<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Nifi LDAPS Configuration in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Nifi-LDAPS-Configuration/m-p/382104#M244491</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/106948"&gt;@LKB&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I recommend creating a new community question with the details around yoru setup and exceptions you may be seeing.&amp;nbsp; You are more likely to get better traction on a community question that does not already have and accepted solution.&lt;/P&gt;&lt;P&gt;Thank you,&lt;BR /&gt;Matt&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jan 2024 14:07:05 GMT</pubDate>
    <dc:creator>MattWho</dc:creator>
    <dc:date>2024-01-12T14:07:05Z</dc:date>
    <item>
      <title>Nifi LDAPS Configuration</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-LDAPS-Configuration/m-p/329327#M230426</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Im trying to connect LDAP from Nifi.&lt;/P&gt;&lt;P class="tw-data-text tw-text-large XcVN5d tw-ta"&gt;&lt;SPAN class="Y2IQFc"&gt;I've done most of the instructions in the official documentation and read most posts on the Cloudera Community. However, I couldn't connect to my company's LDAP system.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="tw-data-text tw-text-large XcVN5d tw-ta"&gt;&lt;SPAN class="Y2IQFc"&gt;I configured login-entity-providers and authorizers for LDAP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="tw-data-text tw-text-large XcVN5d tw-ta"&gt;&lt;SPAN class="Y2IQFc"&gt;When I start Nifi, it starts successfully and gives no error.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="tw-data-text tw-text-large XcVN5d tw-ta"&gt;&lt;SPAN class="Y2IQFc"&gt;When I try to log in with my initial admin it gives me &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="tw-data-text tw-text-large XcVN5d tw-ta"&gt;&lt;SPAN class="Y2IQFc"&gt;"&lt;SPAN&gt;Unable to validate the supplied credentials. Please contact the system administrator.&lt;/SPAN&gt;" error.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="tw-data-text tw-text-large XcVN5d tw-ta"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="tw-data-text tw-text-large XcVN5d tw-ta"&gt;My questions are:&lt;/P&gt;&lt;P class="tw-data-text tw-text-large XcVN5d tw-ta"&gt;1- When we are setting up initial admin, we are not setting password of that user. How do we log in without password?&lt;/P&gt;&lt;P class="tw-data-text tw-text-large XcVN5d tw-ta"&gt;2- I'm using USE_DN for identity strategy for ldap-provider. My initial admin name and ldap user are same. So I'm trying to login with my user like:&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Username: CN=K015576,CN=Users,DC=tcmb,DC=gov,DC=tr&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Password: "my_ldap_password"&lt;BR /&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;P class="tw-data-text tw-text-large XcVN5d tw-ta"&gt;&lt;SPAN class="Y2IQFc"&gt;What path should I follow? Is there a mistake in my configure files?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="tw-data-text tw-text-large XcVN5d tw-ta"&gt;&lt;SPAN class="Y2IQFc"&gt;I have added my conf files below: nifi.properties, login-entity-provider and authorizers. Removed sensitive data.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="tw-data-text tw-text-large XcVN5d tw-ta"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="tw-data-text tw-text-large XcVN5d tw-ta"&gt;&lt;SPAN class="Y2IQFc"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nifi-properties" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/32771i8DFC52A91BC4140A/image-size/large?v=v2&amp;amp;px=999" role="button" title="nifi.properties.PNG" alt="nifi-properties" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;nifi-properties&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="login-identity-providers" style="width: 826px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/32773iD8A74EE5C799C955/image-size/large?v=v2&amp;amp;px=999" role="button" title="login-identity-providers.PNG" alt="login-identity-providers" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;login-identity-providers&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="authorizers-1" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/32772iCD5A506A47736CAD/image-size/large?v=v2&amp;amp;px=999" role="button" title="authorizers-1.PNG" alt="authorizers-1" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;authorizers-1&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="authorizers-2" style="width: 907px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/32774iD28D3C2A013F2BFE/image-size/large?v=v2&amp;amp;px=999" role="button" title="authorizers-2.PNG" alt="authorizers-2" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;authorizers-2&lt;/span&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="tw-data-text tw-text-large XcVN5d tw-ta"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="tw-data-text tw-text-large XcVN5d tw-ta"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="tw-data-text tw-text-large XcVN5d tw-ta"&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 01 Nov 2021 07:48:55 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-LDAPS-Configuration/m-p/329327#M230426</guid>
      <dc:creator>Yemre</dc:creator>
      <dc:date>2021-11-01T07:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi LDAPS Configuration</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-LDAPS-Configuration/m-p/329410#M230450</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/93216"&gt;@Yemre&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The following response you see in the NiFi UI after supplying a username and password in the tells you that the issue happened during the user authentication process:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;"Unable to validate the supplied credentials. Please contact the system administrator."&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;NiFi has not even tried to do any authorization yet, so your authorizers.xml setup has not come in to the equation yet.&lt;BR /&gt;&lt;BR /&gt;Unfortunately, the error produced by the openldap client is rather generic and could mean any of the following could be the issue:&lt;BR /&gt;1. incorrect ldap/AD manager DN&lt;BR /&gt;2. Incorrect ldap/AD manager password&lt;BR /&gt;3. Incorrect username&lt;BR /&gt;4. Incorrect user password&lt;BR /&gt;5. Incorrect user search filter in the login-identity-providers.xml file&lt;BR /&gt;&lt;BR /&gt;In your case it looks like number 5 may be your issue:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MattWho_0-1635858497041.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/32778iFBF3147D277EB730/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MattWho_0-1635858497041.png" alt="MattWho_0-1635858497041.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The ldap-provider expects that the username typed in the login window is passed via the "User Search Filter" so that the entered user's credentials can be verified.&lt;BR /&gt;&lt;BR /&gt;I noticed you are using full DNs to login with which is extremely rare.&amp;nbsp; The more common approach here is to configure your ldap-provider with "Identity strategy" of "USE_USERNAME" instead of "USE_DN".&amp;nbsp; This means upon successful user authentication, it is the user string entered in the login window that is used to authorize your user instead of the user's full DN.&amp;nbsp; This means your initial admin string should match your username as you would type it in at the login prompt.&lt;BR /&gt;&lt;BR /&gt;In order to pass the entered string at the login prompt to the ldap-provider, your "User Search Filter" would need to look something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;property name="User Search Filter"&amp;gt;(cn={0})&amp;lt;/property&amp;gt;

or

&amp;lt;property name="User Search Filter"&amp;gt;(sAMAccountName={0})&amp;lt;/property&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;You should inspect your user ldap/AD entry to see which attribute in your ldap entry contain your username that you type in the login prompt.&lt;BR /&gt;&lt;BR /&gt;The user entered username at login is substituted in place of "{0}" in the User Search Filter.&lt;BR /&gt;&lt;BR /&gt;When you change the initial admin user string from the full DN to just the username, you would need to remove the old authorizations.xml (NOT the authoirizers.xml) file that was built originally with the full DN by the file-access-policy-provider in your authorizers.xml.&amp;nbsp; The authorizatiions.xml file is only seeded via the file-access-policy-provider if the file does not already exist.&amp;nbsp; Once it exist all future edits to content of this file is handled via changes made from within the NiFi UI.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;If you found this response assisted with your query, please take a moment to login and click on "&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;" below this post.&lt;BR /&gt;&lt;BR /&gt;Thank you,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 13:54:28 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-LDAPS-Configuration/m-p/329410#M230450</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2021-11-02T13:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi LDAPS Configuration</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-LDAPS-Configuration/m-p/329415#M230452</link>
      <description>&lt;P&gt;Thanks a lot Matt. It worked finally after trying for 2 weeks.&amp;nbsp;I was tired of trying to get this to work.&amp;nbsp;I really appreciate it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 14:19:06 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-LDAPS-Configuration/m-p/329415#M230452</guid>
      <dc:creator>Yemre</dc:creator>
      <dc:date>2021-11-02T14:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi LDAPS Configuration</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-LDAPS-Configuration/m-p/376412#M242901</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/93216"&gt;@Yemre&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello Bro,&lt;/P&gt;&lt;P&gt;I am trying to set up LDAP and have been loosing hair on getting the right configuration for over a week now. I am trying to configure for LDAPS in NiFi and already have my keystore and trust generated internally so my issue seems quite similar to yours. Can I see the copy of your nifi.properties,&amp;nbsp;&lt;SPAN&gt;login-identity-providers, authorizers.xml (without any sensitive information, of course) that finally worked? I will really appreciate any assistance for you. Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Sep 2023 12:53:41 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-LDAPS-Configuration/m-p/376412#M242901</guid>
      <dc:creator>LKB</dc:creator>
      <dc:date>2023-09-16T12:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi LDAPS Configuration</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-LDAPS-Configuration/m-p/382075#M244483</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/106948"&gt;@LKB&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Just saw your message. Since I have changed my job, I am not able to access those files anymore. Sorry for that.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 08:30:35 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-LDAPS-Configuration/m-p/382075#M244483</guid>
      <dc:creator>Yemre</dc:creator>
      <dc:date>2024-01-12T08:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi LDAPS Configuration</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-LDAPS-Configuration/m-p/382104#M244491</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/106948"&gt;@LKB&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I recommend creating a new community question with the details around yoru setup and exceptions you may be seeing.&amp;nbsp; You are more likely to get better traction on a community question that does not already have and accepted solution.&lt;/P&gt;&lt;P&gt;Thank you,&lt;BR /&gt;Matt&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 14:07:05 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-LDAPS-Configuration/m-p/382104#M244491</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2024-01-12T14:07:05Z</dc:date>
    </item>
  </channel>
</rss>

