<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: NIFI Sensitive Property doesn't appear to work in v1.4.0? in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/NIFI-Sensitive-Property-doesn-t-appear-to-work-in-v1-4-0/m-p/175218#M75361</link>
    <description>&lt;P&gt;Thanks for the detailed response, &lt;A rel="user" href="https://community.cloudera.com/users/525/mclark.html" nodeid="525"&gt;@Matt Clarke&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;In addition to flow.xml.gz, can I assume that sensitive properties will be encrypted in all locations (logs, repositories)?  &lt;/P&gt;</description>
    <pubDate>Wed, 07 Mar 2018 00:49:44 GMT</pubDate>
    <dc:creator>sonnychee</dc:creator>
    <dc:date>2018-03-07T00:49:44Z</dc:date>
    <item>
      <title>NIFI Sensitive Property doesn't appear to work in v1.4.0?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/NIFI-Sensitive-Property-doesn-t-appear-to-work-in-v1-4-0/m-p/175216#M75359</link>
      <description>&lt;P&gt;To whom it may concern:&lt;/P&gt;&lt;P&gt;I am attempting to encrypt sensitive processor properties with the following snippet from my nifi.properties file:&lt;/P&gt;&lt;P&gt;nifi.sensitive.props.key=1756eb0b-4eb3-46d6-98a4-a350b46c7459&lt;BR /&gt;nifi.sensitive.props.key.protected=&lt;BR /&gt;nifi.sensitive.props.algorithm=PBEWITHMD5AND256BITAES-CBC-OPENSSL&lt;BR /&gt;nifi.sensitive.props.provider=BC&lt;BR /&gt;nifi.sensitive.props.additional.keys=my_secret&lt;/P&gt;&lt;P&gt;I restarted Nifi but the value of the my_secret attribute remains unencrypted in flow.xml.gz. I've modified the value of my_secret several times but it is still saved in cleartext.&lt;/P&gt;&lt;P&gt;Any help with this would be greatly appreciated.&lt;/P&gt;&lt;P&gt;In addition, does anyone know what the value of "BC" means for the&lt;/P&gt;&lt;P&gt;nifi.sensitive.props.provider key? Equivalently, anyone know where I can get a list of default sensitive properties?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 10:37:26 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/NIFI-Sensitive-Property-doesn-t-appear-to-work-in-v1-4-0/m-p/175216#M75359</guid>
      <dc:creator>sonnychee</dc:creator>
      <dc:date>2018-03-06T10:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: NIFI Sensitive Property doesn't appear to work in v1.4.0?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/NIFI-Sensitive-Property-doesn-t-appear-to-work-in-v1-4-0/m-p/175217#M75360</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/70256/sonnychee.html" nodeid="70256"&gt;@Sonny Chee&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The "nifi.sensitive.props.additional.keys" property in the nifi.properties file allows you to specify additional properties from the nifi.properties file for encryption.  Only processors properties that have been specifically coded as sensitive will be encrypted.  Users can not define additional processor properties themselves for encryption.&lt;/P&gt;&lt;P&gt;Sorry that the documentation is a bit confusing on this property.&lt;/P&gt;&lt;P&gt;As far as "BC" goes, it stands for Bouncy Castle.   &lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.bouncycastle.org/" target="_blank"&gt;https://www.bouncycastle.org/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Thank you, &lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 22:59:11 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/NIFI-Sensitive-Property-doesn-t-appear-to-work-in-v1-4-0/m-p/175217#M75360</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2018-03-06T22:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: NIFI Sensitive Property doesn't appear to work in v1.4.0?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/NIFI-Sensitive-Property-doesn-t-appear-to-work-in-v1-4-0/m-p/175218#M75361</link>
      <description>&lt;P&gt;Thanks for the detailed response, &lt;A rel="user" href="https://community.cloudera.com/users/525/mclark.html" nodeid="525"&gt;@Matt Clarke&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;In addition to flow.xml.gz, can I assume that sensitive properties will be encrypted in all locations (logs, repositories)?  &lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 00:49:44 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/NIFI-Sensitive-Property-doesn-t-appear-to-work-in-v1-4-0/m-p/175218#M75361</guid>
      <dc:creator>sonnychee</dc:creator>
      <dc:date>2018-03-07T00:49:44Z</dc:date>
    </item>
    <item>
      <title>Re: NIFI Sensitive Property doesn't appear to work in v1.4.0?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/NIFI-Sensitive-Property-doesn-t-appear-to-work-in-v1-4-0/m-p/175219#M75362</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/70256/sonnychee.html" nodeid="70256"&gt;@Sonny Chee&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Processor obscure sensitive property values.  In addition, those sensitive property values are encrypted when stored in the flow.xml.gz file.  &lt;/P&gt;&lt;P&gt;I cannot think of how those sensitive properties would even get in to the nifi logs, flowfile repo, content repo, or provenance repo.  Sensitive properties are generally defined for password property fields.  They are used in facilitating a connection and can see no reason why they would ever be written to the content or attributes of a FlowFile.&lt;/P&gt;&lt;P&gt;Is this what you were concerned about.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;P&gt;Tip: Avoid responding to an answer with another answer.  Instead just add a comment to the answer you want follow-up on.&lt;/P&gt;&lt;P&gt;Once you find an answer that addresses your original question, please click the "accept" link below the answer.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 01:43:48 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/NIFI-Sensitive-Property-doesn-t-appear-to-work-in-v1-4-0/m-p/175219#M75362</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2018-03-07T01:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: NIFI Sensitive Property doesn't appear to work in v1.4.0?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/NIFI-Sensitive-Property-doesn-t-appear-to-work-in-v1-4-0/m-p/175220#M75363</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/525/mclark.html" nodeid="525"&gt;@Matt Clarke&lt;BR /&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Yes, my requirement is to encrypt passwords at rest.  &lt;/P&gt;&lt;P&gt;I notice that property values also appear in the database_repository/ files as well...&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;A rel="user" href="https://community.cloudera.com/users/525/mclark.html" nodeid="525"&gt;&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 01:53:12 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/NIFI-Sensitive-Property-doesn-t-appear-to-work-in-v1-4-0/m-p/175220#M75363</guid>
      <dc:creator>sonnychee</dc:creator>
      <dc:date>2018-03-07T01:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: NIFI Sensitive Property doesn't appear to work in v1.4.0?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/NIFI-Sensitive-Property-doesn-t-appear-to-work-in-v1-4-0/m-p/175221#M75364</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/70256/sonnychee.html" nodeid="70256"&gt;@Sonny Chee&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I am assuming you are referring to the H2 Binary DB file nifi-flow-audit.h2.db?&lt;/P&gt;&lt;P&gt;In that case, properties coded as sensitive are not persisted to the H2 database.  NiFi writes literally " ******** " to the H2 DB for these sensitive property values.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 03:09:09 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/NIFI-Sensitive-Property-doesn-t-appear-to-work-in-v1-4-0/m-p/175221#M75364</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2018-03-07T03:09:09Z</dc:date>
    </item>
  </channel>
</rss>

