I am now trying to test the ELK do auth using SAML. the basic flow is ok since i may follow the documentation. But i think that one of the case is not fit. i would like to use ELK as SP and connect to a IDP proxy and forward to request the real IDP. But i find that there is no configuration in Elasticsearch so that i may create the tag in saml authnrequest xml. So i cannot use the IDP approach. Any idea on that?
One of the criteria on setting up IDP proxy is that the SP (that mean ELK) need to enable the IDP proxy in the authrequest. But Elasticsearch.yaml don't have this configuration.
So the request for a IDP proxy support then should be :
Thanks for the additional details ! We unfortunately don’t support this as you have figured out. I see you have opened an issue in our GitHub repository so you can keep track of the progress there.
One more question, i will trying to setup the SSO connection using ELK (version 8) with OpenAM. i find that the NameID policy : "urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified" is never work. Only other nameid policy is working. Is it Elasticsearch don't allow ?
This is hardly enough information for anyone to help you. Can you please explain how it does not work with this nameid policy ? What do you expect to happen, what happens instead ? What is the error message ? What are the associated logs ?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.