# Kibana, SAML, Okta - help?

**URL:** <https://discuss.elastic.co/t/kibana-saml-okta-help/178126>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [April 23, 2019, 10:42pm UTC](https://discuss.elastic.co/t/kibana-saml-okta-help/178126 "2019-04-23T22:42:31Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![honzo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/honzo/32/40950_2.png) [@honzo](https://discuss.elastic.co/u/honzo)\
**Post date:** [April 23, 2019, 10:42pm UTC](https://discuss.elastic.co/t/kibana-saml-okta-help/178126/1 "2019-04-23T22:42:31Z")

</div>

Hello,  
I am trying to get our EC Kibana to authenticate with Okta, following the steps in the guide, but not having any luck 😢

Here is the elastic.yml override:

```
xpack:
  security:
    authc:
      realms:
        cloud-saml: 
          type: saml
          order: 2
          attributes.principal: "nameid:persistent"
          idp.metadata.path: "https://p.oktapreview.com/app/xxxxxxxxx/sso/saml/metadata" 
          idp.entity_id: "http://www.okta.com/xxxxxxxxx" 
          sp.entity_id: "https://ac41b26xxx.us-central1.gcp.cloud.es.io:9243/" 
          sp.acs: "https://ac41b2xxx.us-central1.gcp.cloud.es.io:9243/api/security/v1/saml"
          sp.logout: "https://ac41b2xxx.us-central1.gcp.cloud.es.io:9243/logout"

```

and the kibana.yml override:

```
xpack.security.authProviders: [saml]
server.xsrf.whitelist: [/api/security/v1/saml]
xpack.security.public:
  protocol: https
  hostname: ac41b2.us-central1.gcp.cloud.es.io 
  port: 9243

```

Contents of [https://p.oktapreview.com/app/xxxxxxxxx/sso/saml/metadata](https://p.oktapreview.com/app/xxxxxxxxx/sso/saml/metadata) here:

```
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" entityID="http://www.okta.com/xxxxxxxxx">
<md:IDPSSODescriptor WantAuthnRequestsSigned="false" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<md:KeyDescriptor use="signing">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>
MIIDnjCCAoaxxxtaQqO6
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress</md:NameIDFormat>
<md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</md:NameIDFormat>
<md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://p.oktapreview.com/app/pppreview_statssio_1/xxxxxxxxx/sso/saml" />
<md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://p.oktapreview.com/app/pppreview_statssio_1/xxxxxxxxx/sso/saml" />
</md:IDPSSODescriptor>
</md:EntityDescriptor>

```

After removing Basic authProvider completely, our error looks like:

```
{"statusCode":401,"error":"Unauthorized","message":"[security_exception] unable to authenticate user [<unauthenticated-saml-user>] for action [cluster:admin/xpack/security/saml/authenticate], with { header={ WWW-Authenticate={ 0=\"Bearer realm=\\\"security\\\"\" & 1=\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\" } } } :: {\"path\":\"/_xpack/security/saml/authenticate\",\"query\":{},\"body\":\"{\\\"ids\\\":[],\\\"content\\\":\\\"PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48c2FtbDJwOlJlc3BvbnNlIHhtbG5zOnNhbWwycD0idXJuOm9hc2lzOm5hbWVzOnRjOlNBTUw6Mi4wOnByb3RvY29sIiBEZXN0aW5hdGlvbj0iaHR0cHM6Ly9hYzQxYjI2MTc0ZTk0NWE1ODBlNzNkNWZmN2MyZmVkM <snip>
 "}\",\"statusCode\":401,\"response\":\"{\\\"error\\\":{\\\"root_cause\\\":[{\\\"type\\\":\\\"security_exception\\\",\\\"reason\\\":\\\"unable to authenticate user [<unauthenticated-saml-user>] for action [cluster:admin/xpack/security/saml/authenticate]\\\",\\\"header\\\":{\\\"WWW-Authenticate\\\":[\\\"Bearer realm=\\\\\\\"security\\\\\\\"\\\",\\\"Basic realm=\\\\\\\"security\\\\\\\" charset=\\\\\\\"UTF-8\\\\\\\"\\\"]}}],\\\"type\\\":\\\"security_exception\\\",\\\"reason\\\":\\\"unable to authenticate user [<unauthenticated-saml-user>] for action [cluster:admin/xpack/security/saml/authenticate]\\\",\\\"header\\\":{\\\"WWW-Authenticate\\\":[\\\"Bearer realm=\\\\\\\"security\\\\\\\"\\\",\\\"Basic realm=\\\\\\\"security\\\\\\\" charset=\\\\\\\"UTF-8\\\\\\\"\\\"]}},\\\"status\\\":401}\",\"wwwAuthenticateDirective\":\"Bearer realm=\\\"security\\\", Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\"}"}

```

Unfortunately I am not the Okta administrator, but they have been in touch with Okta Support and tell me that the IDP is configured correctly. Elastic Support is telling me "this is not a cloud issue" ☹

Is there a log I can check in the Cloud product that might give me some more insight into what is going wrong?

Thanks for any insight!!

Trevor

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [April 24, 2019, 1:43pm UTC](https://discuss.elastic.co/t/kibana-saml-okta-help/178126/2 "2019-04-24T13:43:08Z")

</div>

Hi @honzo

I think there's still a known issue where we filter security log entries out before providing them to the user console (which used to be fine but now people are configuring their own realms doesn't work so well!)

I see in the unfiltered logs that you have `Authentication to realm cloud-saml failed - Provided SAML response is not valid for realm saml/cloud-saml (Caused by ElasticsearchSecurityException[Conditions [ac41b26xxx...] do not match required audience [https://ac41b26xxx.us-central1.gcp.cloud.es.io:9243/]])`

which I think I've seen before and means that your `sp.entity_id` is ~~wrong~~ inconsistent with what's set in the IDP; if you give me the case id (you mentioned engaging with support?) then I'll go check out what happened over there

Alex

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [April 24, 2019, 1:58pm UTC](https://discuss.elastic.co/t/kibana-saml-okta-help/178126/3 "2019-04-24T13:58:49Z")

</div>

That error appears here: [https://www.elastic.co/guide/en/elastic-stack-overview/current/trb-security-saml.html](https://www.elastic.co/guide/en/elastic-stack-overview/current/trb-security-saml.html) and suggests that your Okta side config needs to contain the `sp.entity_id` somewhere but you have it set to just the cluster id or something like that?

---

<div class="post-metadata">

**Author:** ![honzo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/honzo/32/40950_2.png) [@honzo](https://discuss.elastic.co/u/honzo)\
**Post date:** [April 24, 2019, 3:20pm UTC](https://discuss.elastic.co/t/kibana-saml-okta-help/178126/4 "2019-04-24T15:20:22Z")

</div>

Thanks Alex! The case # is 00320253. I'll double check the `sp.entity_id` asap.

Cheers,  
Trevor

---

<div class="post-metadata">

**Author:** ![honzo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/honzo/32/40950_2.png) [@honzo](https://discuss.elastic.co/u/honzo)\
**Post date:** [April 25, 2019, 9:28pm UTC](https://discuss.elastic.co/t/kibana-saml-okta-help/178126/5 "2019-04-25T21:28:36Z")

</div>

hi @Alex_Piggott, the error you showed us from the log and the FAQ led us to the issue.. indeed `sp.entity_id` was inconsistent in the Okta config.

THANK YOU!! 😀 .. we've been wondering what this was for weeks!

So we are able to login. The email address is displayed as `(No email)` though, and I can't seem to set an attribute for it.. When we try, the error is `“xpack.security.authc.realms.cloud-saml.attributes.mail’: is not allowed”` .. Is that one black-listed for Cloud clusters?

The username is set to the email address if we use `attributes.principal: "nameid:persistent"`, and I may just leave as is. If I can only set one attribute then email address isn't bad, but it would be nice to put some polish on this now.

Best regards,  
Trevor

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [April 25, 2019, 9:44pm UTC](https://discuss.elastic.co/t/kibana-saml-okta-help/178126/6 "2019-04-25T21:44:47Z")

</div>

Glad you got it working!

Despite my good luck in helping you with the initial issue, I'm not a SAML expert by any means .. my suggestion would be to ask in the Kibana forum how to set separate username and email addresses for Kibana\<-\>Okta ... if the answer (which you may already have based on your question?) ends up being to set an attribute that isn't whitelisted (which will probably be a mistake in our whitelist tbh), then you can always open a support ticket asking for it to be set

Alex

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [April 26, 2019, 4:20am UTC](https://discuss.elastic.co/t/kibana-saml-okta-help/178126/7 "2019-04-26T04:20:57Z")

</div>

> [@honzo](#):
>
> When we try, the error is `“xpack.security.authc.realms.cloud-saml.attributes.mail’: is not allowed”` .. Is that one black-listed for Cloud clusters?

The mail attribute is exactly what you want for this.  
It has been blacklisted in cloud (or more accurately, not added to the whitelist), but I can see work in progress to resolve that.

Until then, you'll need to raise a case to add it to your cluster.

---

<div class="post-metadata">

**Author:** ![honzo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/honzo/32/40950_2.png) [@honzo](https://discuss.elastic.co/u/honzo)\
**Post date:** [April 26, 2019, 4:34am UTC](https://discuss.elastic.co/t/kibana-saml-okta-help/178126/8 "2019-04-26T04:34:34Z")

</div>

Fabulous, thanks for the info @TimV ! We'll do just that.

Cheers guys, I think we've finally got this under control. We really appreciate you helping us out here.

Trevor

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 10, 2019, 4:35am UTC](https://discuss.elastic.co/t/kibana-saml-okta-help/178126/9 "2019-05-10T04:35:30Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
