# How to add backend role or admin permissions for SAML authenticated user

**URL:** <https://forum.opensearch.org/t/how-to-add-backend-role-or-admin-permissions-for-saml-authenticated-user/10643>\
**Category:** Security\
**Created:** [August 17, 2022, 2:06pm UTC](https://forum.opensearch.org/t/how-to-add-backend-role-or-admin-permissions-for-saml-authenticated-user/10643 "2022-08-17T14:06:42Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![ravis85](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@ravis85](https://forum.opensearch.org/u/ravis85)\
**Post date:** [August 17, 2022, 2:06pm UTC](https://forum.opensearch.org/t/how-to-add-backend-role-or-admin-permissions-for-saml-authenticated-user/10643/1 "2022-08-17T14:06:42Z")

</div>

Hi,

I have configured SAML SSO in my opensearch and I am able to authenticate into my opensearch using single sign-on.

Also my config.yaml file has authc section for SAML, but don’t have authz section. Also in the opensearch documentation, I didn’t find authz section. So is it correct that SAML doesn’t need authz section? please clarify.

But after authentication, I am not able to see any role under backend roles. I want to have admin permissions to the user who is authenticated through single sign-on. Do we need to have something configured on IDP side on SAML or just adding backend role works?

How can I achieve this?

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [August 17, 2022, 2:42pm UTC](https://forum.opensearch.org/t/how-to-add-backend-role-or-admin-permissions-for-saml-authenticated-user/10643/2 "2022-08-17T14:42:36Z")

</div>

Hi @ravis85. Could you share the following?

1. OpenSearch version
2. What is the SAML IdP
3. content of config.yml and opensearch\_dashboards.yml

---

<div class="post-metadata">

**Author:** ![ravis85](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@ravis85](https://forum.opensearch.org/u/ravis85)\
**Post date:** [August 18, 2022, 6:21am UTC](https://forum.opensearch.org/t/how-to-add-backend-role-or-admin-permissions-for-saml-authenticated-user/10643/3 "2022-08-18T06:21:54Z")

</div>

Hi @pablo

Thanks for your reply.

Please see below requested information.

1. OpenSearch version - opensearch:1.3.2
2. SAML IdP - PingIdentity
3. Contents of config.yml and opensearch\_dashboards.yml are as below.

opensearch\_dashboards.yml -

````auto
# SPDX-License-Identifier: Apache-2.0

# Description:
# Default configuration for OpenSearch Dashboards

#timelion.ui.enabled: true
#server.name: opensearch-dashboards
server.host: "0"
opensearch.hosts: ["https://localhost:9200"]
opensearch.ssl.verificationMode: none
opensearch.username: "kibanaserver"
opensearch.password: "kibanaserver"
opensearch.requestHeadersWhitelist: [authorization,securitytenant]

opensearch_security.multitenancy.enabled: true
opensearch_security.multitenancy.tenants.preferred: ["Private", "Global"]
opensearch_security.readonly_mode.roles: ["kibana_read_only"]
# Use this setting if you are running opensearch-dashboards without https
#opensearch_security.cookie.secure: false
opensearch_security.auth.type: "saml"
#server.xsrf.whitelist: ["/_plugins/_security/saml/acs/idpinitiated", "/_plugins/_security/saml/acs", "/_plugins/_security/saml/logout"]
server.xsrf.whitelist: [/_plugins/_security/saml/acs,/_opendistro/_security/saml/acs,/_plugins/_security/saml/acs/idpinitiated,/_opendistro/_security/saml/acs/idpinitiated,/_plugins/_security/saml/logout,/_opendistro/_security/saml/logout]```

````

config.yml -

````nohighlight

# This is the main OpenSearch Security configuration file where authentication
# and authorization is defined.
#
# You need to configure at least one authentication domain in the authc of this file.
# An authentication domain is responsible for extracting the user credentials from
# the request and for validating them against an authentication backend like Active Directory for example.
#
# If more than one authentication domain is configured the first one which succeeds wins.
# If all authentication domains fail then the request is unauthenticated.
# In this case an exception is thrown and/or the HTTP status is set to 401.
#
# After authentication authorization (authz) will be applied. There can be zero or more authorizers which collect
# the roles from a given backend for the authenticated user.
#
# Both, authc and auth can be enabled/disabled separately for REST and TRANSPORT layer. Default is true for both.
# http_enabled: true
# transport_enabled: true
#
# For HTTP it is possible to allow anonymous authentication. If that is the case then the HTTP authenticators try to
# find user credentials in the HTTP request. If credentials are found then the user gets regularly authenticated.
# If none can be found the user will be authenticated as an "anonymous" user. This user has always the username "anonymous"
# and one role named "anonymous_backendrole".
# If you enable anonymous authentication all HTTP authenticators will not challenge.
#
#
# Note: If you define more than one HTTP authenticators make sure to put non-challenging authenticators like "proxy" or "clientcert"
# first and the challenging one last.
# Because it's not possible to challenge a client with two different authentication methods (for example
# Kerberos and Basic) only one can have the challenge flag set to true. You can cope with this situation
# by using pre-authentication, e.g. sending a HTTP Basic authentication header in the request.
#
# Default value of the challenge flag is true.
#
#
# HTTP
# basic (challenging)
# proxy (not challenging, needs xff)
# kerberos (challenging)
# clientcert (not challenging, needs https)
# jwt (not challenging)
# host (not challenging) #DEPRECATED, will be removed in a future version.
# host based authentication is configurable in roles_mapping

# Authc
# internal
# noop
# ldap

# Authz
# ldap
# noop

_meta:
  type: "config"
  config_version: 2

config:
  dynamic:
    # Set filtered_alias_mode to 'disallow' to forbid more than 2 filtered aliases per index
    # Set filtered_alias_mode to 'warn' to allow more than 2 filtered aliases per index but warns about it (default)
    # Set filtered_alias_mode to 'nowarn' to allow more than 2 filtered aliases per index silently
    #filtered_alias_mode: warn
    #do_not_fail_on_forbidden: false
    #kibana:
    # Kibana multitenancy
    #multitenancy_enabled: true
    #server_username: kibanaserver
    #index: '.kibana'
    http:
      anonymous_auth_enabled: false
      xff:
        enabled: false
        internalProxies: '192\.168\.0\.10|192\.168\.0\.11' # regex pattern
        #internalProxies: '.*' # trust all internal proxies, regex pattern
        #remoteIpHeader: 'x-forwarded-for'
        ###### see https://docs.oracle.com/javase/7/docs/api/java/util/regex/Pattern.html for regex help
        ###### more information about XFF https://en.wikipedia.org/wiki/X-Forwarded-For
        ###### and here https://tools.ietf.org/html/rfc7239
        ###### and https://tomcat.apache.org/tomcat-8.0-doc/config/valve.html#Remote_IP_Valve

    authc:
      internal_auth:
        description: "Authenticate via HTTP Basic against internal users database"
        http_enabled: true
        transport_enabled: true
        order: 0
        http_authenticator:
          type: basic
          challenge: false
        authentication_backend:
          type: internal
      saml_auth_domain:
        http_enabled: true
        transport_enabled: false
        order: 1
        description: "SAML provider"
        http_authenticator:
          type: saml
          challenge: true
          config:
            idp:
              enable_ssl: true
              verify_hostnames: true
              metadata_file: /usr/share/opensearch/plugins/opensearch-security/securityconfig/metadata.xml
              entity_id: https://ssodev.example.com/entity
            sp:
              entity_id: https://sandbox.elk.example.com
# forceAuthn: true
            kibana_url: https://sandbox.elk.example.com
# subject_key: UserID
           roles_key: Role
            exchange_key: '88d7fe3fd7624e98490a9e6c68daeaedc7467863189d22d36113b39a8fbf5e60'
        authentication_backend:
          type: noop```
````

---

<div class="post-metadata">

**Author:** ![nomopo](https://avatars.discourse-cdn.com/v4/letter/n/ee59a6/32.png) [@nomopo](https://forum.opensearch.org/u/nomopo)\
**Post date:** [August 18, 2022, 9:22am UTC](https://forum.opensearch.org/t/how-to-add-backend-role-or-admin-permissions-for-saml-authenticated-user/10643/4 "2022-08-18T09:22:37Z")

</div>

Hello @pablo ,

I have the same problem here, since we can’t use two different auth solution at the same time, once saml is enabled i can’t connect with the admin account and set the roles.

I even tried to find the saml users in the database but i can’t find them, i tried to patch the saml user with this command :

```auto
curl -XPATCH https://opensearch-dashboards:9200/_plugins/_security/api/internalusers/me@mydomain.com -u admin:mypassword -k -H 'Content-Type: application/json' -d '[{"op": "replace", "path": "/backend_roles", "value": ["admin"]}]'

```

but answer is :

```auto
{"status":"NOT_FOUND","message":"user me@mydomain.com not found."}

```

When i connect on opensearch dashboards by saml i though it will create the user but apparently not.

opensearch version : 2.0.1  
SAML idp : gsuite  
content of config.yml and opensearch\_dashboards.yml is very very similar to @ravis85

---

<div class="post-metadata">

**Author:** ![nomopo](https://avatars.discourse-cdn.com/v4/letter/n/ee59a6/32.png) [@nomopo](https://forum.opensearch.org/u/nomopo)\
**Post date:** [August 18, 2022, 9:35am UTC](https://forum.opensearch.org/t/how-to-add-backend-role-or-admin-permissions-for-saml-authenticated-user/10643/5 "2022-08-18T09:35:42Z")

</div>

@ravis85 I just managed to change the permission of my saml user with this :

```auto
curl -XPATCH https://opensearch:9200/_plugins/_security/api/rolesmapping/all_access -u admin:mypassword -k -H 'Content-Type: application/json' -H 'Accept: application/json' -d '[{"op":"add", "path": "/users", "value": ["me@mydomain.com"]}]'

```

just change the value field, the -u admin:mypassword to your admin internal user (default is admin:admin) and the host.

hope this help

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [August 18, 2022, 9:53am UTC](https://forum.opensearch.org/t/how-to-add-backend-role-or-admin-permissions-for-saml-authenticated-user/10643/6 "2022-08-18T09:53:28Z")

</div>

@nomopo Have you tried using securityadmin.sh and yml config files instead.

> **[Apply changes with securityadmin.sh](https://opensearch.org/docs/latest/security-plugin/configuration/security-admin/)**
>
> Apply changes using securityadmin.sh

---

<div class="post-metadata">

**Author:** ![ravis85](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@ravis85](https://forum.opensearch.org/u/ravis85)\
**Post date:** [August 18, 2022, 10:25am UTC](https://forum.opensearch.org/t/how-to-add-backend-role-or-admin-permissions-for-saml-authenticated-user/10643/7 "2022-08-18T10:25:46Z")

</div>

Hi @pablo  
Could you please check my files and suggest what can be done?

---

<div class="post-metadata">

**Author:** ![ravis85](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@ravis85](https://forum.opensearch.org/u/ravis85)\
**Post date:** [August 18, 2022, 10:45am UTC](https://forum.opensearch.org/t/how-to-add-backend-role-or-admin-permissions-for-saml-authenticated-user/10643/8 "2022-08-18T10:45:48Z")

</div>

Hi @nomopo Thanks for your help.

It worked for me, however this is a manual approach. I would like to have a setup like whenever a group sign in using single sign-on, he should get the admin privileges, but this needs to be for some group of users(based on distribution list) and not for all.

Rest all the users should be authenticated using single sign on and can have a member privileges.

Is it possible to implement? please suggest.

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [August 18, 2022, 1:20pm UTC](https://forum.opensearch.org/t/how-to-add-backend-role-or-admin-permissions-for-saml-authenticated-user/10643/9 "2022-08-18T13:20:48Z")

</div>

@ravis85 I’ve got the PingID and SAML working in my lab.  
In regards to authz, SAML authentication doesn’t need this section. It is used only by LDAP authentication as LDAP connection is split into a two-phase connection handshake - authentication and authorization.

In SAML authentication, the authorization part is configured by Attribute Mappings and included in the authorization token.

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/6/6d5f63ac7b19d44a72d1cd9efc415aa5fe039393.png)

Then in config.yml you need to point to that mapping.

![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/c/c42058488674892cb897943096680bb29221e298.png)

Below is an example of mapping custom PingID group with role in OpenSearch.

I have a role called **pablo** in OpenSearch.  
roles.yml

![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/a/ac7bd33fb1609d6f51f8d26717d29da4e6dc3b18.png)

and mapping in roles\_mapping.yml  
 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/8/871c4445d77e313f4fcc3a12a224a3b8b7e0f3a3.png)

I created a group in PingID called **custom\_role\_1** and assigned it to user **test2**.

![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/3/304bef59903a8effe81d1078e48e7d830a4cfbf7.png)

**kibanauser** role is required when you want to access OpenSearch Dashboards UI.

Using the above configuration OpenSearch will translate the mapping and assign correct roles.

![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/a/aac41f78bf0896fd18d37a3690f0ead545521f9d.png)  
 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/f/f4424b544a5042d146ed699b510a01cb0f6609a3.png)

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [August 18, 2022, 1:40pm UTC](https://forum.opensearch.org/t/how-to-add-backend-role-or-admin-permissions-for-saml-authenticated-user/10643/10 "2022-08-18T13:40:01Z")

</div>

@ravis85 I’ve just noticed that your **roles\_key** is incorrectly indented in config.yml. It must be under **config** at the same level as **kibana\_url**.

---

<div class="post-metadata">

**Author:** ![ravis85](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@ravis85](https://forum.opensearch.org/u/ravis85)\
**Post date:** [August 18, 2022, 2:13pm UTC](https://forum.opensearch.org/t/how-to-add-backend-role-or-admin-permissions-for-saml-authenticated-user/10643/11 "2022-08-18T14:13:03Z")

</div>

Hi @pablo

Thank you sharing the details and pointing out the issue in the indentation of roles\_key. I will perform these changes and check.

I will let you know incase of any issues or doubts

---

<div class="post-metadata">

**Author:** ![ravis85](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@ravis85](https://forum.opensearch.org/u/ravis85)\
**Post date:** [August 18, 2022, 2:39pm UTC](https://forum.opensearch.org/t/how-to-add-backend-role-or-admin-permissions-for-saml-authenticated-user/10643/12 "2022-08-18T14:39:52Z")

</div>

Hi @pablo  
One question, so for SAML, we need to create the groups on IDP side and map those groups with roles in Opensearch side, this is the way SAML in OpenSearch works?

Please correct me if my understanding is wrong.

Thanks

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [August 18, 2022, 2:45pm UTC](https://forum.opensearch.org/t/how-to-add-backend-role-or-admin-permissions-for-saml-authenticated-user/10643/13 "2022-08-18T14:45:38Z")

</div>

@ravis85 That’s correct.

---

<div class="post-metadata">

**Author:** ![ravis85](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@ravis85](https://forum.opensearch.org/u/ravis85)\
**Post date:** [August 23, 2022, 11:13am UTC](https://forum.opensearch.org/t/how-to-add-backend-role-or-admin-permissions-for-saml-authenticated-user/10643/14 "2022-08-23T11:13:33Z")

</div>

Hi @pablo

I have made the changes on IdP side for atribute mapping of roles with group names(our DLs) and I can see that SAML response is returning the DLs. I have mapped that group to my admin role in backend\_roles.

Now I can see my group from SAML in backend\_roles in OpenSearch UI under “View roles and identities”, but I am not able to see “Security” tab" under “OpenSearch Plugins”.

I want to have “all\_access” kind of role permissions for my group, which is I added in backend\_roles, could you please share the snippet of “all\_access” role, I am not able to find it in roles.yml

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/3/31d8770ce33a09a9b8eb0d500a82761eacc365a1.jpeg)

Please see below my roles.yml and roles\_mapping.yml file

roles.yml -

```auto
i4dadminrole : {
  "reserved" : false,
  "hidden" : false,
  "cluster_permissions" : [
    "cluster_all"
  ],
  "index_permissions" : [
    {
      "index_patterns" : [
        "*"
      ],
      "dls" : "",
      "fls" : [],
      "masked_fields" : [],
      "allowed_actions" : [
        "crud"
      ]
    }
  ],
  "tenant_permissions" : [
    {
      "tenant_patterns" : [
        "global_tenant"
       ],
      "allowed_actions" : [
        "kibana_all_write"
      ]
    }
  ],
  "static" : false
}

```

roles\_mapping.yml -

```auto
i4dadminrole:
  reserved: false
  backend_roles:
  - "DL GIM TI Prod Dev Infrastructure for Developers"
  description: "Maps DL GIM TIProd Dev Infrastructure for Developers from PingID to i4dadminrole role"

```

Could you please check and suggest if I am doing anything wrong here?

Also in the tenant\_permissions, I have mentioned “global\_tenant”, but after login, its showing me private tenant only.

Thanks

---

<div class="post-metadata">

**Author:** ![ravis85](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@ravis85](https://forum.opensearch.org/u/ravis85)\
**Post date:** [August 25, 2022, 4:58am UTC](https://forum.opensearch.org/t/how-to-add-backend-role-or-admin-permissions-for-saml-authenticated-user/10643/15 "2022-08-25T04:58:51Z")

</div>

Hi @pablo

Could you please check the above message and suggest?

---

<div class="post-metadata">

**Author:** ![kannappansenthil](https://avatars.discourse-cdn.com/v4/letter/k/5e9695/32.png) [@kannappansenthil](https://forum.opensearch.org/u/kannappansenthil)\
**Post date:** [August 25, 2022, 6:41am UTC](https://forum.opensearch.org/t/how-to-add-backend-role-or-admin-permissions-for-saml-authenticated-user/10643/16 "2022-08-25T06:41:41Z")

</div>

Add admin backend role along with your group name in role\_mapping.yml

Like grp\_name , admin

---

<div class="post-metadata">

**Author:** ![ravis85](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@ravis85](https://forum.opensearch.org/u/ravis85)\
**Post date:** [August 25, 2022, 6:51am UTC](https://forum.opensearch.org/t/how-to-add-backend-role-or-admin-permissions-for-saml-authenticated-user/10643/17 "2022-08-25T06:51:32Z")

</div>

Hi @kannappansenthil Thank you for your reply.

I tried adding admin backend role along with my group name as you suggested, still its not working. I can’t see “security” tab for my user(who is part of the group)

```auto
i4dadminrole:
  reserved: false
  backend_roles:
  - "DL GIM TI Prod Dev Infrastructure for Developers,admin"
  description: "Maps DL GIM TI Prod Dev Infrastructure for Developers from PingID to i4dadminrole role"

```

---

<div class="post-metadata">

**Author:** ![kannappansenthil](https://avatars.discourse-cdn.com/v4/letter/k/5e9695/32.png) [@kannappansenthil](https://forum.opensearch.org/u/kannappansenthil)\
**Post date:** [August 25, 2022, 8:20am UTC](https://forum.opensearch.org/t/how-to-add-backend-role-or-admin-permissions-for-saml-authenticated-user/10643/18 "2022-08-25T08:20:51Z")

</div>

Hi ,

it should be list.

```auto
backend_roles:
  - "DL GIM TI Prod Dev Infrastructure for Developers"
  - "admin"

```

---

<div class="post-metadata">

**Author:** ![ravis85](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@ravis85](https://forum.opensearch.org/u/ravis85)\
**Post date:** [August 25, 2022, 8:53am UTC](https://forum.opensearch.org/t/how-to-add-backend-role-or-admin-permissions-for-saml-authenticated-user/10643/19 "2022-08-25T08:53:44Z")

</div>

Hi @kannappansenthil

I tried providing as a list, but still I can’t see “security” for my user.

```auto
i4dadminrole:
  reserved: false
  backend_roles:
    - "DL GIM TI Prod Dev Infrastructure for Developers"
    - "admin"

```

Is my role(i4dadminrole) which I am mapping here has “cluster\_all” permissions is correct for getting that “security” plugin tab in UI or some more permissions are required?

Could you please check my role and suggest whether its correct?
