# SAML response state does not have corresponding request id

**URL:** <https://discuss.elastic.co/t/saml-response-state-does-not-have-corresponding-request-id/233372>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 19, 2020, 4:11pm UTC](https://discuss.elastic.co/t/saml-response-state-does-not-have-corresponding-request-id/233372 "2020-05-19T16:11:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jesse\_Bye](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jesse_bye/32/67532_2.png) [@Jesse\_Bye](https://discuss.elastic.co/u/Jesse_Bye)\
**Post date:** [May 19, 2020, 4:11pm UTC](https://discuss.elastic.co/t/saml-response-state-does-not-have-corresponding-request-id/233372/1 "2020-05-19T16:11:19Z")

</div>

We have SAML auth configured for 3 of our ES clusters. When SSO'ing to Kibana, we sometimes get a 401 "access token expired" error. Retrying the SSO will give us a different 401, "SAML response state does not have corresponding request id."

Any further attempts to SSO will give us the same error. The only workaround we have found is to clear cookies for the `found.io` domain. After clearing cookies, SSO works normally.

This happens every couple days for each of our clusters. Is there a problem with our configuration that is causing this? How do we resolve it?

In case it is useful, here is the full text of the first error message:  
`{"statusCode":401,"error":"Unauthorized","message":"[security_exception] token expired, with { header={ WWW-Authenticate=\"Bearer realm=\\\"security\\\", error=\\\"invalid_token\\\", error_description=\\\"The access token expired\\\"\" } }"}`

And the second error message:  
`{"statusCode":401,"error":"Unauthorized","message":"SAML response state does not have corresponding request id."}`

The relevant ES configuration:  
`xpack.security.authc.realms.saml.saml1:`  
`order: 2`  
`idp.metadata.path: "https://portal.sso.us-east-2.amazonaws.com/saml/metadata/[REDACTED]"`  
`idp.entity_id: "https://portal.sso.us-east-2.amazonaws.com/saml/assertion/[REDACTED]"`  
`sp.entity_id: "https://[REDACTED].us-east-1.aws.found.io/"`  
`sp.acs: "https://[REDACTED].us-east-1.aws.found.io/api/security/v1/saml"`  
`sp.logout: "https://[REDACTED].us-east-1.aws.found.io/logout"`  
`attributes.principal: "nameid"`

And the relevant Kibana configuration:  
`xpack.security.authc.providers: [saml, basic]`  
`server.xsrf.whitelist: [/api/security/v1/saml]`  
`xpack.security.authc.saml.realm: saml1`

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 20, 2020, 8:39am UTC](https://discuss.elastic.co/t/saml-response-state-does-not-have-corresponding-request-id/233372/2 "2020-05-20T08:39:40Z")

</div>

What version are you on @Jesse_Bye? This

> When SSO'ing to Kibana, we sometimes get a 401 "access token expired" error.

sounds like [Properly handle SAML IdP initiated login with existing session containing expired access token · Issue #59629 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/59629) that we resolved recently and will be released in the next version. But refreshing the page should have resolved the issue when you come across it, not lead to the next error you're seeing.

If you can open a support ticket so that you can share your debug kibana logs and the elasticsearch trace logs for SAML , we will be able to give you a more qualified RCA.

---

<div class="post-metadata">

**Author:** ![Jesse\_Bye](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jesse_bye/32/67532_2.png) [@Jesse\_Bye](https://discuss.elastic.co/u/Jesse_Bye)\
**Post date:** [May 20, 2020, 3:26pm UTC](https://discuss.elastic.co/t/saml-response-state-does-not-have-corresponding-request-id/233372/3 "2020-05-20T15:26:32Z")

</div>

Hmm, that does seem similar to our problem, except refreshing doesn't resolve it. We're on v7.7.0; should it be fixed on that version? Or only v7.7.1 and greater?

Also, I tried creating a support ticket for this before and they redirected me here 🙂

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 20, 2020, 4:03pm UTC](https://discuss.elastic.co/t/saml-response-state-does-not-have-corresponding-request-id/233372/4 "2020-05-20T16:03:58Z")

</div>

> [@Jesse\_Bye](#):
>
> Also, I tried creating a support ticket for this before and they redirected me here

Apologies for that @Jesse_Bye, I wasn't aware that you had already gone via support.

> [@Jesse\_Bye](#):
>
> We're on v7.7.0; should it be fixed on that version?

We just merged the fixes after 7.7.0 was releases so this fix should be available in the next minor or patch release that is released

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 17, 2020, 4:04pm UTC](https://discuss.elastic.co/t/saml-response-state-does-not-have-corresponding-request-id/233372/5 "2020-06-17T16:04:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
