<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: trying to authenticate nifi with openID using google oAuth and getting an error. in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/trying-to-authenticate-nifi-with-openID-using-google-oAuth/m-p/378467#M243545</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35454"&gt;@MattWho&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;after changing the nifi.security.user.oidc.truststore.strategy to NIFI my error got resolved. now when i access the nifi on browser i get this error&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-11-02 at 4.18.10 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/38827i499A8DFB4EB88C48/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-11-02 at 4.18.10 PM.png" alt="Screenshot 2023-11-02 at 4.18.10 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-11-02 at 4.22.51 PM.png" style="width: 768px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/38829i088B1BF25430BF8E/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-11-02 at 4.22.51 PM.png" alt="Screenshot 2023-11-02 at 4.22.51 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;i think this error is because my nifi is not secured over https.&lt;/P&gt;&lt;P&gt;i've already ran this command&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-11-02 at 4.14.54 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/38828iEBE47C2DB8ECD35D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-11-02 at 4.14.54 PM.png" alt="Screenshot 2023-11-02 at 4.14.54 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;please tell me what can i do next to make it secured. Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 02 Nov 2023 10:53:40 GMT</pubDate>
    <dc:creator>jai1gupta</dc:creator>
    <dc:date>2023-11-02T10:53:40Z</dc:date>
    <item>
      <title>trying to authenticate nifi with openID using google oAuth and getting an error.</title>
      <link>https://community.cloudera.com/t5/Support-Questions/trying-to-authenticate-nifi-with-openID-using-google-oAuth/m-p/378368#M243514</link>
      <description>&lt;P class="p1"&gt;&lt;STRONG&gt;&lt;SPAN class="s1"&gt;Caused by: org.springframework.web.client.ResourceAccessException: I/O error on GET request for "&lt;A href="https://accounts.google.com/.well-known/openid-configuration" target="_blank" rel="noopener"&gt;https://accounts.google.com/.well-known/openid-configuration&lt;/A&gt;": sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;this is error which im getting&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;my nifi.properties file is as follows :-&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.autoreload.enabled&lt;/SPAN&gt;&lt;SPAN&gt;=false&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.autoreload.interval&lt;/SPAN&gt;&lt;SPAN&gt;=10 secs&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.keystore&lt;/SPAN&gt;&lt;SPAN&gt;=./conf/keystore.jks&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.keystoreType&lt;/SPAN&gt;&lt;SPAN&gt;=jks&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.keystorePasswd&lt;/SPAN&gt;&lt;SPAN&gt;=tyiImfLpqM5/qX1l0VsjK7sxhQx5YZFOZgstogGz8Ek&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.keyPasswd&lt;/SPAN&gt;&lt;SPAN&gt;=tyiImfLpqM5/qX1l0VsjK7sxhQx5YZFOZgstogGz8Ek&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.truststore&lt;/SPAN&gt;&lt;SPAN&gt;=./conf/truststore.jks&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.truststoreType&lt;/SPAN&gt;&lt;SPAN&gt;=jks&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.truststorePasswd&lt;/SPAN&gt;&lt;SPAN&gt;=vFF0nH+45S5ESohcQsH37s/bqJ/Kmy5RiHpL+ZWo2VU&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.user.authorizer&lt;/SPAN&gt;&lt;SPAN&gt;=managed-authorizer&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.allow.anonymous.authentication&lt;/SPAN&gt;&lt;SPAN&gt;=false&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.user.login.identity.provider&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.user.jws.key.rotation.period&lt;/SPAN&gt;&lt;SPAN&gt;=PT1H&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.ocsp.responder.url&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.ocsp.responder.certificate&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;# OpenId Connect SSO Properties #&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.user.oidc.discovery.url&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;A href="https://accounts.google.com/.well-known/openid-configuration" target="_blank" rel="noopener"&gt;https://accounts.google.com/.well-known/openid-configuration&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.user.oidc.connect.timeout&lt;/SPAN&gt;&lt;SPAN&gt;=5 secs&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.user.oidc.read.timeout&lt;/SPAN&gt;&lt;SPAN&gt;=5 secs&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.user.oidc.client.id&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;EM&gt;/*my generated client id*/&lt;/EM&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.user.oidc.client.secret&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;EM&gt;/*my generated client secret*/&lt;/EM&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.user.oidc.preferred.jwsalgorithm&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.user.oidc.additional.scopes&lt;/SPAN&gt;&lt;SPAN&gt;=offline_access&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.user.oidc.claim.identifying.user&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.user.oidc.fallback.claims.identifying.user&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.user.oidc.claim.groups&lt;/SPAN&gt;&lt;SPAN&gt;=groups&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.user.oidc.truststore.strategy&lt;/SPAN&gt;&lt;SPAN&gt;=JDK&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nifi.security.user.oidc.token.refresh.window&lt;/SPAN&gt;&lt;SPAN&gt;=60 secs&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;authorizers.xml is as follows:-&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;userGroupProvider&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;identifier&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;file-user-group-provider&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;identifier&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;class&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;org.apache.nifi.authorization.FileUserGroupProvider&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;class&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;property&lt;/SPAN&gt; &lt;SPAN&gt;name&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"Users File"&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;./conf/users.xml&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;property&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;property&lt;/SPAN&gt; &lt;SPAN&gt;name&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"Legacy Authorized Users File"&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;property&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;property&lt;/SPAN&gt; &lt;SPAN&gt;name&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"Initial User Identity 1"&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;myemailID&lt;/SPAN&gt;&lt;SPAN&gt;@gmail.c&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;property&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;userGroupProvider&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;accessPolicyProvider&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;identifier&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;file-access-policy-provider&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;identifier&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;class&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;org.apache.nifi.authorization.FileAccessPolicyProvider&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;class&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;property&lt;/SPAN&gt; &lt;SPAN&gt;name&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"User Group Provider"&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;file-user-group-provider&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;property&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;property&lt;/SPAN&gt; &lt;SPAN&gt;name&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"Authorizations File"&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;./conf/authorizations.xml&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;property&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;property&lt;/SPAN&gt; &lt;SPAN&gt;name&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"Initial Admin Identity"&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;myemailID@gmail.com&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;property&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;property&lt;/SPAN&gt; &lt;SPAN&gt;name&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"Legacy Authorized Users File"&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;property&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;property&lt;/SPAN&gt; &lt;SPAN&gt;name&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"Node Identity 1"&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;property&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;property&lt;/SPAN&gt; &lt;SPAN&gt;name&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"Node Group"&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;property&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;accessPolicyProvider&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;authorizer&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;identifier&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;managed-authorizer&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;identifier&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;class&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;org.apache.nifi.authorization.StandardManagedAuthorizer&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;class&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;property&lt;/SPAN&gt; &lt;SPAN&gt;name&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"Access Policy Provider"&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;file-access-policy-provider&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;property&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;authorizer&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-10-31 at 4.31.07 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/38807i885DF7A37D54CD44/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-10-31 at 4.31.07 PM.png" alt="Screenshot 2023-10-31 at 4.31.07 PM.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-10-31 at 4.31.15 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/38808i91240DC96832703D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-10-31 at 4.31.15 PM.png" alt="Screenshot 2023-10-31 at 4.31.15 PM.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;i also added cerficate for accounts.google.com in /conf/truststore.jks and cacerts in JRE and i'm still getting the same error.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;this is google api console setup as of now&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-10-31 at 4.34.21 PM.png" style="width: 790px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/38809iFA3BEEDB7B530F1F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-10-31 at 4.34.21 PM.png" alt="Screenshot 2023-10-31 at 4.34.21 PM.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;i'm trying to follow this article&amp;nbsp;&lt;A href="https://bryanbende.com/development/2017/10/03/apache-nifi-openid-connect" target="_blank" rel="noopener"&gt;https://bryanbende.com/development/2017/10/03/apache-nifi-openid-connect&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;please help me in fixing this issue. Thanks and Regards.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 31 Oct 2023 11:10:40 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/trying-to-authenticate-nifi-with-openID-using-google-oAuth/m-p/378368#M243514</guid>
      <dc:creator>jai1gupta</dc:creator>
      <dc:date>2023-10-31T11:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: trying to authenticate nifi with openID using google oAuth and getting an error.</title>
      <link>https://community.cloudera.com/t5/Support-Questions/trying-to-authenticate-nifi-with-openID-using-google-oAuth/m-p/378369#M243515</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35454"&gt;@MattWho&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/80381"&gt;@SAMSAL&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/103151"&gt;@cotopaul&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2023 11:11:37 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/trying-to-authenticate-nifi-with-openID-using-google-oAuth/m-p/378369#M243515</guid>
      <dc:creator>jai1gupta</dc:creator>
      <dc:date>2023-10-31T11:11:37Z</dc:date>
    </item>
    <item>
      <title>Re: trying to authenticate nifi with openID using google oAuth and getting an error.</title>
      <link>https://community.cloudera.com/t5/Support-Questions/trying-to-authenticate-nifi-with-openID-using-google-oAuth/m-p/378374#M243518</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/107566"&gt;@jai1gupta&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The exception:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This indicates a trust chain issue in your TLS exchange with accounts.google.com.&amp;nbsp; A complete trust chain requires all know public certs between certificate that signed for accounts.google.com --&amp;gt; intermediate CA(s) --&amp;gt; rootCA (owner and issuer same DN).&lt;BR /&gt;&lt;BR /&gt;Your configuration shows that the oidc authentication client configuration is set to:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;nifi.security.user.oidc.truststore.strategy=JDK&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;HTTPS Certificate Trust Store Strategy defines the source of certificate authorities that NiFi uses when communicating with the OpenID Connect Provider. The value of&amp;nbsp;&lt;/SPAN&gt;JDK&lt;SPAN&gt;&amp;nbsp;uses the Java platform default configuration stored in&amp;nbsp;&lt;/SPAN&gt;cacerts&lt;SPAN&gt;&amp;nbsp;under the Java Home directory. The value of&amp;nbsp;&lt;/SPAN&gt;NIFI&lt;SPAN&gt;&amp;nbsp;enables using the trust store configured in the&amp;nbsp;&lt;/SPAN&gt;nifi.security.truststore&lt;SPAN&gt;&amp;nbsp;property. The default value is&amp;nbsp;&lt;/SPAN&gt;JDK&lt;/P&gt;&lt;P&gt;This means that the Java version you have installed that NiFi is using is missing some trustedCertEntries from the trust chain for&amp;nbsp;accounts.google.com.&lt;BR /&gt;&lt;BR /&gt;Google makes all its public root and intermediate certificates available for download here:&lt;BR /&gt;&lt;A href="https://pki.goog/repository/#:~:text=Download%20CA%20certificates" target="_blank" rel="noopener"&gt;https://pki.goog/repository/#:~:text=Download%20CA%20certificates&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;You'll want to download all these (pem files) and add any that are missing from your Java's cacerts truststore file.&amp;nbsp;While you can use the following openssl command to get all the public certs in the chain,&amp;nbsp; you may find at times you get redirected to a different accounts.google.com server with a different trust chain.&amp;nbsp; So I recommend downloading all instead of just those returned by the openssl command:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;openssl s_client -connect accounts.google.com:443 -showcerts&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Restart your NiFi and this trust issue should be gone.&lt;BR /&gt;&lt;BR /&gt;I am confused why your google console setup is using http instead of https urls for your NiFi?&amp;nbsp; NiFi will not support authentication and authorization unless it is secured over https.&lt;/P&gt;&lt;P&gt;If you found any of the suggestions/solutions provided helped you with your issue, please take a moment to login and click "&lt;SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;Accept as Solution&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/EM&gt;" on one or more of them that helped.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you,&lt;BR /&gt;Matt&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2023 13:22:47 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/trying-to-authenticate-nifi-with-openID-using-google-oAuth/m-p/378374#M243518</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2023-10-31T13:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: trying to authenticate nifi with openID using google oAuth and getting an error.</title>
      <link>https://community.cloudera.com/t5/Support-Questions/trying-to-authenticate-nifi-with-openID-using-google-oAuth/m-p/378467#M243545</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35454"&gt;@MattWho&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;after changing the nifi.security.user.oidc.truststore.strategy to NIFI my error got resolved. now when i access the nifi on browser i get this error&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-11-02 at 4.18.10 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/38827i499A8DFB4EB88C48/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-11-02 at 4.18.10 PM.png" alt="Screenshot 2023-11-02 at 4.18.10 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-11-02 at 4.22.51 PM.png" style="width: 768px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/38829i088B1BF25430BF8E/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-11-02 at 4.22.51 PM.png" alt="Screenshot 2023-11-02 at 4.22.51 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;i think this error is because my nifi is not secured over https.&lt;/P&gt;&lt;P&gt;i've already ran this command&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-11-02 at 4.14.54 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/38828iEBE47C2DB8ECD35D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-11-02 at 4.14.54 PM.png" alt="Screenshot 2023-11-02 at 4.14.54 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;please tell me what can i do next to make it secured. Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 10:53:40 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/trying-to-authenticate-nifi-with-openID-using-google-oAuth/m-p/378467#M243545</guid>
      <dc:creator>jai1gupta</dc:creator>
      <dc:date>2023-11-02T10:53:40Z</dc:date>
    </item>
    <item>
      <title>Re: trying to authenticate nifi with openID using google oAuth and getting an error.</title>
      <link>https://community.cloudera.com/t5/Support-Questions/trying-to-authenticate-nifi-with-openID-using-google-oAuth/m-p/378483#M243553</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/107566"&gt;@jai1gupta&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;What makes you think your NiFi is not secured over https?&lt;BR /&gt;You did not share your nifi.properties web&amp;nbsp; properties.&lt;BR /&gt;If you have set the following properties:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;nifi.web.https.host=&amp;lt;hostname&amp;gt;
nifi.web.https.port=&amp;lt;port&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and have configured the NiFi keystore and truststore properties (which you did share), the your NiFi would have started at logged url being available over &lt;A href="https://community.cloudera.com/" target="_blank"&gt;HTTPS://&amp;lt;hostname&amp;gt;:&amp;lt;port&amp;gt;/nifi&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;My guess is your issue probably extends from the use of "localhost" instead of an actual resolvable hostname.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;If you found any of the suggestions/solutions provided helped you with your issue, please take a moment to login and click "&lt;SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;Accept as Solution&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/EM&gt;" on one or more of them that helped.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you,&lt;BR /&gt;Matt&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 16:54:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/trying-to-authenticate-nifi-with-openID-using-google-oAuth/m-p/378483#M243553</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2023-11-02T16:54:52Z</dc:date>
    </item>
  </channel>
</rss>

