Test Info

Issuerhttps://oidc-conformance.ping-eng.com:9031
Profile[]
Test IDOP-IDToken-RS256
Test descriptionAsymmetric ID Token signature with RS256
Timestamp2018-09-21T17:28:36Z

Conditions


verify-idtoken-is-signed: status=OK [Verifies that an ID Token is signed]
verify-response: status=OK [Checks that the last response was one of a possible set of OpenID Connect Responses]
Done: status=OK

Trace Output

0.0phase<--<-- 0 --- Webfinger -->-->
0.0not expected to doWebFinger
0.0phase<--<-- 1 --- Discovery -->-->
0.0not expected to doDynamic discovery
0.0phase<--<-- 2 --- Registration -->-->
0.0register
kwargs:{'response_types': ['code id_token token'], 'grant_types': ['authorization_code', 'implicit'], 'application_name': 'OIC test tool', 'application_type': 'web', 'redirect_uris': ['https://op.certification.openid.net:61401/authz_cb'], 'contacts': ['roland@example.com'], 'post_logout_redirect_uris': ['https://op.certification.openid.net:61401/logout'], 'url': 'https://oidc-conformance.ping-eng.com:9031/as/clients.oauth2', 'jwks_uri': 'https://op.certification.openid.net:61401/static/jwks_61401.json', 'id_token_signed_response_alg': 'RS256'}
0.001RegistrationRequest
{
    "application_type": "web",
    "contacts": [
        "roland@example.com"
    ],
    "grant_types": [
        "implicit",
        "authorization_code"
    ],
    "id_token_signed_response_alg": "RS256",
    "jwks_uri": "https://op.certification.openid.net:61401/static/jwks_61401.json",
    "post_logout_redirect_uris": [
        "https://op.certification.openid.net:61401/logout"
    ],
    "redirect_uris": [
        "https://op.certification.openid.net:61401/authz_cb"
    ],
    "request_uris": [
        "https://op.certification.openid.net:61401/requests/876669ef2b3891075309a06e00b98e6ace4cfca108af01becb9a804fff95d8c4#eOgUjRR9Nr9XDXPu"
    ],
    "response_types": [
        "code id_token token"
    ]
}
0.374http response
url:https://oidc-conformance.ping-eng.com:9031/as/clients.oauth2 status_code:201
0.374RegistrationResponse
{
    "client_id": "dc-krZHVL0uG5JlOnjuoT89dT",
    "client_name": "dc-krZHVL0uG5JlOnjuoT89dT",
    "client_secret": "T8GI17CVE8V9HkY0W9Y7Ah",
    "client_secret_expires_at": 0,
    "grant_access_session_revocation_api": false,
    "grant_types": [
        "implicit",
        "authorization_code"
    ],
    "id_token_signed_response_alg": "RS256",
    "jwks_uri": "https://op.certification.openid.net:61401/static/jwks_61401.json",
    "persistent_grant_expiration_type": "server_default",
    "pingaccess_logout_capable": false,
    "redirect_uris": [
        "https://op.certification.openid.net:61401/authz_cb"
    ],
    "refresh_token_rolling_policy": "server_default",
    "response_types": [
        "code id_token token"
    ],
    "scope": "address phone edit openid profile admin email",
    "token_endpoint_auth_method": "client_secret_basic",
    "validate_using_all_eligible_atms": false
}
0.374phase<--<-- 3 --- AsyncAuthn -->-->
0.375AuthorizationRequest
{
    "client_id": "dc-krZHVL0uG5JlOnjuoT89dT",
    "nonce": "p0n0knij80XR3Wp4",
    "redirect_uri": "https://op.certification.openid.net:61401/authz_cb",
    "response_type": "code id_token token",
    "scope": "openid",
    "state": "YYlfYFAOKovNboJr"
}
0.375redirect urlhttps://oidc-conformance.ping-eng.com:9031/as/authorization.oauth2?state=YYlfYFAOKovNboJr&nonce=p0n0knij80XR3Wp4&response_type=code+id_token+token&scope=openid&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A61401%2Fauthz_cb&client_id=dc-krZHVL0uG5JlOnjuoT89dT
0.375redirecthttps://oidc-conformance.ping-eng.com:9031/as/authorization.oauth2?state=YYlfYFAOKovNboJr&nonce=p0n0knij80XR3Wp4&response_type=code+id_token+token&scope=openid&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A61401%2Fauthz_cb&client_id=dc-krZHVL0uG5JlOnjuoT89dT
2.37http args{}
2.674responseURL with fragment
2.674responseaccess_token=eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIn0.eyJzY29wZSI6WyJvcGVuaWQiXSwiY2xpZW50X2lkX25hbWUiOiJkYy1rclpIVkwwdUc1SmxPbmp1b1Q4OWRUIiwiYWdpZCI6IkxpMDRYNVJxSzFTUzFrRmlHYjJCTkluVUtzTmNsUTQ2IiwiVXNlcm5hbWUiOiJqb2UiLCJPcmdOYW1lIjoiUGluZyBJZGVudGl0eSBDb3Jwb3JhdGlvbiIsImV4cCI6MTUzNzU1ODExNX0.aavY91bZtKEyB7SfFNh7exFjIAcmuQch_E1G5LeIaHQBlTcZLidNhe1QQNldoBCFgG9NNXhvf5zbp_1QLb0T0B3i3QCbDI4qvoElplwGVb-96dzoJN9LgLFNpXGr_rFx-0O2QKUgNqy30zb__o4CQgq4r0rMdbRPvbI_eacHMaXbEkl0JSGiGIx8lQ7apIaJ8-XVih50WDpxs9AFUXGE-MC3tYnQWgF4igD-_tc0JoZUXmAtCZKUnH2tBdLTKbeXZif-nn8nLeJVGAmREeegf633TVHYLjjKLFrYP_Wyr2U8EcshOs9i9byciW3owEo_rVvMTgiz2NZs7MtnB0KK0w&code=91Yc1_SX1qtSUfNP-c7YDEx2LsWJJ2_AIl5kF0-d&id_token=eyJhbGciOiJSUzI1NiIsImtpZCI6InExa19WZW9TcXRKX0Y1Y2ZlRXRRRkJHcW1LOCJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJkYy1rclpIVkwwdUc1SmxPbmp1b1Q4OWRUIiwianRpIjoiNVlMSHBNM0xEY1JHaEJHeWxWTGJTUCIsImlzcyI6Imh0dHBzOi8vb2lkYy1jb25mb3JtYW5jZS5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTUzNzU1MDkxNSwiZXhwIjoxNTM3NTUxMjE1LCJwaS5zcmkiOiJEQlBWdVNHZ3NzNm1FVW1NaWxoR0NZVUpnRFkiLCJub25jZSI6InAwbjBrbmlqODBYUjNXcDQiLCJhdXRoX3RpbWUiOjE1Mzc1NTA5MDgsImNfaGFzaCI6ImhRY3JraUg2MDRCb3Mwb19rZEl3NXciLCJhdF9oYXNoIjoiaGdNWE9jZDBaLUlFYnloSzBaeWllUSIsInNfaGFzaCI6Ik44MnU5bTRVbFZlSFg2b1JEOWlRQ1EifQ.EcD5Pr5JWFrFO12vtZyvnEeZpzZxqIKLp9GqDEVvFlOnHwAQVs6NM3G1XyPv2pk06yaCx2JlXJ71IHDgO6vPBuQJ7Yt8XsBOfaefAIAw2SS4BlDJfofLQAdr6MFh3TWVA-nYJNM1RZXdZwt-w5iD7KOIfxUk4278C1vBPwwAHcTCm5pZjwlV0shbwgNdKgPdEbW3F8vrlhx8Z_e5EEBK4rpbWsg8t8YDzaW09P7cNYR_6nJp27nRFYVVtNUPbJKb9IBhn0A4LeYZ4oj0vD0fVdISBBkvoC95xRKf8GoZNznfjrWShRhXCUnvEMcG6pGcS2P9ncPt_xT7-SDIgUnQzw&state=YYlfYFAOKovNboJr&token_type=Bearer&expires_in=7199
2.675response{'access_token': 'eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIn0.eyJzY29wZSI6WyJvcGVuaWQiXSwiY2xpZW50X2lkX25hbWUiOiJkYy1rclpIVkwwdUc1SmxPbmp1b1Q4OWRUIiwiYWdpZCI6IkxpMDRYNVJxSzFTUzFrRmlHYjJCTkluVUtzTmNsUTQ2IiwiVXNlcm5hbWUiOiJqb2UiLCJPcmdOYW1lIjoiUGluZyBJZGVudGl0eSBDb3Jwb3JhdGlvbiIsImV4cCI6MTUzNzU1ODExNX0.aavY91bZtKEyB7SfFNh7exFjIAcmuQch_E1G5LeIaHQBlTcZLidNhe1QQNldoBCFgG9NNXhvf5zbp_1QLb0T0B3i3QCbDI4qvoElplwGVb-96dzoJN9LgLFNpXGr_rFx-0O2QKUgNqy30zb__o4CQgq4r0rMdbRPvbI_eacHMaXbEkl0JSGiGIx8lQ7apIaJ8-XVih50WDpxs9AFUXGE-MC3tYnQWgF4igD-_tc0JoZUXmAtCZKUnH2tBdLTKbeXZif-nn8nLeJVGAmREeegf633TVHYLjjKLFrYP_Wyr2U8EcshOs9i9byciW3owEo_rVvMTgiz2NZs7MtnB0KK0w', 'code': '91Yc1_SX1qtSUfNP-c7YDEx2LsWJJ2_AIl5kF0-d', 'id_token': 'eyJhbGciOiJSUzI1NiIsImtpZCI6InExa19WZW9TcXRKX0Y1Y2ZlRXRRRkJHcW1LOCJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJkYy1rclpIVkwwdUc1SmxPbmp1b1Q4OWRUIiwianRpIjoiNVlMSHBNM0xEY1JHaEJHeWxWTGJTUCIsImlzcyI6Imh0dHBzOi8vb2lkYy1jb25mb3JtYW5jZS5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTUzNzU1MDkxNSwiZXhwIjoxNTM3NTUxMjE1LCJwaS5zcmkiOiJEQlBWdVNHZ3NzNm1FVW1NaWxoR0NZVUpnRFkiLCJub25jZSI6InAwbjBrbmlqODBYUjNXcDQiLCJhdXRoX3RpbWUiOjE1Mzc1NTA5MDgsImNfaGFzaCI6ImhRY3JraUg2MDRCb3Mwb19rZEl3NXciLCJhdF9oYXNoIjoiaGdNWE9jZDBaLUlFYnloSzBaeWllUSIsInNfaGFzaCI6Ik44MnU5bTRVbFZlSFg2b1JEOWlRQ1EifQ.EcD5Pr5JWFrFO12vtZyvnEeZpzZxqIKLp9GqDEVvFlOnHwAQVs6NM3G1XyPv2pk06yaCx2JlXJ71IHDgO6vPBuQJ7Yt8XsBOfaefAIAw2SS4BlDJfofLQAdr6MFh3TWVA-nYJNM1RZXdZwt-w5iD7KOIfxUk4278C1vBPwwAHcTCm5pZjwlV0shbwgNdKgPdEbW3F8vrlhx8Z_e5EEBK4rpbWsg8t8YDzaW09P7cNYR_6nJp27nRFYVVtNUPbJKb9IBhn0A4LeYZ4oj0vD0fVdISBBkvoC95xRKf8GoZNznfjrWShRhXCUnvEMcG6pGcS2P9ncPt_xT7-SDIgUnQzw', 'state': 'YYlfYFAOKovNboJr', 'token_type': 'Bearer', 'expires_in': 7199}
3.01AuthorizationResponse
{
    "access_token": "eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIn0.eyJzY29wZSI6WyJvcGVuaWQiXSwiY2xpZW50X2lkX25hbWUiOiJkYy1rclpIVkwwdUc1SmxPbmp1b1Q4OWRUIiwiYWdpZCI6IkxpMDRYNVJxSzFTUzFrRmlHYjJCTkluVUtzTmNsUTQ2IiwiVXNlcm5hbWUiOiJqb2UiLCJPcmdOYW1lIjoiUGluZyBJZGVudGl0eSBDb3Jwb3JhdGlvbiIsImV4cCI6MTUzNzU1ODExNX0.aavY91bZtKEyB7SfFNh7exFjIAcmuQch_E1G5LeIaHQBlTcZLidNhe1QQNldoBCFgG9NNXhvf5zbp_1QLb0T0B3i3QCbDI4qvoElplwGVb-96dzoJN9LgLFNpXGr_rFx-0O2QKUgNqy30zb__o4CQgq4r0rMdbRPvbI_eacHMaXbEkl0JSGiGIx8lQ7apIaJ8-XVih50WDpxs9AFUXGE-MC3tYnQWgF4igD-_tc0JoZUXmAtCZKUnH2tBdLTKbeXZif-nn8nLeJVGAmREeegf633TVHYLjjKLFrYP_Wyr2U8EcshOs9i9byciW3owEo_rVvMTgiz2NZs7MtnB0KK0w",
    "code": "91Yc1_SX1qtSUfNP-c7YDEx2LsWJJ2_AIl5kF0-d",
    "expires_in": 7199,
    "id_token": {
        "at_hash": "hgMXOcd0Z-IEbyhK0ZyieQ",
        "aud": [
            "dc-krZHVL0uG5JlOnjuoT89dT"
        ],
        "auth_time": 1537550908,
        "c_hash": "hQcrkiH604Bos0o_kdIw5w",
        "exp": 1537551215,
        "iat": 1537550915,
        "iss": "https://oidc-conformance.ping-eng.com:9031",
        "jti": "5YLHpM3LDcRGhBGylVLbSP",
        "nonce": "p0n0knij80XR3Wp4",
        "pi.sri": "DBPVuSGgss6mEUmMilhGCYUJgDY",
        "s_hash": "N82u9m4UlVeHX6oRD9iQCQ",
        "sub": "joe"
    },
    "state": "YYlfYFAOKovNboJr",
    "token_type": "Bearer"
}
3.01phase<--<-- 4 --- AccessToken -->-->
3.01requestop_args: {'state': 'YYlfYFAOKovNboJr'}, req_args: {'redirect_uri': 'https://op.certification.openid.net:61401/authz_cb'}
3.01do_access_token_request
kwargs:{'request_args': {'redirect_uri': 'https://op.certification.openid.net:61401/authz_cb', 'code': '91Yc1_SX1qtSUfNP-c7YDEx2LsWJJ2_AIl5kF0-d', 'state': 'YYlfYFAOKovNboJr', 'grant_type': 'authorization_code', 'client_id': 'dc-krZHVL0uG5JlOnjuoT89dT'}, 'state': 'YYlfYFAOKovNboJr'}
3.01AccessTokenRequest
{
    "code": "91Yc1_SX1qtSUfNP-c7YDEx2LsWJJ2_AIl5kF0-d",
    "grant_type": "authorization_code",
    "redirect_uri": "https://op.certification.openid.net:61401/authz_cb",
    "state": "YYlfYFAOKovNboJr"
}
3.01request_urlhttps://oidc-conformance.ping-eng.com:9031/as/token.oauth2
3.01request_http_args{'headers': {'Authorization': 'Basic ZGMta3JaSFZMMHVHNUpsT25qdW9UODlkVDpUOEdJMTdDVkU4VjlIa1kwVzlZN0Fo', 'Content-Type': 'application/x-www-form-urlencoded'}}
3.01requestgrant_type=authorization_code&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A61401%2Fauthz_cb&code=91Yc1_SX1qtSUfNP-c7YDEx2LsWJJ2_AIl5kF0-d&state=YYlfYFAOKovNboJr
3.418http response
url:https://oidc-conformance.ping-eng.com:9031/as/token.oauth2 status_code:200
3.419response{'access_token': 'eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIn0.eyJzY29wZSI6WyJvcGVuaWQiXSwiY2xpZW50X2lkX25hbWUiOiJkYy1rclpIVkwwdUc1SmxPbmp1b1Q4OWRUIiwiVXNlcm5hbWUiOiJqb2UiLCJPcmdOYW1lIjoiUGluZyBJZGVudGl0eSBDb3Jwb3JhdGlvbiIsImV4cCI6MTUzNzU1ODExNn0.sMlTmg10XqvBCyTkBcdyF_Glrg3PXf68ED4rvQLv52TW-IdhbNC06JkaJBz3Egvzue-s5r7gToz86g-1UnH3nIxmpKOWy9nC3cYXSmrchzGShsV4wyioqwLbvoAX44f0shs_mnyBVJ0Na2yCiFZhH1GNr7KINGC1pa0hM7UiN3uJhgk-l3Q32sq0p6nxSSOhlXUbTypPgurTIEkozQZSSCmb20FcvH5UzUq2n3_Uk7Jh5QxsOQRDelN4o_LEu9nsMuTnX9BpC_-3vE8_ApmOoYcoGCkAA4aHM-32k7leh9zRaGe5fhpUa5U0CU3uy-s4dQ3U-TGJ3Y7Ks7ylwGJyBw', 'id_token': 'eyJhbGciOiJSUzI1NiIsImtpZCI6InExa19WZW9TcXRKX0Y1Y2ZlRXRRRkJHcW1LOCJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJkYy1rclpIVkwwdUc1SmxPbmp1b1Q4OWRUIiwianRpIjoiNVlMSHBNM0xEY1JHaEJHeWxWTGJTUCIsImlzcyI6Imh0dHBzOi8vb2lkYy1jb25mb3JtYW5jZS5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTUzNzU1MDkxNSwiZXhwIjoxNTM3NTUxMjE1LCJwaS5zcmkiOiJEQlBWdVNHZ3NzNm1FVW1NaWxoR0NZVUpnRFkiLCJub25jZSI6InAwbjBrbmlqODBYUjNXcDQiLCJhdXRoX3RpbWUiOjE1Mzc1NTA5MDgsImNfaGFzaCI6ImhRY3JraUg2MDRCb3Mwb19rZEl3NXciLCJhdF9oYXNoIjoiaGdNWE9jZDBaLUlFYnloSzBaeWllUSIsInNfaGFzaCI6Ik44MnU5bTRVbFZlSFg2b1JEOWlRQ1EifQ.EcD5Pr5JWFrFO12vtZyvnEeZpzZxqIKLp9GqDEVvFlOnHwAQVs6NM3G1XyPv2pk06yaCx2JlXJ71IHDgO6vPBuQJ7Yt8XsBOfaefAIAw2SS4BlDJfofLQAdr6MFh3TWVA-nYJNM1RZXdZwt-w5iD7KOIfxUk4278C1vBPwwAHcTCm5pZjwlV0shbwgNdKgPdEbW3F8vrlhx8Z_e5EEBK4rpbWsg8t8YDzaW09P7cNYR_6nJp27nRFYVVtNUPbJKb9IBhn0A4LeYZ4oj0vD0fVdISBBkvoC95xRKf8GoZNznfjrWShRhXCUnvEMcG6pGcS2P9ncPt_xT7-SDIgUnQzw', 'token_type': 'Bearer', 'expires_in': 7199}
3.421AccessTokenResponse
{
    "access_token": "eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIn0.eyJzY29wZSI6WyJvcGVuaWQiXSwiY2xpZW50X2lkX25hbWUiOiJkYy1rclpIVkwwdUc1SmxPbmp1b1Q4OWRUIiwiVXNlcm5hbWUiOiJqb2UiLCJPcmdOYW1lIjoiUGluZyBJZGVudGl0eSBDb3Jwb3JhdGlvbiIsImV4cCI6MTUzNzU1ODExNn0.sMlTmg10XqvBCyTkBcdyF_Glrg3PXf68ED4rvQLv52TW-IdhbNC06JkaJBz3Egvzue-s5r7gToz86g-1UnH3nIxmpKOWy9nC3cYXSmrchzGShsV4wyioqwLbvoAX44f0shs_mnyBVJ0Na2yCiFZhH1GNr7KINGC1pa0hM7UiN3uJhgk-l3Q32sq0p6nxSSOhlXUbTypPgurTIEkozQZSSCmb20FcvH5UzUq2n3_Uk7Jh5QxsOQRDelN4o_LEu9nsMuTnX9BpC_-3vE8_ApmOoYcoGCkAA4aHM-32k7leh9zRaGe5fhpUa5U0CU3uy-s4dQ3U-TGJ3Y7Ks7ylwGJyBw",
    "expires_in": 7199,
    "id_token": {
        "at_hash": "hgMXOcd0Z-IEbyhK0ZyieQ",
        "aud": [
            "dc-krZHVL0uG5JlOnjuoT89dT"
        ],
        "auth_time": 1537550908,
        "c_hash": "hQcrkiH604Bos0o_kdIw5w",
        "exp": 1537551215,
        "iat": 1537550915,
        "iss": "https://oidc-conformance.ping-eng.com:9031",
        "jti": "5YLHpM3LDcRGhBGylVLbSP",
        "nonce": "p0n0knij80XR3Wp4",
        "pi.sri": "DBPVuSGgss6mEUmMilhGCYUJgDY",
        "s_hash": "N82u9m4UlVeHX6oRD9iQCQ",
        "sub": "joe"
    },
    "token_type": "Bearer"
}
3.421phase<--<-- 5 --- Done -->-->
3.421end
3.422assertionVerifySignedIdToken
3.422conditionverify-idtoken-is-signed: status=OK [Verifies that an ID Token is signed]
3.422assertionVerifyResponse
3.422conditionverify-response: status=OK [Checks that the last response was one of a possible set of OpenID Connect Responses]
3.422conditionDone: status=OK

Result

PASSED