide.html#tls_toolkit" target="_blank"&gt;https://nifi.apache.org/docs/nifi-docs/html/toolkit-guide.html#tls_toolkit&lt;/A&gt;. Or you could use an external free certificate provider like Tinycert to create a certificate for each your NiFi instance(s) and a certifcate for each of your users.&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Authorization:&lt;OL&gt;&lt;LI&gt;Change the "single-user-authorizer" for the " nifi.security.user.authorizer" property in the nifi.properties file to "managed-authorizer".&lt;/LI&gt;&lt;LI&gt;Build a new authorizers.xml that uses the "managed-authorizer" (&lt;A href="https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html#standardmanagedauthorizer" target="_blank"&gt;https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html#standardmanagedauthorizer&lt;/A&gt;), "file-access-policy-provider" (&lt;A href="https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html#fileaccesspolicyprovider" target="_blank"&gt;https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html#fileaccesspolicyprovider&lt;/A&gt;), and "file-user-group-provider" (&lt;A href="https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html#fileusergroupprovider" target="_blank"&gt;https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html#fileusergroupprovider&lt;/A&gt;).&amp;nbsp;&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Example: Authorizers.xml configuration:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;authorizers&amp;gt;

    &amp;lt;userGroupProvider&amp;gt;
        &amp;lt;identifier&amp;gt;file-user-group-provider&amp;lt;/identifier&amp;gt;
        &amp;lt;class&amp;gt;org.apache.nifi.authorization.FileUserGroupProvider&amp;lt;/class&amp;gt;
        &amp;lt;property name="Users File"&amp;gt;./conf/users.xml&amp;lt;/property&amp;gt;
        &amp;lt;property name="Legacy Authorized Users File"&amp;gt;&amp;lt;/property&amp;gt;
        &amp;lt;property name="Initial User Identity 1"&amp;gt;&amp;lt;full DN from user certifcate 1&amp;gt;&amp;lt;/property&amp;gt;
        &amp;lt;property name="Initial User Identity 2"&amp;gt;&amp;lt;full DN from user certifcate 2&amp;gt;&amp;lt;/property&amp;gt;
        &amp;lt;property name="Initial User Identity 3"&amp;gt;&amp;lt;full DN from user certifcate 3&amp;gt;&amp;lt;/property&amp;gt;
    &amp;lt;/userGroupProvider&amp;gt;

    &amp;lt;accessPolicyProvider&amp;gt;
        &amp;lt;identifier&amp;gt;file-access-policy-provider&amp;lt;/identifier&amp;gt;
        &amp;lt;class&amp;gt;org.apache.nifi.authorization.FileAccessPolicyProvider&amp;lt;/class&amp;gt;
        &amp;lt;property name="User Group Provider"&amp;gt;file-user-group-provider&amp;lt;/property&amp;gt;
        &amp;lt;property name="Authorizations File"&amp;gt;./conf/authorizations.xml&amp;lt;/property&amp;gt;
        &amp;lt;property name="Initial Admin Identity"&amp;gt;&amp;lt;full DN from user certificate 1&amp;gt;&amp;lt;/property&amp;gt;
        &amp;lt;property name="Legacy Authorized Users File"&amp;gt;&amp;lt;/property&amp;gt;
        &amp;lt;property name="Node Identity 1"&amp;gt;&amp;lt;/property&amp;gt;
    &amp;lt;/accessPolicyProvider&amp;gt;

    &amp;lt;authorizer&amp;gt;
        &amp;lt;identifier&amp;gt;managed-authorizer&amp;lt;/identifier&amp;gt;
        &amp;lt;class&amp;gt;org.apache.nifi.authorization.StandardManagedAuthorizer&amp;lt;/class&amp;gt;
        &amp;lt;property name="Access Policy Provider"&amp;gt;file-access-policy-provider&amp;lt;/property&amp;gt;
    &amp;lt;/authorizer&amp;gt;
&amp;lt;/authorizers&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;This authorizers.xml setup will add your three user identities to NiFI for purpose of authorizing them against NiFi policies only.&amp;nbsp; One of those users will be designated as the "initial admin" in the file-access-policy-provider.&amp;nbsp; This user will be assigned to the required policies needed for that user to act as admin.&amp;nbsp; That admin user can then access NiFi and setup authorization policies for the other two users.&lt;BR /&gt;&lt;BR /&gt;The Certificates created for your users would be provided to each user.&amp;nbsp; The user can then load that certificate into their browser.&amp;nbsp; When the user navigates the the HTTPS NiFi URL, NiFi will request that client provide a certifcate and the loaded certificate can be used.&amp;nbsp; This handles the unique user authentication.&lt;BR /&gt;&lt;BR /&gt;More details on setting up additional authorization policies for yoru users can be found here:&lt;BR /&gt;&lt;A href="https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html#config-users-access-policies" target="_blank"&gt;https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html#config-users-access-policies&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic"&gt;If you found that the provided solution(s) assisted you with your query, please take a moment to login and click&lt;/FONT&gt;&amp;nbsp;&lt;FONT face="arial black,avant garde" color="#FF0000"&gt;Accept as Solution&amp;nbsp;&lt;/FONT&gt;&lt;FONT face="batang,apple gothic" color="#000000"&gt;below each response that helped.&lt;BR /&gt;&lt;BR /&gt;Thank you,&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic" color="#000000"&gt;Matt&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 15:58:19 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-set-passwords-for-multiple-users-in-Apache-Nifi/m-p/367341#M239875</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2023-03-30T15:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to set passwords for multiple users in Apache Nifi</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-set-passwords-for-multiple-users-in-Apache-Nifi/m-p/378171#M243439</link>
      <description>&lt;P&gt;Hi matt, can you kindly some detailed explanation on how do i create multiple authorizers.xml like if can change in the existing authorizers.xml or do i need to create new authorizer file and if yes how can i integrate it with the config files? that would be really helpful and kind of you&lt;BR /&gt;&lt;BR /&gt;thanks and regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 07:50:27 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-set-passwords-for-multiple-users-in-Apache-Nifi/m-p/378171#M243439</guid>
      <dc:creator>jai1gupta</dc:creator>
      <dc:date>2023-10-26T07:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to set passwords for multiple users in Apache Nifi</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-set-passwords-for-multiple-users-in-Apache-Nifi/m-p/378176#M243442</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/107566"&gt;@jai1gupta&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I am not clear on your ask here and it does not seem related to the question asked and solution accepted in this thread.&amp;nbsp; Please start a new community question with details around what you are trying to accomplish/solve.&amp;nbsp; Feel free to&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35454"&gt;@MattWho&lt;/a&gt;&amp;nbsp;in that new question so that I get notified and I will try to assist you there.&lt;BR /&gt;&lt;BR /&gt;Thank you,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 15:00:16 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-set-passwords-for-multiple-users-in-Apache-Nifi/m-p/378176#M243442</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2023-10-26T15:00:16Z</dc:date>
    </item>
  </channel>
</rss>

