# Kibana SAML authentication error

**URL:** <https://discuss.elastic.co/t/kibana-saml-authentication-error/183379>\
**Category:** Kibana\
**Created:** [May 29, 2019, 3:55pm UTC](https://discuss.elastic.co/t/kibana-saml-authentication-error/183379 "2019-05-29T15:55:19Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![leobaiano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leobaiano/32/43704_2.png) [@leobaiano](https://discuss.elastic.co/u/leobaiano)\
**Post date:** [May 29, 2019, 3:55pm UTC](https://discuss.elastic.co/t/kibana-saml-authentication-error/183379/1 "2019-05-29T15:55:19Z")

</div>

I'm using elastic cloud and I followed the link tutorial below to enable SAML authentication on Kibana, but I'm having a problem.

Documentation I have followed: [https://www.elastic.co/guide/en/cloud/current/ec-securing-clusters-SAML.html](https://www.elastic.co/guide/en/cloud/current/ec-securing-clusters-SAML.html)

Error that I am recceing after I log in to IdP and am redirected back to my\_host\_kibana / api / security / v1 / saml

`{clue: admin / xpack / security / saml / authenticate} [action_code: 401, "error": "Unauthorized", "message": "[security_exception] unable to authenticate user [<unauthenticated-saml- \ n \ n \ n \ n \ n \ n \ n \ n \ n \ n \ n \ n \ n \ n \ n \ n \ n \ n \ security \\\ "charset = \\\" UTF-8 \\\ "\"}}} "}`

Elasticsearch configuration

```
xpack:
    security
        authc:
            realms:
                cloud-saml:
                    type: saml
                    order: 2
                    attributes.principal: "nameid:persistent"
                    attributes.groups: "http://schemas.microsoft.com/ws/2008/06/identity/claims/groups"
                    idp.metadata.path: "https://login.microsoftonline.com/4a39dff3-ff09-440b-b47b-8c603416bfce/federationmetadata/2007-06/federationmetadata.xml?appid=bdf10ffb-849e-4fd4-8038-335ed137c0aa"
                    idp.entity_id: "https://sts.windows.net/4a39dff3-ff09-440b-b47b-8c603416bfce/"
                    sp.entity_id: "https://8b64c0c41ede48bc9e907a5279089109.us-east-1.aws.found.io:9243"
                    sp.acs: "https://8b64c0c41ede48bc9e907a5279089109.us-east-1.aws.found.io:9243/api/security/v1/saml"
                    sp.logout: "https://8b64c0c41ede48bc9e907a5279089109.us-east-1.aws.found.io:9243/logout"

```

Setting up kibana

```
xpack.security.authProviders: [saml]
server.xsrf.whitelist: [/api/security/v1/saml]
xpack.security.public:
    protocol: https
    hostname: 8b64c0c41ede48bc9e907a5279089109.us-east-1.aws.found.io
    port: 9243
```

---

<div class="post-metadata">

**Author:** ![leobaiano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leobaiano/32/43704_2.png) [@leobaiano](https://discuss.elastic.co/u/leobaiano)\
**Post date:** [May 29, 2019, 4:24pm UTC](https://discuss.elastic.co/t/kibana-saml-authentication-error/183379/2 "2019-05-29T16:24:02Z")

</div>

From what I saw the problem is with

`attributes.principal:" nameid: persistent "`

If I remove `: persistent` holding only `nameid` functions. Maybe I need to do some adjustment on the IdP side to accept the `persistent`, but I have no idea where yet, if anyone has a light.

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [May 29, 2019, 5:25pm UTC](https://discuss.elastic.co/t/kibana-saml-authentication-error/183379/3 "2019-05-29T17:25:24Z")

</div>

Hey @leobaiano, when you're seeing `unable to authenticate user` in Kibana, per [the SAML troubleshooting guide](https://www.elastic.co/guide/en/elastic-stack-overview/7.1/trb-security-saml.html) it's because:

> This error indicates that Elasticsearch failed to process the incoming SAML authentication message. Since the message can’t be processed, Elasticsearch is not aware of who the to-be authenticated user is and the placeholder is used instead. To diagnose the actual problem, you must check the Elasticsearch logs for further details.

It is very possible that your `attributes.principal` is configured incorrectly. It all really depends on the IdP for what should be specified here per: [Configure Elasticsearch for SAML authentication | Elasticsearch Guide [7.1] | Elastic](https://www.elastic.co/guide/en/elastic-stack-overview/7.1/saml-guide-authentication.html#saml-attribute-mapping). I'd suggest by checking your Elasticsearch logs before going down this path though.

---

<div class="post-metadata">

**Author:** ![leobaiano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leobaiano/32/43704_2.png) [@leobaiano](https://discuss.elastic.co/u/leobaiano)\
**Post date:** [May 29, 2019, 5:30pm UTC](https://discuss.elastic.co/t/kibana-saml-authentication-error/183379/4 "2019-05-29T17:30:15Z")

</div>

> [@Brandon\_Kobel](#):
>
> It is very possible that your `attributes.principal` is configured incorrectly. It all really depends on the IdP for what should be specified here per: [Configure Elasticsearch for SAML authentication | Elasticsearch Guide [7.1] | Elastic](https://www.elastic.co/guide/en/elastic-stack-overview/7.1/saml-guide-authentication.html#saml-attribute-mapping). I'd suggest by checking your Elasticsearch logs before going down this path though.

Many thanks for the feedback, I did not set the attributes and kept the nameid on the main because it is default. As I'm working on a PoC I'll keep it that way for the moment, the idea is just to see if the solution we plan meets the needs and if so we go to the details and more advanced settings.

Thank you very much.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 30, 2019, 11:03am UTC](https://discuss.elastic.co/t/kibana-saml-authentication-error/183379/5 "2019-05-30T11:03:30Z")

</div>

We also explain about `nameid` and `nameid:persistent` in [https://www.elastic.co/guide/en/elastic-stack-overview/7.1/saml-guide-authentication.html#\_special\_attribute\_names](https://www.elastic.co/guide/en/elastic-stack-overview/7.1/saml-guide-authentication.html#_special_attribute_names) , hope this is helpful

---

<div class="post-metadata">

**Author:** ![leobaiano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leobaiano/32/43704_2.png) [@leobaiano](https://discuss.elastic.co/u/leobaiano)\
**Post date:** [May 30, 2019, 2:12pm UTC](https://discuss.elastic.co/t/kibana-saml-authentication-error/183379/6 "2019-05-30T14:12:51Z")

</div>

Thank you very much @ikakavas

I can not find where to mark the topic as resolved.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2019, 2:12pm UTC](https://discuss.elastic.co/t/kibana-saml-authentication-error/183379/7 "2019-06-27T14:12:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
