# Unable to configure oidc

**URL:** <https://discuss.elastic.co/t/unable-to-configure-oidc/234821>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 28, 2020, 8:57pm UTC](https://discuss.elastic.co/t/unable-to-configure-oidc/234821 "2020-05-28T20:57:18Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![bandapally\_kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bandapally_kumar/32/69343_2.png) [@bandapally\_kumar](https://discuss.elastic.co/u/bandapally_kumar)\
**Post date:** [May 28, 2020, 8:57pm UTC](https://discuss.elastic.co/t/unable-to-configure-oidc/234821/1 "2020-05-28T20:57:18Z")

</div>

```auto
we are trying to setup elasticsearch to use oidc for authentication here is my yaml file

xpack.security.authc.token.enabled: true
xpack.security.authc.realms.oidc.oidc1:
        order: 1
        rp.client_id: "6bd9f9a3-67a3-4392-b29c-675c16b818e9"
        rp.response_type: "code"
        rp.redirect_uri: "https://<Kibana-Host>/api/security/oidc/callback"
        op.issuer: "https://<Login-Provider>"
        op.authorization_endpoint: "https://<Login-Provider>/oauth2/v2.0/authorize"
        op.token_endpoint: "https://<Login-Provider>/oauth2/v2.0/token"
        op.jwkset_path: "https://<Login-Provider>/discovery/v2.0/keys"
        rp.post_logout_redirect_uri: "https://<Kibana-Host>/login"
        rp.requested_scopes: [openid, profile, email]
        claims.principal: email

once I sign in with credentials I get the following error

{"statusCode":401,"error":"Unauthorized","message":"[security_exception] unable to authenticate user [<OIDC Token>] for action [cluster:admin/xpack/security/oidc/authenticate], with { header={ WWW-Authenticate={ 0=\"Bearer realm=\\\"security\\\"\" & 1=\"ApiKey\" & 2=\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\" } } }"}

what is that I am doing wrong?

```

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 28, 2020, 9:10pm UTC](https://discuss.elastic.co/t/unable-to-configure-oidc/234821/2 "2020-05-28T21:10:58Z")

</div>

Please check your elasticsearch logs, there should be more info there on exactly what fails. If there is not, you can also set the logging level to trace with

```auto
 PUT /_cluster/settings
 {
   "transient": {
     "logger.org.elasticsearch.xpack.security.authc.oidc": "trace"
   }
 }

```

and get additional details

---

<div class="post-metadata">

**Author:** ![bandapally\_kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bandapally_kumar/32/69343_2.png) [@bandapally\_kumar](https://discuss.elastic.co/u/bandapally_kumar)\
**Post date:** [May 29, 2020, 2:27pm UTC](https://discuss.elastic.co/t/unable-to-configure-oidc/234821/3 "2020-05-29T14:27:30Z")

</div>

> [@bandapally\_kumar](#):
>
> `api/security/oidc/callback`

```auto
This is what get from the logs
[2020-05-29T14:23:13,899][WARN][o.e.x.s.a.AuthenticationService] [ip-172-31-8-199.us-west-2.compute.internal] Authentication to realm oidc1 failed - Failed to authenticate user with OpenID Connect (Caused by ElasticsearchSecurityException[Failed to parse or validate the ID Token]; nested: BadJWTException[Unexpected JWT issuer: 

```

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 29, 2020, 2:59pm UTC](https://discuss.elastic.co/t/unable-to-configure-oidc/234821/4 "2020-05-29T14:59:03Z")

</div>

If you didn't truncate the log message we would be able to help more but in summary:  
You have configured your realm as such:

> [@bandapally\_kumar](#):
>
> `op.issuer: "https://<Login-Provider>"`

but the actual issuer string of your OP is a different one, it is the one that is printed in your logs _exactly_ after

```auto
BadJWTException[Unexpected JWT issuer: 

```

You need to fix your configuration.

---

<div class="post-metadata">

**Author:** ![bandapally\_kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bandapally_kumar/32/69343_2.png) [@bandapally\_kumar](https://discuss.elastic.co/u/bandapally_kumar)\
**Post date:** [May 29, 2020, 4:03pm UTC](https://discuss.elastic.co/t/unable-to-configure-oidc/234821/5 "2020-05-29T16:03:17Z")

</div>

```auto
here is my op.issuer: "https://login.microsoftonline.com"
and one in the logs is https://login.microsoftonline.com/<Truncated_id>

```

---

<div class="post-metadata">

**Author:** ![bandapally\_kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bandapally_kumar/32/69343_2.png) [@bandapally\_kumar](https://discuss.elastic.co/u/bandapally_kumar)\
**Post date:** [May 29, 2020, 4:56pm UTC](https://discuss.elastic.co/t/unable-to-configure-oidc/234821/6 "2020-05-29T16:56:21Z")

</div>

```auto
I updated my elasticsearch.yml with op.issuer I got from logs but now it gives me no error but when I try accessing it I get 403 on browser

```

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 30, 2020, 8:32am UTC](https://discuss.elastic.co/t/unable-to-configure-oidc/234821/7 "2020-05-30T08:32:22Z")

</div>

Please read through our docs, you'll find all your questions are already answered there : [https://www.elastic.co/guide/en/elasticsearch/reference/current/oidc-role-mapping.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/oidc-role-mapping.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2020, 8:32am UTC](https://discuss.elastic.co/t/unable-to-configure-oidc/234821/8 "2020-06-27T08:32:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
