# Kibana- not able to login using saml

**URL:** <https://discuss.elastic.co/t/kibana-not-able-to-login-using-saml/227321>\
**Category:** Kibana\
**Created:** [April 9, 2020, 12:50pm UTC](https://discuss.elastic.co/t/kibana-not-able-to-login-using-saml/227321 "2020-04-09T12:50:48Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![jbaskaran\_123](https://avatars.discourse-cdn.com/v4/letter/j/8e7dd6/32.png) [@jbaskaran\_123](https://discuss.elastic.co/u/jbaskaran_123)\
**Post date:** [April 9, 2020, 12:50pm UTC](https://discuss.elastic.co/t/kibana-not-able-to-login-using-saml/227321/1 "2020-04-09T12:50:49Z")

</div>

We have configured SAML for our Elasticsearch cluster running in Kubernetes.  
when I hit the application URL, it redirects to IDP login (IDMS) but after logging in it shows "you are not authorized to use this application".

Below the configuration in kibana:

_ **kibana** _

kibana.yml: |  
server:  
host: 0.0.0.0  
xpack.security.enabled: true  
server.ssl.enabled: true  
server.ssl.key: /usr/share/kibana/config/tls\_server/key.pem  
server.ssl.certificate: /usr/share/kibana/config/tls\_server/crt.pem  
xpack.security.public:  
protocol: https  
hostname: {hostname}  
port: 443  
elasticsearch.url: "[https://es-coordinating](https://es-coordinating).{namespace}.svc.lb.{ APC\_CLUSTER\_NAME}.applecloud.io:443"  
elasticsearch.username: elastic   
elasticsearch.password: \*\*\*\*\*\*\*  
elasticsearch.ssl.certificateAuthorities: /usr/share/kibana/config/tls\_server/crt.pem

```
 xpack.monitoring.enabled: true
xpack.monitoring.kibana.collection.enabled: true
xpack.monitoring.ui.enabled: false
logging.dest: /var/log/kibana.log  
xpack.security.authProviders: [saml]		
server.xsrf.whitelist: [/api/security/v1/saml]

```

_ **Elasticsearch configuration:** _\*

```
xpack.security.authc.realms.saml1: ### saml is for kibana
  type: saml
  order: 2 ### order in which it appears in the realm chain
  idp.metadata.path: /usr/share/elasticsearch/config/saml/idp-metadata.xml
  idp.entity_id: "AppleSSO"
  sp.entity_id: "https://gbiobserver-events-dev.corp.apple.com"
  sp.acs: "https://gbiobserver-events-dev.corp.apple.com:443/api/security/v1/saml"
  sp.logout: "https://gbiobserver-events-dev.corp.apple.com:443/logout"
  attributes.principal: "nameid:persistent"
  attributes.groups: Groups
  encryption.key: /usr/share/elasticsearch/config/saml-cert/tls.key
  encryption.certificate: /usr/share/elasticsearch/config/saml-cert/tls.crt

```

We see all configurations looks correct in IDMS configuration. But still getting error while accessing. Looking forward for your assistance.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [April 10, 2020, 4:29am UTC](https://discuss.elastic.co/t/kibana-not-able-to-login-using-saml/227321/2 "2020-04-10T04:29:39Z")

</div>

We cover this exactly in [our docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/saml-role-mapping.html)

---

<div class="post-metadata">

**Author:** ![jbaskaran\_123](https://avatars.discourse-cdn.com/v4/letter/j/8e7dd6/32.png) [@jbaskaran\_123](https://discuss.elastic.co/u/jbaskaran_123)\
**Post date:** [April 13, 2020, 5:52am UTC](https://discuss.elastic.co/t/kibana-not-able-to-login-using-saml/227321/5 "2020-04-13T05:52:46Z")

</div>

Hi ,  
Thanks for your reply.  
I already added below mapping for saml.

PUT /\_security/role\_mapping/saml-kibana  
{  
"roles": ["kibana\_user"],  
"enabled": true,  
"rules": { "all": [  
{ "field": { "realm.name": "saml1" } },  
{ "field": { "groups": "Group-name" } }  
] }  
}

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [April 13, 2020, 6:29am UTC](https://discuss.elastic.co/t/kibana-not-able-to-login-using-saml/227321/6 "2020-04-13T06:29:32Z")

</div>

> [@jbaskaran\_123](#):
>
> it shows "you are not authorized to use this application".

What shows that ? Is it kibana or your IDP ?

---

<div class="post-metadata">

**Author:** ![jbaskaran\_123](https://avatars.discourse-cdn.com/v4/letter/j/8e7dd6/32.png) [@jbaskaran\_123](https://discuss.elastic.co/u/jbaskaran_123)\
**Post date:** [April 13, 2020, 6:46am UTC](https://discuss.elastic.co/t/kibana-not-able-to-login-using-saml/227321/7 "2020-04-13T06:46:35Z")

</div>

Error from IDP. from below link  
[https://idmsac-uat.corp.apple.com/ssotokenverify](https://idmsac-uat.corp.apple.com/ssotokenverify)

 ![Screenshot 2020-04-08 at 7.08.38 PM](https://us1.discourse-cdn.com/elastic/original/3X/0/3/03c56ff8a9218b877299761ef59f954e5e5c6e3c.jpeg)

Please find attached screenshot for it.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [April 13, 2020, 7:04am UTC](https://discuss.elastic.co/t/kibana-not-able-to-login-using-saml/227321/8 "2020-04-13T07:04:57Z")

</div>

Then you need to fix the configuration in your IDP. This is not an issue with the Elastic stack nor something that can be solved be changing the elasticsearch/kibana configuration, but a missing configuration on your IDP side, please contact your IDP administrator

---

<div class="post-metadata">

**Author:** ![jbaskaran\_123](https://avatars.discourse-cdn.com/v4/letter/j/8e7dd6/32.png) [@jbaskaran\_123](https://discuss.elastic.co/u/jbaskaran_123)\
**Post date:** [April 13, 2020, 7:10am UTC](https://discuss.elastic.co/t/kibana-not-able-to-login-using-saml/227321/9 "2020-04-13T07:10:30Z")

</div>

Ok. Thankyou.  
I will check and get back to you.

---

<div class="post-metadata">

**Author:** ![jbaskaran\_123](https://avatars.discourse-cdn.com/v4/letter/j/8e7dd6/32.png) [@jbaskaran\_123](https://discuss.elastic.co/u/jbaskaran_123)\
**Post date:** [April 17, 2020, 9:43am UTC](https://discuss.elastic.co/t/kibana-not-able-to-login-using-saml/227321/10 "2020-04-17T09:43:56Z")

</div>

Hi Loannis,  
Now I am able to successfully authenticate from saml as SAML Response I get successfully.  
I have created below role and mapping also. I get below error in browser when I get kibana link.  
I referred this in many of your posts related to this error but could not fix the issue.

{"message":"action [indices:data/read/search] is unauthorized for user [j\_baskaran@domain.com]: [security\_exception] action [indices:data/read/search] is unauthorized for user [j\_baskaran@apple.com]","statusCode":403,"error":"Forbidden"}

**Role** :

{  
"saml-kibana-role" : {  
"cluster" : [  
"monitor"  
],  
"indices" : [  
{  
"names" : [  
"\*"  
],  
"privileges" : [  
"read"  
],  
"allow\_restricted\_indices" : false  
}  
],  
"applications" : ,  
"run\_as" : [  
"saml\_user"  
],  
"metadata" : { },  
"transient\_metadata" : {  
"enabled" : true  
}  
}  
}

**role\_mapping** :

{  
"saml-kibana" : {  
"enabled" : true,  
"roles" : [  
"saml-kibana-role"  
],  
"rules" : {  
"all" : [  
{  
"field" : {  
"realm.name" : "saml1"  
}  
},  
{  
"field" : {  
"groups" : "20022489"  
}  
},  
{  
"field" : {  
"username" : "[j\_baskaran@apple.com](mailto:j_baskaran@apple.com)"  
}  
}  
]  
},  
"metadata" : { }  
}  
}

---

<div class="post-metadata">

**Author:** ![jbaskaran\_123](https://avatars.discourse-cdn.com/v4/letter/j/8e7dd6/32.png) [@jbaskaran\_123](https://discuss.elastic.co/u/jbaskaran_123)\
**Post date:** [April 17, 2020, 9:53am UTC](https://discuss.elastic.co/t/kibana-not-able-to-login-using-saml/227321/11 "2020-04-17T09:53:48Z")

</div>

Note: I am getting same error when I use inbuilt "kibana\_user" role also.  
Also,  
"field" : {  
"groups" : "20022489" =\> (tried with both group name and group id as I get group id from SAML Response metadata)

Kindly check and advise

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [April 18, 2020, 9:28am UTC](https://discuss.elastic.co/t/kibana-not-able-to-login-using-saml/227321/12 "2020-04-18T09:28:30Z")

</div>

I can only assume , since you share no other information, that your role mappings are wrong . Maybe your user is not in the group 20022489, or your IDP doesnt send that information in the saml response message or the saml attribute they are using to convey this is not named `Groups` as your configuration assumes.

Please see here [https://www.elastic.co/guide/en/elasticsearch/reference/current/trb-security-saml.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/trb-security-saml.html) how to enable trace logging and the information that you see in these logs will hopefully help you understand what of the above is happening.

---

<div class="post-metadata">

**Author:** ![jbaskaran\_123](https://avatars.discourse-cdn.com/v4/letter/j/8e7dd6/32.png) [@jbaskaran\_123](https://discuss.elastic.co/u/jbaskaran_123)\
**Post date:** [April 22, 2020, 4:20am UTC](https://discuss.elastic.co/t/kibana-not-able-to-login-using-saml/227321/13 "2020-04-22T04:20:49Z")

</div>

Hi Loannis,  
I am able to resolve the issue. Actually i was not part of the group in UAT environment.  
Now i added there and able to login kibana. Thanks for your assistance.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 20, 2020, 4:21am UTC](https://discuss.elastic.co/t/kibana-not-able-to-login-using-saml/227321/14 "2020-05-20T04:21:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
