# Issue connecting google saml with es stack

**URL:** <https://discuss.elastic.co/t/issue-connecting-google-saml-with-es-stack/144791>\
**Category:** Elasticsearch\
**Created:** [August 16, 2018, 10:26pm UTC](https://discuss.elastic.co/t/issue-connecting-google-saml-with-es-stack/144791 "2018-08-16T22:26:53Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ashok\_Bellur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashok_bellur/32/26292_2.png) [@ashok\_Bellur](https://discuss.elastic.co/u/ashok_Bellur)\
**Post date:** [August 16, 2018, 10:26pm UTC](https://discuss.elastic.co/t/issue-connecting-google-saml-with-es-stack/144791/1 "2018-08-16T22:26:53Z")

</div>

Hello,

I had been trying to get Kibana to work with SAML authentication, but with no luck.

[2018-08-16T21:54:02,824][WARN][o.e.x.s.a.AuthenticationService] [ip-x-x-x-x-ip-x-x-x-x.ec2.internal] Authentication to realm saml1 failed - Provided SAML response is not valid for realm saml/saml1 (Caused by ElasticsearchSecurityException[Conditions [[https://accounts.google.com/o/sa](https://accounts.google.com/o/sa)...] do not match required audience [[https://kibana6.qa.internal:80/](https://kibana6.qa.internal:80/)]])

Thanks,  
Ashok

Here's my settings below:

## **Kibana Config**

server.port: 80  
server.host: "0.0.0.0"

elasticsearch.username: kibana  
elasticsearch.password: \<\*\*\*\*\*\*\*\>

xpack.security.authProviders: [saml,basic]  
server.xsrf.whitelist: [/api/security/v1/saml]

server.ssl.enabled: true  
server.ssl.key: /pathtokey  
server.ssl.certificate: /path to cert

elasticsearch.ssl.verificationMode: certificate  
elasticsearch.ssl.certificateAuthorities: /pathtocertificatepem file  
xpack.security.encryptionKey: "\*\*\*\*\*\*\*\*\*\*\*\*

**ES Config**

bootstrap.memory\_lock: true  
cluster.name: es\_qa\_std

discovery.ec2.tag.designation: std

discovery.ec2.tag.environment: qa

discovery.ec2.tag.role: elasticsearch6

discovery.zen.hosts\_provider: ec2

network.host: x.x.x.x

node.name: ip-x-x-x-x.ec2.internal

path.data: "/mnt/elasticsearch/ip-x-x-x-x.ec2.internal\_data/ip-x-x-x-x.ec2.internal"

path.logs: "/var/log/elasticsearch/ip-x-x-x-x.ec2.interna"

node.max\_local\_storage\_nodes: 2

xpack.security.enabled: true

xpack.security.transport.ssl.enabled: true

xpack.security.transport.ssl.verification\_mode: certificate

xpack.security.transport.ssl.certificate: es1.crt

xpack.security.transport.ssl.key: es1.key

xpack.security.transport.ssl.certificate\_authorities: ca.crt

xpack.security.http.ssl.enabled: true

xpack.security.http.ssl.verification\_mode: certificate

xpack.security.http.ssl.certificate: es1.crt

xpack.security.http.ssl.key: es1.key  
xpack.security.http.ssl.certificate\_authorities: ca.crt

xpack.security.authc.realms.native1:  
type: native  
order: 0

xpack.security.authc.realms.saml1:  
type: saml  
order: 1  
idp.metadata.path: saml/idp-metadata.xml  
idp.entity\_id: "[https://accounts.google.com/o/saml2?idpid=xxxxxxx](https://accounts.google.com/o/saml2?idpid=xxxxxxx)"  
sp.entity\_id: "[https://kibana6.qa.internal:80/](https://kibana6.qa.internal:80/)"  
sp.acs: "[https://kibana6.qa.internal:80/api/security/v1/saml](https://kibana6.qa.internal:80/api/security/v1/saml)"  
sp.logout: "[https://kibana6.qa.internal:80/logout](https://kibana6.qa.internal:80/logout)"  
attributes.principal: "nameid:persistent"

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [August 17, 2018, 7:12am UTC](https://discuss.elastic.co/t/issue-connecting-google-saml-with-es-stack/144791/2 "2018-08-17T07:12:47Z")

</div>

Please use the `</>` button for preformatted text when adding configuration and log snippets as it really helps readability.

> [@ashok\_Bellur](#):
>
> [2018-08-16T21:54:02,824][WARN][o.e.x.s.a.AuthenticationService] [ip-x-x-x-x-ip-x-x-x-x.ec2.internal] Authentication to realm saml1 failed - Provided SAML response is not valid for realm saml/saml1 (Caused by ElasticsearchSecurityException[Conditions [[https://accounts.google.com/o/sa](https://accounts.google.com/o/sa)...] do not match required audience [[https://kibana6.qa.internal:80/](https://kibana6.qa.internal:80/)]])

It looks like the Identity Provider is sending a wrong value in the `Audience` element of `<AudienceRestriction>` in the `Conditions` of the SAML Assertion, so I assume you have set the wrong value when configuring your managed Google account for SSO.  
This should be the EntityID of the the Elastic Stack SAML SP ( that is `https://kibana6.qa.internal:80` according to your configuration ) and not a URL pointing to Google ( as it looks like now )

Take a look at [Set up your own custom SAML app - Google Workspace Admin Help](https://support.google.com/a/answer/6087519?hl=en) . In `Set up your own custom SAML app` step 8, make sure you enter the correct values for `ACS URL` ( it should match `sp.acs` of your SAML Realm configuration) and `Entity ID` ( it should match `sp.entity_id` of your SAML Realm configuration)

---

<div class="post-metadata">

**Author:** ![ashok\_Bellur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashok_bellur/32/26292_2.png) [@ashok\_Bellur](https://discuss.elastic.co/u/ashok_Bellur)\
**Post date:** [August 17, 2018, 4:18pm UTC](https://discuss.elastic.co/t/issue-connecting-google-saml-with-es-stack/144791/3 "2018-08-17T16:18:15Z")

</div>

Thanks for the suggestion @ikakavas.

Now i am getting this error.

`[2018-08-17T16:14:36,475][WARN][o.e.x.s.a.AuthenticationService] [ip-x-x-x-x-ip-x-x-x-x.ec2.internal] Authentication to realm saml1 failed - Provided SAML response is not valid for realm saml/saml1 (Caused by ElasticsearchSecurityException[Conditions [https://kibana6.qa.interna...] do not match required audience [https://kibana6.qa.internal:80/]])`

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [August 17, 2018, 4:33pm UTC](https://discuss.elastic.co/t/issue-connecting-google-saml-with-es-stack/144791/4 "2018-08-17T16:33:10Z")

</div>

Still the same issue. You set something as a value in `Entity ID` in your Google SAML Configuration that is not the same as what you set as `sp.entity_id` in your SAML realm in Elasticsearch.

These look like URLs but are matched as strings, so trailing slashes, added ( default ) port numbers make a difference. The two values need to be exactly the same.

---

<div class="post-metadata">

**Author:** ![ashok\_Bellur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashok_bellur/32/26292_2.png) [@ashok\_Bellur](https://discuss.elastic.co/u/ashok_Bellur)\
**Post date:** [August 17, 2018, 6:06pm UTC](https://discuss.elastic.co/t/issue-connecting-google-saml-with-es-stack/144791/5 "2018-08-17T18:06:33Z")

</div>

Thanks @ikakavas. The above issue is resolved. Now i am trying to setup the attributes in IdP. We are using google gsuite.

 ![07%20PM](https://us1.discourse-cdn.com/elastic/original/3X/7/a/7a318fe1da85de6b4592b1ffc9f95cfabec662ae.png)

And in my elasticsearch config, i am using `attributes.principal: "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"`

This is what i am seeing now `[2018-08-17T18:03:37,609][WARN][o.e.x.s.a.AuthenticationService] [ip-x-x-x-x-ip-x-x-x-x.ec2.internal] Authentication to realm saml1 failed - SAML Attribute [http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress] for [attributes.principal] not found in [principal=[ashok@mycompany.com]]`

---

<div class="post-metadata">

**Author:** ![ashok\_Bellur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashok_bellur/32/26292_2.png) [@ashok\_Bellur](https://discuss.elastic.co/u/ashok_Bellur)\
**Post date:** [August 17, 2018, 8:16pm UTC](https://discuss.elastic.co/t/issue-connecting-google-saml-with-es-stack/144791/6 "2018-08-17T20:16:12Z")

</div>

Hello,

Its working now after replacing principal in Google IdP to `urn:oid:0.9.2342.19200300.100.1.1`

Thanks,  
Ashok

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 14, 2018, 8:16pm UTC](https://discuss.elastic.co/t/issue-connecting-google-saml-with-es-stack/144791/7 "2018-09-14T20:16:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
