<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Insufficient Permissions  Untrusted proxy CN=Node_name, OU=NIFI in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Insufficient-Permissions-Untrusted-proxy-CN-Node-name-OU/m-p/390072#M247172</link>
    <description>&lt;P&gt;i face the mentuioned error while logging to nifi althogh in log files no error found and according to logs my ldap user logged successfully as below:&lt;/P&gt;&lt;P&gt;2024-07-10 11:12:19,489 INFO [NiFi Web Server-33] o.a.n.w.s.NiFiAuthenticationFilter Authentication success for AMOHAMED279&lt;BR /&gt;2024-07-10 11:20:07,893 INFO [NiFi Web Server-71] o.a.n.w.s.NiFiAuthenticationFilter Attempting request for (&amp;lt;JWT token&amp;gt;) GET &lt;A href="https://node_name:9443/nifi-api/flow/current-user" target="_blank" rel="noopener"&gt;https://node_name:9443/nifi-api/flow/current-user&lt;/A&gt; (source ip: 10.230.237.150)&lt;BR /&gt;2024-07-10 11:20:07,895 INFO [NiFi Web Server-71] o.a.n.w.s.NiFiAuthenticationFilter Authentication success for AMOHAMED279&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Apr 2026 06:28:50 GMT</pubDate>
    <dc:creator>3ebs</dc:creator>
    <dc:date>2026-04-21T06:28:50Z</dc:date>
    <item>
      <title>Insufficient Permissions  Untrusted proxy CN=Node_name, OU=NIFI</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Insufficient-Permissions-Untrusted-proxy-CN-Node-name-OU/m-p/390072#M247172</link>
      <description>&lt;P&gt;i face the mentuioned error while logging to nifi althogh in log files no error found and according to logs my ldap user logged successfully as below:&lt;/P&gt;&lt;P&gt;2024-07-10 11:12:19,489 INFO [NiFi Web Server-33] o.a.n.w.s.NiFiAuthenticationFilter Authentication success for AMOHAMED279&lt;BR /&gt;2024-07-10 11:20:07,893 INFO [NiFi Web Server-71] o.a.n.w.s.NiFiAuthenticationFilter Attempting request for (&amp;lt;JWT token&amp;gt;) GET &lt;A href="https://node_name:9443/nifi-api/flow/current-user" target="_blank" rel="noopener"&gt;https://node_name:9443/nifi-api/flow/current-user&lt;/A&gt; (source ip: 10.230.237.150)&lt;BR /&gt;2024-07-10 11:20:07,895 INFO [NiFi Web Server-71] o.a.n.w.s.NiFiAuthenticationFilter Authentication success for AMOHAMED279&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 06:28:50 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Insufficient-Permissions-Untrusted-proxy-CN-Node-name-OU/m-p/390072#M247172</guid>
      <dc:creator>3ebs</dc:creator>
      <dc:date>2026-04-21T06:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: Insufficient Permissions  Untrusted proxy CN=Node_name, OU=NIFI</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Insufficient-Permissions-Untrusted-proxy-CN-Node-name-OU/m-p/390437#M247263</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/111521"&gt;@3ebs&lt;/a&gt;,&amp;nbsp;Welcome to our community! To help you get the best possible answer, I have tagged in our NiFi experts&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/80381"&gt;@SAMSAL&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35454"&gt;@MattWho&lt;/a&gt;&amp;nbsp; who may be able to assist you further.&lt;BR /&gt;&lt;BR /&gt;Please feel free to provide any additional information or details about your query, and we hope that you will find a satisfactory solution to your question.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2024 08:08:54 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Insufficient-Permissions-Untrusted-proxy-CN-Node-name-OU/m-p/390437#M247263</guid>
      <dc:creator>VidyaSargur</dc:creator>
      <dc:date>2024-07-16T08:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: Insufficient Permissions  Untrusted proxy CN=Node_name, OU=NIFI</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Insufficient-Permissions-Untrusted-proxy-CN-Node-name-OU/m-p/390476#M247270</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/111521"&gt;@3ebs&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The "Insufficient Permissions Untrusted proxy CN=Node_name,OU=NIFI" shown in the webui when you try to login is not an error.&amp;nbsp; It is an authorization issue.&lt;BR /&gt;&lt;BR /&gt;It tells me that you have a multi-node NiFi cluster setup. You are accessing the UI of one of the NiFi cluster nodes where you are successfully authenticating your user resulting the a user identity of "&lt;SPAN&gt;AMOHAMED279".&amp;nbsp; &amp;nbsp; At this point your user is only successfully authenticated to the one node.&amp;nbsp; What that node does next is to load the NiFi canvas.&amp;nbsp; In order to display that canvas, information that the user is authorized to see (PG, stats, etc) must be collected from all nodes.&amp;nbsp; That requets is forwarded to the elected cluster coordinator node which then replicates that request to all nodes to get those details.&amp;nbsp; So the node itself acts as a proxy in this process making these requests on the authenticated users behalf.&amp;nbsp; &amp;nbsp;In order for this to be successful, the NiFi nodes in your cluster must be authorized to proxy user requests.&amp;nbsp; This message is telling you that one or more of your node identities has not been authorized to proxy user requests.&lt;BR /&gt;&lt;BR /&gt;To help here more, I would need to know what you have configured in the authorizers.xml for user identity authorization.&amp;nbsp; The most common NiFi cluster setup utilizes the standardManagedAuthorizer which calls the file-access-policy-provider (builds the authorizations.xml if it does not already exist) which call one of the user-group-providers (There are multiple options: Composite-Configurable-User-Group-Provider, Composite-User-group-Provider, Ldap-User-Group-Provider, File-User-Group-Provider, etc.).&amp;nbsp; &amp;nbsp;The user-group-providers are responsible for generating user identities (case sensitive) for the purpose of setting up authorization policies.&amp;nbsp; The file-user-group-provider is most commonly used to add the node user identities&amp;nbsp; by creating the users.xml (if it does not already exist).&lt;BR /&gt;&lt;BR /&gt;So somewhere in your authorizers.xml setup, your node user identities have not been added and/or authorized for various policies to include the very important "proxy user requests" which would have been automatically handled on initial startup and first creation of the authorizations.xml and users.xml files assuming a proper setup in the authorizers.xml.&lt;BR /&gt;&lt;BR /&gt;Resources:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL class="sectlevel2"&gt;&lt;LI&gt;&lt;A href="https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html#authorizer-configuration" target="_blank" rel="noopener"&gt;Authorizer Configuration&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html#fileusergroupprovider" target="_blank" rel="noopener"&gt;FileUserGroupProvider&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html#ldapusergroupprovider" target="_blank" rel="noopener"&gt;LdapUserGroupProvider&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html#composite-implementations" target="_blank" rel="noopener"&gt;Composite Implementations&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html#fileaccesspolicyprovider" target="_blank" rel="noopener"&gt;FileAccessPolicyProvider&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html#standardmanagedauthorizer" target="_blank" rel="noopener"&gt;StandardManagedAuthorizer&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html#config-users-access-policies" target="_blank" rel="noopener"&gt;Configuring Users &amp;amp; Access Policies&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;DIV class="lia-quilt-row lia-quilt-row-main"&gt;&lt;DIV class="lia-quilt-column lia-quilt-column-24 lia-quilt-column-single lia-quilt-column-main-content"&gt;&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-single"&gt;&lt;DIV class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;&lt;BR /&gt;Please help our community thrive. If you found&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;any&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;of the suggestions/solutions provided helped you with solving your issue or answering your question, please take a moment to login and click "&lt;SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;Accept as Solution&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/EM&gt;" on&amp;nbsp;&lt;STRONG&gt;one or more&lt;/STRONG&gt;&amp;nbsp;of them that helped.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you,&lt;BR /&gt;Matt&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="lia-quilt-row lia-quilt-row-footer"&gt;&lt;DIV class="lia-quilt-column lia-quilt-column-24 lia-quilt-column-single lia-quilt-column-common-footer"&gt;&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-single"&gt;&lt;DIV class="message_stats"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 16 Jul 2024 12:43:55 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Insufficient-Permissions-Untrusted-proxy-CN-Node-name-OU/m-p/390476#M247270</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2024-07-16T12:43:55Z</dc:date>
    </item>
  </channel>
</rss>

