<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: NiFi - Insufficient Privileges usoing Ranger in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Insufficient-Privileges-usoing-Ranger/m-p/197835#M62370</link>
    <description>&lt;P&gt;Can you check if you have rules to translate kerberos principal to short username?&lt;/P&gt;</description>
    <pubDate>Tue, 06 Jun 2017 00:14:30 GMT</pubDate>
    <dc:creator>vperiasamy</dc:creator>
    <dc:date>2017-06-06T00:14:30Z</dc:date>
    <item>
      <title>NiFi - Insufficient Privileges usoing Ranger</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Insufficient-Privileges-usoing-Ranger/m-p/197834#M62369</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a cluster with 2 nodes, installed HDF and use Ranger for security policies. I just installed kerberos on my cluster using an existing AD.&lt;/P&gt;&lt;P&gt;I am now trying to connect to NiFi UI but I have insufficient privileges (login/password is ok).&lt;/P&gt;&lt;P&gt;I created a policy READ/WRITE for my user raphael.mary (existing in AD) on /* like following :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="16008-2017-06-05-10-31-42.png" style="width: 1518px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/17804i1AEC774B02FAF20B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="16008-2017-06-05-10-31-42.png" alt="16008-2017-06-05-10-31-42.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When I try to connect to NiFi I have insufficient privileges and I get this in Ranger Audt :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="16009-2017-06-05-10-31-02.png" style="width: 1521px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/17805i682C8AC69C7FBD90/image-size/medium?v=v2&amp;amp;px=400" role="button" title="16009-2017-06-05-10-31-02.png" alt="16009-2017-06-05-10-31-02.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The user trying to connect is raph.mary@ZZZZ.COM&lt;/P&gt;&lt;P&gt;1. Is that normal that the user name is with the realm name in the audit log?&lt;/P&gt;&lt;P&gt;2. When I try to connect I use raphael.mary as login, do I need to specify another user name?&lt;/P&gt;&lt;P&gt;Thank you for your help.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2019 06:13:29 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Insufficient-Privileges-usoing-Ranger/m-p/197834#M62369</guid>
      <dc:creator>raphamarymtl</dc:creator>
      <dc:date>2019-08-18T06:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: NiFi - Insufficient Privileges usoing Ranger</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Insufficient-Privileges-usoing-Ranger/m-p/197835#M62370</link>
      <description>&lt;P&gt;Can you check if you have rules to translate kerberos principal to short username?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 00:14:30 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Insufficient-Privileges-usoing-Ranger/m-p/197835#M62370</guid>
      <dc:creator>vperiasamy</dc:creator>
      <dc:date>2017-06-06T00:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: NiFi - Insufficient Privileges usoing Ranger</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Insufficient-Privileges-usoing-Ranger/m-p/197836#M62371</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/47/vperiasamy.html" nodeid="47"&gt;@vperiasamy&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/47/vperiasamy.html" nodeid="47"&gt;&lt;/A&gt;I added this after my post :&lt;/P&gt;&lt;P&gt;nifi.security.identity.mapping.pattern.kerb = ^(.*?)@(.*?)$&lt;/P&gt;&lt;P&gt;nifi.security.identity.mapping.value.kerb = $1&lt;/P&gt;&lt;P&gt;The policy is now working but I get the following error : Untrusted proxy corenifi01-vm.zzzzz.com&lt;/P&gt;&lt;P&gt;Do I have to add the nodes of my cluster in Active Directory as well or do I have to add the nodes of my cluster in Ranger (principal is : corenifi01-vm.zzzzz.com@ZZZZZ.COM) ? I added them at the beginning but with this name : corenifi01-vm.zzzzz.com@AA.ZZZZ.COM&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 00:45:11 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Insufficient-Privileges-usoing-Ranger/m-p/197836#M62371</guid>
      <dc:creator>raphamarymtl</dc:creator>
      <dc:date>2017-06-06T00:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: NiFi - Insufficient Privileges usoing Ranger</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Insufficient-Privileges-usoing-Ranger/m-p/197837#M62372</link>
      <description>&lt;P&gt;yes, i believe the hostname should match. &lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 00:51:05 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Insufficient-Privileges-usoing-Ranger/m-p/197837#M62372</guid>
      <dc:creator>vperiasamy</dc:creator>
      <dc:date>2017-06-06T00:51:05Z</dc:date>
    </item>
  </channel>
</rss>

