# Elastic Cloud can't login with AWS SSO

**URL:** <https://discuss.elastic.co/t/elastic-cloud-cant-login-with-aws-sso/172924>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [March 19, 2019, 9:31am UTC](https://discuss.elastic.co/t/elastic-cloud-cant-login-with-aws-sso/172924 "2019-03-19T09:31:20Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Robin\_Guo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robin_guo/32/42297_2.png) [@Robin\_Guo](https://discuss.elastic.co/u/Robin_Guo)\
**Post date:** [March 19, 2019, 9:31am UTC](https://discuss.elastic.co/t/elastic-cloud-cant-login-with-aws-sso/172924/1 "2019-03-19T09:31:20Z")

</div>

Dear Elastic,  
Those 2 days I've been fighting with Elastic Cloud auth with AWS SSO,  
But It doesn't work, I don't know what am I missing about configuration on Elastic Cloud or AWS SSO.

Could someone help me out?

Regards  
Robin

Detailed configuration as below:

**Elastic config:**

```
xpack:
  security:
    authc:
      realms:
        cloud-saml: 
          type: saml
          order: 2
          attributes.principal: "nameid:persistent" 
          attributes.groups: "groups" 
          idp.metadata.path: "https://portal.sso.us-east-1.amazonaws.com/saml/metadata/XXXXXXXXXXXXXXXXXXXX" 
          idp.entity_id: "https://portal.sso.us-east-1.amazonaws.com/saml/assertion/XXXXXXXXXXXXXXXXXXXX" 
          sp.entity_id: "https://YYYYYYYYYYYYYYYYY.eu-west-1.aws.found.io:9243"
          sp.acs: "https://YYYYYYYYYYYYYYYYY.eu-west-1.aws.found.io:9243/api/security/v1/saml"
          sp.logout: "https://YYYYYYYYYYYYYYYYY.eu-west-1.aws.found.io:9243/logout"  

```

**Kibana config:**

```
xpack.security.authProviders: [saml,basic]
server.xsrf.whitelist: [/api/security/v1/saml]
xpack.security.public:
  protocol: https
  hostname: XXXXXXXXXXXXXXXXXXXX.eu-west-1.aws.found.io 
  port: 9243   

```

**Create a role mapping:**

```
POST /_xpack/security/role_mapping/CLOUD_SAML_TO_KIBANAUSER 
{
   "enabled": true,
    "roles": ["kibana_user"], 
    "rules": { 
        "field": { "realm.name": "cloud-saml" } 
    },
    "metadata": { "version": 1 }
}

          
POST /_xpack/security/role_mapping/CLOUD_SAML_ELASTICADMIN_TO_SUPERUSER 
{
   "enabled": true,
    "roles": ["superuser"], 
    "rules": { "all" : [ 
        { "field": { "realm.name": "cloud-saml" } }, 
        { "field": { "groups": "gu.system" } }
    ]},
    "metadata": { "version": 1 }
}

```

**AWS SSO :**

![image](https://us1.discourse-cdn.com/elastic/original/3X/2/b/2b873f7fc93b547b20ac23ddeb32da8ec0efb229.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/e/de0dfbf442f4ea07bbd6b30c0027359901566c76.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/f/3ff5ddc4f1b3716ac79ff11d85631d52e3a5db12.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/9/39ed042030a011fe9118717a7167bd9b4f97e8ed.png)

**Login Test:**

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/d/dd6a98a20e23cccc54bb909f5e962dbfa9fca541.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/d/1d01cce7a119ac81aafd1ed5d1134869a9ec4e86.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/b/9b2342452b787e9275c031d7e477425d5f14d5c3.png)

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [March 20, 2019, 7:50am UTC](https://discuss.elastic.co/t/elastic-cloud-cant-login-with-aws-sso/172924/2 "2019-03-20T07:50:40Z")

</div>

Hi there,

Please don't post images of text as they are hard to read, may not display correctly for everyone, and not searchable. It's fine to post screenshots to further highlight your issues but do add details in text too.

The error message that AWS SSO gives you is

> "Request NameID Format doesn't match our record"

This implies that the Elastic Stack sends a SAML Authentication Request with a `NameIDPolicy Format` that AWS SSO doesn't like. As you can see in [our docs](https://www.elastic.co/guide/en/elasticsearch/reference/6.6/security-settings.html#ref-saml-settings) :

```auto
 nameid_format
    The NameID format that should be requested when asking the IdP to authenticate the current user. Defaults to requesting transient names (urn:oasis:names:tc:SAML:2.0:nameid-format:transient). 

```

this defaults to `urn:oasis:names:tc:SAML:2.0:nameid-format:transient`. Given the fact that you want to use `persistent` NameIDs , as I can see from the rest of the configuration and you have configured AWS SSO accordingly too, what you'd need to do is to configure the Elastic Stack SAML SP to also request that format. To do so , add

```auto
nameid_format: urn:oasis:names:tc:SAML:2.0:nameid-format:persistent

```

in your `cloud-saml` configuration in the Elasticsearch config.

Hope this helps

---

<div class="post-metadata">

**Author:** ![Robin\_Guo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robin_guo/32/42297_2.png) [@Robin\_Guo](https://discuss.elastic.co/u/Robin_Guo)\
**Post date:** [March 20, 2019, 10:59am UTC](https://discuss.elastic.co/t/elastic-cloud-cant-login-with-aws-sso/172924/3 "2019-03-20T10:59:18Z")

</div>

Hi @ikakavas,

When I follow your instructions to add that statement in Elastic configuration. It doesn't work.

```
xpack:
  security:
    authc:
      realms:
        cloud-saml: 
          type: saml
          order: 2
          nameid_format: "urn:oasis:names:tc:SAML:2.0:nameid-format:persistent"
          attributes.principal: "nameid:persistent" 
          attributes.groups: "groups" 
          idp.metadata.path: "https://portal.sso.us-east-1.amazonaws.com/saml/metadata/MjU5ODM4MjAwNjIxX2lucy0xMzRlYzQ5YjUwOWM0Y2Y3" 
          idp.entity_id: "https://portal.sso.us-east-1.amazonaws.com/saml/assertion/MjU5ODM4MjAwNjIxX2lucy0xMzRlYzQ5YjUwOWM0Y2Y3" 
          sp.entity_id: "https://6a9c147de13c44e5b93df78382758dfe.eu-west-1.aws.found.io:9243"
          sp.acs: "https://6a9c147de13c44e5b93df78382758dfe.eu-west-1.aws.found.io:9243/api/security/v1/saml"
          sp.logout: "https://6a9c147de13c44e5b93df78382758dfe.eu-west-1.aws.found.io:9243/logout"  

```

After saving changes, I got this error:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/0/702ed3c05c1d2d28b87b5f14ed46cf3930d774fc.png)

AWS SSO IDP config:

```
<?xml version="1.0" encoding="UTF-8"?><md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" entityID="https://portal.sso.us-east-1.amazonaws.com/saml/assertion/MjU5ODM4MjAwNjIxX2lucy0xMzRlYzQ5YjUwOWM0Y2Y3">
  <md:IDPSSODescriptor WantAuthnRequestsSigned="false" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
    <md:KeyDescriptor use="signing">
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:X509Data>
          <ds:X509Certificate>MIIDAzCCAeugAwIBAgIBATANBgkqhkiG9w0BAQsFADBFMRYwFAYDVQQDDA1hbWF6b25hd3MuY29tMQ0wCwYDVQQLDARJREFTMQ8wDQYDVQQKDAZBbWF6b24xCzAJBgNVBAYTAlVTMB4XDTE5MDMxODA5MzYxNFoXDTI0MDMxODA5MzYxNFowRTEWMBQGA1UEAwwNYW1hem9uYXdzLmNvbTENMAsGA1UECwwESURBUzEPMA0GA1UECgwGQW1hem9uMQswCQYDVQQGEwJVUzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMB0eA5w3yrgSJoMOV5VFrBinuSPX8pHFvhWxXTptrMv35clA0E1LXf5I4rxA/6FHhgdH/sX1C8F9gck7ToAjEdSWzir7XlKH3JcuFcID/FLnYkCqX9YY5oANR4qTD9b8fJ9JIDmrtWOeSgHgvu4Z3DVe+fYlsF5JmkWRQvJGriSMYTLkV6YKbm9zyKShDkMGVF1kQQriHwXkhSDcTr0D3m2tTsPpDlZf7Ir1CsmkBMzC0OD6zvoCpC6rMk5q1FzV0ISBY3g6h/lf9mVrIefmHE8PfHJ8/1KxB01HDxAVkZweumxoqVqqdcZy4ZEWM1ByLxM0lJ63d89NSS4lC6kBGcCAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAmN1NN/jKoJuTsqrm72pL8mjCuZFZ6vpzg/imUFxtaR+O5UNQuBpxeCitPRBqvZjBKCWaOMb/sfDilk8QsmWmt2wBC0WIxetVPGYetweaA6eVZRoOA8nu9c3hXCOnI399RAyQ6ZvaCb+lyQ8soJx+VOp5XbSoeEfzr7eNKoHTAPYIMEtCrNfhC7QLhouywunqkOTWKI4MqIvq8F4Genw//eypNScATy4eKlTcb5o3A6vp5L5m0ch76d9YM0Py0eoGFdUMf2QK5GtMXWj/NKTutx27q7yV4Z16F0fgYxRHoOTR6/8XPTEyFU3J4zqy4jkNmC8ZoyCFhdCLAIGq/X/bgA==</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </md:KeyDescriptor>
    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://portal.sso.us-east-1.amazonaws.com/saml/logout/MjU5ODM4MjAwNjIxX2lucy0xMzRlYzQ5YjUwOWM0Y2Y3"/>
    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://portal.sso.us-east-1.amazonaws.com/saml/logout/MjU5ODM4MjAwNjIxX2lucy0xMzRlYzQ5YjUwOWM0Y2Y3"/>
    <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</md:NameIDFormat>
    <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://portal.sso.us-east-1.amazonaws.com/saml/assertion/MjU5ODM4MjAwNjIxX2lucy0xMzRlYzQ5YjUwOWM0Y2Y3"/>
    <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://portal.sso.us-east-1.amazonaws.com/saml/assertion/MjU5ODM4MjAwNjIxX2lucy0xMzRlYzQ5YjUwOWM0Y2Y3"/>
  </md:IDPSSODescriptor>
</md:EntityDescriptor>
```

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [March 20, 2019, 11:48am UTC](https://discuss.elastic.co/t/elastic-cloud-cant-login-with-aws-sso/172924/4 "2019-03-20T11:48:49Z")

</div>

Hi,

Yes, apologies, I should have noted this is Elastic Cloud and as such this is currently not a whitelisted config value. Can you please engage with your support engineer? They will be able to apply this setting for your cluster - feel free to mention this post here, and I will provide them with additional details if needed.

---

<div class="post-metadata">

**Author:** ![Robin\_Guo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robin_guo/32/42297_2.png) [@Robin\_Guo](https://discuss.elastic.co/u/Robin_Guo)\
**Post date:** [March 24, 2019, 3:40pm UTC](https://discuss.elastic.co/t/elastic-cloud-cant-login-with-aws-sso/172924/5 "2019-03-24T15:40:40Z")

</div>

Hi @ikakavas

Yeah, The Kibana SSO login is working after Elastic Cloud help enable the below option on ElasticSearch settings.

`urn:oasis:names:tc:SAML:2.0:nameid-format:persistent`

There has a new issue found after we enabled Kibana SSO.

We can only see an attribute with **subject** on AWS Application SSO settings, Don't know if it's normal? when I logged on to Kibana with my AD account(robin.guo), It's not the username that what I logged on.

Could you please advise which attributes should we in place between elastic cloud and AWS SSO?

**The default mappings between AWS SSO and Microsoft AD as following**

| User attribute in AWS SSO | Maps to this attribute in your Microsoft AD directory |
| --- | --- |
| AD\_GUID | ${dir:guid} |
| email | ${dir:windowsUpn} |
| familyName | ${dir:lastname} |
| givenName | ${dir:firstname} |
| middleName | ${dir:initials} |
| name | ${dir:displayname} |
| preferredUsername | ${dir:displayname} |
| subject | ${dir:windowsUpn} |

eg.

**Attribute mappings**

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/5/352bb4338af06567a9962270c31d0658703cd40f.png)

**Kibana Login**

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/e/febfe0e6374de0831f5b95d5b3cc5b67c383f033.png)

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [March 26, 2019, 6:40am UTC](https://discuss.elastic.co/t/elastic-cloud-cant-login-with-aws-sso/172924/6 "2019-03-26T06:40:14Z")

</div>

> [@ikakavas](#):
>
> Hi there,
> 
> Please don't post images of text as they are hard to read, may not display correctly for everyone, and not searchable

You have configured AWS SSO to use the literal string "subject" as the value of the SAML NameID and then you have also configured Elasticsearch to map the value of SAML NameID to the principal user attribute in Elasticsearch. Thus, the principal user attribute in Elasticsearch gets the value "subject". This is all expected behavior based on your configuration.

You should probably want to change the literal sting "subject" in your AWS SSO config to something from the list you have shared above ( like the default value ${dir:windowsUpn} that will get the appropriate value from your AD

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 23, 2019, 6:40am UTC](https://discuss.elastic.co/t/elastic-cloud-cant-login-with-aws-sso/172924/7 "2019-04-23T06:40:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
