# SAML Returning 304 Error

**URL:** <https://discuss.elastic.co/t/saml-returning-304-error/264033>\
**Category:** Kibana\
**Created:** [February 11, 2021, 4:01pm UTC](https://discuss.elastic.co/t/saml-returning-304-error/264033 "2021-02-11T16:01:30Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![teej](https://avatars.discourse-cdn.com/v4/letter/t/b5a626/32.png) [@teej](https://discuss.elastic.co/u/teej)\
**Post date:** [February 11, 2021, 4:01pm UTC](https://discuss.elastic.co/t/saml-returning-304-error/264033/1 "2021-02-11T16:01:30Z")

</div>

Hi,  
I have a system currently using AD to authenticate users. Recently, they've asked for SAML to be used as a primary realm. Problem is when I try to bring up Kibana I get "Error 403 - Forbidden". The logs show:

> {"type":"error","@timestamp":"2021-02-11T14:41:30Z","tags":["connection","client","error"],"pid":3218,"level":"error","error":{"message":"140282498721664:error:14094416:SSL routines:ssl3\_read\_bytes:sslv3 alert certificate unknown:../deps/openssl/openssl/ssl/record/rec\_layer\_s3.c:1544:SSL alert number 46\n","name":"Error","stack":"Error: 140282498721664:error:14094416:SSL routines:ssl3\_read\_bytes:sslv3 alert certificate unknown:../deps/openssl/openssl/ssl/record/rec\_layer\_s3.c:1544:SSL alert number 46\n"},"message":"140282498721664:error:14094416:SSL routines:ssl3\_read\_bytes:sslv3 alert certificate unknown:../deps/openssl/openssl/ssl/record/rec\_layer\_s3.c:1544:SSL alert number 46\n"}
> 
> {"type":"log","@timestamp":"2021-02-11T14:41:30Z","tags":["debug","http","server","Kibana","cookie-session-storage"],"pid":3218,"message":"Error: Unauthorized"}  
> {"type":"log","@timestamp":"2021-02-11T14:41:30Z","tags":["debug","plugins","security","saml"],"pid":3218,"message":"Trying to authenticate user request to /internal/security/me."}  
> {"type":"log","@timestamp":"2021-02-11T14:41:30Z","tags":["debug","plugins","security","saml"],"pid":3218,"message":"Trying to authenticate via header."}  
> {"type":"log","@timestamp":"2021-02-11T14:41:30Z","tags":["debug","plugins","security","saml"],"pid":3218,"message":"Authorization header is not presented."}  
> {"type":"log","@timestamp":"2021-02-11T14:41:30Z","tags":["debug","plugins","security","authentication"],"pid":3218,"message":"Could not handle authentication attempt"}

It seems a little cryptic to me only because the certs all work fine for both AD and other XPACK related applications such as 9300 traffic and such.

---

<div class="post-metadata">

**Author:** ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)\
**Post date:** [February 11, 2021, 11:53pm UTC](https://discuss.elastic.co/t/saml-returning-304-error/264033/2 "2021-02-11T23:53:52Z")

</div>

Hi @teej.

This error usually indicates that your [browser does not trust the certificate](https://github.com/elastic/kibana/issues/35004).

Here are a couple of links that might help out.

> **[Andrew Connell - Updated: Creating and Trusting Self-Signed Certs on MacOS...](https://www.andrewconnell.com/blog/updated-creating-and-trusting-self-signed-certs-on-macos-and-chrome)**
>
> A few years ago I write a post Setup Self-Signed Certificates & Trusting them on OS X.

> **[How to add a trusted CA certificate to Chrome and Firefox](https://www.techrepublic.com/article/how-to-add-a-trusted-certificate-authority-certificate-to-chrome-and-firefox/)**
>
> This detailed walk-through explains a variety of approaches to adding a trusted certificate authority to the Chrome and Firefox browsers.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 11, 2021, 11:54pm UTC](https://discuss.elastic.co/t/saml-returning-304-error/264033/3 "2021-03-11T23:54:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
