I am assuming you have setup NiFi in your ranger "Service Manager". The "Config properties:" for that service in Ranger requires you to provide a NiFi URL, keystore, truststore, etc..
When you click "Test Connection", I am guessing you are getting a not authorized response?
So the client certificate from the supplied keystore is being sent to NiFi for authentication. If NiFi mutual trust (NiFi trusts client cert and Ranger trusts NiFi server cert) is successful, NiFi then tries to communicate with Ranger to verify if that "client user" is authorized to access the /nifi-apr/resources endpoint.
You should have a Ranger Policy within the NiFi service that grants the "client user" here "read" permissions to the "/resources" NiFi Resource Identifier.
Note that with a NiFi cluster all the NiFi nodes will need to authorized as well for the "/proxy" NiFi resource Identifier.