# Elastic Cloud OIDC error

**URL:** <https://discuss.elastic.co/t/elastic-cloud-oidc-error/265200>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [February 23, 2021, 12:05pm UTC](https://discuss.elastic.co/t/elastic-cloud-oidc-error/265200 "2021-02-23T12:05:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Basilis\_Ch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/basilis_ch/32/78997_2.png) [@Basilis\_Ch](https://discuss.elastic.co/u/Basilis_Ch)\
**Post date:** [February 23, 2021, 12:05pm UTC](https://discuss.elastic.co/t/elastic-cloud-oidc-error/265200/1 "2021-02-23T12:05:41Z")

</div>

Using ES 7.10 7.10.1 and 7.10.2 in different clusters, I received below errors applying known working configs with Azure AD realm exposed via OIDC.

`[instance-0000000009] Received Token Response from OP with status [UNAUTHORIZED] and content [{"error":"invalid_client","error_description":"AADSTS7000215: Invalid client secret is provided.\r\nTrace ID: d22a48a9-9da8-444d-9834-8b57ad290100\r\nCorrelation ID: 5c7ea5ff-04df-4e1a-aba6-59494c567d37\r\nTimestamp: 2021-02-23 11:56:14Z","error_codes":[7000215],"timestamp":"2021-02-23 11:56:14Z","trace_id":"d22a48a9-9da8-444d-9834-8b57ad290100","correlation_id":"5c7ea5ff-04df-4e1a-aba6-59494c567d37","error_uri":"https://login.microsoftonline.com/error?code=7000215"}]`

`[instance-0000000009] Received Token Response from OP with status [UNAUTHORIZED] and content [{"error":"invalid_client","error_description":"AADSTS7000215: Invalid client secret is provided.\r\nTrace ID: d22a48a9-9da8-444d-9834-8b57ad290100\r\nCorrelation ID: 5c7ea5ff-04df-4e1a-aba6-59494c567d37\r\nTimestamp: 2021-02-23 11:56:14Z","error_codes":[7000215],"timestamp":"2021-02-23 11:56:14Z","trace_id":"d22a48a9-9da8-444d-9834-8b57ad290100","correlation_id":"5c7ea5ff-04df-4e1a-aba6-59494c567d37","error_uri":"https://login.microsoftonline.com/error?code=7000215"}]`

The client secret is doubled checked to be the correct one.

Here is my config inside elasticsearch.yml

```auto
xpack:
  security:
    authc:
      realms:
        oidc:
          aad:
            order: 2
            rp.client_id: "xxxx"
            rp.response_type: "code"
            rp.requested_scopes: ["openid", "email"]
            rp.redirect_uri: "https://xxxx.eastus2.azure.elastic-cloud.com:9243/api/security/v1/oidc"
            op.issuer: "https://login.microsoftonline.com/xxxxx/v2.0"
            op.authorization_endpoint: "https://login.microsoftonline.com/xxxxx/oauth2/v2.0/authorize"
            op.token_endpoint: "https://login.microsoftonline.com/xxxxx/oauth2/v2.0/token"
            op.userinfo_endpoint: "https://graph.microsoft.com/oidc/userinfo"
            op.endsession_endpoint: "https://login.microsoftonline.com/xxxxx/oauth2/v2.0/logout"
            rp.post_logout_redirect_uri: "https://xxxxx.eastus2.azure.elastic-cloud.com:9243/logged_out"
            op.jwkset_path: "https://login.microsoftonline.com/xxxxx/discovery/v2.0/keys"
            claims.principal: name
            claims.groups: groups

```

kibana.yml

```auto
  xpack.security.authc.providers:
  oidc.aad:
    order: 0
    realm: aad
    icon: "https://aadcdn.msauth.net/shared/1.0/content/images/microsoft_logo_ee5c8d9fb6248c938fd0dc19370e90bd.svg"
    description: "Log in with Azure"
  basic.basic1:
    order: 1

```

---

<div class="post-metadata">

**Author:** ![jportner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jportner/32/75692_2.png) [@jportner](https://discuss.elastic.co/u/jportner)\
**Post date:** [February 23, 2021, 9:40pm UTC](https://discuss.elastic.co/t/elastic-cloud-oidc-error/265200/2 "2021-02-23T21:40:38Z")

</div>

> [@Basilis\_Ch](#):
>
> Using ES 7.10 7.10.1 and 7.10.2 in different clusters, I received below errors applying known working configs with Azure AD realm exposed via OIDC.

Are you saying that this config used to work in an older deployment? If so, what stack version(s) were you using before?

> [@Basilis\_Ch](#):
>
> The client secret is doubled checked to be the correct one.

I don't see the `xpack.security.authc.realms.oidc.aad.rp.client_secret` setting in your config. Did you add a [secret value](https://www.elastic.co/guide/en/cloud/current/ec-configuring-keystore.html) for your deployment?

If so, did you double-check your client\_id to make sure it matches the client secret?

---

<div class="post-metadata">

**Author:** ![Basilis\_Ch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/basilis_ch/32/78997_2.png) [@Basilis\_Ch](https://discuss.elastic.co/u/Basilis_Ch)\
**Post date:** [February 24, 2021, 8:43am UTC](https://discuss.elastic.co/t/elastic-cloud-oidc-error/265200/3 "2021-02-24T08:43:27Z")

</div>

I have added yes my secret value and it is doubled checked to be correct.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 24, 2021, 8:43am UTC](https://discuss.elastic.co/t/elastic-cloud-oidc-error/265200/4 "2021-03-24T08:43:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
