# Jumpcloud.com saml integration

**URL:** <https://discuss.elastic.co/t/jumpcloud-com-saml-integration/161750>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [December 20, 2018, 7:23pm UTC](https://discuss.elastic.co/t/jumpcloud-com-saml-integration/161750 "2018-12-20T19:23:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vladimir\_Khazin](https://avatars.discourse-cdn.com/v4/letter/v/258eb7/32.png) [@Vladimir\_Khazin](https://discuss.elastic.co/u/Vladimir_Khazin)\
**Post date:** [December 20, 2018, 7:23pm UTC](https://discuss.elastic.co/t/jumpcloud-com-saml-integration/161750/1 "2018-12-20T19:23:50Z")

</div>

Hello there,

I am trying to integrate hosted [cloud.elastic.co](http://cloud.elastic.co) deployment on GCP with [jumpcloud.com](http://jumpcloud.com) SAML  
I have configured [jumpcloud.com](http://jumpcloud.com) custom/generic custom provider and am able to login to the sso end-point after the configuration.  
Configuring the xpack cloud-saml is failing with no useful message.

The configuration I am using:  
xpack:  
security:  
authc:  
realms:  
cloud-saml:  
type: saml  
order: 2  
attributes.principal: "nameid:persistent"  
attributes.groups: "groups"  
idp.metadata.path: "[https://s3.us-east-2.amazonaws.com/vk-zubr/JumpCloud-saml2-metadata-2.xml](https://s3.us-east-2.amazonaws.com/vk-zubr/JumpCloud-saml2-metadata-2.xml)"  
idp.entity\_id: "elastic-cloud"  
sp.entity\_id: "[https://2fee30fbb05e49c598325159fcf012fe.us-central1.gcp.cloud.es.io:9243/](https://2fee30fbb05e49c598325159fcf012fe.us-central1.gcp.cloud.es.io:9243/)"  
sp.acs: "[https://2fee30fbb05e49c598325159fcf012fe.us-central1.gcp.cloud.es.io:9243/api/security/v1/saml](https://2fee30fbb05e49c598325159fcf012fe.us-central1.gcp.cloud.es.io:9243/api/security/v1/saml)"  
sp.logout: "[https://2fee30fbb05e49c598325159fcf012fe.us-central1.gcp.cloud.es.io:9243/logout](https://2fee30fbb05e49c598325159fcf012fe.us-central1.gcp.cloud.es.io:9243/logout)"

Any suggestions/ideas?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [December 21, 2018, 4:26am UTC](https://discuss.elastic.co/t/jumpcloud-com-saml-integration/161750/2 "2018-12-21T04:26:20Z")

</div>

We intentionally show minimal information in the browser when SAML authentication fails.  
Because authentication has failed, we cannot know who the user is, so we cannot safely show them any information about the cluster or its configuration.

To diagnose SAML problems, you need to look at the Elasticsearch logs.  
In the cloud console, on the left hand menu, you should see "Elasticsearch -\> Logs".  
Check there for more deails about why authentication failed - it's impossible for us to guess based soley on a config file.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 18, 2019, 4:26am UTC](https://discuss.elastic.co/t/jumpcloud-com-saml-integration/161750/3 "2019-01-18T04:26:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
