# Using GSuite for SAML integration with Elastic Stack (ElasticSearch + Kibana)

**URL:** <https://discuss.elastic.co/t/using-gsuite-for-saml-integration-with-elastic-stack-elasticsearch-kibana/159971>\
**Category:** Elastic Cloud Enterprise (ECE)\
**Tags:** elastic-stack-security\
**Created:** [December 7, 2018, 6:42pm UTC](https://discuss.elastic.co/t/using-gsuite-for-saml-integration-with-elastic-stack-elasticsearch-kibana/159971 "2018-12-07T18:42:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![chiragsc](https://avatars.discourse-cdn.com/v4/letter/c/d07c76/32.png) [@chiragsc](https://discuss.elastic.co/u/chiragsc)\
**Post date:** [December 7, 2018, 6:42pm UTC](https://discuss.elastic.co/t/using-gsuite-for-saml-integration-with-elastic-stack-elasticsearch-kibana/159971/1 "2018-12-07T18:42:37Z")

</div>

I am trying to use GSuite to integration into my ElasticCloud Stack (Elasticsearch + Kibana) and am stuck at what attribute values to state. According to the documentation: [Secure your clusters with SAML | Elasticsearch Service Documentation | Elastic](https://www.elastic.co/guide/en/cloud/current/ec-securing-clusters-SAML.html), I have added the below for both elasticsearch.yml and kibana.yml files.

**_elasticsearch.yml_**

```
xpack:
security:
  authc:
    realms:
      cloud-saml:
        type: saml
        order: 2
        attributes.principal: “nameid:user@sitecompli.com”
        attributes.groups: “groups”
        idp.metadata.path: “https://accounts.google.com/o/saml2/idp?idpid=xxxxxxxxx”
        idp.entity_id: “https://accounts.google.com/o/saml2?idpid=xxxxxxxxx”
        sp.entity_id: “xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx.us-east-1.aws.found.io:9243/”
        sp.acs: “xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx.us-east-1.aws.found.io:9243/api/security/v1/saml”
        sp.logout: “xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx.us-east-1.aws.found.io:9243/logout”

```

**_kibana.yml_**

```
xpack.security.authProviders: [saml]
server.xsrf.whitelist: [/api/security/v1/saml]
xpack.security.public:
protocol: https
hostname: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx.us-east-1.aws.found.io
port: 9243

```

After reading the following: [Issue connecting google saml with es stack](https://discuss.elastic.co/t/issue-connecting-google-saml-with-es-stack/144791), I edited the attributes.principal to "urn:oid:0.9.2342.19200300.100.1.1" and that threw an error. I am not sure if I am missing anything.

I've tried the following for attributes.principal:

- [nameid:user@sitecompli.com](mailto:nameid:user@sitecompli.com)
- urn:oid:0.9.2342.19200300.100.1.1
- nameid:persistent

The Error message I get it is:

> instance-0000000009] Metadata Resolver FilesystemMetadataResolver cloud-saml: Metadata provider failed to properly initialize, fail-fast=true, halting net.shibboleth.utilities.java.support.component.ComponentInitializationException: Error refreshing metadata during init at org.opensaml.saml.metadata.resolver.impl.AbstractReloadingMetadataResolver.initMetadataResolver(AbstractReloadingMetadataResolver.java:264) ~[?:?] at org.opensaml.saml.metadata.resolver.impl.AbstractMetadataResolver.doInitialize(AbstractMetadataResolver.java:287) ~[?:?] at net.shibboleth.utilities.java.support.component.AbstractInitializableComponent.initialize(AbstractInitializableComponent.java:61) ~[?:?] at org.elasticsearch.xpack.security.authc.saml.SamlRealm.lambda$initialiseResolver$11(SamlRealm.java:628) ~[?:?] at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0\_144] at org.elasticsearch.xpack.security.authc.saml.SamlRealm.initialiseResolver(SamlRealm.java:627) ~[?:?] at org.elasticsearch.xpack.security.authc.saml.SamlRealm.parseFileSystemMetadata(SamlRealm.java:592) ~[?:?] at org.elasticsearch.xpack.security.authc.saml.SamlRealm.initializeResolver(SamlRealm.java:517) ~[?:?] at org.elasticsearch.xpack.security.authc.saml.SamlRealm.create(SamlRealm.java:191) ~[?:?] at org.elasticsearch.xpack.security.authc.InternalRealms.lambda$getFactories$5(InternalRealms.java:106) ~[?:?] at org.elasticsearch.xpack.security.authc.Realms.initRealms(Realms.java:191) ~[?:?] at org.elasticsearch.xpack.security.authc.Realms.\<init\>(Realms.java:68) ~[?:?] at org.elasticsearch.xpack.security.Security.createComponents(Security.java:469) ~[?:?] at org.elasticsearch.xpack.security.Security.createComponents(Security.java:399) ~[?:?] at org.elasticsearch.node.Node.lambda$new$11(Node.java:472) ~[elasticsearch-6.5.1.jar:6.5.1] at java.util.stream.ReferencePipeline$7$1.accept(ReferencePipeline.java:267) [?:1.8.0\_144] at java.util.ArrayList$ArrayListSpliterator.forEachRemaining(ArrayList.java:1374) [?:1.8.0\_144] at java.util.stream.AbstractPipeline.copyInto(AbstractPipeline.java:481) [?:1.8.0\_144]

Please let me know if you have any thoughts on the above error message. [support@elastic.co](mailto:support@elastic.co) says I need to enter GSuite specific attributes for attributes.principal and attributes.groups. GSuite support says that I can keep attributes.principal to be "nameid:persistent" and attributes.groups to be "groups".

Thank you!

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [December 7, 2018, 6:56pm UTC](https://discuss.elastic.co/t/using-gsuite-for-saml-integration-with-elastic-stack-elasticsearch-kibana/159971/2 "2018-12-07T18:56:46Z")

</div>

Please don't post unformatted configurations and logs as they're very hard to read.

Instead paste the text and format it with \</\> icon, and check the preview  
window to make sure it's properly formatted before posting it. This makes it  
more likely that your question will receive a useful answer.

It would be great if you could update your post to solve this.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [December 7, 2018, 7:28pm UTC](https://discuss.elastic.co/t/using-gsuite-for-saml-integration-with-elastic-stack-elasticsearch-kibana/159971/3 "2018-12-07T19:28:10Z")

</div>

> [@chiragsc](#):
>
> [instance-0000000009] Metadata Resolver FilesystemMetadataResolver cloud-saml: Metadata provider failed to properly initialize, fail-fast=true, halting

This error doesn't have to do with your attribute mapping. It means that Elasticsearch cannot load your metadata from GSuite's Identity Provider. Reading through [their instructions](https://support.google.com/a/answer/6087519?hl=en) it doesn't look like they host their metadata on an URL that can be accessible and the `https://accounts.google.com/o/saml2/idp?idpid=xxxxxxxxx` you have used is the SSO URL.

Since this is actually not ECE ,you can take a look at our documentation, see step 7 [here](https://www.elastic.co/guide/en/cloud/release-ms-14/ec-securing-clusters-SAML.html)

* * *

Tbe following would apply for elastic cloud enterprise:

You need to download the SAML Metadata XML Document from GSuite and use that as follows:

1. Prepare a ZIP file with a [custom bundle](https://www.elastic.co/guide/en/cloud-enterprise/current/ece-add-plugins.html) that contains your Identity Provider’s metadata ( `metadata.xml` ) inside of a `saml` folder. This bundle allows all Elasticsearch containers to access the metadata file.

2. Update your Elasticsearch cluster with the [advanced configuration editor](https://www.elastic.co/guide/en/cloud-enterprise/current/ece-advanced-configuration.html) to use the bundles you prepared in the previous step. You need to modify the `user_bundles` JSON attribute similar to the following example:

3. Adjust your `saml` realm configuration accordingly:

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 21, 2018, 7:28pm UTC](https://discuss.elastic.co/t/using-gsuite-for-saml-integration-with-elastic-stack-elasticsearch-kibana/159971/4 "2018-12-21T19:28:15Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
