Skip to content

Add Issuer to SAML WARN log events #111022

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
n1v0lg opened this issue Jul 18, 2024 · 4 comments · Fixed by #126310
Closed

Add Issuer to SAML WARN log events #111022

n1v0lg opened this issue Jul 18, 2024 · 4 comments · Fixed by #126310
Labels
>enhancement :Security/Security Security issues without another label Team:Security Meta label for security team

Comments

@n1v0lg
Copy link
Contributor

n1v0lg commented Jul 18, 2024

Description

To aid debugging, we can extend our current WARN log messages for the SAML realm to include the issuer (if available). This will make it easier to diagnose false positive log messages (e.g., around signature validation failure) for deployments that have multiple SAML realms configured.

We should also improve our SAML common issues docs to mention that the WARN log can be benign in multi-realm setups.

@n1v0lg n1v0lg added >enhancement :Security/Security Security issues without another label Team:Security Meta label for security team labels Jul 18, 2024
@elasticsearchmachine
Copy link
Collaborator

Pinging @elastic/es-security (Team:Security)

@rseldner
Copy link
Contributor

I see a PR for 9.1.0 has merged. 🚀
Any chance that can get back-ported to 8.x?

@rseldner
Copy link
Contributor

Awesome! TY!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
>enhancement :Security/Security Security issues without another label Team:Security Meta label for security team
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants