# Github URL to set on op.jwkset\_path parameter

**URL:** <https://discuss.elastic.co/t/github-url-to-set-on-op-jwkset-path-parameter/291474>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [December 10, 2021, 9:27pm UTC](https://discuss.elastic.co/t/github-url-to-set-on-op-jwkset-path-parameter/291474 "2021-12-10T21:27:05Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fabio\_Peruchi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fabio_peruchi/32/98724_2.png) [@Fabio\_Peruchi](https://discuss.elastic.co/u/Fabio_Peruchi)\
**Post date:** [December 10, 2021, 9:27pm UTC](https://discuss.elastic.co/t/github-url-to-set-on-op-jwkset-path-parameter/291474/1 "2021-12-10T21:27:05Z")

</div>

Hello.

I'm struggling to find where is the GitHub URL to set here on this parameter from this documentation: [Configuring single sign-on to the Elastic Stack using OpenID Connect | Elasticsearch Guide [7.16] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.16/oidc-guide.html#oidc-create-realm)

```auto
op.jwkset_path

The path to a file or a URL containing a JSON Web Key Set with the key material that the OpenID Connect Provider uses for signing tokens and claims responses. If a path is set, it is resolved relative to the Elasticsearch config directory. Elasticsearch will automatically monitor this file for changes and will reload the configuration whenever it is updated. Your OpenID Connect Provider should provide you with this file or a URL where it is available.

```

My Elasticsearch and Kibana instances are running on [https://elastic.co](https://elastic.co)

Please, could you help me?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 10, 2021, 9:31pm UTC](https://discuss.elastic.co/t/github-url-to-set-on-op-jwkset-path-parameter/291474/2 "2021-12-10T21:31:08Z")

</div>

Welcome to our community! 😃

It's not clear what you think GitHub has to do with this, there's no mention of it in that document link.

---

<div class="post-metadata">

**Author:** ![Fabio\_Peruchi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fabio_peruchi/32/98724_2.png) [@Fabio\_Peruchi](https://discuss.elastic.co/u/Fabio_Peruchi)\
**Post date:** [December 10, 2021, 9:36pm UTC](https://discuss.elastic.co/t/github-url-to-set-on-op-jwkset-path-parameter/291474/3 "2021-12-10T21:36:30Z")

</div>

_Your OpenID Connect Provider should provide you with this file or a URL where it is available._

I've created an GitHub OAuth App on GitHub to use as my OpenID Connect Provider, but I can't find this file or URL to use on this **op.jwkset\_path** parameter.

ES configuration I'm adding.

```auto
xpack.security.authc.realms.oidc.oidc1:
  order: 2
  rp.client_id: "xxxxxxxxxxxx"
  rp.response_type: code
  rp.redirect_uri: "https://pathable-cosmos.kb.us-east-1.aws.found.io:9243/api/security/oidc/callback"
  op.issuer: "https://github.com"
  op.authorization_endpoint: "https://github.com/login/oauth/authorize"
  op.token_endpoint: "https://github.com/login/oauth/access_token"
  op.jwkset_path: <NEED TO FIND IT>
  claims.principal: email_verified

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/5/359ebe0f61b530c8695001c44bc82ea0bae5ab8f.png)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 10, 2021, 9:42pm UTC](https://discuss.elastic.co/t/github-url-to-set-on-op-jwkset-path-parameter/291474/4 "2021-12-10T21:42:42Z")

</div>

Right, so you want to use GitHub as the auth provider?

---

<div class="post-metadata">

**Author:** ![Fabio\_Peruchi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fabio_peruchi/32/98724_2.png) [@Fabio\_Peruchi](https://discuss.elastic.co/u/Fabio_Peruchi)\
**Post date:** [December 10, 2021, 9:45pm UTC](https://discuss.elastic.co/t/github-url-to-set-on-op-jwkset-path-parameter/291474/5 "2021-12-10T21:45:29Z")

</div>

Exactly @warkolm . My goal is to have it on Kibana for the employees from company login with their GitHub users restrict to users that are inside my GitHub organization [pathable](https://github.com/pathable).

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [December 13, 2021, 8:12am UTC](https://discuss.elastic.co/t/github-url-to-set-on-op-jwkset-path-parameter/291474/6 "2021-12-13T08:12:38Z")

</div>

Hi @Fabio_Peruchi . Unfortunately, Github does not support OpenID Connect, they have instead built their own authentication protocol on top of oAuth2, which is "close to" but "not exactly" OpenID Connect. As such, you can't use the OpenID Connect realm of Elasticsearch to authenticate your users via Github.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 10, 2022, 8:12am UTC](https://discuss.elastic.co/t/github-url-to-set-on-op-jwkset-path-parameter/291474/7 "2022-01-10T08:12:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
