# SSO not working on ECK with Oracle cloud IDP

**URL:** <https://discuss.elastic.co/t/sso-not-working-on-eck-with-oracle-cloud-idp/369239>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [October 22, 2024, 3:18pm UTC](https://discuss.elastic.co/t/sso-not-working-on-eck-with-oracle-cloud-idp/369239 "2024-10-22T15:18:55Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![hsinha09](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hsinha09/32/136891_2.png) [@hsinha09](https://discuss.elastic.co/u/hsinha09)\
**Post date:** [October 22, 2024, 3:18pm UTC](https://discuss.elastic.co/t/sso-not-working-on-eck-with-oracle-cloud-idp/369239/1 "2024-10-22T15:18:55Z")

</div>

Hi,  
I am trying to configure SSO on elasticsearch. While login, it is redirecting to the SSO auth page and asks for username and password, followed by auth code. Once the auth code is entered, I am getting 404 - not found error. Screenshot below.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/c/ec746ca32c08e26383566cc63f977a3842daf41e.png)

Elasticsearch and Kibana is installed via ECK on GKE. Currently using a trial license.

Elasticsearch.yaml (Saml config below) -

```auto
 xpack.security.authc.token.enabled: true
      xpack.security.authc.realms:
        saml:
          saml1:
            order: 0
            attributes.principal: "EmailAddress"
            attributes.groups: "roles"
            nameid_format: "urn:oasis:names:tc:SAML:2.0:nameid-format:persistent"
            idp.metadata.path: /usr/share/elasticsearch/config/saml/idp-saml-metadata.xml
            idp.entity_id: "https://xxxxxx.identity.oraclecloud.com:443/fed"
            sp.entity_id: "https://example.com/"
            sp.acs: "https://example.com/api/security/v1/saml/acs"
            sp.logout: "https://example.com/logout"

```

Above values are configured in oracle cloud identity application.

Kibana.yaml (Saml config)

```auto
	xpack.security.authc.providers:
      saml.saml1:
        order: 0
        realm: "saml1"
      basic.basic1:
        order: 1

```

Also, created a role-mapping

```auto
{
  "saml-role" : {
    "enabled" : true,
    "roles" : [
      "admin"
    ],
    "rules" : {
      "field" : {
        "realm.name" : "saml1"
      }
    },
    "metadata" : { }
  }
}

```

Kibana logs -

```auto
[INFO][plugins.security.authentication] Performing login attempt with "saml1" provider.
[INFO][plugins.security.authentication] Login attempt with "saml1" provider succeeded (requires redirect: true).

```

Please let me know what could be the possible failure reason. Thanks in advance!

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [October 24, 2024, 12:37am UTC](https://discuss.elastic.co/t/sso-not-working-on-eck-with-oracle-cloud-idp/369239/3 "2024-10-24T00:37:54Z")

</div>

> [@hsinha09](#):
>
> ` sp.acs: "https://example.com/api/security/v1/saml/acs"`

Where did you get this URL from? It's not the one covered in our docs,

The docs advise you to use: `api/security/saml/callback`

See:

- [Configuring SAML single-sign-on on the Elastic Stack | Elasticsearch Guide [8.15] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/saml-guide-stack.html#saml-create-realm)

---

<div class="post-metadata">

**Author:** ![hsinha09](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hsinha09/32/136891_2.png) [@hsinha09](https://discuss.elastic.co/u/hsinha09)\
**Post date:** [October 24, 2024, 7:48pm UTC](https://discuss.elastic.co/t/sso-not-working-on-eck-with-oracle-cloud-idp/369239/4 "2024-10-24T19:48:15Z")

</div>

Thanks a lot! Its working now.
