Test info
Profile: {'openid-configuration': 'config', 'response_type': 'id_token+token', 'crypto': 'sign', 'registration': 'static'}
Timestamp: 2016-02-25T00:18:42Z
Test description: Requesting ID Token with max_age=10000 seconds restriction [Basic, Implicit, Hybrid]
Test ID: OP-Req-max_age=10000
Issuer: https://qaportal2.gosecureauth.com/secureauth123
Test output
__AuthorizationRequest:pre__
[check-response-type]
status: OK
description: Checks that the asked for response type are among the supported
[check-endpoint]
status: OK
description: Checks that the necessary endpoint exists at a server
__AuthorizationRequest:pre__
[check-response-type]
status: OK
description: Checks that the asked for response type are among the supported
[check-endpoint]
status: OK
description: Checks that the necessary endpoint exists at a server
__After completing the test flow:__
[verify-response]
status: OK
description: Checks that the last response was one of a possible set of OpenID Connect Responses
[claims-check]
status: OK
description: Checks if specific claims is present or not
[auth_time-check]
status: OK
description: Check that the auth_time returned in the ID Token is in the expected range.
[same-authn]
status: OK
description: Verifies that the same authentication was used twice in the flow.
__X:==== END ====__
Trace output
0.000345 ------------ DiscoveryRequest ------------
0.000360 Provider info discover from 'https://qaportal2.gosecureauth.com/secureauth123'
0.000368 --> URL: https://qaportal2.gosecureauth.com/secureauth123/.well-known/openid-configuration
0.349851 ProviderConfigurationResponse: {
"authorization_endpoint": "https://qaportal2.gosecureauth.com/secureauth123/SecureAuth.aspx",
"check_session_iframe": "https://qaportal2.gosecureauth.com/secureauth123/OidcCheckSession.aspx",
"claim_types_supported": [
"normal"
],
"claims_parameter_supported": false,
"claims_supported": [
"sub",
"name",
"given_name",
"family_name",
"middle_name",
"nickname",
"preferred_username",
"profile"
],
"end_session_endpoint": "https://qaportal2.gosecureauth.com/secureauth123/OidcEndSession.aspx",
"grant_types_supported": [
"authorization_code",
"client_credentials",
"password",
"refresh_token"
],
"id_token_signing_alg_values_supported": [
"HS256",
"RS256"
],
"issuer": "https://qaportal2.gosecureauth.com/secureauth123",
"jwks_uri": "https://qaportal2.gosecureauth.com/secureauth123/.well-known/jwks",
"request_parameter_supported": false,
"request_uri_parameter_supported": true,
"require_request_uri_registration": true,
"response_modes_supported": [
"form_post",
"fragment",
"query"
],
"response_types_supported": [
"code",
"token",
"id_token",
"id_token token",
"code id_token",
"code token",
"code id_token token"
],
"scopes_supported": [
"openid",
"profile",
"email",
"phone",
"address",
"sa.readprofile",
"sa.editprofile"
],
"subject_types_supported": [
"public"
],
"token_endpoint": "https://qaportal2.gosecureauth.com/secureauth123/OidcToken.aspx",
"token_endpoint_auth_methods_supported": [
"client_secret_post",
"client_secret_basic"
],
"userinfo_endpoint": "https://qaportal2.gosecureauth.com/secureauth123/OidcUserInfo.aspx",
"version": "3.0"
}
0.696077 JWKS: {
"keys": [
{
"e": "AQAB",
"kid": "kL3mwBbniGrOr-Hhw0D8e_-rRWU",
"kty": "RSA",
"n": "sy1VZq8v2oqbSaddMMxeyqVORLB3lk71T0_cAv4lWdqCAmd9LWGvVul2be1Q5QUdJgewy9G8dEpwyuT_1qmqtY1psgxua9M3uyBrtY1mYBJ4QZVMgbvfk1-uvxF1YLsuZa_QsAN0k3X5bmvQh35WVNgzVU1QXAgi8m0jxSxY2EM2GO0EMwvPXIgkU6u0yYJ6Vy4i-5Ftwztx2dyz41JTw8CF8m9S2nE4Ppxc4rfWLjCIlPPILCPUnwU2UlfPAqHUxi6RXeAubyjlL5komE6y4XstURH66gePLyfjMtWGxmZpbv4yPmffFQgMO0oYT0Y1trUTF19waIE_JZfA-z8e7w",
"use": "sig",
"x5c": [
"MIIEvTCCA6WgAwIBAgIDAPNJMA0GCSqGSIb3DQEBCwUAMEcxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1HZW9UcnVzdCBJbmMuMSAwHgYDVQQDExdSYXBpZFNTTCBTSEEyNTYgQ0EgLSBHMzAeFw0xNDEyMDcxMjM1NTlaFw0xODAyMDcyMjQ5NDJaMIGWMRMwEQYDVQQLEwpHVDU5NjE0ODM5MTEwLwYDVQQLEyhTZWUgd3d3LnJhcGlkc3NsLmNvbS9yZXNvdXJjZXMvY3BzIChjKTE0MS8wLQYDVQQLEyZEb21haW4gQ29udHJvbCBWYWxpZGF0ZWQgLSBSYXBpZFNTTChSKTEbMBkGA1UEAwwSKi5nb3NlY3VyZWF1dGguY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsy1VZq8v2oqbSaddMMxeyqVORLB3lk71T0/cAv4lWdqCAmd9LWGvVul2be1Q5QUdJgewy9G8dEpwyuT/1qmqtY1psgxua9M3uyBrtY1mYBJ4QZVMgbvfk1+uvxF1YLsuZa/QsAN0k3X5bmvQh35WVNgzVU1QXAgi8m0jxSxY2EM2GO0EMwvPXIgkU6u0yYJ6Vy4i+5Ftwztx2dyz41JTw8CF8m9S2nE4Ppxc4rfWLjCIlPPILCPUnwU2UlfPAqHUxi6RXeAubyjlL5komE6y4XstURH66gePLyfjMtWGxmZpbv4yPmffFQgMO0oYT0Y1trUTF19waIE/JZfA+z8e7wIDAQABo4IBYDCCAVwwHwYDVR0jBBgwFoAUw5zz/NNGCDS7zkZ/oHxb8+IIy1kwVwYIKwYBBQUHAQEESzBJMB8GCCsGAQUFBzABhhNodHRwOi8vZ3Yuc3ltY2QuY29tMCYGCCsGAQUFBzAChhpodHRwOi8vZ3Yuc3ltY2IuY29tL2d2LmNydDAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMC8GA1UdEQQoMCaCEiouZ29zZWN1cmVhdXRoLmNvbYIQZ29zZWN1cmVhdXRoLmNvbTArBgNVHR8EJDAiMCCgHqAchhpodHRwOi8vZ3Yuc3ltY2IuY29tL2d2LmNybDAMBgNVHRMBAf8EAjAAMEUGA1UdIAQ+MDwwOgYKYIZIAYb4RQEHNjAsMCoGCCsGAQUFBwIBFh5odHRwczovL3d3dy5yYXBpZHNzbC5jb20vbGVnYWwwDQYJKoZIhvcNAQELBQADggEBAIBtdMMzImQrQtUtBAOoE8fDupKKg3E2VR9jnuXU8ITdU7+BjiKcrHrus75hUF4BHCWyoQjOAoyQSz5M7DVzVnlVCCEgw6H+L+uvtj4k4hfVpeQVKc/NdzpGe3lQw4XuagDishXCC0otcIPn89X3Kge/6s/QIME0DuDADOB50rprDE8jFYwbiQ56P0qk+uy9R31IetyEu5fG9br35wNjAWvLS6XGIbX2Xy8cnRDhV+Eo7JvP7KEr/E5AZjt+5jTP8ZaqEoiyVFwtz40csFuV11aiecox2xW8A4LyTyy3kV8Hjrm/187y6J5iCbGQTIpL6xPuPA2NesWunoFmQFU7q4s="
],
"x5t": "kL3mwBbniGrOr-Hhw0D8e_-rRWU"
}
]
}
0.705231 ------------ AuthorizationRequest ------------
0.705682 --> URL: https://qaportal2.gosecureauth.com/secureauth123/SecureAuth.aspx?nonce=JqC9lgUpmI5N&state=8PkWbo8Q44RaH9nl&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A60097%2Fauthz_cb&response_type=id_token+token&client_id=8671eb69d3614203b4fec2e4dbef27ff&scope=openid
0.705690 --> BODY: None
6.886258 QUERY_STRING:
7.595409 <-- access_token=eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSIsImtpZCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSJ9.eyJjbGllbnRfaWQiOiI4NjcxZWI2OWQzNjE0MjAzYjRmZWMyZTRkYmVmMjdmZiIsInNjb3BlIjoib3BlbmlkIiwic3ViIjoidXNlcjcxIiwiYW1yIjoicGFzc3dvcmQiLCJhdXRoX3RpbWUiOjE0NTYzNTkyOTgsImlkcCI6IlNlY3VyZUF1dGgxMjMiLCJpc3MiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJhdWQiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJleHAiOjE0NTY0NDU5MTMsIm5iZiI6MTQ1NjM1OTUxM30.I4pFRE1y3R2UmDL5I1IVpi3707lDJi0t0nPQaGzJMSjuMngFe_zhDMehEaW2q5zg-PEFgrb6nPTxOWIrhCq2bh4DHfAEvaO0h4yjyDlzyo-FCZ_zlWjV_PwZbVn5_tgsW1_VdbEgbjLa3egaU4tOWgq6idVkH8bPevooYsIE2Q0IjChBYf-LsEHtV3JTgyUw7iCMZ7QGPuNjkHMLcTp4GlqFDvjodWerafA7JbwbVn_ID8gdO6UKvzK5PUHaA4YvZQDd0pIka50wmcBsuF8AhYYgFrvV6jgmRcPIK1VqO077c6G5R6WeUaVC7EDGdZ5s1L_JbitIMBIgWM6cCByk6Q&token_type=Bearer&id_token=eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSIsImtpZCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSJ9.eyJhbXIiOiJwYXNzd29yZCIsImlkcCI6IlNlY3VyZUF1dGgxMjMiLCJhdXRoX3RpbWUiOjE0NTYzNTkyOTgsInN1YiI6InVzZXI3MSIsIm5vbmNlIjoiSnFDOWxnVXBtSTVOIiwiYXRfaGFzaCI6Ik1hY2t1bmJjM2xVaE90WTJJa3RTbHciLCJpYXQiOjE0NTYzNTk1MTQsImlzcyI6Imh0dHBzOi8vcWFwb3J0YWwyLmdvc2VjdXJlYXV0aC5jb20vc2VjdXJlYXV0aDEyMyIsImF1ZCI6Ijg2NzFlYjY5ZDM2MTQyMDNiNGZlYzJlNGRiZWYyN2ZmIiwiZXhwIjoxNDU2NDQ1OTEzLCJuYmYiOjE0NTYzNTk1MTN9.lv722CdKN3JX6mcrjOUdWBI1Y34Pnh-1aV1-LxelYQdphN8A7rULYEMEnRa1fneFGk87GUf0DT9OsmOGbGggEsZZ6qzoaAiH4_OqbnxbwlKgySpWpthNUHz4Z_lcrhytXaA-_MVWAx4_33vIyQ1yQXmgnL1aDgMWekQ4bpWQ0RqSt16ZYqd51XiFxHy5utYDKATxfOJAiGDPX05YoBpThWkBsMUMIWun98EQgfQqsrm_OD26C2Nh9GJ1wiu6IBHYugIMyCFLpl2Op4lrWZFDhEKyXGWbVBRJJVnBwv704zELkdHlbMTbTvqxT9M-r8auqa_zg6dN41eWybSLiQgSIQ&session_state=pf-Opmj_7qw4QHxJTLVQtdVJJAPa2Hi6Dab56od08ps.a3bd2d9bb0f233a64f2d26e473684cee&state=8PkWbo8Q44RaH9nl
7.933223 AuthorizationResponse: {
"access_token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSIsImtpZCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSJ9.eyJjbGllbnRfaWQiOiI4NjcxZWI2OWQzNjE0MjAzYjRmZWMyZTRkYmVmMjdmZiIsInNjb3BlIjoib3BlbmlkIiwic3ViIjoidXNlcjcxIiwiYW1yIjoicGFzc3dvcmQiLCJhdXRoX3RpbWUiOjE0NTYzNTkyOTgsImlkcCI6IlNlY3VyZUF1dGgxMjMiLCJpc3MiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJhdWQiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJleHAiOjE0NTY0NDU5MTMsIm5iZiI6MTQ1NjM1OTUxM30.I4pFRE1y3R2UmDL5I1IVpi3707lDJi0t0nPQaGzJMSjuMngFe_zhDMehEaW2q5zg-PEFgrb6nPTxOWIrhCq2bh4DHfAEvaO0h4yjyDlzyo-FCZ_zlWjV_PwZbVn5_tgsW1_VdbEgbjLa3egaU4tOWgq6idVkH8bPevooYsIE2Q0IjChBYf-LsEHtV3JTgyUw7iCMZ7QGPuNjkHMLcTp4GlqFDvjodWerafA7JbwbVn_ID8gdO6UKvzK5PUHaA4YvZQDd0pIka50wmcBsuF8AhYYgFrvV6jgmRcPIK1VqO077c6G5R6WeUaVC7EDGdZ5s1L_JbitIMBIgWM6cCByk6Q",
"id_token": {
"claims": {
"amr": [
"password"
],
"at_hash": "Mackunbc3lUhOtY2IktSlw",
"aud": [
"8671eb69d3614203b4fec2e4dbef27ff"
],
"auth_time": 1456359298,
"exp": 1456445913,
"iat": 1456359514,
"idp": "SecureAuth123",
"iss": "https://qaportal2.gosecureauth.com/secureauth123",
"nbf": 1456359513,
"nonce": "JqC9lgUpmI5N",
"sub": "user71"
},
"jws header parameters": {
"alg": "RS256",
"kid": "kL3mwBbniGrOr-Hhw0D8e_-rRWU",
"typ": "JWT",
"x5t": "kL3mwBbniGrOr-Hhw0D8e_-rRWU"
}
},
"session_state": "pf-Opmj_7qw4QHxJTLVQtdVJJAPa2Hi6Dab56od08ps.a3bd2d9bb0f233a64f2d26e473684cee",
"state": "8PkWbo8Q44RaH9nl",
"token_type": "Bearer"
}
7.933990 ------------ AuthorizationRequest ------------
7.934453 --> URL: https://qaportal2.gosecureauth.com/secureauth123/SecureAuth.aspx?nonce=mnohBVtatifx&max_age=10000&state=PtdjhWOT5WS8PMBp&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A60097%2Fauthz_cb&response_type=id_token+token&client_id=8671eb69d3614203b4fec2e4dbef27ff&scope=openid
7.934461 --> BODY: None
13.419649 QUERY_STRING:
13.987920 <-- access_token=eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSIsImtpZCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSJ9.eyJjbGllbnRfaWQiOiI4NjcxZWI2OWQzNjE0MjAzYjRmZWMyZTRkYmVmMjdmZiIsInNjb3BlIjoib3BlbmlkIiwic3ViIjoidXNlcjcxIiwiYW1yIjoicGFzc3dvcmQiLCJhdXRoX3RpbWUiOjE0NTYzNTkyOTgsImlkcCI6IlNlY3VyZUF1dGgxMjMiLCJpc3MiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJhdWQiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJleHAiOjE0NTY0NDU5MjAsIm5iZiI6MTQ1NjM1OTUyMH0.EJEFRGLfLZpMf4SjnJLejwf76sfRanAWMDrk98bBUBkJvYsepTBqiUbDrZLO0sJTZ1gOtxGcIl7oIKx2ee20IlcoRCU1LfzDdukyclEjN0XFzmMFbu2PptE-ibxWPmVl1TInu0X4DotDAcZKaL6rNJHGQ0rtG-l8hpTDTTBSyNimH1kaf9JZCAofjsODYS6I_XbvinLg5r3pcP-8Iaa5shZleNoJnTmZzOhAOsNNiyiOjm4X9H4j8zFqC4-N7mSSi_VPvFQ_SO6n2PDH2_K2fk5fYmw-gviCpGfnMALuHl9AsRMEF8iEOgDYLFyBSZ08olCrM1BlCyXsADJ5LriHpw&token_type=Bearer&id_token=eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSIsImtpZCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSJ9.eyJhbXIiOiJwYXNzd29yZCIsImlkcCI6IlNlY3VyZUF1dGgxMjMiLCJhdXRoX3RpbWUiOjE0NTYzNTkyOTgsInN1YiI6InVzZXI3MSIsIm5vbmNlIjoibW5vaEJWdGF0aWZ4IiwiYXRfaGFzaCI6IldtVlBDZ05tNHlRdzlrdHFoOEN1NVEiLCJpYXQiOjE0NTYzNTk1MjAsImlzcyI6Imh0dHBzOi8vcWFwb3J0YWwyLmdvc2VjdXJlYXV0aC5jb20vc2VjdXJlYXV0aDEyMyIsImF1ZCI6Ijg2NzFlYjY5ZDM2MTQyMDNiNGZlYzJlNGRiZWYyN2ZmIiwiZXhwIjoxNDU2NDQ1OTIwLCJuYmYiOjE0NTYzNTk1MjB9.cNATSJ5jJ_XSVdmm4TevoBQJrazo4lRDbRgElj8L4WakKj2wSZbI1VaOTPeHl8bWZCCeKh32QffbdRP45L1htU1xBnCxJWni9d_9D6OsuEUU2ycJHVjeMwwOqTuecU4C9vfl9wX7re5qGoOLkXPWWmnlkM-5upNtyag_PIs0yAjptvjf_jLBJ9Od-IKCCuZ3VQjoqXL80xULQv-pA42B28betCWOZwOoxPQmPikmhgQMn_FdFIPhyjEe7xRnd3NSVOC5UpmgehMFP1wepM70_UMmS4oTguO0xzJtILZAUk1alrWvPWfNwazuJauo8CnTZL3J014rb6NNSIQeE9hG9w&session_state=hNRHg3qGpcjevtX3dzsXr-O4GHfJ75jolDE5ZxAr4Ug.4317f33f64947a4882a800d8bee69938&state=PtdjhWOT5WS8PMBp
13.997032 AuthorizationResponse: {
"access_token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSIsImtpZCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSJ9.eyJjbGllbnRfaWQiOiI4NjcxZWI2OWQzNjE0MjAzYjRmZWMyZTRkYmVmMjdmZiIsInNjb3BlIjoib3BlbmlkIiwic3ViIjoidXNlcjcxIiwiYW1yIjoicGFzc3dvcmQiLCJhdXRoX3RpbWUiOjE0NTYzNTkyOTgsImlkcCI6IlNlY3VyZUF1dGgxMjMiLCJpc3MiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJhdWQiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJleHAiOjE0NTY0NDU5MjAsIm5iZiI6MTQ1NjM1OTUyMH0.EJEFRGLfLZpMf4SjnJLejwf76sfRanAWMDrk98bBUBkJvYsepTBqiUbDrZLO0sJTZ1gOtxGcIl7oIKx2ee20IlcoRCU1LfzDdukyclEjN0XFzmMFbu2PptE-ibxWPmVl1TInu0X4DotDAcZKaL6rNJHGQ0rtG-l8hpTDTTBSyNimH1kaf9JZCAofjsODYS6I_XbvinLg5r3pcP-8Iaa5shZleNoJnTmZzOhAOsNNiyiOjm4X9H4j8zFqC4-N7mSSi_VPvFQ_SO6n2PDH2_K2fk5fYmw-gviCpGfnMALuHl9AsRMEF8iEOgDYLFyBSZ08olCrM1BlCyXsADJ5LriHpw",
"id_token": {
"claims": {
"amr": [
"password"
],
"at_hash": "WmVPCgNm4yQw9ktqh8Cu5Q",
"aud": [
"8671eb69d3614203b4fec2e4dbef27ff"
],
"auth_time": 1456359298,
"exp": 1456445920,
"iat": 1456359520,
"idp": "SecureAuth123",
"iss": "https://qaportal2.gosecureauth.com/secureauth123",
"nbf": 1456359520,
"nonce": "mnohBVtatifx",
"sub": "user71"
},
"jws header parameters": {
"alg": "RS256",
"kid": "kL3mwBbniGrOr-Hhw0D8e_-rRWU",
"typ": "JWT",
"x5t": "kL3mwBbniGrOr-Hhw0D8e_-rRWU"
}
},
"session_state": "hNRHg3qGpcjevtX3dzsXr-O4GHfJ75jolDE5ZxAr4Ug.4317f33f64947a4882a800d8bee69938",
"state": "PtdjhWOT5WS8PMBp",
"token_type": "Bearer"
}
13.997736 ==== END ====
Result
PASSED