# Google SAML 401

**URL:** <https://discuss.elastic.co/t/google-saml-401/202903>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [October 9, 2019, 7:04pm UTC](https://discuss.elastic.co/t/google-saml-401/202903 "2019-10-09T19:04:28Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Brad\_Wadsworth](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brad_wadsworth/32/46413_2.png) [@Brad\_Wadsworth](https://discuss.elastic.co/u/Brad_Wadsworth)\
**Post date:** [October 9, 2019, 7:04pm UTC](https://discuss.elastic.co/t/google-saml-401/202903/1 "2019-10-09T19:04:29Z")

</div>

Having issues getting Google SAML SSO to work withe Elastic Cloud. I'm getting a 401 after I choose my Google identity.

elasticsearch.yaml:  
xpack:  
security:  
authc:  
realms:  
saml:  
cloud-saml:  
order: 2  
attributes.principal: "[http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress](http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress)"  
attribute\_patterns.principal: "^([^@]+)@example\.com$"  
attributes.groups: "groups"  
idp.metadata.path: /app/config/saml/metadata.xml  
idp.entity\_id: "[https://accounts.google.com/o/saml2?idpid=xxxxxxx](https://accounts.google.com/o/saml2?idpid=xxxxxxx)"  
sp.entity\_id: "https://\<MY\_KIBANA\_URL\>:9243/"  
sp.acs: "https://\<MY\_KIBANA\_URL\>:9243/api/security/v1/saml"  
sp.logout: "https://\<MY\_KIBANA\_URL\>:9243/logout"

kibana.yaml  
xpack.security.authc.providers: [saml,basic]  
server.xsrf.whitelist: [/api/security/v1/saml]  
xpack.security.authc.saml.realm: cloud-saml

Response from browser:  
`{"statusCode":401,"error":"Unauthorized","message":"[security_exception] unable to authenticate user [<unauthenticated-saml-user>] for action [cluster:admin/xpack/security/saml/authenticate], with { header={ WWW-Authenticate={ 0=\"Bearer realm=\\\"security\\\"\" & 1=\"ApiKey\" & 2=\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\" } } }"}`

SAML Response:  
`</ds:X509Certificate></ds:X509Data></ds:KeyInfo></ds:Signature><saml2:Subject><saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient">myusername@example.com</saml2:NameID><saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><saml2:SubjectConfirmationData InResponseTo="responseID" NotOnOrAfter="2019-10-09T18:18:25.399Z" Recipient="https://<MY_KIBANA_URL>:9243/api/security/v1/saml"/></saml2:SubjectConfirmation></saml2:Subject><saml2:Conditions NotBefore="2019-10-09T18:08:25.399Z" NotOnOrAfter="2019-10-09T18:18:25.399Z"><saml2:AudienceRestriction><saml2:Audience>https://<MY_KIBANA_URL>:9243/</saml2:Audience></saml2:AudienceRestriction></saml2:Conditions><saml2:AuthnStatement AuthnInstant="2019-10-07T14:31:18.000Z" SessionIndex="sessionID"><saml2:AuthnContext><saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified</saml2:AuthnContextClassRef></saml2:AuthnContext></saml2:AuthnStatement></saml2:Assertion></saml2p:Response>`

Any ideas on what the issue could be?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [October 10, 2019, 6:59am UTC](https://discuss.elastic.co/t/google-saml-401/202903/2 "2019-10-10T06:59:41Z")

</div>

Hi Brad

The error message you get is contained in our [common SAML troubleshooting guide](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/trb-security-saml.html) ( see point 4 ). It tells you to basically look at the logs as there will be something pointing to the error there.

You are not sharing your logs, but the configuration error is easy to spot in this case.

You have set

```auto
attributes.principal: "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"

```

which means that you configure elasticsearch to expect a SAML Attribute with name `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress` in the SAML Assertion. As you can see in the SAML Response you have posted, there is no such SAML Attribute sent by Google's IDP . As a matter of fact, your IDP doesn't send any attributes, but only a NameID, so you need to change your configuration to

```auto
 attributes.principal: nameid

```

Also please note that you have configured

```auto
attributes.groups: "groups"

```

but Google IDP doesn't send any SAML Attribute with name "groups" so nothing will be mapped to the `groups` user property in Elasticsearch and you won't be able to use any [group based role mappings](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/saml-role-mapping.html)

---

<div class="post-metadata">

**Author:** ![Brad\_Wadsworth](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brad_wadsworth/32/46413_2.png) [@Brad\_Wadsworth](https://discuss.elastic.co/u/Brad_Wadsworth)\
**Post date:** [October 10, 2019, 4:55pm UTC](https://discuss.elastic.co/t/google-saml-401/202903/3 "2019-10-10T16:55:06Z")

</div>

Awesome!  
`attributes.principal: nameid`  
worked, thank you. One other question, it looks like Google SAML doesn't have a full name attribute, only first and last name. Is there a way to combine those attributes for  
`attributes.name`?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [October 11, 2019, 5:12am UTC](https://discuss.elastic.co/t/google-saml-401/202903/4 "2019-10-11T05:12:16Z")

</div>

Hi,

No, we don't unfortunately offer any feature that would allow you to post-process released attributes.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 8, 2019, 5:12am UTC](https://discuss.elastic.co/t/google-saml-401/202903/5 "2019-11-08T05:12:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
