# Okta Integration with elasticsearch

**URL:** <https://discuss.elastic.co/t/okta-integration-with-elasticsearch/233213>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 18, 2020, 10:44pm UTC](https://discuss.elastic.co/t/okta-integration-with-elasticsearch/233213 "2020-05-18T22:44:30Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gauti](https://avatars.discourse-cdn.com/v4/letter/g/cdc98d/32.png) [@Gauti](https://discuss.elastic.co/u/Gauti)\
**Post date:** [May 18, 2020, 10:44pm UTC](https://discuss.elastic.co/t/okta-integration-with-elasticsearch/233213/1 "2020-05-18T22:44:30Z")

</div>

Hi All,

I'm trying to integrate Okta with elasticsearch in our environment, have configured all the details as per documentation.  
Now when i hit the kibana url its taking me to Okta page, after entering the credentials the url is redirecting to elasticsearch url with a failure message,

Screenshot FYI..  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/9/e98779261dd0837dfec19ea0e83309093bdaa3c7.png)

Here is my elasticsearch.yml

```
xpack.security.authc.realms.saml.iff-saml:
   order: 2
   idp.metadata.path: "/etc/elasticsearch/metadata.xml"
   idp.entity_id: "http://www.okta.com/fytnbvn06sa05"
   sp.entity_id: "http://1.3.5.1:5601/"
   sp.acs: "http://1.5.5.1:5601/api/security/v1/saml"
   sp.logout: "http://1.3.5.1:5601/logout"
   attributes.principal: "nameid"
   attributes.groups: "groups"

```

This is an on-premise setup with version 7.6.2

I'm not sure where is the mistake...Please advice...

Thanks  
Gautham

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 19, 2020, 11:43am UTC](https://discuss.elastic.co/t/okta-integration-with-elasticsearch/233213/2 "2020-05-19T11:43:15Z")

</div>

It looks like you have configured okta to redirect you back to Elasticsearch ( you are in `http://something:*9200*`) instead of kibana. Check your OKTA settings (i.e **Single sign on URL** if I remember correctly, this should match the value you have in `sp.acs` )

---

<div class="post-metadata">

**Author:** ![Gauti](https://avatars.discourse-cdn.com/v4/letter/g/cdc98d/32.png) [@Gauti](https://discuss.elastic.co/u/Gauti)\
**Post date:** [May 19, 2020, 12:10pm UTC](https://discuss.elastic.co/t/okta-integration-with-elasticsearch/233213/3 "2020-05-19T12:10:44Z")

</div>

@ikakavas while giving details to okta team i have given details like

Singel Signon URL : [http://elasticsearch:9200/api/security/v1/saml](http://elasticsearch:9200/api/security/v1/saml)

and Audience URI(SP Entity ID) : [http://kibana:5601](http://kibana:5601)

You mean to say i need to give single sign on and sp entity id both as kibana URL?

Thanks  
Gautham

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 19, 2020, 12:24pm UTC](https://discuss.elastic.co/t/okta-integration-with-elasticsearch/233213/4 "2020-05-19T12:24:43Z")

</div>

> [@Gauti](#):
>
> You mean to say i need to give single sign on and sp entity id both as kibana URL?

I mean you need to set `Single Signon URL` to the same value as you've set `sp.acs` and you need to set `Audience URI(SP Entity ID)` to the same value as you've set `sp.entity_id`. And these need to point to Kibana, as [described in detail in our documentation](https://www.elastic.co/guide/en/elasticsearch/reference/7.6/saml-guide-authentication.html)

---

<div class="post-metadata">

**Author:** ![Gauti](https://avatars.discourse-cdn.com/v4/letter/g/cdc98d/32.png) [@Gauti](https://discuss.elastic.co/u/Gauti)\
**Post date:** [May 19, 2020, 2:41pm UTC](https://discuss.elastic.co/t/okta-integration-with-elasticsearch/233213/5 "2020-05-19T14:41:12Z")

</div>

Awesome @ikakavas it worked. Thank you very much.

Thanks  
Gautham

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 16, 2020, 2:54pm UTC](https://discuss.elastic.co/t/okta-integration-with-elasticsearch/233213/6 "2020-06-16T14:54:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
