<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question how to integrate NiFi and ldap and how to add differ users for Nifi web access? in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-integrate-NiFi-and-ldap-and-how-to-add-differ-users/m-p/121054#M38928</link>
    <description />
    <pubDate>Fri, 26 Aug 2016 16:52:32 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2016-08-26T16:52:32Z</dc:date>
    <item>
      <title>how to integrate NiFi and ldap and how to add differ users for Nifi web access?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-integrate-NiFi-and-ldap-and-how-to-add-differ-users/m-p/121054#M38928</link>
      <description />
      <pubDate>Fri, 26 Aug 2016 16:52:32 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-integrate-NiFi-and-ldap-and-how-to-add-differ-users/m-p/121054#M38928</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2016-08-26T16:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: how to integrate NiFi and ldap and how to add differ users for Nifi web access?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-integrate-NiFi-and-ldap-and-how-to-add-differ-users/m-p/121055#M38929</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/3134/sanchinakishore.html" nodeid="3134"&gt;@kishore sanchina&lt;/A&gt;&lt;/P&gt;&lt;P&gt;NiFi only supports user controlled access when it is configured to run securely over HTTPS.&lt;/P&gt;&lt;P&gt;The HTTPS configuration of NiFi will require a keystore and truststore is created/provided.  If you don't have a corporately provided PKI infrastructure that can provide your with TLS certificates for this purpose, you can create your own.  The following HCC article will walk you through manually creating your own:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.hortonworks.com/articles/17293/how-to-create-user-generated-keys-for-securing-nif.html" target="_blank"&gt;https://community.hortonworks.com/articles/17293/how-to-create-user-generated-keys-for-securing-nif.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Once your NiFi is setup securely, you will need to enable user access to the UI.&lt;/P&gt;&lt;P&gt;There are two parts to successful access:&lt;/P&gt;&lt;P&gt;1. User authentication  &amp;lt;-- This can accomplished via TLS certificates, LDAP, or Kerberos.  Setting up NiFi to use one of these login identity providers is covered here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html#user-authentication" target="_blank"&gt;https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html#user-authentication&lt;/A&gt;&lt;/P&gt;&lt;P&gt;2. User Authorization  &amp;lt;--  This is accomplished through NiFi via the authorized-users.xml file.  This process is documented here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html#controlling-levels-of-access" target="_blank"&gt;https://nifi.apache.org/docs/nifi-docs/html/administration-guide.html#controlling-levels-of-access&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You will need to manually populate the Authorized-users.xml file with your first "Admin" role user.  That Admin user will be able to approve access to other users who have passed the authentication phase and submitted a UI based authorization request.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2016 19:00:44 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-integrate-NiFi-and-ldap-and-how-to-add-differ-users/m-p/121055#M38929</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2016-08-26T19:00:44Z</dc:date>
    </item>
  </channel>
</rss>

