Created on 04-08-2022 05:40 AM - edited 04-08-2022 05:42 AM
I have downloaded version 1.16 which is the latest. Im trying to secure nifi with TLS and LDAP. However I keep getting the followning message :
Unknown user with identity 'CN=nifi_admin, OU=NIFI'. Contact the system administrator
My Nifi,properties has the following set :
If I have set as follows it works and it accepts the cert & authentication:
My Authorizer file has the identity set as follows:
...<property name="Initial User Identity 1">CN=nifi_admin, OU=NIFI</property>
<property name="Initial Admin Identity">CN=nifi_admin, OU=NIFI</property>
<property name="Legacy Authorized Users File"></property>
<property name="Node Identity 1"></property>
Im trying to log in first with the cert idenitity nifi_admin so I can start adding ldap users. If I log it as single user I dont see Users & Policies menu items. Can someone help point me in the right direction.
Created 11-23-2022 01:59 PM
If your problem solved ... Can you please share with me the correct conf to solve this issue ?? as i faced same issue to login after enable LDAP
Created 11-28-2022 12:01 PM
I recommend starting a new community question with the details specific to your setup. This allows the community to address/assist with your specific setup versus comparing your issue to what was shared in this post.
Created 11-24-2022 03:33 PM
I know the frustration. Its been a while honestly and I dont recall how did I resolve it, but for me I remember when I upgraded to 1.16 it took few times of uninstall\resinstall for it to work correctly. Can you please post what you have in your authorizer.xml and what is in the nifi.properties file regarding the security configuration -like I did above - . Also keep in mind the Initial User Identity is case sensitive so make sure that the one associated with the certificate files for the trust store and keystore and the one you define in the authorizer are the same letter case. Let me know.
Created 11-27-2022 10:44 PM
have you set in Advanced nifi-properties
Created 11-28-2022 10:41 AM
No . I dont think I have used the following :
Have you tried using simple single authorization just to see if you can log in. It helps in this cases to start from simple config and then build up just to be able to isolate where the issue is.
hope that helps