# Kibana giving unauthenticated first time but allowing to login second time in same session

**URL:** https://discuss.elastic.co/t/kibana-giving-unauthenticated-first-time-but-allowing-to-login-second-time-in-same-session/344984
**Category:** Elastic Security
**Created:** [October 13, 2023, 10:24am UTC](https://discuss.elastic.co/t/kibana-giving-unauthenticated-first-time-but-allowing-to-login-second-time-in-same-session/344984 "2023-10-13T10:24:15Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![amitkumar.gupta](https://avatars.discourse-cdn.com/v4/letter/a/ee7513/32.png) [@amitkumar.gupta](https://discuss.elastic.co/u/amitkumar.gupta)
#### Post date: [October 13, 2023, 10:24am UTC](https://discuss.elastic.co/t/kibana-giving-unauthenticated-first-time-but-allowing-to-login-second-time-in-same-session/344984/1 "2023-10-13T10:24:15Z")

</div>

I have enabled Kibana login from wso2 API manager.

below I have provided Elastic configuration file.

I am following instruction to configure wso2 and kibana- [https://shanchathusanda.medium.com/log-in-to-elastic-stack-with-wso2-identity-server-with-oauth2-oidc-82944204efaf](https://shanchathusanda.medium.com/log-in-to-elastic-stack-with-wso2-identity-server-with-oauth2-oidc-82944204efaf)

But when i login on Kibana first time i am getting unauthenticate error, when i try to login second time in same session, that is sucessfull login.

Not sure what is happening first time.

I have provided logs below, Please help.

Elastic version - 8.6.1

HAR file when user unauthenticated in browser -

Elastic logs -

[2023-10-13T05:10:06.822-05:00][INFO][plugins.security.routes] Logging in with provider "oidc1" (oidc)  
[2023-10-13T05:10:17,633][TRACE][o.e.x.s.a.o.OpenIdConnectAuthenticator] [abc] OpenID Connect Provider redirected user to [/api/security/oidc/callback?code=71e827b7-5c1f-35fa-b06e-35e27d869d1c&session\_state=dfd4eac40cc59c7e5adacac04d12661520a0359ae7033c48bf33f9fbb34a7cc0.3EfOSKqASdmw-a2VOGnK4Q&state=mVIJmoqJWPu0I6tAj1Rul6D7KYjhNWZhNAiQQY61F7A]. Expected Nonce is [n7pvW46f0ddMsrIeeyIg4r6XgMvWQoq-cNCiF6NRc20] and expected State is [mVIJmoqJWPu0I6tAj1Rul6D7KYjhNWZhNAiQQY61F7A]  
[2023-10-13T05:10:17,633][TRACE][o.e.x.s.a.o.OpenIdConnectAuthenticator] [abc] OpenID Connect Provider redirected user to [/api/security/oidc/callback?code=71e827b7-5c1f-35fa-b06e-35e27d869d1c&session\_state=dfd4eac40cc59c7e5adacac04d12661520a0359ae7033c48bf33f9fbb34a7cc0.3EfOSKqASdmw-a2VOGnK4Q&state=mVIJmoqJWPu0I6tAj1Rul6D7KYjhNWZhNAiQQY61F7A]. Expected Nonce is [n7pvW46f0ddMsrIeeyIg4r6XgMvWQoq-cNCiF6NRc20] and expected State is [mVIJmoqJWPu0I6tAj1Rul6D7KYjhNWZhNAiQQY61F7A]  
[2023-10-13T05:10:18,644][DEBUG][o.e.x.s.a.o.OpenIdConnectAuthenticator] [abc] effective HTTP connection keep-alive: [60000]ms  
[2023-10-13T05:10:18,644][DEBUG][o.e.x.s.a.o.OpenIdConnectAuthenticator] [abc] effective HTTP connection keep-alive: [60000]ms  
[2023-10-13T05:10:18,645][TRACE][o.e.x.s.a.o.OpenIdConnectAuthenticator] [abc] Successfully exchanged code for ID Token [com.nimbusds.jwt.SignedJWT@4bcaaeaa] and Access Token [90_**23]  
[2023-10-13T05:10:18,645][TRACE][o.e.x.s.a.o.OpenIdConnectAuthenticator] [abc] Successfully exchanged code for ID Token [com.nimbusds.jwt.SignedJWT@4bcaaeaa] and Access Token [90**_23]  
[2023-10-13T05:10:18,645][DEBUG][o.e.x.s.a.o.OpenIdConnectAuthenticator] [abc] ID Token Header: {"x5t":"YmVlMjY0ZTExNWIwOWYyZDA0MzMyY2Q4NjY1NWYwOTBlM2E4NmJhNjNhMTlmMmZkN2Q1NTVlOGNkYWYwYTBlMQ","kid":"YmVlMjY0ZTExNWIwOWYyZDA0MzMyY2Q4NjY1NWYwOTBlM2E4NmJhNjNhMTlmMmZkN2Q1NTVlOGNkYWYwYTBlMQ\_RS256","alg":"RS256"}  
[2023-10-13T05:10:18,645][DEBUG][o.e.x.s.a.o.OpenIdConnectAuthenticator] [abc] ID Token Header: {"x5t":"YmVlMjY0ZTExNWIwOWYyZDA0MzMyY2Q4NjY1NWYwOTBlM2E4NmJhNjNhMTlmMmZkN2Q1NTVlOGNkYWYwYTBlMQ","kid":"YmVlMjY0ZTExNWIwOWYyZDA0MzMyY2Q4NjY1NWYwOTBlM2E4NmJhNjNhMTlmMmZkN2Q1NTVlOGNkYWYwYTBlMQ\_RS256","alg":"RS256"}  
[2023-10-13T05:10:18,647][TRACE][o.e.x.s.a.o.OpenIdConnectAuthenticator] [abc] Received and validated the Id Token for the user: [{"at\_hash":"oBG44NeB9WZC9jgyRC5axw","sub":"abc","amr":["BasicAuthenticator"],"iss":"https://m/oauth2/token","groups":["Internal],"given\_name":["."," abc"],"nonce":"n7pvW46f0dn7pvW46f0dddMdsrIeeyIg4r6XgMvWQoqddMdsrIeeyIg4r6XgMvWQoq-cNCiF6NRc20","aud":"a3xWdduyoswA8rQsjbmghsz6LJyfoa","c\_hash":"tKEd3-o6dqzNqx9P5LPTweww","nbf":1697191817,"azp":"a3xWuyoswA8rQsjbmghsz6LJyfoa","exp":1697195417,"iat":1697191817,"email":"[abc.com](http://abc.com)"}]  
[2023-10-13T05:10:18,647][TRACE][o.e.x.s.a.o.OpenIdConnectAuthenticator] [abc] Received and validated the Id Token for the user: [{"at\_hash":"oBG44NeB9WZC9jgyRC5axw","sub":"abc","amr":["BasicAuthenticator"],"iss":"https://.com/oauth2/token","groups":["Internal],"given\_name":["."," abc"],"nonce":"n7pvW46f0ddMsrIen7pvW46f0dddMdsrIeeyIg4r6XgMvWQoqeyIg4r6XgMvWQoq-cNCiF6NRc20","aud":"a3xWuyoswA8ddrQsjbmghsz6LJyfoa","c\_hash":"tKdE3-od6qzNqx9P5LPTweww","nbf":1697191817,"azp":"a3xWuyoswA8rQsjbmghsz6LJyfoa","exp":1697195417,"iat":1697191817,"email":"[abc.com](http://abc.com)"}]  
[2023-10-13T05:10:18,647][DEBUG][o.e.x.s.a.o.OpenIdConnectAuthenticator] [abc] OP returned an access token but the UserInfo endpoint is not configured.  
[2023-10-13T05:10:18,647][DEBUG][o.e.x.s.a.o.OpenIdConnectAuthenticator] [abc] OP returned an access token but the UserInfo endpoint is not configured.

Elastic config file -

# Enable security features

#xpack.security.autoconfiguration.enabled: true  
xpack.security.enabled: true  
xpack.security.authc.api\_key.enabled: true  
xpack.security.enrollment.enabled: false  
xpack.security.authc.token.enabled: true

# Enable encryption for HTTP API client connections, such as Kibana, Logstash, and Agents

xpack.security.http.ssl:  
enabled: false  
keystore.path: certs/http.p12

# Enable encryption and mutual authentication between cluster nodes

xpack.security.transport.ssl:  
enabled: false  
verification\_mode: certificate  
keystore.path: certs/transport.p12  
truststore.path: certs/transport.p12

# Create a new cluster with the current node only

# Additional nodes can still join the cluster later

cluster.initial\_master\_nodes: ["abc"]

# Allow HTTP API connections from anywhere

# Connections are encrypted and require user authentication

http.host: 0.0.0.0

# Allow other nodes to join the cluster from anywhere

# Connections are encrypted and mutually authenticated

#transport.host: 0.0.0.0  
ingest.geoip.downloader.enabled: false

xpack.security.authc.realms.oidc.oidc1:  
order: 2  
rp.client\_id: "aaaaaaaaaaaaaaaaaaaa"  
rp.response\_type: code  
rp.redirect\_uri: "[http://abc:5601/api/security/oidc/callback](http://abc:5601/api/security/oidc/callback)"  
#op.issuer: "[https://abc:9443/oauth2/token](https://abc:9443/oauth2/token)"  
op.issuer: "[https://abc/oauth2/token](https://abc/oauth2/token)"  
op.authorization\_endpoint: "[https://abc:9443/oauth2/authorize](https://abc:9443/oauth2/authorize)"  
op.token\_endpoint: "[https://abcl:9443/oauth2/token](https://abcl:9443/oauth2/token)"  
op.jwkset\_path: "[https://abc:9443/oauth2/jwks](https://abc:9443/oauth2/jwks)"  
op.endsession\_endpoint: "[https://abc:9443/oidc/logout](https://abc:9443/oidc/logout)"

# op.userinfo\_endpoint: "[https://abc:9443/oauth2/userinfo](https://abc:9443/oauth2/userinfo)"

rp.post\_logout\_redirect\_uri: "[http://abc:5601/security/logged\_out](http://abc:5601/security/logged_out)"  
claims.principal: sub  
claims.groups: groups  
ssl.verification\_mode: none

# claims.name: name

# claims.mail: email

---

<div class="post-metadata">

### Author: ![amitkumar.gupta](https://avatars.discourse-cdn.com/v4/letter/a/ee7513/32.png) [@amitkumar.gupta](https://discuss.elastic.co/u/amitkumar.gupta)
#### Post date: [October 17, 2023, 5:18am UTC](https://discuss.elastic.co/t/kibana-giving-unauthenticated-first-time-but-allowing-to-login-second-time-in-same-session/344984/2 "2023-10-17T05:18:04Z")

</div>

hi,

is there anyone who can help with this?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 14, 2023, 5:18am UTC](https://discuss.elastic.co/t/kibana-giving-unauthenticated-first-time-but-allowing-to-login-second-time-in-same-session/344984/3 "2023-11-14T05:18:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
