Setting Up a Secure Apache NiFi Registry

preview_player
Показать описание
This video walks you through how to install and secure a NiFi Registry using client certificates. A quick example of modifying user privileges in the Registry is also included.
Рекомендации по теме
Комментарии
Автор

You have created four videos around nifi and all of them are extremely informative and helpful. Many thanks:)

farzad
Автор

Hey, just wanted to say this tutorial was super helpful! One thing I'd mention though is if you're setting up the NiFi Registry on a different host from the NiFi instance, don't forget to create an SSL Context and use the keystore and truststore from the registry box (you'll need to copy them over). It's actually best practice to keep the NiFi Registry and instance separate. Plus, if you're on AWS, you can run the registry on a free tier instance, which is a pretty sweet deal. Highly recommended!

jacekx-bu
Автор

can you also show, how to integrate with LDAP

venkateshkancharla
Автор

How to install secured nifi registry in linux and how to install the .p12 certificates in linux? Please respond for this thread.

rapos
Автор

After entering specified password it says wrong...i dont know whats the problem

Mrnitin
Автор

Hi Andrew,


Thanks for the great tutorial/video.


I followed the instructions, however when trying to start the UI I cannot connect. I first installed Nifi followed by NiFi registry running both on 1Ubuntu 18.04 server. NiFi runs fine. I also opened the port where nifi-registry should be running. On my mac (I downloaded the certificate ('CN=sysadmin_OU=NIFI.p12'), double clicked it and entered the password. When looking at the ni-registry-app log file on the Ubuntu server I see:


2019-10-28 19:00:22, 843 INFO [main] NiFi Registry has started. The UI is available at the following URLs:
2019-10-28 19:00:22, 844 INFO [main] Successfully initiated communication with Bootstrap
2019-10-28 19:00:22, 845 INFO [main] Registry initialization took 19345973268 nanoseconds (19 seconds).


Any idea why I'm unable to connect?


Thanks.
Guy

gdillen
Автор

Hi Andrew my nifi-registry isn't starting because of this "Failed; nested exception is Validate failed: Detected failed migration to version 1.3 " what can i do to fix this error?

luckyguy
Автор

Hi Andrew, thanks for the video - very useful.

One question, can I enable LDAP authentication without forcing user to provide a client cert? Seems possible, based on this statement in the docs below, but not 100% sure. For example, instead of choosing a cert, I want to user to just be prompted for AD credentials and then have nifi-registry query LDAP for auth.

"Any secured instance of NiFi Registry supports authentication via client certificates that are trusted by the NiFi Registry’s SSL Context Truststore. *Alternatively*, a secured NiFi Registry can be configured to authenticate users via username/password."

eddiej
Автор

Hey Andrew, when configuring Nifi Registry and Nifi on the same server (both to use LDAP authentication). Do we need to still independently configure the settings? I currently have a secured Nifi server setup and looking to just add Nifi Registry to the mix. Thanks!

garrettblondell
Автор

Hey Andrew, thanks for this video which is very clear. I have a question :
It might be a beginner question but the part when you click on the .p12 file is not working for me (i'm on ubuntu 18.04), may you give me an hint to deal with that problem? I know that we have to enter the password that is stored in the .password file but there is no pop-up window in my case.. Thanks!

ferdinanddebaecque
Автор

Hi where is the. password file located?

mharongundayao
welcome to shbcf.ru