This page describes how to submit completed RP conformance testing results to the OpenID Foundation to request OpenID Certifications. Before submission, first all tests must be successfully passed for the desired conformance profiles and testing results gathered, as described in the RP testing instructions. Note that results with warnings are acceptable for certification purposes.
While the Basic RP profile requires only one set of test runs (for the
code response type), the Implicit RP profile requires two (for the
id_token+token response types), and the Hybrid RP profile requires three (for the
code+id_token+token response types). The Config RP and Dynamic RP profiles require only one set of test runs each, which are performed using the
code response type. The Form Post RP profile requires you to submit test runs for all the response_type values supported by your implementation.
For each conformance profile being certified to, the following information must be submitted in its own certification package:
- A signed copy of the Certification of Conformance (docx) (PDF) naming that profile. This should use the filename
OpenID-Certification-of-Conformance.pdfin the submitted results. (A different extension such as .jpg for the scanned document may be used as appropriate.)
- A copy of the Certification Terms and Conditions document accompanying the Certification of Conformance. This must use the filename
OpenID-Certification-Terms-and-Conditions.pdfin the submitted results. (This document is not signed but is included for completeness since it is referenced from the Certification of Conformance.)
- Test log files for each test in the profile (which are text file) for each response_type value required for the profile. Each log file should either be retrieved from the log page https://rp.certification.openid.net:8080/log/RP_ID/TEST_ID and saved with the filename response_type/test-ID.txt or from https://rp.certification.openid.net:8080/log/RP_ID/. For instance, the filename
id_token+token/rp-id_token-bad-sig-rs256.txtshould be used for the log of running the bad ID Token signature test with the “id_token token” response type. Note that the log file must demonstrate that the intended response_type was used when running the test.
- Evidence demonstrating the behavior of the relying party when the test is run for each response_type value required for the profile. This can take the form of RP log files, screen captures (image files), or both. For instance, the filename
id_token+token/rp-id_token-bad-sig-rs256.logcould be used for an RP log file confirming that the error was detected and handled by the RP when the ID Token signature is invalid and the test is run with the “id_token token” response type. Or the filename
id_token+token/rp-id_token-bad-sig-rs256.pngcould be used for the screen shot of the error shown by the RP. (A different extension such as .jpg for the screen shot may also be used.)
readme.txtfile describing how third parties can determine from the log files and/or screen shots included that the RP behaved as specified for each test instance. (readme.html or readme.docx files are also fine.)
- Other pertinent material may also be included if described in the readme.txt file.
The certification package should consist of a single .zip or .tar file containing all the files and using the paths above. The filename should contain the name of the organization, the software being certified, the profile being certified to, and the current date. For example, a certification request by the ProseWare organization of its “Humongous Identity” software for the Basic RP profile on December 13, 2016 should use a filename like
- Name of Entity (“Implementer”) Making this Certification: ProseWare
- Software or Service (“Deployment”) Name & Version #: Humongous Identity 3.14159
- OpenID Connect Conformance Profile: Basic Relying Party
- Conformance Test Suite Software & Version #: rp.certification.openid.net 1.0.3
- Test Date: December 10, 2016
- Authorized Signature: HQB
- Name: Harry Q. Bovik
- Title: Senior Computer Scientist
- Date: December 13, 2016
- Implementer’s Name: Jane Doe
- Implementer’s Title: Programmer Extraordinaire
- Implementer’s Phone: +1 (412) 555-1234
- Implementer’s Email: email@example.com
- Implementer’s Address: 5000 Forbes Ave.
- Implementer’s City, State/Province, Postal Code: Pittsburgh, PA 15213
- Implementer’s Country: United States of America
The conformance test suite software version number can be found at the bottom right of the testing Web pages and at the top of the log files.
Contents for several certification submission examples can be viewed at Certification Submission Examples. These examples show the expected contents of the .zip or .tar files for certification submissions for each conformance profile.
The certification package must be sent to the OpenID Foundation as an attachment at firstname.lastname@example.org. The subject line of the e-mail request should be along the lines of “Certification request by ProseWare of Humongous Identity for the Basic RP profile”. If receipt of the submission is not acknowledged within two days (or three days if over a weekend), feel free to inquire about whether it was received by e-mailing a message without the attachment (to keep the size of the inquiry small) to email@example.com, cc’ing firstname.lastname@example.org.
A fee is required for certifications unless the conformance profile is still in the pilot phase. Please pay for your certification application at the Certification Payment page when you make your submission.
Third Party-Initiated Login RP Profile
A Third Party-Initiated Login OP test is now in production. Please submit your results for this test as a separate .zip or .tar file in the normal manner using a filename like
ProseWare-Humongous_Identity-RP-ThirdParty-28-Feb-2019.zip. This test is:
Logout RP Profiles
NEW! Testing for RP logout profiles is currently in the pilot phase. Please submit your results for these profiles as separate .zip or .tar files in the normal manner using filenames like these: