# SAML support, custom authentication plugins

**URL:** <https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 3, 2015, 9:56am UTC](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813 "2015-06-03T09:56:04Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![owulff](https://avatars.discourse-cdn.com/v4/letter/o/f475e1/32.png) [@owulff](https://discuss.elastic.co/u/owulff)\
**Post date:** [June 3, 2015, 9:56am UTC](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813/1 "2015-06-03T09:56:04Z")

</div>

This question has been raised in the Kibana community already:

> [@Validate SAML token in Kibana](https://discuss.elastic.co/t/validate-saml-token-in-kibana/1185/3):
>
> We are also looking into a solution and are considering to Proxy Kibana with Tomcat and the SAML/WS-Federation Plugin Fediz (subproject of Apache CXF). The challenge is the security support in ES itself because it only supports Username/Password and then retrieve the roles from LDAP or file. It would be nice to have an interface where you can provide the roles from any kind of source (SAML Token, HTTP Header). Or is such kind of interface already available?

IMHO, it affects Elasticsearch and Shield as well.

Does Shield provide an interface where I can handle the authentication process (validate SAML token) and then provide Shield the roles the user has by parsing the attributes in the SAML token.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 3, 2015, 12:11pm UTC](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813/2 "2015-06-03T12:11:31Z")

</div>

Currently, no. This type of functionality is something we are working on though.

---

<div class="post-metadata">

**Author:** ![owulff](https://avatars.discourse-cdn.com/v4/letter/o/f475e1/32.png) [@owulff](https://discuss.elastic.co/u/owulff)\
**Post date:** [June 3, 2015, 12:16pm UTC](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813/3 "2015-06-03T12:16:50Z")

</div>

Thanks for the feedback. Can you shed some light on it which industry standards you plan to follow? Do you also have a rough timeline like Q3, Q4, next year?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 3, 2015, 12:26pm UTC](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813/4 "2015-06-03T12:26:57Z")

</div>

I'll ask the product management team to provide a bit more information 🙂

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [June 3, 2015, 12:38pm UTC](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813/5 "2015-06-03T12:38:45Z")

</div>

These are great questions! We have plans to add support for a number of new auth realms. In the very near future, we are planning to add a PKI-based realm that will make application-level authentication using certificates much easier.  
In the longer term - think within this calendar year - we are planning to add additional realms and also allow the realms system to be extended. With the extensibility, it would be straightforward to create your own custom realm for your SAML-based SSO system.

---

<div class="post-metadata">

**Author:** ![owulff](https://avatars.discourse-cdn.com/v4/letter/o/f475e1/32.png) [@owulff](https://discuss.elastic.co/u/owulff)\
**Post date:** [June 3, 2015, 12:41pm UTC](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813/6 "2015-06-03T12:41:43Z")

</div>

Thanks for the update. If you need more details or any other kind of input let me know 🙂

---

<div class="post-metadata">

**Author:** ![rafrey](https://avatars.discourse-cdn.com/v4/letter/r/7bcc69/32.png) [@rafrey](https://discuss.elastic.co/u/rafrey)\
**Post date:** [November 19, 2015, 5:50pm UTC](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813/7 "2015-11-19T17:50:28Z")

</div>

Given the widespread adoption of SAML authentication/authorization in public clouds it may be prudent to include an example implementation of SAML via a custom auth realm using any SAML IdP as a point of reference to provide your customers with a working example which can be modified (if necessary) to work with their own IdP's. One of your competitors recently released native SAML v2.0 SSO/SLO support using the following IdP:

[https://www.pingidentity.com/en/products/pingfederate.html](https://www.pingidentity.com/en/products/pingfederate.html)

There are many organizations that required this type of functionality from production systems hosted in public clouds which could be a barrier to adoption for your project.

I also agree that this needs to be implemented in Shield, simply implementing in Kibana is a half baked solution that isn't going to satisfy security requirements at many organizations.

It doesn't do any good to use SAML for SSO/SLO if you still have to make an LDAP endpoint available for authorization so using authentication proxies for this doesn't really solve the problem at hand.

Any updates on the current status of this work?

-- Rob Frey

---

<div class="post-metadata">

**Author:** ![Micah\_Figone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/micah_figone/32/8011_2.png) [@Micah\_Figone](https://discuss.elastic.co/u/Micah_Figone)\
**Post date:** [February 23, 2016, 11:47pm UTC](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813/8 "2016-02-23T23:47:41Z")

</div>

We would love to have SAML support natively in shield. Through our idp (OneLogin) we provide 2fa as well as a bunch of other ip related restrictions so it would be nice if we could apply these same practices with kibana.

---

<div class="post-metadata">

**Author:** ![Sauraus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sauraus/32/13462_2.png) [@Sauraus](https://discuss.elastic.co/u/Sauraus)\
**Post date:** [November 29, 2016, 1:31am UTC](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813/9 "2016-11-29T01:31:24Z")

</div>

Any update on SAML in Shield? Or is this still a custom realm for which you charge an arm and a leg? ☹

---

<div class="post-metadata">

**Author:** ![Johntdyer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johntdyer/32/3424_2.png) [@Johntdyer](https://discuss.elastic.co/u/Johntdyer)\
**Post date:** [February 18, 2017, 3:54am UTC](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813/10 "2017-02-18T03:54:00Z")

</div>

Any update guys ?

---

<div class="post-metadata">

**Author:** ![Marcel\_Matus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcel_matus/32/140970_2.png) [@Marcel\_Matus](https://discuss.elastic.co/u/Marcel_Matus)\
**Post date:** [May 3, 2017, 6:39pm UTC](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813/11 "2017-05-03T18:39:30Z")

</div>

Any update? I can't believe you work on such a small feature longer than 2 years...  
This would really help us a lot!

---

<div class="post-metadata">

**Author:** ![cblomart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cblomart/32/19229_2.png) [@cblomart](https://discuss.elastic.co/u/cblomart)\
**Post date:** [June 17, 2017, 7:37pm UTC](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813/12 "2017-06-17T19:37:24Z")

</div>

SAML can also be implemented by a third party proxy, thus lowering the need for the application to undestand SAML.

Shibboleth and auth\_melon are common examples.

They basicaly allow to provide a service provider with user information in the http header or execution environement.

---

<div class="post-metadata">

**Author:** ![orenpai](https://avatars.discourse-cdn.com/v4/letter/o/258eb7/32.png) [@orenpai](https://discuss.elastic.co/u/orenpai)\
**Post date:** [June 29, 2017, 5:01pm UTC](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813/13 "2017-06-29T17:01:06Z")

</div>

+1 for this idea. We're going to develop our own SAML proxy for ES... waste of time, would buy it in a second.

---

<div class="post-metadata">

**Author:** ![Aclose](https://avatars.discourse-cdn.com/v4/letter/a/e9bcb4/32.png) [@Aclose](https://discuss.elastic.co/u/Aclose)\
**Post date:** [July 18, 2017, 12:04pm UTC](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813/14 "2017-07-18T12:04:21Z")

</div>

+1 🙂 Any progress on this? It is really required for pretty much all large enterprise companies

---

<div class="post-metadata">

**Author:** ![joshbressers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshbressers/32/42332_2.png) [@joshbressers](https://discuss.elastic.co/u/joshbressers)\
**Post date:** [July 18, 2017, 12:24pm UTC](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813/15 "2017-07-18T12:24:03Z")

</div>

Hi there,

I'm the product manager focusing on x-pack security. We have working happening to support SAML right now. When exactly it will land isn't known yet (there's still a lot of work to do), but it should be supported in the near future. This is literally my #1 feature.

Feel free to let me know if you have any questions.

Thanks.

---

<div class="post-metadata">

**Author:** ![Aclose](https://avatars.discourse-cdn.com/v4/letter/a/e9bcb4/32.png) [@Aclose](https://discuss.elastic.co/u/Aclose)\
**Post date:** [July 18, 2017, 12:36pm UTC](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813/16 "2017-07-18T12:36:04Z")

</div>

Apologies for being picky, but this is a major hurdle for the company I work for to adopt X-Pack. Do you think it will be available this year? knowing roughly when it could land would enable me to work around it and inform my stakeholders. If you could give a ball park period of half 2 this year, half 1 next year, end of next year etc I am sure many other enterprise companies would be content.

---

<div class="post-metadata">

**Author:** ![joshbressers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshbressers/32/42332_2.png) [@joshbressers](https://discuss.elastic.co/u/joshbressers)\
**Post date:** [July 18, 2017, 2:26pm UTC](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813/17 "2017-07-18T14:26:43Z")

</div>

I can't give a great answer unfortunately, there are many moving parts to support this across the stack. The earliest we could maybe see a beta would be end of this calendar year. Feel free to message me near the end of summer, I may have a more concrete timeline by then.

---

<div class="post-metadata">

**Author:** ![Aclose](https://avatars.discourse-cdn.com/v4/letter/a/e9bcb4/32.png) [@Aclose](https://discuss.elastic.co/u/Aclose)\
**Post date:** [July 18, 2017, 2:39pm UTC](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813/18 "2017-07-18T14:39:59Z")

</div>

That is good enough 🙂 I appreciate that it is difficult to give dates in such situations. I shall message towards the end of summer. Many thanks!

---

<div class="post-metadata">

**Author:** ![tlawrie](https://avatars.discourse-cdn.com/v4/letter/t/e274bd/32.png) [@tlawrie](https://discuss.elastic.co/u/tlawrie)\
**Post date:** [September 8, 2017, 5:42pm UTC](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813/19 "2017-09-08T17:42:38Z")

</div>

Do we have an update? is the ETA in 6.0.0? I am another one of the 1000s that have this as a blocker to adoption of elastic.

---

<div class="post-metadata">

**Author:** ![illiash](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/illiash/32/22821_2.png) [@illiash](https://discuss.elastic.co/u/illiash)\
**Post date:** [January 9, 2018, 5:26pm UTC](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813/20 "2018-01-09T17:26:51Z")

</div>

+1  
please any update on this ?

[Next page](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813.md?page=2)
