Hi David,

This typically means one of two things:

  1.  that the DN of the (client) certificate does not match the user in the 
receiving NiFi instance *exactly*.
Inspect the logs (I think it’s nifi-user.log) to find the DN that the sending 
NiFi is providing and edit the username in the receiving NiFi instance.
  2.  The user is correct but does not have permissions to send data to the 
input port. Each input port needs these permissions set separately. Right-click 
on it and click “manage access policies”. In the dropdown box select “receive 
site-to-site data” and add the user or group that should be allowed to send 
data to this port.

Hope this helps you find the issue.

Regards,

Isha

Van: David Early via users <users@nifi.apache.org>
Verzonden: donderdag 27 juni 2024 01:33
Aan: users@nifi.apache.org
Onderwerp: Nifi Site to Site error message meaning

All,

I am trying to get an HTTP site to site set up, and I have done this a bunch of 
times, but I am seeing an error that I have not seen before and the logs are 
not helping.

I have gotten PKIX errors and Forbidden, but I am getting an Unauthorized 
message:

[cid:image001.png@01DAC86E.8FE52D90]

What is this telling me?  Where is the problem in the permission chain?

--
David

Reply via email to