<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Securing Apache Nifi 2.0.0-M2 and configure HTTPS in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Securing-Apache-Nifi-2-0-0-M2-and-configure-HTTPS/m-p/385198#M245647</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/109615"&gt;@darkcoffeelake&lt;/a&gt;&amp;nbsp;Welcome to the Cloudera Community!&lt;BR /&gt;&lt;BR /&gt;To help you get the best possible solution, I have tagged our NiFi experts&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/38301"&gt;@mburgess&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35454"&gt;@MattWho&lt;/a&gt;&amp;nbsp; who may be able to assist you further.&lt;BR /&gt;&lt;BR /&gt;Please keep us updated on your post, and we hope you find a satisfactory solution to your query.&lt;/P&gt;</description>
    <pubDate>Tue, 19 Mar 2024 18:24:22 GMT</pubDate>
    <dc:creator>DianaTorres</dc:creator>
    <dc:date>2024-03-19T18:24:22Z</dc:date>
    <item>
      <title>Securing Apache Nifi 2.0.0-M2 and configure HTTPS</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Securing-Apache-Nifi-2-0-0-M2-and-configure-HTTPS/m-p/385181#M245638</link>
      <description>&lt;P&gt;Hey everyone, I was surfing the web since this morning looking for a way/guide/tutorial on how to secure Nifi so I can connect via https and not http but couldn't find anything that was compatible with the 2.0.0-M2 version.&lt;BR /&gt;&lt;BR /&gt;I am new to Nifi and i just want to secure my access to it.&lt;BR /&gt;&lt;BR /&gt;most of the guides i've stumbled upon use the nifi-toolkit with the command&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;./bin/tls-toolkit.sh standalone -C "CN=my_username, OU=NiFi"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;to&amp;nbsp;&lt;SPAN&gt;generate and sign the client certificate for the access, alongside some tweaks in the nifi.properties file.&lt;BR /&gt;but in the toolkit version of nifi-2.0.0-M2, there is no file called &lt;STRONG&gt;tls-toolkit.sh&amp;nbsp;&lt;BR /&gt;&lt;/STRONG&gt;so im kinda lost here as there is only :&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="darkcoffeelake_0-1710854738987.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/40089i48D9A2B83FC754C3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="darkcoffeelake_0-1710854738987.png" alt="darkcoffeelake_0-1710854738987.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;and according to the documentations with these scripts i didnt know how to secure nifi with the standalone method.&lt;BR /&gt;&lt;BR /&gt;could someone please help provide some insights on how to secure nifi with https?&amp;nbsp;&lt;BR /&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2024 13:28:08 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Securing-Apache-Nifi-2-0-0-M2-and-configure-HTTPS/m-p/385181#M245638</guid>
      <dc:creator>darkcoffeelake</dc:creator>
      <dc:date>2024-03-19T13:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Apache Nifi 2.0.0-M2 and configure HTTPS</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Securing-Apache-Nifi-2-0-0-M2-and-configure-HTTPS/m-p/385198#M245647</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/109615"&gt;@darkcoffeelake&lt;/a&gt;&amp;nbsp;Welcome to the Cloudera Community!&lt;BR /&gt;&lt;BR /&gt;To help you get the best possible solution, I have tagged our NiFi experts&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/38301"&gt;@mburgess&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35454"&gt;@MattWho&lt;/a&gt;&amp;nbsp; who may be able to assist you further.&lt;BR /&gt;&lt;BR /&gt;Please keep us updated on your post, and we hope you find a satisfactory solution to your query.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2024 18:24:22 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Securing-Apache-Nifi-2-0-0-M2-and-configure-HTTPS/m-p/385198#M245647</guid>
      <dc:creator>DianaTorres</dc:creator>
      <dc:date>2024-03-19T18:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Apache Nifi 2.0.0-M2 and configure HTTPS</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Securing-Apache-Nifi-2-0-0-M2-and-configure-HTTPS/m-p/385285#M245672</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/109615"&gt;@darkcoffeelake&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;NiFi out-of-the-box setup generates simply keystore and truststore automatically and set the login provider to single-user-provider and authorizer to single-user-authorizer.&amp;nbsp; This out-of-the-box setup is simplifies secured access for evaluation of NiFi.&amp;nbsp; It is not a production ready setup in that it does not support multi-user authentication, granular access controls, or NiFi cluster setups.&lt;BR /&gt;&lt;BR /&gt;There are bunch of steps that go into securing Apache NiFi for production ready environments.&amp;nbsp; Securing NiFi not only sets up NiFi over an HTTPS connection, but also requires that user authentication and authorization is setup.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;NiFi will require a keystore and truststore which youcan create yourself or use publicly available service to create them for you (example would be tinycert).&amp;nbsp; The keystore created for you NiFi must meet the following requirements for NiFi:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Contains only 1 PrivateKey entry.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Does not use wildcards in the DN of PrivateKey certificate.&lt;/LI&gt;&lt;LI&gt;Has both clientAuth and serverAuth Extended key Usage (EKU)&lt;/LI&gt;&lt;LI&gt;Has SubjectAlternativeNames (SAN) entry(s) matching NiFi hostname and any other name that may be used to access the NiFi.&amp;nbsp;&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;The truststore needs to contain the complete trust chain for your NiFi keystore certficate.&amp;nbsp; A certifcate might be self signed (meaning both issuer and signer are same DN), it may be signed by an intermediate CA, or rootCA.&amp;nbsp; &amp;nbsp; &amp;nbsp; If signed by an intermeidiate CA, your truststore would need to have the trustedCertEntry (public key) for the intermediate CA (intermediate CA is any CA where signer and issuer are different DNs) and the trusted certEntry for that signer and so until you reach the root CA in the chain (root CA will have same signer and issuer DN).&lt;BR /&gt;&lt;BR /&gt;Once you have your certificates, you'll need to decide how your users are going to authenticate with NiFi.&amp;nbsp; NiFi does not have a embedded provider that supports multi-user authentication.&amp;nbsp; Here is what is available to choose from:&lt;/P&gt;&lt;P&gt;&lt;A href="https://nifi.apache.org/documentation/nifi-2.0.0-M1/html/administration-guide.html#user_authentication" target="_blank" rel="noopener"&gt;User Authentication&lt;/A&gt;&lt;/P&gt;&lt;P&gt;LDAP and Kerberos are probably the most commonly used.&lt;BR /&gt;&lt;BR /&gt;Once you have decided how you are going to authenticate your users, you'll need to setup authorization for those users.&amp;nbsp; here are your options here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://nifi.apache.org/documentation/nifi-2.0.0-M1/html/administration-guide.html#multi-tenant-authorization" target="_blank" rel="noopener"&gt;Multi-Tenant Authorization&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The simplest authorizers.xml setup would utilize the&amp;nbsp;&amp;nbsp;&lt;A href="https://nifi.apache.org/documentation/nifi-2.0.0-M1/html/administration-guide.html#standardmanagedauthorizer" target="_blank" rel="noopener"&gt;StandardManagedAuthorizer&lt;/A&gt;,&amp;nbsp;&lt;A href="https://nifi.apache.org/documentation/nifi-2.0.0-M1/html/administration-guide.html#fileaccesspolicyprovider" target="_blank" rel="noopener"&gt;FileAccessPolicyProvider&lt;/A&gt;, and&amp;nbsp;&lt;A href="https://nifi.apache.org/documentation/nifi-2.0.0-M1/html/administration-guide.html#fileusergroupprovider" target="_blank" rel="noopener"&gt;FileUserGroupProvider&lt;/A&gt;.&lt;BR /&gt;a sample configuration can be seen here:&lt;BR /&gt;&lt;A href="https://nifi.apache.org/documentation/nifi-2.0.0-M1/html/administration-guide.html#file-based-ldap-authentication" target="_blank" rel="noopener"&gt;https://nifi.apache.org/documentation/nifi-2.0.0-M1/html/administration-guide.html#file-based-ldap-authentication&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If setup correctly, on first startup, the above authorizers.xml will generate and seed the users.xml and authorizations.xml file so that your initial admin user (a ldap user or kerberos user for example) with the necessary authorization policies to access the NiFi UI.&amp;nbsp; From the NiFi UI, that initial admin user can setup additional user identity authorizations.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;If you found any of the suggestions/solutions provided helped you with your issue, please take a moment to login and click "&lt;SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;Accept as Solution&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/EM&gt;" on one or more of them that helped.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you,&lt;BR /&gt;Matt&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 19:52:11 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Securing-Apache-Nifi-2-0-0-M2-and-configure-HTTPS/m-p/385285#M245672</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2024-03-20T19:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Apache Nifi 2.0.0-M2 and configure HTTPS</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Securing-Apache-Nifi-2-0-0-M2-and-configure-HTTPS/m-p/385486#M245714</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35454"&gt;@MattWho&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your answer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you make a video for setup an instance of Nifi with a self signed Domain?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2024 08:52:31 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Securing-Apache-Nifi-2-0-0-M2-and-configure-HTTPS/m-p/385486#M245714</guid>
      <dc:creator>Dataengineer1</dc:creator>
      <dc:date>2024-03-25T08:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Apache Nifi 2.0.0-M2 and configure HTTPS</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Securing-Apache-Nifi-2-0-0-M2-and-configure-HTTPS/m-p/385496#M245717</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/106071"&gt;@Dataengineer1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Even I was looking for similar sort of solution, latest version seems different from the older one. New toolkit does not have the standalone command to generate the certificate.&lt;/P&gt;&lt;P&gt;Check below video might help you. ( This is old vlog)&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=LanpbWR7Gv8" target="_blank" rel="noopener"&gt;https://www.youtube.com/watch?v=LanpbWR7Gv8&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2024 11:12:11 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Securing-Apache-Nifi-2-0-0-M2-and-configure-HTTPS/m-p/385496#M245717</guid>
      <dc:creator>saquibsk</dc:creator>
      <dc:date>2024-03-25T11:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Apache Nifi 2.0.0-M2 and configure HTTPS</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Securing-Apache-Nifi-2-0-0-M2-and-configure-HTTPS/m-p/385497#M245718</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/104295"&gt;@saquibsk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank for your reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For generating these keys. I used the toolkit:&amp;nbsp;https:// &lt;A href="http://www.apache.org/dyn/closer.lua?path=/nifi/1.25.0/nifi-toolkit-1.25.0-bin.zip" target="_blank" rel="noopener"&gt;www.apache.org/dyn/closer.lua?path=/nifi/1.25.0/nifi-toolkit-1.25.0-bin.zip&lt;/A&gt;&lt;/P&gt;&lt;DIV class="simple-translate-system-theme"&gt;&lt;DIV&gt;&lt;DIV class="simple-translate-button "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="simple-translate-system-theme"&gt;&lt;DIV&gt;&lt;DIV class="simple-translate-panel isShow"&gt;&lt;DIV class="simple-translate-result-wrapper"&gt;&lt;DIV class="simple-translate-result-contents"&gt;&lt;P class="simple-translate-candidate"&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 25 Mar 2024 11:29:23 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Securing-Apache-Nifi-2-0-0-M2-and-configure-HTTPS/m-p/385497#M245718</guid>
      <dc:creator>Dataengineer1</dc:creator>
      <dc:date>2024-03-25T11:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Apache Nifi 2.0.0-M2 and configure HTTPS</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Securing-Apache-Nifi-2-0-0-M2-and-configure-HTTPS/m-p/385501#M245719</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/106071"&gt;@Dataengineer1&lt;/a&gt;,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Did you get a chance to impliment it?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Try below to impliment it. If worked please create document and upload in community to help others &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.youtube.com/watch?v=j-JXo3xPxOk" target="_blank"&gt;https://www.youtube.com/watch?v=j-JXo3xPxOk&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2024 11:39:36 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Securing-Apache-Nifi-2-0-0-M2-and-configure-HTTPS/m-p/385501#M245719</guid>
      <dc:creator>saquibsk</dc:creator>
      <dc:date>2024-03-25T11:39:36Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Apache Nifi 2.0.0-M2 and configure HTTPS</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Securing-Apache-Nifi-2-0-0-M2-and-configure-HTTPS/m-p/385809#M245842</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/106071"&gt;@Dataengineer1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Did you get a chance to implement it? Would you kindly share the resolution if it is done?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 07:30:37 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Securing-Apache-Nifi-2-0-0-M2-and-configure-HTTPS/m-p/385809#M245842</guid>
      <dc:creator>saquibsk</dc:creator>
      <dc:date>2024-04-01T07:30:37Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Apache Nifi 2.0.0-M2 and configure HTTPS</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Securing-Apache-Nifi-2-0-0-M2-and-configure-HTTPS/m-p/386300#M245991</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/109615"&gt;@darkcoffeelake&lt;/a&gt;&amp;nbsp;Has the reply helped resolve your issue? If so, please mark the appropriate reply as the solution, as it will make it easier for others to find the answer in the future. Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 15:43:44 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Securing-Apache-Nifi-2-0-0-M2-and-configure-HTTPS/m-p/386300#M245991</guid>
      <dc:creator>DianaTorres</dc:creator>
      <dc:date>2024-04-08T15:43:44Z</dc:date>
    </item>
  </channel>
</rss>

