# OIDC implicit mode unable to generate Elastic Access Token

**URL:** <https://discuss.elastic.co/t/oidc-implicit-mode-unable-to-generate-elastic-access-token/211506>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [December 11, 2019, 5:39pm UTC](https://discuss.elastic.co/t/oidc-implicit-mode-unable-to-generate-elastic-access-token/211506 "2019-12-11T17:39:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![barneyn](https://avatars.discourse-cdn.com/v4/letter/b/db5fbb/32.png) [@barneyn](https://discuss.elastic.co/u/barneyn)\
**Post date:** [December 11, 2019, 5:39pm UTC](https://discuss.elastic.co/t/oidc-implicit-mode-unable-to-generate-elastic-access-token/211506/1 "2019-12-11T17:39:47Z")

</div>

Hello,  
I am trying to use Keycloak as an OIDC provider in order to query Elastic.

The flow will be...

1. Log into the UI using Keycloak to obtain an id token.
2. Pass this token to the API via a bearer header (spring boot application)
3. Somehow query elastic search as the authenticated user

Question:  
How does ES trust the ID token generated from the login in the UI?

I have configured a realm in Elastic to use OIDC and performed the steps outlined in [https://www.elastic.co/guide/en/elasticsearch/reference/master/oidc-without-kibana.html](https://www.elastic.co/guide/en/elasticsearch/reference/master/oidc-without-kibana.html)

I am performing a `prepare` in ES, then attempting an authenticate but receiving this error from the request: `"reason": "unable to authenticate user [<OIDC Token>] for action [cluster:admin/xpack/security/oidc/authenticate]",`

And I get this error in ES logs:  
`"message": "Authentication to realm oidc1 failed - Failed to authenticate user with OpenID Connect (Caused by ElasticsearchSecurityException[Failed to consume the OpenID connect response.]; nested: ParseException[Missing URI fragment or query string];)"`

ES version: 7.5.0

If anyone could help me out, or point me towards an article that would be great.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [December 12, 2019, 9:22am UTC](https://discuss.elastic.co/t/oidc-implicit-mode-unable-to-generate-elastic-access-token/211506/2 "2019-12-12T09:22:43Z")

</div>

> [@barneyn](#):
>
> The flow will be...
> 
> 1. Log into the UI using Keycloak to obtain an id token.
> 2. Pass this token to the API via a bearer header (spring boot application)
> 3. Somehow query Elasticsearch as the authenticated user

You can't do that.

Third party initiated login is defined in the specification in [Final: OpenID Connect Core 1.0 incorporating errata set 1](https://openid.net/specs/openid-connect-core-1_0.html#ThirdPartyInitiatedLogin). We don't cover the Third PArty initiated login flow without Kibana in our docs ( I've made a note to fix that )

You basically need to

1. initiate a request to the RP ( your spring boot application ) providing the necessary parameters (`iss` should be enough)
2. Your spring boot app will make the necessary call to Elasicsearch ( [OpenID Connect Prepare Authentication API | Elasticsearch Guide [7.2] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.2/security-api-oidc-prepare-authentication.html) passing `state`, `nonce`, `issuer` )
3. Elasticserach will reply with a URL back to keycloak
4. You use that url to redirect that user back to Keycloak..  
..  
..
5. Continue from 3 in [https://www.elastic.co/guide/en/elasticsearch/reference/master/oidc-without-kibana.html](https://www.elastic.co/guide/en/elasticsearch/reference/master/oidc-without-kibana.html)

This will give your spring boot app an Elasticsearch Token Service access token and a refresh token for that user, and you can subsequently use that Elasticsearch Token Service access as a Bearer token for requests to Elasticsearch on behalf of the authenticated user

> [@barneyn](#):
>
> I am performing a `prepare` in ES, then attempting an authenticate but receiving this ...
> 
> And I get this error in ES logs:

You'll need to add a bit more detail here, this is not enough for us to help you.

- Calling prepare gives you a URL back to redirect you to your OP, what do you do with it?
- Calling the `prepare` API would never return that error message, this error message is from the `oidc/authenticate` API .

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 9, 2020, 9:22am UTC](https://discuss.elastic.co/t/oidc-implicit-mode-unable-to-generate-elastic-access-token/211506/3 "2020-01-09T09:22:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
