# Likely root cause: ElasticsearchSecurityException\[Cannot find metadata for entity http://xxx.xxx.xx\]

**URL:** <https://discuss.elastic.co/t/likely-root-cause-elasticsearchsecurityexception-cannot-find-metadata-for-entity-http-xxx-xxx-xx/288639>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [November 8, 2021, 2:32pm UTC](https://discuss.elastic.co/t/likely-root-cause-elasticsearchsecurityexception-cannot-find-metadata-for-entity-http-xxx-xxx-xx/288639 "2021-11-08T14:32:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![slashlinux](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/slashlinux/32/79430_2.png) [@slashlinux](https://discuss.elastic.co/u/slashlinux)\
**Post date:** [November 8, 2021, 2:32pm UTC](https://discuss.elastic.co/t/likely-root-cause-elasticsearchsecurityexception-cannot-find-metadata-for-entity-http-xxx-xxx-xx/288639/1 "2021-11-08T14:32:48Z")

</div>

Hello,

I'm trying to integrate ELK with Keycloak and I've encountered some problems, I'm not expert on elk side so I did some configuration on Kibana/Elasticsearch YML:

**Elasticsearch.yml**

```auto
xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.http.ssl.enabled: true
xpack.security.authc.token.enabled: true
xpack.security.authc.realms:
  saml.saml1:
    order: 2
    idp.metadata.path: saml-elasticsearch-metadata.xml
    idp.entity_id: "http://192.168.XXX.XX1:8080/auth/realms/grafana/protocol/saml"
    sp.entity_id: "http://192.168.XXX.XX2:5601/"
    sp.acs: "http://192.168.XXX.XX:56012/api/security/v1/saml"
    sp.logout: "http://192.168.XXX.XX2:5601/logout"
    attributes.principal: "nameid:persistent"

```

**kibana.yml**

```auto
xpack.security.authc.providers: [saml]
xpack.security.authc.saml.realm: saml1
server.xsrf.whitelist: [/api/security/v1/saml]
xpack.security.enabled: true

```

**Log error Elasticsearch:**

```auto
Nov 08 09:30:25 localhost.localdomain systemd[1]: Starting Elasticsearch...
Nov 08 09:30:29 localhost.localdomain systemd-entrypoint[9048]: WARNING: A terminally deprecated method in java.lang.System has been called
Nov 08 09:30:29 localhost.localdomain systemd-entrypoint[9048]: WARNING: System::setSecurityManager has been called by org.elasticsearch.bootstrap.Elasticsearch (file:/usr/share/elasticsearch/lib/elasticsearch-
Nov 08 09:30:29 localhost.localdomain systemd-entrypoint[9048]: WARNING: Please consider reporting this to the maintainers of org.elasticsearch.bootstrap.Elasticsearch
Nov 08 09:30:29 localhost.localdomain systemd-entrypoint[9048]: WARNING: System::setSecurityManager will be removed in a future release
Nov 08 09:30:31 localhost.localdomain systemd-entrypoint[9048]: WARNING: A terminally deprecated method in java.lang.System has been called
Nov 08 09:30:31 localhost.localdomain systemd-entrypoint[9048]: WARNING: System::setSecurityManager has been called by org.elasticsearch.bootstrap.Security (file:/usr/share/elasticsearch/lib/elasticsearch-7.15.
Nov 08 09:30:31 localhost.localdomain systemd-entrypoint[9048]: WARNING: Please consider reporting this to the maintainers of org.elasticsearch.bootstrap.Security
Nov 08 09:30:31 localhost.localdomain systemd-entrypoint[9048]: WARNING: System::setSecurityManager will be removed in a future release
Nov 08 09:30:45 localhost.localdomain systemd-entrypoint[9048]: uncaught exception in thread [main]
Nov 08 09:30:45 localhost.localdomain systemd-entrypoint[9048]: java.lang.IllegalStateException: security initialization failed
Nov 08 09:30:45 localhost.localdomain systemd-entrypoint[9048]: Likely root cause: ElasticsearchSecurityException[Cannot find metadata for entity [http://192.168.xxx.xx1:8080/auth/realms/grafana/protocol/saml] 
Nov 08 09:30:45 localhost.localdomain systemd-entrypoint[9048]: at org.elasticsearch.xpack.security.authc.saml.SamlUtils.samlException(SamlUtils.java:106)
Nov 08 09:30:45 localhost.localdomain systemd-entrypoint[9048]: at org.elasticsearch.xpack.security.authc.saml.SamlRealm.resolveEntityDescriptor(SamlRealm.java:630)

```

I have generated metadata for **realm = saml1** with below command:

```auto
[root@localhost elasticsearch]# bin/elasticsearch-saml-metadata --realm saml1
What is the friendly name for "principal" attribute "nameid:persistent" [default: principa

```

Thank you for your help

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [November 8, 2021, 11:57pm UTC](https://discuss.elastic.co/t/likely-root-cause-elasticsearchsecurityexception-cannot-find-metadata-for-entity-http-xxx-xxx-xx/288639/2 "2021-11-08T23:57:50Z")

</div>

The error means the entityID `http://192.168.XXX.XX1:8080/auth/realms/grafana/protocol/saml` is not found in the file `saml-elasticsearch-metadata.xml`.

Quote from the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/saml-guide-stack.html#saml-create-realm):

> `idp.metadata.path` is the path to the metadata file that you saved for your Identity Provider. The path that you enter here is relative to your `config/` directory. Elasticsearch will automatically monitor this file for changes and will reload the configuration whenever it is updated.

The file should be provided by your idP, not generated by elasticsearch. The `elasticsearch-saml-metadata` is for generating the SP metadata and upload to your idP if necessary and it is not relevant to your current error.

---

<div class="post-metadata">

**Author:** ![slashlinux](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/slashlinux/32/79430_2.png) [@slashlinux](https://discuss.elastic.co/u/slashlinux)\
**Post date:** [November 9, 2021, 7:13am UTC](https://discuss.elastic.co/t/likely-root-cause-elasticsearchsecurityexception-cannot-find-metadata-for-entity-http-xxx-xxx-xx/288639/3 "2021-11-09T07:13:45Z")

</div>

Thank you, I've copied the idp-metadata from the Keycloak Realm and now it works.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 7, 2021, 7:14am UTC](https://discuss.elastic.co/t/likely-root-cause-elasticsearchsecurityexception-cannot-find-metadata-for-entity-http-xxx-xxx-xx/288639/4 "2021-12-07T07:14:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
