diff --git a/deploy/nifi.env b/deploy/nifi.env index 94ec578d..35826b8d 100644 --- a/deploy/nifi.env +++ b/deploy/nifi.env @@ -55,8 +55,8 @@ NIFI_LOG_LEVEL="ERROR" NIFI_AUTH=tls -NIFI_KEYSTORE_PATH="/opt/nifi/nifi-current/conf/keystore.jks" -NIFI_TRUSTSTORE_PATH="/opt/nifi/nifi-current/conf/truststore.jks" +NIFI_KEYSTORE_PATH="/security/certificates/nifi/nifi-keystore.jks" +NIFI_TRUSTSTORE_PATH="/security/certificates/nifi/nifi-truststore.jks" NIFI_REGISTRY_KEYSTORE_PATH="/opt/nifi-registry/nifi-registry-current/conf/keystore.jks" NIFI_REGISTRY_TRUSTSTORE_PATH="/opt/nifi-registry/nifi-registry-current/conf/truststore.jks" diff --git a/deploy/services.yml b/deploy/services.yml index 788de305..c12f319f 100644 --- a/deploy/services.yml +++ b/deploy/services.yml @@ -458,8 +458,7 @@ services: - ../nifi/user-python-extensions:/opt/nifi/nifi-current/python_extensions:rw # INFO: uncomment below to map security certificates if need to secure NiFi endpoints - - ./${NIFI_SECURITY_DIR:-../security/certificates/nifi/}:/opt/nifi/nifi-current/nifi_certificates:ro - - ./${ELASTICSEARCH_SECURITY_DIR:-../security/certificates/elastic/}:/opt/nifi/nifi-current/es_certificates:ro + - ../security:/security:ro # Security credentials scripts - ../security/scripts/nifi_create_single_user_auth.sh:/opt/nifi/nifi-current/security_scripts/nifi_create_single_user_auth.sh:ro diff --git a/nifi/conf/nifi.properties b/nifi/conf/nifi.properties index 628b6739..1363e7de 100644 --- a/nifi/conf/nifi.properties +++ b/nifi/conf/nifi.properties @@ -201,11 +201,11 @@ nifi.sensitive.props.additional.keys= nifi.security.autoreload.enabled=false nifi.security.autoreload.interval=10 secs -nifi.security.keystore=/opt/nifi/nifi-current/nifi_certificates/nifi-keystore.jks +nifi.security.keystore=/security/certificates/nifi/nifi-keystore.jks nifi.security.keystoreType=jks nifi.security.keystorePasswd=cogstackNifi nifi.security.keyPasswd=cogstackNifi -nifi.security.truststore=/opt/nifi/nifi-current/nifi_certificates/nifi-truststore.jks +nifi.security.truststore=/security/certificates/nifi/nifi-truststore.jks nifi.security.truststoreType=jks nifi.security.truststorePasswd=cogstackNifi nifi.security.user.authorizer=single-user-authorizer