# SAML in Elastic Cloud - Support cant fix and are saying its Consulting now!

**URL:** <https://discuss.elastic.co/t/saml-in-elastic-cloud-support-cant-fix-and-are-saying-its-consulting-now/158805>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [November 29, 2018, 6:03pm UTC](https://discuss.elastic.co/t/saml-in-elastic-cloud-support-cant-fix-and-are-saying-its-consulting-now/158805 "2018-11-29T18:03:50Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![hogbinj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hogbinj/32/14744_2.png) [@hogbinj](https://discuss.elastic.co/u/hogbinj)\
**Post date:** [November 29, 2018, 6:03pm UTC](https://discuss.elastic.co/t/saml-in-elastic-cloud-support-cant-fix-and-are-saying-its-consulting-now/158805/1 "2018-11-29T18:03:50Z")

</div>

I've tried to implement the advice [here on securing a Cloud Cluster with SAML](https://www.elastic.co/guide/en/cloud/current/ec-securing-clusters-SAML.html)

I added the following to the elasticsearch.yml being careful to use spaces rather than the tabs you get if you copy the example because YAML

_There are spaces but the editor removes them in blockquotes_

> xpack.security:  
> authc:  
> realms:  
> cloud-saml:  
> type: saml  
> order: 2  
> attributes.principal: "nameid:persistent"  
> attributes.groups: "groups"  
> idp.metadata.path: "[https://app.onelogin.com/saml/metadata/[UUID]](https://app.onelogin.com/saml/metadata/%5BUUID%5D)"  
> idp.entity\_id: "[https://ip-sentinel.onelogin.com/trust/saml2/http-post/sso/865524](https://ip-sentinel.onelogin.com/trust/saml2/http-post/sso/865524)"  
> sp.entity\_id: "https:/[UUID].europe-west1.gcp.cloud.es.io:9243/"  
> sp.acs: "https://[UUID].europe-west1.gcp.cloud.es.io:9243/api/security/v1/saml"  
> sp.logout: "https://[UUID].europe-west1.gcp.cloud.es.io:9243/logout"

That didn't deploy with error \> xpack is not allowed.

I also noticed the editor turns 4 x spaces into tabs so maybe that was the error anyway

I contacted support and they suggested I expand the YAML keys and it would work so I did

> xpack.security.authc.realms.cloud-saml.type: saml  
> xpack.security.authc.realms.cloud-saml.order: 2  
> xpack.security.authc.realms.cloud-saml.attributes.principal: "nameid:persistent"  
> xpack.security.authc.realms.cloud-saml.attributes.groups: "groups"  
> xpack.security.authc.realms.cloud-saml.idp.metadata.path: "[https://app.onelogin.com/saml/metadata/[UUID]](https://app.onelogin.com/saml/metadata/%5BUUID%5D)"  
> xpack.security.authc.realms.cloud-saml.idp.entity\_id: "[https://ip-sentinel.onelogin.com/trust/saml2/http-post/sso/865524](https://ip-sentinel.onelogin.com/trust/saml2/http-post/sso/865524)"  
> xpack.security.authc.realms.cloud-saml.sp.entity\_id: "https://[UUID].europe-west1.gcp.cloud.es.io:9243/"  
> xpack.security.authc.realms.cloud-saml.sp.acs: "https://[UUID].europe-west1.gcp.cloud.es.io:9243/api/security/v1/saml"  
> xpack.security.authc.realms.cloud-saml.sp.logout: "https://[UUID].europe-west1.gcp.cloud.es.io:9243/logout"

That didn't work either.

Elastic support are now saying this is NOT support but consulting!!!!

Has anybody got this to work at all? Am I doing something obviously dim?

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [November 30, 2018, 12:45pm UTC](https://discuss.elastic.co/t/saml-in-elastic-cloud-support-cant-fix-and-are-saying-its-consulting-now/158805/2 "2018-11-30T12:45:49Z")

</div>

The `idp.entity_id` in your realm config needs to match the `entityID` in the metadata file.

For more information, refer to `Item 2` in [Common SAML issues | Elasticsearch Guide [6.5] | Elastic](https://www.elastic.co/guide/en/elastic-stack-overview/6.5/trb-security-saml.html)

> Cannot find metadata for entity [your:entity.id] in [metadata.xml]

Best

---

<div class="post-metadata">

**Author:** ![dweidenfeld](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dweidenfeld/32/38345_2.png) [@dweidenfeld](https://discuss.elastic.co/u/dweidenfeld)\
**Post date:** [December 3, 2018, 9:42am UTC](https://discuss.elastic.co/t/saml-in-elastic-cloud-support-cant-fix-and-are-saying-its-consulting-now/158805/3 "2018-12-03T09:42:07Z")

</div>

I am having the same issue right now.  
Is there already a solution for this, or do I have to contact the support as well?

cheers

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [December 3, 2018, 10:06am UTC](https://discuss.elastic.co/t/saml-in-elastic-cloud-support-cant-fix-and-are-saying-its-consulting-now/158805/4 "2018-12-03T10:06:02Z")

</div>

> [@dweidenfeld](#):
>
> I am having the same issue right now.

Hello Dominic,

Please open your own topic and share as much information as possible with details on what you have done, what is your current configuration and what is the error message that you are seeing. There is no bug we are aware of that needs to be resolved, this is apparently a configuration error.

---

<div class="post-metadata">

**Author:** ![hogbinj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hogbinj/32/14744_2.png) [@hogbinj](https://discuss.elastic.co/u/hogbinj)\
**Post date:** [December 3, 2018, 10:13am UTC](https://discuss.elastic.co/t/saml-in-elastic-cloud-support-cant-fix-and-are-saying-its-consulting-now/158805/5 "2018-12-03T10:13:22Z")

</div>

So...

A couple of things.

1. use the full path for the item you are configuring e.g.

> \<xpack.security.authc.realms.cloud-saml.type: saml  
> \<xpack.security.authc.realms.cloud-saml.order: 2  
> \<xpack.security.authc.realms.cloud-saml.attributes.principal: "nameid:persistent"  
> \<xpack.security.authc.realms.cloud-saml.attributes.groups: "groups"  
> \<xpack.security.authc.realms.cloud-saml.idp.metadata.path: "[https://app.onelogin.com/saml/metadata/[uuid]](https://app.onelogin.com/saml/metadata/%5Buuid%5D)"  
> \<xpack.security.authc.realms.cloud-saml.idp.entity\_id: "[https://app.onelogin.com/saml/metadata/[uuid]](https://app.onelogin.com/saml/metadata/%5Buuid%5D)"  
> \<xpack.security.authc.realms.cloud-saml.sp.entity\_id: "https://[uuid].europe-west1.gcp.cloud.es.io:9243/"  
> \<xpack.security.authc.realms.cloud-saml.sp.acs: "https://[uuid].europe-west1.gcp.cloud.es.io:9243/api/security/v1/saml"  
> \<xpack.security.authc.realms.cloud-saml.sp.logout: "https://[uuid][4.europe-west1.gcp.cloud.es.io:9243/logout](http://4.europe-west1.gcp.cloud.es.io:9243/logout)"

1. The xpack.security.authc.realms.cloud-saml.idp.entity.id needs to have the same value found in the html headers of the xpack.security.authc.realms.cloud-saml.idp.metadata.path: key

Browse to the metadata.path url and then view source. You should get something like...

> \<?xml version="1.0"?\>  
> \<EntityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" entityID="**[https://app.onelogin.com/saml/metadata/[UUID]](https://app.onelogin.com/saml/metadata/%5BUUID%5D)**"\>  
> \<IDPSSODescriptor xmlns:ds="[XML-Signature Syntax and Processing](http://www.w3.org/2000/09/xmldsig#)" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"\>  
> \<KeyDescriptor use="signing"\>  
> \<ds:KeyInfo xmlns:ds="[XML-Signature Syntax and Processing](http://www.w3.org/2000/09/xmldsig#)"\>  
> \<ds:X509Data\> ... ...

In my case both the entity\_id and the metadata\_path are the same.

---

<div class="post-metadata">

**Author:** ![hogbinj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hogbinj/32/14744_2.png) [@hogbinj](https://discuss.elastic.co/u/hogbinj)\
**Post date:** [December 3, 2018, 10:31am UTC](https://discuss.elastic.co/t/saml-in-elastic-cloud-support-cant-fix-and-are-saying-its-consulting-now/158805/6 "2018-12-03T10:31:25Z")

</div>

Also the key:

> xpack.security.authc.realms.cloud-saml.attributes.principal: "nameid:persistent"

means you need to use a NameID (persistent) app

 ![onelogon%20SAML%20persistent%20](https://us1.discourse-cdn.com/elastic/original/3X/7/8/78b53fe54436f5f4aca078fa4e53af72f51187f2.png)

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [December 3, 2018, 1:57pm UTC](https://discuss.elastic.co/t/saml-in-elastic-cloud-support-cant-fix-and-are-saying-its-consulting-now/158805/7 "2018-12-03T13:57:32Z")

</div>

A few comments in case this is helpful to others:

> [@hogbinj](#):
>
> 1. The xpack.security.authc.realms.cloud-saml.idp.entity.id needs to have the same value found in the html headers of the xpack.security.authc.realms.cloud-saml.idp.metadata.path: key

The `xpack.security.authc.realms.cloud-saml.idp.entity_id` configuration parameter needs to be the same as the Entity ID of the SAML IdP you are using. One way to figure this out is to look at the metadata, as @hogbinj suggests or look at the configuration pages of your IdP . Most have this shown in a prominent place in their UI or config.

> [@hogbinj](#):
>
> Also the key:
> 
> > xpack.security.authc.realms.cloud-saml.attributes.principal: "nameid:persistent"
> 
> means you need to use a NameID (persistent) app

This is actually the other way around. If your Identity Provider sets the SAML2 Name ID with a persistent format, or if you configure it to do so ( as @hogbinj is showing in his previous post ) then you need to configure Elasticsearch to read the value as such by setting:

```auto
xpack.security.authc.realms.cloud-saml.attributes.principal: "nameid:persistent"

```

For detailed information on what this parameter is and what are other potential values, you can [go through our documentation](https://www.elastic.co/guide/en/elastic-stack-overview/6.5/saml-guide-authentication.html#_special_attribute_names)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 31, 2018, 1:57pm UTC](https://discuss.elastic.co/t/saml-in-elastic-cloud-support-cant-fix-and-are-saying-its-consulting-now/158805/8 "2018-12-31T13:57:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
