Test Info

Issuerhttps://oidc-conformance.ping-eng.com:9031
Profile[]
Test IDOP-Req-max_age=10000
Test descriptionRequesting ID Token with max_age=10000 seconds restriction
Timestamp2018-09-20T18:59:50Z

Conditions


claims-check: status=OK [Checks if specific claims is present or not]
same-authn: status=OK [Verifies that the same authentication was used twice in the flow.]
auth_time-check: status=OK [Check that the auth_time returned in the ID Token is in the expected range.]
verify-response: status=OK [Checks that the last response was one of a possible set of OpenID Connect Responses]
Done: status=OK

Trace Output

0.0phase<--<-- 0 --- Webfinger -->-->
0.0not expected to doWebFinger
0.0phase<--<-- 1 --- Discovery -->-->
0.0not expected to doDynamic discovery
0.0phase<--<-- 2 --- Registration -->-->
0.0register
kwargs:{'response_types': ['code'], 'grant_types': ['authorization_code'], 'application_name': 'OIC test tool', 'application_type': 'web', 'redirect_uris': ['https://op.certification.openid.net:61401/authz_cb'], 'contacts': ['roland@example.com'], 'post_logout_redirect_uris': ['https://op.certification.openid.net:61401/logout'], 'url': 'https://oidc-conformance.ping-eng.com:9031/as/clients.oauth2', 'jwks_uri': 'https://op.certification.openid.net:61401/static/jwks_61401.json'}
0.001RegistrationRequest
{
    "application_type": "web",
    "contacts": [
        "roland@example.com"
    ],
    "grant_types": [
        "authorization_code"
    ],
    "jwks_uri": "https://op.certification.openid.net:61401/static/jwks_61401.json",
    "post_logout_redirect_uris": [
        "https://op.certification.openid.net:61401/logout"
    ],
    "redirect_uris": [
        "https://op.certification.openid.net:61401/authz_cb"
    ],
    "request_uris": [
        "https://op.certification.openid.net:61401/requests/876669ef2b3891075309a06e00b98e6ace4cfca108af01becb9a804fff95d8c4#CgdJlOaU8kw3Lril"
    ],
    "response_types": [
        "code"
    ]
}
0.513http response
url:https://oidc-conformance.ping-eng.com:9031/as/clients.oauth2 status_code:201
0.514RegistrationResponse
{
    "client_id": "dc-drFw1l0e5F097Im7OCHIom",
    "client_name": "dc-drFw1l0e5F097Im7OCHIom",
    "client_secret": "fR6wp7NBK4cKwwnxKPikYe",
    "client_secret_expires_at": 0,
    "grant_access_session_revocation_api": false,
    "grant_types": [
        "authorization_code"
    ],
    "jwks_uri": "https://op.certification.openid.net:61401/static/jwks_61401.json",
    "persistent_grant_expiration_type": "server_default",
    "pingaccess_logout_capable": false,
    "redirect_uris": [
        "https://op.certification.openid.net:61401/authz_cb"
    ],
    "refresh_token_rolling_policy": "server_default",
    "response_types": [
        "code"
    ],
    "scope": "address phone edit openid profile admin email",
    "token_endpoint_auth_method": "client_secret_basic",
    "validate_using_all_eligible_atms": false
}
0.514phase<--<-- 3 --- AsyncAuthn -->-->
0.515AuthorizationRequest
{
    "client_id": "dc-drFw1l0e5F097Im7OCHIom",
    "nonce": "T6pZm8zs34l008Aj",
    "redirect_uri": "https://op.certification.openid.net:61401/authz_cb",
    "response_type": "code",
    "scope": "openid",
    "state": "MW2OTQo2NXmodI23"
}
0.515redirect urlhttps://oidc-conformance.ping-eng.com:9031/as/authorization.oauth2?state=MW2OTQo2NXmodI23&nonce=T6pZm8zs34l008Aj&response_type=code&scope=openid&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A61401%2Fauthz_cb&client_id=dc-drFw1l0e5F097Im7OCHIom
0.515redirecthttps://oidc-conformance.ping-eng.com:9031/as/authorization.oauth2?state=MW2OTQo2NXmodI23&nonce=T6pZm8zs34l008Aj&response_type=code&scope=openid&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A61401%2Fauthz_cb&client_id=dc-drFw1l0e5F097Im7OCHIom
5.954responseResponse URL with query part
5.954response{'code': 'TLfdqFDNNtDEEAPNJPe1V_2z94zLacLVJXEUEiRT', 'state': 'MW2OTQo2NXmodI23'}
5.954response{'code': 'TLfdqFDNNtDEEAPNJPe1V_2z94zLacLVJXEUEiRT', 'state': 'MW2OTQo2NXmodI23'}
5.955AuthorizationResponse
{
    "code": "TLfdqFDNNtDEEAPNJPe1V_2z94zLacLVJXEUEiRT",
    "state": "MW2OTQo2NXmodI23"
}
5.955phase<--<-- 4 --- AccessToken -->-->
5.955requestop_args: {'state': 'MW2OTQo2NXmodI23'}, req_args: {'redirect_uri': 'https://op.certification.openid.net:61401/authz_cb'}
5.955do_access_token_request
kwargs:{'request_args': {'redirect_uri': 'https://op.certification.openid.net:61401/authz_cb', 'code': 'TLfdqFDNNtDEEAPNJPe1V_2z94zLacLVJXEUEiRT', 'state': 'MW2OTQo2NXmodI23', 'grant_type': 'authorization_code', 'client_id': 'dc-drFw1l0e5F097Im7OCHIom'}, 'state': 'MW2OTQo2NXmodI23'}
5.955AccessTokenRequest
{
    "code": "TLfdqFDNNtDEEAPNJPe1V_2z94zLacLVJXEUEiRT",
    "grant_type": "authorization_code",
    "redirect_uri": "https://op.certification.openid.net:61401/authz_cb",
    "state": "MW2OTQo2NXmodI23"
}
5.955request_urlhttps://oidc-conformance.ping-eng.com:9031/as/token.oauth2
5.955request_http_args{'headers': {'Authorization': 'Basic ZGMtZHJGdzFsMGU1RjA5N0ltN09DSElvbTpmUjZ3cDdOQks0Y0t3d254S1Bpa1ll', 'Content-Type': 'application/x-www-form-urlencoded'}}
5.955requestgrant_type=authorization_code&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A61401%2Fauthz_cb&code=TLfdqFDNNtDEEAPNJPe1V_2z94zLacLVJXEUEiRT&state=MW2OTQo2NXmodI23
6.423http response
url:https://oidc-conformance.ping-eng.com:9031/as/token.oauth2 status_code:200
6.424response{'access_token': 'eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIn0.eyJzY29wZSI6WyJvcGVuaWQiXSwiY2xpZW50X2lkX25hbWUiOiJkYy1kckZ3MWwwZTVGMDk3SW03T0NISW9tIiwiVXNlcm5hbWUiOiJqb2UiLCJPcmdOYW1lIjoiUGluZyBJZGVudGl0eSBDb3Jwb3JhdGlvbiIsImV4cCI6MTUzNzQ3NzE4OH0.VXpOBKy1SCdu3Fu7k3rVvIEK_Ma4mkzWHjXqQGIivNbcEcHffLRp1AvLZCSApn4hKglPg2WwGV_hz_PjlXDsDJh5KNiBazBp6An1-1qxWEug5Iu1PefcU2ADKi_dfCwKMD_sN-8rcJA8npSu-wIAX8wW5YjcW1XSxpSvjHP0M0NRPaj5HYzMO9aFfd8vvnrK1ahUKUk0140dSGLpFJuLze5k66xdjVJQQexAZe-xaqBSBzF5JRZ6xJlQACcLtM69kx4-Ie_2ggmXk53Tt_WDUL5jNobjffqhqcIf9z8hbfD8bYD83WCj8ebj1ovOYk5SsGHx-tpLuWh35HupdQzuug', 'id_token': 'eyJhbGciOiJSUzI1NiIsImtpZCI6IlJvMmxnRXNPdFdJMlJiRUxLRV85amZvSVRxWSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJkYy1kckZ3MWwwZTVGMDk3SW03T0NISW9tIiwianRpIjoiRkZLV0VVdXBacWlsRXB4Ym9xV2FSMyIsImlzcyI6Imh0dHBzOi8vb2lkYy1jb25mb3JtYW5jZS5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTUzNzQ2OTk4OCwiZXhwIjoxNTM3NDcwMjg4LCJwaS5zcmkiOiJfQ3kzZk93Mko0dFhMdTZ5eUVUQlpuNkZSRVEiLCJub25jZSI6IlQ2cFptOHpzMzRsMDA4QWoiLCJhdXRoX3RpbWUiOjE1Mzc0Njk5ODYsInNfaGFzaCI6Ikh5VnZldE9CZV9ZZjRHNEhxblp0NkEifQ.P_NOFyxyTJa5ylC2TGHfHVKivArKfhm7LHus27e0So3iMVPR5Bsq61RubBAVUCLBYI1gmVkH14EVva8mfwLB-Wv0f7Gq_7etP4x_vRnPnrZOjjJql1w71CrCqZdp9I--k7Dl0ykpiNcgKQJcX0CDZLCJxnYAPS2vlWj8-yZbk_cSYi9Uj3ECBJckubb-SVmBRAHMbxn4s3tyKjEcUq4IPeOsTS5CfqTFCs4qiXWqWdwQK0djaAoZNkQd00OHMAwn7fvCLVby2YjLZycEsNXks70NCwGAGVwFH-xJOLgjBeA1-C1TpJWHbcXDmwhKe58lnr58qJiiv_bcoyTm6ERDog', 'token_type': 'Bearer', 'expires_in': 7199}
6.885AccessTokenResponse
{
    "access_token": "eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIn0.eyJzY29wZSI6WyJvcGVuaWQiXSwiY2xpZW50X2lkX25hbWUiOiJkYy1kckZ3MWwwZTVGMDk3SW03T0NISW9tIiwiVXNlcm5hbWUiOiJqb2UiLCJPcmdOYW1lIjoiUGluZyBJZGVudGl0eSBDb3Jwb3JhdGlvbiIsImV4cCI6MTUzNzQ3NzE4OH0.VXpOBKy1SCdu3Fu7k3rVvIEK_Ma4mkzWHjXqQGIivNbcEcHffLRp1AvLZCSApn4hKglPg2WwGV_hz_PjlXDsDJh5KNiBazBp6An1-1qxWEug5Iu1PefcU2ADKi_dfCwKMD_sN-8rcJA8npSu-wIAX8wW5YjcW1XSxpSvjHP0M0NRPaj5HYzMO9aFfd8vvnrK1ahUKUk0140dSGLpFJuLze5k66xdjVJQQexAZe-xaqBSBzF5JRZ6xJlQACcLtM69kx4-Ie_2ggmXk53Tt_WDUL5jNobjffqhqcIf9z8hbfD8bYD83WCj8ebj1ovOYk5SsGHx-tpLuWh35HupdQzuug",
    "expires_in": 7199,
    "id_token": {
        "aud": [
            "dc-drFw1l0e5F097Im7OCHIom"
        ],
        "auth_time": 1537469986,
        "exp": 1537470288,
        "iat": 1537469988,
        "iss": "https://oidc-conformance.ping-eng.com:9031",
        "jti": "FFKWEUupZqilEpxboqWaR3",
        "nonce": "T6pZm8zs34l008Aj",
        "pi.sri": "_Cy3fOw2J4tXLu6yyETBZn6FREQ",
        "s_hash": "HyVvetOBe_Yf4G4HqnZt6A",
        "sub": "joe"
    },
    "token_type": "Bearer"
}
6.885phase<--<-- 5 --- AsyncAuthn -->-->
6.886AuthorizationRequest
{
    "client_id": "dc-drFw1l0e5F097Im7OCHIom",
    "max_age": 10000,
    "nonce": "XVHSD5CubQ1zcH6C",
    "redirect_uri": "https://op.certification.openid.net:61401/authz_cb",
    "response_type": "code",
    "scope": "openid",
    "state": "lsPxo28R6uJu9RAQ"
}
6.886redirect urlhttps://oidc-conformance.ping-eng.com:9031/as/authorization.oauth2?state=lsPxo28R6uJu9RAQ&nonce=XVHSD5CubQ1zcH6C&response_type=code&scope=openid&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A61401%2Fauthz_cb&max_age=10000&client_id=dc-drFw1l0e5F097Im7OCHIom
6.886redirecthttps://oidc-conformance.ping-eng.com:9031/as/authorization.oauth2?state=lsPxo28R6uJu9RAQ&nonce=XVHSD5CubQ1zcH6C&response_type=code&scope=openid&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A61401%2Fauthz_cb&max_age=10000&client_id=dc-drFw1l0e5F097Im7OCHIom
8.222responseResponse URL with query part
8.223response{'code': '1tK8c-BdNuXAZChB4kBwkEM_o7gWUjKuMNaYQAyK', 'state': 'lsPxo28R6uJu9RAQ'}
8.223response{'code': '1tK8c-BdNuXAZChB4kBwkEM_o7gWUjKuMNaYQAyK', 'state': 'lsPxo28R6uJu9RAQ'}
8.223AuthorizationResponse
{
    "code": "1tK8c-BdNuXAZChB4kBwkEM_o7gWUjKuMNaYQAyK",
    "state": "lsPxo28R6uJu9RAQ"
}
8.223phase<--<-- 6 --- AccessToken -->-->
8.224requestop_args: {'state': 'lsPxo28R6uJu9RAQ'}, req_args: {'redirect_uri': 'https://op.certification.openid.net:61401/authz_cb'}
8.224do_access_token_request
kwargs:{'request_args': {'redirect_uri': 'https://op.certification.openid.net:61401/authz_cb', 'code': '1tK8c-BdNuXAZChB4kBwkEM_o7gWUjKuMNaYQAyK', 'state': 'lsPxo28R6uJu9RAQ', 'grant_type': 'authorization_code', 'client_id': 'dc-drFw1l0e5F097Im7OCHIom'}, 'state': 'lsPxo28R6uJu9RAQ'}
8.224AccessTokenRequest
{
    "code": "1tK8c-BdNuXAZChB4kBwkEM_o7gWUjKuMNaYQAyK",
    "grant_type": "authorization_code",
    "redirect_uri": "https://op.certification.openid.net:61401/authz_cb",
    "state": "lsPxo28R6uJu9RAQ"
}
8.224request_urlhttps://oidc-conformance.ping-eng.com:9031/as/token.oauth2
8.224request_http_args{'headers': {'Authorization': 'Basic ZGMtZHJGdzFsMGU1RjA5N0ltN09DSElvbTpmUjZ3cDdOQks0Y0t3d254S1Bpa1ll', 'Content-Type': 'application/x-www-form-urlencoded'}}
8.224requestgrant_type=authorization_code&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A61401%2Fauthz_cb&code=1tK8c-BdNuXAZChB4kBwkEM_o7gWUjKuMNaYQAyK&state=lsPxo28R6uJu9RAQ
8.647http response
url:https://oidc-conformance.ping-eng.com:9031/as/token.oauth2 status_code:200
8.648response{'access_token': 'eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIn0.eyJzY29wZSI6WyJvcGVuaWQiXSwiY2xpZW50X2lkX25hbWUiOiJkYy1kckZ3MWwwZTVGMDk3SW03T0NISW9tIiwiVXNlcm5hbWUiOiJqb2UiLCJPcmdOYW1lIjoiUGluZyBJZGVudGl0eSBDb3Jwb3JhdGlvbiIsImV4cCI6MTUzNzQ3NzE5MH0.XAGXkhzqfpSdzPs0jfQigaT_nKCcMUrOim8nU9wM29wQAjjDIH7o2MFco6PbN5dksoE55Cr8Xs_0zHQwbz1bs5XE-FRDOCblZaWRjk6JABD3nE5CKhHiwQw7pHU1x9yop5sHiXejV3rfu-0MHK3uQYuH1bl68EcoSgSRb7VzDhlWr-Y0y_mRPoqe6zVCyzNyiV7a-XPcIAFBwQX5qb8Hn7-erKcqHFhhJjfD0dFdqTiR4nYz6ThoXFx12I3EgYXGpssHrYKbTOybpsNHygyMOEzUyHOBowehGUD1BjbpWT8mw2z9hp4VL_yY7tB-eaIhnd_i4B9Ux8vPqeH27XYKBg', 'id_token': 'eyJhbGciOiJSUzI1NiIsImtpZCI6IlJvMmxnRXNPdFdJMlJiRUxLRV85amZvSVRxWSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJkYy1kckZ3MWwwZTVGMDk3SW03T0NISW9tIiwianRpIjoiTzJEMTRDYXJPWldQbkUwSFpjczZGZSIsImlzcyI6Imh0dHBzOi8vb2lkYy1jb25mb3JtYW5jZS5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTUzNzQ2OTk5MCwiZXhwIjoxNTM3NDcwMjkwLCJwaS5zcmkiOiJfQ3kzZk93Mko0dFhMdTZ5eUVUQlpuNkZSRVEiLCJub25jZSI6IlhWSFNENUN1YlExemNINkMiLCJhdXRoX3RpbWUiOjE1Mzc0Njk5ODYsInNfaGFzaCI6ImdwNG9QYkpfbFNxMUdlN2hZdHJVbHcifQ.Abf-zFj9jvKK7eFtjHptBhHcAemPbuzJRR1OTiESV0jRboBnoQpywHAv2B68j5PPdcSG5ZUI3bWV_rQlOmv1-Y8yYf2C6j3XNzl4fMRhRjKEpodLEUnect9Z-XNTY0_nDSf3lFDFSgNCXl2E206gUoukdfF_pAxzRWj_PkuVUUQkM6VbVZwMR6_Tl2SxE30HcRzENJWD3laN0qIdjoM_GpIKwp-xqEdHHZsxu9N-BrhrDpY5vcc9LLW1Jd3lWMZ9slcJ0QMWKicUl4Bb4vjsCcieWotXHpH05sM4TDqHg9Zn6eKAKsd5vhVtersMmnP88-ZRxfMxH3CysVv0GiMcdA', 'token_type': 'Bearer', 'expires_in': 7199}
8.65AccessTokenResponse
{
    "access_token": "eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIn0.eyJzY29wZSI6WyJvcGVuaWQiXSwiY2xpZW50X2lkX25hbWUiOiJkYy1kckZ3MWwwZTVGMDk3SW03T0NISW9tIiwiVXNlcm5hbWUiOiJqb2UiLCJPcmdOYW1lIjoiUGluZyBJZGVudGl0eSBDb3Jwb3JhdGlvbiIsImV4cCI6MTUzNzQ3NzE5MH0.XAGXkhzqfpSdzPs0jfQigaT_nKCcMUrOim8nU9wM29wQAjjDIH7o2MFco6PbN5dksoE55Cr8Xs_0zHQwbz1bs5XE-FRDOCblZaWRjk6JABD3nE5CKhHiwQw7pHU1x9yop5sHiXejV3rfu-0MHK3uQYuH1bl68EcoSgSRb7VzDhlWr-Y0y_mRPoqe6zVCyzNyiV7a-XPcIAFBwQX5qb8Hn7-erKcqHFhhJjfD0dFdqTiR4nYz6ThoXFx12I3EgYXGpssHrYKbTOybpsNHygyMOEzUyHOBowehGUD1BjbpWT8mw2z9hp4VL_yY7tB-eaIhnd_i4B9Ux8vPqeH27XYKBg",
    "expires_in": 7199,
    "id_token": {
        "aud": [
            "dc-drFw1l0e5F097Im7OCHIom"
        ],
        "auth_time": 1537469986,
        "exp": 1537470290,
        "iat": 1537469990,
        "iss": "https://oidc-conformance.ping-eng.com:9031",
        "jti": "O2D14CarOZWPnE0HZcs6Fe",
        "nonce": "XVHSD5CubQ1zcH6C",
        "pi.sri": "_Cy3fOw2J4tXLu6yyETBZn6FREQ",
        "s_hash": "gp4oPbJ_lSq1Ge7hYtrUlw",
        "sub": "joe"
    },
    "token_type": "Bearer"
}
8.651phase<--<-- 7 --- Done -->-->
8.651end
8.651assertionClaimsCheck
8.651conditionclaims-check: status=OK [Checks if specific claims is present or not]
8.651assertionSameAuthn
8.651conditionsame-authn: status=OK [Verifies that the same authentication was used twice in the flow.]
8.652assertionAuthTimeCheck
8.652conditionauth_time-check: status=OK [Check that the auth_time returned in the ID Token is in the expected range.]
8.652assertionVerifyResponse
8.652conditionverify-response: status=OK [Checks that the last response was one of a possible set of OpenID Connect Responses]
8.652conditionDone: status=OK

Result

PASSED