TLS/SSL configuration

Before you can enable user authentication in NiFi, you must configure Transport Layer Security (TLS).

TLS is a standard set of cryptographic protocols for securing communications over a network. When you configure authentication and authorization for your flow management cluster, Cloudera Flow Management sends sensitive information over the network to cluster hosts, such as Kerberos keytabs and configuration files that contain passwords. TLS encryption keeps these transfers secure.

TLS uses public and private keys to establish encrypted connections between clients and servers. Digital certificates verify the identity of the communicating parties and help prevent spoofing and other security threats.

Use one of the following methods to configure TLS in Cloudera Flow Management:

  • Auto-TLS
    Use Cloudera Manager to simplify certificate creation, deployment, and management across the cluster.
  • Manual TLS/SSL configuration
    Configure TLS manually when you need to use certificates issued by your enterprise certificate authority (CA).

Starting with Cloudera Flow Management 4.12.0.10000 (Service Pack 1), NiFi and NiFi Registry accept only TLS 1.3 connections when TLS 1.3 is configured through Cloudera Manager. The CSD configuration template automatically populates the relevant security properties with the supported TLS 1.3 cipher suites.