# SAML role mapping with wildcard

**URL:** <https://discuss.elastic.co/t/saml-role-mapping-with-wildcard/233107>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 18, 2020, 12:54pm UTC](https://discuss.elastic.co/t/saml-role-mapping-with-wildcard/233107 "2020-05-18T12:54:41Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![raphperrin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raphperrin/32/51129_2.png) [@raphperrin](https://discuss.elastic.co/u/raphperrin)\
**Post date:** [May 18, 2020, 12:54pm UTC](https://discuss.elastic.co/t/saml-role-mapping-with-wildcard/233107/1 "2020-05-18T12:54:41Z")

</div>

Hi

I am configuring role mapping on my cluster. As the user has multiple roles/groupes, I am trying to map the role with wildcard. How should I do it ?

From the API :

> POST /\_xpack/security/role\_mapping/plateform-admin  
> {  
> "roles": ["superuser"],  
> "enabled": true,  
> "rules": { "all": [  
> { "field": { "realm.name": "samlprod" } },  
> { "field": { "roles": "\*CN=udspzzzp01\_role\_platform\*" } }  
> ] }  
> }

The complete roles list :  
`CN=udspzzzp01_pki_admin,OU=resources,OU=udspzzzp01,OU=tenants,DC=msad,DC=udsp,DC=ch,CN=udspzzzp01_zenoss_admin,CN=udspzzzp01_role_platform,OU=roles,1`

Thanks a lot  
Raphael

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 18, 2020, 4:07pm UTC](https://discuss.elastic.co/t/saml-role-mapping-with-wildcard/233107/2 "2020-05-18T16:07:04Z")

</div>

Do you want for a user with _all_ these roles in your IDP to get the `superuser` role in Elasticsearch, or a user with _any_ of these roles in your IDP to get the `superuser` role in Elasticsearch?

---

<div class="post-metadata">

**Author:** ![raphperrin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raphperrin/32/51129_2.png) [@raphperrin](https://discuss.elastic.co/u/raphperrin)\
**Post date:** [May 18, 2020, 7:11pm UTC](https://discuss.elastic.co/t/saml-role-mapping-with-wildcard/233107/3 "2020-05-18T19:11:47Z")

</div>

Hi  
In my case, I want user with the IDP role :  
CN=udspzzzp01\_role\_platform

To have superuser role in Elastic.

Thanks

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 18, 2020, 8:56pm UTC](https://discuss.elastic.co/t/saml-role-mapping-with-wildcard/233107/4 "2020-05-18T20:56:59Z")

</div>

You need to  
a) Figure out what SAML attribute is the SAML IDP using to send that group/role in the SAML Response message. You can ask your IDP administrator or you can enable TRACE logging for SAML ( see [how here](https://www.elastic.co/guide/en/elasticsearch/reference/current/trb-security-saml.html) on the bottom of the page ) and look at your elasticsearch logs.

b) Figure out the actual value that this group/role has. `CN=udspzzzp01_role_platform` is not a complete DN so it's not likely that this is the value that the IDP is sending. Again, you can ask your IDP administrator or you can enable TRACE logging for SAML in elasticsearch.

c) Let's say you figured out that the IDP is sending this information in an attribute named `TheRoleAttribute` and the value of the group is `CN=udspzzzp01_role_platform,OU=resources,OU=udspzzzp01,OU=tenants,DC=msad,DC=udsp,DC=ch`  
In your elasticsearch.yml, you need to set

```auto
attributes.groups: TheRoleAttribute

```

and the role mapping should become

```auto
{
  "roles": ["superuser"],
  "enabled": true,
  "rules": { "all": [
    { "field": { "realm.name": "samlprod" } },
    { "field": { "groups": "CN=udspzzzp01_role_platform,OU=resources,OU=udspzzzp01,OU=tenants,DC=msad,DC=udsp,DC=ch" } }
  ]}
}

```

This is also explained in much more detail in our docs, please see here [https://www.elastic.co/guide/en/elasticsearch/reference/master/saml-guide-authentication.html#saml-attribute-mapping](https://www.elastic.co/guide/en/elasticsearch/reference/master/saml-guide-authentication.html#saml-attribute-mapping) and [https://www.elastic.co/guide/en/elasticsearch/reference/master/saml-role-mapping.html](https://www.elastic.co/guide/en/elasticsearch/reference/master/saml-role-mapping.html)

HTH

---

<div class="post-metadata">

**Author:** ![raphperrin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raphperrin/32/51129_2.png) [@raphperrin](https://discuss.elastic.co/u/raphperrin)\
**Post date:** [May 19, 2020, 6:18am UTC](https://discuss.elastic.co/t/saml-role-mapping-with-wildcard/233107/5 "2020-05-19T06:18:10Z")

</div>

Hello  
Thanks a lot, what I was doing wrong was the field name in the mapping. I put the same as the RoleAttribute instead of "groups".

It does work now.

Thank you, best regards  
Raphael

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 16, 2020, 6:18am UTC](https://discuss.elastic.co/t/saml-role-mapping-with-wildcard/233107/6 "2020-06-16T06:18:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
