# Getting 403 forbidden error on User authentication with OpenID connect

**URL:** <https://discuss.elastic.co/t/getting-403-forbidden-error-on-user-authentication-with-openid-connect/218120>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [February 6, 2020, 9:03am UTC](https://discuss.elastic.co/t/getting-403-forbidden-error-on-user-authentication-with-openid-connect/218120 "2020-02-06T09:03:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![piyush\_kashyap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/piyush_kashyap/32/62160_2.png) [@piyush\_kashyap](https://discuss.elastic.co/u/piyush_kashyap)\
**Post date:** [February 6, 2020, 9:03am UTC](https://discuss.elastic.co/t/getting-403-forbidden-error-on-user-authentication-with-openid-connect/218120/1 "2020-02-06T09:03:04Z")

</div>

I am trying to authenticate kibana users using OpenID connect and I am getting 403 forbidden error.  
Please find below the **realm configuration** :-  
xpack.security.authc.realms.oidc.cloud-oidc:  
order: 0  
rp.client\_id: ""  
rp.response\_type: code  
rp.redirect\_uri: "[https://localhost:5601/api/security/v1/oidc](https://localhost:5601/api/security/v1/oidc)"  
op.issuer: "[https://cognito-idp.us-east-1.amazonaws.com/us-east-1\_bBxqRAHER](https://cognito-idp.us-east-1.amazonaws.com/us-east-1_bBxqRAHER)"  
op.authorization\_endpoint: "[https://chatbot-users.auth.us-east-1.amazoncognito.com/oauth2/authorize](https://chatbot-users.auth.us-east-1.amazoncognito.com/oauth2/authorize)"  
op.token\_endpoint: "[https://chatbot-users.auth.us-east-1.amazoncognito.com/oauth2/token](https://chatbot-users.auth.us-east-1.amazoncognito.com/oauth2/token)"  
op.jwkset\_path: [https://cognito-idp.us-east-1.amazonaws.com/us-east-1\_bBxqRAHER/.well-known/jwks.json](https://cognito-idp.us-east-1.amazonaws.com/us-east-1_bBxqRAHER/.well-known/jwks.json)  
// op.userinfo\_endpoint: "[https://chatbot-users.auth.us-east-1.amazoncognito.com/oauth2/userInfo](https://chatbot-users.auth.us-east-1.amazoncognito.com/oauth2/userInfo)"  
op.endsession\_endpoint: "[https://chatbot-users.auth.us-east-1.amazoncognito.com/logout](https://chatbot-users.auth.us-east-1.amazoncognito.com/logout)"  
rp.post\_logout\_redirect\_uri: "[https://localhost:5601/logged\_out](https://localhost:5601/logged_out)"  
claims.principal: sub  
claims.groups: "cognito:groups"

**Elasticsearch logs:-**  
OpenID Connect Provider redirected user to [/api/security/v1/oidc?code=]  
[2020-02-06T13:57:06,502][TRACE][o.e.x.s.a.o.OpenIdConnectAuthenticator] [node-1] Received Token Response from OP with status [200] and content [{"id\_token":"","expires\_in":3600,"token\_type":"Bearer"}]  
[2020-02-06T13:57:06,526][TRACE][o.e.x.s.a.o.OpenIdConnectAuthenticator] [node-1] Successfully exchanged code for ID Token: [com.nimbusds.jwt.SignedJWT@15333bdc] and Access Token []  
[2020-02-06T13:57:06,560][TRACE][o.e.x.s.a.o.OpenIdConnectAuthenticator] [node-1] Received and validated the Id Token for the user: [{"at\_hash":"SOt6DfjuG3jjIBf00BSRig","sub":"","cognito:groups":["kibana-users"],"email\_verified":true,"iss":"[https://cognito-idp.us-east-1.amazonaws.com/us-east-1\_bBxqRAHER","cognito:username":"piyush.a.kashyap","nonce":"](https://cognito-idp.us-east-1.amazonaws.com/us-east-1_bBxqRAHER%22,%22cognito:username%22:%22piyush.a.kashyap%22,%22nonce%22:%22)","cognito:roles":["arn:aws:iam:::role/cognito\_authenticated"],"aud":"","token\_use":"id","auth\_time":1580977626,"exp":1580981226,"iat":1580977626,"email":"piyush.a.kashyap@organization.com"}]  
[2020-02-06T13:57:06,561][DEBUG][o.e.x.s.a.o.OpenIdConnectAuthenticator] [node-1] OP returned an access token but the UserInfo endpoint is not configured.

**Role mapping:-**  
curl --user elastic:123456 -X PUT "localhost:9200/\_security/role\_mapping/cloud-oidc?pretty" -H 'Content-Type: application/json' -d'  
{  
"roles": ["kibana\_dashboard\_only\_user"],  
"enabled": true,  
"rules": { "all": [  
{ "field": { "realm.name": "cloud-oidc" } },  
{ "field": { "groups": "cognito:groups" } }  
] }  
}  
'

Please let me know if there is any issue in the configuration...

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [February 6, 2020, 9:19am UTC](https://discuss.elastic.co/t/getting-403-forbidden-error-on-user-authentication-with-openid-connect/218120/2 "2020-02-06T09:19:02Z")

</div>

> [@piyush\_kashyap](#):
>
> claims.groups: "cognito:groups"

Tells elasticsearch to map the values of the `claim` with name `cognito:groups` to the `groups` property of the elasticsearch user.  
By that effect , your authenticating user has a `groups` user property that has the value `kibana-users` , as this is the value of the `cognito:groups` claim.

Role mappings now, work with user properties, so you need a rule that says that whoever has a value `kibana-users` in their `groups` user property, should get the roles.

In summary, you need to change

```auto
{ "field": { "groups": "cognito:groups" } }

```

to

```auto
{ "field": { "groups": "kibana-users" } }

```

---

<div class="post-metadata">

**Author:** ![piyush\_kashyap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/piyush_kashyap/32/62160_2.png) [@piyush\_kashyap](https://discuss.elastic.co/u/piyush_kashyap)\
**Post date:** [February 7, 2020, 6:33am UTC](https://discuss.elastic.co/t/getting-403-forbidden-error-on-user-authentication-with-openid-connect/218120/3 "2020-02-07T06:33:02Z")

</div>

Thanks ikakavas, It worked 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 6, 2020, 6:33am UTC](https://discuss.elastic.co/t/getting-403-forbidden-error-on-user-authentication-with-openid-connect/218120/4 "2020-03-06T06:33:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
