I need to configure Nifi to LDAP but faced some impasse problem. (Nifi Version: 1.6.0)
- I have a certification, it connected with LDAP so it fetches user information that login. (This does not generate Nifi-Toolkit. So it cointains my private )
- I try to configure this certification.
So edited Truststore and Keystore parameters in nifi.properties.
nifi.security.keystore=./conf/certifications/key.jks
nifi.security.keystoreType=jks
nifi.security.keystorePasswd=password
nifi.security.keyPasswd=password
nifi.security.truststore=./conf/certifications/trust.jks
nifi.security.truststoreType=jks
nifi.security.truststorePasswd=password
nifi.security.user.authorizer=managed-authorizer
nifi.security.allow.anonymous.authentication=false
nifi.security.user.login.identity.provider=ldap-provider
After that Nifi guide show to set "initial admin" in authorizers.xml (The initial admin is the value entered when creating the certificate. )
<authorizer>
<identifier>file-provider</identifier>
<class>org.apache.nifi.authorization.FileAuthorizer</class>
<property name="Authorizations File">./conf/authorizations.xml</property>
<property name="Users File">./conf/users.xml</property>
<property name="Initial Admin Identity">CN=nifiadmin, OU=password</property>
<property name="Legacy Authorized Users File"></property>
<property name="Node Identity 1"></property>
</authorizer>
Also edited the LDAP properties in login-identity-providers.xml
<provider>
<identifier>ldap-provider</identifier>
<class>org.apache.nifi.ldap.LdapProvider</class>
<property name="Authentication Strategy">SIMPLE</property>
<property name="Manager DN">my_ldap_manager_info</property>
<property name="Manager Password">password</property>
<property name="Referral Strategy">FOLLOW</property>
<property name="Connect Timeout">10 secs</property>
<property name="Read Timeout">10 secs</property>
<property name="Url">ldaps:serverid:port/</property>
<property name="User Search Base">CN=xyz,DC=val,DC=user,DC=com,DC=tr</property>
<property name="User Search Filter">(objectclass=person)</property>
<property name="Identity Strategy">USE_USERNAME</property>
<property name="Authentication Expiration">12 hours</property>
</provider>
My problem occurs here. My certification get the value from LDAP itself and It includes my login information like that;
EMAILADDRESS=xyz@mock.com, CN=xyz[xyz, OU=General Dept, OU=Users, DC=domain, DC=xyz, DC=com, DC=tr
So it is never matched with the initial admin.
How can solve this problem and configure LDAP with this SSL certification?