The complete roles list : CN=udspzzzp01_pki_admin,OU=resources,OU=udspzzzp01,OU=tenants,DC=msad,DC=udsp,DC=ch,CN=udspzzzp01_zenoss_admin,CN=udspzzzp01_role_platform,OU=roles,1
Do you want for a user with all these roles in your IDP to get the superuser role in Elasticsearch, or a user with any of these roles in your IDP to get the superuser role in Elasticsearch?
You need to
a) Figure out what SAML attribute is the SAML IDP using to send that group/role in the SAML Response message. You can ask your IDP administrator or you can enable TRACE logging for SAML ( see how here on the bottom of the page ) and look at your elasticsearch logs.
b) Figure out the actual value that this group/role has. CN=udspzzzp01_role_platform is not a complete DN so it's not likely that this is the value that the IDP is sending. Again, you can ask your IDP administrator or you can enable TRACE logging for SAML in elasticsearch.
c) Let's say you figured out that the IDP is sending this information in an attribute named TheRoleAttribute and the value of the group is CN=udspzzzp01_role_platform,OU=resources,OU=udspzzzp01,OU=tenants,DC=msad,DC=udsp,DC=ch
In your elasticsearch.yml, you need to set
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.