# Sporadic unable to authenticate user OIDC errors

**URL:** <https://discuss.elastic.co/t/sporadic-unable-to-authenticate-user-oidc-errors/245788>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [August 20, 2020, 3:11pm UTC](https://discuss.elastic.co/t/sporadic-unable-to-authenticate-user-oidc-errors/245788 "2020-08-20T15:11:01Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eugene\_Marcotte](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eugene_marcotte/32/74112_2.png) [@Eugene\_Marcotte](https://discuss.elastic.co/u/Eugene_Marcotte)\
**Post date:** [August 20, 2020, 3:11pm UTC](https://discuss.elastic.co/t/sporadic-unable-to-authenticate-user-oidc-errors/245788/1 "2020-08-20T15:11:01Z")

</div>

Hey there,

I've been working on setting up a elastic cloud hosted deployment (currently running v7.8.0) with OIDC pointed at Okta. I've run into this error sporadically with various users:

```auto
"[security_exception] unable to authenticate user [<OIDC Token>] for action [cluster:admin/xpack/security/oidc/authenticate], with { header={ WWW-Authenticate={ 0=\"Bearer realm=\\\"security\\\"\" & 1=\"ApiKey\" & 2=\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\" } } }"

```

Following along with [OpenID error after authenticating against AWS Cognito](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018) I have OIDC trace enabled. I find that if I end up _not_ getting the error I see trace logs showing my token and user info responses and am able to log in and everyone is happy. When I _do_ get the error I do not get any trace logs.

Am a bit at a loss for next steps to debug here. Any pointers would be awesome.

This is the relevant es.yaml segment:

```auto
xpack.security.authc.realms.oidc.okta:
  order: 2
  rp.client_id: "okta client id"
  rp.response_type: code
  rp.redirect_uri: "https://kibana-cloud-domain/api/security/v1/oidc"
  rp.requested_scopes: [openid, email, profile, groups]
  op.issuer: "https://our-domain-here.okta.com"
  op.authorization_endpoint: "https://our-domain-here.okta.com/oauth2/v1/authorize"
  op.token_endpoint: "https://our-domain-here.okta.com/oauth2/v1/token"
  op.jwkset_path: "https://our-domain-here.okta.com/oauth2/v1/keys"
  op.userinfo_endpoint: "https://our-domain-here.okta.com/oauth2/v1/userinfo"
  op.endsession_endpoint: "https://our-domain-here.okta.com/oauth2/v1/logout"
  rp.post_logout_redirect_uri: "https://kibana-cloud-domain/logged_out"
  claims.principal: sub
  claims.name: name
  claims.mail: email
  claims.groups: groups

```

Here's my kibana block:

```auto
xpack.security.authc.providers:
  oidc.okta:
    order: 1
    realm: okta
    description: "Log in with Okta"
    hint: "This is probably what you want!"
    icon: "image url here"
  
  basic.basic1:
    order: 2
    hint: "This is for super admins"

```

PS. I also sometimes get what looks like a javascript error on the login screen, clicking the option a second time a few seconds later usually lets the request go through. Not sure if it's related.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [August 20, 2020, 3:25pm UTC](https://discuss.elastic.co/t/sporadic-unable-to-authenticate-user-oidc-errors/245788/2 "2020-08-20T15:25:03Z")

</div>

If you can enable debug logging for kibana and also capture a HAR from your browser when the error happens, we will be more than happy to take a look and see what the issue might be.

> PS. I also sometimes get what looks like a javascript error on the login screen,

You mean in Kibana? Can you share the _exact_ error ?

---

<div class="post-metadata">

**Author:** ![Eugene\_Marcotte](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eugene_marcotte/32/74112_2.png) [@Eugene\_Marcotte](https://discuss.elastic.co/u/Eugene_Marcotte)\
**Post date:** [August 20, 2020, 4:37pm UTC](https://discuss.elastic.co/t/sporadic-unable-to-authenticate-user-oidc-errors/245788/3 "2020-08-20T16:37:33Z")

</div>

For the JS error: yes, in kibana. Reproducing it now in a private window, I realized just now that it is also trying to report an unauthorized response. Here's what it reports...

Header of the dialog: Could not perform login.  
Error field: Unauthorized

Stack trace

```auto
_construct@https://kibana-cloud.tom.takeoff.com/31997/bundles/core/core.entry.js:26:56491
Wrapper@https://kibana-cloud.tom.takeoff.com/31997/bundles/core/core.entry.js:26:55881
_createSuper/<@https://kibana-cloud.tom.takeoff.com/31997/bundles/core/core.entry.js:26:54669
HttpFetchError@https://kibana-cloud.tom.takeoff.com/31997/bundles/core/core.entry.js:26:57648
_callee3$@https://kibana-cloud.tom.takeoff.com/31997/bundles/core/core.entry.js:46:149749
l@https://kibana-cloud.tom.takeoff.com/31997/bundles/kbn-ui-shared-deps/kbn-ui-shared-deps.js:288:969217
s/o._invoke</<@https://kibana-cloud.tom.takeoff.com/31997/bundles/kbn-ui-shared-deps/kbn-ui-shared-deps.js:288:968971
_/</e[t]@https://kibana-cloud.tom.takeoff.com/31997/bundles/kbn-ui-shared-deps/kbn-ui-shared-deps.js:288:969574
asyncGeneratorStep@https://kibana-cloud.tom.takeoff.com/31997/bundles/core/core.entry.js:46:143272
_next@https://kibana-cloud.tom.takeoff.com/31997/bundles/core/core.entry.js:46:143601

```

I clicked the login button again and it brought me to the okta login prompt.

As for debug logs, any particular category or just across the board for kibana? Will try to reproduce (it would be so much eaiser if it happened consistently 😃 ) and capture a HAR.

---

<div class="post-metadata">

**Author:** ![Eugene\_Marcotte](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eugene_marcotte/32/74112_2.png) [@Eugene\_Marcotte](https://discuss.elastic.co/u/Eugene_Marcotte)\
**Post date:** [August 20, 2020, 7:05pm UTC](https://discuss.elastic.co/t/sporadic-unable-to-authenticate-user-oidc-errors/245788/4 "2020-08-20T19:05:47Z")

</div>

While trying to generate the HAR I hit the same sort of pop up on the main page saying an error occurred, in the respond on the network tab it had

```auto
message: "[security_exception] Cannot find OpenID Connect realm with name [okta]"

```

Is it possible that some of the instances are out of sync somehow?

---

<div class="post-metadata">

**Author:** ![Eugene\_Marcotte](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eugene_marcotte/32/74112_2.png) [@Eugene\_Marcotte](https://discuss.elastic.co/u/Eugene_Marcotte)\
**Post date:** [August 20, 2020, 9:03pm UTC](https://discuss.elastic.co/t/sporadic-unable-to-authenticate-user-oidc-errors/245788/5 "2020-08-20T21:03:41Z")

</div>

I may have found a solution. The problem is likely me not understanding that all the different types of ES instances have individual elasticsearch.yaml entry fields in the deployment UI, and even if it says no significant changes when copy-pasting config between them, they are using independent config or something 🙂. Can you tell this is my first time using ES as administrator?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [August 21, 2020, 8:33am UTC](https://discuss.elastic.co/t/sporadic-unable-to-authenticate-user-oidc-errors/245788/6 "2020-08-21T08:33:27Z")

</div>

Thanks for the feedback Eugene. We will try to make this more clear in our documentation!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 18, 2020, 8:33am UTC](https://discuss.elastic.co/t/sporadic-unable-to-authenticate-user-oidc-errors/245788/7 "2020-09-18T08:33:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
