# Validate SAML token in Kibana

**URL:** <https://discuss.elastic.co/t/validate-saml-token-in-kibana/1185>\
**Category:** Kibana\
**Created:** [May 22, 2015, 4:44pm UTC](https://discuss.elastic.co/t/validate-saml-token-in-kibana/1185 "2015-05-22T16:44:50Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![mdconner](https://avatars.discourse-cdn.com/v4/letter/m/898d66/32.png) [@mdconner](https://discuss.elastic.co/u/mdconner)\
**Post date:** [May 22, 2015, 4:44pm UTC](https://discuss.elastic.co/t/validate-saml-token-in-kibana/1185/1 "2015-05-22T16:44:50Z")

</div>

Does Kibana support SAML tokens? If not, any assistance with getting this to done (Apache HTTP Server, or other)?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 24, 2015, 2:12am UTC](https://discuss.elastic.co/t/validate-saml-token-in-kibana/1185/2 "2015-05-24T02:12:55Z")

</div>

It currently doesn't support this.

---

<div class="post-metadata">

**Author:** ![owulff](https://avatars.discourse-cdn.com/v4/letter/o/f475e1/32.png) [@owulff](https://discuss.elastic.co/u/owulff)\
**Post date:** [June 3, 2015, 6:11am UTC](https://discuss.elastic.co/t/validate-saml-token-in-kibana/1185/3 "2015-06-03T06:11:39Z")

</div>

We are also looking into a solution and are considering to Proxy Kibana with Tomcat and the SAML/WS-Federation Plugin Fediz (subproject of Apache CXF). The challenge is the security support in ES itself because it only supports Username/Password and then retrieve the roles from LDAP or file. It would be nice to have an interface where you can provide the roles from any kind of source (SAML Token, HTTP Header). Or is such kind of interface already available?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 3, 2015, 12:04pm UTC](https://discuss.elastic.co/t/validate-saml-token-in-kibana/1185/4 "2015-06-03T12:04:08Z")

</div>

This is not available either sorry!  
We are working on extending the functionality to cater for these sorts of uses 🙂

---

<div class="post-metadata">

**Author:** ![mdconner](https://avatars.discourse-cdn.com/v4/letter/m/898d66/32.png) [@mdconner](https://discuss.elastic.co/u/mdconner)\
**Post date:** [June 5, 2015, 12:17pm UTC](https://discuss.elastic.co/t/validate-saml-token-in-kibana/1185/5 "2015-06-05T12:17:38Z")

</div>

If looking for suggestions, allowing JAAS (Java Authentication & Authorization Service) plugins would be ideal so we could customize for our environment.

Thanks for the feedback.

---

<div class="post-metadata">

**Author:** ![martin\_goldstone](https://avatars.discourse-cdn.com/v4/letter/m/4af34b/32.png) [@martin\_goldstone](https://discuss.elastic.co/u/martin_goldstone)\
**Post date:** [June 14, 2015, 7:01am UTC](https://discuss.elastic.co/t/validate-saml-token-in-kibana/1185/6 "2015-06-14T07:01:47Z")

</div>

I'm about to go through this as well, my plan is to use Apache httpd as a reverse proxy in front of Kibana, and use mod\_shib in httpd for the authentication.

---

<div class="post-metadata">

**Author:** ![slee](https://avatars.discourse-cdn.com/v4/letter/s/f4b2a3/32.png) [@slee](https://discuss.elastic.co/u/slee)\
**Post date:** [June 23, 2015, 5:41pm UTC](https://discuss.elastic.co/t/validate-saml-token-in-kibana/1185/7 "2015-06-23T17:41:48Z")

</div>

> [@martin\_goldstone](#):
>
> mod\_shib

Hi Martin,  
I was wondering how your progress was going on this? We want to do something similar, using CA Siteminder with Apache Reverse Proxy. We have it configured up to the point where you specify the index, at which point because of the URLs that Kibana uses, it constantly craps out.

---

<div class="post-metadata">

**Author:** ![rafrey](https://avatars.discourse-cdn.com/v4/letter/r/7bcc69/32.png) [@rafrey](https://discuss.elastic.co/u/rafrey)\
**Post date:** [November 19, 2015, 6:04pm UTC](https://discuss.elastic.co/t/validate-saml-token-in-kibana/1185/8 "2015-11-19T18:04:00Z")

</div>

Update: One of your competitors has released native SAML v2.0 SSO/SLO support via the following IdP (which is also capable of many other authentication methods being discussed here):

> **[Single Sign-on](https://www.pingidentity.com/en/platform/capabilities/single-sign-on.html)**
>
> Learn how single sign-on (SSO) can increase security and employee productivity, while improving your customer experience.

For most use cases, using an authentication proxy does no good if you still need to make an LDAP endpoint available for authorization.

I see this as a barrier to adoption at large organizations that require SAML auth for production systems hosted in public clouds and I am hoping that in consideration of that and the recent adoption of this functionality by competing solutions will allow for this to receive a higher priority within the Elasticsearch project and that you will share this information with your project managers.

I also believe that this needs to be implemented in Sheild per:

> [@SAML support, custom authentication plugins](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813):
>
> This question has been raised in the Kibana community already: IMHO, it affects Elasticsearch and Shield as well. Does Shield provide an interface where I can handle the authentication process (validate SAML token) and then provide Shield the roles the user has by parsing the attributes in the SAML token.

Can you please provide us with a status update on this work? An ETA would be excellent.

Thank you.

-- Rob Frey

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 20, 2015, 5:43am UTC](https://discuss.elastic.co/t/validate-saml-token-in-kibana/1185/9 "2015-11-20T05:43:27Z")

</div>

FYI there is now [https://www.elastic.co/guide/en/shield/current/custom-realms.html](https://www.elastic.co/guide/en/shield/current/custom-realms.html) in the latest release of Shield.

---

<div class="post-metadata">

**Author:** ![Johntdyer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johntdyer/32/3424_2.png) [@Johntdyer](https://discuss.elastic.co/u/Johntdyer)\
**Post date:** [February 20, 2017, 1:41pm UTC](https://discuss.elastic.co/t/validate-saml-token-in-kibana/1185/10 "2017-02-20T13:41:15Z")

</div>

Are there any plans to support SAML as a first class citizen in xpack ? Seems like I should have to write my own for this... FWIW this is a first class feature in your competitors products

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 20, 2017, 8:24pm UTC](https://discuss.elastic.co/t/validate-saml-token-in-kibana/1185/11 "2017-02-20T20:24:06Z")

</div>

Yes this is something we are working on now.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:33pm UTC](https://discuss.elastic.co/t/validate-saml-token-in-kibana/1185/12 "2017-07-06T13:33:04Z")

</div>


