<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: NiFi Authorization with Ranger in Kerberized environment in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Authorization-with-Ranger-in-Kerberized-environment/m-p/175067#M82883</link>
    <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/48310/raffaelesaggino1.html" nodeid="48310" target="_blank"&gt;@Raffaele S&lt;/A&gt; &lt;/P&gt;&lt;P&gt;I think you may need to adjust the user/group sync in ranger.   Be sure to tail the ranger user sync logs while running the sync so that you can validate things are arriving correctly. Here are my configs:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="87420-usersync.jpg" style="width: 904px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/19840i35D9793E87019AB6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="87420-usersync.jpg" alt="87420-usersync.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="87421-groupsync.jpg" style="width: 906px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/19841iA0DDE939A31EE929/image-size/medium?v=v2&amp;amp;px=400" role="button" title="87421-groupsync.jpg" alt="87421-groupsync.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Additionally you will need to create policies in ranger admin as follows:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="87422-rangeradminui.png" style="width: 1100px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/19842iB8FBA872864F1A04/image-size/medium?v=v2&amp;amp;px=400" role="button" title="87422-rangeradminui.png" alt="87422-rangeradminui.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;the scrambled user for NiFi Proxy is cn=NIFIHOSTNAME, OU=NIFI&lt;/P&gt;&lt;P&gt;Be sure to watch the log files and restart everything after making any changes.&lt;/P&gt;&lt;P&gt;If this answer is helpful, please choose ACCEPT to mark the question as resolved.&lt;/P&gt;</description>
    <pubDate>Sun, 18 Aug 2019 10:14:23 GMT</pubDate>
    <dc:creator>stevenmatison</dc:creator>
    <dc:date>2019-08-18T10:14:23Z</dc:date>
    <item>
      <title>NiFi Authorization with Ranger in Kerberized environment</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Authorization-with-Ranger-in-Kerberized-environment/m-p/175066#M82882</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am setting up an HDF 3.2 cluster that's fully Kerberized and I am trying to handle authorization through Ranger.&lt;/P&gt;&lt;P&gt;We have a single Active Directory which also acts as KDC.&lt;/P&gt;&lt;P&gt;The technical users (for example the service principals automatically created by HDF) are mapped in the following organization unit: OU=HDF,DC=example,DC=com while "normal" users (devs/admins) are mapped in OU=USERS,DC=example,DC=com&lt;/P&gt;&lt;P&gt;The problem is that after enabling NiFi plugin and Kafka plugin I have not been able to use any of the two (I added my username to the "admin" policies of both services in ranger).&lt;/P&gt;&lt;P&gt;Since the two problems are probably linked, I will start from NiFi and if necessary expand on Kafka in another post.&lt;/P&gt;&lt;P&gt;NiFi authentication works (the user is recognized) but I receive the following error: "Unable to view the user interface. Contact the system administrator."&lt;/P&gt;&lt;P&gt;When I check the audit log I notice that the User is indicated with the full qualified domain name USER@EXAMPLE.COM (instead of just the username) and the access is denied.&lt;/P&gt;&lt;PRE&gt;nifi.security.user.login.identity.provider=kerberos-provider 
&lt;/PRE&gt;&lt;P&gt;I tried the following NiFi properties without success:&lt;/P&gt;&lt;PRE&gt;nifi.security.identity.mapping.pattern.kerb=^(.?)@(.?)$
nifi.security.identity.mapping.value.kerb=$1
&lt;/PRE&gt;&lt;P&gt;Could you help me solve this problem?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 12:15:08 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Authorization-with-Ranger-in-Kerberized-environment/m-p/175066#M82882</guid>
      <dc:creator>rsg</dc:creator>
      <dc:date>2026-04-21T12:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: NiFi Authorization with Ranger in Kerberized environment</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Authorization-with-Ranger-in-Kerberized-environment/m-p/175067#M82883</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/48310/raffaelesaggino1.html" nodeid="48310" target="_blank"&gt;@Raffaele S&lt;/A&gt; &lt;/P&gt;&lt;P&gt;I think you may need to adjust the user/group sync in ranger.   Be sure to tail the ranger user sync logs while running the sync so that you can validate things are arriving correctly. Here are my configs:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="87420-usersync.jpg" style="width: 904px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/19840i35D9793E87019AB6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="87420-usersync.jpg" alt="87420-usersync.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="87421-groupsync.jpg" style="width: 906px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/19841iA0DDE939A31EE929/image-size/medium?v=v2&amp;amp;px=400" role="button" title="87421-groupsync.jpg" alt="87421-groupsync.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Additionally you will need to create policies in ranger admin as follows:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="87422-rangeradminui.png" style="width: 1100px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/19842iB8FBA872864F1A04/image-size/medium?v=v2&amp;amp;px=400" role="button" title="87422-rangeradminui.png" alt="87422-rangeradminui.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;the scrambled user for NiFi Proxy is cn=NIFIHOSTNAME, OU=NIFI&lt;/P&gt;&lt;P&gt;Be sure to watch the log files and restart everything after making any changes.&lt;/P&gt;&lt;P&gt;If this answer is helpful, please choose ACCEPT to mark the question as resolved.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2019 10:14:23 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Authorization-with-Ranger-in-Kerberized-environment/m-p/175067#M82883</guid>
      <dc:creator>stevenmatison</dc:creator>
      <dc:date>2019-08-18T10:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: NiFi Authorization with Ranger in Kerberized environment</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Authorization-with-Ranger-in-Kerberized-environment/m-p/175068#M82884</link>
      <description>&lt;P&gt;&lt;EM&gt;&lt;A href="https://community.hortonworks.com/users/48310/raffaelesaggino1.html"&gt;@Raffaele S&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;To avoid unwanted groups and users loaded please see this &lt;A href="https://community.hortonworks.com/content/supportkb/49424/how-to-make-sure-ranger-doesnt-load-unwanted-user.html" target="_blank"&gt;HCC doc&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2018 00:16:39 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Authorization-with-Ranger-in-Kerberized-environment/m-p/175068#M82884</guid>
      <dc:creator>Shelton</dc:creator>
      <dc:date>2018-08-30T00:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: NiFi Authorization with Ranger in Kerberized environment</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Authorization-with-Ranger-in-Kerberized-environment/m-p/175069#M82885</link>
      <description>&lt;P&gt;&lt;A href="https://community.hortonworks.com/users/48310/raffaelesaggino1.html"&gt;&lt;EM&gt;@Raffaele S&lt;/EM&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;That's the default behavior if you are using AD it appends the REALM to username.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2018 00:19:19 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Authorization-with-Ranger-in-Kerberized-environment/m-p/175069#M82885</guid>
      <dc:creator>Shelton</dc:creator>
      <dc:date>2018-08-30T00:19:19Z</dc:date>
    </item>
    <item>
      <title>Re: NiFi Authorization with Ranger in Kerberized environment</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Authorization-with-Ranger-in-Kerberized-environment/m-p/175070#M82886</link>
      <description>&lt;P&gt;Hello &lt;A rel="user" href="https://community.cloudera.com/users/87347/stevenmatison.html" nodeid="87347"&gt;@Steven Matison&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;thanks for replying. &lt;/P&gt;&lt;P&gt;I believe that everything is setup as you proposed, I also added the NiFi proxy users to their own policy but nothing changed.&lt;/P&gt;&lt;P&gt;Tailing the usersync.log doesn't provide any additional evidence.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2018 21:43:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Authorization-with-Ranger-in-Kerberized-environment/m-p/175070#M82886</guid>
      <dc:creator>rsg</dc:creator>
      <dc:date>2018-08-30T21:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: NiFi Authorization with Ranger in Kerberized environment</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Authorization-with-Ranger-in-Kerberized-environment/m-p/175071#M82887</link>
      <description>&lt;P&gt;Thanks, I will use this configuration while testing in the future.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2018 21:44:14 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Authorization-with-Ranger-in-Kerberized-environment/m-p/175071#M82887</guid>
      <dc:creator>rsg</dc:creator>
      <dc:date>2018-08-30T21:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: NiFi Authorization with Ranger in Kerberized environment</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Authorization-with-Ranger-in-Kerberized-environment/m-p/175072#M82888</link>
      <description>&lt;P&gt;There aren't many information in the manual is it possible I have to manually configure all the options under "Advanced ranger-nifi-plugin-properties" (in the ambari console)?&lt;BR /&gt;Currently only a few of those properties are configured.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2018 22:35:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Authorization-with-Ranger-in-Kerberized-environment/m-p/175072#M82888</guid>
      <dc:creator>rsg</dc:creator>
      <dc:date>2018-08-30T22:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: NiFi Authorization with Ranger in Kerberized environment</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Authorization-with-Ranger-in-Kerberized-environment/m-p/175073#M82889</link>
      <description>&lt;P&gt;Properly setting up the nifi.security.identity.mapping.pattern.kerb and nifi.security.identity.mapping.pattern.dn fixed the problem.&lt;/P&gt;&lt;P&gt;Also, while debugging these kind of problems, it's best to delete ranger plugin cache (under /etc/ranger/SERVICE_NAME/policycache/) to ensure that there are no communication problem between NiFi and Ranger.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 18:08:45 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/NiFi-Authorization-with-Ranger-in-Kerberized-environment/m-p/175073#M82889</guid>
      <dc:creator>rsg</dc:creator>
      <dc:date>2018-10-30T18:08:45Z</dc:date>
    </item>
  </channel>
</rss>

