Test Summary

Test Results

Expand All Collapse All
All times are UTC
2021-02-10 09:54:19 INFO
TEST-RUNNER
Test instance HgQnndsopXRfcwQ created
baseUrl
https://www.certification.openid.net/test/a/robotto-internal-2
variant
{
  "client_auth_type": "private_key_jwt",
  "ciba_mode": "ping",
  "fapi_profile": "plain_fapi",
  "client_registration": "static_client"
}
alias
robotto-internal-2
description
Initial test
planId
R3sICwc4v1jsm
config
{
  "alias": "robotto-internal-2",
  "description": "Initial test",
  "server": {
    "discoveryUrl": "https://emea-conformance.ping-eng.com:9031/.well-known/openid-configuration"
  },
  "client": {
    "client_id": "conformance3ping",
    "scope": "openid test",
    "jwks": {
      "keys": [
        {
          "kty": "EC",
          "d": "QPg1PBy12DhqqGeiuWBoIdhrfbOutP8nfSND46mdTgU",
          "use": "sig",
          "crv": "P-256",
          "kid": "2HKyz2Uc4F8hRcwyuPgA5Eg_salnEe7pfujUkvj2yew",
          "x": "NK3-2enqupOW-PGDSp2X2vrtqFIVnsVMciZdVwa7p8Q",
          "y": "Yrp1yMUYXZcWbHRzsXlH94v2SJZs0lxRbbCpvo1kcUw",
          "alg": "ES256"
        }
      ]
    },
    "hint_type": "login_hint",
    "hint_value": "patrick"
  },
  "mtls": {
    "cert": "-----BEGIN CERTIFICATE-----\nMIIDlTCCAn2gAwIBAgIJAKRJoaX7BlZbMA0GCSqGSIb3DQEBCwUAMGAxCzAJBgNV\nBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMR0wGwYDVQQKDBRBdXRobGV0ZSBU\nZXN0IENsaWVudDEdMBsGA1UEAwwUQXV0aGxldGUgVGVzdCBDbGllbnQwIBcNMTgw\nNTI1MjA1NzU0WhgPMjEwNjAxMDQyMDU3NTRaMGAxCzAJBgNVBAYTAlVTMRMwEQYD\nVQQIDApTb21lLVN0YXRlMR0wGwYDVQQKDBRBdXRobGV0ZSBUZXN0IENsaWVudDEd\nMBsGA1UEAwwUQXV0aGxldGUgVGVzdCBDbGllbnQwggEiMA0GCSqGSIb3DQEBAQUA\nA4IBDwAwggEKAoIBAQDEWwl/Q+nuL8KXbObpVzww1VkHwLF4W9QxrPI1V0Uh6V9r\nxUjrfSbtWNEQVDwQmoW8M1XjnRnGvdNRd0m6gNEQLKsqRN2xIvPdR0IO+2b+y7WJ\n9XlwdqHAFSWQJtoHzBAmkRirRMJrQSW5sB/NIBmyVqUdTV/FghNjc+IiPF4X1kxw\nwOzm7y2zlHZUpiPQknwPbWNeyunj/XQRrqWPg+RXzAKIjbVprxGaT8CexKu6oEae\nd8BCTO0rJIOkmjXZMl+SDhXQn9GHKFh60UlJddxVngxhX63MAQ1GsO8HsjrLgO3q\n4LmTDVHkprLy/wgBRDfo0IHb3gWhbOuRGMLLMKKvAgMBAAGjUDBOMB0GA1UdDgQW\nBBRuwpA4lqWaOkwmPcTQR8CH0Iv3vjAfBgNVHSMEGDAWgBRuwpA4lqWaOkwmPcTQ\nR8CH0Iv3vjAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQBiCmvQmmKq\nI/8sB312HTEFlvtpbYp429eNCGXWloOOqVQkJaBnvy9YUS/wCgusyKeMBgbgpV0s\n8bp/gEW2/MnlWW9+fbFuhzRRwvuV/7je1Avv9Y06RH8GKJYwk2j6qcO7Mn9kVhln\nlKxGdFxm/i0OBuZnUe/KDxKPjVEdUJbxAFfxdq4cUjfewMuoxsYruIDnLXjTBcj2\nPbJ6vcPzq/6TYwxRmnrXIAO6Nxe8ZNXn2x2+njwrUKW4WPQ7u3dyHlD+M3iTpm3T\nwSgg0FSYiBcXhWJLQCJVEb0kbKJ/PDmcvomusQWTL/0epS62azWG8PUUs4v9Xeae\nmAbHqPGh+5Bo\n-----END CERTIFICATE-----\n",
    "key": "-----BEGIN PRIVATE KEY-----\nMIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDEWwl/Q+nuL8KX\nbObpVzww1VkHwLF4W9QxrPI1V0Uh6V9rxUjrfSbtWNEQVDwQmoW8M1XjnRnGvdNR\nd0m6gNEQLKsqRN2xIvPdR0IO+2b+y7WJ9XlwdqHAFSWQJtoHzBAmkRirRMJrQSW5\nsB/NIBmyVqUdTV/FghNjc+IiPF4X1kxwwOzm7y2zlHZUpiPQknwPbWNeyunj/XQR\nrqWPg+RXzAKIjbVprxGaT8CexKu6oEaed8BCTO0rJIOkmjXZMl+SDhXQn9GHKFh6\n0UlJddxVngxhX63MAQ1GsO8HsjrLgO3q4LmTDVHkprLy/wgBRDfo0IHb3gWhbOuR\nGMLLMKKvAgMBAAECggEAJ3uOy1JipYxg+oXhYKYz6jXcMxziEquUXXDDO0qTEiCV\nGVyQLxn5S9yCHWByu3v2zEMeUCh02GuvJEBySNhCMZhpypQSZ935X1NGyzBuI2ne\n1SDRDHYuTCt0ZCoLyWmVDcw7Q6UN2vc8mLv7iQmdYSjfBqdaTKK9N1BD9lJhMTWB\njxQDaF1yEZQfR1HOVVddJXt8ILOOltuxhu4EuBKsT8ZlCAN5kGx6+FzXlGlSYjWn\nGoYbERESeDim3JDwGOGX2msPGOmSzF24LnXrPg8IcrwEbzlFRIEzd8yUVA6VNca7\n1uzv/MaOX5+cTtDiAoVdfrk1Ykt1SNNccGKnC7L3MQKBgQD29FIhT21DkUnXlABK\nj0N9dBSQyQ1HzILmY/YSg7aeBAlatEzCDxHtFaS89wXxosz2vNd1QKIrLrAgSzTL\nyemi2KVcvsHyo0g0drSq3NlOw5Rz4WRAZNgBcuhFJ8ZD1BJCisdQxQyCRJ3I0pf/\nD7mGkmovII1WSk/MIEWWvd3P6wKBgQDLjEEOaTeopbnqkJrcL4UbV2GmVAIa9EXS\nqzRTrPlxVA62n8EEX5YLXTx6yrvWHWtlA4VgRmUGuu1km5DqlnVdVz/l8fSk2HFc\ndycJgKd189v/tQ+BLu50+1+uaHiWLXo3VEXgv5QKSgPxWEnNPRVbgqOhav2MaACK\no9sl3h4LTQKBgQCjyIxD7VKREmW/5TeAO53OMVOGZuE48ikKtdc4lkRibljp4FRc\nC/SeodEdRlOZ25hGOB5JdHFZZGCJOneshKBAUaDybs1gp+w2Z1gRTeGNvGbTp/N+\nRaOA6n2jh+qVh6wIl9Py/Iz8RJfE3e7SydIIr0hfMx6p0SU1Q14DyK64uwKBgQCi\nqM5ESejkqKtNu4lFc+QW2Vl7pZ6ZE6PImnASfiRIYDfx0PBaIlixdCyko+Y/UPtF\nme635QlOu4qB35+LF/lqQhMaGqS6Jw1QKxfTDDDGnb2tNm/ReEOu0ELCCVJ0EJue\nI4ZD+FTBdCx6bWdsz+eFXXyNvgYoceQc5px2Qm4X8QKBgHwpmIeHCvU9Erb9X5pY\n5JR609Ei+a9jksoe0ch7ocZi2NoE3vwjUSZFe/hTkvpf0gUhw1Zmekqhm78Qb4H7\nAq7RDbpyCvoRXGS4GulFXM9Tkfe5FejhawT6fG12KLHOSAkJNgdFCPvFOaHlxPoA\naBcf1sY/flehjWEwkVDSh0Js\n-----END PRIVATE KEY-----\n"
  },
  "client2": {
    "client_id": "conformance4ping",
    "scope": "openid test",
    "jwks": {
      "keys": [
        {
          "kty": "EC",
          "d": "MTbmR5F_tN0zlvVrwESkMNHB-ZLoRpk3dlxHYged3Ik",
          "use": "sig",
          "crv": "P-256",
          "kid": "6waBCAJKuKMvSU3k540XHPx_4gJx01tmQh8giaYjj1k",
          "x": "XW7xFTCnyPLhhWb_dE0fIIavYTbilf3HDsUELAC5SwI",
          "y": "sm9SrdwPWJ_oQ5tbsDMi6xnsaoLWZLTFyy0L2q5vURE",
          "alg": "ES256"
        }
      ]
    },
    "acr_value": "high"
  },
  "mtls2": {
    "cert": "-----BEGIN CERTIFICATE-----\nMIIDhTCCAm2gAwIBAgIJAKAe4HusBvwoMA0GCSqGSIb3DQEBCwUAMFgxCzAJBgNV\nBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMSEwHwYDVQQKDBhJbnRlcm5ldCBX\naWRnaXRzIFB0eSBMdGQxETAPBgNVBAMMCGNsaWVudF8yMCAXDTE4MDcwMjE2MzUy\nOFoYDzIxMDYwMjExMTYzNTI4WjBYMQswCQYDVQQGEwJVUzETMBEGA1UECAwKU29t\nZS1TdGF0ZTEhMB8GA1UECgwYSW50ZXJuZXQgV2lkZ2l0cyBQdHkgTHRkMREwDwYD\nVQQDDAhjbGllbnRfMjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANMy\n1QohUbUoyte8cYCCO1+vJ/GImvVkrb79HUTSzL3G46lDC0JYZGMpMvX9NncadCYL\nQV8fmofOouNs4AWJgf0skH5sAJcZMgj3GVqqLsx2iDye3cgqsCCzTf5gzhOVtpXg\nNoBMFckVGxI+dG9h06n71mH9dtGoD/BoWOB4FLae0Ec4olot5eROeJ3Z0J15aXPW\noQrn3J5Eoz0/c7D7+byb+XGjF/r+uJVrKqOLtnO69Ro99fowwVtVQAPHmxLQ9VvF\niLONwbOfELtBvX4MlxHDOuynDsDw/mHxkzMSxPXAd9QfIU05ySZ9eVR3UfNUeCk8\na63NSO8MZdfHFnUsEO8CAwEAAaNQME4wHQYDVR0OBBYEFFEdch1XYRpO5JXxPkBx\ndAoAt6IiMB8GA1UdIwQYMBaAFFEdch1XYRpO5JXxPkBxdAoAt6IiMAwGA1UdEwQF\nMAMBAf8wDQYJKoZIhvcNAQELBQADggEBABTTN0up/ndWCNamqrV8ik1XwUqPCAO7\nTYKmZrRilo3STxyp2aUiFf1uPSkU6WU4Eu0JoDKU46axIFzZO3Ckoq17JMde2OzE\nSlAF+hQyvg/3l+6mbBK/OuzOiC+yfU9roD6vmjsBlH0My1+CnqkZLr6YQSaCHffl\nb6zqA7+aLUEWjyVneD6jQ6CCFwCs6eDorY1eKFM7lCQ5OdJFBc2LOOXuSGRXLZDK\nF3X2SfKCld0VWIOknJk8drfrCc1ylWa7wIuXU/kTyX8Z68a8w1/6ZkGxN9tsHWVt\nSe6ggOD1AFI5OQ3c8lCUzgGeFl69hz2UduHOyWs1KXUhgSy7fViAP90\u003d\n-----END CERTIFICATE-----\n",
    "key": "-----BEGIN PRIVATE KEY-----\nMIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQDTMtUKIVG1KMrX\nvHGAgjtfryfxiJr1ZK2+/R1E0sy9xuOpQwtCWGRjKTL1/TZ3GnQmC0FfH5qHzqLj\nbOAFiYH9LJB+bACXGTII9xlaqi7Mdog8nt3IKrAgs03+YM4TlbaV4DaATBXJFRsS\nPnRvYdOp+9Zh/XbRqA/waFjgeBS2ntBHOKJaLeXkTnid2dCdeWlz1qEK59yeRKM9\nP3Ow+/m8m/lxoxf6/riVayqji7ZzuvUaPfX6MMFbVUADx5sS0PVbxYizjcGznxC7\nQb1+DJcRwzrspw7A8P5h8ZMzEsT1wHfUHyFNOckmfXlUd1HzVHgpPGutzUjvDGXX\nxxZ1LBDvAgMBAAECggEBAJzGiiB39VheTJzy1OqJQhvYQPVp62Wn89XnvLdfJ/7k\nShFWpF/+j56QcbTq32hwabHn/wHmyuZvPLlIE8/ocGcIksZV0+ZWHK9NBjQoSo8a\nmi0t3QJ+tbnAgHAJWlBtfVkqVCrO0AkxsqPLWtFntCDlwhGBfpdJg3N5cihG21Fn\nnqUNxj2lVp1jxCAAcBHwCMfODFi0Kke/FLS3u9vHSRybUAbNid1adNJ6g3f3jKXh\nX5HPR2KYqDIyCQrqs9IAx7mM/T2W75NpZC1rW5GAWyw7sR71YDFI/Mronrdh0ZiH\nOpllwgM4bBD7ipNH3jNRgsAUr5nyTIJAii9z8XxGubkCgYEA+e88Kt3uZbFfcqTv\nb2ZTCUd3fyC0FcZ+/iHhKp2fmwsSIWB7k6++q8Vn/YHdew7KS+i4dvap30+k8Jf0\nu8p1NY82qHb5b/8igj6z015O+q1XE+hNoPUeIlX7JBVf0y3NIiiOTxvcWoIGKpth\nEVvlVk27PfYUEsnefFnKTQ7kNI0CgYEA2FLxXKrDQQRwtmC0My4LuAwhkGqxCwk1\nV8vD0k+J1JqVI3qQPxt5H241KtWwdb6QxAjuBe0i1Yx6vW1qC60NaZpM7RLFOEKy\nfwLuk19S9BKs1q0BRqcPpIP0PIZ+GgpKs7fIWcn19IFI/1KlSVYYV7qDgDmzMG13\nOPeJuAclAmsCgYBIyIdgAGMlUCL4ktl7OnQh9qLw7Ygj8zsWLK2SqHZLQ00TVTKH\njp1bDlC7PW9PH75/npThZ/GOK3Zf7hCCA3Jgl4UWSBdZqxXUkgfyHLupOoNqM7Mv\nlVIiM6HAH01ZhTQAp4jRts5TuRusmrUIxhciK97EK34q/oiA8/D6wcRpHQKBgBWb\nY0RQQiRyXxe4XQdnqAAAJjIYlgp2Jv/X+H0/OJMlxZO/oDzNb7G1/lWC9pcsK6WJ\nBs1MvFf8Kh5VmWwFIvvTT6+2WkCeWNna3x2VPeHnI6Bls2TtNuDF1VVeUaYkNQXy\na26cf5amezYVeTD0CoZouM3L9Zv2sxvbjcP14rp1AoGADoxlSjWxXOxZAr835wFl\nD3EMU5nhUGA0BdCfGgKqMaZmCr/ssfQDARgCKG/zLfmUBBBHbjZcHMXw6SW+E3CT\nN/q7iddT3FOgVder4GWTA+wFYdAywCT5At8wm7zeM2d/4cWlBaKew/u+A0ycUsD6\nbd3gRXjBZpD8Eep8ltVGLHw\u003d\n-----END PRIVATE KEY-----\n"
  },
  "resource": {
    "resourceUrl": "https://emea-conformance.ping-eng.com:3000/get"
  }
}
testName
fapi-ciba-id1-refresh-token
2021-02-10 09:54:19 SUCCESS
CreateCIBANotificationEndpointUri
Created ciba notification endpoint URI
notification_uri
https://www.certification.openid.net/test/a/robotto-internal-2/ciba-notification-endpoint
2021-02-10 09:54:19
GetDynamicServerConfiguration
HTTP request
request_uri
https://emea-conformance.ping-eng.com:9031/.well-known/openid-configuration
request_method
GET
request_headers
{
  "accept": "text/plain, application/json, application/cbor, application/*+json, */*",
  "content-length": "0"
}
request_body

                                
2021-02-10 09:54:19 RESPONSE
GetDynamicServerConfiguration
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "date": "Wed, 10 Feb 2021 09:54:19 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003dyMe348Pq21rURJY882EtCd;Path\u003d/;Secure;HttpOnly;SameSite\u003dNone",
  "content-length": "3631"
}
response_body
{
  "issuer": "https://emea-conformance.ping-eng.com:9031",
  "authorization_endpoint": "https://emea-conformance.ping-eng.com:9031/as/authorization.oauth2",
  "token_endpoint": "https://emea-conformance.ping-eng.com:9032/as/token.oauth2",
  "revocation_endpoint": "https://emea-conformance.ping-eng.com:9031/as/revoke_token.oauth2",
  "userinfo_endpoint": "https://emea-conformance.ping-eng.com:9031/idp/userinfo.openid",
  "introspection_endpoint": "https://emea-conformance.ping-eng.com:9031/as/introspect.oauth2",
  "jwks_uri": "https://emea-conformance.ping-eng.com:9031/pf/JWKS",
  "registration_endpoint": "https://emea-conformance.ping-eng.com:9031/as/clients.oauth2",
  "ping_revoked_sris_endpoint": "https://emea-conformance.ping-eng.com:9031/pf-ws/rest/sessionMgmt/revokedSris",
  "ping_session_management_sris_endpoint": "https://emea-conformance.ping-eng.com:9031/pf-ws/rest/sessionMgmt/sessions",
  "ping_end_session_endpoint": "https://emea-conformance.ping-eng.com:9031/idp/startSLO.ping",
  "device_authorization_endpoint": "https://emea-conformance.ping-eng.com:9031/as/device_authz.oauth2",
  "scopes_supported": [ "test", "openid" ],
  "claims_supported": [ "sub" ],
  "response_types_supported": [ "code", "token", "id_token", "code token", "code id_token", "token id_token", "code token id_token" ],
  "response_modes_supported": [ "fragment", "query", "form_post" ],
  "grant_types_supported": [ "implicit", "authorization_code", "refresh_token", "password", "client_credentials", "urn:pingidentity.com:oauth2:grant_type:validate_bearer", "urn:ietf:params:oauth:grant-type:jwt-bearer", "urn:ietf:params:oauth:grant-type:saml2-bearer", "urn:ietf:params:oauth:grant-type:device_code", "urn:ietf:params:oauth:grant-type:token-exchange", "urn:openid:params:grant-type:ciba" ],
  "subject_types_supported": [ "public", "pairwise" ],
  "id_token_signing_alg_values_supported": [ "none", "HS256", "HS384", "HS512", "RS256", "RS384", "RS512", "ES256", "ES384", "ES512", "PS256", "PS384", "PS512" ],
    "token_endpoint_auth_methods_supported": [ "client_secret_basic", "client_secret_post", "private_key_jwt" , "tls_client_auth"],
  "token_endpoint_auth_signing_alg_values_supported":  [ "RS256", "RS384", "RS512", "ES256", "ES384", "ES512", "PS256", "PS384", "PS512" ],
  "claim_types_supported": [ "normal" ],
  "claims_parameter_supported": false,
  "request_parameter_supported": true,
  "request_uri_parameter_supported": false,
  "request_object_signing_alg_values_supported": [ "RS256", "RS384", "RS512", "ES256", "ES384", "ES512", "PS256", "PS384", "PS512" ],
  "id_token_encryption_alg_values_supported": [ "dir", "A128KW", "A192KW", "A256KW", "A128GCMKW", "A192GCMKW", "A256GCMKW", "ECDH-ES", "ECDH-ES+A128KW", "ECDH-ES+A192KW", "ECDH-ES+A256KW", "RSA-OAEP" ],
  "id_token_encryption_enc_values_supported": [ "A128CBC-HS256", "A192CBC-HS384", "A256CBC-HS512", "A128GCM", "A192GCM", "A256GCM" ],
  "backchannel_authentication_endpoint": "https://emea-conformance.ping-eng.com:9031/as/bc-auth.ciba",
  "backchannel_token_delivery_modes_supported": [ "poll", "ping" ],
  "backchannel_authentication_request_signing_alg_values_supported": [ "RS256", "RS384", "RS512", "ES256", "ES384", "ES512", "PS256", "PS384", "PS512" ],
  "backchannel_user_code_parameter_supported": false,
  "code_challenge_methods_supported": [ "plain", "S256" ],
  "tls_client_certificate_bound_access_tokens": true,
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://emea-conformance.ping-eng.com:9032/as/token.oauth2",
  "backchannel_authentication_endpoint": "https://emea-conformance.ping-eng.com:9032/as/bc-auth.ciba"}
}
2021-02-10 09:54:19
GetDynamicServerConfiguration
Downloaded server configuration
server_config_string
{
  "issuer": "https://emea-conformance.ping-eng.com:9031",
  "authorization_endpoint": "https://emea-conformance.ping-eng.com:9031/as/authorization.oauth2",
  "token_endpoint": "https://emea-conformance.ping-eng.com:9032/as/token.oauth2",
  "revocation_endpoint": "https://emea-conformance.ping-eng.com:9031/as/revoke_token.oauth2",
  "userinfo_endpoint": "https://emea-conformance.ping-eng.com:9031/idp/userinfo.openid",
  "introspection_endpoint": "https://emea-conformance.ping-eng.com:9031/as/introspect.oauth2",
  "jwks_uri": "https://emea-conformance.ping-eng.com:9031/pf/JWKS",
  "registration_endpoint": "https://emea-conformance.ping-eng.com:9031/as/clients.oauth2",
  "ping_revoked_sris_endpoint": "https://emea-conformance.ping-eng.com:9031/pf-ws/rest/sessionMgmt/revokedSris",
  "ping_session_management_sris_endpoint": "https://emea-conformance.ping-eng.com:9031/pf-ws/rest/sessionMgmt/sessions",
  "ping_end_session_endpoint": "https://emea-conformance.ping-eng.com:9031/idp/startSLO.ping",
  "device_authorization_endpoint": "https://emea-conformance.ping-eng.com:9031/as/device_authz.oauth2",
  "scopes_supported": [ "test", "openid" ],
  "claims_supported": [ "sub" ],
  "response_types_supported": [ "code", "token", "id_token", "code token", "code id_token", "token id_token", "code token id_token" ],
  "response_modes_supported": [ "fragment", "query", "form_post" ],
  "grant_types_supported": [ "implicit", "authorization_code", "refresh_token", "password", "client_credentials", "urn:pingidentity.com:oauth2:grant_type:validate_bearer", "urn:ietf:params:oauth:grant-type:jwt-bearer", "urn:ietf:params:oauth:grant-type:saml2-bearer", "urn:ietf:params:oauth:grant-type:device_code", "urn:ietf:params:oauth:grant-type:token-exchange", "urn:openid:params:grant-type:ciba" ],
  "subject_types_supported": [ "public", "pairwise" ],
  "id_token_signing_alg_values_supported": [ "none", "HS256", "HS384", "HS512", "RS256", "RS384", "RS512", "ES256", "ES384", "ES512", "PS256", "PS384", "PS512" ],
    "token_endpoint_auth_methods_supported": [ "client_secret_basic", "client_secret_post", "private_key_jwt" , "tls_client_auth"],
  "token_endpoint_auth_signing_alg_values_supported":  [ "RS256", "RS384", "RS512", "ES256", "ES384", "ES512", "PS256", "PS384", "PS512" ],
  "claim_types_supported": [ "normal" ],
  "claims_parameter_supported": false,
  "request_parameter_supported": true,
  "request_uri_parameter_supported": false,
  "request_object_signing_alg_values_supported": [ "RS256", "RS384", "RS512", "ES256", "ES384", "ES512", "PS256", "PS384", "PS512" ],
  "id_token_encryption_alg_values_supported": [ "dir", "A128KW", "A192KW", "A256KW", "A128GCMKW", "A192GCMKW", "A256GCMKW", "ECDH-ES", "ECDH-ES+A128KW", "ECDH-ES+A192KW", "ECDH-ES+A256KW", "RSA-OAEP" ],
  "id_token_encryption_enc_values_supported": [ "A128CBC-HS256", "A192CBC-HS384", "A256CBC-HS512", "A128GCM", "A192GCM", "A256GCM" ],
  "backchannel_authentication_endpoint": "https://emea-conformance.ping-eng.com:9031/as/bc-auth.ciba",
  "backchannel_token_delivery_modes_supported": [ "poll", "ping" ],
  "backchannel_authentication_request_signing_alg_values_supported": [ "RS256", "RS384", "RS512", "ES256", "ES384", "ES512", "PS256", "PS384", "PS512" ],
  "backchannel_user_code_parameter_supported": false,
  "code_challenge_methods_supported": [ "plain", "S256" ],
  "tls_client_certificate_bound_access_tokens": true,
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://emea-conformance.ping-eng.com:9032/as/token.oauth2",
  "backchannel_authentication_endpoint": "https://emea-conformance.ping-eng.com:9032/as/bc-auth.ciba"}
}
2021-02-10 09:54:19 SUCCESS
GetDynamicServerConfiguration
Successfully parsed server configuration
issuer
https://emea-conformance.ping-eng.com:9031
authorization_endpoint
https://emea-conformance.ping-eng.com:9031/as/authorization.oauth2
token_endpoint
https://emea-conformance.ping-eng.com:9032/as/token.oauth2
revocation_endpoint
https://emea-conformance.ping-eng.com:9031/as/revoke_token.oauth2
userinfo_endpoint
https://emea-conformance.ping-eng.com:9031/idp/userinfo.openid
introspection_endpoint
https://emea-conformance.ping-eng.com:9031/as/introspect.oauth2
jwks_uri
https://emea-conformance.ping-eng.com:9031/pf/JWKS
registration_endpoint
https://emea-conformance.ping-eng.com:9031/as/clients.oauth2
ping_revoked_sris_endpoint
https://emea-conformance.ping-eng.com:9031/pf-ws/rest/sessionMgmt/revokedSris
ping_session_management_sris_endpoint
https://emea-conformance.ping-eng.com:9031/pf-ws/rest/sessionMgmt/sessions
ping_end_session_endpoint
https://emea-conformance.ping-eng.com:9031/idp/startSLO.ping
device_authorization_endpoint
https://emea-conformance.ping-eng.com:9031/as/device_authz.oauth2
scopes_supported
[
  "test",
  "openid"
]
claims_supported
[
  "sub"
]
response_types_supported
[
  "code",
  "token",
  "id_token",
  "code token",
  "code id_token",
  "token id_token",
  "code token id_token"
]
response_modes_supported
[
  "fragment",
  "query",
  "form_post"
]
grant_types_supported
[
  "implicit",
  "authorization_code",
  "refresh_token",
  "password",
  "client_credentials",
  "urn:pingidentity.com:oauth2:grant_type:validate_bearer",
  "urn:ietf:params:oauth:grant-type:jwt-bearer",
  "urn:ietf:params:oauth:grant-type:saml2-bearer",
  "urn:ietf:params:oauth:grant-type:device_code",
  "urn:ietf:params:oauth:grant-type:token-exchange",
  "urn:openid:params:grant-type:ciba"
]
subject_types_supported
[
  "public",
  "pairwise"
]
id_token_signing_alg_values_supported
[
  "none",
  "HS256",
  "HS384",
  "HS512",
  "RS256",
  "RS384",
  "RS512",
  "ES256",
  "ES384",
  "ES512",
  "PS256",
  "PS384",
  "PS512"
]
token_endpoint_auth_methods_supported
[
  "client_secret_basic",
  "client_secret_post",
  "private_key_jwt",
  "tls_client_auth"
]
token_endpoint_auth_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "ES256",
  "ES384",
  "ES512",
  "PS256",
  "PS384",
  "PS512"
]
claim_types_supported
[
  "normal"
]
claims_parameter_supported
false
request_parameter_supported
true
request_uri_parameter_supported
false
request_object_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "ES256",
  "ES384",
  "ES512",
  "PS256",
  "PS384",
  "PS512"
]
id_token_encryption_alg_values_supported
[
  "dir",
  "A128KW",
  "A192KW",
  "A256KW",
  "A128GCMKW",
  "A192GCMKW",
  "A256GCMKW",
  "ECDH-ES",
  "ECDH-ES+A128KW",
  "ECDH-ES+A192KW",
  "ECDH-ES+A256KW",
  "RSA-OAEP"
]
id_token_encryption_enc_values_supported
[
  "A128CBC-HS256",
  "A192CBC-HS384",
  "A256CBC-HS512",
  "A128GCM",
  "A192GCM",
  "A256GCM"
]
backchannel_authentication_endpoint
https://emea-conformance.ping-eng.com:9031/as/bc-auth.ciba
backchannel_token_delivery_modes_supported
[
  "poll",
  "ping"
]
backchannel_authentication_request_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "ES256",
  "ES384",
  "ES512",
  "PS256",
  "PS384",
  "PS512"
]
backchannel_user_code_parameter_supported
false
code_challenge_methods_supported
[
  "plain",
  "S256"
]
tls_client_certificate_bound_access_tokens
true
mtls_endpoint_aliases
{
  "token_endpoint": "https://emea-conformance.ping-eng.com:9032/as/token.oauth2",
  "backchannel_authentication_endpoint": "https://emea-conformance.ping-eng.com:9032/as/bc-auth.ciba"
}
2021-02-10 09:54:19 SUCCESS
CheckCIBAServerConfiguration
Found required server configuration keys
required
[
  "backchannel_authentication_endpoint",
  "token_endpoint",
  "issuer"
]
2021-02-10 09:54:19 SUCCESS
ExtractTLSTestValuesFromServerConfiguration
Extracted TLS information from authorization server configuration
registration_endpoint
{
  "testHost": "emea-conformance.ping-eng.com",
  "testPort": 9031
}
authorization_endpoint
{
  "testHost": "emea-conformance.ping-eng.com",
  "testPort": 9031
}
token_endpoint
{
  "testHost": "emea-conformance.ping-eng.com",
  "testPort": 9032
}
userinfo_endpoint
{
  "testHost": "emea-conformance.ping-eng.com",
  "testPort": 9031
}
2021-02-10 09:54:19
FetchServerKeys
Fetching server key
jwks_uri
https://emea-conformance.ping-eng.com:9031/pf/JWKS
2021-02-10 09:54:19
FetchServerKeys
HTTP request
request_uri
https://emea-conformance.ping-eng.com:9031/pf/JWKS
request_method
GET
request_headers
{
  "accept": "text/plain, application/json, application/cbor, application/*+json, */*",
  "content-length": "0"
}
request_body

                                
2021-02-10 09:54:19 RESPONSE
FetchServerKeys
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "date": "Wed, 10 Feb 2021 09:54:19 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003dDxcI7A3s9cN8McTTFoG38L;Path\u003d/;Secure;HttpOnly;SameSite\u003dNone",
  "transfer-encoding": "chunked"
}
response_body
{"keys":[{"kty":"EC","kid":"9rmD68IwLRrp5HjNxDMgHr1Sbpk","use":"sig","x":"SU3qQmiKxnWIpAU6ZBNQgMjwgHFZmUC1gJ8NJDD0Niog1QOM7KJhGYUlOgap2qsH","y":"aO7xtjSwEl76Ihqi9t-HYs6j6TAApuTctpplw_sYmT8SHvFbQ-36_u-4Tqtl0eJN","crv":"P-384"},{"kty":"RSA","kid":"Zq4_Rs1JhDolLdW0eNa0IpCbaOM","use":"sig","n":"pzKGpHni6bAFoZgCskoYiJL4f6e3-KoRJTOflJ6GYuwiiNJVWigW4Co2tz5Zyp3RVO8GGb1fKs-afJpPdg8R4k0yM8LMftsDPMKjA1ebgddcUE9BRQcEpwQ3Y-1hanS6ZmXuVxkNMoT1uoB_w_chB4I6kXSFucgle-W8Mt206z00mV4ZKjDkrDGGxyKrxLI9zWBc6d0BSyDa4uqhAzMQLHLru3Z21Ot1Zz4Avgy0-fN_ni5YMp3cHwBNBQQxmz-4fKwk4FeAtNUWbrjrGXTp1bE2ItUCWKqV34oPupSHzBWuNTbD3sPljc3iFt3-OSLq0x4sajZ7YFiZjDoQ50kP-Q","e":"AQAB"},{"kty":"EC","kid":"rg0eyU38xRI-2e5UsRiOEnlD2Qs","use":"sig","x":"Aag8ntLcs6qiiQAzJYF5GYdWOlHViqwHeE8sb9_378dy9XB_OZAmOOZsW8dpHf420IIhIZ2zZUP9QEki8kl0o0Zi","y":"AOZ7DsahqsrdGL1vThaJnbmyXezTWUzrLhx3dDbb8U2FFq37PTOHgYymZFQOTTMsi1TAbcHPZM8_mVWkQe8SENqQ","crv":"P-521"},{"kty":"EC","kid":"sKFuroXvCIad-bc7gCJJDe_kw3E","use":"sig","x":"WtryB9PDGZSToMbf0JOQG90PwRj2KMnU7n9T6IRwJzI","y":"L5KHi5bzBcD-q7L0p2pSjg0BY0ZY5uWdOwQubhoVJsc","crv":"P-256"},{"kty":"EC","kid":"6yY2TlBV8jQQofSfyb5XOB4Jb6M","use":"sig","x":"AORGZoxt8oDD_RV2W1-4Ne1RDGjQhZj1BvBXpmY1QpKdrabD7-Wfofo7HU2NbH-q2pHqjQEa2xnmOnKINuQkdtYL","y":"ACC6hcSGMpuj0ZapUKgnvfye4bRKQOBhVgdMA_YWV_8TgU36igiRHeH2N8PGiOsRH3Htk16TfoHyt7hkaCeANik9","crv":"P-521"},{"kty":"EC","kid":"HGp1IEQM1voQSq46IAvk_1YRqaE","use":"sig","x":"lDl885FnLKaM-5F97Kjqo-Lo6R4buuYnhTyiQ-AA8pw","y":"l699BrNxVkOsb7nrap4hgnc5FMzGqEGBCcKIpnoCzW4","crv":"P-256"},{"kty":"RSA","kid":"OoaNeMIHyh-Y_nCgZt8P7S4WRHQ","use":"sig","n":"pwT1pxBXBTVtIXWjM-1eK5o8mYwrVjg0-tH3rVayjWjqDcFdudpZrmfW5DJX_tk8Nmxw05aK9WVV35gX3Z9hNopSDzv25aup_BSjwtMhzjDDZKqH0vZQOxwFg8mj_bKqNh5fLvSyPtonXgVzfSpuXbpsGWY_iKURqQlDB4GoI_fH0e0LCkQv5KdaUa_u46VAopeExNJxZ1sAszIpauhAVaRta7ClANvVoQiWr1yvrMLkwRe-RLK4RkTexFQWDG6-hT6casxmug8NuLP9u7iLDCIUhAppHTcQierZDjTiFdRXcPmMEbVxHTWqDOF06RnNQvKJ-KDfgVxsQ2lh3SlKXQ","e":"AQAB"},{"kty":"EC","kid":"jMHpWAXB63I1bbOLTb8BruHgSAM","use":"sig","x":"CO7-lbGTCdMBCE47l6HYdiy_ZAuXwrsdkhfUk3VoExI3w3G4m-TOZlVPVcSdRicm","y":"Qy3Tuaw1vPHuGO4WP8-g4rIiD4qOtwCqIy1aMEPH0MLfP2cbgT_8lXORDe9Pklbu","crv":"P-384"},{"kty":"EC","kid":"idZdEltozJCPsw9C_4X1oJunzbI","use":"sig","x":"QQmn2hcLohFA4m9yitWE3-RrdbZpyf5mJxhTm3vHSqw","y":"xUu6I85Juq1_kUhAjHz4IEzJ2KK7rpE4x1tJneDdCVA","crv":"P-256"},{"kty":"RSA","kid":"ii3sMTEFa9asTWi9I2oBzP7cxG4","use":"sig","n":"lK95ORbuwmjuFETa4Z_73zlAjGfq7vBVRosZfvEVarce85t7Y9wuVVYSRckg2VijZHwj44ibdTc15l6veStrVLLm7CPySSERpXcLEAdyfftwsn41h9RlHXn8zIgDkR7caHNgvDFLTml6TY89G3iJeZNwe_5-n5WMyfT4zfSNLAaXzPOeFCUbdLuJmm9OzcKTQsm7inYAPEaPb0LnuZB5MKa97s19ZSHP9n_2LImnbl1M3nUFmTyj6cidTB_zfCgBsDf5JEDMP7QYAbkyjbU_yUY3X36z-dBqMYXHdkpRGuSN6tJ-yzvCDR7DRffpb9ld49GQ3gjMilYDFpvAazhlWw","e":"AQAB"},{"kty":"EC","kid":"oMfG-1rmk0z5YYO6yQKVXQs14RU","use":"sig","x":"AF5sVn2wVq0DCho_zfl1Tb9G_684ENBGRuyY5g6cwYvPeQslw0jplPzpfb56OqvNZYrIhtZ9drC8P5SrJ1gsP0FA","y":"AbSw-emm5IeIE-zlRCIa9VaiXXLH6EKqStmjzKPcZZoDVnRVzd9ucWfkGlypaUEChY31DvSWkBBZMVXONa7YQ22a","crv":"P-521"},{"kty":"EC","kid":"yxn8wvV8bguIMfKup61EritQX4s","use":"sig","x":"xg37IIpYhU99yDi4eDujpPx-LdcDXONudlGAzz3Q0j-Z3xTN-1OjoI5wmSqCtWDq","y":"stP9A4-EwbILPpTqvmBaQUYLQU_vRim_oQfxPIp2nf7-Jb9BI_8ALkNALCWGRZRA","crv":"P-384"},{"kty":"EC","kid":"0foAtEfYk8IyeEfbyMxjGHSh7bY","use":"enc","x":"AdY_XnstGI8NAAAMlHmHhVabe1a4IvEAYPGuldazlc1YdObsur0IRaQUMp70n4VseHBxwtimO72wh931oTevMJCB","y":"Aeqyn_9N1E9fKPjcizV3TIrM-psmlfC-df7qhazNX_11uVOjwfIvyxCtRFQAcRJRPnE7CC03sJXck0b5IxW8vtmQ","crv":"P-521"},{"kty":"EC","kid":"cLoJ6YOvJ1Idi8yBLGWv3tVXhqs","use":"enc","x":"RvIPoDC1SJcxNTTbHg9_V-tW95zXiCUxM4WteFmUI4I","y":"Dl5dXtzPssghEAX51zm1VPEiIx-kpkjD87e2CK28TiI","crv":"P-256"},{"kty":"EC","kid":"gKzSjT2gz089ZXcMg4qndGvxH4w","use":"enc","x":"jkq2HdbtP0XMNF5B70hzH3BOKJ3MFulT_HzDy4KpCt6dVvVnptq3dzRClzYjvin9","y":"9GcT-pdGYUwhXrJyde9fGTqxZZBm66pBI5rgnDeFWLdaDSGsbu3GXkgT8_d7kr-9","crv":"P-384"},{"kty":"RSA","kid":"hzPtaW3r_qi0tAz0PbxUmSR7Y7M","use":"enc","n":"zDaj3WiVvT19AwP7hdVkkSVzd5-AvazScBEj3wcKZXagTor5DKAeketT8MLtrGijskK8Ag7LMUGhm0meTdxKO_kDpqhBkY8GVn9p9WPQU9LjtVW1AJR_8Vw86YKOiWXuzXBiNMt-2_v4wMtbADKfvdzVj6KB3uM1Ze-gmNdXCS18MnGe1pnkin6jDM9eshafrImu9RhYXkD6X-S6syWZphRk4YkZ6jaTf3TLoEIb-KxhSBUvgCbEaVRYxo4h0wPze_L6W-A_0SKoG97wlZGjdTGvAUVVJ7puRkYtEnPSEVKux8iHfZf9WqsyQPxIQm-w2dEcSlAPVKf-a9jBhk47jw","e":"AQAB"}]}
2021-02-10 09:54:19
FetchServerKeys
Found JWK set string
jwk_string
{"keys":[{"kty":"EC","kid":"9rmD68IwLRrp5HjNxDMgHr1Sbpk","use":"sig","x":"SU3qQmiKxnWIpAU6ZBNQgMjwgHFZmUC1gJ8NJDD0Niog1QOM7KJhGYUlOgap2qsH","y":"aO7xtjSwEl76Ihqi9t-HYs6j6TAApuTctpplw_sYmT8SHvFbQ-36_u-4Tqtl0eJN","crv":"P-384"},{"kty":"RSA","kid":"Zq4_Rs1JhDolLdW0eNa0IpCbaOM","use":"sig","n":"pzKGpHni6bAFoZgCskoYiJL4f6e3-KoRJTOflJ6GYuwiiNJVWigW4Co2tz5Zyp3RVO8GGb1fKs-afJpPdg8R4k0yM8LMftsDPMKjA1ebgddcUE9BRQcEpwQ3Y-1hanS6ZmXuVxkNMoT1uoB_w_chB4I6kXSFucgle-W8Mt206z00mV4ZKjDkrDGGxyKrxLI9zWBc6d0BSyDa4uqhAzMQLHLru3Z21Ot1Zz4Avgy0-fN_ni5YMp3cHwBNBQQxmz-4fKwk4FeAtNUWbrjrGXTp1bE2ItUCWKqV34oPupSHzBWuNTbD3sPljc3iFt3-OSLq0x4sajZ7YFiZjDoQ50kP-Q","e":"AQAB"},{"kty":"EC","kid":"rg0eyU38xRI-2e5UsRiOEnlD2Qs","use":"sig","x":"Aag8ntLcs6qiiQAzJYF5GYdWOlHViqwHeE8sb9_378dy9XB_OZAmOOZsW8dpHf420IIhIZ2zZUP9QEki8kl0o0Zi","y":"AOZ7DsahqsrdGL1vThaJnbmyXezTWUzrLhx3dDbb8U2FFq37PTOHgYymZFQOTTMsi1TAbcHPZM8_mVWkQe8SENqQ","crv":"P-521"},{"kty":"EC","kid":"sKFuroXvCIad-bc7gCJJDe_kw3E","use":"sig","x":"WtryB9PDGZSToMbf0JOQG90PwRj2KMnU7n9T6IRwJzI","y":"L5KHi5bzBcD-q7L0p2pSjg0BY0ZY5uWdOwQubhoVJsc","crv":"P-256"},{"kty":"EC","kid":"6yY2TlBV8jQQofSfyb5XOB4Jb6M","use":"sig","x":"AORGZoxt8oDD_RV2W1-4Ne1RDGjQhZj1BvBXpmY1QpKdrabD7-Wfofo7HU2NbH-q2pHqjQEa2xnmOnKINuQkdtYL","y":"ACC6hcSGMpuj0ZapUKgnvfye4bRKQOBhVgdMA_YWV_8TgU36igiRHeH2N8PGiOsRH3Htk16TfoHyt7hkaCeANik9","crv":"P-521"},{"kty":"EC","kid":"HGp1IEQM1voQSq46IAvk_1YRqaE","use":"sig","x":"lDl885FnLKaM-5F97Kjqo-Lo6R4buuYnhTyiQ-AA8pw","y":"l699BrNxVkOsb7nrap4hgnc5FMzGqEGBCcKIpnoCzW4","crv":"P-256"},{"kty":"RSA","kid":"OoaNeMIHyh-Y_nCgZt8P7S4WRHQ","use":"sig","n":"pwT1pxBXBTVtIXWjM-1eK5o8mYwrVjg0-tH3rVayjWjqDcFdudpZrmfW5DJX_tk8Nmxw05aK9WVV35gX3Z9hNopSDzv25aup_BSjwtMhzjDDZKqH0vZQOxwFg8mj_bKqNh5fLvSyPtonXgVzfSpuXbpsGWY_iKURqQlDB4GoI_fH0e0LCkQv5KdaUa_u46VAopeExNJxZ1sAszIpauhAVaRta7ClANvVoQiWr1yvrMLkwRe-RLK4RkTexFQWDG6-hT6casxmug8NuLP9u7iLDCIUhAppHTcQierZDjTiFdRXcPmMEbVxHTWqDOF06RnNQvKJ-KDfgVxsQ2lh3SlKXQ","e":"AQAB"},{"kty":"EC","kid":"jMHpWAXB63I1bbOLTb8BruHgSAM","use":"sig","x":"CO7-lbGTCdMBCE47l6HYdiy_ZAuXwrsdkhfUk3VoExI3w3G4m-TOZlVPVcSdRicm","y":"Qy3Tuaw1vPHuGO4WP8-g4rIiD4qOtwCqIy1aMEPH0MLfP2cbgT_8lXORDe9Pklbu","crv":"P-384"},{"kty":"EC","kid":"idZdEltozJCPsw9C_4X1oJunzbI","use":"sig","x":"QQmn2hcLohFA4m9yitWE3-RrdbZpyf5mJxhTm3vHSqw","y":"xUu6I85Juq1_kUhAjHz4IEzJ2KK7rpE4x1tJneDdCVA","crv":"P-256"},{"kty":"RSA","kid":"ii3sMTEFa9asTWi9I2oBzP7cxG4","use":"sig","n":"lK95ORbuwmjuFETa4Z_73zlAjGfq7vBVRosZfvEVarce85t7Y9wuVVYSRckg2VijZHwj44ibdTc15l6veStrVLLm7CPySSERpXcLEAdyfftwsn41h9RlHXn8zIgDkR7caHNgvDFLTml6TY89G3iJeZNwe_5-n5WMyfT4zfSNLAaXzPOeFCUbdLuJmm9OzcKTQsm7inYAPEaPb0LnuZB5MKa97s19ZSHP9n_2LImnbl1M3nUFmTyj6cidTB_zfCgBsDf5JEDMP7QYAbkyjbU_yUY3X36z-dBqMYXHdkpRGuSN6tJ-yzvCDR7DRffpb9ld49GQ3gjMilYDFpvAazhlWw","e":"AQAB"},{"kty":"EC","kid":"oMfG-1rmk0z5YYO6yQKVXQs14RU","use":"sig","x":"AF5sVn2wVq0DCho_zfl1Tb9G_684ENBGRuyY5g6cwYvPeQslw0jplPzpfb56OqvNZYrIhtZ9drC8P5SrJ1gsP0FA","y":"AbSw-emm5IeIE-zlRCIa9VaiXXLH6EKqStmjzKPcZZoDVnRVzd9ucWfkGlypaUEChY31DvSWkBBZMVXONa7YQ22a","crv":"P-521"},{"kty":"EC","kid":"yxn8wvV8bguIMfKup61EritQX4s","use":"sig","x":"xg37IIpYhU99yDi4eDujpPx-LdcDXONudlGAzz3Q0j-Z3xTN-1OjoI5wmSqCtWDq","y":"stP9A4-EwbILPpTqvmBaQUYLQU_vRim_oQfxPIp2nf7-Jb9BI_8ALkNALCWGRZRA","crv":"P-384"},{"kty":"EC","kid":"0foAtEfYk8IyeEfbyMxjGHSh7bY","use":"enc","x":"AdY_XnstGI8NAAAMlHmHhVabe1a4IvEAYPGuldazlc1YdObsur0IRaQUMp70n4VseHBxwtimO72wh931oTevMJCB","y":"Aeqyn_9N1E9fKPjcizV3TIrM-psmlfC-df7qhazNX_11uVOjwfIvyxCtRFQAcRJRPnE7CC03sJXck0b5IxW8vtmQ","crv":"P-521"},{"kty":"EC","kid":"cLoJ6YOvJ1Idi8yBLGWv3tVXhqs","use":"enc","x":"RvIPoDC1SJcxNTTbHg9_V-tW95zXiCUxM4WteFmUI4I","y":"Dl5dXtzPssghEAX51zm1VPEiIx-kpkjD87e2CK28TiI","crv":"P-256"},{"kty":"EC","kid":"gKzSjT2gz089ZXcMg4qndGvxH4w","use":"enc","x":"jkq2HdbtP0XMNF5B70hzH3BOKJ3MFulT_HzDy4KpCt6dVvVnptq3dzRClzYjvin9","y":"9GcT-pdGYUwhXrJyde9fGTqxZZBm66pBI5rgnDeFWLdaDSGsbu3GXkgT8_d7kr-9","crv":"P-384"},{"kty":"RSA","kid":"hzPtaW3r_qi0tAz0PbxUmSR7Y7M","use":"enc","n":"zDaj3WiVvT19AwP7hdVkkSVzd5-AvazScBEj3wcKZXagTor5DKAeketT8MLtrGijskK8Ag7LMUGhm0meTdxKO_kDpqhBkY8GVn9p9WPQU9LjtVW1AJR_8Vw86YKOiWXuzXBiNMt-2_v4wMtbADKfvdzVj6KB3uM1Ze-gmNdXCS18MnGe1pnkin6jDM9eshafrImu9RhYXkD6X-S6syWZphRk4YkZ6jaTf3TLoEIb-KxhSBUvgCbEaVRYxo4h0wPze_L6W-A_0SKoG97wlZGjdTGvAUVVJ7puRkYtEnPSEVKux8iHfZf9WqsyQPxIQm-w2dEcSlAPVKf-a9jBhk47jw","e":"AQAB"}]}
2021-02-10 09:54:19 SUCCESS
FetchServerKeys
Found server JWK set
server_jwks
{
  "keys": [
    {
      "kty": "EC",
      "kid": "9rmD68IwLRrp5HjNxDMgHr1Sbpk",
      "use": "sig",
      "x": "SU3qQmiKxnWIpAU6ZBNQgMjwgHFZmUC1gJ8NJDD0Niog1QOM7KJhGYUlOgap2qsH",
      "y": "aO7xtjSwEl76Ihqi9t-HYs6j6TAApuTctpplw_sYmT8SHvFbQ-36_u-4Tqtl0eJN",
      "crv": "P-384"
    },
    {
      "kty": "RSA",
      "kid": "Zq4_Rs1JhDolLdW0eNa0IpCbaOM",
      "use": "sig",
      "n": "pzKGpHni6bAFoZgCskoYiJL4f6e3-KoRJTOflJ6GYuwiiNJVWigW4Co2tz5Zyp3RVO8GGb1fKs-afJpPdg8R4k0yM8LMftsDPMKjA1ebgddcUE9BRQcEpwQ3Y-1hanS6ZmXuVxkNMoT1uoB_w_chB4I6kXSFucgle-W8Mt206z00mV4ZKjDkrDGGxyKrxLI9zWBc6d0BSyDa4uqhAzMQLHLru3Z21Ot1Zz4Avgy0-fN_ni5YMp3cHwBNBQQxmz-4fKwk4FeAtNUWbrjrGXTp1bE2ItUCWKqV34oPupSHzBWuNTbD3sPljc3iFt3-OSLq0x4sajZ7YFiZjDoQ50kP-Q",
      "e": "AQAB"
    },
    {
      "kty": "EC",
      "kid": "rg0eyU38xRI-2e5UsRiOEnlD2Qs",
      "use": "sig",
      "x": "Aag8ntLcs6qiiQAzJYF5GYdWOlHViqwHeE8sb9_378dy9XB_OZAmOOZsW8dpHf420IIhIZ2zZUP9QEki8kl0o0Zi",
      "y": "AOZ7DsahqsrdGL1vThaJnbmyXezTWUzrLhx3dDbb8U2FFq37PTOHgYymZFQOTTMsi1TAbcHPZM8_mVWkQe8SENqQ",
      "crv": "P-521"
    },
    {
      "kty": "EC",
      "kid": "sKFuroXvCIad-bc7gCJJDe_kw3E",
      "use": "sig",
      "x": "WtryB9PDGZSToMbf0JOQG90PwRj2KMnU7n9T6IRwJzI",
      "y": "L5KHi5bzBcD-q7L0p2pSjg0BY0ZY5uWdOwQubhoVJsc",
      "crv": "P-256"
    },
    {
      "kty": "EC",
      "kid": "6yY2TlBV8jQQofSfyb5XOB4Jb6M",
      "use": "sig",
      "x": "AORGZoxt8oDD_RV2W1-4Ne1RDGjQhZj1BvBXpmY1QpKdrabD7-Wfofo7HU2NbH-q2pHqjQEa2xnmOnKINuQkdtYL",
      "y": "ACC6hcSGMpuj0ZapUKgnvfye4bRKQOBhVgdMA_YWV_8TgU36igiRHeH2N8PGiOsRH3Htk16TfoHyt7hkaCeANik9",
      "crv": "P-521"
    },
    {
      "kty": "EC",
      "kid": "HGp1IEQM1voQSq46IAvk_1YRqaE",
      "use": "sig",
      "x": "lDl885FnLKaM-5F97Kjqo-Lo6R4buuYnhTyiQ-AA8pw",
      "y": "l699BrNxVkOsb7nrap4hgnc5FMzGqEGBCcKIpnoCzW4",
      "crv": "P-256"
    },
    {
      "kty": "RSA",
      "kid": "OoaNeMIHyh-Y_nCgZt8P7S4WRHQ",
      "use": "sig",
      "n": "pwT1pxBXBTVtIXWjM-1eK5o8mYwrVjg0-tH3rVayjWjqDcFdudpZrmfW5DJX_tk8Nmxw05aK9WVV35gX3Z9hNopSDzv25aup_BSjwtMhzjDDZKqH0vZQOxwFg8mj_bKqNh5fLvSyPtonXgVzfSpuXbpsGWY_iKURqQlDB4GoI_fH0e0LCkQv5KdaUa_u46VAopeExNJxZ1sAszIpauhAVaRta7ClANvVoQiWr1yvrMLkwRe-RLK4RkTexFQWDG6-hT6casxmug8NuLP9u7iLDCIUhAppHTcQierZDjTiFdRXcPmMEbVxHTWqDOF06RnNQvKJ-KDfgVxsQ2lh3SlKXQ",
      "e": "AQAB"
    },
    {
      "kty": "EC",
      "kid": "jMHpWAXB63I1bbOLTb8BruHgSAM",
      "use": "sig",
      "x": "CO7-lbGTCdMBCE47l6HYdiy_ZAuXwrsdkhfUk3VoExI3w3G4m-TOZlVPVcSdRicm",
      "y": "Qy3Tuaw1vPHuGO4WP8-g4rIiD4qOtwCqIy1aMEPH0MLfP2cbgT_8lXORDe9Pklbu",
      "crv": "P-384"
    },
    {
      "kty": "EC",
      "kid": "idZdEltozJCPsw9C_4X1oJunzbI",
      "use": "sig",
      "x": "QQmn2hcLohFA4m9yitWE3-RrdbZpyf5mJxhTm3vHSqw",
      "y": "xUu6I85Juq1_kUhAjHz4IEzJ2KK7rpE4x1tJneDdCVA",
      "crv": "P-256"
    },
    {
      "kty": "RSA",
      "kid": "ii3sMTEFa9asTWi9I2oBzP7cxG4",
      "use": "sig",
      "n": "lK95ORbuwmjuFETa4Z_73zlAjGfq7vBVRosZfvEVarce85t7Y9wuVVYSRckg2VijZHwj44ibdTc15l6veStrVLLm7CPySSERpXcLEAdyfftwsn41h9RlHXn8zIgDkR7caHNgvDFLTml6TY89G3iJeZNwe_5-n5WMyfT4zfSNLAaXzPOeFCUbdLuJmm9OzcKTQsm7inYAPEaPb0LnuZB5MKa97s19ZSHP9n_2LImnbl1M3nUFmTyj6cidTB_zfCgBsDf5JEDMP7QYAbkyjbU_yUY3X36z-dBqMYXHdkpRGuSN6tJ-yzvCDR7DRffpb9ld49GQ3gjMilYDFpvAazhlWw",
      "e": "AQAB"
    },
    {
      "kty": "EC",
      "kid": "oMfG-1rmk0z5YYO6yQKVXQs14RU",
      "use": "sig",
      "x": "AF5sVn2wVq0DCho_zfl1Tb9G_684ENBGRuyY5g6cwYvPeQslw0jplPzpfb56OqvNZYrIhtZ9drC8P5SrJ1gsP0FA",
      "y": "AbSw-emm5IeIE-zlRCIa9VaiXXLH6EKqStmjzKPcZZoDVnRVzd9ucWfkGlypaUEChY31DvSWkBBZMVXONa7YQ22a",
      "crv": "P-521"
    },
    {
      "kty": "EC",
      "kid": "yxn8wvV8bguIMfKup61EritQX4s",
      "use": "sig",
      "x": "xg37IIpYhU99yDi4eDujpPx-LdcDXONudlGAzz3Q0j-Z3xTN-1OjoI5wmSqCtWDq",
      "y": "stP9A4-EwbILPpTqvmBaQUYLQU_vRim_oQfxPIp2nf7-Jb9BI_8ALkNALCWGRZRA",
      "crv": "P-384"
    },
    {
      "kty": "EC",
      "kid": "0foAtEfYk8IyeEfbyMxjGHSh7bY",
      "use": "enc",
      "x": "AdY_XnstGI8NAAAMlHmHhVabe1a4IvEAYPGuldazlc1YdObsur0IRaQUMp70n4VseHBxwtimO72wh931oTevMJCB",
      "y": "Aeqyn_9N1E9fKPjcizV3TIrM-psmlfC-df7qhazNX_11uVOjwfIvyxCtRFQAcRJRPnE7CC03sJXck0b5IxW8vtmQ",
      "crv": "P-521"
    },
    {
      "kty": "EC",
      "kid": "cLoJ6YOvJ1Idi8yBLGWv3tVXhqs",
      "use": "enc",
      "x": "RvIPoDC1SJcxNTTbHg9_V-tW95zXiCUxM4WteFmUI4I",
      "y": "Dl5dXtzPssghEAX51zm1VPEiIx-kpkjD87e2CK28TiI",
      "crv": "P-256"
    },
    {
      "kty": "EC",
      "kid": "gKzSjT2gz089ZXcMg4qndGvxH4w",
      "use": "enc",
      "x": "jkq2HdbtP0XMNF5B70hzH3BOKJ3MFulT_HzDy4KpCt6dVvVnptq3dzRClzYjvin9",
      "y": "9GcT-pdGYUwhXrJyde9fGTqxZZBm66pBI5rgnDeFWLdaDSGsbu3GXkgT8_d7kr-9",
      "crv": "P-384"
    },
    {
      "kty": "RSA",
      "kid": "hzPtaW3r_qi0tAz0PbxUmSR7Y7M",
      "use": "enc",
      "n": "zDaj3WiVvT19AwP7hdVkkSVzd5-AvazScBEj3wcKZXagTor5DKAeketT8MLtrGijskK8Ag7LMUGhm0meTdxKO_kDpqhBkY8GVn9p9WPQU9LjtVW1AJR_8Vw86YKOiWXuzXBiNMt-2_v4wMtbADKfvdzVj6KB3uM1Ze-gmNdXCS18MnGe1pnkin6jDM9eshafrImu9RhYXkD6X-S6syWZphRk4YkZ6jaTf3TLoEIb-KxhSBUvgCbEaVRYxo4h0wPze_L6W-A_0SKoG97wlZGjdTGvAUVVJ7puRkYtEnPSEVKux8iHfZf9WqsyQPxIQm-w2dEcSlAPVKf-a9jBhk47jw",
      "e": "AQAB"
    }
  ]
}
2021-02-10 09:54:19 SUCCESS
CheckServerKeysIsValid
Server JWKs is valid
server_jwks
{
  "keys": [
    {
      "kty": "EC",
      "kid": "9rmD68IwLRrp5HjNxDMgHr1Sbpk",
      "use": "sig",
      "x": "SU3qQmiKxnWIpAU6ZBNQgMjwgHFZmUC1gJ8NJDD0Niog1QOM7KJhGYUlOgap2qsH",
      "y": "aO7xtjSwEl76Ihqi9t-HYs6j6TAApuTctpplw_sYmT8SHvFbQ-36_u-4Tqtl0eJN",
      "crv": "P-384"
    },
    {
      "kty": "RSA",
      "kid": "Zq4_Rs1JhDolLdW0eNa0IpCbaOM",
      "use": "sig",
      "n": "pzKGpHni6bAFoZgCskoYiJL4f6e3-KoRJTOflJ6GYuwiiNJVWigW4Co2tz5Zyp3RVO8GGb1fKs-afJpPdg8R4k0yM8LMftsDPMKjA1ebgddcUE9BRQcEpwQ3Y-1hanS6ZmXuVxkNMoT1uoB_w_chB4I6kXSFucgle-W8Mt206z00mV4ZKjDkrDGGxyKrxLI9zWBc6d0BSyDa4uqhAzMQLHLru3Z21Ot1Zz4Avgy0-fN_ni5YMp3cHwBNBQQxmz-4fKwk4FeAtNUWbrjrGXTp1bE2ItUCWKqV34oPupSHzBWuNTbD3sPljc3iFt3-OSLq0x4sajZ7YFiZjDoQ50kP-Q",
      "e": "AQAB"
    },
    {
      "kty": "EC",
      "kid": "rg0eyU38xRI-2e5UsRiOEnlD2Qs",
      "use": "sig",
      "x": "Aag8ntLcs6qiiQAzJYF5GYdWOlHViqwHeE8sb9_378dy9XB_OZAmOOZsW8dpHf420IIhIZ2zZUP9QEki8kl0o0Zi",
      "y": "AOZ7DsahqsrdGL1vThaJnbmyXezTWUzrLhx3dDbb8U2FFq37PTOHgYymZFQOTTMsi1TAbcHPZM8_mVWkQe8SENqQ",
      "crv": "P-521"
    },
    {
      "kty": "EC",
      "kid": "sKFuroXvCIad-bc7gCJJDe_kw3E",
      "use": "sig",
      "x": "WtryB9PDGZSToMbf0JOQG90PwRj2KMnU7n9T6IRwJzI",
      "y": "L5KHi5bzBcD-q7L0p2pSjg0BY0ZY5uWdOwQubhoVJsc",
      "crv": "P-256"
    },
    {
      "kty": "EC",
      "kid": "6yY2TlBV8jQQofSfyb5XOB4Jb6M",
      "use": "sig",
      "x": "AORGZoxt8oDD_RV2W1-4Ne1RDGjQhZj1BvBXpmY1QpKdrabD7-Wfofo7HU2NbH-q2pHqjQEa2xnmOnKINuQkdtYL",
      "y": "ACC6hcSGMpuj0ZapUKgnvfye4bRKQOBhVgdMA_YWV_8TgU36igiRHeH2N8PGiOsRH3Htk16TfoHyt7hkaCeANik9",
      "crv": "P-521"
    },
    {
      "kty": "EC",
      "kid": "HGp1IEQM1voQSq46IAvk_1YRqaE",
      "use": "sig",
      "x": "lDl885FnLKaM-5F97Kjqo-Lo6R4buuYnhTyiQ-AA8pw",
      "y": "l699BrNxVkOsb7nrap4hgnc5FMzGqEGBCcKIpnoCzW4",
      "crv": "P-256"
    },
    {
      "kty": "RSA",
      "kid": "OoaNeMIHyh-Y_nCgZt8P7S4WRHQ",
      "use": "sig",
      "n": "pwT1pxBXBTVtIXWjM-1eK5o8mYwrVjg0-tH3rVayjWjqDcFdudpZrmfW5DJX_tk8Nmxw05aK9WVV35gX3Z9hNopSDzv25aup_BSjwtMhzjDDZKqH0vZQOxwFg8mj_bKqNh5fLvSyPtonXgVzfSpuXbpsGWY_iKURqQlDB4GoI_fH0e0LCkQv5KdaUa_u46VAopeExNJxZ1sAszIpauhAVaRta7ClANvVoQiWr1yvrMLkwRe-RLK4RkTexFQWDG6-hT6casxmug8NuLP9u7iLDCIUhAppHTcQierZDjTiFdRXcPmMEbVxHTWqDOF06RnNQvKJ-KDfgVxsQ2lh3SlKXQ",
      "e": "AQAB"
    },
    {
      "kty": "EC",
      "kid": "jMHpWAXB63I1bbOLTb8BruHgSAM",
      "use": "sig",
      "x": "CO7-lbGTCdMBCE47l6HYdiy_ZAuXwrsdkhfUk3VoExI3w3G4m-TOZlVPVcSdRicm",
      "y": "Qy3Tuaw1vPHuGO4WP8-g4rIiD4qOtwCqIy1aMEPH0MLfP2cbgT_8lXORDe9Pklbu",
      "crv": "P-384"
    },
    {
      "kty": "EC",
      "kid": "idZdEltozJCPsw9C_4X1oJunzbI",
      "use": "sig",
      "x": "QQmn2hcLohFA4m9yitWE3-RrdbZpyf5mJxhTm3vHSqw",
      "y": "xUu6I85Juq1_kUhAjHz4IEzJ2KK7rpE4x1tJneDdCVA",
      "crv": "P-256"
    },
    {
      "kty": "RSA",
      "kid": "ii3sMTEFa9asTWi9I2oBzP7cxG4",
      "use": "sig",
      "n": "lK95ORbuwmjuFETa4Z_73zlAjGfq7vBVRosZfvEVarce85t7Y9wuVVYSRckg2VijZHwj44ibdTc15l6veStrVLLm7CPySSERpXcLEAdyfftwsn41h9RlHXn8zIgDkR7caHNgvDFLTml6TY89G3iJeZNwe_5-n5WMyfT4zfSNLAaXzPOeFCUbdLuJmm9OzcKTQsm7inYAPEaPb0LnuZB5MKa97s19ZSHP9n_2LImnbl1M3nUFmTyj6cidTB_zfCgBsDf5JEDMP7QYAbkyjbU_yUY3X36z-dBqMYXHdkpRGuSN6tJ-yzvCDR7DRffpb9ld49GQ3gjMilYDFpvAazhlWw",
      "e": "AQAB"
    },
    {
      "kty": "EC",
      "kid": "oMfG-1rmk0z5YYO6yQKVXQs14RU",
      "use": "sig",
      "x": "AF5sVn2wVq0DCho_zfl1Tb9G_684ENBGRuyY5g6cwYvPeQslw0jplPzpfb56OqvNZYrIhtZ9drC8P5SrJ1gsP0FA",
      "y": "AbSw-emm5IeIE-zlRCIa9VaiXXLH6EKqStmjzKPcZZoDVnRVzd9ucWfkGlypaUEChY31DvSWkBBZMVXONa7YQ22a",
      "crv": "P-521"
    },
    {
      "kty": "EC",
      "kid": "yxn8wvV8bguIMfKup61EritQX4s",
      "use": "sig",
      "x": "xg37IIpYhU99yDi4eDujpPx-LdcDXONudlGAzz3Q0j-Z3xTN-1OjoI5wmSqCtWDq",
      "y": "stP9A4-EwbILPpTqvmBaQUYLQU_vRim_oQfxPIp2nf7-Jb9BI_8ALkNALCWGRZRA",
      "crv": "P-384"
    },
    {
      "kty": "EC",
      "kid": "0foAtEfYk8IyeEfbyMxjGHSh7bY",
      "use": "enc",
      "x": "AdY_XnstGI8NAAAMlHmHhVabe1a4IvEAYPGuldazlc1YdObsur0IRaQUMp70n4VseHBxwtimO72wh931oTevMJCB",
      "y": "Aeqyn_9N1E9fKPjcizV3TIrM-psmlfC-df7qhazNX_11uVOjwfIvyxCtRFQAcRJRPnE7CC03sJXck0b5IxW8vtmQ",
      "crv": "P-521"
    },
    {
      "kty": "EC",
      "kid": "cLoJ6YOvJ1Idi8yBLGWv3tVXhqs",
      "use": "enc",
      "x": "RvIPoDC1SJcxNTTbHg9_V-tW95zXiCUxM4WteFmUI4I",
      "y": "Dl5dXtzPssghEAX51zm1VPEiIx-kpkjD87e2CK28TiI",
      "crv": "P-256"
    },
    {
      "kty": "EC",
      "kid": "gKzSjT2gz089ZXcMg4qndGvxH4w",
      "use": "enc",
      "x": "jkq2HdbtP0XMNF5B70hzH3BOKJ3MFulT_HzDy4KpCt6dVvVnptq3dzRClzYjvin9",
      "y": "9GcT-pdGYUwhXrJyde9fGTqxZZBm66pBI5rgnDeFWLdaDSGsbu3GXkgT8_d7kr-9",
      "crv": "P-384"
    },
    {
      "kty": "RSA",
      "kid": "hzPtaW3r_qi0tAz0PbxUmSR7Y7M",
      "use": "enc",
      "n": "zDaj3WiVvT19AwP7hdVkkSVzd5-AvazScBEj3wcKZXagTor5DKAeketT8MLtrGijskK8Ag7LMUGhm0meTdxKO_kDpqhBkY8GVn9p9WPQU9LjtVW1AJR_8Vw86YKOiWXuzXBiNMt-2_v4wMtbADKfvdzVj6KB3uM1Ze-gmNdXCS18MnGe1pnkin6jDM9eshafrImu9RhYXkD6X-S6syWZphRk4YkZ6jaTf3TLoEIb-KxhSBUvgCbEaVRYxo4h0wPze_L6W-A_0SKoG97wlZGjdTGvAUVVJ7puRkYtEnPSEVKux8iHfZf9WqsyQPxIQm-w2dEcSlAPVKf-a9jBhk47jw",
      "e": "AQAB"
    }
  ]
}
2021-02-10 09:54:19 SUCCESS
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2021-02-10 09:54:19 SUCCESS
CheckForKeyIdInServerJWKs
All keys contain kids
2021-02-10 09:54:19 SUCCESS
EnsureServerJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2021-02-10 09:54:19 SUCCESS
FAPIEnsureMinimumServerKeyLength
Validated minimum key lengths for server_jwks
server_jwks
{
  "keys": [
    {
      "kty": "EC",
      "kid": "9rmD68IwLRrp5HjNxDMgHr1Sbpk",
      "use": "sig",
      "x": "SU3qQmiKxnWIpAU6ZBNQgMjwgHFZmUC1gJ8NJDD0Niog1QOM7KJhGYUlOgap2qsH",
      "y": "aO7xtjSwEl76Ihqi9t-HYs6j6TAApuTctpplw_sYmT8SHvFbQ-36_u-4Tqtl0eJN",
      "crv": "P-384"
    },
    {
      "kty": "RSA",
      "kid": "Zq4_Rs1JhDolLdW0eNa0IpCbaOM",
      "use": "sig",
      "n": "pzKGpHni6bAFoZgCskoYiJL4f6e3-KoRJTOflJ6GYuwiiNJVWigW4Co2tz5Zyp3RVO8GGb1fKs-afJpPdg8R4k0yM8LMftsDPMKjA1ebgddcUE9BRQcEpwQ3Y-1hanS6ZmXuVxkNMoT1uoB_w_chB4I6kXSFucgle-W8Mt206z00mV4ZKjDkrDGGxyKrxLI9zWBc6d0BSyDa4uqhAzMQLHLru3Z21Ot1Zz4Avgy0-fN_ni5YMp3cHwBNBQQxmz-4fKwk4FeAtNUWbrjrGXTp1bE2ItUCWKqV34oPupSHzBWuNTbD3sPljc3iFt3-OSLq0x4sajZ7YFiZjDoQ50kP-Q",
      "e": "AQAB"
    },
    {
      "kty": "EC",
      "kid": "rg0eyU38xRI-2e5UsRiOEnlD2Qs",
      "use": "sig",
      "x": "Aag8ntLcs6qiiQAzJYF5GYdWOlHViqwHeE8sb9_378dy9XB_OZAmOOZsW8dpHf420IIhIZ2zZUP9QEki8kl0o0Zi",
      "y": "AOZ7DsahqsrdGL1vThaJnbmyXezTWUzrLhx3dDbb8U2FFq37PTOHgYymZFQOTTMsi1TAbcHPZM8_mVWkQe8SENqQ",
      "crv": "P-521"
    },
    {
      "kty": "EC",
      "kid": "sKFuroXvCIad-bc7gCJJDe_kw3E",
      "use": "sig",
      "x": "WtryB9PDGZSToMbf0JOQG90PwRj2KMnU7n9T6IRwJzI",
      "y": "L5KHi5bzBcD-q7L0p2pSjg0BY0ZY5uWdOwQubhoVJsc",
      "crv": "P-256"
    },
    {
      "kty": "EC",
      "kid": "6yY2TlBV8jQQofSfyb5XOB4Jb6M",
      "use": "sig",
      "x": "AORGZoxt8oDD_RV2W1-4Ne1RDGjQhZj1BvBXpmY1QpKdrabD7-Wfofo7HU2NbH-q2pHqjQEa2xnmOnKINuQkdtYL",
      "y": "ACC6hcSGMpuj0ZapUKgnvfye4bRKQOBhVgdMA_YWV_8TgU36igiRHeH2N8PGiOsRH3Htk16TfoHyt7hkaCeANik9",
      "crv": "P-521"
    },
    {
      "kty": "EC",
      "kid": "HGp1IEQM1voQSq46IAvk_1YRqaE",
      "use": "sig",
      "x": "lDl885FnLKaM-5F97Kjqo-Lo6R4buuYnhTyiQ-AA8pw",
      "y": "l699BrNxVkOsb7nrap4hgnc5FMzGqEGBCcKIpnoCzW4",
      "crv": "P-256"
    },
    {
      "kty": "RSA",
      "kid": "OoaNeMIHyh-Y_nCgZt8P7S4WRHQ",
      "use": "sig",
      "n": "pwT1pxBXBTVtIXWjM-1eK5o8mYwrVjg0-tH3rVayjWjqDcFdudpZrmfW5DJX_tk8Nmxw05aK9WVV35gX3Z9hNopSDzv25aup_BSjwtMhzjDDZKqH0vZQOxwFg8mj_bKqNh5fLvSyPtonXgVzfSpuXbpsGWY_iKURqQlDB4GoI_fH0e0LCkQv5KdaUa_u46VAopeExNJxZ1sAszIpauhAVaRta7ClANvVoQiWr1yvrMLkwRe-RLK4RkTexFQWDG6-hT6casxmug8NuLP9u7iLDCIUhAppHTcQierZDjTiFdRXcPmMEbVxHTWqDOF06RnNQvKJ-KDfgVxsQ2lh3SlKXQ",
      "e": "AQAB"
    },
    {
      "kty": "EC",
      "kid": "jMHpWAXB63I1bbOLTb8BruHgSAM",
      "use": "sig",
      "x": "CO7-lbGTCdMBCE47l6HYdiy_ZAuXwrsdkhfUk3VoExI3w3G4m-TOZlVPVcSdRicm",
      "y": "Qy3Tuaw1vPHuGO4WP8-g4rIiD4qOtwCqIy1aMEPH0MLfP2cbgT_8lXORDe9Pklbu",
      "crv": "P-384"
    },
    {
      "kty": "EC",
      "kid": "idZdEltozJCPsw9C_4X1oJunzbI",
      "use": "sig",
      "x": "QQmn2hcLohFA4m9yitWE3-RrdbZpyf5mJxhTm3vHSqw",
      "y": "xUu6I85Juq1_kUhAjHz4IEzJ2KK7rpE4x1tJneDdCVA",
      "crv": "P-256"
    },
    {
      "kty": "RSA",
      "kid": "ii3sMTEFa9asTWi9I2oBzP7cxG4",
      "use": "sig",
      "n": "lK95ORbuwmjuFETa4Z_73zlAjGfq7vBVRosZfvEVarce85t7Y9wuVVYSRckg2VijZHwj44ibdTc15l6veStrVLLm7CPySSERpXcLEAdyfftwsn41h9RlHXn8zIgDkR7caHNgvDFLTml6TY89G3iJeZNwe_5-n5WMyfT4zfSNLAaXzPOeFCUbdLuJmm9OzcKTQsm7inYAPEaPb0LnuZB5MKa97s19ZSHP9n_2LImnbl1M3nUFmTyj6cidTB_zfCgBsDf5JEDMP7QYAbkyjbU_yUY3X36z-dBqMYXHdkpRGuSN6tJ-yzvCDR7DRffpb9ld49GQ3gjMilYDFpvAazhlWw",
      "e": "AQAB"
    },
    {
      "kty": "EC",
      "kid": "oMfG-1rmk0z5YYO6yQKVXQs14RU",
      "use": "sig",
      "x": "AF5sVn2wVq0DCho_zfl1Tb9G_684ENBGRuyY5g6cwYvPeQslw0jplPzpfb56OqvNZYrIhtZ9drC8P5SrJ1gsP0FA",
      "y": "AbSw-emm5IeIE-zlRCIa9VaiXXLH6EKqStmjzKPcZZoDVnRVzd9ucWfkGlypaUEChY31DvSWkBBZMVXONa7YQ22a",
      "crv": "P-521"
    },
    {
      "kty": "EC",
      "kid": "yxn8wvV8bguIMfKup61EritQX4s",
      "use": "sig",
      "x": "xg37IIpYhU99yDi4eDujpPx-LdcDXONudlGAzz3Q0j-Z3xTN-1OjoI5wmSqCtWDq",
      "y": "stP9A4-EwbILPpTqvmBaQUYLQU_vRim_oQfxPIp2nf7-Jb9BI_8ALkNALCWGRZRA",
      "crv": "P-384"
    },
    {
      "kty": "EC",
      "kid": "0foAtEfYk8IyeEfbyMxjGHSh7bY",
      "use": "enc",
      "x": "AdY_XnstGI8NAAAMlHmHhVabe1a4IvEAYPGuldazlc1YdObsur0IRaQUMp70n4VseHBxwtimO72wh931oTevMJCB",
      "y": "Aeqyn_9N1E9fKPjcizV3TIrM-psmlfC-df7qhazNX_11uVOjwfIvyxCtRFQAcRJRPnE7CC03sJXck0b5IxW8vtmQ",
      "crv": "P-521"
    },
    {
      "kty": "EC",
      "kid": "cLoJ6YOvJ1Idi8yBLGWv3tVXhqs",
      "use": "enc",
      "x": "RvIPoDC1SJcxNTTbHg9_V-tW95zXiCUxM4WteFmUI4I",
      "y": "Dl5dXtzPssghEAX51zm1VPEiIx-kpkjD87e2CK28TiI",
      "crv": "P-256"
    },
    {
      "kty": "EC",
      "kid": "gKzSjT2gz089ZXcMg4qndGvxH4w",
      "use": "enc",
      "x": "jkq2HdbtP0XMNF5B70hzH3BOKJ3MFulT_HzDy4KpCt6dVvVnptq3dzRClzYjvin9",
      "y": "9GcT-pdGYUwhXrJyde9fGTqxZZBm66pBI5rgnDeFWLdaDSGsbu3GXkgT8_d7kr-9",
      "crv": "P-384"
    },
    {
      "kty": "RSA",
      "kid": "hzPtaW3r_qi0tAz0PbxUmSR7Y7M",
      "use": "enc",
      "n": "zDaj3WiVvT19AwP7hdVkkSVzd5-AvazScBEj3wcKZXagTor5DKAeketT8MLtrGijskK8Ag7LMUGhm0meTdxKO_kDpqhBkY8GVn9p9WPQU9LjtVW1AJR_8Vw86YKOiWXuzXBiNMt-2_v4wMtbADKfvdzVj6KB3uM1Ze-gmNdXCS18MnGe1pnkin6jDM9eshafrImu9RhYXkD6X-S6syWZphRk4YkZ6jaTf3TLoEIb-KxhSBUvgCbEaVRYxo4h0wPze_L6W-A_0SKoG97wlZGjdTGvAUVVJ7puRkYtEnPSEVKux8iHfZf9WqsyQPxIQm-w2dEcSlAPVKf-a9jBhk47jw",
      "e": "AQAB"
    }
  ]
}
Verify First client: static client configuration
2021-02-10 09:54:19 SUCCESS
GetStaticClientConfiguration
Found a static client object
client_id
conformance3ping
scope
openid test
jwks
{
  "keys": [
    {
      "kty": "EC",
      "d": "QPg1PBy12DhqqGeiuWBoIdhrfbOutP8nfSND46mdTgU",
      "use": "sig",
      "crv": "P-256",
      "kid": "2HKyz2Uc4F8hRcwyuPgA5Eg_salnEe7pfujUkvj2yew",
      "x": "NK3-2enqupOW-PGDSp2X2vrtqFIVnsVMciZdVwa7p8Q",
      "y": "Yrp1yMUYXZcWbHRzsXlH94v2SJZs0lxRbbCpvo1kcUw",
      "alg": "ES256"
    }
  ]
}
hint_type
login_hint
hint_value
patrick
2021-02-10 09:54:20 SUCCESS
ValidateClientJWKsPrivatePart
Valid client JWKs: keys are valid JSON, contain the required fields, the private/public exponents match and are correctly encoded using unpadded base64url
2021-02-10 09:54:20 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "kty": "EC",
      "d": "QPg1PBy12DhqqGeiuWBoIdhrfbOutP8nfSND46mdTgU",
      "use": "sig",
      "crv": "P-256",
      "kid": "2HKyz2Uc4F8hRcwyuPgA5Eg_salnEe7pfujUkvj2yew",
      "x": "NK3-2enqupOW-PGDSp2X2vrtqFIVnsVMciZdVwa7p8Q",
      "y": "Yrp1yMUYXZcWbHRzsXlH94v2SJZs0lxRbbCpvo1kcUw",
      "alg": "ES256"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "EC",
      "use": "sig",
      "crv": "P-256",
      "kid": "2HKyz2Uc4F8hRcwyuPgA5Eg_salnEe7pfujUkvj2yew",
      "x": "NK3-2enqupOW-PGDSp2X2vrtqFIVnsVMciZdVwa7p8Q",
      "y": "Yrp1yMUYXZcWbHRzsXlH94v2SJZs0lxRbbCpvo1kcUw",
      "alg": "ES256"
    }
  ]
}
2021-02-10 09:54:20
ValidateMTLSCertificatesHeader
No certificate authority found for MTLS
2021-02-10 09:54:20 SUCCESS
ValidateMTLSCertificatesHeader
MTLS certificates header is valid
2021-02-10 09:54:20
ExtractMTLSCertificatesFromConfiguration
No certificate authority found for MTLS
2021-02-10 09:54:20 SUCCESS
ExtractMTLSCertificatesFromConfiguration
Mutual TLS authentication credentials loaded
cert
MIIDlTCCAn2gAwIBAgIJAKRJoaX7BlZbMA0GCSqGSIb3DQEBCwUAMGAxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMR0wGwYDVQQKDBRBdXRobGV0ZSBUZXN0IENsaWVudDEdMBsGA1UEAwwUQXV0aGxldGUgVGVzdCBDbGllbnQwIBcNMTgwNTI1MjA1NzU0WhgPMjEwNjAxMDQyMDU3NTRaMGAxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMR0wGwYDVQQKDBRBdXRobGV0ZSBUZXN0IENsaWVudDEdMBsGA1UEAwwUQXV0aGxldGUgVGVzdCBDbGllbnQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDEWwl/Q+nuL8KXbObpVzww1VkHwLF4W9QxrPI1V0Uh6V9rxUjrfSbtWNEQVDwQmoW8M1XjnRnGvdNRd0m6gNEQLKsqRN2xIvPdR0IO+2b+y7WJ9XlwdqHAFSWQJtoHzBAmkRirRMJrQSW5sB/NIBmyVqUdTV/FghNjc+IiPF4X1kxwwOzm7y2zlHZUpiPQknwPbWNeyunj/XQRrqWPg+RXzAKIjbVprxGaT8CexKu6oEaed8BCTO0rJIOkmjXZMl+SDhXQn9GHKFh60UlJddxVngxhX63MAQ1GsO8HsjrLgO3q4LmTDVHkprLy/wgBRDfo0IHb3gWhbOuRGMLLMKKvAgMBAAGjUDBOMB0GA1UdDgQWBBRuwpA4lqWaOkwmPcTQR8CH0Iv3vjAfBgNVHSMEGDAWgBRuwpA4lqWaOkwmPcTQR8CH0Iv3vjAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQBiCmvQmmKqI/8sB312HTEFlvtpbYp429eNCGXWloOOqVQkJaBnvy9YUS/wCgusyKeMBgbgpV0s8bp/gEW2/MnlWW9+fbFuhzRRwvuV/7je1Avv9Y06RH8GKJYwk2j6qcO7Mn9kVhlnlKxGdFxm/i0OBuZnUe/KDxKPjVEdUJbxAFfxdq4cUjfewMuoxsYruIDnLXjTBcj2PbJ6vcPzq/6TYwxRmnrXIAO6Nxe8ZNXn2x2+njwrUKW4WPQ7u3dyHlD+M3iTpm3TwSgg0FSYiBcXhWJLQCJVEb0kbKJ/PDmcvomusQWTL/0epS62azWG8PUUs4v9XeaemAbHqPGh+5Bo
key
MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDEWwl/Q+nuL8KXbObpVzww1VkHwLF4W9QxrPI1V0Uh6V9rxUjrfSbtWNEQVDwQmoW8M1XjnRnGvdNRd0m6gNEQLKsqRN2xIvPdR0IO+2b+y7WJ9XlwdqHAFSWQJtoHzBAmkRirRMJrQSW5sB/NIBmyVqUdTV/FghNjc+IiPF4X1kxwwOzm7y2zlHZUpiPQknwPbWNeyunj/XQRrqWPg+RXzAKIjbVprxGaT8CexKu6oEaed8BCTO0rJIOkmjXZMl+SDhXQn9GHKFh60UlJddxVngxhX63MAQ1GsO8HsjrLgO3q4LmTDVHkprLy/wgBRDfo0IHb3gWhbOuRGMLLMKKvAgMBAAECggEAJ3uOy1JipYxg+oXhYKYz6jXcMxziEquUXXDDO0qTEiCVGVyQLxn5S9yCHWByu3v2zEMeUCh02GuvJEBySNhCMZhpypQSZ935X1NGyzBuI2ne1SDRDHYuTCt0ZCoLyWmVDcw7Q6UN2vc8mLv7iQmdYSjfBqdaTKK9N1BD9lJhMTWBjxQDaF1yEZQfR1HOVVddJXt8ILOOltuxhu4EuBKsT8ZlCAN5kGx6+FzXlGlSYjWnGoYbERESeDim3JDwGOGX2msPGOmSzF24LnXrPg8IcrwEbzlFRIEzd8yUVA6VNca71uzv/MaOX5+cTtDiAoVdfrk1Ykt1SNNccGKnC7L3MQKBgQD29FIhT21DkUnXlABKj0N9dBSQyQ1HzILmY/YSg7aeBAlatEzCDxHtFaS89wXxosz2vNd1QKIrLrAgSzTLyemi2KVcvsHyo0g0drSq3NlOw5Rz4WRAZNgBcuhFJ8ZD1BJCisdQxQyCRJ3I0pf/D7mGkmovII1WSk/MIEWWvd3P6wKBgQDLjEEOaTeopbnqkJrcL4UbV2GmVAIa9EXSqzRTrPlxVA62n8EEX5YLXTx6yrvWHWtlA4VgRmUGuu1km5DqlnVdVz/l8fSk2HFcdycJgKd189v/tQ+BLu50+1+uaHiWLXo3VEXgv5QKSgPxWEnNPRVbgqOhav2MaACKo9sl3h4LTQKBgQCjyIxD7VKREmW/5TeAO53OMVOGZuE48ikKtdc4lkRibljp4FRcC/SeodEdRlOZ25hGOB5JdHFZZGCJOneshKBAUaDybs1gp+w2Z1gRTeGNvGbTp/N+RaOA6n2jh+qVh6wIl9Py/Iz8RJfE3e7SydIIr0hfMx6p0SU1Q14DyK64uwKBgQCiqM5ESejkqKtNu4lFc+QW2Vl7pZ6ZE6PImnASfiRIYDfx0PBaIlixdCyko+Y/UPtFme635QlOu4qB35+LF/lqQhMaGqS6Jw1QKxfTDDDGnb2tNm/ReEOu0ELCCVJ0EJueI4ZD+FTBdCx6bWdsz+eFXXyNvgYoceQc5px2Qm4X8QKBgHwpmIeHCvU9Erb9X5pY5JR609Ei+a9jksoe0ch7ocZi2NoE3vwjUSZFe/hTkvpf0gUhw1Zmekqhm78Qb4H7Aq7RDbpyCvoRXGS4GulFXM9Tkfe5FejhawT6fG12KLHOSAkJNgdFCPvFOaHlxPoAaBcf1sY/flehjWEwkVDSh0Js
2021-02-10 09:54:20 SUCCESS
CheckForKeyIdInClientJWKs
All keys contain kids
2021-02-10 09:54:20 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2021-02-10 09:54:20 SUCCESS
FAPICheckKeyAlgInClientJWKs
Found a key with alg PS256 or ES256
2021-02-10 09:54:20 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "kty": "EC",
      "d": "QPg1PBy12DhqqGeiuWBoIdhrfbOutP8nfSND46mdTgU",
      "use": "sig",
      "crv": "P-256",
      "kid": "2HKyz2Uc4F8hRcwyuPgA5Eg_salnEe7pfujUkvj2yew",
      "x": "NK3-2enqupOW-PGDSp2X2vrtqFIVnsVMciZdVwa7p8Q",
      "y": "Yrp1yMUYXZcWbHRzsXlH94v2SJZs0lxRbbCpvo1kcUw",
      "alg": "ES256"
    }
  ]
}
2021-02-10 09:54:20 SUCCESS
ValidateMTLSCertificatesAsX509
Mutual TLS authentication cert validated as X.509
Verify Second client: static client configuration
2021-02-10 09:54:20 SUCCESS
GetStaticClient2Configuration
Found a static second client object
client_id
conformance4ping
scope
openid test
jwks
{
  "keys": [
    {
      "kty": "EC",
      "d": "MTbmR5F_tN0zlvVrwESkMNHB-ZLoRpk3dlxHYged3Ik",
      "use": "sig",
      "crv": "P-256",
      "kid": "6waBCAJKuKMvSU3k540XHPx_4gJx01tmQh8giaYjj1k",
      "x": "XW7xFTCnyPLhhWb_dE0fIIavYTbilf3HDsUELAC5SwI",
      "y": "sm9SrdwPWJ_oQ5tbsDMi6xnsaoLWZLTFyy0L2q5vURE",
      "alg": "ES256"
    }
  ]
}
acr_value
high
2021-02-10 09:54:20 SUCCESS
ValidateClientJWKsPrivatePart
Valid client JWKs: keys are valid JSON, contain the required fields, the private/public exponents match and are correctly encoded using unpadded base64url
2021-02-10 09:54:20 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "kty": "EC",
      "d": "MTbmR5F_tN0zlvVrwESkMNHB-ZLoRpk3dlxHYged3Ik",
      "use": "sig",
      "crv": "P-256",
      "kid": "6waBCAJKuKMvSU3k540XHPx_4gJx01tmQh8giaYjj1k",
      "x": "XW7xFTCnyPLhhWb_dE0fIIavYTbilf3HDsUELAC5SwI",
      "y": "sm9SrdwPWJ_oQ5tbsDMi6xnsaoLWZLTFyy0L2q5vURE",
      "alg": "ES256"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "EC",
      "use": "sig",
      "crv": "P-256",
      "kid": "6waBCAJKuKMvSU3k540XHPx_4gJx01tmQh8giaYjj1k",
      "x": "XW7xFTCnyPLhhWb_dE0fIIavYTbilf3HDsUELAC5SwI",
      "y": "sm9SrdwPWJ_oQ5tbsDMi6xnsaoLWZLTFyy0L2q5vURE",
      "alg": "ES256"
    }
  ]
}
2021-02-10 09:54:20
ValidateMTLSCertificates2Header
No certificate authority found for MTLS
2021-02-10 09:54:20 SUCCESS
ValidateMTLSCertificates2Header
MTLS certificates header is valid
2021-02-10 09:54:20
ExtractMTLSCertificates2FromConfiguration
No certificate authority found for MTLS
2021-02-10 09:54:20 SUCCESS
ExtractMTLSCertificates2FromConfiguration
Mutual TLS authentication credentials loaded
cert
MIIDhTCCAm2gAwIBAgIJAKAe4HusBvwoMA0GCSqGSIb3DQEBCwUAMFgxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMSEwHwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQxETAPBgNVBAMMCGNsaWVudF8yMCAXDTE4MDcwMjE2MzUyOFoYDzIxMDYwMjExMTYzNTI4WjBYMQswCQYDVQQGEwJVUzETMBEGA1UECAwKU29tZS1TdGF0ZTEhMB8GA1UECgwYSW50ZXJuZXQgV2lkZ2l0cyBQdHkgTHRkMREwDwYDVQQDDAhjbGllbnRfMjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANMy1QohUbUoyte8cYCCO1+vJ/GImvVkrb79HUTSzL3G46lDC0JYZGMpMvX9NncadCYLQV8fmofOouNs4AWJgf0skH5sAJcZMgj3GVqqLsx2iDye3cgqsCCzTf5gzhOVtpXgNoBMFckVGxI+dG9h06n71mH9dtGoD/BoWOB4FLae0Ec4olot5eROeJ3Z0J15aXPWoQrn3J5Eoz0/c7D7+byb+XGjF/r+uJVrKqOLtnO69Ro99fowwVtVQAPHmxLQ9VvFiLONwbOfELtBvX4MlxHDOuynDsDw/mHxkzMSxPXAd9QfIU05ySZ9eVR3UfNUeCk8a63NSO8MZdfHFnUsEO8CAwEAAaNQME4wHQYDVR0OBBYEFFEdch1XYRpO5JXxPkBxdAoAt6IiMB8GA1UdIwQYMBaAFFEdch1XYRpO5JXxPkBxdAoAt6IiMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBABTTN0up/ndWCNamqrV8ik1XwUqPCAO7TYKmZrRilo3STxyp2aUiFf1uPSkU6WU4Eu0JoDKU46axIFzZO3Ckoq17JMde2OzESlAF+hQyvg/3l+6mbBK/OuzOiC+yfU9roD6vmjsBlH0My1+CnqkZLr6YQSaCHfflb6zqA7+aLUEWjyVneD6jQ6CCFwCs6eDorY1eKFM7lCQ5OdJFBc2LOOXuSGRXLZDKF3X2SfKCld0VWIOknJk8drfrCc1ylWa7wIuXU/kTyX8Z68a8w1/6ZkGxN9tsHWVtSe6ggOD1AFI5OQ3c8lCUzgGeFl69hz2UduHOyWs1KXUhgSy7fViAP90=
key
MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQDTMtUKIVG1KMrXvHGAgjtfryfxiJr1ZK2+/R1E0sy9xuOpQwtCWGRjKTL1/TZ3GnQmC0FfH5qHzqLjbOAFiYH9LJB+bACXGTII9xlaqi7Mdog8nt3IKrAgs03+YM4TlbaV4DaATBXJFRsSPnRvYdOp+9Zh/XbRqA/waFjgeBS2ntBHOKJaLeXkTnid2dCdeWlz1qEK59yeRKM9P3Ow+/m8m/lxoxf6/riVayqji7ZzuvUaPfX6MMFbVUADx5sS0PVbxYizjcGznxC7Qb1+DJcRwzrspw7A8P5h8ZMzEsT1wHfUHyFNOckmfXlUd1HzVHgpPGutzUjvDGXXxxZ1LBDvAgMBAAECggEBAJzGiiB39VheTJzy1OqJQhvYQPVp62Wn89XnvLdfJ/7kShFWpF/+j56QcbTq32hwabHn/wHmyuZvPLlIE8/ocGcIksZV0+ZWHK9NBjQoSo8ami0t3QJ+tbnAgHAJWlBtfVkqVCrO0AkxsqPLWtFntCDlwhGBfpdJg3N5cihG21FnnqUNxj2lVp1jxCAAcBHwCMfODFi0Kke/FLS3u9vHSRybUAbNid1adNJ6g3f3jKXhX5HPR2KYqDIyCQrqs9IAx7mM/T2W75NpZC1rW5GAWyw7sR71YDFI/Mronrdh0ZiHOpllwgM4bBD7ipNH3jNRgsAUr5nyTIJAii9z8XxGubkCgYEA+e88Kt3uZbFfcqTvb2ZTCUd3fyC0FcZ+/iHhKp2fmwsSIWB7k6++q8Vn/YHdew7KS+i4dvap30+k8Jf0u8p1NY82qHb5b/8igj6z015O+q1XE+hNoPUeIlX7JBVf0y3NIiiOTxvcWoIGKpthEVvlVk27PfYUEsnefFnKTQ7kNI0CgYEA2FLxXKrDQQRwtmC0My4LuAwhkGqxCwk1V8vD0k+J1JqVI3qQPxt5H241KtWwdb6QxAjuBe0i1Yx6vW1qC60NaZpM7RLFOEKyfwLuk19S9BKs1q0BRqcPpIP0PIZ+GgpKs7fIWcn19IFI/1KlSVYYV7qDgDmzMG13OPeJuAclAmsCgYBIyIdgAGMlUCL4ktl7OnQh9qLw7Ygj8zsWLK2SqHZLQ00TVTKHjp1bDlC7PW9PH75/npThZ/GOK3Zf7hCCA3Jgl4UWSBdZqxXUkgfyHLupOoNqM7MvlVIiM6HAH01ZhTQAp4jRts5TuRusmrUIxhciK97EK34q/oiA8/D6wcRpHQKBgBWbY0RQQiRyXxe4XQdnqAAAJjIYlgp2Jv/X+H0/OJMlxZO/oDzNb7G1/lWC9pcsK6WJBs1MvFf8Kh5VmWwFIvvTT6+2WkCeWNna3x2VPeHnI6Bls2TtNuDF1VVeUaYkNQXya26cf5amezYVeTD0CoZouM3L9Zv2sxvbjcP14rp1AoGADoxlSjWxXOxZAr835wFlD3EMU5nhUGA0BdCfGgKqMaZmCr/ssfQDARgCKG/zLfmUBBBHbjZcHMXw6SW+E3CTN/q7iddT3FOgVder4GWTA+wFYdAywCT5At8wm7zeM2d/4cWlBaKew/u+A0ycUsD6bd3gRXjBZpD8Eep8ltVGLHw=
2021-02-10 09:54:20 SUCCESS
CheckForKeyIdInClientJWKs
All keys contain kids
2021-02-10 09:54:20 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2021-02-10 09:54:20 SUCCESS
FAPICheckKeyAlgInClientJWKs
Found a key with alg PS256 or ES256
2021-02-10 09:54:20 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "kty": "EC",
      "d": "MTbmR5F_tN0zlvVrwESkMNHB-ZLoRpk3dlxHYged3Ik",
      "use": "sig",
      "crv": "P-256",
      "kid": "6waBCAJKuKMvSU3k540XHPx_4gJx01tmQh8giaYjj1k",
      "x": "XW7xFTCnyPLhhWb_dE0fIIavYTbilf3HDsUELAC5SwI",
      "y": "sm9SrdwPWJ_oQ5tbsDMi6xnsaoLWZLTFyy0L2q5vURE",
      "alg": "ES256"
    }
  ]
}
2021-02-10 09:54:20 SUCCESS
ValidateMTLSCertificatesAsX509
Mutual TLS authentication cert validated as X.509
2021-02-10 09:54:20 SUCCESS
GetResourceEndpointConfiguration
Found a resource endpoint object
resourceUrl
https://emea-conformance.ping-eng.com:3000/get
2021-02-10 09:54:20 SUCCESS
SetProtectedResourceUrlToSingleResourceEndpoint
Set protected resource URL
protected_resource_url
https://emea-conformance.ping-eng.com:3000/get
2021-02-10 09:54:20 SUCCESS
ExtractTLSTestValuesFromResourceConfiguration
Extracted TLS information from resource endpoint
resource_endpoint
{
  "testHost": "emea-conformance.ping-eng.com",
  "testPort": 3000
}
2021-02-10 09:54:20 SUCCESS
ExtractTLSTestValuesFromOBResourceConfiguration
Extracted TLS information from resource endpoint
accounts_resource_endpoint
{
  "testHost": "emea-conformance.ping-eng.com",
  "testPort": 3000
}
accounts_request_endpoint
{
  "testHost": "emea-conformance.ping-eng.com",
  "testPort": 3000
}
2021-02-10 09:54:20
fapi-ciba-id1-refresh-token
Setup Done
Call backchannel authentication endpoint
2021-02-10 09:54:20 SUCCESS
CreateEmptyAuthorizationEndpointRequest
Created empty authorization endpoint request
2021-02-10 09:54:20 SUCCESS
AddScopeToAuthorizationEndpointRequest
Added scope of 'openid test' to authorization endpoint request
scope
openid test
2021-02-10 09:54:20 SUCCESS
AddHintToAuthorizationEndpointRequest
Added hint to authorization endpoint request
login_hint
patrick
2021-02-10 09:54:20 SUCCESS
AddBindingMessageToAuthorizationEndpointRequest
Added binding message to authorization endpoint request
binding_message
1234
2021-02-10 09:54:20
CreateRandomClientNotificationToken
Created token value
client_notification_token
xd0zex65C_9+q4L4hvHU=
requested_notification_token_length
21
2021-02-10 09:54:20 SUCCESS
AddClientNotificationTokenToAuthorizationEndpointRequest
Added client_notification_token 'xd0zex65C_9+q4L4hvHU=' to authorization endpoint request
scope
openid test
login_hint
patrick
binding_message
1234
client_notification_token
xd0zex65C_9+q4L4hvHU=
2021-02-10 09:54:20 SUCCESS
ConvertAuthorizationEndpointRequestToRequestObject
Created request object claims
request_object_claims
{
  "scope": "openid test",
  "login_hint": "patrick",
  "binding_message": "1234",
  "client_notification_token": "xd0zex65C_9+q4L4hvHU\u003d"
}
2021-02-10 09:54:20 SUCCESS
AddIatToRequestObject
Added iat to request object claims
iat
1.61295086E9
2021-02-10 09:54:20 SUCCESS
AddExpToRequestObject
Added exp to request object claims
exp
1.61295116E9
2021-02-10 09:54:20 SUCCESS
AddNbfToRequestObject
Added nbf to request object claims
nbf
1.61295086E9
2021-02-10 09:54:20 SUCCESS
AddJtiToRequestObject
Added jti to request object claims
jti
4ifQ5LWblNxhZVJWzy0D
2021-02-10 09:54:20 SUCCESS
AddAudToRequestObject
Added aud to request object claims
aud
https://emea-conformance.ping-eng.com:9031
2021-02-10 09:54:20 SUCCESS
AddIssToRequestObject
Added iss to request object claims
iss
conformance3ping
2021-02-10 09:54:20 SUCCESS
SignRequestObject
Signed the request object
claims
{"client_notification_token":"xd0zex65C_9+q4L4hvHU=","aud":"https:\/\/emea-conformance.ping-eng.com:9031","login_hint":"patrick","nbf":1612950860,"scope":"openid test","iss":"conformance3ping","binding_message":"1234","exp":1612951160,"iat":1612950860,"jti":"4ifQ5LWblNxhZVJWzy0D"}
header
{"kid":"2HKyz2Uc4F8hRcwyuPgA5Eg_salnEe7pfujUkvj2yew","alg":"ES256"}
request_object
eyJraWQiOiIySEt5ejJVYzRGOGhSY3d5dVBnQTVFZ19zYWxuRWU3cGZ1alVrdmoyeWV3IiwiYWxnIjoiRVMyNTYifQ.eyJjbGllbnRfbm90aWZpY2F0aW9uX3Rva2VuIjoieGQwemV4NjVDXzkrcTRMNGh2SFU9IiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzEiLCJsb2dpbl9oaW50IjoicGF0cmljayIsIm5iZiI6MTYxMjk1MDg2MCwic2NvcGUiOiJvcGVuaWQgdGVzdCIsImlzcyI6ImNvbmZvcm1hbmNlM3BpbmciLCJiaW5kaW5nX21lc3NhZ2UiOiIxMjM0IiwiZXhwIjoxNjEyOTUxMTYwLCJpYXQiOjE2MTI5NTA4NjAsImp0aSI6IjRpZlE1TFdibE54aFpWSld6eTBEIn0.BWTCVBjVpw8WPkFfH_aj98whN_GCbZkl3JncCRMRDlFEmMN6YwQwH9yIa3vSWIi-nfrqQMT5d_YWiRRkgmdDbw
key
{"kty":"EC","d":"QPg1PBy12DhqqGeiuWBoIdhrfbOutP8nfSND46mdTgU","use":"sig","crv":"P-256","kid":"2HKyz2Uc4F8hRcwyuPgA5Eg_salnEe7pfujUkvj2yew","x":"NK3-2enqupOW-PGDSp2X2vrtqFIVnsVMciZdVwa7p8Q","y":"Yrp1yMUYXZcWbHRzsXlH94v2SJZs0lxRbbCpvo1kcUw","alg":"ES256"}
2021-02-10 09:54:20 SUCCESS
CreateBackchannelAuthenticationEndpointRequest
Created backchannel authentication endpoint request
2021-02-10 09:54:20
AddRequestToBackchannelAuthenticationEndpointRequest
request
eyJraWQiOiIySEt5ejJVYzRGOGhSY3d5dVBnQTVFZ19zYWxuRWU3cGZ1alVrdmoyeWV3IiwiYWxnIjoiRVMyNTYifQ.eyJjbGllbnRfbm90aWZpY2F0aW9uX3Rva2VuIjoieGQwemV4NjVDXzkrcTRMNGh2SFU9IiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzEiLCJsb2dpbl9oaW50IjoicGF0cmljayIsIm5iZiI6MTYxMjk1MDg2MCwic2NvcGUiOiJvcGVuaWQgdGVzdCIsImlzcyI6ImNvbmZvcm1hbmNlM3BpbmciLCJiaW5kaW5nX21lc3NhZ2UiOiIxMjM0IiwiZXhwIjoxNjEyOTUxMTYwLCJpYXQiOjE2MTI5NTA4NjAsImp0aSI6IjRpZlE1TFdibE54aFpWSld6eTBEIn0.BWTCVBjVpw8WPkFfH_aj98whN_GCbZkl3JncCRMRDlFEmMN6YwQwH9yIa3vSWIi-nfrqQMT5d_YWiRRkgmdDbw
2021-02-10 09:54:20 SUCCESS
CreateClientAuthenticationAssertionClaims
Created client assertion claims
iss
conformance3ping
sub
conformance3ping
aud
https://emea-conformance.ping-eng.com:9032/as/token.oauth2
jti
aoj3slX0iQS01kjVeG1t
iat
1612950860
exp
1612950920
2021-02-10 09:54:20 SUCCESS
SetClientAuthenticationAudIssuerIdentifierToBackchannelAuthenticationEndpoint
Add Issuer Identifier as aud value to client_assertion_claims
iss
conformance3ping
sub
conformance3ping
aud
https://emea-conformance.ping-eng.com:9031
jti
aoj3slX0iQS01kjVeG1t
iat
1612950860
exp
1612950920
2021-02-10 09:54:20 SUCCESS
SignClientAuthenticationAssertion
Signed the client assertion
client_assertion
eyJraWQiOiIySEt5ejJVYzRGOGhSY3d5dVBnQTVFZ19zYWxuRWU3cGZ1alVrdmoyeWV3IiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTNwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzEiLCJpc3MiOiJjb25mb3JtYW5jZTNwaW5nIiwiZXhwIjoxNjEyOTUwOTIwLCJpYXQiOjE2MTI5NTA4NjAsImp0aSI6ImFvajNzbFgwaVFTMDFralZlRzF0In0.70OoLP4bHqAfOHCetLzr1UrLJVp-JWmviQyvF8uZmdE-_EnkGominBfC-Vyd3EKGs6n6egQ7LJuccqhgEnE8tA
2021-02-10 09:54:20
AddClientAssertionToBackchannelAuthenticationEndpoint
Added client assertion
request
eyJraWQiOiIySEt5ejJVYzRGOGhSY3d5dVBnQTVFZ19zYWxuRWU3cGZ1alVrdmoyeWV3IiwiYWxnIjoiRVMyNTYifQ.eyJjbGllbnRfbm90aWZpY2F0aW9uX3Rva2VuIjoieGQwemV4NjVDXzkrcTRMNGh2SFU9IiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzEiLCJsb2dpbl9oaW50IjoicGF0cmljayIsIm5iZiI6MTYxMjk1MDg2MCwic2NvcGUiOiJvcGVuaWQgdGVzdCIsImlzcyI6ImNvbmZvcm1hbmNlM3BpbmciLCJiaW5kaW5nX21lc3NhZ2UiOiIxMjM0IiwiZXhwIjoxNjEyOTUxMTYwLCJpYXQiOjE2MTI5NTA4NjAsImp0aSI6IjRpZlE1TFdibE54aFpWSld6eTBEIn0.BWTCVBjVpw8WPkFfH_aj98whN_GCbZkl3JncCRMRDlFEmMN6YwQwH9yIa3vSWIi-nfrqQMT5d_YWiRRkgmdDbw
client_assertion
eyJraWQiOiIySEt5ejJVYzRGOGhSY3d5dVBnQTVFZ19zYWxuRWU3cGZ1alVrdmoyeWV3IiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTNwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzEiLCJpc3MiOiJjb25mb3JtYW5jZTNwaW5nIiwiZXhwIjoxNjEyOTUwOTIwLCJpYXQiOjE2MTI5NTA4NjAsImp0aSI6ImFvajNzbFgwaVFTMDFralZlRzF0In0.70OoLP4bHqAfOHCetLzr1UrLJVp-JWmviQyvF8uZmdE-_EnkGominBfC-Vyd3EKGs6n6egQ7LJuccqhgEnE8tA
client_assertion_type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-02-10 09:54:20
CallBackchannelAuthenticationEndpoint
HTTP request
request_uri
https://emea-conformance.ping-eng.com:9031/as/bc-auth.ciba
request_method
POST
request_headers
{
  "accept": "application/json;charset\u003dUTF-8",
  "accept-charset": "utf-8",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "1067"
}
request_body
request=eyJraWQiOiIySEt5ejJVYzRGOGhSY3d5dVBnQTVFZ19zYWxuRWU3cGZ1alVrdmoyeWV3IiwiYWxnIjoiRVMyNTYifQ.eyJjbGllbnRfbm90aWZpY2F0aW9uX3Rva2VuIjoieGQwemV4NjVDXzkrcTRMNGh2SFU9IiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzEiLCJsb2dpbl9oaW50IjoicGF0cmljayIsIm5iZiI6MTYxMjk1MDg2MCwic2NvcGUiOiJvcGVuaWQgdGVzdCIsImlzcyI6ImNvbmZvcm1hbmNlM3BpbmciLCJiaW5kaW5nX21lc3NhZ2UiOiIxMjM0IiwiZXhwIjoxNjEyOTUxMTYwLCJpYXQiOjE2MTI5NTA4NjAsImp0aSI6IjRpZlE1TFdibE54aFpWSld6eTBEIn0.BWTCVBjVpw8WPkFfH_aj98whN_GCbZkl3JncCRMRDlFEmMN6YwQwH9yIa3vSWIi-nfrqQMT5d_YWiRRkgmdDbw&client_assertion=eyJraWQiOiIySEt5ejJVYzRGOGhSY3d5dVBnQTVFZ19zYWxuRWU3cGZ1alVrdmoyeWV3IiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTNwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzEiLCJpc3MiOiJjb25mb3JtYW5jZTNwaW5nIiwiZXhwIjoxNjEyOTUwOTIwLCJpYXQiOjE2MTI5NTA4NjAsImp0aSI6ImFvajNzbFgwaVFTMDFralZlRzF0In0.70OoLP4bHqAfOHCetLzr1UrLJVp-JWmviQyvF8uZmdE-_EnkGominBfC-Vyd3EKGs6n6egQ7LJuccqhgEnE8tA&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
request_mutual_tls
{
  "cert": "MIIDlTCCAn2gAwIBAgIJAKRJoaX7BlZbMA0GCSqGSIb3DQEBCwUAMGAxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMR0wGwYDVQQKDBRBdXRobGV0ZSBUZXN0IENsaWVudDEdMBsGA1UEAwwUQXV0aGxldGUgVGVzdCBDbGllbnQwIBcNMTgwNTI1MjA1NzU0WhgPMjEwNjAxMDQyMDU3NTRaMGAxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMR0wGwYDVQQKDBRBdXRobGV0ZSBUZXN0IENsaWVudDEdMBsGA1UEAwwUQXV0aGxldGUgVGVzdCBDbGllbnQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDEWwl/Q+nuL8KXbObpVzww1VkHwLF4W9QxrPI1V0Uh6V9rxUjrfSbtWNEQVDwQmoW8M1XjnRnGvdNRd0m6gNEQLKsqRN2xIvPdR0IO+2b+y7WJ9XlwdqHAFSWQJtoHzBAmkRirRMJrQSW5sB/NIBmyVqUdTV/FghNjc+IiPF4X1kxwwOzm7y2zlHZUpiPQknwPbWNeyunj/XQRrqWPg+RXzAKIjbVprxGaT8CexKu6oEaed8BCTO0rJIOkmjXZMl+SDhXQn9GHKFh60UlJddxVngxhX63MAQ1GsO8HsjrLgO3q4LmTDVHkprLy/wgBRDfo0IHb3gWhbOuRGMLLMKKvAgMBAAGjUDBOMB0GA1UdDgQWBBRuwpA4lqWaOkwmPcTQR8CH0Iv3vjAfBgNVHSMEGDAWgBRuwpA4lqWaOkwmPcTQR8CH0Iv3vjAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQBiCmvQmmKqI/8sB312HTEFlvtpbYp429eNCGXWloOOqVQkJaBnvy9YUS/wCgusyKeMBgbgpV0s8bp/gEW2/MnlWW9+fbFuhzRRwvuV/7je1Avv9Y06RH8GKJYwk2j6qcO7Mn9kVhlnlKxGdFxm/i0OBuZnUe/KDxKPjVEdUJbxAFfxdq4cUjfewMuoxsYruIDnLXjTBcj2PbJ6vcPzq/6TYwxRmnrXIAO6Nxe8ZNXn2x2+njwrUKW4WPQ7u3dyHlD+M3iTpm3TwSgg0FSYiBcXhWJLQCJVEb0kbKJ/PDmcvomusQWTL/0epS62azWG8PUUs4v9XeaemAbHqPGh+5Bo",
  "key": "MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDEWwl/Q+nuL8KXbObpVzww1VkHwLF4W9QxrPI1V0Uh6V9rxUjrfSbtWNEQVDwQmoW8M1XjnRnGvdNRd0m6gNEQLKsqRN2xIvPdR0IO+2b+y7WJ9XlwdqHAFSWQJtoHzBAmkRirRMJrQSW5sB/NIBmyVqUdTV/FghNjc+IiPF4X1kxwwOzm7y2zlHZUpiPQknwPbWNeyunj/XQRrqWPg+RXzAKIjbVprxGaT8CexKu6oEaed8BCTO0rJIOkmjXZMl+SDhXQn9GHKFh60UlJddxVngxhX63MAQ1GsO8HsjrLgO3q4LmTDVHkprLy/wgBRDfo0IHb3gWhbOuRGMLLMKKvAgMBAAECggEAJ3uOy1JipYxg+oXhYKYz6jXcMxziEquUXXDDO0qTEiCVGVyQLxn5S9yCHWByu3v2zEMeUCh02GuvJEBySNhCMZhpypQSZ935X1NGyzBuI2ne1SDRDHYuTCt0ZCoLyWmVDcw7Q6UN2vc8mLv7iQmdYSjfBqdaTKK9N1BD9lJhMTWBjxQDaF1yEZQfR1HOVVddJXt8ILOOltuxhu4EuBKsT8ZlCAN5kGx6+FzXlGlSYjWnGoYbERESeDim3JDwGOGX2msPGOmSzF24LnXrPg8IcrwEbzlFRIEzd8yUVA6VNca71uzv/MaOX5+cTtDiAoVdfrk1Ykt1SNNccGKnC7L3MQKBgQD29FIhT21DkUnXlABKj0N9dBSQyQ1HzILmY/YSg7aeBAlatEzCDxHtFaS89wXxosz2vNd1QKIrLrAgSzTLyemi2KVcvsHyo0g0drSq3NlOw5Rz4WRAZNgBcuhFJ8ZD1BJCisdQxQyCRJ3I0pf/D7mGkmovII1WSk/MIEWWvd3P6wKBgQDLjEEOaTeopbnqkJrcL4UbV2GmVAIa9EXSqzRTrPlxVA62n8EEX5YLXTx6yrvWHWtlA4VgRmUGuu1km5DqlnVdVz/l8fSk2HFcdycJgKd189v/tQ+BLu50+1+uaHiWLXo3VEXgv5QKSgPxWEnNPRVbgqOhav2MaACKo9sl3h4LTQKBgQCjyIxD7VKREmW/5TeAO53OMVOGZuE48ikKtdc4lkRibljp4FRcC/SeodEdRlOZ25hGOB5JdHFZZGCJOneshKBAUaDybs1gp+w2Z1gRTeGNvGbTp/N+RaOA6n2jh+qVh6wIl9Py/Iz8RJfE3e7SydIIr0hfMx6p0SU1Q14DyK64uwKBgQCiqM5ESejkqKtNu4lFc+QW2Vl7pZ6ZE6PImnASfiRIYDfx0PBaIlixdCyko+Y/UPtFme635QlOu4qB35+LF/lqQhMaGqS6Jw1QKxfTDDDGnb2tNm/ReEOu0ELCCVJ0EJueI4ZD+FTBdCx6bWdsz+eFXXyNvgYoceQc5px2Qm4X8QKBgHwpmIeHCvU9Erb9X5pY5JR609Ei+a9jksoe0ch7ocZi2NoE3vwjUSZFe/hTkvpf0gUhw1Zmekqhm78Qb4H7Aq7RDbpyCvoRXGS4GulFXM9Tkfe5FejhawT6fG12KLHOSAkJNgdFCPvFOaHlxPoAaBcf1sY/flehjWEwkVDSh0Js"
}
2021-02-10 09:54:20 RESPONSE
CallBackchannelAuthenticationEndpoint
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "date": "Wed, 10 Feb 2021 09:54:20 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003dloNTjUMGxO4FYkmHcvpNX8;Path\u003d/;Secure;HttpOnly;SameSite\u003dNone",
  "transfer-encoding": "chunked"
}
response_body
{"auth_req_id":"d-gTNt1vl6wzcDYb_b_fMDstqTC5rgBgI63Ecir45ISgP9nIqF6jj1fqag","interval":3,"expires_in":120}
2021-02-10 09:54:20
CallBackchannelAuthenticationEndpoint
Backchannel Authentication endpoint response
backchannel_authentication_endpoint_response
{"auth_req_id":"d-gTNt1vl6wzcDYb_b_fMDstqTC5rgBgI63Ecir45ISgP9nIqF6jj1fqag","interval":3,"expires_in":120}
2021-02-10 09:54:20 SUCCESS
CallBackchannelAuthenticationEndpoint
Parsed backchannel authentication endpoint response
auth_req_id
d-gTNt1vl6wzcDYb_b_fMDstqTC5rgBgI63Ecir45ISgP9nIqF6jj1fqag
interval
3
expires_in
120
2021-02-10 09:54:20 SUCCESS
CheckBackchannelAuthenticationEndpointHttpStatus200
Backchannel authentication endpoint http status code was 200
2021-02-10 09:54:20 SUCCESS
CheckBackchannelAuthenticationEndpointContentType
Backchannel authentication endpoint Content-Type: header is application/json
2021-02-10 09:54:20 SUCCESS
CheckIfBackchannelAuthenticationEndpointResponseError
No error from Backchannel authentication endpoint
2021-02-10 09:54:20 SUCCESS
ValidateAuthenticationRequestId
auth_req_id passed all validation checks
2021-02-10 09:54:20 SUCCESS
EnsureMinimumAuthenticationRequestIdLength
auth_req_id is of sufficient length
actual
464
required
128
2021-02-10 09:54:20 SUCCESS
EnsureMinimumAuthenticationRequestIdEntropy
Calculated shannon entropy seems sufficient
actual
291.88859473647193
expected
96.0
2021-02-10 09:54:20 SUCCESS
EnsureRecommendedAuthenticationRequestIdEntropy
Calculated entropy
actual
291.88859473647193
recommended
160.0
2021-02-10 09:54:20 SUCCESS
ValidateAuthenticationRequestIdExpiresIn
expires_in passed all validation checks
expires_in
120
2021-02-10 09:54:20 SUCCESS
ValidateAuthenticationRequestIdInterval
interval passed all validation checks
interval
3
Call token endpoint expecting pending
2021-02-10 09:54:20 SUCCESS
CreateTokenEndpointRequestForCIBAGrant
grant_type
urn:openid:params:grant-type:ciba
2021-02-10 09:54:20
AddAuthReqIdToTokenEndpointRequest
grant_type
urn:openid:params:grant-type:ciba
auth_req_id
d-gTNt1vl6wzcDYb_b_fMDstqTC5rgBgI63Ecir45ISgP9nIqF6jj1fqag
2021-02-10 09:54:20 SUCCESS
CreateClientAuthenticationAssertionClaims
Created client assertion claims
iss
conformance3ping
sub
conformance3ping
aud
https://emea-conformance.ping-eng.com:9032/as/token.oauth2
jti
bi1UAS3djldWtN5kYhJj
iat
1612950860
exp
1612950920
2021-02-10 09:54:20 SUCCESS
SignClientAuthenticationAssertion
Signed the client assertion
client_assertion
eyJraWQiOiIySEt5ejJVYzRGOGhSY3d5dVBnQTVFZ19zYWxuRWU3cGZ1alVrdmoyeWV3IiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTNwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTNwaW5nIiwiZXhwIjoxNjEyOTUwOTIwLCJpYXQiOjE2MTI5NTA4NjAsImp0aSI6ImJpMVVBUzNkamxkV3RONWtZaEpqIn0.O6Gpj6rQlzfRbvX-gi1VscQi24EXrEawqwqRfmy3Ap2WJP1w4Fv_Zeq8RaY7DXAmDmBBRS3i3kFtpfEgR4YBEQ
2021-02-10 09:54:20
AddClientAssertionToTokenEndpointRequest
Added client assertion
grant_type
urn:openid:params:grant-type:ciba
auth_req_id
d-gTNt1vl6wzcDYb_b_fMDstqTC5rgBgI63Ecir45ISgP9nIqF6jj1fqag
client_assertion
eyJraWQiOiIySEt5ejJVYzRGOGhSY3d5dVBnQTVFZ19zYWxuRWU3cGZ1alVrdmoyeWV3IiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTNwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTNwaW5nIiwiZXhwIjoxNjEyOTUwOTIwLCJpYXQiOjE2MTI5NTA4NjAsImp0aSI6ImJpMVVBUzNkamxkV3RONWtZaEpqIn0.O6Gpj6rQlzfRbvX-gi1VscQi24EXrEawqwqRfmy3Ap2WJP1w4Fv_Zeq8RaY7DXAmDmBBRS3i3kFtpfEgR4YBEQ
client_assertion_type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-02-10 09:54:20
CallTokenEndpointAndReturnFullResponse
HTTP request
request_uri
https://emea-conformance.ping-eng.com:9032/as/token.oauth2
request_method
POST
request_headers
{
  "accept": "application/json;charset\u003dUTF-8",
  "accept-charset": "utf-8",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "653"
}
request_body
grant_type=urn%3Aopenid%3Aparams%3Agrant-type%3Aciba&auth_req_id=d-gTNt1vl6wzcDYb_b_fMDstqTC5rgBgI63Ecir45ISgP9nIqF6jj1fqag&client_assertion=eyJraWQiOiIySEt5ejJVYzRGOGhSY3d5dVBnQTVFZ19zYWxuRWU3cGZ1alVrdmoyeWV3IiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTNwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTNwaW5nIiwiZXhwIjoxNjEyOTUwOTIwLCJpYXQiOjE2MTI5NTA4NjAsImp0aSI6ImJpMVVBUzNkamxkV3RONWtZaEpqIn0.O6Gpj6rQlzfRbvX-gi1VscQi24EXrEawqwqRfmy3Ap2WJP1w4Fv_Zeq8RaY7DXAmDmBBRS3i3kFtpfEgR4YBEQ&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
request_mutual_tls
{
  "cert": "MIIDlTCCAn2gAwIBAgIJAKRJoaX7BlZbMA0GCSqGSIb3DQEBCwUAMGAxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMR0wGwYDVQQKDBRBdXRobGV0ZSBUZXN0IENsaWVudDEdMBsGA1UEAwwUQXV0aGxldGUgVGVzdCBDbGllbnQwIBcNMTgwNTI1MjA1NzU0WhgPMjEwNjAxMDQyMDU3NTRaMGAxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMR0wGwYDVQQKDBRBdXRobGV0ZSBUZXN0IENsaWVudDEdMBsGA1UEAwwUQXV0aGxldGUgVGVzdCBDbGllbnQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDEWwl/Q+nuL8KXbObpVzww1VkHwLF4W9QxrPI1V0Uh6V9rxUjrfSbtWNEQVDwQmoW8M1XjnRnGvdNRd0m6gNEQLKsqRN2xIvPdR0IO+2b+y7WJ9XlwdqHAFSWQJtoHzBAmkRirRMJrQSW5sB/NIBmyVqUdTV/FghNjc+IiPF4X1kxwwOzm7y2zlHZUpiPQknwPbWNeyunj/XQRrqWPg+RXzAKIjbVprxGaT8CexKu6oEaed8BCTO0rJIOkmjXZMl+SDhXQn9GHKFh60UlJddxVngxhX63MAQ1GsO8HsjrLgO3q4LmTDVHkprLy/wgBRDfo0IHb3gWhbOuRGMLLMKKvAgMBAAGjUDBOMB0GA1UdDgQWBBRuwpA4lqWaOkwmPcTQR8CH0Iv3vjAfBgNVHSMEGDAWgBRuwpA4lqWaOkwmPcTQR8CH0Iv3vjAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQBiCmvQmmKqI/8sB312HTEFlvtpbYp429eNCGXWloOOqVQkJaBnvy9YUS/wCgusyKeMBgbgpV0s8bp/gEW2/MnlWW9+fbFuhzRRwvuV/7je1Avv9Y06RH8GKJYwk2j6qcO7Mn9kVhlnlKxGdFxm/i0OBuZnUe/KDxKPjVEdUJbxAFfxdq4cUjfewMuoxsYruIDnLXjTBcj2PbJ6vcPzq/6TYwxRmnrXIAO6Nxe8ZNXn2x2+njwrUKW4WPQ7u3dyHlD+M3iTpm3TwSgg0FSYiBcXhWJLQCJVEb0kbKJ/PDmcvomusQWTL/0epS62azWG8PUUs4v9XeaemAbHqPGh+5Bo",
  "key": "MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDEWwl/Q+nuL8KXbObpVzww1VkHwLF4W9QxrPI1V0Uh6V9rxUjrfSbtWNEQVDwQmoW8M1XjnRnGvdNRd0m6gNEQLKsqRN2xIvPdR0IO+2b+y7WJ9XlwdqHAFSWQJtoHzBAmkRirRMJrQSW5sB/NIBmyVqUdTV/FghNjc+IiPF4X1kxwwOzm7y2zlHZUpiPQknwPbWNeyunj/XQRrqWPg+RXzAKIjbVprxGaT8CexKu6oEaed8BCTO0rJIOkmjXZMl+SDhXQn9GHKFh60UlJddxVngxhX63MAQ1GsO8HsjrLgO3q4LmTDVHkprLy/wgBRDfo0IHb3gWhbOuRGMLLMKKvAgMBAAECggEAJ3uOy1JipYxg+oXhYKYz6jXcMxziEquUXXDDO0qTEiCVGVyQLxn5S9yCHWByu3v2zEMeUCh02GuvJEBySNhCMZhpypQSZ935X1NGyzBuI2ne1SDRDHYuTCt0ZCoLyWmVDcw7Q6UN2vc8mLv7iQmdYSjfBqdaTKK9N1BD9lJhMTWBjxQDaF1yEZQfR1HOVVddJXt8ILOOltuxhu4EuBKsT8ZlCAN5kGx6+FzXlGlSYjWnGoYbERESeDim3JDwGOGX2msPGOmSzF24LnXrPg8IcrwEbzlFRIEzd8yUVA6VNca71uzv/MaOX5+cTtDiAoVdfrk1Ykt1SNNccGKnC7L3MQKBgQD29FIhT21DkUnXlABKj0N9dBSQyQ1HzILmY/YSg7aeBAlatEzCDxHtFaS89wXxosz2vNd1QKIrLrAgSzTLyemi2KVcvsHyo0g0drSq3NlOw5Rz4WRAZNgBcuhFJ8ZD1BJCisdQxQyCRJ3I0pf/D7mGkmovII1WSk/MIEWWvd3P6wKBgQDLjEEOaTeopbnqkJrcL4UbV2GmVAIa9EXSqzRTrPlxVA62n8EEX5YLXTx6yrvWHWtlA4VgRmUGuu1km5DqlnVdVz/l8fSk2HFcdycJgKd189v/tQ+BLu50+1+uaHiWLXo3VEXgv5QKSgPxWEnNPRVbgqOhav2MaACKo9sl3h4LTQKBgQCjyIxD7VKREmW/5TeAO53OMVOGZuE48ikKtdc4lkRibljp4FRcC/SeodEdRlOZ25hGOB5JdHFZZGCJOneshKBAUaDybs1gp+w2Z1gRTeGNvGbTp/N+RaOA6n2jh+qVh6wIl9Py/Iz8RJfE3e7SydIIr0hfMx6p0SU1Q14DyK64uwKBgQCiqM5ESejkqKtNu4lFc+QW2Vl7pZ6ZE6PImnASfiRIYDfx0PBaIlixdCyko+Y/UPtFme635QlOu4qB35+LF/lqQhMaGqS6Jw1QKxfTDDDGnb2tNm/ReEOu0ELCCVJ0EJueI4ZD+FTBdCx6bWdsz+eFXXyNvgYoceQc5px2Qm4X8QKBgHwpmIeHCvU9Erb9X5pY5JR609Ei+a9jksoe0ch7ocZi2NoE3vwjUSZFe/hTkvpf0gUhw1Zmekqhm78Qb4H7Aq7RDbpyCvoRXGS4GulFXM9Tkfe5FejhawT6fG12KLHOSAkJNgdFCPvFOaHlxPoAaBcf1sY/flehjWEwkVDSh0Js"
}
2021-02-10 09:54:21 RESPONSE
CallTokenEndpointAndReturnFullResponse
HTTP response
response_status_code
400 BAD_REQUEST
response_status_text
Bad Request
response_headers
{
  "date": "Wed, 10 Feb 2021 09:54:21 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003dbt2HvwN5PER0KlKXgRfJgG;Path\u003d/;Secure;HttpOnly;SameSite\u003dNone",
  "transfer-encoding": "chunked"
}
response_body
{"error_description":"Pending user authorization","error":"authorization_pending"}
2021-02-10 09:54:21 SUCCESS
CallTokenEndpointAndReturnFullResponse
Parsed token endpoint response
error_description
Pending user authorization
error
authorization_pending
2021-02-10 09:54:21 SUCCESS
CheckTokenEndpointReturnedJsonContentType
token_endpoint_response_headers Content-Type: header is application/json
Verify token endpoint response is pending or slow_down
2021-02-10 09:54:21 SUCCESS
CheckTokenEndpointHttpStatus400
Token endpoint http status code was 400
2021-02-10 09:54:21 SUCCESS
ValidateErrorFromTokenEndpointResponseError
Token endpoint response error returned valid 'error' field
error
authorization_pending
2021-02-10 09:54:21 SUCCESS
CheckErrorDescriptionFromTokenEndpointResponseErrorContainsCRLFTAB
token_endpoint_response 'error_description' field does not include CR/LF/TAB
error_description
Pending user authorization
2021-02-10 09:54:21 SUCCESS
ValidateErrorDescriptionFromTokenEndpointResponseError
token_endpoint_response error returned valid 'error_description' field
error_description
Pending user authorization
2021-02-10 09:54:21 SUCCESS
ValidateErrorUriFromTokenEndpointResponseError
token_endpoint_response did not include optional 'error_uri' field
2021-02-10 09:54:21 SUCCESS
EnsureErrorTokenEndpointSlowdownOrAuthorizationPending
error met 'slow_down' or 'authorization_pending'
error
authorization_pending
Call token endpoint expecting pending (second time)
2021-02-10 09:54:26 SUCCESS
CreateTokenEndpointRequestForCIBAGrant
grant_type
urn:openid:params:grant-type:ciba
2021-02-10 09:54:26
AddAuthReqIdToTokenEndpointRequest
grant_type
urn:openid:params:grant-type:ciba
auth_req_id
d-gTNt1vl6wzcDYb_b_fMDstqTC5rgBgI63Ecir45ISgP9nIqF6jj1fqag
2021-02-10 09:54:26 SUCCESS
CreateClientAuthenticationAssertionClaims
Created client assertion claims
iss
conformance3ping
sub
conformance3ping
aud
https://emea-conformance.ping-eng.com:9032/as/token.oauth2
jti
eAWzpsWgh37Ujf1nDTcd
iat
1612950866
exp
1612950926
2021-02-10 09:54:26 SUCCESS
SignClientAuthenticationAssertion
Signed the client assertion
client_assertion
eyJraWQiOiIySEt5ejJVYzRGOGhSY3d5dVBnQTVFZ19zYWxuRWU3cGZ1alVrdmoyeWV3IiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTNwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTNwaW5nIiwiZXhwIjoxNjEyOTUwOTI2LCJpYXQiOjE2MTI5NTA4NjYsImp0aSI6ImVBV3pwc1dnaDM3VWpmMW5EVGNkIn0.PPaemOPMBsO4pHpUIlAj1I5_MQG_buUIkV_QqSfVhvTwJtg7fI5b8hdIVeXjrox8RktmbLZjoSKG4FSvr2_2iA
2021-02-10 09:54:26
AddClientAssertionToTokenEndpointRequest
Added client assertion
grant_type
urn:openid:params:grant-type:ciba
auth_req_id
d-gTNt1vl6wzcDYb_b_fMDstqTC5rgBgI63Ecir45ISgP9nIqF6jj1fqag
client_assertion
eyJraWQiOiIySEt5ejJVYzRGOGhSY3d5dVBnQTVFZ19zYWxuRWU3cGZ1alVrdmoyeWV3IiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTNwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTNwaW5nIiwiZXhwIjoxNjEyOTUwOTI2LCJpYXQiOjE2MTI5NTA4NjYsImp0aSI6ImVBV3pwc1dnaDM3VWpmMW5EVGNkIn0.PPaemOPMBsO4pHpUIlAj1I5_MQG_buUIkV_QqSfVhvTwJtg7fI5b8hdIVeXjrox8RktmbLZjoSKG4FSvr2_2iA
client_assertion_type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-02-10 09:54:26
CallTokenEndpointAndReturnFullResponse
HTTP request
request_uri
https://emea-conformance.ping-eng.com:9032/as/token.oauth2
request_method
POST
request_headers
{
  "accept": "application/json;charset\u003dUTF-8",
  "accept-charset": "utf-8",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "653"
}
request_body
grant_type=urn%3Aopenid%3Aparams%3Agrant-type%3Aciba&auth_req_id=d-gTNt1vl6wzcDYb_b_fMDstqTC5rgBgI63Ecir45ISgP9nIqF6jj1fqag&client_assertion=eyJraWQiOiIySEt5ejJVYzRGOGhSY3d5dVBnQTVFZ19zYWxuRWU3cGZ1alVrdmoyeWV3IiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTNwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTNwaW5nIiwiZXhwIjoxNjEyOTUwOTI2LCJpYXQiOjE2MTI5NTA4NjYsImp0aSI6ImVBV3pwc1dnaDM3VWpmMW5EVGNkIn0.PPaemOPMBsO4pHpUIlAj1I5_MQG_buUIkV_QqSfVhvTwJtg7fI5b8hdIVeXjrox8RktmbLZjoSKG4FSvr2_2iA&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
request_mutual_tls
{
  "cert": "MIIDlTCCAn2gAwIBAgIJAKRJoaX7BlZbMA0GCSqGSIb3DQEBCwUAMGAxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMR0wGwYDVQQKDBRBdXRobGV0ZSBUZXN0IENsaWVudDEdMBsGA1UEAwwUQXV0aGxldGUgVGVzdCBDbGllbnQwIBcNMTgwNTI1MjA1NzU0WhgPMjEwNjAxMDQyMDU3NTRaMGAxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMR0wGwYDVQQKDBRBdXRobGV0ZSBUZXN0IENsaWVudDEdMBsGA1UEAwwUQXV0aGxldGUgVGVzdCBDbGllbnQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDEWwl/Q+nuL8KXbObpVzww1VkHwLF4W9QxrPI1V0Uh6V9rxUjrfSbtWNEQVDwQmoW8M1XjnRnGvdNRd0m6gNEQLKsqRN2xIvPdR0IO+2b+y7WJ9XlwdqHAFSWQJtoHzBAmkRirRMJrQSW5sB/NIBmyVqUdTV/FghNjc+IiPF4X1kxwwOzm7y2zlHZUpiPQknwPbWNeyunj/XQRrqWPg+RXzAKIjbVprxGaT8CexKu6oEaed8BCTO0rJIOkmjXZMl+SDhXQn9GHKFh60UlJddxVngxhX63MAQ1GsO8HsjrLgO3q4LmTDVHkprLy/wgBRDfo0IHb3gWhbOuRGMLLMKKvAgMBAAGjUDBOMB0GA1UdDgQWBBRuwpA4lqWaOkwmPcTQR8CH0Iv3vjAfBgNVHSMEGDAWgBRuwpA4lqWaOkwmPcTQR8CH0Iv3vjAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQBiCmvQmmKqI/8sB312HTEFlvtpbYp429eNCGXWloOOqVQkJaBnvy9YUS/wCgusyKeMBgbgpV0s8bp/gEW2/MnlWW9+fbFuhzRRwvuV/7je1Avv9Y06RH8GKJYwk2j6qcO7Mn9kVhlnlKxGdFxm/i0OBuZnUe/KDxKPjVEdUJbxAFfxdq4cUjfewMuoxsYruIDnLXjTBcj2PbJ6vcPzq/6TYwxRmnrXIAO6Nxe8ZNXn2x2+njwrUKW4WPQ7u3dyHlD+M3iTpm3TwSgg0FSYiBcXhWJLQCJVEb0kbKJ/PDmcvomusQWTL/0epS62azWG8PUUs4v9XeaemAbHqPGh+5Bo",
  "key": "MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDEWwl/Q+nuL8KXbObpVzww1VkHwLF4W9QxrPI1V0Uh6V9rxUjrfSbtWNEQVDwQmoW8M1XjnRnGvdNRd0m6gNEQLKsqRN2xIvPdR0IO+2b+y7WJ9XlwdqHAFSWQJtoHzBAmkRirRMJrQSW5sB/NIBmyVqUdTV/FghNjc+IiPF4X1kxwwOzm7y2zlHZUpiPQknwPbWNeyunj/XQRrqWPg+RXzAKIjbVprxGaT8CexKu6oEaed8BCTO0rJIOkmjXZMl+SDhXQn9GHKFh60UlJddxVngxhX63MAQ1GsO8HsjrLgO3q4LmTDVHkprLy/wgBRDfo0IHb3gWhbOuRGMLLMKKvAgMBAAECggEAJ3uOy1JipYxg+oXhYKYz6jXcMxziEquUXXDDO0qTEiCVGVyQLxn5S9yCHWByu3v2zEMeUCh02GuvJEBySNhCMZhpypQSZ935X1NGyzBuI2ne1SDRDHYuTCt0ZCoLyWmVDcw7Q6UN2vc8mLv7iQmdYSjfBqdaTKK9N1BD9lJhMTWBjxQDaF1yEZQfR1HOVVddJXt8ILOOltuxhu4EuBKsT8ZlCAN5kGx6+FzXlGlSYjWnGoYbERESeDim3JDwGOGX2msPGOmSzF24LnXrPg8IcrwEbzlFRIEzd8yUVA6VNca71uzv/MaOX5+cTtDiAoVdfrk1Ykt1SNNccGKnC7L3MQKBgQD29FIhT21DkUnXlABKj0N9dBSQyQ1HzILmY/YSg7aeBAlatEzCDxHtFaS89wXxosz2vNd1QKIrLrAgSzTLyemi2KVcvsHyo0g0drSq3NlOw5Rz4WRAZNgBcuhFJ8ZD1BJCisdQxQyCRJ3I0pf/D7mGkmovII1WSk/MIEWWvd3P6wKBgQDLjEEOaTeopbnqkJrcL4UbV2GmVAIa9EXSqzRTrPlxVA62n8EEX5YLXTx6yrvWHWtlA4VgRmUGuu1km5DqlnVdVz/l8fSk2HFcdycJgKd189v/tQ+BLu50+1+uaHiWLXo3VEXgv5QKSgPxWEnNPRVbgqOhav2MaACKo9sl3h4LTQKBgQCjyIxD7VKREmW/5TeAO53OMVOGZuE48ikKtdc4lkRibljp4FRcC/SeodEdRlOZ25hGOB5JdHFZZGCJOneshKBAUaDybs1gp+w2Z1gRTeGNvGbTp/N+RaOA6n2jh+qVh6wIl9Py/Iz8RJfE3e7SydIIr0hfMx6p0SU1Q14DyK64uwKBgQCiqM5ESejkqKtNu4lFc+QW2Vl7pZ6ZE6PImnASfiRIYDfx0PBaIlixdCyko+Y/UPtFme635QlOu4qB35+LF/lqQhMaGqS6Jw1QKxfTDDDGnb2tNm/ReEOu0ELCCVJ0EJueI4ZD+FTBdCx6bWdsz+eFXXyNvgYoceQc5px2Qm4X8QKBgHwpmIeHCvU9Erb9X5pY5JR609Ei+a9jksoe0ch7ocZi2NoE3vwjUSZFe/hTkvpf0gUhw1Zmekqhm78Qb4H7Aq7RDbpyCvoRXGS4GulFXM9Tkfe5FejhawT6fG12KLHOSAkJNgdFCPvFOaHlxPoAaBcf1sY/flehjWEwkVDSh0Js"
}
2021-02-10 09:54:26 RESPONSE
CallTokenEndpointAndReturnFullResponse
HTTP response
response_status_code
400 BAD_REQUEST
response_status_text
Bad Request
response_headers
{
  "date": "Wed, 10 Feb 2021 09:54:26 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003dwLk5ByjWgX0A01pLJI4nwl;Path\u003d/;Secure;HttpOnly;SameSite\u003dNone",
  "transfer-encoding": "chunked"
}
response_body
{"error_description":"Pending user authorization","error":"authorization_pending"}
2021-02-10 09:54:26 SUCCESS
CallTokenEndpointAndReturnFullResponse
Parsed token endpoint response
error_description
Pending user authorization
error
authorization_pending
2021-02-10 09:54:26 SUCCESS
CheckTokenEndpointReturnedJsonContentType
token_endpoint_response_headers Content-Type: header is application/json
Verify token endpoint response is pending or slow_down
2021-02-10 09:54:26 SUCCESS
CheckTokenEndpointHttpStatus400
Token endpoint http status code was 400
2021-02-10 09:54:26 SUCCESS
ValidateErrorFromTokenEndpointResponseError
Token endpoint response error returned valid 'error' field
error
authorization_pending
2021-02-10 09:54:26 SUCCESS
CheckErrorDescriptionFromTokenEndpointResponseErrorContainsCRLFTAB
token_endpoint_response 'error_description' field does not include CR/LF/TAB
error_description
Pending user authorization
2021-02-10 09:54:26 SUCCESS
ValidateErrorDescriptionFromTokenEndpointResponseError
token_endpoint_response error returned valid 'error_description' field
error_description
Pending user authorization
2021-02-10 09:54:26 SUCCESS
ValidateErrorUriFromTokenEndpointResponseError
token_endpoint_response did not include optional 'error_uri' field
2021-02-10 09:54:26 SUCCESS
EnsureErrorTokenEndpointSlowdownOrAuthorizationPending
error met 'slow_down' or 'authorization_pending'
error
authorization_pending
2021-02-10 09:54:26
CallAutomatedCibaApprovalEndpoint
If your server supports automated testing, you can set 'automated_ciba_approval_url' in your configuration to a url like https://cibasim.example.com/action?token={auth_req_id}&type={action} (auth_req_id will be automatically substituted for the current auth_req_id by the conformance suite, action will be allow or deny depending on the test)
2021-02-10 09:54:26
TellUserToDoCIBAAuthentication
Please authenticate and authorize the request
2021-02-10 09:54:29 INCOMING
fapi-ciba-id1-refresh-token
Incoming HTTP request to test instance HgQnndsopXRfcwQ
incoming_headers
{
  "host": "www.certification.openid.net",
  "authorization": "Bearer xd0zex65C_9+q4L4hvHU\u003d",
  "content-type": "application/json; charset\u003dUTF-8",
  "user-agent": "PingFederate",
  "accept-encoding": "gzip,deflate",
  "x-ssl-cipher": "ECDHE-RSA-AES256-GCM-SHA384",
  "x-ssl-protocol": "TLSv1.2",
  "content-length": "76",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net",
  "connection": "close"
}
incoming_path
ciba-notification-endpoint
incoming_body_form_params
incoming_method
POST
incoming_body_json
{
  "auth_req_id": "d-gTNt1vl6wzcDYb_b_fMDstqTC5rgBgI63Ecir45ISgP9nIqF6jj1fqag"
}
incoming_query_string_params
{}
incoming_body
{"auth_req_id":"d-gTNt1vl6wzcDYb_b_fMDstqTC5rgBgI63Ecir45ISgP9nIqF6jj1fqag"}
2021-02-10 09:54:29 OUTGOING
fapi-ciba-id1-refresh-token
Response to HTTP request to test instance HgQnndsopXRfcwQ
outgoing_status_code
204
outgoing_headers
{}
outgoing_body

                                
outgoing_path
ciba-notification-endpoint
Verify notification callback
2021-02-10 09:54:29 SUCCESS
EnsureIncomingTls12
Found TLS 1.2 connection
2021-02-10 09:54:29 SUCCESS
EnsureIncomingTlsSecureCipher
TLS cipher is allowed
actual
ECDHE-RSA-AES256-GCM-SHA384
expected
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-02-10 09:54:29 SUCCESS
CheckIncomingContentTypeIsApplicationJson
Incoming request Content-Type: header has the expected value
content_type
application/json; charset=UTF-8
expected
application/json
2021-02-10 09:54:29 SUCCESS
VerifyBearerTokenHeaderCallback
'Authorization' header in notification callback contained client_notification_token.
2021-02-10 09:54:29
CheckAuthReqIdInCallback
notification_callback contents
headers
{
  "host": "www.certification.openid.net",
  "authorization": "Bearer xd0zex65C_9+q4L4hvHU\u003d",
  "content-type": "application/json; charset\u003dUTF-8",
  "user-agent": "PingFederate",
  "accept-encoding": "gzip,deflate",
  "x-ssl-cipher": "ECDHE-RSA-AES256-GCM-SHA384",
  "x-ssl-protocol": "TLSv1.2",
  "content-length": "76",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net",
  "connection": "close"
}
query_string_params
{}
method
POST
body
{"auth_req_id":"d-gTNt1vl6wzcDYb_b_fMDstqTC5rgBgI63Ecir45ISgP9nIqF6jj1fqag"}
body_json
{
  "auth_req_id": "d-gTNt1vl6wzcDYb_b_fMDstqTC5rgBgI63Ecir45ISgP9nIqF6jj1fqag"
}
2021-02-10 09:54:29 SUCCESS
CheckAuthReqIdInCallback
auth_req_id valued received in callback is correct
2021-02-10 09:54:29 SUCCESS
CheckNotificationCallbackOnlyAuthReqId
body received in notification callback contained only auth_req_id
body
{
  "auth_req_id": "d-gTNt1vl6wzcDYb_b_fMDstqTC5rgBgI63Ecir45ISgP9nIqF6jj1fqag"
}
Calling token endpoint after ping notification
2021-02-10 09:54:29 SUCCESS
CreateTokenEndpointRequestForCIBAGrant
grant_type
urn:openid:params:grant-type:ciba
2021-02-10 09:54:29
AddAuthReqIdToTokenEndpointRequest
grant_type
urn:openid:params:grant-type:ciba
auth_req_id
d-gTNt1vl6wzcDYb_b_fMDstqTC5rgBgI63Ecir45ISgP9nIqF6jj1fqag
2021-02-10 09:54:29 SUCCESS
CreateClientAuthenticationAssertionClaims
Created client assertion claims
iss
conformance3ping
sub
conformance3ping
aud
https://emea-conformance.ping-eng.com:9032/as/token.oauth2
jti
ZgA2ip4bVhlycFH8Iyvb
iat
1612950869
exp
1612950929
2021-02-10 09:54:29 SUCCESS
SignClientAuthenticationAssertion
Signed the client assertion
client_assertion
eyJraWQiOiIySEt5ejJVYzRGOGhSY3d5dVBnQTVFZ19zYWxuRWU3cGZ1alVrdmoyeWV3IiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTNwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTNwaW5nIiwiZXhwIjoxNjEyOTUwOTI5LCJpYXQiOjE2MTI5NTA4NjksImp0aSI6IlpnQTJpcDRiVmhseWNGSDhJeXZiIn0.bUp7Lhn2_gK3H2XBpwF3UQIpzP7rz6hmrekBX_6chXCfUcOAa_Lkm6Jnxw2FbTF4FGW8zSNLs9GFdCzbZI-qQA
2021-02-10 09:54:29
AddClientAssertionToTokenEndpointRequest
Added client assertion
grant_type
urn:openid:params:grant-type:ciba
auth_req_id
d-gTNt1vl6wzcDYb_b_fMDstqTC5rgBgI63Ecir45ISgP9nIqF6jj1fqag
client_assertion
eyJraWQiOiIySEt5ejJVYzRGOGhSY3d5dVBnQTVFZ19zYWxuRWU3cGZ1alVrdmoyeWV3IiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTNwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTNwaW5nIiwiZXhwIjoxNjEyOTUwOTI5LCJpYXQiOjE2MTI5NTA4NjksImp0aSI6IlpnQTJpcDRiVmhseWNGSDhJeXZiIn0.bUp7Lhn2_gK3H2XBpwF3UQIpzP7rz6hmrekBX_6chXCfUcOAa_Lkm6Jnxw2FbTF4FGW8zSNLs9GFdCzbZI-qQA
client_assertion_type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-02-10 09:54:29
CallTokenEndpointAndReturnFullResponse
HTTP request
request_uri
https://emea-conformance.ping-eng.com:9032/as/token.oauth2
request_method
POST
request_headers
{
  "accept": "application/json;charset\u003dUTF-8",
  "accept-charset": "utf-8",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "653"
}
request_body
grant_type=urn%3Aopenid%3Aparams%3Agrant-type%3Aciba&auth_req_id=d-gTNt1vl6wzcDYb_b_fMDstqTC5rgBgI63Ecir45ISgP9nIqF6jj1fqag&client_assertion=eyJraWQiOiIySEt5ejJVYzRGOGhSY3d5dVBnQTVFZ19zYWxuRWU3cGZ1alVrdmoyeWV3IiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTNwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTNwaW5nIiwiZXhwIjoxNjEyOTUwOTI5LCJpYXQiOjE2MTI5NTA4NjksImp0aSI6IlpnQTJpcDRiVmhseWNGSDhJeXZiIn0.bUp7Lhn2_gK3H2XBpwF3UQIpzP7rz6hmrekBX_6chXCfUcOAa_Lkm6Jnxw2FbTF4FGW8zSNLs9GFdCzbZI-qQA&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
request_mutual_tls
{
  "cert": "MIIDlTCCAn2gAwIBAgIJAKRJoaX7BlZbMA0GCSqGSIb3DQEBCwUAMGAxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMR0wGwYDVQQKDBRBdXRobGV0ZSBUZXN0IENsaWVudDEdMBsGA1UEAwwUQXV0aGxldGUgVGVzdCBDbGllbnQwIBcNMTgwNTI1MjA1NzU0WhgPMjEwNjAxMDQyMDU3NTRaMGAxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMR0wGwYDVQQKDBRBdXRobGV0ZSBUZXN0IENsaWVudDEdMBsGA1UEAwwUQXV0aGxldGUgVGVzdCBDbGllbnQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDEWwl/Q+nuL8KXbObpVzww1VkHwLF4W9QxrPI1V0Uh6V9rxUjrfSbtWNEQVDwQmoW8M1XjnRnGvdNRd0m6gNEQLKsqRN2xIvPdR0IO+2b+y7WJ9XlwdqHAFSWQJtoHzBAmkRirRMJrQSW5sB/NIBmyVqUdTV/FghNjc+IiPF4X1kxwwOzm7y2zlHZUpiPQknwPbWNeyunj/XQRrqWPg+RXzAKIjbVprxGaT8CexKu6oEaed8BCTO0rJIOkmjXZMl+SDhXQn9GHKFh60UlJddxVngxhX63MAQ1GsO8HsjrLgO3q4LmTDVHkprLy/wgBRDfo0IHb3gWhbOuRGMLLMKKvAgMBAAGjUDBOMB0GA1UdDgQWBBRuwpA4lqWaOkwmPcTQR8CH0Iv3vjAfBgNVHSMEGDAWgBRuwpA4lqWaOkwmPcTQR8CH0Iv3vjAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQBiCmvQmmKqI/8sB312HTEFlvtpbYp429eNCGXWloOOqVQkJaBnvy9YUS/wCgusyKeMBgbgpV0s8bp/gEW2/MnlWW9+fbFuhzRRwvuV/7je1Avv9Y06RH8GKJYwk2j6qcO7Mn9kVhlnlKxGdFxm/i0OBuZnUe/KDxKPjVEdUJbxAFfxdq4cUjfewMuoxsYruIDnLXjTBcj2PbJ6vcPzq/6TYwxRmnrXIAO6Nxe8ZNXn2x2+njwrUKW4WPQ7u3dyHlD+M3iTpm3TwSgg0FSYiBcXhWJLQCJVEb0kbKJ/PDmcvomusQWTL/0epS62azWG8PUUs4v9XeaemAbHqPGh+5Bo",
  "key": "MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDEWwl/Q+nuL8KXbObpVzww1VkHwLF4W9QxrPI1V0Uh6V9rxUjrfSbtWNEQVDwQmoW8M1XjnRnGvdNRd0m6gNEQLKsqRN2xIvPdR0IO+2b+y7WJ9XlwdqHAFSWQJtoHzBAmkRirRMJrQSW5sB/NIBmyVqUdTV/FghNjc+IiPF4X1kxwwOzm7y2zlHZUpiPQknwPbWNeyunj/XQRrqWPg+RXzAKIjbVprxGaT8CexKu6oEaed8BCTO0rJIOkmjXZMl+SDhXQn9GHKFh60UlJddxVngxhX63MAQ1GsO8HsjrLgO3q4LmTDVHkprLy/wgBRDfo0IHb3gWhbOuRGMLLMKKvAgMBAAECggEAJ3uOy1JipYxg+oXhYKYz6jXcMxziEquUXXDDO0qTEiCVGVyQLxn5S9yCHWByu3v2zEMeUCh02GuvJEBySNhCMZhpypQSZ935X1NGyzBuI2ne1SDRDHYuTCt0ZCoLyWmVDcw7Q6UN2vc8mLv7iQmdYSjfBqdaTKK9N1BD9lJhMTWBjxQDaF1yEZQfR1HOVVddJXt8ILOOltuxhu4EuBKsT8ZlCAN5kGx6+FzXlGlSYjWnGoYbERESeDim3JDwGOGX2msPGOmSzF24LnXrPg8IcrwEbzlFRIEzd8yUVA6VNca71uzv/MaOX5+cTtDiAoVdfrk1Ykt1SNNccGKnC7L3MQKBgQD29FIhT21DkUnXlABKj0N9dBSQyQ1HzILmY/YSg7aeBAlatEzCDxHtFaS89wXxosz2vNd1QKIrLrAgSzTLyemi2KVcvsHyo0g0drSq3NlOw5Rz4WRAZNgBcuhFJ8ZD1BJCisdQxQyCRJ3I0pf/D7mGkmovII1WSk/MIEWWvd3P6wKBgQDLjEEOaTeopbnqkJrcL4UbV2GmVAIa9EXSqzRTrPlxVA62n8EEX5YLXTx6yrvWHWtlA4VgRmUGuu1km5DqlnVdVz/l8fSk2HFcdycJgKd189v/tQ+BLu50+1+uaHiWLXo3VEXgv5QKSgPxWEnNPRVbgqOhav2MaACKo9sl3h4LTQKBgQCjyIxD7VKREmW/5TeAO53OMVOGZuE48ikKtdc4lkRibljp4FRcC/SeodEdRlOZ25hGOB5JdHFZZGCJOneshKBAUaDybs1gp+w2Z1gRTeGNvGbTp/N+RaOA6n2jh+qVh6wIl9Py/Iz8RJfE3e7SydIIr0hfMx6p0SU1Q14DyK64uwKBgQCiqM5ESejkqKtNu4lFc+QW2Vl7pZ6ZE6PImnASfiRIYDfx0PBaIlixdCyko+Y/UPtFme635QlOu4qB35+LF/lqQhMaGqS6Jw1QKxfTDDDGnb2tNm/ReEOu0ELCCVJ0EJueI4ZD+FTBdCx6bWdsz+eFXXyNvgYoceQc5px2Qm4X8QKBgHwpmIeHCvU9Erb9X5pY5JR609Ei+a9jksoe0ch7ocZi2NoE3vwjUSZFe/hTkvpf0gUhw1Zmekqhm78Qb4H7Aq7RDbpyCvoRXGS4GulFXM9Tkfe5FejhawT6fG12KLHOSAkJNgdFCPvFOaHlxPoAaBcf1sY/flehjWEwkVDSh0Js"
}
2021-02-10 09:54:29 RESPONSE
CallTokenEndpointAndReturnFullResponse
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "date": "Wed, 10 Feb 2021 09:54:29 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003d4gfWSsgoUTTbxTsHxW3txQ;Path\u003d/;Secure;HttpOnly;SameSite\u003dNone",
  "transfer-encoding": "chunked"
}
response_body
{"access_token":"eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2UzcGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiItby0xbGtvSWJjUGFUNHBtd1VlZnFHZDk2VElvUGRkNFAtYVFWbnNnVmJRIn0sImV4cCI6MTYxMjk1ODA2OX0.XMnhqwZSLWrERJIvdl5qkq7AOV4i_NNDCaScSYQqfSzit5xWgkUVhWp60wfmxX6XnZuoGtfM8dFYV6Fakgzen01vw4giTatqIVCQQqqyRhtuqeqABoGfqDX9RIdJEEyxs0xQqj9TxGpiFIC1okEYkPpkfAEE8BdeRwyA8waWrhuIMzx5qrbzt3ZVVRsz29cAYgpK0_wpf-bBrT_SwM4l-w3ZaUfp1yzVvA7GIl3qZ2ERG7umLiSDdQqU9D173-4KqHZCoj9bPGtkIKr9RSqWfe84OUMYVu0dNlK_b3KJgyTXRH3E-Wac-VGWSc0SzR82rD8OgCjNETv67Z7C9z4mnQ","refresh_token":"s5eQ8fZAj61fQre8wnf9PV3N387WnVOlNA40K9HInC","scope":"openid test","id_token":"eyJhbGciOiJFUzI1NiIsImtpZCI6IkhHcDFJRVFNMXZvUVNxNDZJQXZrXzFZUnFhRSJ9.eyJzdWIiOiJwYXRyaWNrIiwiYXVkIjoiY29uZm9ybWFuY2UzcGluZyIsImp0aSI6IkNHYmZWZGtaeGg0M2RwVnQ5VUhmZ3oiLCJpc3MiOiJodHRwczovL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2MTI5NTA4NjksImV4cCI6MTYxMjk1MTE2OX0.Ex0ZA1D5zUw3ACN4bHWzdfw_Gu8IR_R2eTIMwQMaBMVujo611np69V8IVNI6mxlJsvehm3ccUhNMFzOV_eF6dg","token_type":"Bearer","expires_in":7199}
2021-02-10 09:54:29 SUCCESS
CallTokenEndpointAndReturnFullResponse
Parsed token endpoint response
access_token
eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2UzcGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiItby0xbGtvSWJjUGFUNHBtd1VlZnFHZDk2VElvUGRkNFAtYVFWbnNnVmJRIn0sImV4cCI6MTYxMjk1ODA2OX0.XMnhqwZSLWrERJIvdl5qkq7AOV4i_NNDCaScSYQqfSzit5xWgkUVhWp60wfmxX6XnZuoGtfM8dFYV6Fakgzen01vw4giTatqIVCQQqqyRhtuqeqABoGfqDX9RIdJEEyxs0xQqj9TxGpiFIC1okEYkPpkfAEE8BdeRwyA8waWrhuIMzx5qrbzt3ZVVRsz29cAYgpK0_wpf-bBrT_SwM4l-w3ZaUfp1yzVvA7GIl3qZ2ERG7umLiSDdQqU9D173-4KqHZCoj9bPGtkIKr9RSqWfe84OUMYVu0dNlK_b3KJgyTXRH3E-Wac-VGWSc0SzR82rD8OgCjNETv67Z7C9z4mnQ
refresh_token
s5eQ8fZAj61fQre8wnf9PV3N387WnVOlNA40K9HInC
scope
openid test
id_token
eyJhbGciOiJFUzI1NiIsImtpZCI6IkhHcDFJRVFNMXZvUVNxNDZJQXZrXzFZUnFhRSJ9.eyJzdWIiOiJwYXRyaWNrIiwiYXVkIjoiY29uZm9ybWFuY2UzcGluZyIsImp0aSI6IkNHYmZWZGtaeGg0M2RwVnQ5VUhmZ3oiLCJpc3MiOiJodHRwczovL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2MTI5NTA4NjksImV4cCI6MTYxMjk1MTE2OX0.Ex0ZA1D5zUw3ACN4bHWzdfw_Gu8IR_R2eTIMwQMaBMVujo611np69V8IVNI6mxlJsvehm3ccUhNMFzOV_eF6dg
token_type
Bearer
expires_in
7199
2021-02-10 09:54:29 SUCCESS
CheckTokenEndpointReturnedJsonContentType
token_endpoint_response_headers Content-Type: header is application/json
Verify token endpoint response
2021-02-10 09:54:29 SUCCESS
CheckTokenEndpointHttpStatus200
Token endpoint http status code was 200
2021-02-10 09:54:29 SUCCESS
CheckTokenEndpointCacheHeaders
'pragma' and 'cache-control' headers in token endpoint response contain expected values.
cache_control_header
no-cache, no-store
pragma_header
no-cache
2021-02-10 09:54:29 SUCCESS
CheckIfTokenEndpointResponseError
No error from token endpoint
2021-02-10 09:54:29 SUCCESS
CheckForAccessTokenValue
Found an access token
access_token
eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2UzcGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiItby0xbGtvSWJjUGFUNHBtd1VlZnFHZDk2VElvUGRkNFAtYVFWbnNnVmJRIn0sImV4cCI6MTYxMjk1ODA2OX0.XMnhqwZSLWrERJIvdl5qkq7AOV4i_NNDCaScSYQqfSzit5xWgkUVhWp60wfmxX6XnZuoGtfM8dFYV6Fakgzen01vw4giTatqIVCQQqqyRhtuqeqABoGfqDX9RIdJEEyxs0xQqj9TxGpiFIC1okEYkPpkfAEE8BdeRwyA8waWrhuIMzx5qrbzt3ZVVRsz29cAYgpK0_wpf-bBrT_SwM4l-w3ZaUfp1yzVvA7GIl3qZ2ERG7umLiSDdQqU9D173-4KqHZCoj9bPGtkIKr9RSqWfe84OUMYVu0dNlK_b3KJgyTXRH3E-Wac-VGWSc0SzR82rD8OgCjNETv67Z7C9z4mnQ
2021-02-10 09:54:29 SUCCESS
ExtractAccessTokenFromTokenResponse
Extracted the access token
value
eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2UzcGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiItby0xbGtvSWJjUGFUNHBtd1VlZnFHZDk2VElvUGRkNFAtYVFWbnNnVmJRIn0sImV4cCI6MTYxMjk1ODA2OX0.XMnhqwZSLWrERJIvdl5qkq7AOV4i_NNDCaScSYQqfSzit5xWgkUVhWp60wfmxX6XnZuoGtfM8dFYV6Fakgzen01vw4giTatqIVCQQqqyRhtuqeqABoGfqDX9RIdJEEyxs0xQqj9TxGpiFIC1okEYkPpkfAEE8BdeRwyA8waWrhuIMzx5qrbzt3ZVVRsz29cAYgpK0_wpf-bBrT_SwM4l-w3ZaUfp1yzVvA7GIl3qZ2ERG7umLiSDdQqU9D173-4KqHZCoj9bPGtkIKr9RSqWfe84OUMYVu0dNlK_b3KJgyTXRH3E-Wac-VGWSc0SzR82rD8OgCjNETv67Z7C9z4mnQ
type
Bearer
2021-02-10 09:54:29 SUCCESS
ExtractExpiresInFromTokenEndpointResponse
Extracted 'expires_in'
expires_in
7199
2021-02-10 09:54:29 SUCCESS
ValidateExpiresIn
expires_in passed all validation checks
expires_in
7199
2021-02-10 09:54:29 SUCCESS
CheckForRefreshTokenValue
Found a refresh token
refresh_token
s5eQ8fZAj61fQre8wnf9PV3N387WnVOlNA40K9HInC
2021-02-10 09:54:29 SUCCESS
EnsureMinimumRefreshTokenLength
Refresh token is of sufficient length
actual
336
required
128
2021-02-10 09:54:29 SUCCESS
EnsureMinimumRefreshTokenEntropy
Calculated shannon entropy seems sufficient
actual
198.2126692502176
expected
96.0
2021-02-10 09:54:29 SUCCESS
EnsureMinimumAccessTokenLength
Access token is of sufficient length
actual
4824
required
128
2021-02-10 09:54:29 SUCCESS
EnsureMinimumAccessTokenEntropy
Calculated shannon entropy seems sufficient
actual
3549.1697816401506
expected
96.0
2021-02-10 09:54:29 SUCCESS
ExtractIdTokenFromTokenResponse
Found and parsed the id_token from token_endpoint_response
value
eyJhbGciOiJFUzI1NiIsImtpZCI6IkhHcDFJRVFNMXZvUVNxNDZJQXZrXzFZUnFhRSJ9.eyJzdWIiOiJwYXRyaWNrIiwiYXVkIjoiY29uZm9ybWFuY2UzcGluZyIsImp0aSI6IkNHYmZWZGtaeGg0M2RwVnQ5VUhmZ3oiLCJpc3MiOiJodHRwczovL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2MTI5NTA4NjksImV4cCI6MTYxMjk1MTE2OX0.Ex0ZA1D5zUw3ACN4bHWzdfw_Gu8IR_R2eTIMwQMaBMVujo611np69V8IVNI6mxlJsvehm3ccUhNMFzOV_eF6dg
header
{
  "kid": "HGp1IEQM1voQSq46IAvk_1YRqaE",
  "alg": "ES256"
}
claims
{
  "sub": "patrick",
  "aud": "conformance3ping",
  "iss": "https://emea-conformance.ping-eng.com:9031",
  "exp": 1612951169,
  "iat": 1612950869,
  "jti": "CGbfVdkZxh43dpVt9UHfgz"
}
2021-02-10 09:54:29 SUCCESS
ValidateIdToken
ID token iss, aud, exp, iat, auth_time, acr & nbf claims passed validation checks
2021-02-10 09:54:29 SUCCESS
EnsureIdTokenContainsKid
kid was found in the ID token header
kid
HGp1IEQM1voQSq46IAvk_1YRqaE
2021-02-10 09:54:29 SUCCESS
ValidateIdTokenSignature
id_token signature validated
id_token
eyJhbGciOiJFUzI1NiIsImtpZCI6IkhHcDFJRVFNMXZvUVNxNDZJQXZrXzFZUnFhRSJ9.eyJzdWIiOiJwYXRyaWNrIiwiYXVkIjoiY29uZm9ybWFuY2UzcGluZyIsImp0aSI6IkNHYmZWZGtaeGg0M2RwVnQ5VUhmZ3oiLCJpc3MiOiJodHRwczovL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2MTI5NTA4NjksImV4cCI6MTYxMjk1MTE2OX0.Ex0ZA1D5zUw3ACN4bHWzdfw_Gu8IR_R2eTIMwQMaBMVujo611np69V8IVNI6mxlJsvehm3ccUhNMFzOV_eF6dg
2021-02-10 09:54:29 SUCCESS
ValidateIdTokenSignatureUsingKid
id_token signature validated
id_token
eyJhbGciOiJFUzI1NiIsImtpZCI6IkhHcDFJRVFNMXZvUVNxNDZJQXZrXzFZUnFhRSJ9.eyJzdWIiOiJwYXRyaWNrIiwiYXVkIjoiY29uZm9ybWFuY2UzcGluZyIsImp0aSI6IkNHYmZWZGtaeGg0M2RwVnQ5VUhmZ3oiLCJpc3MiOiJodHRwczovL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2MTI5NTA4NjksImV4cCI6MTYxMjk1MTE2OX0.Ex0ZA1D5zUw3ACN4bHWzdfw_Gu8IR_R2eTIMwQMaBMVujo611np69V8IVNI6mxlJsvehm3ccUhNMFzOV_eF6dg
2021-02-10 09:54:29 SUCCESS
CheckForSubjectInIdToken
Found 'sub' in id_token
sub
patrick
2021-02-10 09:54:29 SUCCESS
FAPIValidateIdTokenSigningAlg
id_token was signed with a permitted algorithm
alg
ES256
2021-02-10 09:54:29 INFO
FAPIValidateIdTokenEncryptionAlg
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2021-02-10 09:54:29 INFO
FAPIValidateEncryptedIdTokenHasKid
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2021-02-10 09:54:29 INFO
FAPICIBAValidateIdTokenAuthRequestIdClaims
Skipped evaluation due to missing required element: id_token claims.urn:openid:params:jwt:claim:auth_req_id
path
claims.urn:openid:params:jwt:claim:auth_req_id
mapped
object
id_token
2021-02-10 09:54:29 SUCCESS
ValidateIdTokenNotIncludeCHashAndSHash
id_token claims correctly does not contain 'c_hash' and 's_hash'
claims
{
  "sub": "patrick",
  "aud": "conformance3ping",
  "iss": "https://emea-conformance.ping-eng.com:9031",
  "exp": 1612951169,
  "iat": 1612950869,
  "jti": "CGbfVdkZxh43dpVt9UHfgz"
}
2021-02-10 09:54:29 INFO
ExtractAtHash
Couldn't find at_hash in ID token
2021-02-10 09:54:29 INFO
ExtractRtHash
Couldn't find urn:openid:params:jwt:claim:rt_hash claim in the ID token
2021-02-10 09:54:29 INFO
FAPICIBAValidateRtHash
Skipped evaluation due to missing required object: rt_hash
expected
rt_hash
mapped
2021-02-10 09:54:29 INFO
ValidateAtHash
Skipped evaluation due to missing required object: at_hash
expected
at_hash
mapped
Check for refresh token
2021-02-10 09:54:29 SUCCESS
ExtractRefreshTokenFromTokenResponse
Extracted refresh token from response
refresh_token
s5eQ8fZAj61fQre8wnf9PV3N387WnVOlNA40K9HInC
2021-02-10 09:54:29 SUCCESS
EnsureServerConfigurationSupportsRefreshToken
The server configuration indicates support for refresh tokens
supported_grant_types
[
  "implicit",
  "authorization_code",
  "refresh_token",
  "password",
  "client_credentials",
  "urn:pingidentity.com:oauth2:grant_type:validate_bearer",
  "urn:ietf:params:oauth:grant-type:jwt-bearer",
  "urn:ietf:params:oauth:grant-type:saml2-bearer",
  "urn:ietf:params:oauth:grant-type:device_code",
  "urn:ietf:params:oauth:grant-type:token-exchange",
  "urn:openid:params:grant-type:ciba"
]
2021-02-10 09:54:29 SUCCESS
EnsureRefreshTokenContainsAllowedCharactersOnly
Refresh token does not contain any illegal characters
Refresh Token Request
2021-02-10 09:54:29 SUCCESS
CreateRefreshTokenRequest
Created token endpoint request parameters
grant_type
refresh_token
refresh_token
s5eQ8fZAj61fQre8wnf9PV3N387WnVOlNA40K9HInC
2021-02-10 09:54:29 SUCCESS
AddScopeToTokenEndpointRequest
Added scope of 'openid test' to token endpoint request
grant_type
refresh_token
refresh_token
s5eQ8fZAj61fQre8wnf9PV3N387WnVOlNA40K9HInC
scope
openid test
2021-02-10 09:54:29 SUCCESS
CreateClientAuthenticationAssertionClaims
Created client assertion claims
iss
conformance3ping
sub
conformance3ping
aud
https://emea-conformance.ping-eng.com:9032/as/token.oauth2
jti
DqncgSD0HleT5nFcGjMN
iat
1612950869
exp
1612950929
2021-02-10 09:54:29 SUCCESS
SignClientAuthenticationAssertion
Signed the client assertion
client_assertion
eyJraWQiOiIySEt5ejJVYzRGOGhSY3d5dVBnQTVFZ19zYWxuRWU3cGZ1alVrdmoyeWV3IiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTNwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTNwaW5nIiwiZXhwIjoxNjEyOTUwOTI5LCJpYXQiOjE2MTI5NTA4NjksImp0aSI6IkRxbmNnU0QwSGxlVDVuRmNHak1OIn0.jOOoU2c4gCNmlgITP7M4KcwfACJa21h9VwplrARNrBDec26NtCJK70xXrtQe0sHMYS3SLE_sPEpyCiOCA0F2yg
2021-02-10 09:54:29
AddClientAssertionToTokenEndpointRequest
Added client assertion
grant_type
refresh_token
refresh_token
s5eQ8fZAj61fQre8wnf9PV3N387WnVOlNA40K9HInC
scope
openid test
client_assertion
eyJraWQiOiIySEt5ejJVYzRGOGhSY3d5dVBnQTVFZ19zYWxuRWU3cGZ1alVrdmoyeWV3IiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTNwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTNwaW5nIiwiZXhwIjoxNjEyOTUwOTI5LCJpYXQiOjE2MTI5NTA4NjksImp0aSI6IkRxbmNnU0QwSGxlVDVuRmNHak1OIn0.jOOoU2c4gCNmlgITP7M4KcwfACJa21h9VwplrARNrBDec26NtCJK70xXrtQe0sHMYS3SLE_sPEpyCiOCA0F2yg
client_assertion_type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-02-10 09:54:29 SUCCESS
WaitForOneSecond
Pausing for 1 seconds
2021-02-10 09:54:30 SUCCESS
WaitForOneSecond
Woke up after 1 seconds sleep
2021-02-10 09:54:30
CallTokenEndpointAndReturnFullResponse
HTTP request
request_uri
https://emea-conformance.ping-eng.com:9032/as/token.oauth2
request_method
POST
request_headers
{
  "accept": "application/json;charset\u003dUTF-8",
  "accept-charset": "utf-8",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "629"
}
request_body
grant_type=refresh_token&refresh_token=s5eQ8fZAj61fQre8wnf9PV3N387WnVOlNA40K9HInC&scope=openid+test&client_assertion=eyJraWQiOiIySEt5ejJVYzRGOGhSY3d5dVBnQTVFZ19zYWxuRWU3cGZ1alVrdmoyeWV3IiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTNwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTNwaW5nIiwiZXhwIjoxNjEyOTUwOTI5LCJpYXQiOjE2MTI5NTA4NjksImp0aSI6IkRxbmNnU0QwSGxlVDVuRmNHak1OIn0.jOOoU2c4gCNmlgITP7M4KcwfACJa21h9VwplrARNrBDec26NtCJK70xXrtQe0sHMYS3SLE_sPEpyCiOCA0F2yg&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
request_mutual_tls
{
  "cert": "MIIDlTCCAn2gAwIBAgIJAKRJoaX7BlZbMA0GCSqGSIb3DQEBCwUAMGAxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMR0wGwYDVQQKDBRBdXRobGV0ZSBUZXN0IENsaWVudDEdMBsGA1UEAwwUQXV0aGxldGUgVGVzdCBDbGllbnQwIBcNMTgwNTI1MjA1NzU0WhgPMjEwNjAxMDQyMDU3NTRaMGAxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMR0wGwYDVQQKDBRBdXRobGV0ZSBUZXN0IENsaWVudDEdMBsGA1UEAwwUQXV0aGxldGUgVGVzdCBDbGllbnQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDEWwl/Q+nuL8KXbObpVzww1VkHwLF4W9QxrPI1V0Uh6V9rxUjrfSbtWNEQVDwQmoW8M1XjnRnGvdNRd0m6gNEQLKsqRN2xIvPdR0IO+2b+y7WJ9XlwdqHAFSWQJtoHzBAmkRirRMJrQSW5sB/NIBmyVqUdTV/FghNjc+IiPF4X1kxwwOzm7y2zlHZUpiPQknwPbWNeyunj/XQRrqWPg+RXzAKIjbVprxGaT8CexKu6oEaed8BCTO0rJIOkmjXZMl+SDhXQn9GHKFh60UlJddxVngxhX63MAQ1GsO8HsjrLgO3q4LmTDVHkprLy/wgBRDfo0IHb3gWhbOuRGMLLMKKvAgMBAAGjUDBOMB0GA1UdDgQWBBRuwpA4lqWaOkwmPcTQR8CH0Iv3vjAfBgNVHSMEGDAWgBRuwpA4lqWaOkwmPcTQR8CH0Iv3vjAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQBiCmvQmmKqI/8sB312HTEFlvtpbYp429eNCGXWloOOqVQkJaBnvy9YUS/wCgusyKeMBgbgpV0s8bp/gEW2/MnlWW9+fbFuhzRRwvuV/7je1Avv9Y06RH8GKJYwk2j6qcO7Mn9kVhlnlKxGdFxm/i0OBuZnUe/KDxKPjVEdUJbxAFfxdq4cUjfewMuoxsYruIDnLXjTBcj2PbJ6vcPzq/6TYwxRmnrXIAO6Nxe8ZNXn2x2+njwrUKW4WPQ7u3dyHlD+M3iTpm3TwSgg0FSYiBcXhWJLQCJVEb0kbKJ/PDmcvomusQWTL/0epS62azWG8PUUs4v9XeaemAbHqPGh+5Bo",
  "key": "MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDEWwl/Q+nuL8KXbObpVzww1VkHwLF4W9QxrPI1V0Uh6V9rxUjrfSbtWNEQVDwQmoW8M1XjnRnGvdNRd0m6gNEQLKsqRN2xIvPdR0IO+2b+y7WJ9XlwdqHAFSWQJtoHzBAmkRirRMJrQSW5sB/NIBmyVqUdTV/FghNjc+IiPF4X1kxwwOzm7y2zlHZUpiPQknwPbWNeyunj/XQRrqWPg+RXzAKIjbVprxGaT8CexKu6oEaed8BCTO0rJIOkmjXZMl+SDhXQn9GHKFh60UlJddxVngxhX63MAQ1GsO8HsjrLgO3q4LmTDVHkprLy/wgBRDfo0IHb3gWhbOuRGMLLMKKvAgMBAAECggEAJ3uOy1JipYxg+oXhYKYz6jXcMxziEquUXXDDO0qTEiCVGVyQLxn5S9yCHWByu3v2zEMeUCh02GuvJEBySNhCMZhpypQSZ935X1NGyzBuI2ne1SDRDHYuTCt0ZCoLyWmVDcw7Q6UN2vc8mLv7iQmdYSjfBqdaTKK9N1BD9lJhMTWBjxQDaF1yEZQfR1HOVVddJXt8ILOOltuxhu4EuBKsT8ZlCAN5kGx6+FzXlGlSYjWnGoYbERESeDim3JDwGOGX2msPGOmSzF24LnXrPg8IcrwEbzlFRIEzd8yUVA6VNca71uzv/MaOX5+cTtDiAoVdfrk1Ykt1SNNccGKnC7L3MQKBgQD29FIhT21DkUnXlABKj0N9dBSQyQ1HzILmY/YSg7aeBAlatEzCDxHtFaS89wXxosz2vNd1QKIrLrAgSzTLyemi2KVcvsHyo0g0drSq3NlOw5Rz4WRAZNgBcuhFJ8ZD1BJCisdQxQyCRJ3I0pf/D7mGkmovII1WSk/MIEWWvd3P6wKBgQDLjEEOaTeopbnqkJrcL4UbV2GmVAIa9EXSqzRTrPlxVA62n8EEX5YLXTx6yrvWHWtlA4VgRmUGuu1km5DqlnVdVz/l8fSk2HFcdycJgKd189v/tQ+BLu50+1+uaHiWLXo3VEXgv5QKSgPxWEnNPRVbgqOhav2MaACKo9sl3h4LTQKBgQCjyIxD7VKREmW/5TeAO53OMVOGZuE48ikKtdc4lkRibljp4FRcC/SeodEdRlOZ25hGOB5JdHFZZGCJOneshKBAUaDybs1gp+w2Z1gRTeGNvGbTp/N+RaOA6n2jh+qVh6wIl9Py/Iz8RJfE3e7SydIIr0hfMx6p0SU1Q14DyK64uwKBgQCiqM5ESejkqKtNu4lFc+QW2Vl7pZ6ZE6PImnASfiRIYDfx0PBaIlixdCyko+Y/UPtFme635QlOu4qB35+LF/lqQhMaGqS6Jw1QKxfTDDDGnb2tNm/ReEOu0ELCCVJ0EJueI4ZD+FTBdCx6bWdsz+eFXXyNvgYoceQc5px2Qm4X8QKBgHwpmIeHCvU9Erb9X5pY5JR609Ei+a9jksoe0ch7ocZi2NoE3vwjUSZFe/hTkvpf0gUhw1Zmekqhm78Qb4H7Aq7RDbpyCvoRXGS4GulFXM9Tkfe5FejhawT6fG12KLHOSAkJNgdFCPvFOaHlxPoAaBcf1sY/flehjWEwkVDSh0Js"
}
2021-02-10 09:54:30 RESPONSE
CallTokenEndpointAndReturnFullResponse
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "date": "Wed, 10 Feb 2021 09:54:30 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003dHMtAC8Hkb8oiLQ3gDOjdHN;Path\u003d/;Secure;HttpOnly;SameSite\u003dNone",
  "transfer-encoding": "chunked"
}
response_body
{"access_token":"eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2UzcGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiItby0xbGtvSWJjUGFUNHBtd1VlZnFHZDk2VElvUGRkNFAtYVFWbnNnVmJRIn0sImV4cCI6MTYxMjk1ODA3MH0.DnKscPPlPLQATdJlfZx83G042wX_wKJNlvsmeXbzuvukKLpHV8ochykAtRlDz7WMqLcPD9MsrMO74pcCp8TztLX-XVAi4OJs6bqYDI3sRlGzWpyMEUK2uvnM6VmanKVrLF9i64NcNtsok-qDsKYFnafCf0jhVIMjbfN7S9594ubYmrpWEHjl2GQTscClHmI-X7mQ9rFt0-MnCGe8DYnppM86jty_mlkk4HKYLEZ-8Lr_lLx3os5foY-wHTB7YYTvLFjnjgFZJi2rprUhfPE4scvHO_3hhY_k02MCueJqF_p8-9tDpckglyZEm1Fx-YDnyPyqPdxruicJMUq4lTHpYw","token_type":"Bearer","expires_in":7199}
2021-02-10 09:54:30 SUCCESS
CallTokenEndpointAndReturnFullResponse
Parsed token endpoint response
access_token
eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2UzcGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiItby0xbGtvSWJjUGFUNHBtd1VlZnFHZDk2VElvUGRkNFAtYVFWbnNnVmJRIn0sImV4cCI6MTYxMjk1ODA3MH0.DnKscPPlPLQATdJlfZx83G042wX_wKJNlvsmeXbzuvukKLpHV8ochykAtRlDz7WMqLcPD9MsrMO74pcCp8TztLX-XVAi4OJs6bqYDI3sRlGzWpyMEUK2uvnM6VmanKVrLF9i64NcNtsok-qDsKYFnafCf0jhVIMjbfN7S9594ubYmrpWEHjl2GQTscClHmI-X7mQ9rFt0-MnCGe8DYnppM86jty_mlkk4HKYLEZ-8Lr_lLx3os5foY-wHTB7YYTvLFjnjgFZJi2rprUhfPE4scvHO_3hhY_k02MCueJqF_p8-9tDpckglyZEm1Fx-YDnyPyqPdxruicJMUq4lTHpYw
token_type
Bearer
expires_in
7199
2021-02-10 09:54:30 SUCCESS
CheckTokenEndpointHttpStatus200
Token endpoint http status code was 200
2021-02-10 09:54:30 SUCCESS
CheckTokenEndpointReturnedJsonContentType
token_endpoint_response_headers Content-Type: header is application/json
2021-02-10 09:54:30 SUCCESS
CheckTokenEndpointCacheHeaders
'pragma' and 'cache-control' headers in token endpoint response contain expected values.
cache_control_header
no-cache, no-store
pragma_header
no-cache
2021-02-10 09:54:30 SUCCESS
CheckIfTokenEndpointResponseError
No error from token endpoint
2021-02-10 09:54:30 SUCCESS
ExtractAccessTokenFromTokenResponse
Extracted the access token
value
eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2UzcGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiItby0xbGtvSWJjUGFUNHBtd1VlZnFHZDk2VElvUGRkNFAtYVFWbnNnVmJRIn0sImV4cCI6MTYxMjk1ODA3MH0.DnKscPPlPLQATdJlfZx83G042wX_wKJNlvsmeXbzuvukKLpHV8ochykAtRlDz7WMqLcPD9MsrMO74pcCp8TztLX-XVAi4OJs6bqYDI3sRlGzWpyMEUK2uvnM6VmanKVrLF9i64NcNtsok-qDsKYFnafCf0jhVIMjbfN7S9594ubYmrpWEHjl2GQTscClHmI-X7mQ9rFt0-MnCGe8DYnppM86jty_mlkk4HKYLEZ-8Lr_lLx3os5foY-wHTB7YYTvLFjnjgFZJi2rprUhfPE4scvHO_3hhY_k02MCueJqF_p8-9tDpckglyZEm1Fx-YDnyPyqPdxruicJMUq4lTHpYw
type
Bearer
2021-02-10 09:54:30 SUCCESS
CheckTokenTypeIsBearer
Token type is bearer
2021-02-10 09:54:30 SUCCESS
EnsureMinimumAccessTokenEntropy
Calculated shannon entropy seems sufficient
actual
3536.5434512881843
expected
96.0
2021-02-10 09:54:30 SUCCESS
EnsureAccessTokenContainsAllowedCharactersOnly
Access token does not contain any illegal characters
2021-02-10 09:54:30 SUCCESS
ExtractExpiresInFromTokenEndpointResponse
Extracted 'expires_in'
expires_in
7199
2021-02-10 09:54:30 SUCCESS
ValidateExpiresIn
expires_in passed all validation checks
expires_in
7199
2021-02-10 09:54:30 SUCCESS
EnsureAccessTokenValuesAreDifferent
Access token values are not the same
first_access_token
eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2UzcGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiItby0xbGtvSWJjUGFUNHBtd1VlZnFHZDk2VElvUGRkNFAtYVFWbnNnVmJRIn0sImV4cCI6MTYxMjk1ODA2OX0.XMnhqwZSLWrERJIvdl5qkq7AOV4i_NNDCaScSYQqfSzit5xWgkUVhWp60wfmxX6XnZuoGtfM8dFYV6Fakgzen01vw4giTatqIVCQQqqyRhtuqeqABoGfqDX9RIdJEEyxs0xQqj9TxGpiFIC1okEYkPpkfAEE8BdeRwyA8waWrhuIMzx5qrbzt3ZVVRsz29cAYgpK0_wpf-bBrT_SwM4l-w3ZaUfp1yzVvA7GIl3qZ2ERG7umLiSDdQqU9D173-4KqHZCoj9bPGtkIKr9RSqWfe84OUMYVu0dNlK_b3KJgyTXRH3E-Wac-VGWSc0SzR82rD8OgCjNETv67Z7C9z4mnQ
second_access_token
eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2UzcGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiItby0xbGtvSWJjUGFUNHBtd1VlZnFHZDk2VElvUGRkNFAtYVFWbnNnVmJRIn0sImV4cCI6MTYxMjk1ODA3MH0.DnKscPPlPLQATdJlfZx83G042wX_wKJNlvsmeXbzuvukKLpHV8ochykAtRlDz7WMqLcPD9MsrMO74pcCp8TztLX-XVAi4OJs6bqYDI3sRlGzWpyMEUK2uvnM6VmanKVrLF9i64NcNtsok-qDsKYFnafCf0jhVIMjbfN7S9594ubYmrpWEHjl2GQTscClHmI-X7mQ9rFt0-MnCGe8DYnppM86jty_mlkk4HKYLEZ-8Lr_lLx3os5foY-wHTB7YYTvLFjnjgFZJi2rprUhfPE4scvHO_3hhY_k02MCueJqF_p8-9tDpckglyZEm1Fx-YDnyPyqPdxruicJMUq4lTHpYw
2021-02-10 09:54:30 INFO
ExtractIdTokenFromTokenResponse
Couldn't find id_token in token_endpoint_response
2021-02-10 09:54:30 INFO
ExtractRefreshTokenFromTokenResponse
Token endpoint response does not contain a refresh token
2021-02-10 09:54:30 INFO
EnsureMinimumRefreshTokenLength
Skipped evaluation due to missing required element: token_endpoint_response refresh_token
path
refresh_token
mapped
object
token_endpoint_response
2021-02-10 09:54:30 INFO
EnsureMinimumRefreshTokenEntropy
Skipped evaluation due to missing required element: token_endpoint_response refresh_token
path
refresh_token
mapped
object
token_endpoint_response
2021-02-10 09:54:30 INFO
CompareIdTokenClaims
Skipped evaluation due to missing required object: second_id_token
expected
second_id_token
mapped
second_id_token
Resource server endpoint tests
2021-02-10 09:54:30
CreateEmptyResourceEndpointRequestHeaders
Created empty headers
resource_endpoint_request_headers
{}
2021-02-10 09:54:30 SUCCESS
AddFAPIAuthDateToResourceEndpointRequest
Added x-fapi-auth-date to resource endpoint request headers
resource_endpoint_request_headers
{
  "x-fapi-auth-date": "Wed, 10 Feb 2021 09:54:30 GMT"
}
2021-02-10 09:54:30
CreateRandomFAPIInteractionId
Created interaction ID
fapi_interaction_id
ee225414-c15a-4c35-ba9c-0cbec87c62d5
2021-02-10 09:54:30
AddFAPIInteractionIdToResourceEndpointRequest
Condition ran but did not log anything
2021-02-10 09:54:30
CallProtectedResourceWithBearerTokenAndCustomHeaders
HTTP request
request_uri
https://emea-conformance.ping-eng.com:3000/get
request_method
GET
request_headers
{
  "accept": "application/json;charset\u003dUTF-8",
  "x-fapi-auth-date": "Wed, 10 Feb 2021 09:54:30 GMT",
  "x-fapi-interaction-id": "ee225414-c15a-4c35-ba9c-0cbec87c62d5",
  "authorization": "Bearer eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2UzcGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiItby0xbGtvSWJjUGFUNHBtd1VlZnFHZDk2VElvUGRkNFAtYVFWbnNnVmJRIn0sImV4cCI6MTYxMjk1ODA3MH0.DnKscPPlPLQATdJlfZx83G042wX_wKJNlvsmeXbzuvukKLpHV8ochykAtRlDz7WMqLcPD9MsrMO74pcCp8TztLX-XVAi4OJs6bqYDI3sRlGzWpyMEUK2uvnM6VmanKVrLF9i64NcNtsok-qDsKYFnafCf0jhVIMjbfN7S9594ubYmrpWEHjl2GQTscClHmI-X7mQ9rFt0-MnCGe8DYnppM86jty_mlkk4HKYLEZ-8Lr_lLx3os5foY-wHTB7YYTvLFjnjgFZJi2rprUhfPE4scvHO_3hhY_k02MCueJqF_p8-9tDpckglyZEm1Fx-YDnyPyqPdxruicJMUq4lTHpYw",
  "accept-charset": "utf-8",
  "content-length": "0"
}
request_body

                                
request_mutual_tls
{
  "cert": "MIIDlTCCAn2gAwIBAgIJAKRJoaX7BlZbMA0GCSqGSIb3DQEBCwUAMGAxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMR0wGwYDVQQKDBRBdXRobGV0ZSBUZXN0IENsaWVudDEdMBsGA1UEAwwUQXV0aGxldGUgVGVzdCBDbGllbnQwIBcNMTgwNTI1MjA1NzU0WhgPMjEwNjAxMDQyMDU3NTRaMGAxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMR0wGwYDVQQKDBRBdXRobGV0ZSBUZXN0IENsaWVudDEdMBsGA1UEAwwUQXV0aGxldGUgVGVzdCBDbGllbnQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDEWwl/Q+nuL8KXbObpVzww1VkHwLF4W9QxrPI1V0Uh6V9rxUjrfSbtWNEQVDwQmoW8M1XjnRnGvdNRd0m6gNEQLKsqRN2xIvPdR0IO+2b+y7WJ9XlwdqHAFSWQJtoHzBAmkRirRMJrQSW5sB/NIBmyVqUdTV/FghNjc+IiPF4X1kxwwOzm7y2zlHZUpiPQknwPbWNeyunj/XQRrqWPg+RXzAKIjbVprxGaT8CexKu6oEaed8BCTO0rJIOkmjXZMl+SDhXQn9GHKFh60UlJddxVngxhX63MAQ1GsO8HsjrLgO3q4LmTDVHkprLy/wgBRDfo0IHb3gWhbOuRGMLLMKKvAgMBAAGjUDBOMB0GA1UdDgQWBBRuwpA4lqWaOkwmPcTQR8CH0Iv3vjAfBgNVHSMEGDAWgBRuwpA4lqWaOkwmPcTQR8CH0Iv3vjAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQBiCmvQmmKqI/8sB312HTEFlvtpbYp429eNCGXWloOOqVQkJaBnvy9YUS/wCgusyKeMBgbgpV0s8bp/gEW2/MnlWW9+fbFuhzRRwvuV/7je1Avv9Y06RH8GKJYwk2j6qcO7Mn9kVhlnlKxGdFxm/i0OBuZnUe/KDxKPjVEdUJbxAFfxdq4cUjfewMuoxsYruIDnLXjTBcj2PbJ6vcPzq/6TYwxRmnrXIAO6Nxe8ZNXn2x2+njwrUKW4WPQ7u3dyHlD+M3iTpm3TwSgg0FSYiBcXhWJLQCJVEb0kbKJ/PDmcvomusQWTL/0epS62azWG8PUUs4v9XeaemAbHqPGh+5Bo",
  "key": "MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDEWwl/Q+nuL8KXbObpVzww1VkHwLF4W9QxrPI1V0Uh6V9rxUjrfSbtWNEQVDwQmoW8M1XjnRnGvdNRd0m6gNEQLKsqRN2xIvPdR0IO+2b+y7WJ9XlwdqHAFSWQJtoHzBAmkRirRMJrQSW5sB/NIBmyVqUdTV/FghNjc+IiPF4X1kxwwOzm7y2zlHZUpiPQknwPbWNeyunj/XQRrqWPg+RXzAKIjbVprxGaT8CexKu6oEaed8BCTO0rJIOkmjXZMl+SDhXQn9GHKFh60UlJddxVngxhX63MAQ1GsO8HsjrLgO3q4LmTDVHkprLy/wgBRDfo0IHb3gWhbOuRGMLLMKKvAgMBAAECggEAJ3uOy1JipYxg+oXhYKYz6jXcMxziEquUXXDDO0qTEiCVGVyQLxn5S9yCHWByu3v2zEMeUCh02GuvJEBySNhCMZhpypQSZ935X1NGyzBuI2ne1SDRDHYuTCt0ZCoLyWmVDcw7Q6UN2vc8mLv7iQmdYSjfBqdaTKK9N1BD9lJhMTWBjxQDaF1yEZQfR1HOVVddJXt8ILOOltuxhu4EuBKsT8ZlCAN5kGx6+FzXlGlSYjWnGoYbERESeDim3JDwGOGX2msPGOmSzF24LnXrPg8IcrwEbzlFRIEzd8yUVA6VNca71uzv/MaOX5+cTtDiAoVdfrk1Ykt1SNNccGKnC7L3MQKBgQD29FIhT21DkUnXlABKj0N9dBSQyQ1HzILmY/YSg7aeBAlatEzCDxHtFaS89wXxosz2vNd1QKIrLrAgSzTLyemi2KVcvsHyo0g0drSq3NlOw5Rz4WRAZNgBcuhFJ8ZD1BJCisdQxQyCRJ3I0pf/D7mGkmovII1WSk/MIEWWvd3P6wKBgQDLjEEOaTeopbnqkJrcL4UbV2GmVAIa9EXSqzRTrPlxVA62n8EEX5YLXTx6yrvWHWtlA4VgRmUGuu1km5DqlnVdVz/l8fSk2HFcdycJgKd189v/tQ+BLu50+1+uaHiWLXo3VEXgv5QKSgPxWEnNPRVbgqOhav2MaACKo9sl3h4LTQKBgQCjyIxD7VKREmW/5TeAO53OMVOGZuE48ikKtdc4lkRibljp4FRcC/SeodEdRlOZ25hGOB5JdHFZZGCJOneshKBAUaDybs1gp+w2Z1gRTeGNvGbTp/N+RaOA6n2jh+qVh6wIl9Py/Iz8RJfE3e7SydIIr0hfMx6p0SU1Q14DyK64uwKBgQCiqM5ESejkqKtNu4lFc+QW2Vl7pZ6ZE6PImnASfiRIYDfx0PBaIlixdCyko+Y/UPtFme635QlOu4qB35+LF/lqQhMaGqS6Jw1QKxfTDDDGnb2tNm/ReEOu0ELCCVJ0EJueI4ZD+FTBdCx6bWdsz+eFXXyNvgYoceQc5px2Qm4X8QKBgHwpmIeHCvU9Erb9X5pY5JR609Ei+a9jksoe0ch7ocZi2NoE3vwjUSZFe/hTkvpf0gUhw1Zmekqhm78Qb4H7Aq7RDbpyCvoRXGS4GulFXM9Tkfe5FejhawT6fG12KLHOSAkJNgdFCPvFOaHlxPoAaBcf1sY/flehjWEwkVDSh0Js"
}
2021-02-10 09:54:31 RESPONSE
CallProtectedResourceWithBearerTokenAndCustomHeaders
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "date": "Wed, 10 Feb 2021 09:54:31 GMT",
  "content-type": "application/json",
  "content-length": "1194",
  "server": "gunicorn/19.9.0",
  "access-control-allow-origin": "*",
  "access-control-allow-credentials": "true",
  "x-fapi-interaction-id": "ee225414-c15a-4c35-ba9c-0cbec87c62d5"
}
response_body
{
  "args": {}, 
  "headers": {
    "Accept": "application/json;charset=UTF-8", 
    "Accept-Charset": "utf-8", 
    "Accept-Encoding": "gzip,deflate", 
    "Authorization": "Bearer eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2UzcGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiItby0xbGtvSWJjUGFUNHBtd1VlZnFHZDk2VElvUGRkNFAtYVFWbnNnVmJRIn0sImV4cCI6MTYxMjk1ODA3MH0.DnKscPPlPLQATdJlfZx83G042wX_wKJNlvsmeXbzuvukKLpHV8ochykAtRlDz7WMqLcPD9MsrMO74pcCp8TztLX-XVAi4OJs6bqYDI3sRlGzWpyMEUK2uvnM6VmanKVrLF9i64NcNtsok-qDsKYFnafCf0jhVIMjbfN7S9594ubYmrpWEHjl2GQTscClHmI-X7mQ9rFt0-MnCGe8DYnppM86jty_mlkk4HKYLEZ-8Lr_lLx3os5foY-wHTB7YYTvLFjnjgFZJi2rprUhfPE4scvHO_3hhY_k02MCueJqF_p8-9tDpckglyZEm1Fx-YDnyPyqPdxruicJMUq4lTHpYw", 
    "Host": "emea-conformance.ping-eng.com", 
    "User-Agent": "Apache-HttpClient/4.5.5 (Java/11.0.10)", 
    "X-Amzn-Trace-Id": "Root=1-6023ad57-65365bb36a588b6b71a6ad33", 
    "X-Fapi-Auth-Date": "Wed, 10 Feb 2021 09:54:30 GMT", 
    "X-Fapi-Interaction-Id": "ee225414-c15a-4c35-ba9c-0cbec87c62d5"
  }, 
  "origin": "35.196.44.185, 54.74.38.30", 
  "url": "https://emea-conformance.ping-eng.com/get"
}
2021-02-10 09:54:31 SUCCESS
CallProtectedResourceWithBearerTokenAndCustomHeaders
Got a response from the resource endpoint
headers
{
  "date": "Wed, 10 Feb 2021 09:54:31 GMT",
  "content-type": "application/json",
  "content-length": "1194",
  "server": "gunicorn/19.9.0",
  "access-control-allow-origin": "*",
  "access-control-allow-credentials": "true",
  "x-fapi-interaction-id": "ee225414-c15a-4c35-ba9c-0cbec87c62d5"
}
status_code
{
  "code": 200
}
body
{
  "args": {}, 
  "headers": {
    "Accept": "application/json;charset=UTF-8", 
    "Accept-Charset": "utf-8", 
    "Accept-Encoding": "gzip,deflate", 
    "Authorization": "Bearer eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2UzcGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiItby0xbGtvSWJjUGFUNHBtd1VlZnFHZDk2VElvUGRkNFAtYVFWbnNnVmJRIn0sImV4cCI6MTYxMjk1ODA3MH0.DnKscPPlPLQATdJlfZx83G042wX_wKJNlvsmeXbzuvukKLpHV8ochykAtRlDz7WMqLcPD9MsrMO74pcCp8TztLX-XVAi4OJs6bqYDI3sRlGzWpyMEUK2uvnM6VmanKVrLF9i64NcNtsok-qDsKYFnafCf0jhVIMjbfN7S9594ubYmrpWEHjl2GQTscClHmI-X7mQ9rFt0-MnCGe8DYnppM86jty_mlkk4HKYLEZ-8Lr_lLx3os5foY-wHTB7YYTvLFjnjgFZJi2rprUhfPE4scvHO_3hhY_k02MCueJqF_p8-9tDpckglyZEm1Fx-YDnyPyqPdxruicJMUq4lTHpYw", 
    "Host": "emea-conformance.ping-eng.com", 
    "User-Agent": "Apache-HttpClient/4.5.5 (Java/11.0.10)", 
    "X-Amzn-Trace-Id": "Root=1-6023ad57-65365bb36a588b6b71a6ad33", 
    "X-Fapi-Auth-Date": "Wed, 10 Feb 2021 09:54:30 GMT", 
    "X-Fapi-Interaction-Id": "ee225414-c15a-4c35-ba9c-0cbec87c62d5"
  }, 
  "origin": "35.196.44.185, 54.74.38.30", 
  "url": "https://emea-conformance.ping-eng.com/get"
}
2021-02-10 09:54:31 SUCCESS
CheckForDateHeaderInResourceResponse
Date header present and validated
date
Wed, 10 Feb 2021 09:54:31 GMT
skew
464
2021-02-10 09:54:31 SUCCESS
CheckForFAPIInteractionIdInResourceResponse
Found x-fapi-interaction-id
interaction_id
ee225414-c15a-4c35-ba9c-0cbec87c62d5
2021-02-10 09:54:31 SUCCESS
EnsureMatchingFAPIInteractionId
Interaction ID matched
fapi_interaction_id
ee225414-c15a-4c35-ba9c-0cbec87c62d5
2021-02-10 09:54:31 SUCCESS
EnsureResourceResponseReturnedJsonContentType
Response content type is JSON
content_type
application/json
Second client: Call backchannel authentication endpoint
2021-02-10 09:54:31 SUCCESS
CreateEmptyAuthorizationEndpointRequest
Created empty authorization endpoint request
2021-02-10 09:54:31 SUCCESS
AddScopeToAuthorizationEndpointRequest
Added scope of 'openid test' to authorization endpoint request
scope
openid test
2021-02-10 09:54:31 SUCCESS
AddHintToAuthorizationEndpointRequest
Added hint to authorization endpoint request
login_hint
patrick
2021-02-10 09:54:31 SUCCESS
AddBindingMessageToAuthorizationEndpointRequest
Added binding message to authorization endpoint request
binding_message
1234
2021-02-10 09:54:31
CreateRandomClientNotificationToken
Created token value
client_notification_token
785jHa-oj+Sc89ORvCv8=
requested_notification_token_length
21
2021-02-10 09:54:31 SUCCESS
AddClientNotificationTokenToAuthorizationEndpointRequest
Added client_notification_token '785jHa-oj+Sc89ORvCv8=' to authorization endpoint request
scope
openid test
login_hint
patrick
binding_message
1234
client_notification_token
785jHa-oj+Sc89ORvCv8=
2021-02-10 09:54:31 SUCCESS
ConvertAuthorizationEndpointRequestToRequestObject
Created request object claims
request_object_claims
{
  "scope": "openid test",
  "login_hint": "patrick",
  "binding_message": "1234",
  "client_notification_token": "785jHa-oj+Sc89ORvCv8\u003d"
}
2021-02-10 09:54:31 SUCCESS
AddIatToRequestObject
Added iat to request object claims
iat
1.612950871E9
2021-02-10 09:54:31 SUCCESS
AddExpToRequestObject
Added exp to request object claims
exp
1.612951171E9
2021-02-10 09:54:31 SUCCESS
AddNbfToRequestObject
Added nbf to request object claims
nbf
1.612950871E9
2021-02-10 09:54:31 SUCCESS
AddJtiToRequestObject
Added jti to request object claims
jti
nRhhd2xki6sKC3oj9Un2
2021-02-10 09:54:31 SUCCESS
AddAudToRequestObject
Added aud to request object claims
aud
https://emea-conformance.ping-eng.com:9031
2021-02-10 09:54:31 SUCCESS
AddIssToRequestObject
Added iss to request object claims
iss
conformance4ping
2021-02-10 09:54:31 SUCCESS
SignRequestObject
Signed the request object
claims
{"client_notification_token":"785jHa-oj+Sc89ORvCv8=","aud":"https:\/\/emea-conformance.ping-eng.com:9031","login_hint":"patrick","nbf":1612950871,"scope":"openid test","iss":"conformance4ping","binding_message":"1234","exp":1612951171,"iat":1612950871,"jti":"nRhhd2xki6sKC3oj9Un2"}
header
{"kid":"6waBCAJKuKMvSU3k540XHPx_4gJx01tmQh8giaYjj1k","alg":"ES256"}
request_object
eyJraWQiOiI2d2FCQ0FKS3VLTXZTVTNrNTQwWEhQeF80Z0p4MDF0bVFoOGdpYVlqajFrIiwiYWxnIjoiRVMyNTYifQ.eyJjbGllbnRfbm90aWZpY2F0aW9uX3Rva2VuIjoiNzg1akhhLW9qK1NjODlPUnZDdjg9IiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzEiLCJsb2dpbl9oaW50IjoicGF0cmljayIsIm5iZiI6MTYxMjk1MDg3MSwic2NvcGUiOiJvcGVuaWQgdGVzdCIsImlzcyI6ImNvbmZvcm1hbmNlNHBpbmciLCJiaW5kaW5nX21lc3NhZ2UiOiIxMjM0IiwiZXhwIjoxNjEyOTUxMTcxLCJpYXQiOjE2MTI5NTA4NzEsImp0aSI6Im5SaGhkMnhraTZzS0Mzb2o5VW4yIn0.w2o_mV60z80kg8xfBsIShJ75AzS44q3_w2iTjIoit2V8IEQ4uzM5dur3bAI5MKxnWGzpx7TC5w6paCrDlwH3uA
key
{"kty":"EC","d":"MTbmR5F_tN0zlvVrwESkMNHB-ZLoRpk3dlxHYged3Ik","use":"sig","crv":"P-256","kid":"6waBCAJKuKMvSU3k540XHPx_4gJx01tmQh8giaYjj1k","x":"XW7xFTCnyPLhhWb_dE0fIIavYTbilf3HDsUELAC5SwI","y":"sm9SrdwPWJ_oQ5tbsDMi6xnsaoLWZLTFyy0L2q5vURE","alg":"ES256"}
2021-02-10 09:54:31 SUCCESS
CreateBackchannelAuthenticationEndpointRequest
Created backchannel authentication endpoint request
2021-02-10 09:54:31
AddRequestToBackchannelAuthenticationEndpointRequest
request
eyJraWQiOiI2d2FCQ0FKS3VLTXZTVTNrNTQwWEhQeF80Z0p4MDF0bVFoOGdpYVlqajFrIiwiYWxnIjoiRVMyNTYifQ.eyJjbGllbnRfbm90aWZpY2F0aW9uX3Rva2VuIjoiNzg1akhhLW9qK1NjODlPUnZDdjg9IiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzEiLCJsb2dpbl9oaW50IjoicGF0cmljayIsIm5iZiI6MTYxMjk1MDg3MSwic2NvcGUiOiJvcGVuaWQgdGVzdCIsImlzcyI6ImNvbmZvcm1hbmNlNHBpbmciLCJiaW5kaW5nX21lc3NhZ2UiOiIxMjM0IiwiZXhwIjoxNjEyOTUxMTcxLCJpYXQiOjE2MTI5NTA4NzEsImp0aSI6Im5SaGhkMnhraTZzS0Mzb2o5VW4yIn0.w2o_mV60z80kg8xfBsIShJ75AzS44q3_w2iTjIoit2V8IEQ4uzM5dur3bAI5MKxnWGzpx7TC5w6paCrDlwH3uA
2021-02-10 09:54:31 SUCCESS
CreateClientAuthenticationAssertionClaims
Created client assertion claims
iss
conformance4ping
sub
conformance4ping
aud
https://emea-conformance.ping-eng.com:9032/as/token.oauth2
jti
LXhuCpe5ljDUSdq3g0v4
iat
1612950871
exp
1612950931
2021-02-10 09:54:31 SUCCESS
SetClientAuthenticationAudTokenEndpointToBackchannelAuthenticationEndpoint
Add token_endpoint as aud value to client_assertion_claims - as per section 7.1 of CIBA, 'the OP MUST accept its Issuer Identifier, Token Endpoint URL, or Backchannel Authentication Endpoint URL as values that identify it as an intended audience'
iss
conformance4ping
sub
conformance4ping
aud
https://emea-conformance.ping-eng.com:9032/as/token.oauth2
jti
LXhuCpe5ljDUSdq3g0v4
iat
1612950871
exp
1612950931
2021-02-10 09:54:31 SUCCESS
SignClientAuthenticationAssertion
Signed the client assertion
client_assertion
eyJraWQiOiI2d2FCQ0FKS3VLTXZTVTNrNTQwWEhQeF80Z0p4MDF0bVFoOGdpYVlqajFrIiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTRwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTRwaW5nIiwiZXhwIjoxNjEyOTUwOTMxLCJpYXQiOjE2MTI5NTA4NzEsImp0aSI6IkxYaHVDcGU1bGpEVVNkcTNnMHY0In0.aJP9EtnpKtEOyAOGWLMuOTXl4llRgo5ru6MntuKViRXYNdsgkRr0ibuT4pxaWuKNmXBbhX55mXahpCwK8PulBw
2021-02-10 09:54:31
AddClientAssertionToBackchannelAuthenticationEndpoint
Added client assertion
request
eyJraWQiOiI2d2FCQ0FKS3VLTXZTVTNrNTQwWEhQeF80Z0p4MDF0bVFoOGdpYVlqajFrIiwiYWxnIjoiRVMyNTYifQ.eyJjbGllbnRfbm90aWZpY2F0aW9uX3Rva2VuIjoiNzg1akhhLW9qK1NjODlPUnZDdjg9IiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzEiLCJsb2dpbl9oaW50IjoicGF0cmljayIsIm5iZiI6MTYxMjk1MDg3MSwic2NvcGUiOiJvcGVuaWQgdGVzdCIsImlzcyI6ImNvbmZvcm1hbmNlNHBpbmciLCJiaW5kaW5nX21lc3NhZ2UiOiIxMjM0IiwiZXhwIjoxNjEyOTUxMTcxLCJpYXQiOjE2MTI5NTA4NzEsImp0aSI6Im5SaGhkMnhraTZzS0Mzb2o5VW4yIn0.w2o_mV60z80kg8xfBsIShJ75AzS44q3_w2iTjIoit2V8IEQ4uzM5dur3bAI5MKxnWGzpx7TC5w6paCrDlwH3uA
client_assertion
eyJraWQiOiI2d2FCQ0FKS3VLTXZTVTNrNTQwWEhQeF80Z0p4MDF0bVFoOGdpYVlqajFrIiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTRwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTRwaW5nIiwiZXhwIjoxNjEyOTUwOTMxLCJpYXQiOjE2MTI5NTA4NzEsImp0aSI6IkxYaHVDcGU1bGpEVVNkcTNnMHY0In0.aJP9EtnpKtEOyAOGWLMuOTXl4llRgo5ru6MntuKViRXYNdsgkRr0ibuT4pxaWuKNmXBbhX55mXahpCwK8PulBw
client_assertion_type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-02-10 09:54:31
CallBackchannelAuthenticationEndpoint
HTTP request
request_uri
https://emea-conformance.ping-eng.com:9031/as/bc-auth.ciba
request_method
POST
request_headers
{
  "accept": "application/json;charset\u003dUTF-8",
  "accept-charset": "utf-8",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "1091"
}
request_body
request=eyJraWQiOiI2d2FCQ0FKS3VLTXZTVTNrNTQwWEhQeF80Z0p4MDF0bVFoOGdpYVlqajFrIiwiYWxnIjoiRVMyNTYifQ.eyJjbGllbnRfbm90aWZpY2F0aW9uX3Rva2VuIjoiNzg1akhhLW9qK1NjODlPUnZDdjg9IiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzEiLCJsb2dpbl9oaW50IjoicGF0cmljayIsIm5iZiI6MTYxMjk1MDg3MSwic2NvcGUiOiJvcGVuaWQgdGVzdCIsImlzcyI6ImNvbmZvcm1hbmNlNHBpbmciLCJiaW5kaW5nX21lc3NhZ2UiOiIxMjM0IiwiZXhwIjoxNjEyOTUxMTcxLCJpYXQiOjE2MTI5NTA4NzEsImp0aSI6Im5SaGhkMnhraTZzS0Mzb2o5VW4yIn0.w2o_mV60z80kg8xfBsIShJ75AzS44q3_w2iTjIoit2V8IEQ4uzM5dur3bAI5MKxnWGzpx7TC5w6paCrDlwH3uA&client_assertion=eyJraWQiOiI2d2FCQ0FKS3VLTXZTVTNrNTQwWEhQeF80Z0p4MDF0bVFoOGdpYVlqajFrIiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTRwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTRwaW5nIiwiZXhwIjoxNjEyOTUwOTMxLCJpYXQiOjE2MTI5NTA4NzEsImp0aSI6IkxYaHVDcGU1bGpEVVNkcTNnMHY0In0.aJP9EtnpKtEOyAOGWLMuOTXl4llRgo5ru6MntuKViRXYNdsgkRr0ibuT4pxaWuKNmXBbhX55mXahpCwK8PulBw&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
request_mutual_tls
{
  "cert": "MIIDhTCCAm2gAwIBAgIJAKAe4HusBvwoMA0GCSqGSIb3DQEBCwUAMFgxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMSEwHwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQxETAPBgNVBAMMCGNsaWVudF8yMCAXDTE4MDcwMjE2MzUyOFoYDzIxMDYwMjExMTYzNTI4WjBYMQswCQYDVQQGEwJVUzETMBEGA1UECAwKU29tZS1TdGF0ZTEhMB8GA1UECgwYSW50ZXJuZXQgV2lkZ2l0cyBQdHkgTHRkMREwDwYDVQQDDAhjbGllbnRfMjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANMy1QohUbUoyte8cYCCO1+vJ/GImvVkrb79HUTSzL3G46lDC0JYZGMpMvX9NncadCYLQV8fmofOouNs4AWJgf0skH5sAJcZMgj3GVqqLsx2iDye3cgqsCCzTf5gzhOVtpXgNoBMFckVGxI+dG9h06n71mH9dtGoD/BoWOB4FLae0Ec4olot5eROeJ3Z0J15aXPWoQrn3J5Eoz0/c7D7+byb+XGjF/r+uJVrKqOLtnO69Ro99fowwVtVQAPHmxLQ9VvFiLONwbOfELtBvX4MlxHDOuynDsDw/mHxkzMSxPXAd9QfIU05ySZ9eVR3UfNUeCk8a63NSO8MZdfHFnUsEO8CAwEAAaNQME4wHQYDVR0OBBYEFFEdch1XYRpO5JXxPkBxdAoAt6IiMB8GA1UdIwQYMBaAFFEdch1XYRpO5JXxPkBxdAoAt6IiMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBABTTN0up/ndWCNamqrV8ik1XwUqPCAO7TYKmZrRilo3STxyp2aUiFf1uPSkU6WU4Eu0JoDKU46axIFzZO3Ckoq17JMde2OzESlAF+hQyvg/3l+6mbBK/OuzOiC+yfU9roD6vmjsBlH0My1+CnqkZLr6YQSaCHfflb6zqA7+aLUEWjyVneD6jQ6CCFwCs6eDorY1eKFM7lCQ5OdJFBc2LOOXuSGRXLZDKF3X2SfKCld0VWIOknJk8drfrCc1ylWa7wIuXU/kTyX8Z68a8w1/6ZkGxN9tsHWVtSe6ggOD1AFI5OQ3c8lCUzgGeFl69hz2UduHOyWs1KXUhgSy7fViAP90\u003d",
  "key": "MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQDTMtUKIVG1KMrXvHGAgjtfryfxiJr1ZK2+/R1E0sy9xuOpQwtCWGRjKTL1/TZ3GnQmC0FfH5qHzqLjbOAFiYH9LJB+bACXGTII9xlaqi7Mdog8nt3IKrAgs03+YM4TlbaV4DaATBXJFRsSPnRvYdOp+9Zh/XbRqA/waFjgeBS2ntBHOKJaLeXkTnid2dCdeWlz1qEK59yeRKM9P3Ow+/m8m/lxoxf6/riVayqji7ZzuvUaPfX6MMFbVUADx5sS0PVbxYizjcGznxC7Qb1+DJcRwzrspw7A8P5h8ZMzEsT1wHfUHyFNOckmfXlUd1HzVHgpPGutzUjvDGXXxxZ1LBDvAgMBAAECggEBAJzGiiB39VheTJzy1OqJQhvYQPVp62Wn89XnvLdfJ/7kShFWpF/+j56QcbTq32hwabHn/wHmyuZvPLlIE8/ocGcIksZV0+ZWHK9NBjQoSo8ami0t3QJ+tbnAgHAJWlBtfVkqVCrO0AkxsqPLWtFntCDlwhGBfpdJg3N5cihG21FnnqUNxj2lVp1jxCAAcBHwCMfODFi0Kke/FLS3u9vHSRybUAbNid1adNJ6g3f3jKXhX5HPR2KYqDIyCQrqs9IAx7mM/T2W75NpZC1rW5GAWyw7sR71YDFI/Mronrdh0ZiHOpllwgM4bBD7ipNH3jNRgsAUr5nyTIJAii9z8XxGubkCgYEA+e88Kt3uZbFfcqTvb2ZTCUd3fyC0FcZ+/iHhKp2fmwsSIWB7k6++q8Vn/YHdew7KS+i4dvap30+k8Jf0u8p1NY82qHb5b/8igj6z015O+q1XE+hNoPUeIlX7JBVf0y3NIiiOTxvcWoIGKpthEVvlVk27PfYUEsnefFnKTQ7kNI0CgYEA2FLxXKrDQQRwtmC0My4LuAwhkGqxCwk1V8vD0k+J1JqVI3qQPxt5H241KtWwdb6QxAjuBe0i1Yx6vW1qC60NaZpM7RLFOEKyfwLuk19S9BKs1q0BRqcPpIP0PIZ+GgpKs7fIWcn19IFI/1KlSVYYV7qDgDmzMG13OPeJuAclAmsCgYBIyIdgAGMlUCL4ktl7OnQh9qLw7Ygj8zsWLK2SqHZLQ00TVTKHjp1bDlC7PW9PH75/npThZ/GOK3Zf7hCCA3Jgl4UWSBdZqxXUkgfyHLupOoNqM7MvlVIiM6HAH01ZhTQAp4jRts5TuRusmrUIxhciK97EK34q/oiA8/D6wcRpHQKBgBWbY0RQQiRyXxe4XQdnqAAAJjIYlgp2Jv/X+H0/OJMlxZO/oDzNb7G1/lWC9pcsK6WJBs1MvFf8Kh5VmWwFIvvTT6+2WkCeWNna3x2VPeHnI6Bls2TtNuDF1VVeUaYkNQXya26cf5amezYVeTD0CoZouM3L9Zv2sxvbjcP14rp1AoGADoxlSjWxXOxZAr835wFlD3EMU5nhUGA0BdCfGgKqMaZmCr/ssfQDARgCKG/zLfmUBBBHbjZcHMXw6SW+E3CTN/q7iddT3FOgVder4GWTA+wFYdAywCT5At8wm7zeM2d/4cWlBaKew/u+A0ycUsD6bd3gRXjBZpD8Eep8ltVGLHw\u003d"
}
2021-02-10 09:54:31 RESPONSE
CallBackchannelAuthenticationEndpoint
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "date": "Wed, 10 Feb 2021 09:54:31 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003ducH4gpTWh0gQtxD4QItwzR;Path\u003d/;Secure;HttpOnly;SameSite\u003dNone",
  "transfer-encoding": "chunked"
}
response_body
{"auth_req_id":"rGexz4_wnsxo9uWdqBOzuZV9u6NHJABgI63PWJ8A2gbIJCXizrcUUFAAtA","interval":3,"expires_in":120}
2021-02-10 09:54:31
CallBackchannelAuthenticationEndpoint
Backchannel Authentication endpoint response
backchannel_authentication_endpoint_response
{"auth_req_id":"rGexz4_wnsxo9uWdqBOzuZV9u6NHJABgI63PWJ8A2gbIJCXizrcUUFAAtA","interval":3,"expires_in":120}
2021-02-10 09:54:31 SUCCESS
CallBackchannelAuthenticationEndpoint
Parsed backchannel authentication endpoint response
auth_req_id
rGexz4_wnsxo9uWdqBOzuZV9u6NHJABgI63PWJ8A2gbIJCXizrcUUFAAtA
interval
3
expires_in
120
2021-02-10 09:54:31 SUCCESS
CheckBackchannelAuthenticationEndpointHttpStatus200
Backchannel authentication endpoint http status code was 200
2021-02-10 09:54:31 SUCCESS
CheckBackchannelAuthenticationEndpointContentType
Backchannel authentication endpoint Content-Type: header is application/json
2021-02-10 09:54:31 SUCCESS
CheckIfBackchannelAuthenticationEndpointResponseError
No error from Backchannel authentication endpoint
2021-02-10 09:54:31 SUCCESS
ValidateAuthenticationRequestId
auth_req_id passed all validation checks
2021-02-10 09:54:31 SUCCESS
EnsureMinimumAuthenticationRequestIdLength
auth_req_id is of sufficient length
actual
464
required
128
2021-02-10 09:54:31 SUCCESS
EnsureMinimumAuthenticationRequestIdEntropy
Calculated shannon entropy seems sufficient
actual
295.88859473647204
expected
96.0
2021-02-10 09:54:31 SUCCESS
EnsureRecommendedAuthenticationRequestIdEntropy
Calculated entropy
actual
295.88859473647204
recommended
160.0
2021-02-10 09:54:31 SUCCESS
ValidateAuthenticationRequestIdExpiresIn
expires_in passed all validation checks
expires_in
120
2021-02-10 09:54:31 SUCCESS
ValidateAuthenticationRequestIdInterval
interval passed all validation checks
interval
3
Second client: Call token endpoint expecting pending
2021-02-10 09:54:31 SUCCESS
CreateTokenEndpointRequestForCIBAGrant
grant_type
urn:openid:params:grant-type:ciba
2021-02-10 09:54:31
AddAuthReqIdToTokenEndpointRequest
grant_type
urn:openid:params:grant-type:ciba
auth_req_id
rGexz4_wnsxo9uWdqBOzuZV9u6NHJABgI63PWJ8A2gbIJCXizrcUUFAAtA
2021-02-10 09:54:31 SUCCESS
CreateClientAuthenticationAssertionClaims
Created client assertion claims
iss
conformance4ping
sub
conformance4ping
aud
https://emea-conformance.ping-eng.com:9032/as/token.oauth2
jti
2YUSxDlrolyaiEI5igEf
iat
1612950871
exp
1612950931
2021-02-10 09:54:31 SUCCESS
SignClientAuthenticationAssertion
Signed the client assertion
client_assertion
eyJraWQiOiI2d2FCQ0FKS3VLTXZTVTNrNTQwWEhQeF80Z0p4MDF0bVFoOGdpYVlqajFrIiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTRwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTRwaW5nIiwiZXhwIjoxNjEyOTUwOTMxLCJpYXQiOjE2MTI5NTA4NzEsImp0aSI6IjJZVVN4RGxyb2x5YWlFSTVpZ0VmIn0.Jj4LDchaDrOV497qsiwTqjq7fFc2YDh0wBt_Qnr2Z3sDTpk1tfsu-kWEKFKnH0QEirr1eJBWIS57Vi92Azu8_Q
2021-02-10 09:54:31
AddClientAssertionToTokenEndpointRequest
Added client assertion
grant_type
urn:openid:params:grant-type:ciba
auth_req_id
rGexz4_wnsxo9uWdqBOzuZV9u6NHJABgI63PWJ8A2gbIJCXizrcUUFAAtA
client_assertion
eyJraWQiOiI2d2FCQ0FKS3VLTXZTVTNrNTQwWEhQeF80Z0p4MDF0bVFoOGdpYVlqajFrIiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTRwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTRwaW5nIiwiZXhwIjoxNjEyOTUwOTMxLCJpYXQiOjE2MTI5NTA4NzEsImp0aSI6IjJZVVN4RGxyb2x5YWlFSTVpZ0VmIn0.Jj4LDchaDrOV497qsiwTqjq7fFc2YDh0wBt_Qnr2Z3sDTpk1tfsu-kWEKFKnH0QEirr1eJBWIS57Vi92Azu8_Q
client_assertion_type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-02-10 09:54:32
CallTokenEndpointAndReturnFullResponse
HTTP request
request_uri
https://emea-conformance.ping-eng.com:9032/as/token.oauth2
request_method
POST
request_headers
{
  "accept": "application/json;charset\u003dUTF-8",
  "accept-charset": "utf-8",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "653"
}
request_body
grant_type=urn%3Aopenid%3Aparams%3Agrant-type%3Aciba&auth_req_id=rGexz4_wnsxo9uWdqBOzuZV9u6NHJABgI63PWJ8A2gbIJCXizrcUUFAAtA&client_assertion=eyJraWQiOiI2d2FCQ0FKS3VLTXZTVTNrNTQwWEhQeF80Z0p4MDF0bVFoOGdpYVlqajFrIiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTRwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTRwaW5nIiwiZXhwIjoxNjEyOTUwOTMxLCJpYXQiOjE2MTI5NTA4NzEsImp0aSI6IjJZVVN4RGxyb2x5YWlFSTVpZ0VmIn0.Jj4LDchaDrOV497qsiwTqjq7fFc2YDh0wBt_Qnr2Z3sDTpk1tfsu-kWEKFKnH0QEirr1eJBWIS57Vi92Azu8_Q&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
request_mutual_tls
{
  "cert": "MIIDhTCCAm2gAwIBAgIJAKAe4HusBvwoMA0GCSqGSIb3DQEBCwUAMFgxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMSEwHwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQxETAPBgNVBAMMCGNsaWVudF8yMCAXDTE4MDcwMjE2MzUyOFoYDzIxMDYwMjExMTYzNTI4WjBYMQswCQYDVQQGEwJVUzETMBEGA1UECAwKU29tZS1TdGF0ZTEhMB8GA1UECgwYSW50ZXJuZXQgV2lkZ2l0cyBQdHkgTHRkMREwDwYDVQQDDAhjbGllbnRfMjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANMy1QohUbUoyte8cYCCO1+vJ/GImvVkrb79HUTSzL3G46lDC0JYZGMpMvX9NncadCYLQV8fmofOouNs4AWJgf0skH5sAJcZMgj3GVqqLsx2iDye3cgqsCCzTf5gzhOVtpXgNoBMFckVGxI+dG9h06n71mH9dtGoD/BoWOB4FLae0Ec4olot5eROeJ3Z0J15aXPWoQrn3J5Eoz0/c7D7+byb+XGjF/r+uJVrKqOLtnO69Ro99fowwVtVQAPHmxLQ9VvFiLONwbOfELtBvX4MlxHDOuynDsDw/mHxkzMSxPXAd9QfIU05ySZ9eVR3UfNUeCk8a63NSO8MZdfHFnUsEO8CAwEAAaNQME4wHQYDVR0OBBYEFFEdch1XYRpO5JXxPkBxdAoAt6IiMB8GA1UdIwQYMBaAFFEdch1XYRpO5JXxPkBxdAoAt6IiMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBABTTN0up/ndWCNamqrV8ik1XwUqPCAO7TYKmZrRilo3STxyp2aUiFf1uPSkU6WU4Eu0JoDKU46axIFzZO3Ckoq17JMde2OzESlAF+hQyvg/3l+6mbBK/OuzOiC+yfU9roD6vmjsBlH0My1+CnqkZLr6YQSaCHfflb6zqA7+aLUEWjyVneD6jQ6CCFwCs6eDorY1eKFM7lCQ5OdJFBc2LOOXuSGRXLZDKF3X2SfKCld0VWIOknJk8drfrCc1ylWa7wIuXU/kTyX8Z68a8w1/6ZkGxN9tsHWVtSe6ggOD1AFI5OQ3c8lCUzgGeFl69hz2UduHOyWs1KXUhgSy7fViAP90\u003d",
  "key": "MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQDTMtUKIVG1KMrXvHGAgjtfryfxiJr1ZK2+/R1E0sy9xuOpQwtCWGRjKTL1/TZ3GnQmC0FfH5qHzqLjbOAFiYH9LJB+bACXGTII9xlaqi7Mdog8nt3IKrAgs03+YM4TlbaV4DaATBXJFRsSPnRvYdOp+9Zh/XbRqA/waFjgeBS2ntBHOKJaLeXkTnid2dCdeWlz1qEK59yeRKM9P3Ow+/m8m/lxoxf6/riVayqji7ZzuvUaPfX6MMFbVUADx5sS0PVbxYizjcGznxC7Qb1+DJcRwzrspw7A8P5h8ZMzEsT1wHfUHyFNOckmfXlUd1HzVHgpPGutzUjvDGXXxxZ1LBDvAgMBAAECggEBAJzGiiB39VheTJzy1OqJQhvYQPVp62Wn89XnvLdfJ/7kShFWpF/+j56QcbTq32hwabHn/wHmyuZvPLlIE8/ocGcIksZV0+ZWHK9NBjQoSo8ami0t3QJ+tbnAgHAJWlBtfVkqVCrO0AkxsqPLWtFntCDlwhGBfpdJg3N5cihG21FnnqUNxj2lVp1jxCAAcBHwCMfODFi0Kke/FLS3u9vHSRybUAbNid1adNJ6g3f3jKXhX5HPR2KYqDIyCQrqs9IAx7mM/T2W75NpZC1rW5GAWyw7sR71YDFI/Mronrdh0ZiHOpllwgM4bBD7ipNH3jNRgsAUr5nyTIJAii9z8XxGubkCgYEA+e88Kt3uZbFfcqTvb2ZTCUd3fyC0FcZ+/iHhKp2fmwsSIWB7k6++q8Vn/YHdew7KS+i4dvap30+k8Jf0u8p1NY82qHb5b/8igj6z015O+q1XE+hNoPUeIlX7JBVf0y3NIiiOTxvcWoIGKpthEVvlVk27PfYUEsnefFnKTQ7kNI0CgYEA2FLxXKrDQQRwtmC0My4LuAwhkGqxCwk1V8vD0k+J1JqVI3qQPxt5H241KtWwdb6QxAjuBe0i1Yx6vW1qC60NaZpM7RLFOEKyfwLuk19S9BKs1q0BRqcPpIP0PIZ+GgpKs7fIWcn19IFI/1KlSVYYV7qDgDmzMG13OPeJuAclAmsCgYBIyIdgAGMlUCL4ktl7OnQh9qLw7Ygj8zsWLK2SqHZLQ00TVTKHjp1bDlC7PW9PH75/npThZ/GOK3Zf7hCCA3Jgl4UWSBdZqxXUkgfyHLupOoNqM7MvlVIiM6HAH01ZhTQAp4jRts5TuRusmrUIxhciK97EK34q/oiA8/D6wcRpHQKBgBWbY0RQQiRyXxe4XQdnqAAAJjIYlgp2Jv/X+H0/OJMlxZO/oDzNb7G1/lWC9pcsK6WJBs1MvFf8Kh5VmWwFIvvTT6+2WkCeWNna3x2VPeHnI6Bls2TtNuDF1VVeUaYkNQXya26cf5amezYVeTD0CoZouM3L9Zv2sxvbjcP14rp1AoGADoxlSjWxXOxZAr835wFlD3EMU5nhUGA0BdCfGgKqMaZmCr/ssfQDARgCKG/zLfmUBBBHbjZcHMXw6SW+E3CTN/q7iddT3FOgVder4GWTA+wFYdAywCT5At8wm7zeM2d/4cWlBaKew/u+A0ycUsD6bd3gRXjBZpD8Eep8ltVGLHw\u003d"
}
2021-02-10 09:54:32 RESPONSE
CallTokenEndpointAndReturnFullResponse
HTTP response
response_status_code
400 BAD_REQUEST
response_status_text
Bad Request
response_headers
{
  "date": "Wed, 10 Feb 2021 09:54:32 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003dBxHMF81u5RMIZM6kxhmCTw;Path\u003d/;Secure;HttpOnly;SameSite\u003dNone",
  "transfer-encoding": "chunked"
}
response_body
{"error_description":"Pending user authorization","error":"authorization_pending"}
2021-02-10 09:54:32 SUCCESS
CallTokenEndpointAndReturnFullResponse
Parsed token endpoint response
error_description
Pending user authorization
error
authorization_pending
2021-02-10 09:54:32 SUCCESS
CheckTokenEndpointReturnedJsonContentType
token_endpoint_response_headers Content-Type: header is application/json
Second client: Verify token endpoint response is pending or slow_down
2021-02-10 09:54:32 SUCCESS
CheckTokenEndpointHttpStatus400
Token endpoint http status code was 400
2021-02-10 09:54:32 SUCCESS
ValidateErrorFromTokenEndpointResponseError
Token endpoint response error returned valid 'error' field
error
authorization_pending
2021-02-10 09:54:32 SUCCESS
CheckErrorDescriptionFromTokenEndpointResponseErrorContainsCRLFTAB
token_endpoint_response 'error_description' field does not include CR/LF/TAB
error_description
Pending user authorization
2021-02-10 09:54:32 SUCCESS
ValidateErrorDescriptionFromTokenEndpointResponseError
token_endpoint_response error returned valid 'error_description' field
error_description
Pending user authorization
2021-02-10 09:54:32 SUCCESS
ValidateErrorUriFromTokenEndpointResponseError
token_endpoint_response did not include optional 'error_uri' field
2021-02-10 09:54:32 SUCCESS
EnsureErrorTokenEndpointSlowdownOrAuthorizationPending
error met 'slow_down' or 'authorization_pending'
error
authorization_pending
Second client: Call token endpoint expecting pending (second time)
2021-02-10 09:54:37 SUCCESS
CreateTokenEndpointRequestForCIBAGrant
grant_type
urn:openid:params:grant-type:ciba
2021-02-10 09:54:37
AddAuthReqIdToTokenEndpointRequest
grant_type
urn:openid:params:grant-type:ciba
auth_req_id
rGexz4_wnsxo9uWdqBOzuZV9u6NHJABgI63PWJ8A2gbIJCXizrcUUFAAtA
2021-02-10 09:54:37 SUCCESS
CreateClientAuthenticationAssertionClaims
Created client assertion claims
iss
conformance4ping
sub
conformance4ping
aud
https://emea-conformance.ping-eng.com:9032/as/token.oauth2
jti
e65UUiQxh7saNY3QI3GO
iat
1612950877
exp
1612950937
2021-02-10 09:54:37 SUCCESS
SignClientAuthenticationAssertion
Signed the client assertion
client_assertion
eyJraWQiOiI2d2FCQ0FKS3VLTXZTVTNrNTQwWEhQeF80Z0p4MDF0bVFoOGdpYVlqajFrIiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTRwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTRwaW5nIiwiZXhwIjoxNjEyOTUwOTM3LCJpYXQiOjE2MTI5NTA4NzcsImp0aSI6ImU2NVVVaVF4aDdzYU5ZM1FJM0dPIn0.Lg_mX6nIXQoGBvBmAGBolqoCH7uNQZZmJzrg4KnaTcmezn5QsAtSs82WYts0fJxGarA1yKFqpTUzD5Gd8dk3CQ
2021-02-10 09:54:37
AddClientAssertionToTokenEndpointRequest
Added client assertion
grant_type
urn:openid:params:grant-type:ciba
auth_req_id
rGexz4_wnsxo9uWdqBOzuZV9u6NHJABgI63PWJ8A2gbIJCXizrcUUFAAtA
client_assertion
eyJraWQiOiI2d2FCQ0FKS3VLTXZTVTNrNTQwWEhQeF80Z0p4MDF0bVFoOGdpYVlqajFrIiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTRwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTRwaW5nIiwiZXhwIjoxNjEyOTUwOTM3LCJpYXQiOjE2MTI5NTA4NzcsImp0aSI6ImU2NVVVaVF4aDdzYU5ZM1FJM0dPIn0.Lg_mX6nIXQoGBvBmAGBolqoCH7uNQZZmJzrg4KnaTcmezn5QsAtSs82WYts0fJxGarA1yKFqpTUzD5Gd8dk3CQ
client_assertion_type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-02-10 09:54:37
CallTokenEndpointAndReturnFullResponse
HTTP request
request_uri
https://emea-conformance.ping-eng.com:9032/as/token.oauth2
request_method
POST
request_headers
{
  "accept": "application/json;charset\u003dUTF-8",
  "accept-charset": "utf-8",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "653"
}
request_body
grant_type=urn%3Aopenid%3Aparams%3Agrant-type%3Aciba&auth_req_id=rGexz4_wnsxo9uWdqBOzuZV9u6NHJABgI63PWJ8A2gbIJCXizrcUUFAAtA&client_assertion=eyJraWQiOiI2d2FCQ0FKS3VLTXZTVTNrNTQwWEhQeF80Z0p4MDF0bVFoOGdpYVlqajFrIiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTRwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTRwaW5nIiwiZXhwIjoxNjEyOTUwOTM3LCJpYXQiOjE2MTI5NTA4NzcsImp0aSI6ImU2NVVVaVF4aDdzYU5ZM1FJM0dPIn0.Lg_mX6nIXQoGBvBmAGBolqoCH7uNQZZmJzrg4KnaTcmezn5QsAtSs82WYts0fJxGarA1yKFqpTUzD5Gd8dk3CQ&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
request_mutual_tls
{
  "cert": "MIIDhTCCAm2gAwIBAgIJAKAe4HusBvwoMA0GCSqGSIb3DQEBCwUAMFgxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMSEwHwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQxETAPBgNVBAMMCGNsaWVudF8yMCAXDTE4MDcwMjE2MzUyOFoYDzIxMDYwMjExMTYzNTI4WjBYMQswCQYDVQQGEwJVUzETMBEGA1UECAwKU29tZS1TdGF0ZTEhMB8GA1UECgwYSW50ZXJuZXQgV2lkZ2l0cyBQdHkgTHRkMREwDwYDVQQDDAhjbGllbnRfMjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANMy1QohUbUoyte8cYCCO1+vJ/GImvVkrb79HUTSzL3G46lDC0JYZGMpMvX9NncadCYLQV8fmofOouNs4AWJgf0skH5sAJcZMgj3GVqqLsx2iDye3cgqsCCzTf5gzhOVtpXgNoBMFckVGxI+dG9h06n71mH9dtGoD/BoWOB4FLae0Ec4olot5eROeJ3Z0J15aXPWoQrn3J5Eoz0/c7D7+byb+XGjF/r+uJVrKqOLtnO69Ro99fowwVtVQAPHmxLQ9VvFiLONwbOfELtBvX4MlxHDOuynDsDw/mHxkzMSxPXAd9QfIU05ySZ9eVR3UfNUeCk8a63NSO8MZdfHFnUsEO8CAwEAAaNQME4wHQYDVR0OBBYEFFEdch1XYRpO5JXxPkBxdAoAt6IiMB8GA1UdIwQYMBaAFFEdch1XYRpO5JXxPkBxdAoAt6IiMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBABTTN0up/ndWCNamqrV8ik1XwUqPCAO7TYKmZrRilo3STxyp2aUiFf1uPSkU6WU4Eu0JoDKU46axIFzZO3Ckoq17JMde2OzESlAF+hQyvg/3l+6mbBK/OuzOiC+yfU9roD6vmjsBlH0My1+CnqkZLr6YQSaCHfflb6zqA7+aLUEWjyVneD6jQ6CCFwCs6eDorY1eKFM7lCQ5OdJFBc2LOOXuSGRXLZDKF3X2SfKCld0VWIOknJk8drfrCc1ylWa7wIuXU/kTyX8Z68a8w1/6ZkGxN9tsHWVtSe6ggOD1AFI5OQ3c8lCUzgGeFl69hz2UduHOyWs1KXUhgSy7fViAP90\u003d",
  "key": "MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQDTMtUKIVG1KMrXvHGAgjtfryfxiJr1ZK2+/R1E0sy9xuOpQwtCWGRjKTL1/TZ3GnQmC0FfH5qHzqLjbOAFiYH9LJB+bACXGTII9xlaqi7Mdog8nt3IKrAgs03+YM4TlbaV4DaATBXJFRsSPnRvYdOp+9Zh/XbRqA/waFjgeBS2ntBHOKJaLeXkTnid2dCdeWlz1qEK59yeRKM9P3Ow+/m8m/lxoxf6/riVayqji7ZzuvUaPfX6MMFbVUADx5sS0PVbxYizjcGznxC7Qb1+DJcRwzrspw7A8P5h8ZMzEsT1wHfUHyFNOckmfXlUd1HzVHgpPGutzUjvDGXXxxZ1LBDvAgMBAAECggEBAJzGiiB39VheTJzy1OqJQhvYQPVp62Wn89XnvLdfJ/7kShFWpF/+j56QcbTq32hwabHn/wHmyuZvPLlIE8/ocGcIksZV0+ZWHK9NBjQoSo8ami0t3QJ+tbnAgHAJWlBtfVkqVCrO0AkxsqPLWtFntCDlwhGBfpdJg3N5cihG21FnnqUNxj2lVp1jxCAAcBHwCMfODFi0Kke/FLS3u9vHSRybUAbNid1adNJ6g3f3jKXhX5HPR2KYqDIyCQrqs9IAx7mM/T2W75NpZC1rW5GAWyw7sR71YDFI/Mronrdh0ZiHOpllwgM4bBD7ipNH3jNRgsAUr5nyTIJAii9z8XxGubkCgYEA+e88Kt3uZbFfcqTvb2ZTCUd3fyC0FcZ+/iHhKp2fmwsSIWB7k6++q8Vn/YHdew7KS+i4dvap30+k8Jf0u8p1NY82qHb5b/8igj6z015O+q1XE+hNoPUeIlX7JBVf0y3NIiiOTxvcWoIGKpthEVvlVk27PfYUEsnefFnKTQ7kNI0CgYEA2FLxXKrDQQRwtmC0My4LuAwhkGqxCwk1V8vD0k+J1JqVI3qQPxt5H241KtWwdb6QxAjuBe0i1Yx6vW1qC60NaZpM7RLFOEKyfwLuk19S9BKs1q0BRqcPpIP0PIZ+GgpKs7fIWcn19IFI/1KlSVYYV7qDgDmzMG13OPeJuAclAmsCgYBIyIdgAGMlUCL4ktl7OnQh9qLw7Ygj8zsWLK2SqHZLQ00TVTKHjp1bDlC7PW9PH75/npThZ/GOK3Zf7hCCA3Jgl4UWSBdZqxXUkgfyHLupOoNqM7MvlVIiM6HAH01ZhTQAp4jRts5TuRusmrUIxhciK97EK34q/oiA8/D6wcRpHQKBgBWbY0RQQiRyXxe4XQdnqAAAJjIYlgp2Jv/X+H0/OJMlxZO/oDzNb7G1/lWC9pcsK6WJBs1MvFf8Kh5VmWwFIvvTT6+2WkCeWNna3x2VPeHnI6Bls2TtNuDF1VVeUaYkNQXya26cf5amezYVeTD0CoZouM3L9Zv2sxvbjcP14rp1AoGADoxlSjWxXOxZAr835wFlD3EMU5nhUGA0BdCfGgKqMaZmCr/ssfQDARgCKG/zLfmUBBBHbjZcHMXw6SW+E3CTN/q7iddT3FOgVder4GWTA+wFYdAywCT5At8wm7zeM2d/4cWlBaKew/u+A0ycUsD6bd3gRXjBZpD8Eep8ltVGLHw\u003d"
}
2021-02-10 09:54:37 RESPONSE
CallTokenEndpointAndReturnFullResponse
HTTP response
response_status_code
400 BAD_REQUEST
response_status_text
Bad Request
response_headers
{
  "date": "Wed, 10 Feb 2021 09:54:37 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003dS7G3pjPjE7WwrdkqxaX4n3;Path\u003d/;Secure;HttpOnly;SameSite\u003dNone",
  "transfer-encoding": "chunked"
}
response_body
{"error_description":"Pending user authorization","error":"authorization_pending"}
2021-02-10 09:54:37 SUCCESS
CallTokenEndpointAndReturnFullResponse
Parsed token endpoint response
error_description
Pending user authorization
error
authorization_pending
2021-02-10 09:54:37 SUCCESS
CheckTokenEndpointReturnedJsonContentType
token_endpoint_response_headers Content-Type: header is application/json
Second client: Verify token endpoint response is pending or slow_down
2021-02-10 09:54:37 SUCCESS
CheckTokenEndpointHttpStatus400
Token endpoint http status code was 400
2021-02-10 09:54:37 SUCCESS
ValidateErrorFromTokenEndpointResponseError
Token endpoint response error returned valid 'error' field
error
authorization_pending
2021-02-10 09:54:37 SUCCESS
CheckErrorDescriptionFromTokenEndpointResponseErrorContainsCRLFTAB
token_endpoint_response 'error_description' field does not include CR/LF/TAB
error_description
Pending user authorization
2021-02-10 09:54:37 SUCCESS
ValidateErrorDescriptionFromTokenEndpointResponseError
token_endpoint_response error returned valid 'error_description' field
error_description
Pending user authorization
2021-02-10 09:54:37 SUCCESS
ValidateErrorUriFromTokenEndpointResponseError
token_endpoint_response did not include optional 'error_uri' field
2021-02-10 09:54:37 SUCCESS
EnsureErrorTokenEndpointSlowdownOrAuthorizationPending
error met 'slow_down' or 'authorization_pending'
error
authorization_pending
2021-02-10 09:54:37
CallAutomatedCibaApprovalEndpoint
If your server supports automated testing, you can set 'automated_ciba_approval_url' in your configuration to a url like https://cibasim.example.com/action?token={auth_req_id}&type={action} (auth_req_id will be automatically substituted for the current auth_req_id by the conformance suite, action will be allow or deny depending on the test)
2021-02-10 09:54:37
TellUserToDoCIBAAuthentication
Please authenticate and authorize the request
2021-02-10 09:54:43 INCOMING
fapi-ciba-id1-refresh-token
Incoming HTTP request to test instance HgQnndsopXRfcwQ
incoming_headers
{
  "host": "www.certification.openid.net",
  "authorization": "Bearer 785jHa-oj+Sc89ORvCv8\u003d",
  "content-type": "application/json; charset\u003dUTF-8",
  "user-agent": "PingFederate",
  "accept-encoding": "gzip,deflate",
  "x-ssl-cipher": "ECDHE-RSA-AES256-GCM-SHA384",
  "x-ssl-protocol": "TLSv1.2",
  "content-length": "76",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net",
  "connection": "close"
}
incoming_path
ciba-notification-endpoint
incoming_body_form_params
incoming_method
POST
incoming_body_json
{
  "auth_req_id": "rGexz4_wnsxo9uWdqBOzuZV9u6NHJABgI63PWJ8A2gbIJCXizrcUUFAAtA"
}
incoming_query_string_params
{}
incoming_body
{"auth_req_id":"rGexz4_wnsxo9uWdqBOzuZV9u6NHJABgI63PWJ8A2gbIJCXizrcUUFAAtA"}
2021-02-10 09:54:43 OUTGOING
fapi-ciba-id1-refresh-token
Response to HTTP request to test instance HgQnndsopXRfcwQ
outgoing_status_code
204
outgoing_headers
{}
outgoing_body

                                
outgoing_path
ciba-notification-endpoint
Second client: Verify notification callback
2021-02-10 09:54:43 SUCCESS
EnsureIncomingTls12
Found TLS 1.2 connection
2021-02-10 09:54:43 SUCCESS
EnsureIncomingTlsSecureCipher
TLS cipher is allowed
actual
ECDHE-RSA-AES256-GCM-SHA384
expected
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-02-10 09:54:43 SUCCESS
CheckIncomingContentTypeIsApplicationJson
Incoming request Content-Type: header has the expected value
content_type
application/json; charset=UTF-8
expected
application/json
2021-02-10 09:54:43 SUCCESS
VerifyBearerTokenHeaderCallback
'Authorization' header in notification callback contained client_notification_token.
2021-02-10 09:54:43
CheckAuthReqIdInCallback
notification_callback contents
headers
{
  "host": "www.certification.openid.net",
  "authorization": "Bearer 785jHa-oj+Sc89ORvCv8\u003d",
  "content-type": "application/json; charset\u003dUTF-8",
  "user-agent": "PingFederate",
  "accept-encoding": "gzip,deflate",
  "x-ssl-cipher": "ECDHE-RSA-AES256-GCM-SHA384",
  "x-ssl-protocol": "TLSv1.2",
  "content-length": "76",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net",
  "connection": "close"
}
query_string_params
{}
method
POST
body
{"auth_req_id":"rGexz4_wnsxo9uWdqBOzuZV9u6NHJABgI63PWJ8A2gbIJCXizrcUUFAAtA"}
body_json
{
  "auth_req_id": "rGexz4_wnsxo9uWdqBOzuZV9u6NHJABgI63PWJ8A2gbIJCXizrcUUFAAtA"
}
2021-02-10 09:54:43 SUCCESS
CheckAuthReqIdInCallback
auth_req_id valued received in callback is correct
2021-02-10 09:54:43 SUCCESS
CheckNotificationCallbackOnlyAuthReqId
body received in notification callback contained only auth_req_id
body
{
  "auth_req_id": "rGexz4_wnsxo9uWdqBOzuZV9u6NHJABgI63PWJ8A2gbIJCXizrcUUFAAtA"
}
Second client: Calling token endpoint after ping notification
2021-02-10 09:54:43 SUCCESS
CreateTokenEndpointRequestForCIBAGrant
grant_type
urn:openid:params:grant-type:ciba
2021-02-10 09:54:43
AddAuthReqIdToTokenEndpointRequest
grant_type
urn:openid:params:grant-type:ciba
auth_req_id
rGexz4_wnsxo9uWdqBOzuZV9u6NHJABgI63PWJ8A2gbIJCXizrcUUFAAtA
2021-02-10 09:54:43 SUCCESS
CreateClientAuthenticationAssertionClaims
Created client assertion claims
iss
conformance4ping
sub
conformance4ping
aud
https://emea-conformance.ping-eng.com:9032/as/token.oauth2
jti
ooQpBQlTiVmzPpoP1TJp
iat
1612950883
exp
1612950943
2021-02-10 09:54:43 SUCCESS
SignClientAuthenticationAssertion
Signed the client assertion
client_assertion
eyJraWQiOiI2d2FCQ0FKS3VLTXZTVTNrNTQwWEhQeF80Z0p4MDF0bVFoOGdpYVlqajFrIiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTRwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTRwaW5nIiwiZXhwIjoxNjEyOTUwOTQzLCJpYXQiOjE2MTI5NTA4ODMsImp0aSI6Im9vUXBCUWxUaVZtelBwb1AxVEpwIn0.Ci0PXqs8R59hSQpUarmWHd41WvLQkVd1yRr3sOrifXb_KTSA87yuceH7FSCuGa4Hog-MawxfHYsWph5q5LRkAw
2021-02-10 09:54:43
AddClientAssertionToTokenEndpointRequest
Added client assertion
grant_type
urn:openid:params:grant-type:ciba
auth_req_id
rGexz4_wnsxo9uWdqBOzuZV9u6NHJABgI63PWJ8A2gbIJCXizrcUUFAAtA
client_assertion
eyJraWQiOiI2d2FCQ0FKS3VLTXZTVTNrNTQwWEhQeF80Z0p4MDF0bVFoOGdpYVlqajFrIiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTRwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTRwaW5nIiwiZXhwIjoxNjEyOTUwOTQzLCJpYXQiOjE2MTI5NTA4ODMsImp0aSI6Im9vUXBCUWxUaVZtelBwb1AxVEpwIn0.Ci0PXqs8R59hSQpUarmWHd41WvLQkVd1yRr3sOrifXb_KTSA87yuceH7FSCuGa4Hog-MawxfHYsWph5q5LRkAw
client_assertion_type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-02-10 09:54:43
CallTokenEndpointAndReturnFullResponse
HTTP request
request_uri
https://emea-conformance.ping-eng.com:9032/as/token.oauth2
request_method
POST
request_headers
{
  "accept": "application/json;charset\u003dUTF-8",
  "accept-charset": "utf-8",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "653"
}
request_body
grant_type=urn%3Aopenid%3Aparams%3Agrant-type%3Aciba&auth_req_id=rGexz4_wnsxo9uWdqBOzuZV9u6NHJABgI63PWJ8A2gbIJCXizrcUUFAAtA&client_assertion=eyJraWQiOiI2d2FCQ0FKS3VLTXZTVTNrNTQwWEhQeF80Z0p4MDF0bVFoOGdpYVlqajFrIiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTRwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTRwaW5nIiwiZXhwIjoxNjEyOTUwOTQzLCJpYXQiOjE2MTI5NTA4ODMsImp0aSI6Im9vUXBCUWxUaVZtelBwb1AxVEpwIn0.Ci0PXqs8R59hSQpUarmWHd41WvLQkVd1yRr3sOrifXb_KTSA87yuceH7FSCuGa4Hog-MawxfHYsWph5q5LRkAw&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
request_mutual_tls
{
  "cert": "MIIDhTCCAm2gAwIBAgIJAKAe4HusBvwoMA0GCSqGSIb3DQEBCwUAMFgxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMSEwHwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQxETAPBgNVBAMMCGNsaWVudF8yMCAXDTE4MDcwMjE2MzUyOFoYDzIxMDYwMjExMTYzNTI4WjBYMQswCQYDVQQGEwJVUzETMBEGA1UECAwKU29tZS1TdGF0ZTEhMB8GA1UECgwYSW50ZXJuZXQgV2lkZ2l0cyBQdHkgTHRkMREwDwYDVQQDDAhjbGllbnRfMjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANMy1QohUbUoyte8cYCCO1+vJ/GImvVkrb79HUTSzL3G46lDC0JYZGMpMvX9NncadCYLQV8fmofOouNs4AWJgf0skH5sAJcZMgj3GVqqLsx2iDye3cgqsCCzTf5gzhOVtpXgNoBMFckVGxI+dG9h06n71mH9dtGoD/BoWOB4FLae0Ec4olot5eROeJ3Z0J15aXPWoQrn3J5Eoz0/c7D7+byb+XGjF/r+uJVrKqOLtnO69Ro99fowwVtVQAPHmxLQ9VvFiLONwbOfELtBvX4MlxHDOuynDsDw/mHxkzMSxPXAd9QfIU05ySZ9eVR3UfNUeCk8a63NSO8MZdfHFnUsEO8CAwEAAaNQME4wHQYDVR0OBBYEFFEdch1XYRpO5JXxPkBxdAoAt6IiMB8GA1UdIwQYMBaAFFEdch1XYRpO5JXxPkBxdAoAt6IiMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBABTTN0up/ndWCNamqrV8ik1XwUqPCAO7TYKmZrRilo3STxyp2aUiFf1uPSkU6WU4Eu0JoDKU46axIFzZO3Ckoq17JMde2OzESlAF+hQyvg/3l+6mbBK/OuzOiC+yfU9roD6vmjsBlH0My1+CnqkZLr6YQSaCHfflb6zqA7+aLUEWjyVneD6jQ6CCFwCs6eDorY1eKFM7lCQ5OdJFBc2LOOXuSGRXLZDKF3X2SfKCld0VWIOknJk8drfrCc1ylWa7wIuXU/kTyX8Z68a8w1/6ZkGxN9tsHWVtSe6ggOD1AFI5OQ3c8lCUzgGeFl69hz2UduHOyWs1KXUhgSy7fViAP90\u003d",
  "key": "MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQDTMtUKIVG1KMrXvHGAgjtfryfxiJr1ZK2+/R1E0sy9xuOpQwtCWGRjKTL1/TZ3GnQmC0FfH5qHzqLjbOAFiYH9LJB+bACXGTII9xlaqi7Mdog8nt3IKrAgs03+YM4TlbaV4DaATBXJFRsSPnRvYdOp+9Zh/XbRqA/waFjgeBS2ntBHOKJaLeXkTnid2dCdeWlz1qEK59yeRKM9P3Ow+/m8m/lxoxf6/riVayqji7ZzuvUaPfX6MMFbVUADx5sS0PVbxYizjcGznxC7Qb1+DJcRwzrspw7A8P5h8ZMzEsT1wHfUHyFNOckmfXlUd1HzVHgpPGutzUjvDGXXxxZ1LBDvAgMBAAECggEBAJzGiiB39VheTJzy1OqJQhvYQPVp62Wn89XnvLdfJ/7kShFWpF/+j56QcbTq32hwabHn/wHmyuZvPLlIE8/ocGcIksZV0+ZWHK9NBjQoSo8ami0t3QJ+tbnAgHAJWlBtfVkqVCrO0AkxsqPLWtFntCDlwhGBfpdJg3N5cihG21FnnqUNxj2lVp1jxCAAcBHwCMfODFi0Kke/FLS3u9vHSRybUAbNid1adNJ6g3f3jKXhX5HPR2KYqDIyCQrqs9IAx7mM/T2W75NpZC1rW5GAWyw7sR71YDFI/Mronrdh0ZiHOpllwgM4bBD7ipNH3jNRgsAUr5nyTIJAii9z8XxGubkCgYEA+e88Kt3uZbFfcqTvb2ZTCUd3fyC0FcZ+/iHhKp2fmwsSIWB7k6++q8Vn/YHdew7KS+i4dvap30+k8Jf0u8p1NY82qHb5b/8igj6z015O+q1XE+hNoPUeIlX7JBVf0y3NIiiOTxvcWoIGKpthEVvlVk27PfYUEsnefFnKTQ7kNI0CgYEA2FLxXKrDQQRwtmC0My4LuAwhkGqxCwk1V8vD0k+J1JqVI3qQPxt5H241KtWwdb6QxAjuBe0i1Yx6vW1qC60NaZpM7RLFOEKyfwLuk19S9BKs1q0BRqcPpIP0PIZ+GgpKs7fIWcn19IFI/1KlSVYYV7qDgDmzMG13OPeJuAclAmsCgYBIyIdgAGMlUCL4ktl7OnQh9qLw7Ygj8zsWLK2SqHZLQ00TVTKHjp1bDlC7PW9PH75/npThZ/GOK3Zf7hCCA3Jgl4UWSBdZqxXUkgfyHLupOoNqM7MvlVIiM6HAH01ZhTQAp4jRts5TuRusmrUIxhciK97EK34q/oiA8/D6wcRpHQKBgBWbY0RQQiRyXxe4XQdnqAAAJjIYlgp2Jv/X+H0/OJMlxZO/oDzNb7G1/lWC9pcsK6WJBs1MvFf8Kh5VmWwFIvvTT6+2WkCeWNna3x2VPeHnI6Bls2TtNuDF1VVeUaYkNQXya26cf5amezYVeTD0CoZouM3L9Zv2sxvbjcP14rp1AoGADoxlSjWxXOxZAr835wFlD3EMU5nhUGA0BdCfGgKqMaZmCr/ssfQDARgCKG/zLfmUBBBHbjZcHMXw6SW+E3CTN/q7iddT3FOgVder4GWTA+wFYdAywCT5At8wm7zeM2d/4cWlBaKew/u+A0ycUsD6bd3gRXjBZpD8Eep8ltVGLHw\u003d"
}
2021-02-10 09:54:43 RESPONSE
CallTokenEndpointAndReturnFullResponse
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "date": "Wed, 10 Feb 2021 09:54:43 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003dwLIQ2osD9eZAnjiu8hwRdv;Path\u003d/;Secure;HttpOnly;SameSite\u003dNone",
  "transfer-encoding": "chunked"
}
response_body
{"access_token":"eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2U0cGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiJVckV1X3VqVG9hc0w5YWlkanB1eWhCR0Q4SUtvbDJTN1lfeG9GLUFJUGVnIn0sImV4cCI6MTYxMjk1ODA4M30.Rl9r7-Dfz6LHuUIp_X5e6OnAsOdn6vrOA1mGvdmSidK1olpc9QRV3clS7rN907jEpKMBlapsf-sFK8gevknGgy9XBH3YEx2biZrSTBbDIT5pOF534zLDFe2C2vnX8fjzrz-LBJGFjU6ytEP2fBOGj1N_aXv4Li0lvD8uINgduRfwtoayx9A_eMWV0j-BMgrpSUeB2B5WVO4d66J24UekXN7FPSPcLxY-m0YBljxGjU3SsuMw-Odo5hPLQzLcoSby3XjjKMV0IIucH6qBVnr4Ube25Z4nXMTnnOz3j3OsqtDjYeT53IwxKjzANSr6E2Z5OnvcjyAZNBec5E1n6xKVrw","refresh_token":"m1SkwtC0l87VFFln0u6hZZzS8RsIvxeD0wrwVWMFNt","scope":"openid test","id_token":"eyJhbGciOiJFUzI1NiIsImtpZCI6IkhHcDFJRVFNMXZvUVNxNDZJQXZrXzFZUnFhRSJ9.eyJzdWIiOiJwYXRyaWNrIiwiYXVkIjoiY29uZm9ybWFuY2U0cGluZyIsImp0aSI6IjJlbEdEMENJYVNsSFdWQmp6Z3ZORE0iLCJpc3MiOiJodHRwczovL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2MTI5NTA4ODMsImV4cCI6MTYxMjk1MTE4M30.ET7r9xAQ8m9MznFhIZi0eXjVaq4hm0m7Po8y62ISef-0T3y8CRqXfFyd1Xz_CvC29aTuJGFPG-wBdIui_q7xkQ","token_type":"Bearer","expires_in":7199}
2021-02-10 09:54:43 SUCCESS
CallTokenEndpointAndReturnFullResponse
Parsed token endpoint response
access_token
eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2U0cGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiJVckV1X3VqVG9hc0w5YWlkanB1eWhCR0Q4SUtvbDJTN1lfeG9GLUFJUGVnIn0sImV4cCI6MTYxMjk1ODA4M30.Rl9r7-Dfz6LHuUIp_X5e6OnAsOdn6vrOA1mGvdmSidK1olpc9QRV3clS7rN907jEpKMBlapsf-sFK8gevknGgy9XBH3YEx2biZrSTBbDIT5pOF534zLDFe2C2vnX8fjzrz-LBJGFjU6ytEP2fBOGj1N_aXv4Li0lvD8uINgduRfwtoayx9A_eMWV0j-BMgrpSUeB2B5WVO4d66J24UekXN7FPSPcLxY-m0YBljxGjU3SsuMw-Odo5hPLQzLcoSby3XjjKMV0IIucH6qBVnr4Ube25Z4nXMTnnOz3j3OsqtDjYeT53IwxKjzANSr6E2Z5OnvcjyAZNBec5E1n6xKVrw
refresh_token
m1SkwtC0l87VFFln0u6hZZzS8RsIvxeD0wrwVWMFNt
scope
openid test
id_token
eyJhbGciOiJFUzI1NiIsImtpZCI6IkhHcDFJRVFNMXZvUVNxNDZJQXZrXzFZUnFhRSJ9.eyJzdWIiOiJwYXRyaWNrIiwiYXVkIjoiY29uZm9ybWFuY2U0cGluZyIsImp0aSI6IjJlbEdEMENJYVNsSFdWQmp6Z3ZORE0iLCJpc3MiOiJodHRwczovL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2MTI5NTA4ODMsImV4cCI6MTYxMjk1MTE4M30.ET7r9xAQ8m9MznFhIZi0eXjVaq4hm0m7Po8y62ISef-0T3y8CRqXfFyd1Xz_CvC29aTuJGFPG-wBdIui_q7xkQ
token_type
Bearer
expires_in
7199
2021-02-10 09:54:43 SUCCESS
CheckTokenEndpointReturnedJsonContentType
token_endpoint_response_headers Content-Type: header is application/json
Second client: Verify token endpoint response
2021-02-10 09:54:43 SUCCESS
CheckTokenEndpointHttpStatus200
Token endpoint http status code was 200
2021-02-10 09:54:43 SUCCESS
CheckTokenEndpointCacheHeaders
'pragma' and 'cache-control' headers in token endpoint response contain expected values.
cache_control_header
no-cache, no-store
pragma_header
no-cache
2021-02-10 09:54:43 SUCCESS
CheckIfTokenEndpointResponseError
No error from token endpoint
2021-02-10 09:54:43 SUCCESS
CheckForAccessTokenValue
Found an access token
access_token
eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2U0cGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiJVckV1X3VqVG9hc0w5YWlkanB1eWhCR0Q4SUtvbDJTN1lfeG9GLUFJUGVnIn0sImV4cCI6MTYxMjk1ODA4M30.Rl9r7-Dfz6LHuUIp_X5e6OnAsOdn6vrOA1mGvdmSidK1olpc9QRV3clS7rN907jEpKMBlapsf-sFK8gevknGgy9XBH3YEx2biZrSTBbDIT5pOF534zLDFe2C2vnX8fjzrz-LBJGFjU6ytEP2fBOGj1N_aXv4Li0lvD8uINgduRfwtoayx9A_eMWV0j-BMgrpSUeB2B5WVO4d66J24UekXN7FPSPcLxY-m0YBljxGjU3SsuMw-Odo5hPLQzLcoSby3XjjKMV0IIucH6qBVnr4Ube25Z4nXMTnnOz3j3OsqtDjYeT53IwxKjzANSr6E2Z5OnvcjyAZNBec5E1n6xKVrw
2021-02-10 09:54:43 SUCCESS
ExtractAccessTokenFromTokenResponse
Extracted the access token
value
eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2U0cGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiJVckV1X3VqVG9hc0w5YWlkanB1eWhCR0Q4SUtvbDJTN1lfeG9GLUFJUGVnIn0sImV4cCI6MTYxMjk1ODA4M30.Rl9r7-Dfz6LHuUIp_X5e6OnAsOdn6vrOA1mGvdmSidK1olpc9QRV3clS7rN907jEpKMBlapsf-sFK8gevknGgy9XBH3YEx2biZrSTBbDIT5pOF534zLDFe2C2vnX8fjzrz-LBJGFjU6ytEP2fBOGj1N_aXv4Li0lvD8uINgduRfwtoayx9A_eMWV0j-BMgrpSUeB2B5WVO4d66J24UekXN7FPSPcLxY-m0YBljxGjU3SsuMw-Odo5hPLQzLcoSby3XjjKMV0IIucH6qBVnr4Ube25Z4nXMTnnOz3j3OsqtDjYeT53IwxKjzANSr6E2Z5OnvcjyAZNBec5E1n6xKVrw
type
Bearer
2021-02-10 09:54:43 SUCCESS
ExtractExpiresInFromTokenEndpointResponse
Extracted 'expires_in'
expires_in
7199
2021-02-10 09:54:43 SUCCESS
ValidateExpiresIn
expires_in passed all validation checks
expires_in
7199
2021-02-10 09:54:43 SUCCESS
CheckForRefreshTokenValue
Found a refresh token
refresh_token
m1SkwtC0l87VFFln0u6hZZzS8RsIvxeD0wrwVWMFNt
2021-02-10 09:54:43 SUCCESS
EnsureMinimumRefreshTokenLength
Refresh token is of sufficient length
actual
336
required
128
2021-02-10 09:54:43 SUCCESS
EnsureMinimumRefreshTokenEntropy
Calculated shannon entropy seems sufficient
actual
200.21266925021754
expected
96.0
2021-02-10 09:54:43 SUCCESS
EnsureMinimumAccessTokenLength
Access token is of sufficient length
actual
4824
required
128
2021-02-10 09:54:43 SUCCESS
EnsureMinimumAccessTokenEntropy
Calculated shannon entropy seems sufficient
actual
3540.4770729677134
expected
96.0
2021-02-10 09:54:43 SUCCESS
ExtractIdTokenFromTokenResponse
Found and parsed the id_token from token_endpoint_response
value
eyJhbGciOiJFUzI1NiIsImtpZCI6IkhHcDFJRVFNMXZvUVNxNDZJQXZrXzFZUnFhRSJ9.eyJzdWIiOiJwYXRyaWNrIiwiYXVkIjoiY29uZm9ybWFuY2U0cGluZyIsImp0aSI6IjJlbEdEMENJYVNsSFdWQmp6Z3ZORE0iLCJpc3MiOiJodHRwczovL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2MTI5NTA4ODMsImV4cCI6MTYxMjk1MTE4M30.ET7r9xAQ8m9MznFhIZi0eXjVaq4hm0m7Po8y62ISef-0T3y8CRqXfFyd1Xz_CvC29aTuJGFPG-wBdIui_q7xkQ
header
{
  "kid": "HGp1IEQM1voQSq46IAvk_1YRqaE",
  "alg": "ES256"
}
claims
{
  "sub": "patrick",
  "aud": "conformance4ping",
  "iss": "https://emea-conformance.ping-eng.com:9031",
  "exp": 1612951183,
  "iat": 1612950883,
  "jti": "2elGD0CIaSlHWVBjzgvNDM"
}
2021-02-10 09:54:43 SUCCESS
ValidateIdToken
ID token iss, aud, exp, iat, auth_time, acr & nbf claims passed validation checks
2021-02-10 09:54:43 SUCCESS
EnsureIdTokenContainsKid
kid was found in the ID token header
kid
HGp1IEQM1voQSq46IAvk_1YRqaE
2021-02-10 09:54:43 SUCCESS
ValidateIdTokenSignature
id_token signature validated
id_token
eyJhbGciOiJFUzI1NiIsImtpZCI6IkhHcDFJRVFNMXZvUVNxNDZJQXZrXzFZUnFhRSJ9.eyJzdWIiOiJwYXRyaWNrIiwiYXVkIjoiY29uZm9ybWFuY2U0cGluZyIsImp0aSI6IjJlbEdEMENJYVNsSFdWQmp6Z3ZORE0iLCJpc3MiOiJodHRwczovL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2MTI5NTA4ODMsImV4cCI6MTYxMjk1MTE4M30.ET7r9xAQ8m9MznFhIZi0eXjVaq4hm0m7Po8y62ISef-0T3y8CRqXfFyd1Xz_CvC29aTuJGFPG-wBdIui_q7xkQ
2021-02-10 09:54:43 SUCCESS
ValidateIdTokenSignatureUsingKid
id_token signature validated
id_token
eyJhbGciOiJFUzI1NiIsImtpZCI6IkhHcDFJRVFNMXZvUVNxNDZJQXZrXzFZUnFhRSJ9.eyJzdWIiOiJwYXRyaWNrIiwiYXVkIjoiY29uZm9ybWFuY2U0cGluZyIsImp0aSI6IjJlbEdEMENJYVNsSFdWQmp6Z3ZORE0iLCJpc3MiOiJodHRwczovL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2MTI5NTA4ODMsImV4cCI6MTYxMjk1MTE4M30.ET7r9xAQ8m9MznFhIZi0eXjVaq4hm0m7Po8y62ISef-0T3y8CRqXfFyd1Xz_CvC29aTuJGFPG-wBdIui_q7xkQ
2021-02-10 09:54:43 SUCCESS
CheckForSubjectInIdToken
Found 'sub' in id_token
sub
patrick
2021-02-10 09:54:43 SUCCESS
FAPIValidateIdTokenSigningAlg
id_token was signed with a permitted algorithm
alg
ES256
2021-02-10 09:54:43 INFO
FAPIValidateIdTokenEncryptionAlg
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2021-02-10 09:54:43 INFO
FAPIValidateEncryptedIdTokenHasKid
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2021-02-10 09:54:43 INFO
FAPICIBAValidateIdTokenAuthRequestIdClaims
Skipped evaluation due to missing required element: id_token claims.urn:openid:params:jwt:claim:auth_req_id
path
claims.urn:openid:params:jwt:claim:auth_req_id
mapped
object
id_token
2021-02-10 09:54:43 SUCCESS
ValidateIdTokenNotIncludeCHashAndSHash
id_token claims correctly does not contain 'c_hash' and 's_hash'
claims
{
  "sub": "patrick",
  "aud": "conformance4ping",
  "iss": "https://emea-conformance.ping-eng.com:9031",
  "exp": 1612951183,
  "iat": 1612950883,
  "jti": "2elGD0CIaSlHWVBjzgvNDM"
}
2021-02-10 09:54:43 INFO
ExtractAtHash
Couldn't find at_hash in ID token
2021-02-10 09:54:43 INFO
ExtractRtHash
Couldn't find urn:openid:params:jwt:claim:rt_hash claim in the ID token
2021-02-10 09:54:43 INFO
FAPICIBAValidateRtHash
Skipped evaluation due to missing required object: rt_hash
expected
rt_hash
mapped
2021-02-10 09:54:43 INFO
ValidateAtHash
Skipped evaluation due to missing required object: at_hash
expected
at_hash
mapped
Second client: Check for refresh token
2021-02-10 09:54:43 SUCCESS
ExtractRefreshTokenFromTokenResponse
Extracted refresh token from response
refresh_token
m1SkwtC0l87VFFln0u6hZZzS8RsIvxeD0wrwVWMFNt
2021-02-10 09:54:43 SUCCESS
EnsureServerConfigurationSupportsRefreshToken
The server configuration indicates support for refresh tokens
supported_grant_types
[
  "implicit",
  "authorization_code",
  "refresh_token",
  "password",
  "client_credentials",
  "urn:pingidentity.com:oauth2:grant_type:validate_bearer",
  "urn:ietf:params:oauth:grant-type:jwt-bearer",
  "urn:ietf:params:oauth:grant-type:saml2-bearer",
  "urn:ietf:params:oauth:grant-type:device_code",
  "urn:ietf:params:oauth:grant-type:token-exchange",
  "urn:openid:params:grant-type:ciba"
]
2021-02-10 09:54:43 SUCCESS
EnsureRefreshTokenContainsAllowedCharactersOnly
Refresh token does not contain any illegal characters
Second client: Refresh Token Request
2021-02-10 09:54:43 SUCCESS
CreateRefreshTokenRequest
Created token endpoint request parameters
grant_type
refresh_token
refresh_token
m1SkwtC0l87VFFln0u6hZZzS8RsIvxeD0wrwVWMFNt
2021-02-10 09:54:43 SUCCESS
CreateClientAuthenticationAssertionClaims
Created client assertion claims
iss
conformance4ping
sub
conformance4ping
aud
https://emea-conformance.ping-eng.com:9032/as/token.oauth2
jti
i4YBeO0nMJfIEkUCJE8T
iat
1612950883
exp
1612950943
2021-02-10 09:54:43 SUCCESS
SignClientAuthenticationAssertion
Signed the client assertion
client_assertion
eyJraWQiOiI2d2FCQ0FKS3VLTXZTVTNrNTQwWEhQeF80Z0p4MDF0bVFoOGdpYVlqajFrIiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTRwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTRwaW5nIiwiZXhwIjoxNjEyOTUwOTQzLCJpYXQiOjE2MTI5NTA4ODMsImp0aSI6Imk0WUJlTzBuTUpmSUVrVUNKRThUIn0.URELvbGHO3erA9FAenDiUJTeQfkiwOJls-b2PCT3uNI4B4KEh5psKxJGec8OouPZruyi6LDfVeE653B-ERZoDg
2021-02-10 09:54:43
AddClientAssertionToTokenEndpointRequest
Added client assertion
grant_type
refresh_token
refresh_token
m1SkwtC0l87VFFln0u6hZZzS8RsIvxeD0wrwVWMFNt
client_assertion
eyJraWQiOiI2d2FCQ0FKS3VLTXZTVTNrNTQwWEhQeF80Z0p4MDF0bVFoOGdpYVlqajFrIiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTRwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTRwaW5nIiwiZXhwIjoxNjEyOTUwOTQzLCJpYXQiOjE2MTI5NTA4ODMsImp0aSI6Imk0WUJlTzBuTUpmSUVrVUNKRThUIn0.URELvbGHO3erA9FAenDiUJTeQfkiwOJls-b2PCT3uNI4B4KEh5psKxJGec8OouPZruyi6LDfVeE653B-ERZoDg
client_assertion_type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-02-10 09:54:43 SUCCESS
WaitForOneSecond
Pausing for 1 seconds
2021-02-10 09:54:44 SUCCESS
WaitForOneSecond
Woke up after 1 seconds sleep
2021-02-10 09:54:44
CallTokenEndpointAndReturnFullResponse
HTTP request
request_uri
https://emea-conformance.ping-eng.com:9032/as/token.oauth2
request_method
POST
request_headers
{
  "accept": "application/json;charset\u003dUTF-8",
  "accept-charset": "utf-8",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "611"
}
request_body
grant_type=refresh_token&refresh_token=m1SkwtC0l87VFFln0u6hZZzS8RsIvxeD0wrwVWMFNt&client_assertion=eyJraWQiOiI2d2FCQ0FKS3VLTXZTVTNrNTQwWEhQeF80Z0p4MDF0bVFoOGdpYVlqajFrIiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTRwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTRwaW5nIiwiZXhwIjoxNjEyOTUwOTQzLCJpYXQiOjE2MTI5NTA4ODMsImp0aSI6Imk0WUJlTzBuTUpmSUVrVUNKRThUIn0.URELvbGHO3erA9FAenDiUJTeQfkiwOJls-b2PCT3uNI4B4KEh5psKxJGec8OouPZruyi6LDfVeE653B-ERZoDg&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
request_mutual_tls
{
  "cert": "MIIDhTCCAm2gAwIBAgIJAKAe4HusBvwoMA0GCSqGSIb3DQEBCwUAMFgxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMSEwHwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQxETAPBgNVBAMMCGNsaWVudF8yMCAXDTE4MDcwMjE2MzUyOFoYDzIxMDYwMjExMTYzNTI4WjBYMQswCQYDVQQGEwJVUzETMBEGA1UECAwKU29tZS1TdGF0ZTEhMB8GA1UECgwYSW50ZXJuZXQgV2lkZ2l0cyBQdHkgTHRkMREwDwYDVQQDDAhjbGllbnRfMjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANMy1QohUbUoyte8cYCCO1+vJ/GImvVkrb79HUTSzL3G46lDC0JYZGMpMvX9NncadCYLQV8fmofOouNs4AWJgf0skH5sAJcZMgj3GVqqLsx2iDye3cgqsCCzTf5gzhOVtpXgNoBMFckVGxI+dG9h06n71mH9dtGoD/BoWOB4FLae0Ec4olot5eROeJ3Z0J15aXPWoQrn3J5Eoz0/c7D7+byb+XGjF/r+uJVrKqOLtnO69Ro99fowwVtVQAPHmxLQ9VvFiLONwbOfELtBvX4MlxHDOuynDsDw/mHxkzMSxPXAd9QfIU05ySZ9eVR3UfNUeCk8a63NSO8MZdfHFnUsEO8CAwEAAaNQME4wHQYDVR0OBBYEFFEdch1XYRpO5JXxPkBxdAoAt6IiMB8GA1UdIwQYMBaAFFEdch1XYRpO5JXxPkBxdAoAt6IiMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBABTTN0up/ndWCNamqrV8ik1XwUqPCAO7TYKmZrRilo3STxyp2aUiFf1uPSkU6WU4Eu0JoDKU46axIFzZO3Ckoq17JMde2OzESlAF+hQyvg/3l+6mbBK/OuzOiC+yfU9roD6vmjsBlH0My1+CnqkZLr6YQSaCHfflb6zqA7+aLUEWjyVneD6jQ6CCFwCs6eDorY1eKFM7lCQ5OdJFBc2LOOXuSGRXLZDKF3X2SfKCld0VWIOknJk8drfrCc1ylWa7wIuXU/kTyX8Z68a8w1/6ZkGxN9tsHWVtSe6ggOD1AFI5OQ3c8lCUzgGeFl69hz2UduHOyWs1KXUhgSy7fViAP90\u003d",
  "key": "MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQDTMtUKIVG1KMrXvHGAgjtfryfxiJr1ZK2+/R1E0sy9xuOpQwtCWGRjKTL1/TZ3GnQmC0FfH5qHzqLjbOAFiYH9LJB+bACXGTII9xlaqi7Mdog8nt3IKrAgs03+YM4TlbaV4DaATBXJFRsSPnRvYdOp+9Zh/XbRqA/waFjgeBS2ntBHOKJaLeXkTnid2dCdeWlz1qEK59yeRKM9P3Ow+/m8m/lxoxf6/riVayqji7ZzuvUaPfX6MMFbVUADx5sS0PVbxYizjcGznxC7Qb1+DJcRwzrspw7A8P5h8ZMzEsT1wHfUHyFNOckmfXlUd1HzVHgpPGutzUjvDGXXxxZ1LBDvAgMBAAECggEBAJzGiiB39VheTJzy1OqJQhvYQPVp62Wn89XnvLdfJ/7kShFWpF/+j56QcbTq32hwabHn/wHmyuZvPLlIE8/ocGcIksZV0+ZWHK9NBjQoSo8ami0t3QJ+tbnAgHAJWlBtfVkqVCrO0AkxsqPLWtFntCDlwhGBfpdJg3N5cihG21FnnqUNxj2lVp1jxCAAcBHwCMfODFi0Kke/FLS3u9vHSRybUAbNid1adNJ6g3f3jKXhX5HPR2KYqDIyCQrqs9IAx7mM/T2W75NpZC1rW5GAWyw7sR71YDFI/Mronrdh0ZiHOpllwgM4bBD7ipNH3jNRgsAUr5nyTIJAii9z8XxGubkCgYEA+e88Kt3uZbFfcqTvb2ZTCUd3fyC0FcZ+/iHhKp2fmwsSIWB7k6++q8Vn/YHdew7KS+i4dvap30+k8Jf0u8p1NY82qHb5b/8igj6z015O+q1XE+hNoPUeIlX7JBVf0y3NIiiOTxvcWoIGKpthEVvlVk27PfYUEsnefFnKTQ7kNI0CgYEA2FLxXKrDQQRwtmC0My4LuAwhkGqxCwk1V8vD0k+J1JqVI3qQPxt5H241KtWwdb6QxAjuBe0i1Yx6vW1qC60NaZpM7RLFOEKyfwLuk19S9BKs1q0BRqcPpIP0PIZ+GgpKs7fIWcn19IFI/1KlSVYYV7qDgDmzMG13OPeJuAclAmsCgYBIyIdgAGMlUCL4ktl7OnQh9qLw7Ygj8zsWLK2SqHZLQ00TVTKHjp1bDlC7PW9PH75/npThZ/GOK3Zf7hCCA3Jgl4UWSBdZqxXUkgfyHLupOoNqM7MvlVIiM6HAH01ZhTQAp4jRts5TuRusmrUIxhciK97EK34q/oiA8/D6wcRpHQKBgBWbY0RQQiRyXxe4XQdnqAAAJjIYlgp2Jv/X+H0/OJMlxZO/oDzNb7G1/lWC9pcsK6WJBs1MvFf8Kh5VmWwFIvvTT6+2WkCeWNna3x2VPeHnI6Bls2TtNuDF1VVeUaYkNQXya26cf5amezYVeTD0CoZouM3L9Zv2sxvbjcP14rp1AoGADoxlSjWxXOxZAr835wFlD3EMU5nhUGA0BdCfGgKqMaZmCr/ssfQDARgCKG/zLfmUBBBHbjZcHMXw6SW+E3CTN/q7iddT3FOgVder4GWTA+wFYdAywCT5At8wm7zeM2d/4cWlBaKew/u+A0ycUsD6bd3gRXjBZpD8Eep8ltVGLHw\u003d"
}
2021-02-10 09:54:45 RESPONSE
CallTokenEndpointAndReturnFullResponse
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "date": "Wed, 10 Feb 2021 09:54:45 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003d5dfp5qU3rduJhtWobv7gUI;Path\u003d/;Secure;HttpOnly;SameSite\u003dNone",
  "transfer-encoding": "chunked"
}
response_body
{"access_token":"eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2U0cGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiJVckV1X3VqVG9hc0w5YWlkanB1eWhCR0Q4SUtvbDJTN1lfeG9GLUFJUGVnIn0sImV4cCI6MTYxMjk1ODA4NX0.XUgJoPD0-8YAA9Osp5MXNIcojV5dF1cEdbhg0StdByX3iHLtz-8Spnsu8ddfL8jplUkKEfOCky4Rp8Pg6EYwDRoDJy2N39DO--M5Z9fbGEQCoHtRE-vHhOx1zeoXCfh3pbrgTzABpdW5uc2bxpTrMp-yIHTaD-h0qveorZanD5M96YcnBNCExSqRHcaHUxGkOCIHpmMZUZfR1FkV4fCVzjYmHo-NVMFEO72Er_289h_zJgykzR0Qjdztal9ZYcvALSMIBCSCYsyBReJlzD064VslXrbsVIKSHB0yg7QrXXm6gusRDnNSKYqC3e80yZiwhU2avfTOKlKgXA27beypiQ","token_type":"Bearer","expires_in":7199}
2021-02-10 09:54:45 SUCCESS
CallTokenEndpointAndReturnFullResponse
Parsed token endpoint response
access_token
eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2U0cGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiJVckV1X3VqVG9hc0w5YWlkanB1eWhCR0Q4SUtvbDJTN1lfeG9GLUFJUGVnIn0sImV4cCI6MTYxMjk1ODA4NX0.XUgJoPD0-8YAA9Osp5MXNIcojV5dF1cEdbhg0StdByX3iHLtz-8Spnsu8ddfL8jplUkKEfOCky4Rp8Pg6EYwDRoDJy2N39DO--M5Z9fbGEQCoHtRE-vHhOx1zeoXCfh3pbrgTzABpdW5uc2bxpTrMp-yIHTaD-h0qveorZanD5M96YcnBNCExSqRHcaHUxGkOCIHpmMZUZfR1FkV4fCVzjYmHo-NVMFEO72Er_289h_zJgykzR0Qjdztal9ZYcvALSMIBCSCYsyBReJlzD064VslXrbsVIKSHB0yg7QrXXm6gusRDnNSKYqC3e80yZiwhU2avfTOKlKgXA27beypiQ
token_type
Bearer
expires_in
7199
2021-02-10 09:54:45 SUCCESS
CheckTokenEndpointHttpStatus200
Token endpoint http status code was 200
2021-02-10 09:54:45 SUCCESS
CheckTokenEndpointReturnedJsonContentType
token_endpoint_response_headers Content-Type: header is application/json
2021-02-10 09:54:45 SUCCESS
CheckTokenEndpointCacheHeaders
'pragma' and 'cache-control' headers in token endpoint response contain expected values.
cache_control_header
no-cache, no-store
pragma_header
no-cache
2021-02-10 09:54:45 SUCCESS
CheckIfTokenEndpointResponseError
No error from token endpoint
2021-02-10 09:54:45 SUCCESS
ExtractAccessTokenFromTokenResponse
Extracted the access token
value
eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2U0cGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiJVckV1X3VqVG9hc0w5YWlkanB1eWhCR0Q4SUtvbDJTN1lfeG9GLUFJUGVnIn0sImV4cCI6MTYxMjk1ODA4NX0.XUgJoPD0-8YAA9Osp5MXNIcojV5dF1cEdbhg0StdByX3iHLtz-8Spnsu8ddfL8jplUkKEfOCky4Rp8Pg6EYwDRoDJy2N39DO--M5Z9fbGEQCoHtRE-vHhOx1zeoXCfh3pbrgTzABpdW5uc2bxpTrMp-yIHTaD-h0qveorZanD5M96YcnBNCExSqRHcaHUxGkOCIHpmMZUZfR1FkV4fCVzjYmHo-NVMFEO72Er_289h_zJgykzR0Qjdztal9ZYcvALSMIBCSCYsyBReJlzD064VslXrbsVIKSHB0yg7QrXXm6gusRDnNSKYqC3e80yZiwhU2avfTOKlKgXA27beypiQ
type
Bearer
2021-02-10 09:54:45 SUCCESS
CheckTokenTypeIsBearer
Token type is bearer
2021-02-10 09:54:45 SUCCESS
EnsureMinimumAccessTokenEntropy
Calculated shannon entropy seems sufficient
actual
3551.551647889437
expected
96.0
2021-02-10 09:54:45 SUCCESS
EnsureAccessTokenContainsAllowedCharactersOnly
Access token does not contain any illegal characters
2021-02-10 09:54:45 SUCCESS
ExtractExpiresInFromTokenEndpointResponse
Extracted 'expires_in'
expires_in
7199
2021-02-10 09:54:45 SUCCESS
ValidateExpiresIn
expires_in passed all validation checks
expires_in
7199
2021-02-10 09:54:45 SUCCESS
EnsureAccessTokenValuesAreDifferent
Access token values are not the same
first_access_token
eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2U0cGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiJVckV1X3VqVG9hc0w5YWlkanB1eWhCR0Q4SUtvbDJTN1lfeG9GLUFJUGVnIn0sImV4cCI6MTYxMjk1ODA4M30.Rl9r7-Dfz6LHuUIp_X5e6OnAsOdn6vrOA1mGvdmSidK1olpc9QRV3clS7rN907jEpKMBlapsf-sFK8gevknGgy9XBH3YEx2biZrSTBbDIT5pOF534zLDFe2C2vnX8fjzrz-LBJGFjU6ytEP2fBOGj1N_aXv4Li0lvD8uINgduRfwtoayx9A_eMWV0j-BMgrpSUeB2B5WVO4d66J24UekXN7FPSPcLxY-m0YBljxGjU3SsuMw-Odo5hPLQzLcoSby3XjjKMV0IIucH6qBVnr4Ube25Z4nXMTnnOz3j3OsqtDjYeT53IwxKjzANSr6E2Z5OnvcjyAZNBec5E1n6xKVrw
second_access_token
eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2U0cGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiJVckV1X3VqVG9hc0w5YWlkanB1eWhCR0Q4SUtvbDJTN1lfeG9GLUFJUGVnIn0sImV4cCI6MTYxMjk1ODA4NX0.XUgJoPD0-8YAA9Osp5MXNIcojV5dF1cEdbhg0StdByX3iHLtz-8Spnsu8ddfL8jplUkKEfOCky4Rp8Pg6EYwDRoDJy2N39DO--M5Z9fbGEQCoHtRE-vHhOx1zeoXCfh3pbrgTzABpdW5uc2bxpTrMp-yIHTaD-h0qveorZanD5M96YcnBNCExSqRHcaHUxGkOCIHpmMZUZfR1FkV4fCVzjYmHo-NVMFEO72Er_289h_zJgykzR0Qjdztal9ZYcvALSMIBCSCYsyBReJlzD064VslXrbsVIKSHB0yg7QrXXm6gusRDnNSKYqC3e80yZiwhU2avfTOKlKgXA27beypiQ
2021-02-10 09:54:45 INFO
ExtractIdTokenFromTokenResponse
Couldn't find id_token in token_endpoint_response
2021-02-10 09:54:45 INFO
ExtractRefreshTokenFromTokenResponse
Token endpoint response does not contain a refresh token
2021-02-10 09:54:45 INFO
EnsureMinimumRefreshTokenLength
Skipped evaluation due to missing required element: token_endpoint_response refresh_token
path
refresh_token
mapped
object
token_endpoint_response
2021-02-10 09:54:45 INFO
EnsureMinimumRefreshTokenEntropy
Skipped evaluation due to missing required element: token_endpoint_response refresh_token
path
refresh_token
mapped
object
token_endpoint_response
2021-02-10 09:54:45 INFO
CompareIdTokenClaims
Skipped evaluation due to missing required object: second_id_token
expected
second_id_token
mapped
second_id_token
Second client: Resource server endpoint tests
2021-02-10 09:54:45
CreateEmptyResourceEndpointRequestHeaders
Created empty headers
resource_endpoint_request_headers
{}
2021-02-10 09:54:45
CallProtectedResourceWithBearerTokenAndCustomHeaders
HTTP request
request_uri
https://emea-conformance.ping-eng.com:3000/get
request_method
GET
request_headers
{
  "accept": "application/json;charset\u003dUTF-8",
  "authorization": "Bearer eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2U0cGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiJVckV1X3VqVG9hc0w5YWlkanB1eWhCR0Q4SUtvbDJTN1lfeG9GLUFJUGVnIn0sImV4cCI6MTYxMjk1ODA4NX0.XUgJoPD0-8YAA9Osp5MXNIcojV5dF1cEdbhg0StdByX3iHLtz-8Spnsu8ddfL8jplUkKEfOCky4Rp8Pg6EYwDRoDJy2N39DO--M5Z9fbGEQCoHtRE-vHhOx1zeoXCfh3pbrgTzABpdW5uc2bxpTrMp-yIHTaD-h0qveorZanD5M96YcnBNCExSqRHcaHUxGkOCIHpmMZUZfR1FkV4fCVzjYmHo-NVMFEO72Er_289h_zJgykzR0Qjdztal9ZYcvALSMIBCSCYsyBReJlzD064VslXrbsVIKSHB0yg7QrXXm6gusRDnNSKYqC3e80yZiwhU2avfTOKlKgXA27beypiQ",
  "accept-charset": "utf-8",
  "content-length": "0"
}
request_body

                                
request_mutual_tls
{
  "cert": "MIIDhTCCAm2gAwIBAgIJAKAe4HusBvwoMA0GCSqGSIb3DQEBCwUAMFgxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMSEwHwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQxETAPBgNVBAMMCGNsaWVudF8yMCAXDTE4MDcwMjE2MzUyOFoYDzIxMDYwMjExMTYzNTI4WjBYMQswCQYDVQQGEwJVUzETMBEGA1UECAwKU29tZS1TdGF0ZTEhMB8GA1UECgwYSW50ZXJuZXQgV2lkZ2l0cyBQdHkgTHRkMREwDwYDVQQDDAhjbGllbnRfMjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANMy1QohUbUoyte8cYCCO1+vJ/GImvVkrb79HUTSzL3G46lDC0JYZGMpMvX9NncadCYLQV8fmofOouNs4AWJgf0skH5sAJcZMgj3GVqqLsx2iDye3cgqsCCzTf5gzhOVtpXgNoBMFckVGxI+dG9h06n71mH9dtGoD/BoWOB4FLae0Ec4olot5eROeJ3Z0J15aXPWoQrn3J5Eoz0/c7D7+byb+XGjF/r+uJVrKqOLtnO69Ro99fowwVtVQAPHmxLQ9VvFiLONwbOfELtBvX4MlxHDOuynDsDw/mHxkzMSxPXAd9QfIU05ySZ9eVR3UfNUeCk8a63NSO8MZdfHFnUsEO8CAwEAAaNQME4wHQYDVR0OBBYEFFEdch1XYRpO5JXxPkBxdAoAt6IiMB8GA1UdIwQYMBaAFFEdch1XYRpO5JXxPkBxdAoAt6IiMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBABTTN0up/ndWCNamqrV8ik1XwUqPCAO7TYKmZrRilo3STxyp2aUiFf1uPSkU6WU4Eu0JoDKU46axIFzZO3Ckoq17JMde2OzESlAF+hQyvg/3l+6mbBK/OuzOiC+yfU9roD6vmjsBlH0My1+CnqkZLr6YQSaCHfflb6zqA7+aLUEWjyVneD6jQ6CCFwCs6eDorY1eKFM7lCQ5OdJFBc2LOOXuSGRXLZDKF3X2SfKCld0VWIOknJk8drfrCc1ylWa7wIuXU/kTyX8Z68a8w1/6ZkGxN9tsHWVtSe6ggOD1AFI5OQ3c8lCUzgGeFl69hz2UduHOyWs1KXUhgSy7fViAP90\u003d",
  "key": "MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQDTMtUKIVG1KMrXvHGAgjtfryfxiJr1ZK2+/R1E0sy9xuOpQwtCWGRjKTL1/TZ3GnQmC0FfH5qHzqLjbOAFiYH9LJB+bACXGTII9xlaqi7Mdog8nt3IKrAgs03+YM4TlbaV4DaATBXJFRsSPnRvYdOp+9Zh/XbRqA/waFjgeBS2ntBHOKJaLeXkTnid2dCdeWlz1qEK59yeRKM9P3Ow+/m8m/lxoxf6/riVayqji7ZzuvUaPfX6MMFbVUADx5sS0PVbxYizjcGznxC7Qb1+DJcRwzrspw7A8P5h8ZMzEsT1wHfUHyFNOckmfXlUd1HzVHgpPGutzUjvDGXXxxZ1LBDvAgMBAAECggEBAJzGiiB39VheTJzy1OqJQhvYQPVp62Wn89XnvLdfJ/7kShFWpF/+j56QcbTq32hwabHn/wHmyuZvPLlIE8/ocGcIksZV0+ZWHK9NBjQoSo8ami0t3QJ+tbnAgHAJWlBtfVkqVCrO0AkxsqPLWtFntCDlwhGBfpdJg3N5cihG21FnnqUNxj2lVp1jxCAAcBHwCMfODFi0Kke/FLS3u9vHSRybUAbNid1adNJ6g3f3jKXhX5HPR2KYqDIyCQrqs9IAx7mM/T2W75NpZC1rW5GAWyw7sR71YDFI/Mronrdh0ZiHOpllwgM4bBD7ipNH3jNRgsAUr5nyTIJAii9z8XxGubkCgYEA+e88Kt3uZbFfcqTvb2ZTCUd3fyC0FcZ+/iHhKp2fmwsSIWB7k6++q8Vn/YHdew7KS+i4dvap30+k8Jf0u8p1NY82qHb5b/8igj6z015O+q1XE+hNoPUeIlX7JBVf0y3NIiiOTxvcWoIGKpthEVvlVk27PfYUEsnefFnKTQ7kNI0CgYEA2FLxXKrDQQRwtmC0My4LuAwhkGqxCwk1V8vD0k+J1JqVI3qQPxt5H241KtWwdb6QxAjuBe0i1Yx6vW1qC60NaZpM7RLFOEKyfwLuk19S9BKs1q0BRqcPpIP0PIZ+GgpKs7fIWcn19IFI/1KlSVYYV7qDgDmzMG13OPeJuAclAmsCgYBIyIdgAGMlUCL4ktl7OnQh9qLw7Ygj8zsWLK2SqHZLQ00TVTKHjp1bDlC7PW9PH75/npThZ/GOK3Zf7hCCA3Jgl4UWSBdZqxXUkgfyHLupOoNqM7MvlVIiM6HAH01ZhTQAp4jRts5TuRusmrUIxhciK97EK34q/oiA8/D6wcRpHQKBgBWbY0RQQiRyXxe4XQdnqAAAJjIYlgp2Jv/X+H0/OJMlxZO/oDzNb7G1/lWC9pcsK6WJBs1MvFf8Kh5VmWwFIvvTT6+2WkCeWNna3x2VPeHnI6Bls2TtNuDF1VVeUaYkNQXya26cf5amezYVeTD0CoZouM3L9Zv2sxvbjcP14rp1AoGADoxlSjWxXOxZAr835wFlD3EMU5nhUGA0BdCfGgKqMaZmCr/ssfQDARgCKG/zLfmUBBBHbjZcHMXw6SW+E3CTN/q7iddT3FOgVder4GWTA+wFYdAywCT5At8wm7zeM2d/4cWlBaKew/u+A0ycUsD6bd3gRXjBZpD8Eep8ltVGLHw\u003d"
}
2021-02-10 09:54:46 RESPONSE
CallProtectedResourceWithBearerTokenAndCustomHeaders
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "date": "Wed, 10 Feb 2021 09:54:46 GMT",
  "content-type": "application/json",
  "content-length": "1066",
  "server": "gunicorn/19.9.0",
  "access-control-allow-origin": "*",
  "access-control-allow-credentials": "true",
  "x-fapi-interaction-id": "a3b2c5a3-2851-405c-9678-0adf8afeefdc"
}
response_body
{
  "args": {}, 
  "headers": {
    "Accept": "application/json;charset=UTF-8", 
    "Accept-Charset": "utf-8", 
    "Accept-Encoding": "gzip,deflate", 
    "Authorization": "Bearer eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2U0cGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiJVckV1X3VqVG9hc0w5YWlkanB1eWhCR0Q4SUtvbDJTN1lfeG9GLUFJUGVnIn0sImV4cCI6MTYxMjk1ODA4NX0.XUgJoPD0-8YAA9Osp5MXNIcojV5dF1cEdbhg0StdByX3iHLtz-8Spnsu8ddfL8jplUkKEfOCky4Rp8Pg6EYwDRoDJy2N39DO--M5Z9fbGEQCoHtRE-vHhOx1zeoXCfh3pbrgTzABpdW5uc2bxpTrMp-yIHTaD-h0qveorZanD5M96YcnBNCExSqRHcaHUxGkOCIHpmMZUZfR1FkV4fCVzjYmHo-NVMFEO72Er_289h_zJgykzR0Qjdztal9ZYcvALSMIBCSCYsyBReJlzD064VslXrbsVIKSHB0yg7QrXXm6gusRDnNSKYqC3e80yZiwhU2avfTOKlKgXA27beypiQ", 
    "Host": "emea-conformance.ping-eng.com", 
    "User-Agent": "Apache-HttpClient/4.5.5 (Java/11.0.10)", 
    "X-Amzn-Trace-Id": "Root=1-6023ad66-7367abd33aa7cd89395e737a"
  }, 
  "origin": "35.196.44.185, 54.74.38.30", 
  "url": "https://emea-conformance.ping-eng.com/get"
}
2021-02-10 09:54:46 SUCCESS
CallProtectedResourceWithBearerTokenAndCustomHeaders
Got a response from the resource endpoint
headers
{
  "date": "Wed, 10 Feb 2021 09:54:46 GMT",
  "content-type": "application/json",
  "content-length": "1066",
  "server": "gunicorn/19.9.0",
  "access-control-allow-origin": "*",
  "access-control-allow-credentials": "true",
  "x-fapi-interaction-id": "a3b2c5a3-2851-405c-9678-0adf8afeefdc"
}
status_code
{
  "code": 200
}
body
{
  "args": {}, 
  "headers": {
    "Accept": "application/json;charset=UTF-8", 
    "Accept-Charset": "utf-8", 
    "Accept-Encoding": "gzip,deflate", 
    "Authorization": "Bearer eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIiwicGkuYXRtIjoicTVqdSJ9.eyJzY29wZSI6Im9wZW5pZCB0ZXN0IiwiY2xpZW50X2lkIjoiY29uZm9ybWFuY2U0cGluZyIsInN1YiI6InBhdHJpY2siLCJjbmYiOnsieDV0I1MyNTYiOiJVckV1X3VqVG9hc0w5YWlkanB1eWhCR0Q4SUtvbDJTN1lfeG9GLUFJUGVnIn0sImV4cCI6MTYxMjk1ODA4NX0.XUgJoPD0-8YAA9Osp5MXNIcojV5dF1cEdbhg0StdByX3iHLtz-8Spnsu8ddfL8jplUkKEfOCky4Rp8Pg6EYwDRoDJy2N39DO--M5Z9fbGEQCoHtRE-vHhOx1zeoXCfh3pbrgTzABpdW5uc2bxpTrMp-yIHTaD-h0qveorZanD5M96YcnBNCExSqRHcaHUxGkOCIHpmMZUZfR1FkV4fCVzjYmHo-NVMFEO72Er_289h_zJgykzR0Qjdztal9ZYcvALSMIBCSCYsyBReJlzD064VslXrbsVIKSHB0yg7QrXXm6gusRDnNSKYqC3e80yZiwhU2avfTOKlKgXA27beypiQ", 
    "Host": "emea-conformance.ping-eng.com", 
    "User-Agent": "Apache-HttpClient/4.5.5 (Java/11.0.10)", 
    "X-Amzn-Trace-Id": "Root=1-6023ad66-7367abd33aa7cd89395e737a"
  }, 
  "origin": "35.196.44.185, 54.74.38.30", 
  "url": "https://emea-conformance.ping-eng.com/get"
}
2021-02-10 09:54:46 SUCCESS
CheckForDateHeaderInResourceResponse
Date header present and validated
date
Wed, 10 Feb 2021 09:54:46 GMT
skew
58
2021-02-10 09:54:46 SUCCESS
CheckForFAPIInteractionIdInResourceResponse
Found x-fapi-interaction-id
interaction_id
a3b2c5a3-2851-405c-9678-0adf8afeefdc
2021-02-10 09:54:46 SUCCESS
EnsureResourceResponseReturnedJsonContentType
Response content type is JSON
content_type
application/json
Attempting to use refresh_token issued to client 2 with client 1
2021-02-10 09:54:46 SUCCESS
CreateRefreshTokenRequest
Created token endpoint request parameters
grant_type
refresh_token
refresh_token
m1SkwtC0l87VFFln0u6hZZzS8RsIvxeD0wrwVWMFNt
2021-02-10 09:54:46 SUCCESS
AddScopeToTokenEndpointRequest
Added scope of 'openid test' to token endpoint request
grant_type
refresh_token
refresh_token
m1SkwtC0l87VFFln0u6hZZzS8RsIvxeD0wrwVWMFNt
scope
openid test
2021-02-10 09:54:46 SUCCESS
CreateClientAuthenticationAssertionClaims
Created client assertion claims
iss
conformance3ping
sub
conformance3ping
aud
https://emea-conformance.ping-eng.com:9032/as/token.oauth2
jti
ijyMRCC7itXppAwZR2cA
iat
1612950886
exp
1612950946
2021-02-10 09:54:46 SUCCESS
SignClientAuthenticationAssertion
Signed the client assertion
client_assertion
eyJraWQiOiIySEt5ejJVYzRGOGhSY3d5dVBnQTVFZ19zYWxuRWU3cGZ1alVrdmoyeWV3IiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTNwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTNwaW5nIiwiZXhwIjoxNjEyOTUwOTQ2LCJpYXQiOjE2MTI5NTA4ODYsImp0aSI6ImlqeU1SQ0M3aXRYcHBBd1pSMmNBIn0.vtFW0ikSSjp6jEd-rR_4tztdDlUxSkiAYEGsuAuxDcoem-qyJJHLFIqDarvwbHs5e2woXouYwZSv9O4zHkOFYA
2021-02-10 09:54:46
AddClientAssertionToTokenEndpointRequest
Added client assertion
grant_type
refresh_token
refresh_token
m1SkwtC0l87VFFln0u6hZZzS8RsIvxeD0wrwVWMFNt
scope
openid test
client_assertion
eyJraWQiOiIySEt5ejJVYzRGOGhSY3d5dVBnQTVFZ19zYWxuRWU3cGZ1alVrdmoyeWV3IiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTNwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTNwaW5nIiwiZXhwIjoxNjEyOTUwOTQ2LCJpYXQiOjE2MTI5NTA4ODYsImp0aSI6ImlqeU1SQ0M3aXRYcHBBd1pSMmNBIn0.vtFW0ikSSjp6jEd-rR_4tztdDlUxSkiAYEGsuAuxDcoem-qyJJHLFIqDarvwbHs5e2woXouYwZSv9O4zHkOFYA
client_assertion_type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-02-10 09:54:46
CallTokenEndpointAndReturnFullResponse
HTTP request
request_uri
https://emea-conformance.ping-eng.com:9032/as/token.oauth2
request_method
POST
request_headers
{
  "accept": "application/json;charset\u003dUTF-8",
  "accept-charset": "utf-8",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "629"
}
request_body
grant_type=refresh_token&refresh_token=m1SkwtC0l87VFFln0u6hZZzS8RsIvxeD0wrwVWMFNt&scope=openid+test&client_assertion=eyJraWQiOiIySEt5ejJVYzRGOGhSY3d5dVBnQTVFZ19zYWxuRWU3cGZ1alVrdmoyeWV3IiwiYWxnIjoiRVMyNTYifQ.eyJzdWIiOiJjb25mb3JtYW5jZTNwaW5nIiwiYXVkIjoiaHR0cHM6XC9cL2VtZWEtY29uZm9ybWFuY2UucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJjb25mb3JtYW5jZTNwaW5nIiwiZXhwIjoxNjEyOTUwOTQ2LCJpYXQiOjE2MTI5NTA4ODYsImp0aSI6ImlqeU1SQ0M3aXRYcHBBd1pSMmNBIn0.vtFW0ikSSjp6jEd-rR_4tztdDlUxSkiAYEGsuAuxDcoem-qyJJHLFIqDarvwbHs5e2woXouYwZSv9O4zHkOFYA&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
request_mutual_tls
{
  "cert": "MIIDlTCCAn2gAwIBAgIJAKRJoaX7BlZbMA0GCSqGSIb3DQEBCwUAMGAxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMR0wGwYDVQQKDBRBdXRobGV0ZSBUZXN0IENsaWVudDEdMBsGA1UEAwwUQXV0aGxldGUgVGVzdCBDbGllbnQwIBcNMTgwNTI1MjA1NzU0WhgPMjEwNjAxMDQyMDU3NTRaMGAxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApTb21lLVN0YXRlMR0wGwYDVQQKDBRBdXRobGV0ZSBUZXN0IENsaWVudDEdMBsGA1UEAwwUQXV0aGxldGUgVGVzdCBDbGllbnQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDEWwl/Q+nuL8KXbObpVzww1VkHwLF4W9QxrPI1V0Uh6V9rxUjrfSbtWNEQVDwQmoW8M1XjnRnGvdNRd0m6gNEQLKsqRN2xIvPdR0IO+2b+y7WJ9XlwdqHAFSWQJtoHzBAmkRirRMJrQSW5sB/NIBmyVqUdTV/FghNjc+IiPF4X1kxwwOzm7y2zlHZUpiPQknwPbWNeyunj/XQRrqWPg+RXzAKIjbVprxGaT8CexKu6oEaed8BCTO0rJIOkmjXZMl+SDhXQn9GHKFh60UlJddxVngxhX63MAQ1GsO8HsjrLgO3q4LmTDVHkprLy/wgBRDfo0IHb3gWhbOuRGMLLMKKvAgMBAAGjUDBOMB0GA1UdDgQWBBRuwpA4lqWaOkwmPcTQR8CH0Iv3vjAfBgNVHSMEGDAWgBRuwpA4lqWaOkwmPcTQR8CH0Iv3vjAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQBiCmvQmmKqI/8sB312HTEFlvtpbYp429eNCGXWloOOqVQkJaBnvy9YUS/wCgusyKeMBgbgpV0s8bp/gEW2/MnlWW9+fbFuhzRRwvuV/7je1Avv9Y06RH8GKJYwk2j6qcO7Mn9kVhlnlKxGdFxm/i0OBuZnUe/KDxKPjVEdUJbxAFfxdq4cUjfewMuoxsYruIDnLXjTBcj2PbJ6vcPzq/6TYwxRmnrXIAO6Nxe8ZNXn2x2+njwrUKW4WPQ7u3dyHlD+M3iTpm3TwSgg0FSYiBcXhWJLQCJVEb0kbKJ/PDmcvomusQWTL/0epS62azWG8PUUs4v9XeaemAbHqPGh+5Bo",
  "key": "MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDEWwl/Q+nuL8KXbObpVzww1VkHwLF4W9QxrPI1V0Uh6V9rxUjrfSbtWNEQVDwQmoW8M1XjnRnGvdNRd0m6gNEQLKsqRN2xIvPdR0IO+2b+y7WJ9XlwdqHAFSWQJtoHzBAmkRirRMJrQSW5sB/NIBmyVqUdTV/FghNjc+IiPF4X1kxwwOzm7y2zlHZUpiPQknwPbWNeyunj/XQRrqWPg+RXzAKIjbVprxGaT8CexKu6oEaed8BCTO0rJIOkmjXZMl+SDhXQn9GHKFh60UlJddxVngxhX63MAQ1GsO8HsjrLgO3q4LmTDVHkprLy/wgBRDfo0IHb3gWhbOuRGMLLMKKvAgMBAAECggEAJ3uOy1JipYxg+oXhYKYz6jXcMxziEquUXXDDO0qTEiCVGVyQLxn5S9yCHWByu3v2zEMeUCh02GuvJEBySNhCMZhpypQSZ935X1NGyzBuI2ne1SDRDHYuTCt0ZCoLyWmVDcw7Q6UN2vc8mLv7iQmdYSjfBqdaTKK9N1BD9lJhMTWBjxQDaF1yEZQfR1HOVVddJXt8ILOOltuxhu4EuBKsT8ZlCAN5kGx6+FzXlGlSYjWnGoYbERESeDim3JDwGOGX2msPGOmSzF24LnXrPg8IcrwEbzlFRIEzd8yUVA6VNca71uzv/MaOX5+cTtDiAoVdfrk1Ykt1SNNccGKnC7L3MQKBgQD29FIhT21DkUnXlABKj0N9dBSQyQ1HzILmY/YSg7aeBAlatEzCDxHtFaS89wXxosz2vNd1QKIrLrAgSzTLyemi2KVcvsHyo0g0drSq3NlOw5Rz4WRAZNgBcuhFJ8ZD1BJCisdQxQyCRJ3I0pf/D7mGkmovII1WSk/MIEWWvd3P6wKBgQDLjEEOaTeopbnqkJrcL4UbV2GmVAIa9EXSqzRTrPlxVA62n8EEX5YLXTx6yrvWHWtlA4VgRmUGuu1km5DqlnVdVz/l8fSk2HFcdycJgKd189v/tQ+BLu50+1+uaHiWLXo3VEXgv5QKSgPxWEnNPRVbgqOhav2MaACKo9sl3h4LTQKBgQCjyIxD7VKREmW/5TeAO53OMVOGZuE48ikKtdc4lkRibljp4FRcC/SeodEdRlOZ25hGOB5JdHFZZGCJOneshKBAUaDybs1gp+w2Z1gRTeGNvGbTp/N+RaOA6n2jh+qVh6wIl9Py/Iz8RJfE3e7SydIIr0hfMx6p0SU1Q14DyK64uwKBgQCiqM5ESejkqKtNu4lFc+QW2Vl7pZ6ZE6PImnASfiRIYDfx0PBaIlixdCyko+Y/UPtFme635QlOu4qB35+LF/lqQhMaGqS6Jw1QKxfTDDDGnb2tNm/ReEOu0ELCCVJ0EJueI4ZD+FTBdCx6bWdsz+eFXXyNvgYoceQc5px2Qm4X8QKBgHwpmIeHCvU9Erb9X5pY5JR609Ei+a9jksoe0ch7ocZi2NoE3vwjUSZFe/hTkvpf0gUhw1Zmekqhm78Qb4H7Aq7RDbpyCvoRXGS4GulFXM9Tkfe5FejhawT6fG12KLHOSAkJNgdFCPvFOaHlxPoAaBcf1sY/flehjWEwkVDSh0Js"
}
2021-02-10 09:54:46 RESPONSE
CallTokenEndpointAndReturnFullResponse
HTTP response
response_status_code
400 BAD_REQUEST
response_status_text
Bad Request
response_headers
{
  "date": "Wed, 10 Feb 2021 09:54:46 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003dQ7nFxbaJMairIVGoP7ljl4;Path\u003d/;Secure;HttpOnly;SameSite\u003dNone",
  "transfer-encoding": "chunked"
}
response_body
{"error_description":"Client id does not match the id of the client to whom the refresh token was issued. Grant revoked.","error":"invalid_grant"}
2021-02-10 09:54:46 SUCCESS
CallTokenEndpointAndReturnFullResponse
Parsed token endpoint response
error_description
Client id does not match the id of the client to whom the refresh token was issued. Grant revoked.
error
invalid_grant
2021-02-10 09:54:46 SUCCESS
ValidateErrorFromTokenEndpointResponseError
Token endpoint response error returned valid 'error' field
error
invalid_grant
2021-02-10 09:54:46 SUCCESS
CheckTokenEndpointHttpStatus400
Token endpoint http status code was 400
2021-02-10 09:54:46 SUCCESS
CheckTokenEndpointReturnedJsonContentType
token_endpoint_response_headers Content-Type: header is application/json
2021-02-10 09:54:46 SUCCESS
CheckErrorFromTokenEndpointResponseErrorInvalidGrant
Token Endpoint response error returned expected 'error' of 'invalid_grant'
error
invalid_grant
2021-02-10 09:54:46 FINISHED
fapi-ciba-id1-refresh-token
Test has run to completion
testmodule_result
PASSED
Unregister dynamically registered client
2021-02-10 09:54:46 INFO
UnregisterDynamicallyRegisteredClient
Skipped evaluation due to missing required string: registration_client_uri
expected
registration_client_uri
Unregister dynamically registered client2
2021-02-10 09:54:46 INFO
UnregisterDynamicallyRegisteredClient
Skipped evaluation due to missing required string: registration_client_uri
expected
registration_client_uri
2021-02-10 09:54:50
TEST-RUNNER
Alias has now been claimed by another test
alias
robotto-internal-2
new_test_id
H6Kxmzdw8sEnQxQ
Test Results