# Auth to ECK using Azure AAD SAML failing

**URL:** <https://discuss.elastic.co/t/auth-to-eck-using-azure-aad-saml-failing/245275>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [August 17, 2020, 4:05pm UTC](https://discuss.elastic.co/t/auth-to-eck-using-azure-aad-saml-failing/245275 "2020-08-17T16:05:16Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![damjank](https://avatars.discourse-cdn.com/v4/letter/d/ecae2f/32.png) [@damjank](https://discuss.elastic.co/u/damjank)\
**Post date:** [August 17, 2020, 4:05pm UTC](https://discuss.elastic.co/t/auth-to-eck-using-azure-aad-saml-failing/245275/1 "2020-08-17T16:05:17Z")

</div>

Hey guys,

I am facing a weird issue. Following this guide as a roadmap: [SSO / Azure AD setup](https://discuss.elastic.co/t/sso-azure-ad-setup/230639/2) and mostly [https://www.elastic.co/blog/saml-based-single-sign-on-with-elasticsearch-and-azure-active-directory](https://www.elastic.co/blog/saml-based-single-sign-on-with-elasticsearch-and-azure-active-directory) I have a combination of mostly working SAML auth.

If I load up the Kibana page, it redirects me correctly to the Azure Auth portal. I enter credentials (twice? once in the login form then a pop-up appears to enter them again) and I am forwarded to Elastic and can do things. If I click logout URL then I encounter problems - I do not get redirect or my session does not get processed correctly because when I get back to Kibana, I only get this:

`{"statusCode":401,"error":"Unauthorized","message":"Unauthorized"}`

Now regardless of how I try again, I only get this response. Short of restarting pods (did I mention this is on ECK?) or remove all of my browsing histories or get the password in AAD reset, I cannot log in using SAML. If I try to go to the Elastic trough the user portal online, where I see my application, and I try to log in, I sometimes can log in, but after I close the tab with Elastic, and load it up again, I still get error 401.

I also caught:  
`{"statusCode":500,"error":"Internal Server Error","message":"[security_exception] Authenticating realm saml_aad does not exist"}`  
but I think that was perhaps my mistake with config, I did see that only 2 times.

Now I also catch sometimes this error:

 ![es-auth-err](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1a1a61153abc32e798d0eac533cb48094e28c424.png)

My elastic config is:

```auto
      xpack.security.authc.api_key.enabled: true
      xpack.security.authc.token.enabled: true
      xpack.security.authc.realms.native.native1:
        order: 0
      xpack.security.authc.realms.saml.saml_aad:
        order: 1
        idp.metadata.path: "https://login.microsoftonline.com/1234/federationmetadata/2007-06/federationmetadata.xml?appid=1234"
        idp.entity_id: "https://sts.windows.net/1234/"
        sp.entity_id: "https://kibana.juhu.com:5601"
        sp.acs: "https://kibana.juhu.com:5601/api/security/v1/saml"
        sp.logout: "https://kibana.juhu.com:5601/logout"
        attributes.principal: "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name"
        attributes.groups: "http://schemas.microsoft.com/ws/2008/06/identity/claims/role"
        attributes.name: "http://schemas.microsoft.com/identity/claims/displayname"
        attributes.mail: "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"

```

and my Kibana config is:

```auto
     server.xsrf.whitelist: [/api/security/v1/saml]
     xpack.security.public.protocol: "https"
     xpack.security.public.hostname: "kibana.juhu.com"
     xpack.security.public.port: "5601"
     xpack.security.authc.providers:
       basic.basic1:
         order: 0
         hint: "ES Local"
       saml.saml1:
         order: 1
         realm: saml_aad
         description: "ES AAD"

```

Any thoughts about what I am missing? I configured simple Azure Enterprise Application, following guide I provided above and since sometimes is working sometimes not, I am puzzled on how to proceed actually. TIA

---

<div class="post-metadata">

**Author:** ![forloop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/forloop/32/9021_2.png) [@forloop](https://discuss.elastic.co/u/forloop)\
**Post date:** [August 18, 2020, 12:59am UTC](https://discuss.elastic.co/t/auth-to-eck-using-azure-aad-saml-failing/245275/2 "2020-08-18T00:59:49Z")

</div>

Hi @damjank,

If you're using Elastic Stack 7.7.0+, I don't think you need all of the parts that you have in Kibana config. I think it just needs to be

```auto
xpack.security.authc.providers:
    basic.basic1:
        order: 0
        hint: "ES Local"
    saml.saml1:
        order: 1
        realm: saml_aad
        description: "ES AAD"
        icon: "logoAzure"

```

---

<div class="post-metadata">

**Author:** ![damjank](https://avatars.discourse-cdn.com/v4/letter/d/ecae2f/32.png) [@damjank](https://discuss.elastic.co/u/damjank)\
**Post date:** [August 18, 2020, 5:44am UTC](https://discuss.elastic.co/t/auth-to-eck-using-azure-aad-saml-failing/245275/3 "2020-08-18T05:44:51Z")

</div>

ES is at version 7.8. So you are referring to remove server.xsfr... and all x.pack.security until providers, right? Will try that and report back.

EDIT: after amending deployment, there is still same issue. We can login, after logout we get:  
`{"statusCode":500,"error":"Internal Server Error","message":"[security_exception] Authenticating realm saml_aad does not exist"}`

we reload, login and get  
`{"statusCode":401,"error":"Unauthorized","message":"Unauthorized"}`

---

<div class="post-metadata">

**Author:** ![forloop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/forloop/32/9021_2.png) [@forloop](https://discuss.elastic.co/u/forloop)\
**Post date:** [August 18, 2020, 9:04am UTC](https://discuss.elastic.co/t/auth-to-eck-using-azure-aad-saml-failing/245275/4 "2020-08-18T09:04:27Z")

</div>

I'm not sure what's going on here. Do the kibana logs show anything relevant?

---

<div class="post-metadata">

**Author:** ![damjank](https://avatars.discourse-cdn.com/v4/letter/d/ecae2f/32.png) [@damjank](https://discuss.elastic.co/u/damjank)\
**Post date:** [August 18, 2020, 9:14am UTC](https://discuss.elastic.co/t/auth-to-eck-using-azure-aad-saml-failing/245275/5 "2020-08-18T09:14:36Z")

</div>

I will get logs from pods themselves or login into one and get those. Also just to confirm - ES configuration on SAML is only for master nodes, right?

---

<div class="post-metadata">

**Author:** ![forloop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/forloop/32/9021_2.png) [@forloop](https://discuss.elastic.co/u/forloop)\
**Post date:** [August 18, 2020, 9:19am UTC](https://discuss.elastic.co/t/auth-to-eck-using-azure-aad-saml-failing/245275/6 "2020-08-18T09:19:14Z")

</div>

The Elasticsearch configuration for the SAML realm must be in the configuration of all nodes, as far as I am aware. If it isn't, that could explain why you are seeing intermittent failures.

---

<div class="post-metadata">

**Author:** ![damjank](https://avatars.discourse-cdn.com/v4/letter/d/ecae2f/32.png) [@damjank](https://discuss.elastic.co/u/damjank)\
**Post date:** [August 18, 2020, 9:20am UTC](https://discuss.elastic.co/t/auth-to-eck-using-azure-aad-saml-failing/245275/7 "2020-08-18T09:20:03Z")

</div>

Even the data nodes? OK will try this as well.

---

<div class="post-metadata">

**Author:** ![forloop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/forloop/32/9021_2.png) [@forloop](https://discuss.elastic.co/u/forloop)\
**Post date:** [August 18, 2020, 9:21am UTC](https://discuss.elastic.co/t/auth-to-eck-using-azure-aad-saml-failing/245275/8 "2020-08-18T09:21:14Z")

</div>

Yes, all nodes - data, master, coordinating, etc.

---

<div class="post-metadata">

**Author:** ![damjank](https://avatars.discourse-cdn.com/v4/letter/d/ecae2f/32.png) [@damjank](https://discuss.elastic.co/u/damjank)\
**Post date:** [August 18, 2020, 11:00am UTC](https://discuss.elastic.co/t/auth-to-eck-using-azure-aad-saml-failing/245275/9 "2020-08-18T11:00:46Z")

</div>

I can confirm, that after adding configuration for auth to ALL nodes, it is working as expected - intermittent failures were because node participating in auth did not have correct configuration. I did not know that ALL nodes, regardless of type, do that. Thanks for all help! Cheers!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 15, 2020, 11:00am UTC](https://discuss.elastic.co/t/auth-to-eck-using-azure-aad-saml-failing/245275/10 "2020-09-15T11:00:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
