RE: I need help configuring Site-to-Site in Secure Mode.

2016-09-12 Thread Paul Gibeault (pagibeault)
eault From: Bryan Bende [mailto:bbe...@gmail.com] Sent: Friday, September 02, 2016 11:54 AM To: users@nifi.apache.org<mailto:users@nifi.apache.org> Subject: Re: I need help configuring Site-to-Site in Secure Mode. Ok, I am not completely familiar with all the ins and outs of the site-to-s

RE: I need help configuring Site-to-Site in Secure Mode.

2016-09-02 Thread Paul Gibeault (pagibeault)
[mailto:bbe...@gmail.com] Sent: Friday, September 02, 2016 11:54 AM To: users@nifi.apache.org Subject: Re: I need help configuring Site-to-Site in Secure Mode. Ok, I am not completely familiar with all the ins and outs of the site-to-site client code, but I know one place that it creates a connection is

Re: I need help configuring Site-to-Site in Secure Mode.

2016-09-02 Thread Bryan Bende
ging the client to find > out why no cert is being sent? > > > > Thanks, > > Peter > > > > > > > > *From:* Bryan Bende [mailto:bbe...@gmail.com] > *Sent:* Friday, September 02, 2016 10:09 AM > > *To:* users@nifi.apache.org > *Subject:* Re: I ne

RE: I need help configuring Site-to-Site in Secure Mode.

2016-09-02 Thread Peter Wicks (pwicks)
lto:matt.clarke@gmail.com>] Sent: Friday, September 02, 2016 9:23 AM To: users@nifi.apache.org<mailto:users@nifi.apache.org> Subject: Re: I need help configuring Site-to-Site in Secure Mode. Do the certs you created/obtained support being used for both client and server auth. If they

Re: I need help configuring Site-to-Site in Secure Mode.

2016-09-02 Thread Bryan Bende
Peter > > > > *From:* Matthew Clarke [mailto:matt.clarke....@gmail.com] > *Sent:* Friday, September 02, 2016 9:23 AM > > *To:* users@nifi.apache.org > *Subject:* Re: I need help configuring Site-to-Site in Secure Mode. > > > > Do the certs you created/obtained su

RE: I need help configuring Site-to-Site in Secure Mode.

2016-09-02 Thread Peter Wicks (pwicks)
: ObjectId: 2.5.29.37 Criticality=false ExtendedKeyUsages [ clientAuth serverAuth ] Thanks, Peter From: Matthew Clarke [mailto:matt.clarke@gmail.com] Sent: Friday, September 02, 2016 9:23 AM To: users@nifi.apache.org Subject: Re: I need help configuring Site-to-Site in Secure Mode. Do the certs

Re: I need help configuring Site-to-Site in Secure Mode.

2016-09-02 Thread Matthew Clarke
re, just SSL certs. > > > > I’ve asked our security team for Client Authentication certs for each > server, since it would be our preference to use our CA rather than having > TLS-Toolkit be its own CA. > > > > Thoughts? > > > > Thanks, > > Peter > >

RE: I need help configuring Site-to-Site in Secure Mode.

2016-09-02 Thread Peter Wicks (pwicks)
information of any kind. Looking for further guidance/next steps. Thanks, Peter From: Bryan Bende [mailto:bbe...@gmail.com] Sent: Thursday, September 01, 2016 9:44 AM To: users@nifi.apache.org Subject: Re: I need help configuring Site-to-Site in Secure Mode. Peter, Yes, by no means am I saying

Re: I need help configuring Site-to-Site in Secure Mode.

2016-09-01 Thread Bryan Bende
cross NiFi instances I see > this error: > > > > Unable to refresh Remote Group's peers due to Unable to communicate with > remote NiFi cluster in order to determine which nodes exist in the remote > cluster > > > > Our NiFi servers are not set up for clust

RE: I need help configuring Site-to-Site in Secure Mode.

2016-09-01 Thread Peter Wicks (pwicks)
et up for clustering. Is clustering required to perform Site-to-Site? Thanks, Paul Gibeault From: Bryan Bende [mailto:bbe...@gmail.com<mailto:bbe...@gmail.com>] Sent: Tuesday, August 30, 2016 5:09 PM To: users@nifi.apache.org<mailto:users@nifi.apache.org> Subject: Re: I need help configuri

Re: I need help configuring Site-to-Site in Secure Mode.

2016-09-01 Thread Bryan Bende
in order to determine which nodes exist in the remote > cluster > > > > Our NiFi servers are not set up for clustering. Is clustering required to > perform Site-to-Site? > > > > Thanks, > > Paul Gibeault > > > > *From:* Bryan Bende [mailto:bbe

RE: I need help configuring Site-to-Site in Secure Mode.

2016-09-01 Thread Paul Gibeault (pagibeault)
ering required to perform Site-to-Site? Thanks, Paul Gibeault From: Bryan Bende [mailto:bbe...@gmail.com] Sent: Tuesday, August 30, 2016 5:09 PM To: users@nifi.apache.org Subject: Re: I need help configuring Site-to-Site in Secure Mode. Paul, It sounds like you probably have the certifi

Re: I need help configuring Site-to-Site in Secure Mode.

2016-08-30 Thread Bryan Bende
Paul, It sounds like you probably have the certificates/truststores setup correctly and just need to create the appropriate policies... Lets say you have nifi-1 with an Remote Process Group pointing at the URL of nifi-2, and nifi-2 has an Input port to receive data. In nifi-2 there needs to be a