# Elastic cloud entreprise - saml

**URL:** <https://discuss.elastic.co/t/elastic-cloud-entreprise-saml/222705>\
**Category:** Elastic Cloud Enterprise (ECE)\
**Created:** [March 9, 2020, 12:04pm UTC](https://discuss.elastic.co/t/elastic-cloud-entreprise-saml/222705 "2020-03-09T12:04:12Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![raphperrin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raphperrin/32/51129_2.png) [@raphperrin](https://discuss.elastic.co/u/raphperrin)\
**Post date:** [March 9, 2020, 12:04pm UTC](https://discuss.elastic.co/t/elastic-cloud-entreprise-saml/222705/1 "2020-03-09T12:04:12Z")

</div>

Hi  
I am trying to configure the SAML authentication to secure one of my elastic cloud cluster.  
I added the configuration

> "user\_bundles": [  
> {  
> "name": "saml-metadata",  
> "url": "[https://servername/saml-metadata.zip](https://servername/saml-metadata.zip)",  
> "elasticsearch\_version": "7.6.0"   
> }  
> ],

But the configuration never applies, I don't see any errors in the logs.

I've done it with a non cloud entreprise and it did work since I am able to provide the file directly on the system.

any help, please  
Raphael

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [March 9, 2020, 2:34pm UTC](https://discuss.elastic.co/t/elastic-cloud-entreprise-saml/222705/2 "2020-03-09T14:34:30Z")

</div>

When you say "the configuration never applies", what does that mean exactly? (Eg does the configuration change fail, does it appear but SAML continues to fail in some way, etc?)

What is the format of `saml-metadata.zip`?

---

<div class="post-metadata">

**Author:** ![raphperrin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raphperrin/32/51129_2.png) [@raphperrin](https://discuss.elastic.co/u/raphperrin)\
**Post date:** [March 10, 2020, 6:03am UTC](https://discuss.elastic.co/t/elastic-cloud-entreprise-saml/222705/3 "2020-03-10T06:03:26Z")

</div>

Hi, thank you for your answer.  
The configuration never gets apply.  
The zip file looks like this :

> unzip -l saml-metadata.zip  
> Archive: saml-metadata.zip  
> Length Date Time Name  
> --------- ---------- ----- ----  
> 0 03-06-2020 09:22 saml/  
> 4729 03-09-2020 11:08 saml/metadata.xml

Thank you

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [March 10, 2020, 12:54pm UTC](https://discuss.elastic.co/t/elastic-cloud-entreprise-saml/222705/4 "2020-03-10T12:54:27Z")

</div>

Hi - I think I still need more details

> The configuration never gets apply.

Does the configuration change report as successful or as an error?

> The zip file looks like this

What is the ES config, eg the "user settings YAML" in the configuration page (or the contents of `user_settings_yaml` or `user_settings_json` if you specified it in the advanced editor)?

(Generally when SAML fails for any reason - assuming it was configured at all - eg the config change didn't fail, it will report an error in the ES logs which appear in the L+M cluster)

---

<div class="post-metadata">

**Author:** ![raphperrin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raphperrin/32/51129_2.png) [@raphperrin](https://discuss.elastic.co/u/raphperrin)\
**Post date:** [March 10, 2020, 1:12pm UTC](https://discuss.elastic.co/t/elastic-cloud-entreprise-saml/222705/5 "2020-03-10T13:12:34Z")

</div>

Hi, no problem.  
To start I am "only" trying to add the zip file with the metadata in the config under "user\_bundles". I am able to save it.  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/a/9aa8b4b816efd6d0eaa39052bb43df0951d2eab2.png)

Here is what I get in the container logs :

> 2020-03-10T13:09:16+0000 Booting at Tue Mar 10 13:09:16 UTC 2020  
> 2020-03-10T13:09:16+0000 Enabling QuotaAwareFileSystemProvider  
> 2020-03-10T13:09:17+0000 Installing user plugins.  
> 2020-03-10T13:09:18+0000 Installing user bundles.  
> 2020-03-10T13:09:18+0000 Installing saml-metadata...  
> 2020-03-10T13:09:18+0000 --2020-03-10 13:09:18-- [https://samlmetadata-int.domain.ch/saml-metadata.zip](https://samlmetadata-int.domain.ch/saml-metadata.zip)  
> 2020-03-10T13:09:18+0000 Resolving samlmetadata-int.domain.ch (samlmetadata-int.domain.ch)... 100.76.0.30  
> 2020-03-10T13:09:18+0000 Connecting to samlmetadata-int.domain.ch (samlmetadata-int.domain.ch)|100.76.0.30|:443... connected.  
> \*\*\* setuser exited with status 1.  
> \*\*\* Killing all processes...  
> usermod: no changes  
> \*\*\* Running setuser founduser /app/elasticsearch.sh...

And on the l+m cluster :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/0/702fc960a5bd7096f6d1a3d5df331b513d458fb6.png)

Thank you

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [March 10, 2020, 1:54pm UTC](https://discuss.elastic.co/t/elastic-cloud-entreprise-saml/222705/6 "2020-03-10T13:54:33Z")

</div>

OK so it sounds like you have successfully configured the cluster to download the metadata zip (and it will put `metadata.xml` into `$config/saml/metadata/xml`)

Now you should be able to follow the instructions here: [https://www.elastic.co/guide/en/cloud-enterprise/current/ece-securing-clusters-SAML.html](https://www.elastic.co/guide/en/cloud-enterprise/current/ece-securing-clusters-SAML.html)

and configure the cluster to use the client metadata (etc) to actually enable SAML?

Alex

---

<div class="post-metadata">

**Author:** ![raphperrin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raphperrin/32/51129_2.png) [@raphperrin](https://discuss.elastic.co/u/raphperrin)\
**Post date:** [March 10, 2020, 1:59pm UTC](https://discuss.elastic.co/t/elastic-cloud-entreprise-saml/222705/7 "2020-03-10T13:59:25Z")

</div>

But the settings are not being applied ☹

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/2/72d3a9101b0af59c7d5c5564d813f39854c8ee07.png)

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [March 10, 2020, 9:09pm UTC](https://discuss.elastic.co/t/elastic-cloud-entreprise-saml/222705/8 "2020-03-10T21:09:01Z")

</div>

That server bootloop (almost) always means one of two things

- The user-bundle is not accessible from the allocator host (you could try ssh'ing into the allocator and confirming ... the ES install literally just `wgets` it and then unzips it, so if you can do that from the command-line that should be fine)
- One or more of the user settings is invalid ... in that case the relevant info is always logged

---

<div class="post-metadata">

**Author:** ![raphperrin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raphperrin/32/51129_2.png) [@raphperrin](https://discuss.elastic.co/u/raphperrin)\
**Post date:** [March 11, 2020, 5:54am UTC](https://discuss.elastic.co/t/elastic-cloud-entreprise-saml/222705/9 "2020-03-11T05:54:59Z")

</div>

From the allocator, the wget works just fine. But from the Docker container, it fails because of the self-signed certificate on the metadata side ☹ . Is there any extra parameter to put in the user bundle ?

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [March 11, 2020, 12:27pm UTC](https://discuss.elastic.co/t/elastic-cloud-entreprise-saml/222705/10 "2020-03-11T12:27:35Z")

</div>

Ah so the web server that is serving the zip file is encrypted with a self-signed cert?

Ugh - that is a known bug in ECE at the moment (both that it happens, and that we provide no useful info to reveal that it's happening)

I believe the only workarounds are:

- Run your own local haproxy instance on each allocator to terminate the self-signed ssl (also needed for minio access if using a minio S3 clone for snapshots)
- Use a publicly signed ssl at the server

(I'll go ping the issue discussing this bug and see what's happened with it)

---

<div class="post-metadata">

**Author:** ![raphperrin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raphperrin/32/51129_2.png) [@raphperrin](https://discuss.elastic.co/u/raphperrin)\
**Post date:** [March 11, 2020, 2:28pm UTC](https://discuss.elastic.co/t/elastic-cloud-entreprise-saml/222705/11 "2020-03-11T14:28:28Z")

</div>

Hi,  
Thank you, I change the web server to http and the configuration does apply and it works now.  
Thanks again

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 25, 2020, 2:28pm UTC](https://discuss.elastic.co/t/elastic-cloud-entreprise-saml/222705/12 "2020-03-25T14:28:36Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
