-
Notifications
You must be signed in to change notification settings - Fork 523
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Security Plugin] The root_ca
property for Open ID configurations isn't documented
#786
Comments
thanks for filing this issue, I'm moving this to the documentation repo where it can be updated, if you'd like to update the documentation around Open ID see openid-connect.md, we would be happy to review a pull request. |
root_ca
property for Open ID configurations isn't documented
@opensearch-project/security Could someone weigh in and provide a description for this property? Then we'll get it into documentation. Thanks. |
Based on the name and usage, its a path to a root certification authority file, in a |
If this property is used for certificate validation using OpenID, it's not clear to me how |
Actually, they are the same file, but used in different places. Kibana verify OpenID TLS with |
@zehonghuang Thanks for the reply and additional information. I just wanted to confirm that you're using |
I think names should at least be consistent, and documented. :p |
@opensearch-project/security I've looked into this a little more. The |
@cwillum I've started a discussion to try to get help looking into this issue, follow up at https://github.com/orgs/opensearch-project/teams/security/discussions/3 |
Hi @peternied - did you find any resolution to this issue? I can't access the above link, so not sure if there was any discussion about this. Thanks! |
I can't find it either, looks like that was deleated. Can we document the setting for |
Sounds good! Can you please update the file with the description? And would it go here: https://opensearch.org/docs/latest/install-and-configure/configuring-opensearch/security-settings/? |
@derek-ho Would you mind taking a look at making this change? |
https://github.com/opensearch-project/security-dashboards-plugin/blob/5e4004fbb7195f5a5f9f7ded14ea7ea49dadecaa/server/auth/types/openid/openid_auth.ts#L115
I have expended efforts to solve just because
this.config.openid.root_ca
display no in documentnation.Using https keycloak-openid maybe occur
OpenId authentication failed: Error: Client request error: unable to get issuer certificate
.So, Please Update doc !
The text was updated successfully, but these errors were encountered: