# SSO test using OpenID Connect in elasticsearch

**URL:** <https://discuss.elastic.co/t/sso-test-using-openid-connect-in-elasticsearch/222429>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [March 6, 2020, 9:36am UTC](https://discuss.elastic.co/t/sso-test-using-openid-connect-in-elasticsearch/222429 "2020-03-06T09:36:25Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yungyoung\_Ok](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yungyoung_ok/32/43465_2.png) [@Yungyoung\_Ok](https://discuss.elastic.co/u/Yungyoung_Ok)\
**Post date:** [March 6, 2020, 9:36am UTC](https://discuss.elastic.co/t/sso-test-using-openid-connect-in-elasticsearch/222429/1 "2020-03-06T09:36:25Z")

</div>

I am currently conducting the sso test.

User authentication has all been successful.  
However 403 error occurs.

What settings should I add?

ERROR:  
{"statusCode":403,"error":"Forbidden","message":"Forbidden"}

ES LOG:  
[2020-03-06T12:51:57,553][TRACE][o.e.x.s.a.o.OpenIdConnectAuthenticator] [DESKTOP-O6EUAL0] OpenID Connect Provider redirected user to [/api/security/v1/oidc?state= ~~&code=~~ ~&scope=openid&authuser=0&prompt=consent]. Expected Nonce is [~~~~] and expected State is [~~ ~]  
"access\_token": "access\_token\_value",  
"expires\_in": 3599,  
"scope": "openid",  
"token\_type": "Bearer",  
"id\_token": "id\_token\_value"  
}]  
[2020-03-06T12:51:57,933][TRACE][o.e.x.s.a.o.OpenIdConnectAuthenticator] [DESKTOP-O6EUAL0] Successfully exchanged code for ID Token: [value] and Access Token [value]  
[2020-03-06T12:51:57,981][TRACE][o.e.x.s.a.o.OpenIdConnectAuthenticator] [DESKTOP-O6EUAL0] Received and validated the Id Token for the user: [{"at\_hash":"value","aud":"value","sub":"value","azp":"value","iss":"[https://accounts.google.com](https://accounts.google.com/)","exp":1583470318,"nonce":"value","iat":1583466718}]  
[2020-03-06T12:51:58,325][TRACE][o.e.x.s.a.o.OpenIdConnectAuthenticator] [DESKTOP-O6EUAL0] Received UserInfo Response from OP with status [200] and content [{  
"sub": "value",  
"picture": "value"  
}]  
[2020-03-06T12:51:58,328][TRACE][o.e.x.s.a.o.OpenIdConnectAuthenticator] [DESKTOP-O6EUAL0] Successfully retrieved user information: [{"sub":"116021723082891204727","picture":"value"}]  
[2020-03-06T12:52:42,021][WARN][o.e.x.s.t.n.SecurityNetty4HttpServerTransport] [DESKTOP-O6EUAL0] received plaintext http traffic on an https channel, closing connection Netty4HttpChannel{localAddress=0.0.0.0/0.0.0.0:9200, remoteAddress=/127.0.0.1:56539}  
[2020-03-06T12:53:42,030][WARN][o.e.x.s.t.n.SecurityNetty4HttpServerTransport] [DESKTOP-O6EUAL0] received plaintext http traffic on an https channel, closing connection Netty4HttpChannel{localAddress=0.0.0.0/0.0.0.0:9200, remoteAddress=/0:0:0:0:0:0:0:1:56551}  
[2020-03-06T12:54:42,039][WARN][o.e.x.s.t.n.SecurityNetty4HttpServerTransport] [DESKTOP-O6EUAL0] received plaintext http traffic on an https channel, closing connection Netty4HttpChannel{localAddress=0.0.0.0/0.0.0.0:9200, remoteAddress=/127.0.0.1:56563}  
[2020-03-06T12:55:42,047][WARN][o.e.x.s.t.n.SecurityNetty4HttpServerTransport] [DESKTOP-O6EUAL0] received plaintext http traffic on an https channel, closing connection Netty4HttpChannel{localAddress=0.0.0.0/0.0.0.0:9200, remoteAddress=/0:0:0:0:0:0:0:1:56569}

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [March 6, 2020, 9:41am UTC](https://discuss.elastic.co/t/sso-test-using-openid-connect-in-elasticsearch/222429/2 "2020-03-06T09:41:06Z")

</div>

Users authenticating with OpenID Connect have no roles be default so they can't see anything. See [our documentation](https://www.elastic.co/guide/en/elasticsearch/reference/7.6/oidc-role-mapping.html) that also explains this and guides you through the necessary steps to give access to these users as needed.

---

<div class="post-metadata">

**Author:** ![Yungyoung\_Ok](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yungyoung_ok/32/43465_2.png) [@Yungyoung\_Ok](https://discuss.elastic.co/u/Yungyoung_Ok)\
**Post date:** [March 7, 2020, 7:28am UTC](https://discuss.elastic.co/t/sso-test-using-openid-connect-in-elasticsearch/222429/3 "2020-03-07T07:28:03Z")

</div>

The following settings have already been added.  
Is there anything wrong?

PUT /\_security/role\_mapping/oidc-test  
{  
"roles": ["superuser"],  
"enabled": true,  
"rules": { "all": [  
{ "field": { "realm.name": "oidc1" } },  
{ "field": { "groups": "kibana-users" } }  
] }

}

es config  
xpack.security.authc.token.enabled: true  
xpack.security.authc.realms.oidc.oidc1:  
order: 0  
rp.client\_id: "[87589987116-q6qur5tspjaosha0t9rd638a01t3vi6j.apps.googleusercontent.com](http://87589987116-q6qur5tspjaosha0t9rd638a01t3vi6j.apps.googleusercontent.com)"  
rp.response\_type: code  
rp.redirect\_uri: "[http://localhost:5601/api/security/v1/oidc](http://localhost:5601/api/security/v1/oidc)"  
op.issuer: "[https://accounts.google.com](https://accounts.google.com)"  
op.authorization\_endpoint: "[https://accounts.google.com/o/oauth2/auth](https://accounts.google.com/o/oauth2/auth)"  
op.token\_endpoint: "[https://oauth2.googleapis.com/token](https://oauth2.googleapis.com/token)"  
op.jwkset\_path: [https://www.googleapis.com/oauth2/v3/certs](https://www.googleapis.com/oauth2/v3/certs)  
op.userinfo\_endpoint: "[https://openidconnect.googleapis.com/v1/userinfo](https://openidconnect.googleapis.com/v1/userinfo)"  
op.endsession\_endpoint: "[https://oauth2.googleapis.com/revoke](https://oauth2.googleapis.com/revoke)"  
rp.post\_logout\_redirect\_uri: "[http://localhost:5601/logged\_out](http://localhost:5601/logged_out)"  
claims.principal: sub  
claims.groups: kibana-users

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [March 7, 2020, 8:56am UTC](https://discuss.elastic.co/t/sso-test-using-openid-connect-in-elasticsearch/222429/4 "2020-03-07T08:56:20Z")

</div>

`claims.groups` doesn't work the way you think it works unfortunately. Please read through our documentation, we explicitly describe this here: [https://www.elastic.co/guide/en/elasticsearch/reference/7.6/oidc-guide-authentication.html#oidc-claims-mapping](https://www.elastic.co/guide/en/elasticsearch/reference/7.6/oidc-guide-authentication.html#oidc-claims-mapping)

---

<div class="post-metadata">

**Author:** ![Yungyoung\_Ok](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yungyoung_ok/32/43465_2.png) [@Yungyoung\_Ok](https://discuss.elastic.co/u/Yungyoung_Ok)\
**Post date:** [March 10, 2020, 12:26pm UTC](https://discuss.elastic.co/t/sso-test-using-openid-connect-in-elasticsearch/222429/5 "2020-03-10T12:26:55Z")

</div>

Thank you very much.  
I deleted 'claims,groups' setting and succeeded in SSO.

But I have a new question.  
How should I set the Refresh Token?

Access Token is thought to be unavailable after the expiration date.  
Access token issued by Google cannot be used for more than 3,600 seconds.  
As far as I know, Access Tokens are updated using Refresh Tokens.  
Is that right?  
How do I set it up?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [March 10, 2020, 12:59pm UTC](https://discuss.elastic.co/t/sso-test-using-openid-connect-in-elasticsearch/222429/6 "2020-03-10T12:59:44Z")

</div>

> [@Yungyoung\_Ok](#):
>
> How should I set the Refresh Token?

You should not. The access token and refresh token that you get from the OP during the OIDC login are not exposed to you and are not meant to be used. You are logged in to the Elastic Stack after that and all related session and authentication information is held on that side, there is no reason to communicate with the OP ( Google ) after that.

Session timeouts are handled in [kibana](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html#_access_and_refresh_tokens) . Please note that the access token and refresh token that are discussed there have _nothing_ to do with the access token and refresh token from Google. These are internal implementation details of Elasticsearch, part of the [Elasticsearch Token Service](https://www.elastic.co/guide/en/elasticsearch/reference/7.1/token-authentication-services.html).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 7, 2020, 12:59pm UTC](https://discuss.elastic.co/t/sso-test-using-openid-connect-in-elasticsearch/222429/7 "2020-04-07T12:59:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
