<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: NIFI Toolkit not working with OIDC configuration in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/NIFI-Toolkit-not-working-with-OIDC-configuration/m-p/375121#M242293</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions on the above topic is greatly appreciated.&lt;/P&gt;</description>
    <pubDate>Thu, 10 Aug 2023 17:39:01 GMT</pubDate>
    <dc:creator>ravi_tadepally</dc:creator>
    <dc:date>2023-08-10T17:39:01Z</dc:date>
    <item>
      <title>NIFI Toolkit not working with OIDC configuration</title>
      <link>https://community.cloudera.com/t5/Support-Questions/NIFI-Toolkit-not-working-with-OIDC-configuration/m-p/373045#M241468</link>
      <description>&lt;P&gt;Hi NIFI Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have currently installed NIFI with OIDC configuration which is working perfectly fine using the UI without any issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when using NIFI toolkit commands and providing Bearer token we are receiving ''Unauthorized error".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does NiFI provide any endpoint to get the OIDC Token separately which can then be used in the Toolkit commands? or please suggest if there is any other approach by which we can make a successful call to NIFI from Nifi Toolkit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 16:51:57 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/NIFI-Toolkit-not-working-with-OIDC-configuration/m-p/373045#M241468</guid>
      <dc:creator>ravi_tadepally</dc:creator>
      <dc:date>2023-06-21T16:51:57Z</dc:date>
    </item>
    <item>
      <title>Re: NIFI Toolkit not working with OIDC configuration</title>
      <link>https://community.cloudera.com/t5/Support-Questions/NIFI-Toolkit-not-working-with-OIDC-configuration/m-p/373064#M241476</link>
      <description>&lt;P&gt;Hello ravi_tadepally,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First of all check your Authentication Configuration, Verify Token Generation, Check Token Authorization, Investigates Error Logs, Validate OIDC Configuration.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope This will help.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2023 06:11:22 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/NIFI-Toolkit-not-working-with-OIDC-configuration/m-p/373064#M241476</guid>
      <dc:creator>Lorecrook5</dc:creator>
      <dc:date>2023-06-22T06:11:22Z</dc:date>
    </item>
    <item>
      <title>Re: NIFI Toolkit not working with OIDC configuration</title>
      <link>https://community.cloudera.com/t5/Support-Questions/NIFI-Toolkit-not-working-with-OIDC-configuration/m-p/374126#M241883</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Lorecrook5,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you for your reply.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have verified the OIDC configuration used for NIFI and toolkit. In case of NIFI I am able to login to UI using OIDC configuration without any issues. But when using toolkit commands especially when running&amp;nbsp; "&lt;STRONG&gt;access-token" &lt;/STRONG&gt;cli command from toolkit I am getting below error.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;STRONG&gt;"ERROR: Error executing command 'get-access-token' : Error performing login: Username/Password login not supported by this NiFi."&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So my question here is if there is any command or endpoint that NIFI provides to get the OIDC token which can be used as a bearer token to pass on to rest of the commands? Without the token we are not able to perform any operations using other commands.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Appreciate your help on this. Thanks in advance.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 14:12:53 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/NIFI-Toolkit-not-working-with-OIDC-configuration/m-p/374126#M241883</guid>
      <dc:creator>ravi_tadepally</dc:creator>
      <dc:date>2023-07-19T14:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: NIFI Toolkit not working with OIDC configuration</title>
      <link>https://community.cloudera.com/t5/Support-Questions/NIFI-Toolkit-not-working-with-OIDC-configuration/m-p/375121#M242293</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions on the above topic is greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 17:39:01 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/NIFI-Toolkit-not-working-with-OIDC-configuration/m-p/375121#M242293</guid>
      <dc:creator>ravi_tadepally</dc:creator>
      <dc:date>2023-08-10T17:39:01Z</dc:date>
    </item>
    <item>
      <title>Re: NIFI Toolkit not working with OIDC configuration</title>
      <link>https://community.cloudera.com/t5/Support-Questions/NIFI-Toolkit-not-working-with-OIDC-configuration/m-p/375123#M242295</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/83067"&gt;@ravi_tadepally&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The NiFi CLI toolkit currently only supports authentication with client certificate, client certificate with proxied user identity or basic auth (via basic auth token).&amp;nbsp; There is no option to obtain a token via OIDC authentication method.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Using token based authentication to perform other NiFi Toolkit CLI commands is probably not the best approach.&amp;nbsp; Tokens have limited life, are only valid fro use interacting with the specific NiFi instance from which it was issued.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The better approach would be to create a cli-nifi.properties file with a proxied entity (this would be your OIDC user identity):&lt;/P&gt;&lt;LI-CODE lang="markup"&gt; baseUrl=https://&amp;lt;nifi-hostname&amp;gt;:&amp;lt;NiFi-port&amp;gt;
 keystore=/path/to/&amp;lt;nifi-keystore.jks&amp;gt;
 keystoreType=JKS
 keystorePasswd=&amp;lt;nifi-keystore-password&amp;gt;
 keyPasswd=&amp;lt;nifi-key-password&amp;gt;
 truststore=/path/to/truststore.jks
 truststoreType=JKS
 truststorePasswd=&amp;lt;nifi-truststore-password&amp;gt;
 proxiedEntity=&amp;lt;OIDC username&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;In a NIfI cluster, the NiFi keystore certificate should already be authorized to "proxy user requests". The "-p cli-nifi.properties" option in NiFi Cli toolkit will utilize the config file above to authenticate via the NiFi node certificate and then make authorized request on behalf of the proxied entity.&amp;nbsp; So, no need to directly authenticate and obtain a token for that proxied entity.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;example:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;./cli.sh nifi cluster-summary -p cli-nifi.properties&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;would return following provided the proxied entity is authorized for that endpoint data:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Total node count: 3
Connected node count: 3
Clustered: true
Connected to cluster: true&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic"&gt;If you found that the provided solution(s) assisted you with your query, please take a moment to login and click&lt;/FONT&gt;&amp;nbsp;&lt;FONT face="arial black,avant garde" color="#FF0000"&gt;Accept as Solution&amp;nbsp;&lt;/FONT&gt;&lt;FONT face="batang,apple gothic" color="#000000"&gt;below each response that helped.&lt;BR /&gt;&lt;BR /&gt;Thank you,&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic" color="#000000"&gt;Matt&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 19:28:51 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/NIFI-Toolkit-not-working-with-OIDC-configuration/m-p/375123#M242295</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2023-08-10T19:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: NIFI Toolkit not working with OIDC configuration</title>
      <link>https://community.cloudera.com/t5/Support-Questions/NIFI-Toolkit-not-working-with-OIDC-configuration/m-p/375124#M242296</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35454"&gt;@MattWho&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your prompt response. The solution you have provided actually worked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your help!&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 20:30:17 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/NIFI-Toolkit-not-working-with-OIDC-configuration/m-p/375124#M242296</guid>
      <dc:creator>ravi_tadepally</dc:creator>
      <dc:date>2023-08-10T20:30:17Z</dc:date>
    </item>
  </channel>
</rss>

