Test info
Profile: {'openid-configuration': 'config', 'response_type': 'code+token', 'crypto': 'sign', 'registration': 'static'}
Timestamp: 2016-02-25T19:07:24Z
Test description: Request with nonce, verifies it was returned in ID Token [Implicit, Hybrid]
Test ID: OP-nonce-noncode
Issuer: https://qaportal2.gosecureauth.com/secureauth123
Test output
__AuthorizationRequest:pre__
[check-response-type]
status: OK
description: Checks that the asked for response type are among the supported
[check-endpoint]
status: OK
description: Checks that the necessary endpoint exists at a server
__After completing the test flow:__
[check-idtoken-nonce]
status: OK
description: Verify that I in the IDToken gets back the nonce I included in the Authorization Request.
[verify-response]
status: OK
description: Checks that the last response was one of a possible set of OpenID Connect Responses
__X:==== END ====__
Trace output
0.000471 ------------ DiscoveryRequest ------------
0.000488 Provider info discover from 'https://qaportal2.gosecureauth.com/secureauth123'
0.000496 --> URL: https://qaportal2.gosecureauth.com/secureauth123/.well-known/openid-configuration
0.327661 ProviderConfigurationResponse: {
"authorization_endpoint": "https://qaportal2.gosecureauth.com/secureauth123/SecureAuth.aspx",
"check_session_iframe": "https://qaportal2.gosecureauth.com/secureauth123/OidcCheckSession.aspx",
"claim_types_supported": [
"normal"
],
"claims_parameter_supported": false,
"claims_supported": [
"sub",
"name",
"given_name",
"family_name",
"middle_name",
"nickname",
"preferred_username",
"profile"
],
"end_session_endpoint": "https://qaportal2.gosecureauth.com/secureauth123/OidcEndSession.aspx",
"grant_types_supported": [
"authorization_code",
"client_credentials",
"password",
"refresh_token"
],
"id_token_signing_alg_values_supported": [
"HS256",
"RS256"
],
"issuer": "https://qaportal2.gosecureauth.com/secureauth123",
"jwks_uri": "https://qaportal2.gosecureauth.com/secureauth123/.well-known/jwks",
"request_parameter_supported": false,
"request_uri_parameter_supported": true,
"require_request_uri_registration": true,
"response_modes_supported": [
"form_post",
"fragment",
"query"
],
"response_types_supported": [
"code",
"token",
"id_token",
"id_token token",
"code id_token",
"code token",
"code id_token token"
],
"scopes_supported": [
"openid",
"profile",
"email",
"phone",
"address",
"sa.readprofile",
"sa.editprofile"
],
"subject_types_supported": [
"public"
],
"token_endpoint": "https://qaportal2.gosecureauth.com/secureauth123/OidcToken.aspx",
"token_endpoint_auth_methods_supported": [
"client_secret_post",
"client_secret_basic"
],
"userinfo_endpoint": "https://qaportal2.gosecureauth.com/secureauth123/OidcUserInfo.aspx",
"version": "3.0"
}
0.744819 JWKS: {
"keys": [
{
"e": "AQAB",
"kid": "kL3mwBbniGrOr-Hhw0D8e_-rRWU",
"kty": "RSA",
"n": "sy1VZq8v2oqbSaddMMxeyqVORLB3lk71T0_cAv4lWdqCAmd9LWGvVul2be1Q5QUdJgewy9G8dEpwyuT_1qmqtY1psgxua9M3uyBrtY1mYBJ4QZVMgbvfk1-uvxF1YLsuZa_QsAN0k3X5bmvQh35WVNgzVU1QXAgi8m0jxSxY2EM2GO0EMwvPXIgkU6u0yYJ6Vy4i-5Ftwztx2dyz41JTw8CF8m9S2nE4Ppxc4rfWLjCIlPPILCPUnwU2UlfPAqHUxi6RXeAubyjlL5komE6y4XstURH66gePLyfjMtWGxmZpbv4yPmffFQgMO0oYT0Y1trUTF19waIE_JZfA-z8e7w",
"use": "sig",
"x5c": [
"MIIEvTCCA6WgAwIBAgIDAPNJMA0GCSqGSIb3DQEBCwUAMEcxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1HZW9UcnVzdCBJbmMuMSAwHgYDVQQDExdSYXBpZFNTTCBTSEEyNTYgQ0EgLSBHMzAeFw0xNDEyMDcxMjM1NTlaFw0xODAyMDcyMjQ5NDJaMIGWMRMwEQYDVQQLEwpHVDU5NjE0ODM5MTEwLwYDVQQLEyhTZWUgd3d3LnJhcGlkc3NsLmNvbS9yZXNvdXJjZXMvY3BzIChjKTE0MS8wLQYDVQQLEyZEb21haW4gQ29udHJvbCBWYWxpZGF0ZWQgLSBSYXBpZFNTTChSKTEbMBkGA1UEAwwSKi5nb3NlY3VyZWF1dGguY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsy1VZq8v2oqbSaddMMxeyqVORLB3lk71T0/cAv4lWdqCAmd9LWGvVul2be1Q5QUdJgewy9G8dEpwyuT/1qmqtY1psgxua9M3uyBrtY1mYBJ4QZVMgbvfk1+uvxF1YLsuZa/QsAN0k3X5bmvQh35WVNgzVU1QXAgi8m0jxSxY2EM2GO0EMwvPXIgkU6u0yYJ6Vy4i+5Ftwztx2dyz41JTw8CF8m9S2nE4Ppxc4rfWLjCIlPPILCPUnwU2UlfPAqHUxi6RXeAubyjlL5komE6y4XstURH66gePLyfjMtWGxmZpbv4yPmffFQgMO0oYT0Y1trUTF19waIE/JZfA+z8e7wIDAQABo4IBYDCCAVwwHwYDVR0jBBgwFoAUw5zz/NNGCDS7zkZ/oHxb8+IIy1kwVwYIKwYBBQUHAQEESzBJMB8GCCsGAQUFBzABhhNodHRwOi8vZ3Yuc3ltY2QuY29tMCYGCCsGAQUFBzAChhpodHRwOi8vZ3Yuc3ltY2IuY29tL2d2LmNydDAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMC8GA1UdEQQoMCaCEiouZ29zZWN1cmVhdXRoLmNvbYIQZ29zZWN1cmVhdXRoLmNvbTArBgNVHR8EJDAiMCCgHqAchhpodHRwOi8vZ3Yuc3ltY2IuY29tL2d2LmNybDAMBgNVHRMBAf8EAjAAMEUGA1UdIAQ+MDwwOgYKYIZIAYb4RQEHNjAsMCoGCCsGAQUFBwIBFh5odHRwczovL3d3dy5yYXBpZHNzbC5jb20vbGVnYWwwDQYJKoZIhvcNAQELBQADggEBAIBtdMMzImQrQtUtBAOoE8fDupKKg3E2VR9jnuXU8ITdU7+BjiKcrHrus75hUF4BHCWyoQjOAoyQSz5M7DVzVnlVCCEgw6H+L+uvtj4k4hfVpeQVKc/NdzpGe3lQw4XuagDishXCC0otcIPn89X3Kge/6s/QIME0DuDADOB50rprDE8jFYwbiQ56P0qk+uy9R31IetyEu5fG9br35wNjAWvLS6XGIbX2Xy8cnRDhV+Eo7JvP7KEr/E5AZjt+5jTP8ZaqEoiyVFwtz40csFuV11aiecox2xW8A4LyTyy3kV8Hjrm/187y6J5iCbGQTIpL6xPuPA2NesWunoFmQFU7q4s="
],
"x5t": "kL3mwBbniGrOr-Hhw0D8e_-rRWU"
}
]
}
0.751266 ------------ AuthorizationRequest ------------
0.751706 --> URL: https://qaportal2.gosecureauth.com/secureauth123/SecureAuth.aspx?nonce=kY3SlXGyXTRc&state=rlXibIfF6wPY7V4P&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A60097%2Fauthz_cb&response_type=code+token&client_id=977c322203ed497eb718a51a8f35d54b&scope=openid
0.751714 --> BODY: None
5.046400 QUERY_STRING:
5.989458 <-- code=TCL1xr1g4HovhN6vuUwFzNWNxEJWggeKSMirSIIs5_EIa7aaf5AGgF5n0T4_q-g8ddmwW1M1xI-t3gABgOqQXuEcvR1P9Yy_g2WhSqhZyFqtDFqN_dFsmMHKk4Zu60ugwRfiEWwqs-0aGhQda8QcwU6E7ViZ6Yn8RY5vV1kC5qPcDzkDer5G3Ui42r4PfUVOrGODBb91qxUoDI0KCIyi2BdwA6IG0zSc47rlFiuJFwo3uD3UznjwU2S6uN7U-GLJ9Uwo-g8iZvyWbkV7SwRS0vhGoQYLt61cPU2dbRFwI6Q&access_token=eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSIsImtpZCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSJ9.eyJjbGllbnRfaWQiOiI5NzdjMzIyMjAzZWQ0OTdlYjcxOGE1MWE4ZjM1ZDU0YiIsInNjb3BlIjoib3BlbmlkIiwic3ViIjoidXNlcjcxIiwiYW1yIjoicGFzc3dvcmQiLCJhdXRoX3RpbWUiOjE0NTY0MjcxNjQsImlkcCI6IlNlY3VyZUF1dGgxMjMiLCJpc3MiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJhdWQiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJleHAiOjE0NTY1MTM2NDIsIm5iZiI6MTQ1NjQyNzI0Mn0.TIG6r9yXPgeFL3K2h7oCt79FU55JN8cldRzqKKRsNaj-ZcMbMqYX_RsvVjONhbjFPKfVELDq5J_TAeBtfGLsoZ7hIs0nq5CE8oQJAFRVONAjIdMnGdQ5LIOmEPkGk5Ogmq3-1cnxnny1CPNaHkU-j8khInlZGTkdDpopsJziuI5yCYd4QzFYovGSVRV74_a37aGLZa3cQgap2hxclDMvZEfdo_uMtbqazc39skf1L_pa4sCwGzeUY5GHU_rYSvPxV8l2cMIsN-rP9sAf6VKRg12XiCuRAnRWBw82L8OBPTjijwWDMp_neUxW6x1TWH4E67f7bVVFpJSQi_h3gfuzUQ&token_type=Bearer&session_state=SQc0iTB-FH2RcxQvtPbGnkiwGfmyEvrv0rqUkVt97OM.833f933ba718ffc857745dd2ae0b1668&state=rlXibIfF6wPY7V4P
5.990543 AuthorizationResponse: {
"access_token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSIsImtpZCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSJ9.eyJjbGllbnRfaWQiOiI5NzdjMzIyMjAzZWQ0OTdlYjcxOGE1MWE4ZjM1ZDU0YiIsInNjb3BlIjoib3BlbmlkIiwic3ViIjoidXNlcjcxIiwiYW1yIjoicGFzc3dvcmQiLCJhdXRoX3RpbWUiOjE0NTY0MjcxNjQsImlkcCI6IlNlY3VyZUF1dGgxMjMiLCJpc3MiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJhdWQiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJleHAiOjE0NTY1MTM2NDIsIm5iZiI6MTQ1NjQyNzI0Mn0.TIG6r9yXPgeFL3K2h7oCt79FU55JN8cldRzqKKRsNaj-ZcMbMqYX_RsvVjONhbjFPKfVELDq5J_TAeBtfGLsoZ7hIs0nq5CE8oQJAFRVONAjIdMnGdQ5LIOmEPkGk5Ogmq3-1cnxnny1CPNaHkU-j8khInlZGTkdDpopsJziuI5yCYd4QzFYovGSVRV74_a37aGLZa3cQgap2hxclDMvZEfdo_uMtbqazc39skf1L_pa4sCwGzeUY5GHU_rYSvPxV8l2cMIsN-rP9sAf6VKRg12XiCuRAnRWBw82L8OBPTjijwWDMp_neUxW6x1TWH4E67f7bVVFpJSQi_h3gfuzUQ",
"code": "TCL1xr1g4HovhN6vuUwFzNWNxEJWggeKSMirSIIs5_EIa7aaf5AGgF5n0T4_q-g8ddmwW1M1xI-t3gABgOqQXuEcvR1P9Yy_g2WhSqhZyFqtDFqN_dFsmMHKk4Zu60ugwRfiEWwqs-0aGhQda8QcwU6E7ViZ6Yn8RY5vV1kC5qPcDzkDer5G3Ui42r4PfUVOrGODBb91qxUoDI0KCIyi2BdwA6IG0zSc47rlFiuJFwo3uD3UznjwU2S6uN7U-GLJ9Uwo-g8iZvyWbkV7SwRS0vhGoQYLt61cPU2dbRFwI6Q",
"session_state": "SQc0iTB-FH2RcxQvtPbGnkiwGfmyEvrv0rqUkVt97OM.833f933ba718ffc857745dd2ae0b1668",
"state": "rlXibIfF6wPY7V4P",
"token_type": "Bearer"
}
5.990984 ------------ AccessTokenRequest ------------
5.991401 --> URL: https://qaportal2.gosecureauth.com/secureauth123/OidcToken.aspx
5.991409 --> BODY: code=TCL1xr1g4HovhN6vuUwFzNWNxEJWggeKSMirSIIs5_EIa7aaf5AGgF5n0T4_q-g8ddmwW1M1xI-t3gABgOqQXuEcvR1P9Yy_g2WhSqhZyFqtDFqN_dFsmMHKk4Zu60ugwRfiEWwqs-0aGhQda8QcwU6E7ViZ6Yn8RY5vV1kC5qPcDzkDer5G3Ui42r4PfUVOrGODBb91qxUoDI0KCIyi2BdwA6IG0zSc47rlFiuJFwo3uD3UznjwU2S6uN7U-GLJ9Uwo-g8iZvyWbkV7SwRS0vhGoQYLt61cPU2dbRFwI6Q&grant_type=authorization_code&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A60097%2Fauthz_cb
5.991423 --> HEADERS: {'Content-Type': 'application/x-www-form-urlencoded', 'Authorization': u'Basic OTc3YzMyMjIwM2VkNDk3ZWI3MThhNTFhOGYzNWQ1NGI6NmMxYTQ4YmFkOWRhOWVhNjBhY2YyNzQ4OTY3YzllZjE3Y2QxOWY1ZThhYmQzNGM4Mjg4MWJhNDM1NDE0OTIyNA=='}
6.489138 <-- STATUS: 200
6.489213 <-- BODY: {"access_token":"eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSIsImtpZCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSJ9.eyJjbGllbnRfaWQiOiI5NzdjMzIyMjAzZWQ0OTdlYjcxOGE1MWE4ZjM1ZDU0YiIsInNjb3BlIjoib3BlbmlkIiwic3ViIjoidXNlcjcxIiwiYW1yIjoicGFzc3dvcmQiLCJhdXRoX3RpbWUiOjE0NTY0MjcxNjQsImlkcCI6IlNlY3VyZUF1dGgxMjMiLCJpc3MiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJhdWQiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJleHAiOjE0NTY1MTM2NDMsIm5iZiI6MTQ1NjQyNzI0M30.OZmR7MZU8wuUaFj_3Af_oEK_hiGCQ32UZx89njpgLB_1Quz1MB9mIvseGVYih1ZNIVRk4UbQpC7MRk6LujrG5cgEjR5A4U113Dbmz7EV7PyQOd7162NNG3o5uqmaicd5HOxloUzqDerYboj36H6VaHTxPZauKFwXvGpSboFXKFnzgLWVy7BQl6KPr-94hoJZ1Jp0bUZabkFldgZMQj-XL_qcTZ9hoaDwciXQefHWhRite2nNuW14n5KE4BLVU9yV6WI2ohoGeO-wimo0Pr5pwcZy0JJtULHWz0wLYjEMiXAq8mEDk_-qGIDxA2LkQJBGX2U97UKOkl_M532vjTpMXw","id_token":"eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSIsImtpZCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSJ9.eyJhbXIiOiJwYXNzd29yZCIsImlkcCI6IlNlY3VyZUF1dGgxMjMiLCJhdXRoX3RpbWUiOjE0NTY0MjcxNjQsInN1YiI6InVzZXI3MSIsIm5vbmNlIjoia1kzU2xYR3lYVFJjIiwiYXRfaGFzaCI6IjhiWUl6YTRkby1hY3VyVkZobDFYMFEiLCJpYXQiOjE0NTY0MjcyNDQsImlzcyI6Imh0dHBzOi8vcWFwb3J0YWwyLmdvc2VjdXJlYXV0aC5jb20vc2VjdXJlYXV0aDEyMyIsImF1ZCI6Ijk3N2MzMjIyMDNlZDQ5N2ViNzE4YTUxYThmMzVkNTRiIiwiZXhwIjoxNDU2NTEzNjQzLCJuYmYiOjE0NTY0MjcyNDN9.PAbuw3BWQY0H3__RdHV81mPx3KHtAEhaHA5hjVmtjQhCG5KuxD3On1x9cxqdFyyI7v_UbN79XKy2V2Ufu4E9Kbb1xupkiSkPs_JBoE2kBYN4ZECp19_vFeXuJFYzM5pfBRo_Id8Lkhq9OstQEorVzqVfNWnGX_wMsYp5Y7Ttdn9S13SKqcClMQF_gNCB9Z38VfUPN-TFteVkOHzDEhX-ekm-HXgp3dCmX3faicQY3PE1-a3gLTdqpGuVKBmwwL3vxeGyTgHTx9TYoURoSUGPPWWf6qyysL0hQJSHjB1GGxjAviXuu7031WE4nHcb6blrxfPY7hHDKbKbLbmYRphIiQ","token_type":"Bearer","expires_in":"86400"}
6.820118 AccessTokenResponse: {
"access_token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSIsImtpZCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSJ9.eyJjbGllbnRfaWQiOiI5NzdjMzIyMjAzZWQ0OTdlYjcxOGE1MWE4ZjM1ZDU0YiIsInNjb3BlIjoib3BlbmlkIiwic3ViIjoidXNlcjcxIiwiYW1yIjoicGFzc3dvcmQiLCJhdXRoX3RpbWUiOjE0NTY0MjcxNjQsImlkcCI6IlNlY3VyZUF1dGgxMjMiLCJpc3MiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJhdWQiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJleHAiOjE0NTY1MTM2NDMsIm5iZiI6MTQ1NjQyNzI0M30.OZmR7MZU8wuUaFj_3Af_oEK_hiGCQ32UZx89njpgLB_1Quz1MB9mIvseGVYih1ZNIVRk4UbQpC7MRk6LujrG5cgEjR5A4U113Dbmz7EV7PyQOd7162NNG3o5uqmaicd5HOxloUzqDerYboj36H6VaHTxPZauKFwXvGpSboFXKFnzgLWVy7BQl6KPr-94hoJZ1Jp0bUZabkFldgZMQj-XL_qcTZ9hoaDwciXQefHWhRite2nNuW14n5KE4BLVU9yV6WI2ohoGeO-wimo0Pr5pwcZy0JJtULHWz0wLYjEMiXAq8mEDk_-qGIDxA2LkQJBGX2U97UKOkl_M532vjTpMXw",
"expires_in": "86400",
"id_token": {
"claims": {
"amr": [
"password"
],
"at_hash": "8bYIza4do-acurVFhl1X0Q",
"aud": [
"977c322203ed497eb718a51a8f35d54b"
],
"auth_time": 1456427164,
"exp": 1456513643,
"iat": 1456427244,
"idp": "SecureAuth123",
"iss": "https://qaportal2.gosecureauth.com/secureauth123",
"nbf": 1456427243,
"nonce": "kY3SlXGyXTRc",
"sub": "user71"
},
"jws header parameters": {
"alg": "RS256",
"kid": "kL3mwBbniGrOr-Hhw0D8e_-rRWU",
"typ": "JWT",
"x5t": "kL3mwBbniGrOr-Hhw0D8e_-rRWU"
}
},
"token_type": "Bearer"
}
6.827721 ==== END ====
Result
PASSED