# Unable to login to kibana . getting {"statusCode":401,"error":"Unauthorized","message":"\[security\_exception\] unable to authenticate user Error

**URL:** <https://discuss.elastic.co/t/unable-to-login-to-kibana-getting-statuscode-401-error-unauthorized-message-security-exception-unable-to-authenticate-user-error/158633>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [November 28, 2018, 6:10pm UTC](https://discuss.elastic.co/t/unable-to-login-to-kibana-getting-statuscode-401-error-unauthorized-message-security-exception-unable-to-authenticate-user-error/158633 "2018-11-28T18:10:35Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Udaya\_Ganga\_Santosh](https://avatars.discourse-cdn.com/v4/letter/u/22d042/32.png) [@Udaya\_Ganga\_Santosh](https://discuss.elastic.co/u/Udaya_Ganga_Santosh)\
**Post date:** [November 28, 2018, 6:10pm UTC](https://discuss.elastic.co/t/unable-to-login-to-kibana-getting-statuscode-401-error-unauthorized-message-security-exception-unable-to-authenticate-user-error/158633/1 "2018-11-28T18:10:35Z")

</div>

please follow the below link for detailed explanation

"[https://docs.google.com/document/d/10T\_QPIxwGYAIIIuTaD\_nUS8\_d5FJbeHY5ER0B-cSoyQ/edit?usp=sharing](https://docs.google.com/document/d/10T_QPIxwGYAIIIuTaD_nUS8_d5FJbeHY5ER0B-cSoyQ/edit?usp=sharing)".

Kibana SOS configuration with OKTA

Not able to login to the kibana through SOS .Getting the following error when trying to login to kibana

{"statusCode":401,"error":"Unauthorized","message":"[security\_exception] unable to authenticate user [\<unauthenticated-saml-user\>] for action [cluster:admin/xpack/security/saml/authenticate], with { header={ WWW-Authenticate={ 0=&quot;Bearer realm=\&quot;security\&quot;&quot; & 1=&quot;Basic realm=\&quot;security\&quot; charset=\&quot;UTF-8\&quot;&quot; } } }

We created the users in kibana and okta with the same names and provided super user privileges .

In the Okta groups are created with name elasticadmin , same user is assigned to group .The user and groups are also assigned application

Created Deployment in elastic cloud and applied the configurations as follows.

We followed the steps from the below url and followed it in the same order

[https://www.elastic.co/guide/en/cloud/current/ec-securing-clusters-SAML.html](https://www.elastic.co/guide/en/cloud/current/ec-securing-clusters-SAML.html)

Elasticsearch.yml

xpack:

security:

authc:

realms:

cloud-saml:

type: saml

order: 2

attributes.principal: "nameid:persistent"

attributes.groups: "groups"

idp.metadata.path: "[https://dev-782126.oktapreview.com/app/exkhqawlen68fzSuB0h7/sso/saml/metadata](https://dev-782126.oktapreview.com/app/exkhqawlen68fzSuB0h7/sso/saml/metadata)"

idp.entity\_id: "[http://www.okta.com/exkhqawlen68fzSuB0h7](http://www.okta.com/exkhqawlen68fzSuB0h7)"

sp.entity\_id: "[https://6213c4f5xxx.us-east-1.aws.found.io:9243/](https://6213c4f5xxx.us-east-1.aws.found.io:9243/)"

sp.acs: "[https://6213c4fxxx.us-east-1.aws.found.io:9243/api/security/v1/saml](https://6213c4fxxx.us-east-1.aws.found.io:9243/api/security/v1/saml)"

sp.logout: "[https://6213c4f57f8a4f7aa9f375d5e49dff30.us-east-1.aws.found.io:9243/logout](https://6213c4f57f8a4f7aa9f375d5e49dff30.us-east-1.aws.found.io:9243/logout)"

We map an elasticadmin group to the superuser role as follows from API Console

POST /\_xpack/security/role\_mapping/CLOUD\_SAML\_ELASTICADMIN\_TO\_SUPERUSER ![](https://lh6.googleusercontent.com/zvHXPzTVPvWlpYjMvDFtmYEZL8Xd12XM8b_KXajNn3KHArPkUEmsZUxpfwMs0mv2yGEoFe6o-fPnuVvzlYqjPSoyvkBlVMg2I9MksGjv2nijxgii8IG-wfGsdIdd_326sC1XJkLT)  
{  
"enabled": true,  
"roles": ["superuser"], ![](https://lh4.googleusercontent.com/aAtaIivwwCtkIAjGrYk5bR8v9awaNrRBl8K0KCsmpnAyNxt3cSmsR0kVhDcZjkfR4H4LQhNbNFBaLBfEu95t9kzN2QjVZ6l99haBYCywhusCxvkgSpCJU2cP1h4wn7nwETLABv3h)  
"rules": { ![](https://lh4.googleusercontent.com/U8ewYbWzr6leOXlpdAKOLJSa5oWDHog5m-WUC1wMRcVV8hYH_oR-LTxUW6aT-kWEmZb9EEDymvZ6AMMgO84ErVhVFjJpMqV42kJlpy-Giy83jG1v1Xr0SYWAlUGRGI1D2B4In4kA)  
"field": { "groups": "elasticadmin" }  
},  
"metadata": { "version": 1 }  
}

kibana.yml

xpack.security.authProviders: [saml]

server.xsrf.whitelist: [/api/security/v1/saml]

xpack.security.public:

protocol: https

hostname: [6213c4f57f8xxxxx.us-east-1.aws.found.io](http://6213c4f57f8xxxxx.us-east-1.aws.found.io)

port: 9243

We are using OKTA as IDP and its configurations is as follows

We found no errors in the Okta Log and it seems everything is fine there .

Please let me know what might be the cause and suggest us the solutions .

If there any other configurations are required or anything wrong in my configuration please let us know so that we will change accordingly and test it

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 28, 2018, 7:29pm UTC](https://discuss.elastic.co/t/unable-to-login-to-kibana-getting-statuscode-401-error-unauthorized-message-security-exception-unable-to-authenticate-user-error/158633/2 "2018-11-28T19:29:02Z")

</div>

Hi there,

Please don't post unformatted code as it's very hard to read.

Instead paste the text and format it with `</>` icon, and check the preview  
window to make sure it's properly formatted before posting it. This makes it  
more likely that your question will receive a useful answer.

Also please add all related information in your post here, people don't usually feel very positive to click links to external URLs/Documents.

It would be great if you could update your post to solve this.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 28, 2018, 7:51pm UTC](https://discuss.elastic.co/t/unable-to-login-to-kibana-getting-statuscode-401-error-unauthorized-message-security-exception-unable-to-authenticate-user-error/158633/3 "2018-11-28T19:51:12Z")

</div>

> [@Udaya\_Ganga\_Santosh](#):
>
> {"statusCode":401,"error":"Unauthorized","message":"[security\_exception] unable to authenticate user [\<unauthenticated-saml-user\>] for action [cluster:admin/xpack/security/saml/authenticate], with { header={ WWW-Authenticate={ 0=&quot;Bearer realm=&amp;quot;security&amp;quot;&quot; & 1=&quot;Basic realm=&amp;quot;security&amp;quot; charset=&amp;quot;UTF-8&amp;quot;&quot; } } }

This is the error you are getting. In case 3 from our [troubleshooting guide](https://www.elastic.co/guide/en/elastic-stack-overview/current/trb-security-saml.html), we explain what the cause of this might be. You need to look at your Elasticsearch logs, an error message will be printed there that is relevant to what went wrong.

From a quick look at your config it looks like that this is a configuration error with regards to the SAML Service Provider Entity ID. Your `elasticsearch.yml` has

```auto
sp.entity_id: "https://6213cxxx.us-east-1.aws.found.io:9243/"

```

while your Okta configuration has

```auto
https://6213c4xxx.us-east-1.aws.found.io:9243

```

set as the `Audience URI (SP Entity ID)`, judging from the SAML Response. Mind the trailing `/` .  
You can remove the `/` from your elasticsearch.yml or add it in your OKTA config, it doesn't really matter. The Entity ID is just a string ( Using a URL for it is a good convention ) and it is matched as a string, not as a canonicalized URL.

---

<div class="post-metadata">

**Author:** ![Udaya\_Ganga\_Santosh](https://avatars.discourse-cdn.com/v4/letter/u/22d042/32.png) [@Udaya\_Ganga\_Santosh](https://discuss.elastic.co/u/Udaya_Ganga_Santosh)\
**Post date:** [November 29, 2018, 12:31pm UTC](https://discuss.elastic.co/t/unable-to-login-to-kibana-getting-statuscode-401-error-unauthorized-message-security-exception-unable-to-authenticate-user-error/158633/4 "2018-11-29T12:31:03Z")

</div>

After making the suggested changes i am getting the following error .

```
{"message":"action [indices:data/read/search] is unauthorized for user [pudaysantosh@magazinemanager.com]: [security_exception] action [indices:data/read/search] is unauthorized for user [pudaysantosh@magazinemanager.com]","statusCode":403,"error":"Forbidden"}

```

Elastic search Cloud Id:

kibana search Cloud Id:

my configuration are as follows  
-------------- elasticsearch.yml-----------------

```
    xpack:
      security:
        authc:
          realms:
            cloud-saml: 
              type: saml
              order: 2
              attributes.principal: "email" 
              attributes.groups: "Role" 
              idp.metadata.path: "https://dev-782126.oktapreview.com/app/exkhqawlen68fzSuB0h7/sso/saml/metadata" 
              idp.entity_id: "http://www.okta.com/exkhqawlen68fzSuB0h7" 
              sp.entity_id: "https://6213c4xxx.us-east-1.aws.found.io:9243/" 
              sp.acs: "https://6213c4xxxx.us-east-1.aws.found.io:9243/api/security/v1/saml"
              sp.logout: "https://6213c4fxxxx.us-east-1.aws.found.io:9243/logout"

```

-------------- kibana.yml-----------------  
xpack.security.authProviders: [saml]  
server.xsrf.whitelist: [/api/security/v1/saml]  
xpack.security.public:  
protocol: https  
hostname: [6213c4fxxxx.us-east-1.aws.found.io](http://6213c4fxxxx.us-east-1.aws.found.io)  
port: 9243 .

please let me know the cause ?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 29, 2018, 2:24pm UTC](https://discuss.elastic.co/t/unable-to-login-to-kibana-getting-statuscode-401-error-unauthorized-message-security-exception-unable-to-authenticate-user-error/158633/5 "2018-11-29T14:24:04Z")

</div>

Hi,

Please make an effort to remove possibly sensitive information from your configuration and don't post any unnecessary details in a public forum.

Your error message indicates that the user that you logged in with doesn't have the necessary permissions. This means that

- Either your role mapping is wrong / doesn't apply to that user
- Or the role that gets assigned to that user via the role mapping doesn't grant them the necessary privileges.

1. Please share with us the role mappings you have created. Do that by querying Elasticsearch, i.e.

2. If you have created custom roles that you assign to users via the aforementioned role mappings, also share the role definitionss

3. Share with us the response from the `_authenticate` API by executing

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 27, 2018, 2:25pm UTC](https://discuss.elastic.co/t/unable-to-login-to-kibana-getting-statuscode-401-error-unauthorized-message-security-exception-unable-to-authenticate-user-error/158633/6 "2018-12-27T14:25:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
