# OpenID error after authenticating against AWS Cognito

**URL:** <https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [October 31, 2019, 10:11am UTC](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018 "2019-10-31T10:11:41Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![nahojkap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nahojkap/32/56856_2.png) [@nahojkap](https://discuss.elastic.co/u/nahojkap)\
**Post date:** [October 31, 2019, 10:11am UTC](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018/1 "2019-10-31T10:11:41Z")

</div>

Attempting to configure a Elastic Cloud Kibana instance to use AWS Cognito for login but running into a the below error after successful login at the OP (AWS Cognito) side.

```
{"statusCode":401,"error":"Unauthorized","message":"[security_exception] unable to authenticate user [<OIDC Token>] for action [cluster:admin/xpack/security/oidc/authenticate], with { header={ WWW-Authenticate={ 0=\"Bearer realm=\\\"security\\\"\" & 1=\"ApiKey\" & 2=\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\" } } }"}

```

Have an EC2 instance running nginx in front of Kibana, to make sure my domain name is correctly reflected & secure.

```
xpack.security.authc.realms:
  oidc.cloud-oidc:
    order: 2
      rp.client_id: "<clientid>"
      rp.response_type: code
    rp.redirect_uri: "https://<KIBANA EXTEARNAL URL>/api/security/v1/oidc"
    op.issuer: "https://cognito-idp.eu-west-1.amazonaws.com/xxxxxxxxxxxxxx"
    op.authorization_endpoint: "https://xxxx.auth.eu-west-1.amazoncognito.com/oauth2/authorize"
    op.token_endpoint: "https://xxxx.auth.eu-west-1.amazoncognito.com/oauth2/token"
    op.jwkset_path: https://cognito-idp.eu-west-1.amazonaws.com/xxxxxxxxxxxxxx/.well-known/jwks.json
    op.userinfo_endpoint: "https://xxxx.auth.eu-west-1.amazoncognito.com/oauth2/userInfo"
    op.endsession_endpoint: "https://xxxx.auth.eu-west-1.amazoncognito.com/logout"
    rp.post_logout_redirect_uri: "https://<KIBANA EXTEARNAL URL>/logged_out"
    claims.principal: sub
    claims.groups: "cognito:groups"

```

In Kibana, I have configured the following

```
    xpack.security.public:
      protocol: https
      hostname: "<KIBANA EXTERNAL URL>"
      port: 443

```

There is a slight delay before I get the above error, which feels like its a comms problem, but cant be sure.

I tried to enable the logs in ES but my settings dont seem to have any effect:

```
   PUT /_cluster/settings
    {
      "transient": {
        "logger.org.elasticsearch.xpack.security.authc.saml" : "TRACE",
        "logger.org.elasticsearch.xpack.security.authc.oidc": "TRACE",
        "logger.org.elasticsearch.xpack.security.authc": "TRACE",
        "logger.org.elasticsearch.xpack.security" : "TRACE"
      }
    }

```

Anyone had a similar issue?

Thanks,

Johan

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 2, 2019, 10:49pm UTC](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018/2 "2019-11-02T22:49:10Z")

</div>

Hi there

You only need

```auto
"logger.org.elasticsearch.xpack.security.authc.oidc": "TRACE"

```

There should be a few related log lines in your elasticsearch log. If you can't see them, could you please engage with your support engineer and reference this post If needed ?

---

<div class="post-metadata">

**Author:** ![nahojkap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nahojkap/32/56856_2.png) [@nahojkap](https://discuss.elastic.co/u/nahojkap)\
**Post date:** [November 3, 2019, 2:36pm UTC](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018/3 "2019-11-03T14:36:17Z")

</div>

Hi,

I tried that initially with no luck. Will do what you suggest.

Thanks,

Johan

---

<div class="post-metadata">

**Author:** ![Olumide\_Ajiboye](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/olumide_ajiboye/32/57185_2.png) [@Olumide\_Ajiboye](https://discuss.elastic.co/u/Olumide_Ajiboye)\
**Post date:** [November 5, 2019, 12:20pm UTC](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018/4 "2019-11-05T12:20:23Z")

</div>

Hi,  
I have observed the same issue with Okta, the authentication is succesful but Elastic Cloud returns the error below.  
`{"statusCode":401,"error":"Unauthorized","message":"[security_exception] unable to authenticate user [<OIDC Token>] for action [cluster:admin/xpack/security/oidc/authenticate], with { header={ WWW-Authenticate={ 0=\"Bearer realm=\\\"security\\\"\" & 1=\"ApiKey\" & 2=\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\" } } }"}`  
It seems this feature is probably not working.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 5, 2019, 9:50pm UTC](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018/5 "2019-11-05T21:50:17Z")

</div>

Hi @Olumide_Ajiboye ,

Please open an issue for your problem and share your configuration and the logs from your instance so that we can help you address the issues you're facing.

---

<div class="post-metadata">

**Author:** ![nickbabkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickbabkin/32/57493_2.png) [@nickbabkin](https://discuss.elastic.co/u/nickbabkin)\
**Post date:** [November 11, 2019, 3:21pm UTC](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018/6 "2019-11-11T15:21:27Z")

</div>

We're hitting the exact same issue with 7.4.  
This is the first time for us to configure OpenID auth.

We're in the cloud and enabling trace for oidc doesn't produce any new logs in deployments -\> logs.

Any hints?

---

<div class="post-metadata">

**Author:** ![nickbabkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickbabkin/32/57493_2.png) [@nickbabkin](https://discuss.elastic.co/u/nickbabkin)\
**Post date:** [November 11, 2019, 9:52pm UTC](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018/7 "2019-11-11T21:52:27Z")

</div>

@Olumide_Ajiboye @nahojkap wonder which version of stack are you having? Is it 7.4 for you both?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 12, 2019, 7:05am UTC](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018/8 "2019-11-12T07:05:17Z")

</div>

Hi @nickbabkin,

There is currently an unintended limitation prohibiting you from seeing the OpenID Connect related logs in the Elastic Cloud interface. While we are working to resolve this, please contact your support engineer and they would be able to relay the necessary logs to you that will allow you to troubleshoot your configuration.

---

<div class="post-metadata">

**Author:** ![nickbabkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickbabkin/32/57493_2.png) [@nickbabkin](https://discuss.elastic.co/u/nickbabkin)\
**Post date:** [November 12, 2019, 9:20am UTC](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018/9 "2019-11-12T09:20:31Z")

</div>

Just FYI,  
after bit of playing around I was able to fix this by changing principal claim from:

`claims.principal: sub`

to:

`claims.principal: preferred_username`

---

<div class="post-metadata">

**Author:** ![nahojkap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nahojkap/32/56856_2.png) [@nahojkap](https://discuss.elastic.co/u/nahojkap)\
**Post date:** [November 12, 2019, 11:02am UTC](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018/10 "2019-11-12T11:02:06Z")

</div>

@nickbabkin indeed, on 7.4 here as well. Can you confirm if your token contained the sub claim?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 12, 2019, 12:24pm UTC](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018/11 "2019-11-12T12:24:24Z")

</div>

Glad you got this figured out

> [@nickbabkin](#):
>
> Just FYI,  
> after bit of playing around I was able to fix this by changing principal claim from:
> 
> `claims.principal: sub`
> 
> to:
> 
> `claims.principal: preferred_username`

This would mean that the ID Token didn't contain a `sub` claim which is rather strange. The logs ( if you get them from your support engineer ) would contain a line that says

`claims.principal not found in {your ID Tokens claims here in json format}`

---

<div class="post-metadata">

**Author:** ![nahojkap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nahojkap/32/56856_2.png) [@nahojkap](https://discuss.elastic.co/u/nahojkap)\
**Post date:** [November 13, 2019, 3:02pm UTC](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018/12 "2019-11-13T15:02:23Z")

</div>

@ikakavas Resorted to debugging this locally and it seem AWS is returning claims with values of different types in token request vs user info:

`"email_verified": true`  
vs  
`"email_verified": "true"`

Parsing fails and as a result the authentication times out. Removing one of the claims before the merge happens fixes this problem and authentication is possible. Worth noting that there is nothing logged about this error, its simply times out.

Checking why AWS insists on sending the email\_verified claim even when I set the scope to openid only

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 13, 2019, 3:19pm UTC](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018/13 "2019-11-13T15:19:14Z")

</div>

Thank you so much for the details @nahojkap . I recently came across a similar issue with AWS Cognito that lead to a timeout. It looked like `email` claim was to blame, but your findings shed some additional light. This is a bug on our side, I will be looking into it.

Would you also be opening an issue against Cognito regarding the different types for `email_verified` ? To be clear, this is supposed to be boolean so `"email_verified": true` that comes in the ID Token is the correct version.

---

<div class="post-metadata">

**Author:** ![nahojkap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nahojkap/32/56856_2.png) [@nahojkap](https://discuss.elastic.co/u/nahojkap)\
**Post date:** [November 13, 2019, 4:42pm UTC](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018/14 "2019-11-13T16:42:23Z")

</div>

Will be raising an issue with AWS, will update here when I know more. Let me know if you need anything else from me otherwise.

---

<div class="post-metadata">

**Author:** ![nahojkap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nahojkap/32/56856_2.png) [@nahojkap](https://discuss.elastic.co/u/nahojkap)\
**Post date:** [November 13, 2019, 5:11pm UTC](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018/15 "2019-11-13T17:11:01Z")

</div>

Also @ikakavas (and not had time to check if there is an issue reported about this already) the AWS Cognito logout pages require some custom URL parameters (client\_id and logout\_uri) and while I can specify these in the op.endsession\_endpoint config, the LogoutRequest class ignores the fact the URI passed already contains a ? for the query string and simply appends a ? and the generated query string.

Cognito will in this case report missing parameter. Changing the URL manually fixes it but now running into some other mysterious error in Cognito but still digging into what that can be.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 13, 2019, 6:03pm UTC](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018/16 "2019-11-13T18:03:44Z")

</div>

Already tracking this in [https://github.com/elastic/elasticsearch/issues/48409](https://github.com/elastic/elasticsearch/issues/48409)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 11, 2019, 6:11pm UTC](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018/17 "2019-12-11T18:11:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
