# SSO Using OpenID Connect

**URL:** <https://discuss.elastic.co/t/sso-using-openid-connect/222428>\
**Category:** Kibana\
**Created:** [March 6, 2020, 9:31am UTC](https://discuss.elastic.co/t/sso-using-openid-connect/222428 "2020-03-06T09:31:57Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yungyoung\_Ok](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yungyoung_ok/32/43465_2.png) [@Yungyoung\_Ok](https://discuss.elastic.co/u/Yungyoung_Ok)\
**Post date:** [March 6, 2020, 9:31am UTC](https://discuss.elastic.co/t/sso-using-openid-connect/222428/1 "2020-03-06T09:31:58Z")

</div>

I am currently conducting the sso test.

User authentication has all been successful.  
However 403 error occurs.

What settings should I add?

ERROR:  
{"statusCode":403,"error":"Forbidden","message":"Forbidden"}

ES LOG:  
[2020-03-06T12:51:57,553][TRACE][o.e.x.s.a.o.OpenIdConnectAuthenticator] [DESKTOP-O6EUAL0] OpenID Connect Provider redirected user to [/api/security/v1/oidc?state= ~~&code=~~~ &scope=openid&authuser=0&prompt=consent]. Expected Nonce is [~~~~] and expected State is [~~~]  
"access\_token": "access\_token\_value",  
"expires\_in": 3599,  
"scope": "openid",  
"token\_type": "Bearer",  
"id\_token": "id\_token\_value"  
}]  
[2020-03-06T12:51:57,933][TRACE][o.e.x.s.a.o.OpenIdConnectAuthenticator] [DESKTOP-O6EUAL0] Successfully exchanged code for ID Token: [value] and Access Token [value]  
[2020-03-06T12:51:57,981][TRACE][o.e.x.s.a.o.OpenIdConnectAuthenticator] [DESKTOP-O6EUAL0] Received and validated the Id Token for the user: [{"at\_hash":"value","aud":"value","sub":"value","azp":"value","iss":"[https://accounts.google.com](https://accounts.google.com)","exp":1583470318,"nonce":"value","iat":1583466718}]  
[2020-03-06T12:51:58,325][TRACE][o.e.x.s.a.o.OpenIdConnectAuthenticator] [DESKTOP-O6EUAL0] Received UserInfo Response from OP with status [200] and content [{  
"sub": "value",  
"picture": "value"  
}]  
[2020-03-06T12:51:58,328][TRACE][o.e.x.s.a.o.OpenIdConnectAuthenticator] [DESKTOP-O6EUAL0] Successfully retrieved user information: [{"sub":"116021723082891204727","picture":"value"}]  
[2020-03-06T12:52:42,021][WARN][o.e.x.s.t.n.SecurityNetty4HttpServerTransport] [DESKTOP-O6EUAL0] received plaintext http traffic on an https channel, closing connection Netty4HttpChannel{localAddress=0.0.0.0/0.0.0.0:9200, remoteAddress=/127.0.0.1:56539}  
[2020-03-06T12:53:42,030][WARN][o.e.x.s.t.n.SecurityNetty4HttpServerTransport] [DESKTOP-O6EUAL0] received plaintext http traffic on an https channel, closing connection Netty4HttpChannel{localAddress=0.0.0.0/0.0.0.0:9200, remoteAddress=/0:0:0:0:0:0:0:1:56551}  
[2020-03-06T12:54:42,039][WARN][o.e.x.s.t.n.SecurityNetty4HttpServerTransport] [DESKTOP-O6EUAL0] received plaintext http traffic on an https channel, closing connection Netty4HttpChannel{localAddress=0.0.0.0/0.0.0.0:9200, remoteAddress=/127.0.0.1:56563}  
[2020-03-06T12:55:42,047][WARN][o.e.x.s.t.n.SecurityNetty4HttpServerTransport] [DESKTOP-O6EUAL0] received plaintext http traffic on an https channel, closing connection Netty4HttpChannel{localAddress=0.0.0.0/0.0.0.0:9200, remoteAddress=/0:0:0:0:0:0:0:1:56569}

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [March 12, 2020, 1:30pm UTC](https://discuss.elastic.co/t/sso-using-openid-connect/222428/2 "2020-03-12T13:30:11Z")

</div>

There is not much we can figure out from the logs, without the config.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 9, 2020, 1:30pm UTC](https://discuss.elastic.co/t/sso-using-openid-connect/222428/3 "2020-04-09T13:30:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
