Apache Nifi - Secure with SSL and LDAP configuration issue

Viewed 597

I need to configure Nifi to LDAP but faced some impasse problem. (Nifi Version: 1.6.0)

  • I have a certification, it connected with LDAP so it fetches user information that login. (This does not generate Nifi-Toolkit. So it cointains my private )
  • I try to configure this certification.

So edited Truststore and Keystore parameters in nifi.properties.

nifi.security.keystore=./conf/certifications/key.jks
nifi.security.keystoreType=jks
nifi.security.keystorePasswd=password
nifi.security.keyPasswd=password
nifi.security.truststore=./conf/certifications/trust.jks
nifi.security.truststoreType=jks
nifi.security.truststorePasswd=password
nifi.security.user.authorizer=managed-authorizer
nifi.security.allow.anonymous.authentication=false
nifi.security.user.login.identity.provider=ldap-provider

After that Nifi guide show to set "initial admin" in authorizers.xml (The initial admin is the value entered when creating the certificate. )

<authorizer>
        <identifier>file-provider</identifier>
        <class>org.apache.nifi.authorization.FileAuthorizer</class>
        <property name="Authorizations File">./conf/authorizations.xml</property>
        <property name="Users File">./conf/users.xml</property>
        <property name="Initial Admin Identity">CN=nifiadmin, OU=password</property>
         
        
        <property name="Legacy Authorized Users File"></property>
        <property name="Node Identity 1"></property>
    </authorizer>

Also edited the LDAP properties in login-identity-providers.xml

<provider>
        <identifier>ldap-provider</identifier>
        <class>org.apache.nifi.ldap.LdapProvider</class>
        <property name="Authentication Strategy">SIMPLE</property>

        <property name="Manager DN">my_ldap_manager_info</property>
        <property name="Manager Password">password</property>

        <property name="Referral Strategy">FOLLOW</property>
        <property name="Connect Timeout">10 secs</property>
        <property name="Read Timeout">10 secs</property>

        <property name="Url">ldaps:serverid:port/</property>
        <property name="User Search Base">CN=xyz,DC=val,DC=user,DC=com,DC=tr</property>
        <property name="User Search Filter">(objectclass=person)</property>

        <property name="Identity Strategy">USE_USERNAME</property>
        <property name="Authentication Expiration">12 hours</property>
    </provider>

My problem occurs here. My certification get the value from LDAP itself and It includes my login information like that;

EMAILADDRESS=xyz@mock.com, CN=xyz[xyz, OU=General Dept, OU=Users, DC=domain, DC=xyz, DC=com, DC=tr

So it is never matched with the initial admin.

How can solve this problem and configure LDAP with this SSL certification?

0 Answers
Related