# Kibana SAML integration issue

**URL:** <https://discuss.elastic.co/t/kibana-saml-integration-issue/134761>\
**Category:** Kibana\
**Created:** [June 6, 2018, 8:34am UTC](https://discuss.elastic.co/t/kibana-saml-integration-issue/134761 "2018-06-06T08:34:29Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Indisol](https://avatars.discourse-cdn.com/v4/letter/i/5f8ce5/32.png) [@Indisol](https://discuss.elastic.co/u/Indisol)\
**Post date:** [June 6, 2018, 8:34am UTC](https://discuss.elastic.co/t/kibana-saml-integration-issue/134761/1 "2018-06-06T08:34:30Z")

</div>

Hello Experts,

While trying to enable SAML authentication for Kibana 6.2, i am getting an error in the elasticsearch logs

[WARN][o.e.x.s.a.AuthenticationService] [nfvn304-1] Authentication to realm saml1 failed - Provided SAML response is not valid for realm saml/saml1 (Caused by ElasticsearchSecurityException[SAML response zXOgCxQAuXSqVMZI6Ick7Yv\_KFA is for destination null but this realm uses [https://nfvn304-1:5605/api/security/v1/saml](https://nfvn304-1:5605/api/security/v1/saml)])"

#SAML authentication configuration  
xpack.security.authc.realms.saml1:  
type: saml  
order: 1  
idp.metadata.path: saml/idp-metadata.xml  
idp.entity\_id: "[https://vm00000617.nopl.com](https://vm00000617.nopl.com)"  
sp.entity\_id: "[https://nfvn304-1:5605/](https://nfvn304-1:5605/)"  
sp.acs: "[https://nfvn304-1:5605/api/security/v1/saml](https://nfvn304-1:5605/api/security/v1/saml)"  
sp.logout: "[https://nfvn304-1:5605/logout](https://nfvn304-1:5605/logout)"  
attributes.principal: "nameid:persistent"

I have installed the security certificate also from the SAML response XML. some how i feel its related to encryption.  
thanks in advance

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [June 7, 2018, 1:28am UTC](https://discuss.elastic.co/t/kibana-saml-integration-issue/134761/2 "2018-06-07T01:28:17Z")

</div>

It looks like your Identity Provider is sending an invalid SAML response.  
Can you tell us which IdP you are using?

---

<div class="post-metadata">

**Author:** ![Indisol](https://avatars.discourse-cdn.com/v4/letter/i/5f8ce5/32.png) [@Indisol](https://discuss.elastic.co/u/Indisol)\
**Post date:** [June 8, 2018, 11:06am UTC](https://discuss.elastic.co/t/kibana-saml-integration-issue/134761/3 "2018-06-08T11:06:13Z")

</div>

thanks for the response Tim, we are using PingFederate.  
The IDP response is signed with \*.p12 certificate.

we have extracted the certificate from xml, stored in the server as _.p12.  
And imported this certicate(_.p12) in our elastic Keystore.  
we have made the following change also in the elasticsearch.yml file  
encryption.keystore.path  
encryption.keystore.alias  
encryption.keystore.secure\_password

Is there some thing/step that i am missing here.

Regards,  
indi

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [June 10, 2018, 9:11pm UTC](https://discuss.elastic.co/t/kibana-saml-integration-issue/134761/4 "2018-06-10T21:11:19Z")

</div>

Hi Indi.

The issue at hand is that Ping Federate doesn't set the Destination element in the SAML Response it sends, and the Elastic Stack SAML implementation attempts to match it to the Assertion Consuming Service endpoint of the SP, which fails.

> SAML response zXOgCxQAuXSqVMZI6Ick7Yv\_KFA is for destination null but this realm uses [https://nfvn304-1:5605/api/security/v1/saml](https://nfvn304-1:5605/api/security/v1/saml)])

According to the SAML 2 specification, If the SAML Response is not signed (only the Assertion it contains is), it's not mandatory that the Destination element is included and this is what Ping Federate does. \*\*

We have identified this behavior as a potential point where our SAML implementation is stricter than it should be and harming interoperability so we addressed it in this [PR](https://github.com/elastic/elasticsearch/pull/31175) . The changes will be available in one of our future releases.

In the meantime, assuming my interpretation of your setup is correct, one way to temporarily fix this issue is to configure Ping Federate to sign the SAML Responses (instead of just the SAML Assertions). Please consult your PingFederation configuration on how to do this, [this](https://support.pingidentity.com/Security-implications-for-signing-a-SAML-Response-or-SAML-assertion) seems to suggest that you need to uncheck the "Always sign the SAML Assertion" option in your configuration

\*\* If you have configured Ping Federate to sign responses ( this is apparently the default configuration ) and it still doesn't set the Destination element, then this is something that Ping needs to fix.

---

<div class="post-metadata">

**Author:** ![Indisol](https://avatars.discourse-cdn.com/v4/letter/i/5f8ce5/32.png) [@Indisol](https://discuss.elastic.co/u/Indisol)\
**Post date:** [June 11, 2018, 11:54am UTC](https://discuss.elastic.co/t/kibana-saml-integration-issue/134761/5 "2018-06-11T11:54:25Z")

</div>

Hi Loannis,

thanks for your suggestion. post unchecking the "Always sign the SAML Assertion"option, SAML log-in is happening successfully.

regards,  
Indi

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [July 6, 2018, 6:48am UTC](https://discuss.elastic.co/t/kibana-saml-integration-issue/134761/6 "2018-07-06T06:48:33Z")

</div>

> [@ikakavas](#):
>
> We have identified this behavior as a potential point where our SAML implementation is stricter than it should be and harming interoperability so we addressed it in this [PR](https://github.com/elastic/elasticsearch/pull/31175) . The changes will be available in one of our future releases.

@Indisol , for completeness, the aforementioned fix is now included in 6.3.1 ( see [Release notes](https://www.elastic.co/guide/en/elasticsearch/reference/current/release-notes-6.3.1.html) ), so that means that there will not be any interoperability issues now if you revert your configuration back to signing SAML Assertions.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 3, 2018, 6:58am UTC](https://discuss.elastic.co/t/kibana-saml-integration-issue/134761/7 "2018-08-03T06:58:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
