# Configure Elasticsearch to use SSO by OIDC - Groups claim is not mapped correctly

**URL:** <https://discuss.elastic.co/t/configure-elasticsearch-to-use-sso-by-oidc-groups-claim-is-not-mapped-correctly/285134>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 25, 2021, 12:28pm UTC](https://discuss.elastic.co/t/configure-elasticsearch-to-use-sso-by-oidc-groups-claim-is-not-mapped-correctly/285134 "2021-09-25T12:28:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ismaeel\_Enjreny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ismaeel_enjreny/32/69578_2.png) [@Ismaeel\_Enjreny](https://discuss.elastic.co/u/Ismaeel_Enjreny)\
**Post date:** [September 25, 2021, 12:28pm UTC](https://discuss.elastic.co/t/configure-elasticsearch-to-use-sso-by-oidc-groups-claim-is-not-mapped-correctly/285134/1 "2021-09-25T12:28:20Z")

</div>

We are trying to configure Elasticsearch so uses can login using SSO feature based on oidc protocol, everything is working fine till we tried to map claims.groups.

The Identity Provider send groups as JSON array but it seems Elasticsearch expects it as string, here Elasticsearch throws the following error when it tries to get user information from UserInfo end point

`Caused by: java.lang.IllegalStateException: Error merging ID token and userinfo claim value for claim [groups]. Cannot merge [com.nimbusds.jose.shaded.json.JSONArray] with [java.lang.String]`

The configuration we have is as following

```auto
xpack.security.authc.realms.oidc.oidc1:
  order: 2
  rp.client_id: "HT57sBPfQCVUnT1P8U34kmkL0gAa"
  rp.response_type: code
  rp.redirect_uri: "http://localhost:5601/api/security/oidc/callback"
  op.issuer: "https://localhost:9443/oauth2/token"
  op.authorization_endpoint: "https://localhost:9443/oauth2/authorize"
  op.token_endpoint: "https://localhost:9443/oauth2/token"
  op.jwkset_path: "https://localhost:9443/oauth2/jwks"
  op.userinfo_endpoint: "https://localhost:9443/oauth2/userinfo"
  op.endsession_endpoint: "https://localhost:9443/oidc/logout"
  rp.post_logout_redirect_uri: "http://localhost:5601/security/logged_out"
  ssl.certificate_authorities: ["oidc/wso2carbon.cer"]
  claims.principal: sub
  claims.groups: groups
  claims.name: name
  claims.mail: email

```

We can't change the identity provider to return string because it is ready made product, what do you suggest to resolve this issue and what the exact format which is expected by Elasticsearch to map groups claim correctly (i.e. group1,group2,...)

Thanks

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [September 28, 2021, 10:06am UTC](https://discuss.elastic.co/t/configure-elasticsearch-to-use-sso-by-oidc-groups-claim-is-not-mapped-correctly/285134/2 "2021-09-28T10:06:43Z")

</div>

> [@Ismaeel\_Enjreny](#):
>
> The Identity Provider send groups as JSON array but it seems Elasticsearch expects it as string,

The OP sends an array in the ID token and a string in the userinfo endpoint response, and elasticsearch doesn't know how it is supposed to merge these. Can't you configure the OP to send the same type of value for the `groups` claim in both the ID token and the response of the Userinfo endpoint ?

Alternatively, if all information you need is in the ID token and you _don't have to_ query the userinfo endpoint, you can remove the

```auto
op.userinfo_endpoint: "https://localhost:9443/oauth2/userinfo"

```

line from your configuration entirely.

---

<div class="post-metadata">

**Author:** ![Ismaeel\_Enjreny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ismaeel_enjreny/32/69578_2.png) [@Ismaeel\_Enjreny](https://discuss.elastic.co/u/Ismaeel_Enjreny)\
**Post date:** [September 28, 2021, 10:51am UTC](https://discuss.elastic.co/t/configure-elasticsearch-to-use-sso-by-oidc-groups-claim-is-not-mapped-correctly/285134/3 "2021-09-28T10:51:49Z")

</div>

Thanks ikakavas, after commenting the line every is working fine

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 26, 2021, 10:52am UTC](https://discuss.elastic.co/t/configure-elasticsearch-to-use-sso-by-oidc-groups-claim-is-not-mapped-correctly/285134/4 "2021-10-26T10:52:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
