# Opensearch-Dashboards + Okta (OpenID Connect)

**URL:** <https://forum.opensearch.org/t/opensearch-dashboards-okta-openid-connect/10739>\
**Category:** Security\
**Tags:** discuss, troubleshoot, configure\
**Created:** [August 25, 2022, 10:34am UTC](https://forum.opensearch.org/t/opensearch-dashboards-okta-openid-connect/10739 "2022-08-25T10:34:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![nardixcx](https://avatars.discourse-cdn.com/v4/letter/n/6bbea6/32.png) [@nardixcx](https://forum.opensearch.org/u/nardixcx)\
**Post date:** [August 25, 2022, 10:34am UTC](https://forum.opensearch.org/t/opensearch-dashboards-okta-openid-connect/10739/1 "2022-08-25T10:34:33Z")

</div>

I have this issue in integrating Okta OpenID Connect to my Opensearch-dashboards;

{“statusCode”:401,“error”:“Unauthorized”,“message”:“Unauthorized”}

Here are my configs:

- config.yml

> ```
> openid_auth_domain:
> http_enabled: true
> transport_enabled: true
> order: 1
> http_authenticator:
> type: openid
> challenge: true
> config:
> openid_connect_idp:
> verify_hostnames: false
> enable_ssl: true
> openid_connect_url: https://IDP.com/.well-known/openid-configuration 
> authentication_backend:
> type: noop
> 
> ```

- opensearch-dashboards.yml

> ```
> opensearch_security.auth.type: "openid"
> opensearch_security.openid.connect_url: "https://IDP.com/.well-known/openid-configuration"
> opensearch_security.openid.client_id: "ea9613IIIDDDIDIDI42489e0ff2"
> opensearch_security.openid.client_secret: "dcc22711SECRETTTb4dd6b"
> opensearch_security.cookie.isSameSite: None
> opensearch_security.openid.verify_hostnames: false
> opensearch_security.openid.base_redirect_url: "https://k1b4naUrL:5601/"
> 
> ```

I am using Opensearch v1.2.3 and Opensearch-dashboards v1.2.0

Did I missed something here? Thanks in advance!

---

<div class="post-metadata">

**Author:** ![Mussorgsky](https://avatars.discourse-cdn.com/v4/letter/m/87869e/32.png) [@Mussorgsky](https://forum.opensearch.org/u/Mussorgsky)\
**Post date:** [August 29, 2022, 3:40pm UTC](https://forum.opensearch.org/t/opensearch-dashboards-okta-openid-connect/10739/2 "2022-08-29T15:40:20Z")

</div>

As with any other YAML file, please pay special attention to the proper indentation in your `config.yml` file. Please make sure all your values are indented as shown in the example configuration here:

> **[OpenID Connect](https://opensearch.org/docs/latest/security-plugin/configuration/openid-connect/)**
>
> OpenID Connect

Also, since you’re using SSL/TLS when connecting to the IdP to obtain the “.well-known” config, you’d need to configure the CA certificate in `pemtrustedcas_filepath:` or `pemtrustedcas_content:`  
(this would be the CA that signed your IdP certificate)

---

<div class="post-metadata">

**Author:** ![nardixcx](https://avatars.discourse-cdn.com/v4/letter/n/6bbea6/32.png) [@nardixcx](https://forum.opensearch.org/u/nardixcx)\
**Post date:** [August 30, 2022, 10:43am UTC](https://forum.opensearch.org/t/opensearch-dashboards-okta-openid-connect/10739/3 "2022-08-30T10:43:04Z")

</div>

Hello. Thanks for your response.

Is it not possible to make the connection unsecured so it will ignore the cert configuration?

---

<div class="post-metadata">

**Author:** ![Mussorgsky](https://avatars.discourse-cdn.com/v4/letter/m/87869e/32.png) [@Mussorgsky](https://forum.opensearch.org/u/Mussorgsky)\
**Post date:** [September 1, 2022, 12:44pm UTC](https://forum.opensearch.org/t/opensearch-dashboards-okta-openid-connect/10739/4 "2022-09-01T12:44:22Z")

</div>

You could use an insecure connection by disabling hostname verification (NOT recommended for a Production cluster) - or you can provide the CA cert (the one that signed the IdP certificate).

However, I’d first confirm your `config.yml` file is correctly formatted (proper indentation). You can upload your configuration as usual, by executing `securityadmin.sh`

```auto
./securityadmin.sh -cd ../../../config/opensearch-security/ -icl -nhnv \
  -cacert ../../../config/root-ca.pem \
  -cert ../../../config/kirk.pem \
  -key ../../../config/kirk-key.pem

```

And then retrieve it (obtain a backup) also by executing `securityadmin.sh`

```auto
./securityadmin.sh -backup my-backup-directory \
  -icl \
  -nhnv \
  -cacert ../../../config/root-ca.pem \
  -cert ../../../config/kirk.pem \
  -key ../../../config/kirk-key.pem

```

So that you can compare what was actually stored in the security index (what you’ll obtain in your backup) against what you initially uploaded. If there are any differences, please share the config you get in your backup.

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [September 5, 2022, 10:44am UTC](https://forum.opensearch.org/t/opensearch-dashboards-okta-openid-connect/10739/5 "2022-09-05T10:44:45Z")

</div>

@nardixcx Could you take a look at this thread?

[Okta/OpenID(OIDC) authentication](https://forum.opensearch.org/t/okta-openid-oidc-authentication/10172)

Please verify the OKTA application configuration including the `roles claim` config and the redirect URL value.

Are you getting redirected to the OKTA login page?
