Getting untrusted proxy message while trying to setup secure NIFI cluster

Viewed 1573

I am using nifi V-1.3, and trying to setup 3 node secure NIFI cluster.

I have added all the required properties, I can see nodes sending heartbeats in logs in all the nodes but on screen I'm getting Untrusted proxy message for all nodes. error screen shot attached.

Error log getting as NiFiAuthenticationFilter Rejecting access to web api: Untrusted proxy CN=hostname

could you please tell if anybody overcomes it.

Thanks.

  Find the nifi properties below:
<authorizer>
            <identifier>file-provider</identifier>
            <class>org.apache.nifi.authorization.FileAuthorizer</class>
            <property name="AuthorizationsFile">./conf/authorizations.xml</property>
            <property name="Users File">./conf/users.xml</property>
            <property name="Initial Admin Identity">Mathes@example.com</property>
            <property name="Legacy Authorized Users File"></property>
            <property name="Node Identity 1">CN=node1@example.com, OU=NIFI</property>
            <property name="Node Identity 2">CN=CN=node2@example.com, OU=NIFI</property>
            <property name="Node Identity 3">CN=CN=node3@example.com, OU=NIFI</property>
    </authorizer>
2 Answers

I had the same problem and my workarround was this:

Edit nifi.properties maping so when you try to connect to nifi using a certificate it map you to the initial admin user:

nifi.security.identity.mapping.pattern.dn=^CN=(.*?), OU=(.*?)
nifi.security.identity.mapping.value.dn=<Initial Admin Identity>, OU=

Then you have to edit the authorizations.xml and add this line:

<policy identifier="nifi-cluster-write" resource="/proxy" action="W">
        <user identifier="HASH OF INITIAL ADMIN"/>
</policy>

Aparently the problem is that the initial admin identity does not have the "/proxy" policy.

Related