# SAML Issues with Sales Force IPd

**URL:** <https://discuss.elastic.co/t/saml-issues-with-sales-force-ipd/145056>\
**Category:** Elasticsearch\
**Created:** [August 19, 2018, 1:37pm UTC](https://discuss.elastic.co/t/saml-issues-with-sales-force-ipd/145056 "2018-08-19T13:37:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Wayne\_Taylor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wayne_taylor/32/45984_2.png) [@Wayne\_Taylor](https://discuss.elastic.co/u/Wayne_Taylor)\
**Post date:** [August 19, 2018, 1:37pm UTC](https://discuss.elastic.co/t/saml-issues-with-sales-force-ipd/145056/1 "2018-08-19T13:37:39Z")

</div>

Hi there, I am getting the following error when I use [salesforce.com](http://salesforce.com) for SAML:

**Elasticsearch Logs:**

> `[2018-08-19T13:11:37,693][WARN][o.e.x.s.a.AuthenticationService] [MYtrM5v] Authentication to realm saml1 failed - Provided SAML response is not valid for realm saml/saml1 (Caused by ElasticsearchSecurityException[SAML Response is not a 'success' response: Code=urn:oasis:names:tc:SAML:2.0:status:AuthnFailed Message=null Detail=null])`

**My ES Config:**

> xpack.security.enabled: true  
> xpack.security.authc.token.enabled: true  
> xpack.security.http.ssl.enabled: true  
> xpack.security.http.ssl.keystore.path: certs/elastic-certificates.p12  
> xpack.security.http.ssl.truststore.path: certs/elastic-certificates.p12  
> xpack.security.http.ssl.verification\_mode: certificate
> 
> xpack.security.transport.ssl.enabled: true  
> xpack.security.transport.ssl.verification\_mode: certificate  
> xpack.security.transport.ssl.keystore.path: certs/elastic-certificates.p12  
> xpack.security.transport.ssl.truststore.path: certs/elastic-certificates.p12
> 
> xpack.security.authc.realms.saml1:  
> type: saml  
> enabled: true  
> order: 0  
> idp.metadata.path: saml/ipd-external.xml  
> idp.entity\_id: "[https://mydomain.my.salesforce.com](https://mydomain.my.salesforce.com)"  
> sp.entity\_id: "[https://myip:5601](https://myip:5601)"  
> sp.acs: "[https://myip:5601/api/security/v1/saml](https://myip:5601/api/security/v1/saml)"  
> sp.logout: "[https://myip:5601/logout](https://myip:5601/logout)"  
> attributes.principal: "nameid:persistent"

Kibana Logs show nothing.

**Kibana Config:**

> server.host: "0.0.0.0"
> 
> xpack.security.public:  
> protocol: https  
> hostname: 18.212.241.36  
> port: 5601
> 
> server.ssl.enabled: true  
> server.ssl.key: /home/ec2-user/kibana-6.3.2-linux-x86\_64/config/certs/server.key  
> server.ssl.certificate: /home/ec2-user/kibana-6.3.2-linux-x86\_64/config/certs/server.crt
> 
> elasticsearch.url: "[https://localhost:9200](https://localhost:9200)"
> 
> lasticsearch.username: "elastic"  
> elasticsearch.password: "xxx"
> 
> pack.security.authProviders: [saml]  
> server.xsrf.whitelist: [/api/security/v1/saml]

Browser Shows:

> `{"statusCode": 401,"error": "Unauthorized","message": "[security_exception] unable to authenticate user [&lt;unauthenticated-saml-user&gt;] for action [cluster:admin/xpack/security/saml/authenticate], with { header={ WWW-Authenticate=\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\" } } :: {\"path\":\"/_xpack/security/saml/authenticate\",\"query\":{},\"body\":\"{\\\"ids\\\"\",\"statusCode\":401,\"response\":\"{\\\"error\\\":{\\\"root_cause\\\":[{\\\"type\\\":\\\"security_exception\\\",\\\"reason\\\":\\\"unable to authenticate user [&lt;unauthenticated-saml-user&gt;] for action [cluster:admin/xpack/security/saml/authenticate]\\\",\\\"header\\\":{\\\"WWW-Authenticate\\\":\\\"Basic realm=\\\\\\\"security\\\\\\\" charset=\\\\\\\"UTF-8\\\\\\\"\\\"}}],\\\"type\\\":\\\"security_exception\\\",\\\"reason\\\":\\\"unable to authenticate user [&lt;unauthenticated-saml-user&gt;] for action [cluster:admin/xpack/security/saml/authenticate]\\\",\\\"header\\\":{\\\"WWW-Authenticate\\\":\\\"Basic realm=\\\\\\\"security\\\\\\\" charset=\\\\\\\"UTF-8\\\\\\\"\\\"}},\\\"status\\\":401}\",\"wwwAuthenticateDirective\":\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\"}"}`

Any ideas?

Thanks  
Wayne

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [August 19, 2018, 1:52pm UTC](https://discuss.elastic.co/t/saml-issues-with-sales-force-ipd/145056/2 "2018-08-19T13:52:35Z")

</div>

Hi

Your IdP returns a SAML Response saying that your authentication to the IdP has failed

```auto
Response is not a 'success' response: Code=urn:oasis:names:tc:SAML:2.0:status:AuthnFailed Message=null Detail=null])

```

I think you should start from the logs of your IdP in order to figure out what is wrong there.

---

<div class="post-metadata">

**Author:** ![Wayne\_Taylor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wayne_taylor/32/45984_2.png) [@Wayne\_Taylor](https://discuss.elastic.co/u/Wayne_Taylor)\
**Post date:** [August 19, 2018, 2:34pm UTC](https://discuss.elastic.co/t/saml-issues-with-sales-force-ipd/145056/3 "2018-08-19T14:34:27Z")

</div>

Thank you so much. That helped. I had to do a bit of googling for idP logs for sales force. But it informed with the last post that even System Admin doesn't get it by default.

[https://success.salesforce.com/answers?id=90630000000gur9AAA](https://success.salesforce.com/answers?id=90630000000gur9AAA)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 16, 2018, 2:34pm UTC](https://discuss.elastic.co/t/saml-issues-with-sales-force-ipd/145056/4 "2018-09-16T14:34:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
