Test Info

Profile[]
Test descriptionDoes the OP sign the ID Token and with what
Timestamp2017-10-13T14:30:20Z
Issuerhttps://ofis.theoptimalcloud.com/odn/
Test IDOP-IDToken-C-Signature

Conditions


is-idtoken-signed: status=OK [Checks if the id_token is signed]
verify-response: status=OK [Checks that the last response was one of a possible set of OpenID Connect Responses]
Done: status=OK

Trace Output

0.0phase<--<-- 0 --- Webfinger -->-->
0.0not expected to doWebFinger
0.0phase<--<-- 1 --- Discovery -->-->
0.0not expected to doDynamic discovery
0.0phase<--<-- 2 --- Registration -->-->
0.001not expected to doDynamic registration
0.001phase<--<-- 3 --- AsyncAuthn -->-->
0.001AuthorizationRequest
{
    "client_id": "https://op.certification.openid.net/",
    "nonce": "ge9wiHRNeJAkGX2R",
    "redirect_uri": "https://op.certification.openid.net:60044/authz_cb",
    "response_type": "id_token token",
    "scope": "openid",
    "state": "9LD9EDj5ee3bjArV"
}
0.001redirect urlhttps://ofis.theoptimalcloud.com/odn/?nonce=ge9wiHRNeJAkGX2R&response_type=id_token+token&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A60044%2Fauthz_cb&client_id=https%3A%2F%2Fop.certification.openid.net%2F&state=9LD9EDj5ee3bjArV&scope=openid
0.001redirecthttps://ofis.theoptimalcloud.com/odn/?nonce=ge9wiHRNeJAkGX2R&response_type=id_token+token&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A60044%2Fauthz_cb&client_id=https%3A%2F%2Fop.certification.openid.net%2F&state=9LD9EDj5ee3bjArV&scope=openid
0.22http args{}
0.301responseaccess_token=dHIXCTpJvCaQgKV9vHKPIHwsaPmEBPrv423LhebIeqeafjyjRmDGZ3X_zwOW2HOrml8Sqey7BCy29YzrYKeUZuaKfnm9RBOEziy-sFC29pzwgm-jOJdb7918u0XzarouRICXQ2Xpqdu087VF6YaRTM3A1naM4Zby4ub5RsGpIk90aQCZ3_LyBeQ8CNUcZvFnctR0QZd1qjv1qk1Lhb7xF_X46kRveE7SVNxOLqu4_egYAQXT4NhmeIdt_cG-wccU&id_token=eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6Il9zZnJweWVzUFVyQTl5TkhXYXBOZXYwOVlYQSJ9.eyJzdWIiOiJqQnJEYWJVVTdFR1V5QXhEQjZLekNnPT0iLCJlbWFpbCI6ImplZmYuYm9ocmVuQG9wdGltYWxpZG0uY29tIiwiZ2l2ZW5fbmFtZSI6IkplZmZyZXkiLCJmYW1pbHlfbmFtZSI6IkJvaHJlbiIsIm5hbWUiOiJKZWZmcmV5IEJvaHJlbiIsIm1pZGRsZV9uYW1lIjoiU2NvdHQiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJqZWZmLmJvaHJlbkBvcHRpbWFsaWRtLmNvbSIsInBob25lX251bWJlciI6IjU1NS0xMjEyIiwibmlja25hbWUiOiJKZWZmcmV5IiwicHJvZmlsZSI6Imh0dHBzOi8vb3B0aW1hbGlkbS5jb20iLCJwaWN0dXJlIjoiaHR0cHM6Ly9vcHRpbWFsaWRtLmNvbSIsIndlYnNpdGUiOiJodHRwOi8vb3B0aW1hbGlkbS5jb20iLCJnZW5kZXIiOiJtYWxlIiwiYmlydGhkYXRlIjoiMTk3Mi0wMS0wMSIsInpvbmVpbmZvIjoiRWFzdCBVUyIsImxvY2FsZSI6ImVuLVVTIiwibm9uY2UiOiJnZTl3aUhSTmVKQWtHWDJSIiwiYXRfaGFzaCI6IkotcDlHU1J2bFZtUVltVzVQZ1VlOVEiLCJjX2hhc2giOiJsTGxnOV9jZGVWV25CZG5xWHNzdmx3IiwiaWF0IjoxNTA3OTA1MDIwLCJpc3MiOiJodHRwczovL29maXMudGhlb3B0aW1hbGNsb3VkLmNvbS9vZG4vIiwiYXVkIjoiaHR0cHM6Ly9vcC5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvIiwiZXhwIjoxNTA3OTA1NjIwLCJuYmYiOjE1MDc5MDUwMTl9.PRRK1ZDatKed7Oqv0fXWVBHrBMsJPK29To9v6vapQ-slny6ChICSwpZivISER0RdU_mpl0IFpX4fuavWDkU1ZdJGCMlwsRqvs16hvUKV5SziFe2MGrSYMWhSQH5q6L0KwzjZni9SKGz84S6s0IisLH6v0pDZJ3T22k_L7CzwxDA_YL51K_SWhZQsZl3G2_I9dxMT0clIGMoY23qQdKa3UyPY8RpPR-AXaCs_XOmWdhfOI_naU4HSsaoEqvUkcFR5yTZxJt9oGAts_2Apw7LG-lol8gM5zEh62owcdbSUwEcnYNAaOgKyo27Ic-wPhchM0KAekVdcMKH6wtIz8nrazQ&token_type=Bearer&state=9LD9EDj5ee3bjArV&expires_in=36000
0.302response{'access_token': 'dHIXCTpJvCaQgKV9vHKPIHwsaPmEBPrv423LhebIeqeafjyjRmDGZ3X_zwOW2HOrml8Sqey7BCy29YzrYKeUZuaKfnm9RBOEziy-sFC29pzwgm-jOJdb7918u0XzarouRICXQ2Xpqdu087VF6YaRTM3A1naM4Zby4ub5RsGpIk90aQCZ3_LyBeQ8CNUcZvFnctR0QZd1qjv1qk1Lhb7xF_X46kRveE7SVNxOLqu4_egYAQXT4NhmeIdt_cG-wccU', 'id_token': 'eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6Il9zZnJweWVzUFVyQTl5TkhXYXBOZXYwOVlYQSJ9.eyJzdWIiOiJqQnJEYWJVVTdFR1V5QXhEQjZLekNnPT0iLCJlbWFpbCI6ImplZmYuYm9ocmVuQG9wdGltYWxpZG0uY29tIiwiZ2l2ZW5fbmFtZSI6IkplZmZyZXkiLCJmYW1pbHlfbmFtZSI6IkJvaHJlbiIsIm5hbWUiOiJKZWZmcmV5IEJvaHJlbiIsIm1pZGRsZV9uYW1lIjoiU2NvdHQiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJqZWZmLmJvaHJlbkBvcHRpbWFsaWRtLmNvbSIsInBob25lX251bWJlciI6IjU1NS0xMjEyIiwibmlja25hbWUiOiJKZWZmcmV5IiwicHJvZmlsZSI6Imh0dHBzOi8vb3B0aW1hbGlkbS5jb20iLCJwaWN0dXJlIjoiaHR0cHM6Ly9vcHRpbWFsaWRtLmNvbSIsIndlYnNpdGUiOiJodHRwOi8vb3B0aW1hbGlkbS5jb20iLCJnZW5kZXIiOiJtYWxlIiwiYmlydGhkYXRlIjoiMTk3Mi0wMS0wMSIsInpvbmVpbmZvIjoiRWFzdCBVUyIsImxvY2FsZSI6ImVuLVVTIiwibm9uY2UiOiJnZTl3aUhSTmVKQWtHWDJSIiwiYXRfaGFzaCI6IkotcDlHU1J2bFZtUVltVzVQZ1VlOVEiLCJjX2hhc2giOiJsTGxnOV9jZGVWV25CZG5xWHNzdmx3IiwiaWF0IjoxNTA3OTA1MDIwLCJpc3MiOiJodHRwczovL29maXMudGhlb3B0aW1hbGNsb3VkLmNvbS9vZG4vIiwiYXVkIjoiaHR0cHM6Ly9vcC5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvIiwiZXhwIjoxNTA3OTA1NjIwLCJuYmYiOjE1MDc5MDUwMTl9.PRRK1ZDatKed7Oqv0fXWVBHrBMsJPK29To9v6vapQ-slny6ChICSwpZivISER0RdU_mpl0IFpX4fuavWDkU1ZdJGCMlwsRqvs16hvUKV5SziFe2MGrSYMWhSQH5q6L0KwzjZni9SKGz84S6s0IisLH6v0pDZJ3T22k_L7CzwxDA_YL51K_SWhZQsZl3G2_I9dxMT0clIGMoY23qQdKa3UyPY8RpPR-AXaCs_XOmWdhfOI_naU4HSsaoEqvUkcFR5yTZxJt9oGAts_2Apw7LG-lol8gM5zEh62owcdbSUwEcnYNAaOgKyo27Ic-wPhchM0KAekVdcMKH6wtIz8nrazQ', 'state': '9LD9EDj5ee3bjArV', 'expires_in': 36000, 'token_type': 'Bearer'}
0.431AuthorizationResponse
{
    "access_token": "dHIXCTpJvCaQgKV9vHKPIHwsaPmEBPrv423LhebIeqeafjyjRmDGZ3X_zwOW2HOrml8Sqey7BCy29YzrYKeUZuaKfnm9RBOEziy-sFC29pzwgm-jOJdb7918u0XzarouRICXQ2Xpqdu087VF6YaRTM3A1naM4Zby4ub5RsGpIk90aQCZ3_LyBeQ8CNUcZvFnctR0QZd1qjv1qk1Lhb7xF_X46kRveE7SVNxOLqu4_egYAQXT4NhmeIdt_cG-wccU",
    "expires_in": 36000,
    "id_token": {
        "at_hash": "J-p9GSRvlVmQYmW5PgUe9Q",
        "aud": [
            "https://op.certification.openid.net/"
        ],
        "birthdate": "1972-01-01",
        "c_hash": "lLlg9_cdeVWnBdnqXssvlw",
        "email": "jeff.bohren@optimalidm.com",
        "exp": 1507905620,
        "family_name": "Bohren",
        "gender": "male",
        "given_name": "Jeffrey",
        "iat": 1507905020,
        "iss": "https://ofis.theoptimalcloud.com/odn/",
        "locale": "en-US",
        "middle_name": "Scott",
        "name": "Jeffrey Bohren",
        "nbf": 1507905019,
        "nickname": "Jeffrey",
        "nonce": "ge9wiHRNeJAkGX2R",
        "phone_number": "555-1212",
        "picture": "https://optimalidm.com",
        "preferred_username": "jeff.bohren@optimalidm.com",
        "profile": "https://optimalidm.com",
        "sub": "jBrDabUU7EGUyAxDB6KzCg==",
        "website": "http://optimalidm.com",
        "zoneinfo": "East US"
    },
    "state": "9LD9EDj5ee3bjArV",
    "token_type": "Bearer"
}
0.431phase<--<-- 4 --- AccessToken -->-->
0.431phase<--<-- 5 --- Done -->-->
0.431end
0.432assertionIsIDTokenSigned
0.432conditionis-idtoken-signed: status=OK [Checks if the id_token is signed]
0.432assertionVerifyResponse
0.432conditionverify-response: status=OK [Checks that the last response was one of a possible set of OpenID Connect Responses]
0.432conditionDone: status=OK

Result

PASSED