<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: OIDC With Azure AD in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/OIDC-With-Azure-AD/m-p/232324#M82756</link>
    <description>&lt;P&gt;Turns out I'd misconfigured the proxy settings on the nginx ingress. The bearer token, and all state values for the OIDC login statemachine, are not replicated to the other cluster members. This means one must configure sticky sessions on the ingress.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Aug 2018 20:25:11 GMT</pubDate>
    <dc:creator>tyler_gregory</dc:creator>
    <dc:date>2018-08-28T20:25:11Z</dc:date>
    <item>
      <title>OIDC With Azure AD</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/OIDC-With-Azure-AD/m-p/232323#M82755</link>
      <description>&lt;P&gt;I've deployed a secured NiFi cluster on Kubernetes in Azure, and am attempting to configure OIDC against Azure AD for auth. I've created an app registration in AAD and configured the OIDC settings in nifi.properties as follows:&lt;/P&gt;&lt;PRE&gt;nifi.security.user.oidc.discovery.url=https://login.microsoftonline.com/dvn.onmicrosoft.com/.well-known/openid-configuration
nifi.security.user.oidc.connect.timeout=5 secs
nifi.security.user.oidc.read.timeout=5 secs
nifi.security.user.oidc.client.id=a8d7d98f-588a-4e30-b93c-1730de5512b1
nifi.security.user.oidc.client.secret=*********************************
nifi.security.user.oidc.preferred.jwsalgorithm=&lt;/PRE&gt;&lt;P&gt;However, the login sequence always fails with:&lt;/P&gt;&lt;PRE&gt; Purposed state does not match the stored state. Unable to continue login process.&lt;/PRE&gt;&lt;P&gt;Can anyone shed some light on what I might be doing wrong? Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 13:38:24 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/OIDC-With-Azure-AD/m-p/232323#M82755</guid>
      <dc:creator>tyler_gregory</dc:creator>
      <dc:date>2022-09-16T13:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: OIDC With Azure AD</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/OIDC-With-Azure-AD/m-p/232324#M82756</link>
      <description>&lt;P&gt;Turns out I'd misconfigured the proxy settings on the nginx ingress. The bearer token, and all state values for the OIDC login statemachine, are not replicated to the other cluster members. This means one must configure sticky sessions on the ingress.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 20:25:11 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/OIDC-With-Azure-AD/m-p/232324#M82756</guid>
      <dc:creator>tyler_gregory</dc:creator>
      <dc:date>2018-08-28T20:25:11Z</dc:date>
    </item>
  </channel>
</rss>

