Test Info

Issuerhttps://oidc-conformance.ping-eng.com:9031
Profile[]
Test IDOP-IDToken-kid
Test descriptionIDToken has kid [Basic, Implicit, Hybrid]
Timestamp2018-09-20T23:41:31Z

Conditions


verify-response: status=OK [Checks that the last response was one of a possible set of OpenID Connect Responses]
verify-signed-idtoken-has-kid: status=OK [Verifies that the header of a signed IDToken includes a kid claim.]
Done: status=OK

Trace Output

0.0phase<--<-- 0 --- Webfinger -->-->
0.0not expected to doWebFinger
0.0phase<--<-- 1 --- Discovery -->-->
0.0not expected to doDynamic discovery
0.0phase<--<-- 2 --- Registration -->-->
0.0register
kwargs:{'response_types': ['code id_token'], 'grant_types': ['authorization_code', 'implicit'], 'application_name': 'OIC test tool', 'application_type': 'web', 'redirect_uris': ['https://op.certification.openid.net:61401/authz_cb'], 'contacts': ['roland@example.com'], 'post_logout_redirect_uris': ['https://op.certification.openid.net:61401/logout'], 'url': 'https://oidc-conformance.ping-eng.com:9031/as/clients.oauth2', 'jwks_uri': 'https://op.certification.openid.net:61401/static/jwks_61401.json'}
0.001RegistrationRequest
{
    "application_type": "web",
    "contacts": [
        "roland@example.com"
    ],
    "grant_types": [
        "implicit",
        "authorization_code"
    ],
    "jwks_uri": "https://op.certification.openid.net:61401/static/jwks_61401.json",
    "post_logout_redirect_uris": [
        "https://op.certification.openid.net:61401/logout"
    ],
    "redirect_uris": [
        "https://op.certification.openid.net:61401/authz_cb"
    ],
    "request_uris": [
        "https://op.certification.openid.net:61401/requests/876669ef2b3891075309a06e00b98e6ace4cfca108af01becb9a804fff95d8c4#KzkMpuFCYn3KsQbd"
    ],
    "response_types": [
        "code id_token"
    ]
}
0.316http response
url:https://oidc-conformance.ping-eng.com:9031/as/clients.oauth2 status_code:201
0.317RegistrationResponse
{
    "client_id": "dc-WRymVBuxuZTZDsKpY5W6nX",
    "client_name": "dc-WRymVBuxuZTZDsKpY5W6nX",
    "client_secret": "iJb9GZWOwYnmLH92KXlLNb",
    "client_secret_expires_at": 0,
    "grant_access_session_revocation_api": false,
    "grant_types": [
        "implicit",
        "authorization_code"
    ],
    "jwks_uri": "https://op.certification.openid.net:61401/static/jwks_61401.json",
    "persistent_grant_expiration_type": "server_default",
    "pingaccess_logout_capable": false,
    "redirect_uris": [
        "https://op.certification.openid.net:61401/authz_cb"
    ],
    "refresh_token_rolling_policy": "server_default",
    "response_types": [
        "code id_token"
    ],
    "scope": "address phone edit openid profile admin email",
    "token_endpoint_auth_method": "client_secret_basic",
    "validate_using_all_eligible_atms": false
}
0.317phase<--<-- 3 --- AsyncAuthn -->-->
0.318AuthorizationRequest
{
    "client_id": "dc-WRymVBuxuZTZDsKpY5W6nX",
    "nonce": "nRqJvoyyZCHsMWgN",
    "redirect_uri": "https://op.certification.openid.net:61401/authz_cb",
    "response_type": "code id_token",
    "scope": "openid",
    "state": "6zvu1qiZFVe48bLq"
}
0.318redirect urlhttps://oidc-conformance.ping-eng.com:9031/as/authorization.oauth2?state=6zvu1qiZFVe48bLq&nonce=nRqJvoyyZCHsMWgN&response_type=code+id_token&scope=openid&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A61401%2Fauthz_cb&client_id=dc-WRymVBuxuZTZDsKpY5W6nX
0.318redirecthttps://oidc-conformance.ping-eng.com:9031/as/authorization.oauth2?state=6zvu1qiZFVe48bLq&nonce=nRqJvoyyZCHsMWgN&response_type=code+id_token&scope=openid&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A61401%2Fauthz_cb&client_id=dc-WRymVBuxuZTZDsKpY5W6nX
3.244http args{}
3.564responseURL with fragment
3.564responsecode=tZvHFpDp8U0h24pqm3gUXd7V6kdXbApEZEb9wTYN&id_token=eyJhbGciOiJSUzI1NiIsImtpZCI6IlJvMmxnRXNPdFdJMlJiRUxLRV85amZvSVRxWSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJkYy1XUnltVkJ1eHVaVFpEc0twWTVXNm5YIiwianRpIjoiVDRLWXpwQ1hKYUozN2lLQ2lVdUdicSIsImlzcyI6Imh0dHBzOi8vb2lkYy1jb25mb3JtYW5jZS5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTUzNzQ4Njg5MCwiZXhwIjoxNTM3NDg3MTkwLCJwaS5zcmkiOiJhSlgxT20zZ2p1MkF1Unl1ZWg5WnVZdzllbTAiLCJub25jZSI6Im5ScUp2b3l5WkNIc01XZ04iLCJhdXRoX3RpbWUiOjE1Mzc0ODUxMjMsImNfaGFzaCI6IkxXWDhWUXBtVjY4a2RVeXpKTEZxSVEiLCJzX2hhc2giOiIyd3MxRDluQUZaT1BET2xBU1RyT3RRIn0.UJV8rPw9Hb8XAv7G-rnTogdynBGVC9i7ANLVUIcfkGGQ2PNJi1mqWsXl8zP55TRdBsLj1tWcmTkn4dJCgH13ja6entVpow71Jg9rZ6gxJw-SScXUB-5I99MeHQuzQ5ec475_WwIqXzOd0hJEK9z1Ya9L8EWZSWaxqnchfjHsEXm9emVV1NDv7nmbVfCeBh5sdGyw-KsnxMSHft7sQjP_UhlChXohl3L4V33TyGOOjSpvnVP5wAoqATGhkQBxxzzPL3rXEzeSBrN5DhgqvXZ71V9x5nRmmRwmPFJM90pR_k5Tjj5UAC58OzK4I9j-vzduW4VLAuljBJG6oN2fmbxoHQ&state=6zvu1qiZFVe48bLq
3.564response{'code': 'tZvHFpDp8U0h24pqm3gUXd7V6kdXbApEZEb9wTYN', 'id_token': 'eyJhbGciOiJSUzI1NiIsImtpZCI6IlJvMmxnRXNPdFdJMlJiRUxLRV85amZvSVRxWSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJkYy1XUnltVkJ1eHVaVFpEc0twWTVXNm5YIiwianRpIjoiVDRLWXpwQ1hKYUozN2lLQ2lVdUdicSIsImlzcyI6Imh0dHBzOi8vb2lkYy1jb25mb3JtYW5jZS5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTUzNzQ4Njg5MCwiZXhwIjoxNTM3NDg3MTkwLCJwaS5zcmkiOiJhSlgxT20zZ2p1MkF1Unl1ZWg5WnVZdzllbTAiLCJub25jZSI6Im5ScUp2b3l5WkNIc01XZ04iLCJhdXRoX3RpbWUiOjE1Mzc0ODUxMjMsImNfaGFzaCI6IkxXWDhWUXBtVjY4a2RVeXpKTEZxSVEiLCJzX2hhc2giOiIyd3MxRDluQUZaT1BET2xBU1RyT3RRIn0.UJV8rPw9Hb8XAv7G-rnTogdynBGVC9i7ANLVUIcfkGGQ2PNJi1mqWsXl8zP55TRdBsLj1tWcmTkn4dJCgH13ja6entVpow71Jg9rZ6gxJw-SScXUB-5I99MeHQuzQ5ec475_WwIqXzOd0hJEK9z1Ya9L8EWZSWaxqnchfjHsEXm9emVV1NDv7nmbVfCeBh5sdGyw-KsnxMSHft7sQjP_UhlChXohl3L4V33TyGOOjSpvnVP5wAoqATGhkQBxxzzPL3rXEzeSBrN5DhgqvXZ71V9x5nRmmRwmPFJM90pR_k5Tjj5UAC58OzK4I9j-vzduW4VLAuljBJG6oN2fmbxoHQ', 'state': '6zvu1qiZFVe48bLq'}
3.867AuthorizationResponse
{
    "code": "tZvHFpDp8U0h24pqm3gUXd7V6kdXbApEZEb9wTYN",
    "id_token": {
        "aud": [
            "dc-WRymVBuxuZTZDsKpY5W6nX"
        ],
        "auth_time": 1537485123,
        "c_hash": "LWX8VQpmV68kdUyzJLFqIQ",
        "exp": 1537487190,
        "iat": 1537486890,
        "iss": "https://oidc-conformance.ping-eng.com:9031",
        "jti": "T4KYzpCXJaJ37iKCiUuGbq",
        "nonce": "nRqJvoyyZCHsMWgN",
        "pi.sri": "aJX1Om3gju2AuRyueh9ZuYw9em0",
        "s_hash": "2ws1D9nAFZOPDOlASTrOtQ",
        "sub": "joe"
    },
    "state": "6zvu1qiZFVe48bLq"
}
3.867phase<--<-- 4 --- AccessToken -->-->
3.867requestop_args: {'state': '6zvu1qiZFVe48bLq'}, req_args: {'redirect_uri': 'https://op.certification.openid.net:61401/authz_cb'}
3.867do_access_token_request
kwargs:{'request_args': {'redirect_uri': 'https://op.certification.openid.net:61401/authz_cb', 'code': 'tZvHFpDp8U0h24pqm3gUXd7V6kdXbApEZEb9wTYN', 'state': '6zvu1qiZFVe48bLq', 'grant_type': 'authorization_code', 'client_id': 'dc-WRymVBuxuZTZDsKpY5W6nX'}, 'state': '6zvu1qiZFVe48bLq'}
3.867AccessTokenRequest
{
    "code": "tZvHFpDp8U0h24pqm3gUXd7V6kdXbApEZEb9wTYN",
    "grant_type": "authorization_code",
    "redirect_uri": "https://op.certification.openid.net:61401/authz_cb",
    "state": "6zvu1qiZFVe48bLq"
}
3.867request_urlhttps://oidc-conformance.ping-eng.com:9031/as/token.oauth2
3.867request_http_args{'headers': {'Authorization': 'Basic ZGMtV1J5bVZCdXh1WlRaRHNLcFk1VzZuWDppSmI5R1pXT3dZbm1MSDkyS1hsTE5i', 'Content-Type': 'application/x-www-form-urlencoded'}}
3.867requestgrant_type=authorization_code&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A61401%2Fauthz_cb&code=tZvHFpDp8U0h24pqm3gUXd7V6kdXbApEZEb9wTYN&state=6zvu1qiZFVe48bLq
4.22http response
url:https://oidc-conformance.ping-eng.com:9031/as/token.oauth2 status_code:200
4.221response{'access_token': 'eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIn0.eyJzY29wZSI6WyJvcGVuaWQiXSwiY2xpZW50X2lkX25hbWUiOiJkYy1XUnltVkJ1eHVaVFpEc0twWTVXNm5YIiwiVXNlcm5hbWUiOiJqb2UiLCJPcmdOYW1lIjoiUGluZyBJZGVudGl0eSBDb3Jwb3JhdGlvbiIsImV4cCI6MTUzNzQ5NDA5MX0.qYVi6McVXBTJp59qnndvSBXUwITYVOlEt87RHUSSCNEkWjcMT9yljN6zHxX-yiHuYvoQ5w5AC3oX_mD0YMvIclD6KZteixIoZlZnySCvG4IQKjR2ZUE2Nv-sInV3Q-zSE91aItASfOxbcQ9iNqXpe7EPocHDPpbAHpu6qzSRnE-YTgW3ksOGPtE9jc2iAwu2S_nFRlI9rGF7YoVhaKY965yxs5ZXR8SaDvHYmq4Qu08yb7Nc-iPGQUnk3TFqqiFNkRO0609xtN1v0iDzvs0HS-UgG9lH6jMmjge66ielXD8X9_L4nqICSLaclKglS1b-FS7IfBVhmYUKlinvr6miQw', 'id_token': 'eyJhbGciOiJSUzI1NiIsImtpZCI6IlJvMmxnRXNPdFdJMlJiRUxLRV85amZvSVRxWSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJkYy1XUnltVkJ1eHVaVFpEc0twWTVXNm5YIiwianRpIjoiVDRLWXpwQ1hKYUozN2lLQ2lVdUdicSIsImlzcyI6Imh0dHBzOi8vb2lkYy1jb25mb3JtYW5jZS5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTUzNzQ4Njg5MCwiZXhwIjoxNTM3NDg3MTkwLCJwaS5zcmkiOiJhSlgxT20zZ2p1MkF1Unl1ZWg5WnVZdzllbTAiLCJub25jZSI6Im5ScUp2b3l5WkNIc01XZ04iLCJhdXRoX3RpbWUiOjE1Mzc0ODUxMjMsImNfaGFzaCI6IkxXWDhWUXBtVjY4a2RVeXpKTEZxSVEiLCJzX2hhc2giOiIyd3MxRDluQUZaT1BET2xBU1RyT3RRIn0.UJV8rPw9Hb8XAv7G-rnTogdynBGVC9i7ANLVUIcfkGGQ2PNJi1mqWsXl8zP55TRdBsLj1tWcmTkn4dJCgH13ja6entVpow71Jg9rZ6gxJw-SScXUB-5I99MeHQuzQ5ec475_WwIqXzOd0hJEK9z1Ya9L8EWZSWaxqnchfjHsEXm9emVV1NDv7nmbVfCeBh5sdGyw-KsnxMSHft7sQjP_UhlChXohl3L4V33TyGOOjSpvnVP5wAoqATGhkQBxxzzPL3rXEzeSBrN5DhgqvXZ71V9x5nRmmRwmPFJM90pR_k5Tjj5UAC58OzK4I9j-vzduW4VLAuljBJG6oN2fmbxoHQ', 'token_type': 'Bearer', 'expires_in': 7199}
4.224AccessTokenResponse
{
    "access_token": "eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIn0.eyJzY29wZSI6WyJvcGVuaWQiXSwiY2xpZW50X2lkX25hbWUiOiJkYy1XUnltVkJ1eHVaVFpEc0twWTVXNm5YIiwiVXNlcm5hbWUiOiJqb2UiLCJPcmdOYW1lIjoiUGluZyBJZGVudGl0eSBDb3Jwb3JhdGlvbiIsImV4cCI6MTUzNzQ5NDA5MX0.qYVi6McVXBTJp59qnndvSBXUwITYVOlEt87RHUSSCNEkWjcMT9yljN6zHxX-yiHuYvoQ5w5AC3oX_mD0YMvIclD6KZteixIoZlZnySCvG4IQKjR2ZUE2Nv-sInV3Q-zSE91aItASfOxbcQ9iNqXpe7EPocHDPpbAHpu6qzSRnE-YTgW3ksOGPtE9jc2iAwu2S_nFRlI9rGF7YoVhaKY965yxs5ZXR8SaDvHYmq4Qu08yb7Nc-iPGQUnk3TFqqiFNkRO0609xtN1v0iDzvs0HS-UgG9lH6jMmjge66ielXD8X9_L4nqICSLaclKglS1b-FS7IfBVhmYUKlinvr6miQw",
    "expires_in": 7199,
    "id_token": {
        "aud": [
            "dc-WRymVBuxuZTZDsKpY5W6nX"
        ],
        "auth_time": 1537485123,
        "c_hash": "LWX8VQpmV68kdUyzJLFqIQ",
        "exp": 1537487190,
        "iat": 1537486890,
        "iss": "https://oidc-conformance.ping-eng.com:9031",
        "jti": "T4KYzpCXJaJ37iKCiUuGbq",
        "nonce": "nRqJvoyyZCHsMWgN",
        "pi.sri": "aJX1Om3gju2AuRyueh9ZuYw9em0",
        "s_hash": "2ws1D9nAFZOPDOlASTrOtQ",
        "sub": "joe"
    },
    "token_type": "Bearer"
}
4.224phase<--<-- 5 --- Done -->-->
4.224end
4.224assertionVerifyResponse
4.224conditionverify-response: status=OK [Checks that the last response was one of a possible set of OpenID Connect Responses]
4.225assertionVerifySignedIdTokenHasKID
4.225conditionverify-signed-idtoken-has-kid: status=OK [Verifies that the header of a signed IDToken includes a kid claim.]
4.225conditionDone: status=OK

Result

PASSED