# Cannot configure Open ID Connect - cant store key in elastic keystore for persistent usage

**URL:** <https://discuss.elastic.co/t/cannot-configure-open-id-connect-cant-store-key-in-elastic-keystore-for-persistent-usage/250099>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security, docker\
**Created:** [September 27, 2020, 6:23pm UTC](https://discuss.elastic.co/t/cannot-configure-open-id-connect-cant-store-key-in-elastic-keystore-for-persistent-usage/250099 "2020-09-27T18:23:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dorinand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dorinand/32/70521_2.png) [@dorinand](https://discuss.elastic.co/u/dorinand)\
**Post date:** [September 27, 2020, 6:23pm UTC](https://discuss.elastic.co/t/cannot-configure-open-id-connect-cant-store-key-in-elastic-keystore-for-persistent-usage/250099/1 "2020-09-27T18:23:31Z")

</div>

I am trying to configure OIDC according to documentation. According to [instructions](https://www.elastic.co/guide/en/elasticsearch/reference/7.8/oidc-guide-authentication.html#oidc-create-realm), I have to store `xpack.security.authc.realms.oidc.oidc1.rp.client_secret` into keystore.

> bin/elasticsearch-keystore add xpack.security.authc.realms.oidc.oidc1.rp.client\_secret

This works fine, except, when I restart my elasticsearch I will lost my secret stored in keystore.

I google little bit, and find this [issue](https://github.com/bitnami/bitnami-docker-elasticsearch/issues/84). According to solution, which was already merged, I should be able to add values to keystore via `ELASTICSEARCH_KEYS` variable. I tested it on elastic `7.8.1`, `7.9.1` and `7.9.2`, none of them works properly. Env variable `ELASTICSEARCH_KEYS` is present with right values.

Right now, I am running Elasticsearch `7.8.1` in Kubernetes, and my tests I performed locally runs in docker.

How can I settle up OIDC right now, what are my options?  
Why `ELASTICSEARCH_KEYS` variable does not work? From comments, they fixed it for versions `7.X`.

Thank you.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [October 1, 2020, 3:37pm UTC](https://discuss.elastic.co/t/cannot-configure-open-id-connect-cant-store-key-in-elastic-keystore-for-persistent-usage/250099/2 "2020-10-01T15:37:47Z")

</div>

See [https://www.elastic.co/guide/en/elasticsearch/reference/master/docker.html#docker-keystore-bind-mount](https://www.elastic.co/guide/en/elasticsearch/reference/master/docker.html#docker-keystore-bind-mount), you can pre-create the elasticsearch keystore, add the client\_secret to it and then bind mount it to your container.

---

<div class="post-metadata">

**Author:** ![dorinand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dorinand/32/70521_2.png) [@dorinand](https://discuss.elastic.co/u/dorinand)\
**Post date:** [October 6, 2020, 9:09am UTC](https://discuss.elastic.co/t/cannot-configure-open-id-connect-cant-store-key-in-elastic-keystore-for-persistent-usage/250099/3 "2020-10-06T09:09:36Z")

</div>

I solved it by using [helm chart](https://github.com/elastic/helm-charts). For Elasticsearch, there is section [How to use the keystore](https://github.com/elastic/helm-charts/blob/master/elasticsearch/README.md#how-to-use-the-keystore).

---

<div class="post-metadata">

**Author:** ![dorinand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dorinand/32/70521_2.png) [@dorinand](https://discuss.elastic.co/u/dorinand)\
**Post date:** [October 6, 2020, 9:11am UTC](https://discuss.elastic.co/t/cannot-configure-open-id-connect-cant-store-key-in-elastic-keystore-for-persistent-usage/250099/4 "2020-10-06T09:11:52Z")

</div>

@ikakavas thank you for you reply. I did not try your solution, because I fix it with helm value `keystore`. But this should works too.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2020, 9:11am UTC](https://discuss.elastic.co/t/cannot-configure-open-id-connect-cant-store-key-in-elastic-keystore-for-persistent-usage/250099/5 "2020-11-03T09:11:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
