[ 
https://issues.apache.org/jira/browse/NIFI-7765?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17186759#comment-17186759
 ] 

Bryan Bende commented on NIFI-7765:
-----------------------------------

Seems like something must not be correct with the p12 file. I would try to 
verify that the p12 works in some other way outside of the CLI, you could 
import into one of you browsers and try to access NiFi UI and if it should 
prompt you if you want to use that cert, if you select it then it won't ever go 
to the OIDC login. I think if it never prompts you to use the cert then it is 
not trusted by the truststore that NiFi is running with.

You could also try with curl to hit the NiFi API - 
https://stackoverflow.com/a/55890905/5650316

> Toolket CLI OpenID Connect Support
> ----------------------------------
>
>                 Key: NIFI-7765
>                 URL: https://issues.apache.org/jira/browse/NIFI-7765
>             Project: Apache NiFi
>          Issue Type: Improvement
>          Components: Tools and Build
>    Affects Versions: 1.11.4
>         Environment: CentOS Linux 7
>            Reporter: W Chang
>            Priority: Major
>              Labels: Authentication, CLI, Connect, OIDC, OpenID
>
> When a NiFi or a Registry instance is configured for OpenID Connect 
> authentication, a user cannot authenticate to the secure NiFi or the secure 
> Registry using Toolkit CLI to use CLI commands.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to