Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st.
We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here.
Need help or have questions? Drop us a line at [email protected]
Created on 06-05-2017 02:38 PM - edited 08-17-2019 11:13 PM
Hi,
I have a cluster with 2 nodes, installed HDF and use Ranger for security policies. I just installed kerberos on my cluster using an existing AD.
I am now trying to connect to NiFi UI but I have insufficient privileges (login/password is ok).
I created a policy READ/WRITE for my user raphael.mary (existing in AD) on /* like following :
When I try to connect to NiFi I have insufficient privileges and I get this in Ranger Audt :
The user trying to connect is [email protected]
1. Is that normal that the user name is with the realm name in the audit log?
2. When I try to connect I use raphael.mary as login, do I need to specify another user name?
Thank you for your help.
Created 06-05-2017 05:51 PM
yes, i believe the hostname should match.
Created 06-05-2017 05:14 PM
Can you check if you have rules to translate kerberos principal to short username?
Created 06-05-2017 05:45 PM
nifi.security.identity.mapping.pattern.kerb = ^(.*?)@(.*?)$
nifi.security.identity.mapping.value.kerb = $1
The policy is now working but I get the following error : Untrusted proxy corenifi01-vm.zzzzz.com
Do I have to add the nodes of my cluster in Active Directory as well or do I have to add the nodes of my cluster in Ranger (principal is : [email protected]) ? I added them at the beginning but with this name : [email protected]
Created 06-05-2017 05:51 PM
yes, i believe the hostname should match.