# Getting unauthorised saml user error

**URL:** <https://discuss.elastic.co/t/getting-unauthorised-saml-user-error/176605>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [April 12, 2019, 11:01am UTC](https://discuss.elastic.co/t/getting-unauthorised-saml-user-error/176605 "2019-04-12T11:01:08Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ronnie16](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ronnie16/32/66399_2.png) [@Ronnie16](https://discuss.elastic.co/u/Ronnie16)\
**Post date:** [April 12, 2019, 11:01am UTC](https://discuss.elastic.co/t/getting-unauthorised-saml-user-error/176605/1 "2019-04-12T11:01:08Z")

</div>

I'm implementing SAML for elasticsearch cluster. After hitting kibana url I get redirected to IDP saml page for login but after login I get below error in browser -

\< {"statusCode":401,"error":"Unauthorized","message":"[security\_exception] unable to authenticate user [\<unauthenticated-saml-user\>] for action [cluster:admin/xpack/security/saml/authenticate], with { header={ WWW-Authenticate="Basic realm=\"security\" charset=\"UTF-8\"" } } :: {"path":"/\_xpack/security/saml/authenticate","query":{},"body":"{\"ids\":[\"\_d263c43dea4fa7997bddfa0eaf6fbbdb7ed11011\"]\>

Seeing below error in elasticsearch.yml file:-  
\<[2019-04-12T09:57:43,977][WARN][o.a.x.s.s.XMLSignature] Signature verification failed.  
[2019-04-12T09:57:43,997][WARN][o.e.x.s.a.AuthenticationService] [es-coordinating] Authentication to realm saml1 failed - Provided SAML response is not valid for realm saml/saml1 (Caused by ElasticsearchSecurityException[SAML assertion [U8eyywQktnmBPxDobRY/fZisgzoe62kh...] is encrypted, but no decryption key is available])\>

NOTE- I have confirmed that ( `sp.entity_id` ) match with what has been configured as the SAML Service Provider Entity ID in the SAML Identity Provider documentation

Elasticsearch configuration:-  
xpack.security.authc.token.enabled: true  
xpack.security.authc.realms.saml1:  
type: saml  
order: 2  
idp.metadata.path: /usr/share/elasticsearch/config/saml/idp-metadata.xml  
idp.entity\_id: "XXXSSO"  
sp.entity\_id: "[https://gbikibana-xxxx.corp.XXXX.com](https://gbikibana-xxxx.corp.XXXX.com)"  
sp.acs: "[https://gbikibana-xxxx.corp.XXXX.com:443/api/security/v1/saml](https://gbikibana-xxxx.corp.XXXX.com:443/api/security/v1/saml)"  
sp.logout: "[https://gbikibana-xxxx.corp.XXXX.com:443/logout](https://gbikibana-xxxx.corp.XXXX.com:443/logout)"  
attributes.principal: "nameid:persistent"

kibana config:-  
server:  
host: 0.0.0.0  
xpack.security.public:  
protocol: https  
hostname: [gbikibana-xxxx.corp.XXXX.com](http://gbikibana-xxxx.corp.XXXX.com)  
port: 443  
elasticsearch.url: "[https://es-coordinating.gbi-xxxx.svc.lb.usrno1.XXXX.io:9200](https://es-coordinating.gbi-xxxx.svc.lb.usrno1.XXXX.io:9200)"  
elasticsearch.username: kibana  
elasticsearch.password: kibana  
xpack.security.enabled: true  
server.ssl.enabled: true  
server.ssl.key: /usr/share/kibana/config/tls\_server/key.pem  
server.ssl.certificate: /usr/share/kibana/config/tls\_server/crt.pem  
elasticsearch.ssl.certificateAuthorities: /usr/share/kibana/config/tls\_server/crt.pem  
xpack.security.authProviders: [saml]  
server.xsrf.whitelist: [/api/security/v1/saml]

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [April 12, 2019, 7:46pm UTC](https://discuss.elastic.co/t/getting-unauthorised-saml-user-error/176605/2 "2019-04-12T19:46:15Z")

</div>

Hi there

The error is actually very clearly pointed out in your logs:

> [@Ronnie16](#):
>
> Caused by ElasticsearchSecurityException[SAML assertion [U8eyywQktnmBPxDobRY/fZisgzoe62kh...] is encrypted, but no decryption key is available])\>

Your SAML IDP is sending an encrypted SAML Assertion but you haven't configured Elasticsearch for this and it can't decrypt it.

Have you read our documentation? We have a very detailed saml guide and the encryption settings in particular are discussed in this part: [Configure Elasticsearch for SAML authentication | Elasticsearch Guide [7.0] | Elastic](https://www.elastic.co/guide/en/elastic-stack-overview/7.0/saml-guide-authentication.html#saml-enc-sign)

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [April 14, 2019, 11:46pm UTC](https://discuss.elastic.co/t/getting-unauthorised-saml-user-error/176605/4 "2019-04-14T23:46:14Z")

</div>

> [@Ronnie16](#):
>
> So can I use the same certificate i.e "/usr/share/elasticsearch/config/tls\_server/crt.pem" ?

You _can_, but we discourage it. The signing & encryption certificates for SAML are unrelated to your server identity for network services (TLS), and it is not usually a good idea to mix them.  
It will work, but you're better off just generating a new certificate.

> [@Ronnie16](#):
>
> Do I have to provide this certificate to IDP team ?

You do, but your IdP team already thinks you have a certificate, so you should probably ask them about that before you go any further.

```auto
SAML assertion [U8eyywQktnmBPxDobRY/fZisgzoe62kh...] is encrypted,
  but no decryption key is available

```

If you are getting this error, then the IdP thinks it is supposed to send you encrypted assertions, and is encrypting them using some sort of certificate that it got from somewhere.

That _could_ be a mistake from your IdP team - maybe they just copied the config from another service and forgot to remove the encryption certificate. Maybe they generated a new certificate for you, but didn't give you a copy.

It would be advisable for you to talk to them about this before you try and fix it from your side.

---

<div class="post-metadata">

**Author:** ![Ronnie16](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ronnie16/32/66399_2.png) [@Ronnie16](https://discuss.elastic.co/u/Ronnie16)\
**Post date:** [April 15, 2019, 4:25am UTC](https://discuss.elastic.co/t/getting-unauthorised-saml-user-error/176605/5 "2019-04-15T04:25:29Z")

</div>

yes the IDP is using some certificate to encrypt responses. So I should provide them my own crt.pem and ask them to use the same. Just one question, I should provide crt.pem of es-coordinating or kibana ?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [April 15, 2019, 4:55am UTC](https://discuss.elastic.co/t/getting-unauthorised-saml-user-error/176605/6 "2019-04-15T04:55:40Z")

</div>

> [@Ronnie16](#):
>
> yes the IDP is using some certificate to encrypt responses.

The question is _why?_ and can they just turn it off.  
You might have a local policy to always encrypt assertions, but the circumstances under which this is truly necessary are pretty rare. So for simplicity's sake, I would suggest you simply disable encryption (on the IdP) if you have that option.

> [@Ronnie16](#):
>
> I should provide them my own crt.pem and ask them to use the same. Just one question, I should provide crt.pem of es-coordinating or kibana ?

No, as mentioned above, we recommend that you generate a new certificate specifically for SAML encryption and/or signing. The documentation that @ikakavas linked to (above) walks you through that process.  
They don't need a copy of your TLS certificates, they just need your SAML encryption certificate (the `encryption.certificate` setting from your realm).

Alternatively, If your IdP can import SAML metadata, then you can simply generate a metadata file using the `elasticsearch-saml-metadata` tool, and pass that to your IdP team.

---

<div class="post-metadata">

**Author:** ![Ronnie16](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ronnie16/32/66399_2.png) [@Ronnie16](https://discuss.elastic.co/u/Ronnie16)\
**Post date:** [April 19, 2019, 7:45am UTC](https://discuss.elastic.co/t/getting-unauthorised-saml-user-error/176605/7 "2019-04-19T07:45:09Z")

</div>

Hi TimV,  
This worked after IDP disabled encryption from there end. As of now this is in UAT so disabling encryption is fine but once I move to production, is it mandatory to enable encryption from IDP end ? Any harm to Elasticsearch security if we keep encryption disabled ?

Not sure about any local policy to encrypt assertions

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [April 19, 2019, 9:13am UTC](https://discuss.elastic.co/t/getting-unauthorised-saml-user-error/176605/8 "2019-04-19T09:13:24Z")

</div>

Elasticsearch will not impose any requirements on the encryption of SAML Assertions. For most of the cases, the necessary confidentiality property which is provided by TLS (over which the SAML Assertion is sent, via https ) is enough. If the IDP, or a local security policy dictates the use of encrypted SAML Assertions, Elasticsearch can consume them if correctly configured.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [April 22, 2019, 8:07am UTC](https://discuss.elastic.co/t/getting-unauthorised-saml-user-error/176605/10 "2019-04-22T08:07:54Z")

</div>

> [@Ronnie16](#):
>
> Do I have to create a role mapping with saml realm ?

Yes, you do. By default your users have no roles, and as such no privilege to access anything, please see our documentation: [Configuring role mappings | Elasticsearch Guide [7.0] | Elastic](https://www.elastic.co/guide/en/elastic-stack-overview/7.0/saml-role-mapping.html)

> [@Ronnie16](#):
>
> I didn't do anything in the previous set up and it had routed me to kibana UI

Not sure what you mean by "it had routed me to kibana UI" but there is no way your SAML user would have access to any indices or the kibana UI (you need the `kibana_user` role) unless you have explicitly granted them the role.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [April 23, 2019, 5:20am UTC](https://discuss.elastic.co/t/getting-unauthorised-saml-user-error/176605/12 "2019-04-23T05:20:29Z")

</div>

@Ronnie16  
It's best to open a new topic when you run into a differerent issue.

The error you are seeing is a Kibana matter, and you're going to get a better result in the `kibana` forum.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 21, 2019, 5:20am UTC](https://discuss.elastic.co/t/getting-unauthorised-saml-user-error/176605/13 "2019-05-21T05:20:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
