# Elasticsearch SAML integration while using HTTP-Redirect

**URL:** <https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 12, 2018, 2:08am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658 "2018-07-12T02:08:19Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![talon](https://avatars.discourse-cdn.com/v4/letter/t/c77e96/32.png) [@talon](https://discuss.elastic.co/u/talon)\
**Post date:** [July 12, 2018, 2:08am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658/1 "2018-07-12T02:08:20Z")

</div>

I am integrating ELK with a AD serve via SAML, the partial message from metadata file supplied by AD serve is  
{

> \</ds:X509Data\>\</ds:KeyInfo\>\</md:KeyDescriptor\>md:NameIDFormaturn:oasis:names:tc:SAML:1.1:nameid-format:unspecified\</md:NameIDFormat\>\<md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:_HTTP-POST_"  
> }

but when i login in face a problem that "Cannot find [{urn:oasis:names:tc:SAML:2.0:metadata}IDPSSODescriptor]/[urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect] in descriptor"

and i search in google , i saw  
• An with an entityID that matches the {es} configuration  
• An that supports the SAML 2.0 protocol (urn:oasis:names:tc:SAML:2.0:protocol).  
• At least one that is configured for signing (that is, it has use="signing" or leaves the use unspecified)  
• A with binding of HTTP-Redirect (urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect)  
• If you wish to support Single Logout, a with binding of HTTP-Redirect (urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect)  
Here is the link to describe it.  
[https://github.com/elastic/elasticsearch/blob/master/x-pack/docs/en/security/authentication/saml-guide.asciidoc](https://github.com/elastic/elasticsearch/blob/master/x-pack/docs/en/security/authentication/saml-guide.asciidoc).

As we need SSO, So HTTP-Redirect is necessary.  
my question is  
1 if we use SSO, Do AD server have to support HTTP-Redirect?  
2 if the answer is yes ,why.  
3 can i disable SSO temporarily. how?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 12, 2018, 3:29am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658/2 "2018-07-12T03:29:54Z")

</div>

When you say "AD", I assume you mean ADFS - is that correct?

ADFS can support HTTP-Redirect and has been successfully used with the Elastic Stack. You may need to look at configuration options for your AD install.

> 1 if we use SSO, Do AD server have to support HTTP-Redirect?

Your Identity Provider must support a HTTP-Redirect binding for sign on, yes.  
It's OK if it supports additional bindings, but we require a Redirect binding.

> 2 if the answer is yes ,why.

Because implementing support for each binding type is additional work, and we have chosen to implement HTTP-Redirect support, because it is required by the SAML comformance spec and all interoperability profiles.

> 3 can i disable SSO temporarily. how?

You can turn off SAML support in Kibana.

See: "[SingleSignOnService Binding HTTP-POST](https://discuss.elastic.co/t/singlesignonservice-binding-http-post/134474)" for previous discussion on this topic.

---

<div class="post-metadata">

**Author:** ![talon](https://avatars.discourse-cdn.com/v4/letter/t/c77e96/32.png) [@talon](https://discuss.elastic.co/u/talon)\
**Post date:** [July 12, 2018, 3:33am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658/3 "2018-07-12T03:33:17Z")

</div>

HI Tim  
Thank you very much.

---

<div class="post-metadata">

**Author:** ![talon](https://avatars.discourse-cdn.com/v4/letter/t/c77e96/32.png) [@talon](https://discuss.elastic.co/u/talon)\
**Post date:** [July 12, 2018, 8:30am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658/4 "2018-07-12T08:30:57Z")

</div>

HI Tim  
I have another question。  
do you have tetative time to get POST Binding implemented? or you wont implement anytime?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 12, 2018, 8:57am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658/5 "2018-07-12T08:57:41Z")

</div>

There is no current plan to implement POST bindings.  
We may do it if there is sufficient demand, but we haven't seen enough requests for it to make it a priority right now.

---

<div class="post-metadata">

**Author:** ![talon](https://avatars.discourse-cdn.com/v4/letter/t/c77e96/32.png) [@talon](https://discuss.elastic.co/u/talon)\
**Post date:** [July 17, 2018, 1:13am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658/6 "2018-07-17T01:13:01Z")

</div>

HI Tim  
I face a issue that when i enter the home page url of ELK in my environment, the browser return  
“  
{"statusCode":401,"error":"Unauthorized","message":"[security\_exception] unable to authenticate user [] for action [cluster:admin/xpack/security/saml/authenticate], with { header={ WWW-Authenticate="Basic realm=\"security\" charset=\"UTF-8\"" } } :: {"path":"/\_xpack/security/saml/authenticate","query":{},"body":"{\"ids\":[],\"content\":\"PHNhbWxwOlJlc3BvbnNlIFZlcnNpb249IjIuMCIgSUQ9Ik9FVHM3WmJ2am53MlcyR3B3VWhqWFNtMmI4eSIgSXNzdWVJbnN0YW50PSIyMDE4LTA3LTE3VDAwOjQxOjM1Ljg0NFoiIEluUmVzcG9uc2VUbz0iX2UxOTk0OTI4NTY1OTI5NGZkOWQxMTAzNDAyYTZhOTdhMjI4YjUzY2IiIERlc3RpbmF0aW9uPSJodHRwczovL3NlbnQyLWtpYmFuYS1kZXYuZHNlbnRpZW5jZS5uZXQ6NDQzL2FwaS9zZWN1cml0eS92MS9zYW1sIiB4bWxuczpzYW1scD0idXJuOm9hc2lzOm5hbWVzOnRjOlNBTUw6Mi4wOnByb3RvY29sIj48c2FtbDpJc3N1ZXIgeG1sbnM6c2FtbD0idXJuOm9hc2lzOm5hbWVzOnRjOlNBTUw6Mi4wOmFzc2VydGlvbiI+aHR0cHM6Ly9xY3dhLmhvbmV5d2VsbC5jb20vc2FtbDI8L3NhbWw6SXNzdWVyPjxkczpTaWduYXR1cmUgeG1sbnM6ZHM9Imh0dHA6Ly93d3cudzMub3JnLzIwMDAvMDkveG1sZHNpZyMiPgo8ZHM6U2lnbmVkSW5mbz4KPGRzOkNhbm9uaWNhbGl6YXRpb25NZXRob2QgQWxnb3JpdGhtPSJodHRwOi8vd3d3LnczLm9yZy8yMDAxLzEwL3htbC1leGMtYzE0biMiLz4KPGRzOlNpZ25hdHVyZU1ldGhvZCBBbGdvcml0aG09Imh0dHA6Ly93d3cudzMub3JnLzIwMDEvMDQveG1sZHNpZy1tb3JlI3JzYS1zaGEyNTYiLz4KPGRzOlJlZmVyZW5jZSBVUkk9IiNPRVRzN1pidmpudzJXMkdwd1VoalhTbTJiOHkiPgo8ZHM6VHJhbnNmb3Jtcz4KPGRzOlRyYW5zZm9ybSBBbGdvcml0aG09Imh0dHA6Ly93d3cudzMub3JnLzIwMDAvMDkveG1sZHNpZyNlbnZlbG9wZWQtc2lnbmF0dXJlIi8+CjxkczpUcmFuc2Zvcm0gQWxnb3JpdGhtPSJodHRwOi8vd3d3LnczLm9yZy8yMDAxLzEwL3htbC1leGMtYzE0biMiLz4KPC9kczpUcmFuc2Zvcm1zPgo8ZHM6RGlnZXN0TWV0aG9kIEFsZ29yaXRobT0iaHR0cDovL3d3dy53My5vcmcvMjAwMS8wNC94bWxlbmMjc2hhMjU2Ii8+CjxkczpEaWdlc3RWYWx1ZT5HTFlGejdQdTM4elFXTzl2SzNxU293Y0lKUXltOGJNUWNIWlMzS3F0cWlRPTwvZHM6RGlnZXN0VmFsdWU+CjwvZHM6UmVmZXJlbmNlPgo8L2RzOlNpZ25lZEluZm8+CjxkczpTaWduYXR1cmVWYWx1ZT4Kd3M3aFVZSUpEU2tOV3JDVkNQTkc2TTFhZHFwVzdiRjl5aXN2YmdleC96Qy9uTU9LaFdTV1BDQ0pXTlhsYW82aFhycWFZRnB1OVdodgptTXJQdHBnODJUQUZ6QWpqQXllczFidWtpS1kvM3d3aVZWdklnMUc4UkRONzR3dWlzTWt6aTE2MmtibUtXZWV5aVMwL3RTeFEzRkpQCk8xNkFUOXhDSEZWSTlyNlFNWmoxbjdRTUZjM29IKzVkTUVSODFYclpJNXhkS042UmpBTFV6Vlh0aDNwdUJaTTFZK1dLek9Db3Y5YTIKZjg1UlZ1a0VWczR2YWRhUTh0SURmZ1hVeUhjYVdiWTRzL09IaVdMeTMrMXRzSXczRlNobG9yQXlkQWZmRFdwUjBsRFZZTEdXK3BscApvS3hmYlQ5S0tqNFplTm1FYkZ0bFFPa3VlUFR4ZkJaVjhxSVFSdz09CjwvZHM6U2lnbmF0dXJlVmFsdWU+CjwvZHM6U2lnbmF0dXJlPjxzYW1scDpTdGF0dXM+PHNhbWxwOlN0YXR1c0NvZGUgVmFsdWU9InVybjpvYXNpczpuYW1lczp0YzpTQU1MOjIuMDpzdGF0dXM6UmVxdWVzdGVyIi8+PHNhbWxwOlN0YXR1c01lc3NhZ2U+U2lnbmF0dXJlIHJlcXVpcmVkPC9zYW1scDpTdGF0dXNNZXNzYWdlPjwvc2FtbHA6U3RhdHVzPjwvc2FtbHA6UmVzcG9uc2U+\"}","statusCode":401,"response":"{\"error\":{\"root\_cause\":[{\"type\":\"security\_exception\",\"reason\":\"unable to authenticate user [] for action [cluster:admin/xpack/security/saml/authenticate]\",\"header\":{\"WWW-Authenticate\":\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\"}}],\"type\":\"security\_exception\",\"reason\":\"unable to authenticate user [] for action [cluster:admin/xpack/security/saml/authenticate]\",\"header\":{\"WWW-Authenticate\":\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\"}},\"status\":401}","wwwAuthenticateDirective":"Basic realm=\"security\" charset=\"UTF-8\""}"}  
”

some log in Kibana  
"  
{"type":"error","@timestamp":"2018-07-16T13:44:40Z","tags":["warning","monitoring-ui","kibana-monitoring"],"pid":81410,"level":"error","e rror":{"message":"[no\_shard\_available\_action\_exception] No shard available for [get [.kibana][doc][config:6.2.4]: routing [null]]","name" :"Error","stack":"[no\_shard\_available\_action\_exception] No shard available for [get [.kibana][doc][config:6.2.4]: routing [null]] :: {"p ath":"/.kibana/doc/config%3A6.2.4","query":{},"statusCode":503,"response":"{\"error\":{\"root\_cause\":[{\"type\":\ "no\_shard\_available\_action\_exception\",\"reason\":\"No shard available for [get [.kibana][doc][config:6.2.4]: routing [null]]\\ "}],\"type\":\"no\_shard\_available\_action\_exception\",\"reason\":\"No shard available for [get [.kibana][doc][config:6.2.4]: routing [null]]\"},\"status\":503}"}\n at respond (/usr/share/kibana/node\_modules/elasticsearch/src/lib/transport.js:295:15)\n at checkRespForFailure (/usr/share/kibana/node\_modules/elasticsearch/src/lib/transport.js:254:7)\n at HttpConnector. (/ usr/share/kibana/node\_modules/elasticsearch/src/lib/connectors/http.js:159:7)\n at IncomingMessage.bound (/usr/share/kibana/node\_modul es/elasticsearch/node\_modules/lodash/dist/lodash.js:729:21)\n at emitNone (events.js:91:20)\n at IncomingMessage.emit (events.js:18 5:7)\n at endReadableNT (\_stream\_readable.js:974:12)\n at \_combinedTickCallback (internal/process/next\_tick.js:80:11)\n at proce ss.\_tickDomainCallback (internal/process/next\_tick.js:128:9)"},"message":"[no\_shard\_available\_action\_exception] No shard available for [g et [.kibana][doc][config:6.2.4]: routing [null]]"}  
{"type":"log","@timestamp":"2018-07-16T13:44:40Z","tags":["warning","monitoring-ui","kibana-monitoring"],"pid":81410,"message":"Unable to fetch data from kibana\_settings collector"}

"  
some log in Elasticsearch  
"  
org.elasticsearch.action.NoShardAvailableActionException: No shard available for [get [.kibana][doc][config:6.2.4]: routing [null]]  
at org.elasticsearch.action.support.single.shard.TransportSingleShardAction$AsyncSingleAction.perform(TransportSingleShardAction. java:209) ~[elasticsearch-6.2.4.jar:6.2.4]  
at org.elasticsearch.action.support.single.shard.TransportSingleShardAction$AsyncSingleAction.start(TransportSingleShardAction.ja

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 17, 2018, 1:40am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658/7 "2018-07-17T01:40:27Z")

</div>

> [@talon](#):
>
> org.elasticsearch.action.NoShardAvailableActionException: No shard available for [get [.kibana][doc][config:6.2.4]: routing [null]]

That's a cluster problem that's not specifically security related.  
Something looks wrong with your cluster - like you've got unavailable shards.

Check your [cluster health](https://www.elastic.co/guide/en/elasticsearch/reference/6.3/cluster-health.html) and resolve any issues there.

---

<div class="post-metadata">

**Author:** ![talon](https://avatars.discourse-cdn.com/v4/letter/t/c77e96/32.png) [@talon](https://discuss.elastic.co/u/talon)\
**Post date:** [July 17, 2018, 4:34am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658/9 "2018-07-17T04:34:22Z")

</div>

HI Tim  
Another question  
Does Elasticsearch support SP-initiated SSO?  
if the answer is yes ,how to config?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 17, 2018, 4:37am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658/10 "2018-07-17T04:37:46Z")

</div>

The [SAML Guide](https://www.elastic.co/guide/en/elastic-stack-overview/6.3/saml-guide.html) configures the Elastic Stack for SP initiated SSO.

---

<div class="post-metadata">

**Author:** ![talon](https://avatars.discourse-cdn.com/v4/letter/t/c77e96/32.png) [@talon](https://discuss.elastic.co/u/talon)\
**Post date:** [July 17, 2018, 8:36am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658/11 "2018-07-17T08:36:59Z")

</div>

Thank you Tim  
Another question  
The the IdP went the cert of our ELK stack, i do not know we should supply the cert in kibana or the cert in elasticsearch?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 17, 2018, 8:51am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658/12 "2018-07-17T08:51:33Z")

</div>

That request is ambiguous - they could want a bunch of different certificates.

_Probably_ they want the [SAML encryption and/or signing certificates](https://www.elastic.co/guide/en/elastic-stack-overview/6.3/saml-guide-authentication.html#saml-enc-sign), in which case you probably should provide them with a full [metadata file](https://www.elastic.co/guide/en/elastic-stack-overview/6.3/_generating_sp_metadata.html).

---

<div class="post-metadata">

**Author:** ![talon](https://avatars.discourse-cdn.com/v4/letter/t/c77e96/32.png) [@talon](https://discuss.elastic.co/u/talon)\
**Post date:** [July 17, 2018, 9:14am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658/13 "2018-07-17T09:14:48Z")

</div>

server.ssl.certificate: /home/sshuser/cloud/kibana-6.2.4-linux-x86\_64/config/server.crt  
server.ssl.key: /home/sshuser/cloud/kibana-6.2.4-linux-x86\_64/config/server.key  
Is this the certificate configured here？  
can we generate the cert and key by ourselves(openssl) instead of elasticsearch-certutil tool?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 17, 2018, 10:18am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658/14 "2018-07-17T10:18:21Z")

</div>

I'm happy to help you here, but you need to show some evidence that you are reading the documentation that I link to.  
The questions you are asking are answered in those links.

---

<div class="post-metadata">

**Author:** ![talon](https://avatars.discourse-cdn.com/v4/letter/t/c77e96/32.png) [@talon](https://discuss.elastic.co/u/talon)\
**Post date:** [July 18, 2018, 8:05am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658/15 "2018-07-18T08:05:33Z")

</div>

HI Tim  
i have fixed the issue above ,thank you

and i have another question.  
the IDP provide me a cert, this cert is used to validate the saml response.

the response from idp is  
\<saml:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" NameQualifier="\_https://qcwa.honeywell.com/saml2" SPNameQualifier="elasticsearch\_demo" \>VGBP2LW7Crd1RfJ8D3cJAD0FnBI\</saml:NameID\>  
VGBP2LW7Crd1RfJ8D3cJAD0FnBI  
so i think the use account message is encrypted.  
my question is where to config the cert for decrypt the message.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [July 18, 2018, 9:05am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658/16 "2018-07-18T09:05:50Z")

</div>

Hi

> the IDP provide me a cert, this cert is used to validate the saml response.

The cert is used to ensure the authenticity and integrity of the SAML Response by validating the Digital Signature of the response. You don't have to configure this explicitly, the certificate should be included in the metadata file you acquired and you mention in your first message. Assuming you have configured Elasticsearch to read that metadata file (see `idp.metadata.path` in the [SAML Guide](https://www.elastic.co/guide/en/elastic-stack-overview/6.3/saml-guide-authentication.html#saml-create-realm) that Tim has shared with you, you don't need to do anything else.

> [@talon](#):
>
> he response from idp is  
> \<saml:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" NameQualifier="\_[https://qcwa.honeywell.com/saml2](https://qcwa.honeywell.com/saml2)" SPNameQualifier="elasticsearch\_demo" \>VGBP2LW7Crd1RfJ8D3cJAD0FnBI\</saml:NameID\>  
> VGBP2LW7Crd1RfJ8D3cJAD0FnBI  
> so i think the use account message is encrypted.  
> my question is where to config the cert for decrypt the message.

This is not encrypted. Transient NameIDs are usually opaque random strings that change every time a user logs in to the SAML Identity Provider.

---

<div class="post-metadata">

**Author:** ![talon](https://avatars.discourse-cdn.com/v4/letter/t/c77e96/32.png) [@talon](https://discuss.elastic.co/u/talon)\
**Post date:** [July 18, 2018, 9:10am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658/17 "2018-07-18T09:10:41Z")

</div>

Got it  
thank you

---

<div class="post-metadata">

**Author:** ![talon](https://avatars.discourse-cdn.com/v4/letter/t/c77e96/32.png) [@talon](https://discuss.elastic.co/u/talon)\
**Post date:** [July 19, 2018, 12:27am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658/18 "2018-07-19T00:27:53Z")

</div>

HI kakavas  
i faced another problem  
[2018-07-19T00:14:16,276][WARN][o.e.x.s.a.AuthenticationService] [logging-dev03] Authentication to realm saml3 failed - Provided SAML response is not valid for realm saml/saml3 (Caused by ElasticsearchSecurityException[SAML response yXAxKpCT8ZUdHQ8qZREyADXJSB- is for destination null but this realm uses [https://sent2-kibana-dev.dsentience.net:443/api/security/v1/saml](https://sent2-kibana-dev.dsentience.net:443/api/security/v1/saml)])

what could be the reason?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 19, 2018, 1:08am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658/19 "2018-07-19T01:08:02Z")

</div>

What version of Elasticsearch are you running?  
This issue should be [resolved in 6.3.1](https://github.com/elastic/elasticsearch/pull/31175)

---

<div class="post-metadata">

**Author:** ![talon](https://avatars.discourse-cdn.com/v4/letter/t/c77e96/32.png) [@talon](https://discuss.elastic.co/u/talon)\
**Post date:** [July 19, 2018, 1:50am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658/20 "2018-07-19T01:50:38Z")

</div>

the version of my Elasticsearch is 6.2.4,  
Is there any other solution to this problem other than an updated version?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 19, 2018, 2:10am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658/21 "2018-07-19T02:10:07Z")

</div>

Reconfigured your IdP to send a `Destination` parameter.  
Not all IdPs do that by default, but every one I've seen has the ability to turn it on in some way.

[Next page](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658.md?page=2)
