Hi Andy,

Thanks for the reply. Yes, it is an odd requirement that doesn't make a lot
of sense. This is an interim solution to keep moving forward on what I am
putting together. Here is a bigger picture: browser/api/client -> https ->
trusted infrastructure/dmz/proxy -> http -> NGINX -> secure NiFi. The http
hop will soon move to be https, thus the interim solution until that is
available. I think this is the answer to my question for what Koji recently
replied with as a solution. I'll give it a go and follow up. Thanks for the
help thus far!

Cheers,

Ryan H

On Wed, Feb 7, 2018 at 10:22 PM, Andy LoPresto <[email protected]> wrote:

> Hi Ryan,
>
> I want to try to understand your requirements a bit more in order to offer
> the best advice. Full disclosure, I have not performed this activity
> personally, so a lot of this will be speculation.
>
> From your diagram and the fact that you specify incoming traffic is on
> port 80, it appears that you do not want the communications between the
> browser and NGINX to be encrypted/secured via TLS. I don’t necessarily
> understand this (aside from intentionally not securing the data in transit,
> I am also unsure how authentication will work if you are transmitting
> credentials in plaintext between the browser and the proxy server), but
> this would not be the first requirement I do not understand. Assuming that
> is correct though, I do not believe you will need to extract the server key
> from the keystore to place in NGINX. In this role, NGINX is acting as a
> client to the actual NiFi server, so the private key should remain safely
> on the NiFi server only. I believe you will need to extract the following
> pieces to reside on the NGINX server:
>
> * client public certificate (this is to allow NGINX to present the
> certificate to NiFi during TLS negotiation)
> * client private key (this is to allow NGINX to prove identity during NiFi
> client authentication)
>
> To extract the client certificate and key from the keystore file that is
> generated, I use a custom script, which I have provided below. It splits
> the provided keystore into the private key and public certificate in the
> proper format.
>
> export_client ()
> {
>     echo "Exporting client certificate and key from $1";
>     read -s -p "Keystore Password: " PASSWORD;
>     openssl pkcs12 -in "$1" -out client.der -nodes -password
> "pass:$PASSWORD";
>     openssl pkcs12 -in "$1" -nodes -nocerts -out client.key -password
> "pass:$PASSWORD";
>     unset PASSWORD;
>     if [ "$(grep -e '-----BEGIN CERTIFICATE-----' client.der -F -c)" -gt 0
> ]; then
>         perl -pe 'BEGIN{undef $/;} s|-----BEGIN PRIVATE
> KEY-----.*?-----END PRIVATE KEY-----|Removed private key|gs' client.der >
> client.pem;
>     else
>         openssl x509 -inform der -in client.der -out client.pem;
>     fi;
>     ls -alGFh client.*
> }
>
>
> Andy LoPresto
> [email protected]
> *[email protected] <[email protected]>*
> PGP Fingerprint: 70EC B3E5 98A6 5A3F D3C4  BACE 3C6E F65B 2F7D EF69
>
> On Feb 7, 2018, at 1:55 PM, Ryan H <[email protected]>
> wrote:
>
> Hi All,
>
> This may trivial, but I'm asking anyways for clarity. I am setting up a
> secure instance of NiFi behind NGINX for reverse proxy capabilities. I have
> a certain requirement that traffic coming in will hit NGINX as HTTP on port
> 80. NGINX will need to forward the request to the secure instance as HTTPS
> on port 8443.
>
> So: browser/API -> http -> NGINX -> https -> Secure NiFi
>
> Currently I am using the tls-toolkit in client/server mode for the secure
> instance to get its certs. I plan to have an OpenID provider configured for
> AuthN.
>
> From what I understand I will need to place the client key and certificate
> as well as server key and certificate on NGINX. This may be a bad
> assumption, but it's where I'm at, at this point.
>
> My question is: what would act as each of the key/certificates for both
> the client/server to be placed on NGINX based on what is generated from the
> tls-toolkit (which keys/certs would be extracted from each of the generated
> files/stores)? Is what I'm doing feasible (I'm assuming it is, but open to
> being wrong). I've tried a few different extractions from the keystore and
> truststore, but this is a weaker area of expertise for me and would rather
> be clear on what I'm doing.
>
> Any help is greatly appreciated.
>
> Cheers,
>
> Ryan H
>
>
>

Reply via email to