<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: No applicable policy found error while login to nifi in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/No-applicable-policy-found-error-while-login-to-nifi/m-p/373813#M241753</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/93743"&gt;@shamika&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;When you log in to NiFi, you'll want to inspect the nifi-user.log to see the exact exception and NiFi policy that the authenticated user is missing authorization for.&amp;nbsp; The screenshot you shared above that appears right after successful authentication implies that your authenticated user's identity string (you see this in nifi-user.log) is not authorized on the "view the user interface" NiFi Policy (/flow NiFi resource Identifier in Ranger).&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic"&gt;If you found that the provided solution(s) assisted you with your query, please take a moment to login and click&lt;/FONT&gt;&amp;nbsp;&lt;FONT face="arial black,avant garde" color="#FF0000"&gt;Accept as Solution&amp;nbsp;&lt;/FONT&gt;&lt;FONT face="batang,apple gothic" color="#000000"&gt;below each response that helped.&lt;BR /&gt;&lt;BR /&gt;Thank you,&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic" color="#000000"&gt;Matt&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jul 2023 13:44:32 GMT</pubDate>
    <dc:creator>MattWho</dc:creator>
    <dc:date>2023-07-12T13:44:32Z</dc:date>
    <item>
      <title>No applicable policy found error while login to nifi</title>
      <link>https://community.cloudera.com/t5/Support-Questions/No-applicable-policy-found-error-while-login-to-nifi/m-p/373798#M241743</link>
      <description>&lt;DIV class="mail-message expanded"&gt;&lt;DIV class="mail-message-content collapsible zoom-normal mail-show-images "&gt;&lt;DIV class="clear"&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV class="gmail_signature"&gt;&lt;DIV class="gmail_signature"&gt;Logs from nifi-app.log file&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="gmail_signature"&gt;ERROR [nifi.async.multi_dest.batch_nifi.async.multi_dest.batch.solr_destWriter] o.a.s.client.solrj.impl.CloudSolrClient Request to collection ranger_audits failed due to (401) org.apache.solr.client.solrj.impl.HttpSolrClient$RemoteSolrException: Error from server at http://&amp;lt;hostname&amp;gt;:8886/solr/ranger_audits_shard1_replica_n1: Expected mime type application/octet-stream but got text/html. &amp;lt;html&amp;gt;&lt;/DIV&gt;&lt;DIV class="gmail_signature"&gt;&amp;lt;head&amp;gt;&lt;/DIV&gt;&lt;DIV class="gmail_signature"&gt;&amp;lt;meta http-equiv="Content-Type" content="text/html;charset=utf-8"/&amp;gt;&lt;/DIV&gt;&lt;DIV class="gmail_signature"&gt;&amp;lt;title&amp;gt;Error 401 Authentication required&amp;lt;/title&amp;gt;&lt;/DIV&gt;&lt;DIV class="gmail_signature"&gt;&amp;lt;/head&amp;gt;&lt;/DIV&gt;&lt;DIV class="gmail_signature"&gt;&amp;lt;body&amp;gt;&amp;lt;h2&amp;gt;HTTP ERROR 401&amp;lt;/h2&amp;gt;&lt;/DIV&gt;&lt;DIV class="gmail_signature"&gt;&amp;lt;p&amp;gt;Problem accessing /solr/ranger_audits_shard1_replica_n1/update. Reason:&lt;/DIV&gt;&lt;DIV class="gmail_signature"&gt;&amp;lt;pre&amp;gt;&amp;nbsp; &amp;nbsp; Authentication required&amp;lt;/pre&amp;gt;&amp;lt;/p&amp;gt;&lt;/DIV&gt;&lt;DIV class="gmail_signature"&gt;&amp;lt;/body&amp;gt;&lt;/DIV&gt;&lt;DIV class="gmail_signature"&gt;&amp;lt;/html&amp;gt;&lt;/DIV&gt;&lt;DIV class="gmail_signature"&gt;, retry? 0&lt;/DIV&gt;&lt;DIV class="gmail_signature"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="gmail_signature"&gt;Pfa the error attachment&lt;/DIV&gt;&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IMG20230712163228.jpg" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/37987iFD98D3801E872F6B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="IMG20230712163228.jpg" alt="IMG20230712163228.jpg" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="mail-message-footer spacer collapsible"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 12 Jul 2023 11:06:02 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/No-applicable-policy-found-error-while-login-to-nifi/m-p/373798#M241743</guid>
      <dc:creator>shamika</dc:creator>
      <dc:date>2023-07-12T11:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: No applicable policy found error while login to nifi</title>
      <link>https://community.cloudera.com/t5/Support-Questions/No-applicable-policy-found-error-while-login-to-nifi/m-p/373813#M241753</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/93743"&gt;@shamika&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;When you log in to NiFi, you'll want to inspect the nifi-user.log to see the exact exception and NiFi policy that the authenticated user is missing authorization for.&amp;nbsp; The screenshot you shared above that appears right after successful authentication implies that your authenticated user's identity string (you see this in nifi-user.log) is not authorized on the "view the user interface" NiFi Policy (/flow NiFi resource Identifier in Ranger).&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic"&gt;If you found that the provided solution(s) assisted you with your query, please take a moment to login and click&lt;/FONT&gt;&amp;nbsp;&lt;FONT face="arial black,avant garde" color="#FF0000"&gt;Accept as Solution&amp;nbsp;&lt;/FONT&gt;&lt;FONT face="batang,apple gothic" color="#000000"&gt;below each response that helped.&lt;BR /&gt;&lt;BR /&gt;Thank you,&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic" color="#000000"&gt;Matt&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 13:44:32 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/No-applicable-policy-found-error-while-login-to-nifi/m-p/373813#M241753</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2023-07-12T13:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: No applicable policy found error while login to nifi</title>
      <link>https://community.cloudera.com/t5/Support-Questions/No-applicable-policy-found-error-while-login-to-nifi/m-p/373817#M241757</link>
      <description>&lt;P&gt;Can you please suggest what things i need chacke in ranger policy to resolve this no applicable policy issue&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 15:33:30 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/No-applicable-policy-found-error-while-login-to-nifi/m-p/373817#M241757</guid>
      <dc:creator>shamika</dc:creator>
      <dc:date>2023-07-12T15:33:30Z</dc:date>
    </item>
    <item>
      <title>Re: No applicable policy found error while login to nifi</title>
      <link>https://community.cloudera.com/t5/Support-Questions/No-applicable-policy-found-error-while-login-to-nifi/m-p/373843#M241765</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/93743"&gt;@shamika&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;You need to check the nifi-user.log to see your exact user identity string which is being denied when trying to view the user interface.&amp;nbsp; &amp;nbsp;That exact user identity string (case sensitive) must then exist as a user in Ranger service and be authorized fro Read on the "/flow" NiFi Resource identifier under the NIFI service in service manager.&lt;BR /&gt;&lt;BR /&gt;You can find a full list of NiFi Resource Identifier descriptions in the following Cloudera Community article and how they relate to the policies within the NiFi service:&lt;BR /&gt;&lt;A href="https://community.cloudera.com/t5/Community-Articles/NiFi-Ranger-based-policy-descriptions/ta-p/246586" target="_blank"&gt;https://community.cloudera.com/t5/Community-Articles/NiFi-Ranger-based-policy-descriptions/ta-p/246586&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic"&gt;If you found that the provided solution(s) assisted you with your query, please take a moment to login and click&lt;/FONT&gt;&amp;nbsp;&lt;FONT face="arial black,avant garde" color="#FF0000"&gt;Accept as Solution&amp;nbsp;&lt;/FONT&gt;&lt;FONT face="batang,apple gothic" color="#000000"&gt;below each response that helped.&lt;BR /&gt;&lt;BR /&gt;Thank you,&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic" color="#000000"&gt;Matt&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 18:44:34 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/No-applicable-policy-found-error-while-login-to-nifi/m-p/373843#M241765</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2023-07-12T18:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: No applicable policy found error while login to nifi</title>
      <link>https://community.cloudera.com/t5/Support-Questions/No-applicable-policy-found-error-while-login-to-nifi/m-p/373852#M241773</link>
      <description>&lt;P&gt;I checked the ranger policy into that /flow having acess group nd user acess for username and group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which its menstion in nifi-user.log&lt;/P&gt;&lt;DIV&gt;-07-12 10:46:36,228 WARN [NiFi Web Server-262] o.a.n.a.util.IdentityMappingUtil Identity Mapping property nifi.security.identity.mapping.pattern.dn was found, but was empty&lt;/DIV&gt;&lt;DIV&gt;2023-07-12 10:46:40,796 INFO [NiFi Web Server-19] o.a.n.w.s.NiFiAuthenticationFilter Attempting request for (&amp;lt;JWT token&amp;gt;) GET&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://hostname:9091/nifi-api/flow/current-user" target="_blank" rel="noopener noreferrer"&gt;https://hostname:9091/nifi-api/flow/current-user&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(source ip:&amp;lt;xy87284hdsshdg)&amp;gt;&lt;/DIV&gt;&lt;DIV&gt;2023-07-12 10:46:40,798 INFO [NiFi Web Server-19] o.a.n.w.s.NiFiAuthenticationFilter Authentication success for myuser&lt;/DIV&gt;&lt;DIV&gt;2023-07-12 10:46:40,800 INFO [NiFi Web Server-19] o.a.n.w.a.c.AccessDeniedExceptionMapper identity[myuser], groups[bigG, bigdGer] does not have permission to access the requested resource. No applicable policies could be found. Returning Forbidden response&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2023 08:23:13 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/No-applicable-policy-found-error-while-login-to-nifi/m-p/373852#M241773</guid>
      <dc:creator>shamika</dc:creator>
      <dc:date>2023-07-13T08:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: No applicable policy found error while login to nifi</title>
      <link>https://community.cloudera.com/t5/Support-Questions/No-applicable-policy-found-error-while-login-to-nifi/m-p/373854#M241775</link>
      <description>&lt;P&gt;Have a same issue, when you'll know how to solve it, tag me please&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2023 09:53:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/No-applicable-policy-found-error-while-login-to-nifi/m-p/373854#M241775</guid>
      <dc:creator>Ganesha</dc:creator>
      <dc:date>2023-07-13T09:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: No applicable policy found error while login to nifi</title>
      <link>https://community.cloudera.com/t5/Support-Questions/No-applicable-policy-found-error-while-login-to-nifi/m-p/373879#M241786</link>
      <description>&lt;P&gt;Sure, if you got the fix. Let me know &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2023 13:27:12 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/No-applicable-policy-found-error-while-login-to-nifi/m-p/373879#M241786</guid>
      <dc:creator>shamika</dc:creator>
      <dc:date>2023-07-13T13:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: No applicable policy found error while login to nifi</title>
      <link>https://community.cloudera.com/t5/Support-Questions/No-applicable-policy-found-error-while-login-to-nifi/m-p/373917#M241811</link>
      <description>&lt;P&gt;The nifi-user.log is showing the user "myuser", which belongs to the groups "&lt;SPAN&gt;bigG, bigdGer", does not have access to the /flow resource. You can check on the Ranger audit section, for the resource that is denied, then give access to the groups or the username to this resource.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 19:05:29 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/No-applicable-policy-found-error-while-login-to-nifi/m-p/373917#M241811</guid>
      <dc:creator>gtorres</dc:creator>
      <dc:date>2023-07-14T19:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: No applicable policy found error while login to nifi</title>
      <link>https://community.cloudera.com/t5/Support-Questions/No-applicable-policy-found-error-while-login-to-nifi/m-p/373923#M241817</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/93743"&gt;@shamika&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;NiFi based authorization is case sensitive.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2023-07-12 10:46:40,800 INFO [NiFi Web Server-19] o.a.n.w.a.c.AccessDeniedExceptionMapper identity[myuser], groups[bigG, bigdGer] does not have permission to access the requested resource. No applicable policies could be found. Returning Forbidden response&lt;/LI-CODE&gt;&lt;P&gt;the nifi-user.log is telling you that your successfully authenticated user "myuser" is known by NiFi to belong to groups "bigG" and "bigdGer".&amp;nbsp; In Ranger you'll need to make sure that yoru user "myuser" or one of these groups&amp;nbsp;"bigG" and/or "bigdGer" has been authorized for "READ" on the "/flow" NiFi resource Identifier.&amp;nbsp; If Ranger has the group as "bigg" or "BIGG", "bigDGER", etc it will not work because NiFi is case sensitive.&lt;BR /&gt;&lt;BR /&gt;You could also share your authorizers.xml if you'd like use to verify your configuration there.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic"&gt;If you found that the provided solution(s) assisted you with your query, please take a moment to login and click&lt;/FONT&gt;&amp;nbsp;&lt;FONT face="arial black,avant garde" color="#FF0000"&gt;Accept as Solution&amp;nbsp;&lt;/FONT&gt;&lt;FONT face="batang,apple gothic" color="#000000"&gt;below each response that helped.&lt;BR /&gt;&lt;BR /&gt;Thank you,&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic" color="#000000"&gt;Matt&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 21:27:15 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/No-applicable-policy-found-error-while-login-to-nifi/m-p/373923#M241817</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2023-07-14T21:27:15Z</dc:date>
    </item>
  </channel>
</rss>

