SAP Cloud Logging - SAML Authentication Reference
Source: https://github.com/SAP-docs/btp-cloud-logging/blob/main/docs/prerequisites-41d8559.md Last Updated: 2025-11-22
Table of Contents
- Overview
- Prerequisites
- SAML 2.0 Configuration Steps
- SAML Parameter Reference (Official Nested Structure)
- Role Mapping
- Troubleshooting
- Security Best Practices
- Complete Configuration Example
- Documentation Links
Overview
SAP Cloud Logging strongly recommends integrating with SAP Cloud Identity Services using SAML 2.0 protocol for secure dashboard access. This enables centralized user management and group-based access control.
Security Notice: Review SAP BTP Security Recommendation BTP-CLS-0001 before configuring SAML.
Important: SAP officially recommends Identity Authentication. Other SAML providers may work but lack official support or documentation. SAML configurations can be reused across multiple SAP Cloud Logging instances.
Prerequisites
- SAP Cloud Identity Services tenant (Identity Authentication)
- Administrator access to Identity Authentication admin console:
https://<tenantID>.accounts.ondemand.com/admin - Cloud Logging instance ready for SAML configuration
SAML 2.0 Configuration Steps
Step 1: Gather Identity Provider Information
From your Identity Authentication tenant:
Metadata URL:
https://<tenant-id>.accounts.ondemand.com/saml2/metadataEntity ID:
Extract from metadata file - look for entityID attribute in the root element.
Example:
<EntityDescriptor entityID="https://mytenant.accounts.ondemand.com">Step 2: Create SAML 2.0 Application
- Log into Identity Authentication admin console
- Navigate to Applications & Resources → Applications
- Click Create → SAML 2.0
- Enter application name (e.g., "SAP Cloud Logging - Production")
Step 3: Configure Application Attributes
3.1 Self-Defined Attribute
- Go to application → Attributes
- Add attribute:
- Name:
groups - Source: Identity Directory
- Value: User Groups
- Name:
3.2 Name ID Format
- Go to SAML 2.0 Configuration
- Set Name ID Format:
E-mail
3.3 Manual SAML 2.0 Configuration
Configure the service provider settings:
| Setting | Value |
|---|---|
| Assertion Consumer Service | https://<dashboards-url>/_opendistro/_security/saml/acs |
| Single Logout Service | https://<dashboards-url>/_opendistro/_security/saml/logout |
| SP Entity ID | cloud-logging-<instance-id> |
Step 4: Configure SAML 2.0 (Choose One Option)
OPTION 1: Request Signing (Recommended)
Request signing removes the need to manually configure assertion/logout URLs for each instance.
Generate Certificate and Private Key (Official SAP Commands):
# Generate certificate and private key
openssl req -x509 -newkey rsa:2048 -keyout private.key -out cert.pem -nodes -days <validity>
# Convert to PKCS#8 format (REQUIRED)
openssl pkcs8 -topk8 -v1 PBE-SHA1-3DES -in private.key -out private_pkcs8.key
# Base64 encode the private key for configuration
printf "%s" "$(< private_pkcs8.key)" | base64Configure in Identity Authentication:
- Go to application → SAML 2.0 Configuration
- Set Require signed authentication requests to ON
- Upload certificate in the Signing Certificate section
- Provide the signing key to
sp.signature_private_keyfield - Set
sp.signature_private_key_passwordif the key is encrypted
Warning: Expired signing certificates cause login failures with message: "The digital signature of the received SAML2 message is invalid."
OPTION 2: Manual Endpoint Configuration
Only available after creating a Cloud Logging instance. Must be repeated for each new instance.
- Go to application → SAML 2.0 Configuration → Configure Manually
- Set Assertion Consumer Service Endpoint:
<dashboards-url>/_opendistro/_security/saml/acs - Set Single Logout Endpoint:
- Binding:
HTTP_REDIRECT - URL:
<dashboards-url>(no path)
- Binding:
- Click Save
Step 5: Create Access Group
- In Identity Authentication, go to Users & Authorizations → User Groups
- Create a group (e.g.,
CLS-Administrators) - Add users who need dashboard access
Important: The group configured as admin_group in Cloud Logging automatically maps to the all_access role in OpenSearch.
Step 6: Configure Cloud Logging Instance
Update your Cloud Logging instance with SAML parameters using the official nested structure:
{
"saml": {
"enabled": true,
"initiated": true,
"admin_group": "CLS-Administrators",
"roles_key": "groups",
"idp": {
"metadata_url": "https://<tenant-id>.accounts.ondemand.com/saml2/metadata",
"entity_id": "https://<tenant-id>.accounts.ondemand.com"
},
"sp": {
"entity_id": "cloud-logging-<unique-identifier>"
}
}
}With request signing (Option 1):
{
"saml": {
"enabled": true,
"initiated": true,
"admin_group": "CLS-Administrators",
"roles_key": "groups",
"idp": {
"metadata_url": "https://<tenant-id>.accounts.ondemand.com/saml2/metadata",
"entity_id": "https://<tenant-id>.accounts.ondemand.com"
},
"sp": {
"entity_id": "cloud-logging-<unique-identifier>",
"signature_private_key": "<base64-encoded-pkcs8-private-key>",
"signature_private_key_password": ""
}
}
}SAML Parameter Reference (Official Nested Structure)
Required Parameters (when enabled: true)
| Parameter | Type | Conditional | Description |
|---|---|---|---|
enabled |
boolean | Yes | Enable SAML authentication |
initiated |
boolean | Required if enabled | Enable IdP-initiated SSO |
admin_group |
string | Required if enabled | Group mapped to all_access role |
roles_key |
string | Required if enabled | Attribute for backend_roles during login |
idp.metadata_url |
string | Required if enabled | Identity Provider metadata URL |
idp.entity_id |
string | Required if enabled | Entity ID from metadata's entityID field |
sp.entity_id |
string | Required if enabled | Service Provider application name in IdP |
Optional Parameters (Request Signing)
| Parameter | Type | Description |
|---|---|---|
sp.signature_private_key |
string | Base64-encoded PKCS#8 private key |
sp.signature_private_key_password |
string | Password for encrypted private key |
Note: Identity Authentication group names are forwarded to OpenSearch as backend roles, which map to OpenSearch roles granting permissions.
Role Mapping
Default Role Mapping
| Group | OpenSearch Role |
|---|---|
admin_group value |
all_access |
| Other groups | Configurable via OpenSearch Security |
Custom Role Mapping
After SAML setup, configure additional role mappings in OpenSearch Dashboards:
- Go to Security → Roles
- Create custom roles with specific index permissions
- Go to Security → Role Mappings
- Map SAML groups to OpenSearch roles
Example custom role for read-only access:
role_name: cls_readonly
cluster_permissions:
- cluster_composite_ops_ro
index_permissions:
- index_patterns:
- "logs-*"
- "metrics-*"
allowed_actions:
- readTroubleshooting
Login Fails with "Invalid SAML Response"
- Verify
idp_entity_idmatches metadata exactly - Check
sp_entity_idis unique - Ensure clock sync between IdP and Cloud Logging
- Validate certificate hasn't expired
User Not Authorized
- Verify user is in the configured
admin_group - Check group attribute is being sent in SAML assertion
- Confirm
roles_keymatches the attribute name (groups)
IdP Metadata URL Not Accessible
- Check URL is publicly accessible
- Verify network connectivity from Cloud Logging
- Try downloading metadata manually and hosting it
Request Signing Errors
- Ensure private key is PKCS#8 format
- Verify base64 encoding is correct (no headers)
- Check certificate matches private key
- Confirm certificate is uploaded to IdP
IdP-Initiated SSO Not Working
- Set
idp_initiated_sso: true - Configure correct Relay State in IdP
- Verify SP Entity ID matches
Security Best Practices
- Enable request signing for production environments
- Rotate signing certificates annually
- Use dedicated group for Cloud Logging admins
- Implement least privilege with custom role mappings
- Review access periodically
- Enable audit logging in Identity Authentication
Complete Configuration Example
Identity Authentication Application Settings
| Setting | Value |
|---|---|
| Application Type | SAML 2.0 |
| Name ID Format | |
| Assertion Consumer Service | https://dashboards.cls.example.com/_opendistro/_security/saml/acs |
| SP Entity ID | cloud-logging-prod-001 |
| Sign SAML Requests | Enabled |
| Groups Attribute | groups |
Cloud Logging Instance Configuration
{
"retention_period": 14,
"saml": {
"enabled": true,
"initiated": true,
"admin_group": "CLS-Administrators",
"roles_key": "groups",
"idp": {
"metadata_url": "https://mytenant.accounts.ondemand.com/saml2/metadata",
"entity_id": "https://mytenant.accounts.ondemand.com"
},
"sp": {
"entity_id": "cloud-logging-prod-001",
"signature_private_key": "MIIEvgIBADANBg...",
"signature_private_key_password": ""
}
}
}Documentation Links
- Source: https://raw.githubusercontent.com/SAP-docs/btp-cloud-logging/main/docs/prerequisites-41d8559.md
- SAP Cloud Identity Services: https://help.sap.com/docs/cloud-identity
- Identity Authentication Admin Guide: https://help.sap.com/docs/identity-authentication
- OpenSearch Security: https://opensearch.org/docs/latest/security/