# SAML Authentication unknown secure setting

**URL:** <https://discuss.elastic.co/t/saml-authentication-unknown-secure-setting/140213>\
**Category:** Elasticsearch\
**Created:** [July 16, 2018, 8:25pm UTC](https://discuss.elastic.co/t/saml-authentication-unknown-secure-setting/140213 "2018-07-16T20:25:29Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![DaveyDevOps](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daveydevops/32/57124_2.png) [@DaveyDevOps](https://discuss.elastic.co/u/DaveyDevOps)\
**Post date:** [July 16, 2018, 8:25pm UTC](https://discuss.elastic.co/t/saml-authentication-unknown-secure-setting/140213/1 "2018-07-16T20:25:30Z")

</div>

Elasticsearch 6.3.1

Got SAML authentication up and running, final steps were to set up signing and encryption with the IdP.

Following [guide](https://www.elastic.co/guide/en/elastic-stack-overview/6.3/saml-guide-authentication.html) and wanted to use JKS. Updated the realm setting in elasticsearch.yml and the secure settings in the elasticsearch keystore however was with met with errors and a failed startup.

```
java.lang.IllegalArgumentException: unknown secure setting [encryption.keystore.secure_password] did you mean [xpack.ssl.keystore.secure_password]?
java.lang.IllegalArgumentException: unknown secure setting [signing.keystore.secure_password] did you mean [xpack.ssl.keystore.secure_password]?

```

Did some digging around and looks like need to set the secure settings like in the [tests](https://github.com/elastic/elasticsearch/blob/b2e48c9fa7b67cb7bbea0d72500332baa2459b92/x-pack/plugin/security/src/test/java/org/elasticsearch/xpack/security/authc/saml/SamlRealmTests.java#L84) with the full realm setting prefix.

```
xpack.security.authc.realms.realmname.signing.keystore.secure_password
xpack.security.authc.realms.realmname.encryption.keystore.secure_password

```

Perhaps the guide/documentation could be updated to make this easier to understand.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [July 17, 2018, 8:49pm UTC](https://discuss.elastic.co/t/saml-authentication-unknown-secure-setting/140213/2 "2018-07-17T20:49:17Z")

</div>

Hi David ,

Thanks for your feedback. As you can see in every place in the guide you refer to, all settings are discussed relevant to `xpack.security.authc.realms.saml1` . So when we for instance discuss

> _idp.entity\_id_  
> This is the identifier (SAML EntityID) that your IdP uses. It should match the entityID attribute within the  
> metadata file.

`idp_entity_id` goes under `xpack.security.authc.realms.saml1`, either as

`xpack.security.authc.realms.saml1.idp_entity_id: value`

or

```auto
xpack.security.authc.realms.saml1:
    idp_entity_id: value

```

The same applies to the [signing settings](https://www.elastic.co/guide/en/elastic-stack-overview/6.3/saml-guide-authentication.html#_configuring_elasticsearch_for_signing)

That said, we will look into how this could be made more clear in our documentation and the guide.

Thanks again

---

<div class="post-metadata">

**Author:** ![DaveyDevOps](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daveydevops/32/57124_2.png) [@DaveyDevOps](https://discuss.elastic.co/u/DaveyDevOps)\
**Post date:** [July 18, 2018, 9:01pm UTC](https://discuss.elastic.co/t/saml-authentication-unknown-secure-setting/140213/3 "2018-07-18T21:01:01Z")

</div>

Thanks for the response. It is easy to follow along and configure the .yml  
But the secure setting that needs to be set with the command-line tool is where it gets a bit unclear.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 15, 2018, 9:01pm UTC](https://discuss.elastic.co/t/saml-authentication-unknown-secure-setting/140213/4 "2018-08-15T21:01:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
