# Elastic OpenID Keyclock failed cannot find realm

**URL:** <https://discuss.elastic.co/t/elastic-openid-keyclock-failed-cannot-find-realm/354403>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [February 29, 2024, 5:42am UTC](https://discuss.elastic.co/t/elastic-openid-keyclock-failed-cannot-find-realm/354403 "2024-02-29T05:42:20Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 29, 2024, 9:03am UTC](https://discuss.elastic.co/t/elastic-openid-keyclock-failed-cannot-find-realm/354403/4 "2024-02-29T09:03:46Z")

</div>

Unfortunately, I / we are not experts on Keycloak portion

did you try setting the realm name in keycloak to `oidc1` as it is defined in elasticsearch.yml perhaps they need to be consistent

You can up the logging with

```auto
 PUT /_cluster/settings
 {
   "transient": {
     "logger.org.elasticsearch.xpack.security.authc.oidc": "trace"
   }
 }

```

There is also some advice here

> [@Unable to configure oidc](https://discuss.elastic.co/t/unable-to-configure-oidc/234821):
>
> we are trying to setup elasticsearch to use oidc for authentication here is my yaml file xpack.security.authc.token.enabled: true xpack.security.authc.realms.oidc.oidc1: order: 1 rp.client\_id: "6bd9f9a3-67a3-4392-b29c-675c16b818e9" rp.response\_type: "code" rp.redirect\_uri: "https://\<Kibana-Host\>/api/security/oidc/callback" op.issuer: "https://\<Login-Provider\>" op.authorization\_endpoint: "https://\<Login-Provider\>/oauth2/v2.0/authorize" op.t…

> [@Authentication failed for an OpenID integration](https://discuss.elastic.co/t/authentication-failed-for-an-openid-integration/220390):
>
> Hello, I am using OIDC with Elasticsearch and Kibana. My configuration is as follows: xpack.security.enabled: true xpack.security.transport.ssl.enabled: true xpack.security.transport.ssl.verification\_mode: certificate xpack.security.transport.ssl.keystore.path: elastic-certificates.p12 xpack.security.transport.ssl.truststore.path: elastic-certificates.p12 xpack.security.http.ssl.enabled: true xpack.security.http.ssl.keystore.path: elastic-stack-ca.p12 xpack.security.http.ssl.truststore.path: …

Post some of the additional logs and perhaps we can help.

I also notice that you elasticsearch.yml definitions do not follow the same patterns as in our example...

```auto
xpack.security.authc.realms.oidc.oidc1:
  order: 2
  rp.client_id: "the_client_id"
  rp.response_type: code
  rp.redirect_uri: "https://kibana.example.org:5601/api/security/oidc/callback"
  op.issuer: "https://op.example.org"
  op.authorization_endpoint: "https://op.example.org/oauth2/v1/authorize"
  op.token_endpoint: "https://op.example.org/oauth2/v1/token"
  op.jwkset_path: oidc/jwkset.json
  op.userinfo_endpoint: "https://op.example.org/oauth2/v1/userinfo"
  op.endsession_endpoint: "https://op.example.org/oauth2/v1/logout"
  rp.post_logout_redirect_uri: "https://kibana.example.org:5601/security/logged_out"
  claims.principal: sub
  claims.groups: "http://example.info/claims/groups"`

```

I am not an expert on that portion but what you have does not seem to follow the patterns but perhaps you are more of the expert

Example from [here](https://www.elastic.co/guide/en/elasticsearch/reference/8.12/oidc-guide.html)

---

_[View the full topic](https://discuss.elastic.co/t/elastic-openid-keyclock-failed-cannot-find-realm/354403)._
