<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Looking for details for generating client certificate when not using NiFi CA in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-details-for-generating-client-certificate-when/m-p/105197#M46386</link>
    <description>&lt;P&gt;
	If you are not using the NiFi CA, you can still secure your HDF instances by providing each with resources meeting the following requirements:&lt;/P&gt;&lt;UL&gt;
	
&lt;LI&gt;Keystore

	
&lt;UL&gt;
		
&lt;LI&gt;The keystore must contain a &lt;CODE&gt;PrivateKeyEntry&lt;/CODE&gt; containing the private key and public certificate with valid dates and a DN matching the fully-qualified domain name (FQDN) of the host, and if signed by another key, the public certificate of that resource&lt;/LI&gt;	&lt;/UL&gt;&lt;/LI&gt;	
&lt;LI&gt;Truststore
	
&lt;UL&gt;
		
&lt;LI&gt;The truststore must contain a &lt;CODE&gt;trustedCertEntry&lt;/CODE&gt; containing the public certificate of each authorized user or the CA used to sign the individual certificates. &lt;/LI&gt;	&lt;/UL&gt;&lt;/LI&gt;	
&lt;LI&gt;The &lt;CODE&gt;nifi.properties&lt;/CODE&gt; file must contain the path to each keystore and truststore and the corresponding password to access each. &lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;
	To configure LDAP authentication, you follow the same steps as for a standalone instance. The &lt;CODE&gt;nifi.properties&lt;/CODE&gt; and &lt;CODE&gt;login-identity-providers.xml&lt;/CODE&gt; files must be synchronized to all nodes in the cluster.&lt;/P&gt;</description>
    <pubDate>Wed, 16 Nov 2016 09:55:55 GMT</pubDate>
    <dc:creator>alopresto</dc:creator>
    <dc:date>2016-11-16T09:55:55Z</dc:date>
    <item>
      <title>Looking for details for generating client certificate when not using NiFi CA</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-details-for-generating-client-certificate-when/m-p/105196#M46385</link>
      <description>&lt;P&gt;Hi, we are installing HDF 2 using Ambari and in the step to secure nifi. We have generated certificate and not using NiFi CA.&lt;/P&gt;&lt;P&gt;Trying to follow instructions here: &lt;/P&gt;&lt;P&gt;&lt;A href="https://community.hortonworks.com/articles/58009/hdf-20-enable-ssl-for-apache-nifi-from-ambari.html" target="_blank"&gt;https://community.hortonworks.com/articles/58009/hdf-20-enable-ssl-for-apache-nifi-from-ambari.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://docs.hortonworks.com/HDPDocuments/HDF2/HDF-2.0.1/bk_ambari-installation/content/generating-client-certificates.html" target="_blank"&gt;http://docs.hortonworks.com/HDPDocuments/HDF2/HDF-2.0.1/bk_ambari-installation/content/generating-client-certificates.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The instructions are specific to using NiFi CA and am having trouble in understanding what to do if we are not using NiFi CA. We also want to use LDAP authentication which we had done on a standalone nifi instance and are hoping to do the same with this cluster instance. Our installation of nifi through ambari does work in non ssl mode.&lt;/P&gt;&lt;P&gt;Any help/direction is appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 12:26:57 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-details-for-generating-client-certificate-when/m-p/105196#M46385</guid>
      <dc:creator>setty_sharath</dc:creator>
      <dc:date>2026-04-21T12:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for details for generating client certificate when not using NiFi CA</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-details-for-generating-client-certificate-when/m-p/105197#M46386</link>
      <description>&lt;P&gt;
	If you are not using the NiFi CA, you can still secure your HDF instances by providing each with resources meeting the following requirements:&lt;/P&gt;&lt;UL&gt;
	
&lt;LI&gt;Keystore

	
&lt;UL&gt;
		
&lt;LI&gt;The keystore must contain a &lt;CODE&gt;PrivateKeyEntry&lt;/CODE&gt; containing the private key and public certificate with valid dates and a DN matching the fully-qualified domain name (FQDN) of the host, and if signed by another key, the public certificate of that resource&lt;/LI&gt;	&lt;/UL&gt;&lt;/LI&gt;	
&lt;LI&gt;Truststore
	
&lt;UL&gt;
		
&lt;LI&gt;The truststore must contain a &lt;CODE&gt;trustedCertEntry&lt;/CODE&gt; containing the public certificate of each authorized user or the CA used to sign the individual certificates. &lt;/LI&gt;	&lt;/UL&gt;&lt;/LI&gt;	
&lt;LI&gt;The &lt;CODE&gt;nifi.properties&lt;/CODE&gt; file must contain the path to each keystore and truststore and the corresponding password to access each. &lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;
	To configure LDAP authentication, you follow the same steps as for a standalone instance. The &lt;CODE&gt;nifi.properties&lt;/CODE&gt; and &lt;CODE&gt;login-identity-providers.xml&lt;/CODE&gt; files must be synchronized to all nodes in the cluster.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2016 09:55:55 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-details-for-generating-client-certificate-when/m-p/105197#M46386</guid>
      <dc:creator>alopresto</dc:creator>
      <dc:date>2016-11-16T09:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for details for generating client certificate when not using NiFi CA</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-details-for-generating-client-certificate-when/m-p/277487#M46387</link>
      <description>&lt;P&gt;Hi Alo,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We did the SSL on Nifi server with CA signed certificates but not Nifi CA.&lt;/P&gt;&lt;P&gt;I now want to create once client certificate to authenticate to Nifi can you please help me outline the steps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2019 09:46:20 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-details-for-generating-client-certificate-when/m-p/277487#M46387</guid>
      <dc:creator>shariquealam786</dc:creator>
      <dc:date>2019-09-17T09:46:20Z</dc:date>
    </item>
  </channel>
</rss>

