# Elastic Stack OIDC Google

**URL:** <https://discuss.elastic.co/t/elastic-stack-oidc-google/251898>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [October 13, 2020, 12:06pm UTC](https://discuss.elastic.co/t/elastic-stack-oidc-google/251898 "2020-10-13T12:06:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bjoern\_Boschman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bjoern_boschman/32/77086_2.png) [@Bjoern\_Boschman](https://discuss.elastic.co/u/Bjoern_Boschman)\
**Post date:** [October 13, 2020, 12:06pm UTC](https://discuss.elastic.co/t/elastic-stack-oidc-google/251898/1 "2020-10-13T12:06:33Z")

</div>

Hi,

I'm trying to get OIDC integration with google working without any success for quite some time.  
Im using Elastic Stack as a Service

First I configured within Elasticsearch keystore:  
`xpack.security.authc.realms.oidc.google.rp.client_secret`

Then I added the following config to all ES and the ML configurations:

> ```
> > xpack.security.authc.realms.oidc.google:
> > order: 2
> > rp.client_id: "my-client-id.apps.googleusercontent.com"
> > rp.response_type: code
> > rp.redirect_uri: "https://my-kibana.us-east-2.aws.elastic-cloud.com:9243/api/security/oidc/callback"
> > op.issuer: "https://accounts.google.com"
> > op.authorization_endpoint: "https://accounts.google.com/o/oauth2/v2/auth"
> > op.token_endpoint: "https://oauth2.googleapis.com/token"
> > op.jwkset_path: "https://www.googleapis.com/oauth2/v3/certs"
> > op.userinfo_endpoint: "https://openidconnect.googleapis.com/v1/userinfo"
> > claims.principal: "sub"
> 
> ```

And this config to kibana:

> ```
> > xpack.security.authc.providers:
> > oidc.oidc1:
> > order: 0
> > realm: google
> > description: "Log in with Google" 
> 
> ```

Yet I get a 401 with this message:

> [security\_exception] unable to authenticate user [] for action [cluster:admin/xpack/security/oidc/authenticate], with { header={ WWW-Authenticate={ 0="Bearer realm=\"security\"" & 1="ApiKey" & 2="Basic realm=\"security\" charset=\"UTF-8\"" } } }

I've seen some threads about having a wrong claims.principal - I tested with "sub" and "email"  
Google does not provide a claim for group mapping. Yet I tested with claims.groups: "", "groups" or removed that claim mapping

No idea where to go from here  
As a side note: from a product mgmt point of view I guess it might be interesting to ease OIDC integration for common providers (google, microsoft, github)  
`

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [October 13, 2020, 2:53pm UTC](https://discuss.elastic.co/t/elastic-stack-oidc-google/251898/2 "2020-10-13T14:53:54Z")

</div>

Your elasticsearch logs will contain more information about why the failure happens

Have you seen our [docs](https://www.elastic.co/guide/en/cloud/current/ec-secure-clusters-oidc.html) and [this blogpost](https://www.elastic.co/blog/how-to-set-up-openid-connect-on-elastic-cloud-with-azure-google-okta#google) that describes the steps for setting up OIDC with google in detail ?

> As a side note: from a product mgmt point of view I guess it might be interesting to ease OIDC integration for common providers (google, microsoft, github)

Thanks for the feedback! The blogpost should cover google and microsoft. Github is not an OpenID Connect provider unfortunately, they have their own bespoke protocol based on oAuth2.

---

<div class="post-metadata">

**Author:** ![Bjoern\_Boschman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bjoern_boschman/32/77086_2.png) [@Bjoern\_Boschman](https://discuss.elastic.co/u/Bjoern_Boschman)\
**Post date:** [October 26, 2020, 12:28pm UTC](https://discuss.elastic.co/t/elastic-stack-oidc-google/251898/3 "2020-10-26T12:28:39Z")

</div>

sry for the late reply  
that blogpost was the solution! thank you very much!!  
You should consider adding that information to the documentation

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 23, 2020, 12:28pm UTC](https://discuss.elastic.co/t/elastic-stack-oidc-google/251898/4 "2020-11-23T12:28:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
