Test Summary

Test Results

Expand All Collapse All
All times are UTC
2020-09-01 12:50:53 INFO
TEST-RUNNER
Test instance GXsduuuUgWmCmPQ created
baseUrl
https://www.certification.openid.net/test/GXsduuuUgWmCmPQ
variant
{
  "client_auth_type": "client_secret_basic",
  "response_type": "id_token",
  "request_type": "plain_http_request",
  "response_mode": "form_post",
  "client_registration": "dynamic_client"
}
alias

                                
description
test suite runner for openid-client
planId
2AWaC6uTX8byR
config
{
  "description": "test suite runner for openid-client",
  "waitTimeoutSeconds": 2
}
testName
oidcc-client-test-invalid-sig-rs256
2020-09-01 12:50:53 SUCCESS
OIDCCGenerateServerConfigurationIdTokenSigningAlgRS256Only
Generated default server configuration
server_configuration
{
  "issuer": "https://www.certification.openid.net/test/GXsduuuUgWmCmPQ/",
  "authorization_endpoint": "https://www.certification.openid.net/test/GXsduuuUgWmCmPQ/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/GXsduuuUgWmCmPQ/token",
  "jwks_uri": "https://www.certification.openid.net/test/GXsduuuUgWmCmPQ/jwks",
  "userinfo_endpoint": "https://www.certification.openid.net/test/GXsduuuUgWmCmPQ/userinfo",
  "registration_endpoint": "https://www.certification.openid.net/test/GXsduuuUgWmCmPQ/register",
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access"
  ],
  "response_types_supported": [
    "code",
    "id_token code",
    "token code id_token",
    "id_token",
    "token id_token",
    "token code",
    "token"
  ],
  "response_modes_supported": [
    "query",
    "fragment",
    "form_post"
  ],
  "token_endpoint_auth_methods_supported": [
    "client_secret_basic",
    "client_secret_post",
    "client_secret_jwt",
    "private_key_jwt"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "RS256",
    "RS384",
    "RS512",
    "PS256",
    "PS384",
    "PS512",
    "ES256",
    "ES256K",
    "ES384",
    "ES512",
    "EdDSA"
  ],
  "grant_types_supported": [
    "authorization_code",
    "implicit"
  ],
  "claims_parameter_supported": true,
  "acr_values_supported": [
    "PASSWORD"
  ],
  "subject_types_supported": [
    "public",
    "pairwise"
  ],
  "claim_types_supported": [
    "normal",
    "aggregated",
    "distributed"
  ],
  "claims_supported": [
    "sub",
    "name",
    "given_name",
    "family_name",
    "middle_name",
    "nickname",
    "gender",
    "birthdate",
    "preferred_username",
    "profile",
    "website",
    "locale",
    "updated_at",
    "address",
    "zoneinfo",
    "phone_number",
    "phone_number_verified",
    "email",
    "email_verified"
  ],
  "id_token_signing_alg_values_supported": [
    "RS256"
  ],
  "id_token_encryption_alg_values_supported": [
    "RSA1_5",
    "RSA-OAEP",
    "RSA-OAEP-256",
    "ECDH-ES",
    "ECDH-ES+A128KW",
    "ECDH-ES+A192KW",
    "ECDH-ES+A256KW",
    "A128KW",
    "A192KW",
    "A256KW",
    "A128GCMKW",
    "A192GCMKW",
    "A256GCMKW",
    "dir"
  ],
  "id_token_encryption_enc_values_supported": [
    "A128CBC-HS256",
    "A192CBC-HS384",
    "A256CBC-HS512",
    "A128GCM",
    "A192GCM",
    "A256GCM"
  ],
  "request_object_signing_alg_values_supported": [
    "none",
    "RS256",
    "RS384",
    "RS512",
    "PS256",
    "PS384",
    "PS512",
    "ES256",
    "ES256K",
    "ES384",
    "ES512",
    "EdDSA"
  ],
  "request_object_encryption_alg_values_supported": [
    "RSA1_5",
    "RSA-OAEP",
    "RSA-OAEP-256",
    "ECDH-ES",
    "ECDH-ES+A128KW",
    "ECDH-ES+A192KW",
    "ECDH-ES+A256KW",
    "A128KW",
    "A192KW",
    "A256KW",
    "A128GCMKW",
    "A192GCMKW",
    "A256GCMKW",
    "dir"
  ],
  "request_object_encryption_enc_values_supported": [
    "A128CBC-HS256",
    "A192CBC-HS384",
    "A256CBC-HS512",
    "A128GCM",
    "A192GCM",
    "A256GCM"
  ],
  "userinfo_signing_alg_values_supported": [
    "RS256",
    "RS384",
    "RS512",
    "PS256",
    "PS384",
    "PS512",
    "ES256",
    "ES256K",
    "ES384",
    "ES512",
    "EdDSA"
  ],
  "userinfo_encryption_alg_values_supported": [
    "RSA1_5",
    "RSA-OAEP",
    "RSA-OAEP-256",
    "ECDH-ES",
    "ECDH-ES+A128KW",
    "ECDH-ES+A192KW",
    "ECDH-ES+A256KW",
    "A128KW",
    "A192KW",
    "A256KW",
    "A128GCMKW",
    "A192GCMKW",
    "A256GCMKW",
    "dir"
  ],
  "userinfo_encryption_enc_values_supported": [
    "A128CBC-HS256",
    "A192CBC-HS384",
    "A256CBC-HS512",
    "A128GCM",
    "A192GCM",
    "A256GCM"
  ]
}
2020-09-01 12:50:53
SetTokenEndpointAuthMethodsSupportedToClientSecretBasicOnly
Changed token_endpoint_auth_methods_supported to client_secret_basic only in server configuration
server_configuration
{
  "issuer": "https://www.certification.openid.net/test/GXsduuuUgWmCmPQ/",
  "authorization_endpoint": "https://www.certification.openid.net/test/GXsduuuUgWmCmPQ/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/GXsduuuUgWmCmPQ/token",
  "jwks_uri": "https://www.certification.openid.net/test/GXsduuuUgWmCmPQ/jwks",
  "userinfo_endpoint": "https://www.certification.openid.net/test/GXsduuuUgWmCmPQ/userinfo",
  "registration_endpoint": "https://www.certification.openid.net/test/GXsduuuUgWmCmPQ/register",
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access"
  ],
  "response_types_supported": [
    "code",
    "id_token code",
    "token code id_token",
    "id_token",
    "token id_token",
    "token code",
    "token"
  ],
  "response_modes_supported": [
    "query",
    "fragment",
    "form_post"
  ],
  "token_endpoint_auth_methods_supported": [
    "client_secret_basic"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "RS256",
    "RS384",
    "RS512",
    "PS256",
    "PS384",
    "PS512",
    "ES256",
    "ES256K",
    "ES384",
    "ES512",
    "EdDSA"
  ],
  "grant_types_supported": [
    "authorization_code",
    "implicit"
  ],
  "claims_parameter_supported": true,
  "acr_values_supported": [
    "PASSWORD"
  ],
  "subject_types_supported": [
    "public",
    "pairwise"
  ],
  "claim_types_supported": [
    "normal",
    "aggregated",
    "distributed"
  ],
  "claims_supported": [
    "sub",
    "name",
    "given_name",
    "family_name",
    "middle_name",
    "nickname",
    "gender",
    "birthdate",
    "preferred_username",
    "profile",
    "website",
    "locale",
    "updated_at",
    "address",
    "zoneinfo",
    "phone_number",
    "phone_number_verified",
    "email",
    "email_verified"
  ],
  "id_token_signing_alg_values_supported": [
    "RS256"
  ],
  "id_token_encryption_alg_values_supported": [
    "RSA1_5",
    "RSA-OAEP",
    "RSA-OAEP-256",
    "ECDH-ES",
    "ECDH-ES+A128KW",
    "ECDH-ES+A192KW",
    "ECDH-ES+A256KW",
    "A128KW",
    "A192KW",
    "A256KW",
    "A128GCMKW",
    "A192GCMKW",
    "A256GCMKW",
    "dir"
  ],
  "id_token_encryption_enc_values_supported": [
    "A128CBC-HS256",
    "A192CBC-HS384",
    "A256CBC-HS512",
    "A128GCM",
    "A192GCM",
    "A256GCM"
  ],
  "request_object_signing_alg_values_supported": [
    "none",
    "RS256",
    "RS384",
    "RS512",
    "PS256",
    "PS384",
    "PS512",
    "ES256",
    "ES256K",
    "ES384",
    "ES512",
    "EdDSA"
  ],
  "request_object_encryption_alg_values_supported": [
    "RSA1_5",
    "RSA-OAEP",
    "RSA-OAEP-256",
    "ECDH-ES",
    "ECDH-ES+A128KW",
    "ECDH-ES+A192KW",
    "ECDH-ES+A256KW",
    "A128KW",
    "A192KW",
    "A256KW",
    "A128GCMKW",
    "A192GCMKW",
    "A256GCMKW",
    "dir"
  ],
  "request_object_encryption_enc_values_supported": [
    "A128CBC-HS256",
    "A192CBC-HS384",
    "A256CBC-HS512",
    "A128GCM",
    "A192GCM",
    "A256GCM"
  ],
  "userinfo_signing_alg_values_supported": [
    "RS256",
    "RS384",
    "RS512",
    "PS256",
    "PS384",
    "PS512",
    "ES256",
    "ES256K",
    "ES384",
    "ES512",
    "EdDSA"
  ],
  "userinfo_encryption_alg_values_supported": [
    "RSA1_5",
    "RSA-OAEP",
    "RSA-OAEP-256",
    "ECDH-ES",
    "ECDH-ES+A128KW",
    "ECDH-ES+A192KW",
    "ECDH-ES+A256KW",
    "A128KW",
    "A192KW",
    "A256KW",
    "A128GCMKW",
    "A192GCMKW",
    "A256GCMKW",
    "dir"
  ],
  "userinfo_encryption_enc_values_supported": [
    "A128CBC-HS256",
    "A192CBC-HS384",
    "A256CBC-HS512",
    "A128GCM",
    "A192GCM",
    "A256GCM"
  ]
}
2020-09-01 12:50:53
OIDCCGenerateServerJWKs
Generated server public private JWK sets
server_jwks
{
  "keys": [
    {
      "p": "3KCEbfPKnc7-gbPD6S6FG46uh-ee_MaL0e53j7VxzvvC5XwsTcv5ggAprG8-QSAmc2X8egx139zSfYQ8g0Z8wDgqLeJLtkEfScLD91IQhWxpFgSiXsz2DZv_dm19yOmPs_ySwHpmrGhWmQgvfMK7yGhbmxDFrtmg-aryQqRC5G8",
      "kty": "RSA",
      "q": "xXucxMJqMS66UhSwSv833pn-_22Ee1rWCAO0Q4ZwqyYz4yijTknMcUiqK1IqzWQbLz3rIOJrwD9uDZmA1BSQXUc0htxJLYOSmYXFwjODwp_Xj0shHvEOEII-P5vOmUCUMVfSbp6y1IPpHTmxcXWL7E_VYcHa6dDFFb_ROUVzlf0",
      "d": "yhqmr6gA0PAUMl9RprcpbsceKi3GhTkbyc0gHPqMadsDGlh-Rfk4PdUxNcKPmM3nXkjiRIQZyEQ82eVTb6Tu6uAm-nbNHwHhdUCEIcMVN6Q9YwbmhSSWZq7KDlPTRjA7DkhhBgSkABR4KaA8l-UlAbO9juJOSjbPaQjeYADVr5F8E48cGPqC4VqtyJ3pI94MitkTFtweJ_uP2bEYMQcLgwoW_kYjUL9DtzfRw4MC6Yra3D5_qJB_bnCTK27PIxXe2vaWyaGmIm8YmhvZ3mvDN31hhnE9tjGh7AtsY_sXRoQB56cFngWtV1gQ6X1I7RzhKONuadJz0jqv5GNLq7WB",
      "e": "AQAB",
      "use": "sig",
      "kid": "d96c50db-04f4-4a45-8b6c-4739d5574109",
      "qi": "kCWGawAwK269o4H50jJtr6ihLsRwU7QDTC37ANXy3QZu4g3bynrzv0UjwlghlJteJhtW-AQJAM85cFc1-oJLdqpwtRiTblZipu8pCw9lLyK-Dl4Vm99swXz-7Z5RIdqEqf5-f-gHe-hnO9hZ77mk7avuUL-YMGyUwfspPJGDiV8",
      "dp": "zk88ByWGPvOlgtv7Qz5BMnfGNUgen_l6HiGEpFnjxs4efkITm9w1wZ8tWRXdfUD3M8oWwnqMb34rRzw06f0sAwOCTc3jRta2z17VqZyP3nR2ACTtQQEgxbEuviu9B_eAbaquAFd1U5tt_0RsQ5pFxy3vG54ffVX89fso97Bq7Pk",
      "dq": "STntxnPEhpoqEneDazu5jrwRdss4PblP9cbR19wI-R2ATfHqpAPvX-4u00NzhZdiESFnh1kN1Upv13Ec-QbrBPt7OaqDI_JOsMiOrNUHPWqhtouIK3381hhFVrbCY8czbByBde04qF6FWQXkiwqoKKbtm4MTVnHIMqlevlrHYk0",
      "n": "qjIOI6CUm71io7-XmUrKOuWEKYNRblCHlqkwxSPs9jwl3Bc9JyFB3YSTZ4npkE68xuVD1WOtuZKLC-bizkpqlAywuBkT3HhsLm1zsROMnT3b0DmBTYKd7osbkchSMNqHyNp4rc7gA_mooBSL-V_HfwddsV4zg85ma6in7IYSQ7bUVkWQvQR6qWXuAR-8ZSFY0dquBD2_uQu4HwQzIrlpvqqoq9qq5a0s7_iBANjeCBdVgXY5KrlWAGj4Qsx7NDnA0OoHD5v-hMPEJ95RFPdW5pH9vsXSFR6DRLS9I755HgT55PNwKtIsLRvYKD26W_vAvQxuwtc4XX_AXILMze1csw"
    },
    {
      "kty": "EC",
      "d": "OOB84eU3hWr9x_kEUmrKdh7hQ3p7aw8XJ2khp0F1HAs",
      "use": "sig",
      "crv": "P-256",
      "kid": "9ff67717-69cc-45f3-84a6-63cbedcbdc33",
      "x": "MJdvm3w6qbkPFAhXCsSrku41Z6YqgixH8N7aw95TCAE",
      "y": "MzjExnt1cABaif9X5p3Z--07xjuVC-eG7FTzV9GBo5I"
    },
    {
      "kty": "EC",
      "d": "zo13JEG1s5FST-6fNUIV_-tVKUnKzHxTTGu3_Ur3Jd0",
      "use": "sig",
      "crv": "secp256k1",
      "kid": "6e2fdea0-d70f-4c5f-a91e-7f528fa0cae7",
      "x": "GblGBRW9tMaAEGcjl1eUAaAW0BiubgAtqiq4K_DcMsA",
      "y": "ZeqtWw-DsZLF3W4OZDF1Q7tx2TOfqXhusE8DLAHVyGw"
    },
    {
      "kty": "OKP",
      "d": "7i7AAYwUBUfoIPjvBXOPSWZz1sU4eDiwdqH3z1Pq6mw",
      "use": "sig",
      "crv": "Ed25519",
      "kid": "f2b47240-7fd5-4d77-9722-f47dc51c242f",
      "x": "cuPTXi7mz_5pKTdEXT_SBQlAZBkafisQ3vD55ft9sxA"
    }
  ]
}
server_encryption_keys
{
  "keys": [
    {
      "p": "2Z61aaobC-NLf9W0SCC7gTQEasWXlFjpzMlMi5WlZrxRo9sbEtWuXZzT_rcUTp05-gAS5WLUd9xyVZNK19yWZppWj-htyB1cg1CJUBs38xsttSSU8qneTiesx0AU31eSseWY2D-5zyPlxnmbg6VgCuH_DNso_mad6gTj6IV9rR8",
      "kty": "RSA",
      "q": "rkffkUpxGjLJ4C2zrcztU7VTTT8aGzlOLViVv3gTHlvp43pfUBZipyXcEV5IOzB8pr2-_qaPZc9Ov-RQ39Z1paYoR7Mnjjx12zXa6WV2Qj62TwfFpu3osDdkq-e9_nGYzmUr7PgJd6QNqNVfQVEYSxImxqfGajbdev4vyyim558",
      "d": "BIvJlUfUwognhU-PQHPJ3Z_0ctsUpbylaryTPlH39dPQV2WHmKOp-WL0Oe11_507kcsFco_hnquq_8ZdOL8N25dtDShQTyYvPPgj46XNDyes1iBUdLDJjEidfmv6Cnxov2uqpwv8blDx6NxPbt-Wg2SYH_LX3gMmpRlNqkJQuDSe9c5LKmtC8KxV9B2e_4Q6eAa1GSvJ_30YCbNoQYMZlKpCWkrRqfS-Q61SOz6DX-Ndwn0641CvwARp8nN_4ywOPQnpaDVmBdxebpEErMIyHs3pgKwAPhDA8nzaExBU43nkzmWfCiAM4N6sFu9MtaoM2V2QEwj6I0HfwwIMZ-M67Q",
      "e": "AQAB",
      "use": "enc",
      "kid": "2ff7f73b-7403-4b8b-9678-6c4424b1c97a",
      "qi": "YSxOMDXNzNHLabO5ji7kl3yulavLMGfS0b6LDDt-4dZUypmSopOP6ps5M2lMAhs0VhaS3-kIbWPXUQoukAdrvVmaunE3KhpQAuqXv-CCSBRsmX04lvrQDacxRWzfHBSvEBJEWVkVxO9Cf9su1DDUaYSnJ7ZLK7PkDp0IO5sLbCA",
      "dp": "Y-fnsw3EAu4jcBmk_WQBkOxXhskVsKYtF7XmbUKTP5n_BPGG-VueBB4GeS6FpR2rSymTgzme_zP2TXEkb_s2FP6P9Nso4zEPkr17fIoyYmo8zqdvtgPkKg8u0_6IVox2rTMRu11uKTl6uGaFzaczc2uTUsyegkSMBK6gDtSSANM",
      "alg": "RSA-OAEP",
      "dq": "pqVfJ4RxBcYOtue8abIMNQCreK-f_Owczstn1T-xuFPXH4cB4IinKIDRH2Jx2vcQGjhRixolAArsmBxvILnmoNByr6ylZCJ353Zlrssv-0QP-x3JZ0cSOn2dK6taRxTEMocXK245T0d1MD1m6gPrIM1oeogu950ixtqLRM3IWq0",
      "n": "lCb4XuQgYV-b382pLtn6UvoGuQi4byuOXrXIGh-bJw1jUheMsBa8yseOj43uD27GNYqIaZLMxLcD4BgPKamDVA3UiahZjPvZMXDFCH1aYJY2dYTZDIGfIkOx-EtroJUZDnAIfhuvVJMv96BO0m3os6I-9In4N2C0SdPMAYZtCPXXIrMlkGq28fcoUD22KyyVzZ0c858fHwYkf0BcvO5Ak9H_1Gr6QMXP_AwWxmcu1dPcrmpREyNVS4lSbTn-kEl1aeMVfaSki8XuXZXm--Pp3MJSJ7U5_8fi58M7YzJ2ZNR2yBYLErrgCjeI-RoKNZSIzJwkzgx0e-BYhYj_al9_QQ"
    },
    {
      "kty": "EC",
      "d": "nJTMYIIKZB-hbINJ0-erbN6rHexiVWL697Urk8CKzLs",
      "use": "enc",
      "crv": "P-256",
      "kid": "078846eb-fc61-4ada-be15-c9df9c3da9fa",
      "x": "RNy5H4yNgoFjVh2bg6TV9Wx4xIFkqUyFfwwLvFUuZkA",
      "y": "fjJcF9BLvhFALHBPtNnuwrU9k9oUq5mGczYV9PLGSZw",
      "alg": "ECDH-ES"
    }
  ]
}
server_public_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "d96c50db-04f4-4a45-8b6c-4739d5574109",
      "n": "qjIOI6CUm71io7-XmUrKOuWEKYNRblCHlqkwxSPs9jwl3Bc9JyFB3YSTZ4npkE68xuVD1WOtuZKLC-bizkpqlAywuBkT3HhsLm1zsROMnT3b0DmBTYKd7osbkchSMNqHyNp4rc7gA_mooBSL-V_HfwddsV4zg85ma6in7IYSQ7bUVkWQvQR6qWXuAR-8ZSFY0dquBD2_uQu4HwQzIrlpvqqoq9qq5a0s7_iBANjeCBdVgXY5KrlWAGj4Qsx7NDnA0OoHD5v-hMPEJ95RFPdW5pH9vsXSFR6DRLS9I755HgT55PNwKtIsLRvYKD26W_vAvQxuwtc4XX_AXILMze1csw"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "8ddad6d5-9fac-454a-9bc0-a66ff5a2a004",
      "n": "jPyUwnH42UjMbyhhqbvXARYJuZLnr7MXyHQ0kmjBrBImU1BeE_WzoqjkLXRFWHQtF9RZI8Xch30wwtvs7w5X0r9V6Hslxl9jfk6qSQBYPH22kuRClBmW9cSF0uAuA1-WorLhbxN8wiAoRBkgDYo6Z-X2T3GX1yI_Yac6MNLZvR5tvu1JZEv72yUj43o07U9N_fo4P0EXl635j26ZvEYe0VkB4hL4J2wQXZUrhaKqLWa0BulKrwyqggMIvhUehZEX3bHk8tSkzG6OdBA7heAZIC2YnWrDlL5JTsijqNPZv1_bMmkvjwmt25v4opWUXNyGXUE0tzDqkYGfLzcos99WYw"
    },
    {
      "kty": "EC",
      "use": "sig",
      "crv": "P-256",
      "kid": "9ff67717-69cc-45f3-84a6-63cbedcbdc33",
      "x": "MJdvm3w6qbkPFAhXCsSrku41Z6YqgixH8N7aw95TCAE",
      "y": "MzjExnt1cABaif9X5p3Z--07xjuVC-eG7FTzV9GBo5I"
    },
    {
      "kty": "EC",
      "use": "sig",
      "crv": "P-256",
      "kid": "b49a31c0-7b88-4af8-a0f1-75e815d98e96",
      "x": "ttL5LOcVh1W7NFIEOkh38Ohy1Br6jJiuH0GdwthLQJw",
      "y": "C3pZICT3lZzJSRF6gNaEmj8rCNnkLIfx0lTKPRx2RYo"
    },
    {
      "kty": "EC",
      "use": "sig",
      "crv": "secp256k1",
      "kid": "6e2fdea0-d70f-4c5f-a91e-7f528fa0cae7",
      "x": "GblGBRW9tMaAEGcjl1eUAaAW0BiubgAtqiq4K_DcMsA",
      "y": "ZeqtWw-DsZLF3W4OZDF1Q7tx2TOfqXhusE8DLAHVyGw"
    },
    {
      "kty": "OKP",
      "use": "sig",
      "crv": "Ed25519",
      "kid": "f2b47240-7fd5-4d77-9722-f47dc51c242f",
      "x": "cuPTXi7mz_5pKTdEXT_SBQlAZBkafisQ3vD55ft9sxA"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "2ff7f73b-7403-4b8b-9678-6c4424b1c97a",
      "alg": "RSA-OAEP",
      "n": "lCb4XuQgYV-b382pLtn6UvoGuQi4byuOXrXIGh-bJw1jUheMsBa8yseOj43uD27GNYqIaZLMxLcD4BgPKamDVA3UiahZjPvZMXDFCH1aYJY2dYTZDIGfIkOx-EtroJUZDnAIfhuvVJMv96BO0m3os6I-9In4N2C0SdPMAYZtCPXXIrMlkGq28fcoUD22KyyVzZ0c858fHwYkf0BcvO5Ak9H_1Gr6QMXP_AwWxmcu1dPcrmpREyNVS4lSbTn-kEl1aeMVfaSki8XuXZXm--Pp3MJSJ7U5_8fi58M7YzJ2ZNR2yBYLErrgCjeI-RoKNZSIzJwkzgx0e-BYhYj_al9_QQ"
    },
    {
      "kty": "EC",
      "use": "enc",
      "crv": "P-256",
      "kid": "078846eb-fc61-4ada-be15-c9df9c3da9fa",
      "x": "RNy5H4yNgoFjVh2bg6TV9Wx4xIFkqUyFfwwLvFUuZkA",
      "y": "fjJcF9BLvhFALHBPtNnuwrU9k9oUq5mGczYV9PLGSZw",
      "alg": "ECDH-ES"
    }
  ]
}
2020-09-01 12:50:53 SUCCESS
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2020-09-01 12:50:53 SUCCESS
CheckDistinctKeyIdValueInServerJWKs
Distinct 'kid' value in all keys of server_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2020-09-01 12:50:53 SUCCESS
OIDCCLoadUserInfo
Added user information
user_info
{
  "sub": "user-subject-1234531",
  "name": "Demo T. User",
  "given_name": "Demo",
  "family_name": "User",
  "middle_name": "Theresa",
  "nickname": "Dee",
  "preferred_username": "d.tu",
  "gender": "female",
  "birthdate": "2000-02-03",
  "address": {
    "street_address": "100 Universal City Plaza",
    "locality": "Hollywood",
    "region": "CA",
    "postal_code": "91608",
    "country": "USA"
  },
  "zoneinfo": "America/Los_Angeles",
  "locale": "en-US",
  "phone_number": "+1 555 5550000",
  "phone_number_verified": false,
  "email": "user@example.com",
  "email_verified": false,
  "website": "https://openid.net/",
  "updated_at": "1580000000"
}
2020-09-01 12:50:53 SUCCESS
GetDynamicClientConfiguration
No client details on configuration, created an empty dynamic_client_registration_template object.
2020-09-01 12:50:53
oidcc-client-test-invalid-sig-rs256
Setup Done
2020-09-01 12:50:54 INCOMING
oidcc-client-test-invalid-sig-rs256
Incoming HTTP request to test instance GXsduuuUgWmCmPQ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/3.15.9 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate",
  "x-ssl-cipher": "ECDHE-RSA-AES128-GCM-SHA256",
  "x-ssl-protocol": "TLSv1.2",
  "connection": "close",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net"
}
incoming_path
.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_body_json
incoming_query_string_params
{}
incoming_body
Discovery endpoint
2020-09-01 12:50:54 OUTGOING
oidcc-client-test-invalid-sig-rs256
Response to HTTP request to test instance GXsduuuUgWmCmPQ
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/GXsduuuUgWmCmPQ/",
  "authorization_endpoint": "https://www.certification.openid.net/test/GXsduuuUgWmCmPQ/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/GXsduuuUgWmCmPQ/token",
  "jwks_uri": "https://www.certification.openid.net/test/GXsduuuUgWmCmPQ/jwks",
  "userinfo_endpoint": "https://www.certification.openid.net/test/GXsduuuUgWmCmPQ/userinfo",
  "registration_endpoint": "https://www.certification.openid.net/test/GXsduuuUgWmCmPQ/register",
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access"
  ],
  "response_types_supported": [
    "code",
    "id_token code",
    "token code id_token",
    "id_token",
    "token id_token",
    "token code",
    "token"
  ],
  "response_modes_supported": [
    "query",
    "fragment",
    "form_post"
  ],
  "token_endpoint_auth_methods_supported": [
    "client_secret_basic"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "RS256",
    "RS384",
    "RS512",
    "PS256",
    "PS384",
    "PS512",
    "ES256",
    "ES256K",
    "ES384",
    "ES512",
    "EdDSA"
  ],
  "grant_types_supported": [
    "authorization_code",
    "implicit"
  ],
  "claims_parameter_supported": true,
  "acr_values_supported": [
    "PASSWORD"
  ],
  "subject_types_supported": [
    "public",
    "pairwise"
  ],
  "claim_types_supported": [
    "normal",
    "aggregated",
    "distributed"
  ],
  "claims_supported": [
    "sub",
    "name",
    "given_name",
    "family_name",
    "middle_name",
    "nickname",
    "gender",
    "birthdate",
    "preferred_username",
    "profile",
    "website",
    "locale",
    "updated_at",
    "address",
    "zoneinfo",
    "phone_number",
    "phone_number_verified",
    "email",
    "email_verified"
  ],
  "id_token_signing_alg_values_supported": [
    "RS256"
  ],
  "id_token_encryption_alg_values_supported": [
    "RSA1_5",
    "RSA-OAEP",
    "RSA-OAEP-256",
    "ECDH-ES",
    "ECDH-ES+A128KW",
    "ECDH-ES+A192KW",
    "ECDH-ES+A256KW",
    "A128KW",
    "A192KW",
    "A256KW",
    "A128GCMKW",
    "A192GCMKW",
    "A256GCMKW",
    "dir"
  ],
  "id_token_encryption_enc_values_supported": [
    "A128CBC-HS256",
    "A192CBC-HS384",
    "A256CBC-HS512",
    "A128GCM",
    "A192GCM",
    "A256GCM"
  ],
  "request_object_signing_alg_values_supported": [
    "none",
    "RS256",
    "RS384",
    "RS512",
    "PS256",
    "PS384",
    "PS512",
    "ES256",
    "ES256K",
    "ES384",
    "ES512",
    "EdDSA"
  ],
  "request_object_encryption_alg_values_supported": [
    "RSA1_5",
    "RSA-OAEP",
    "RSA-OAEP-256",
    "ECDH-ES",
    "ECDH-ES+A128KW",
    "ECDH-ES+A192KW",
    "ECDH-ES+A256KW",
    "A128KW",
    "A192KW",
    "A256KW",
    "A128GCMKW",
    "A192GCMKW",
    "A256GCMKW",
    "dir"
  ],
  "request_object_encryption_enc_values_supported": [
    "A128CBC-HS256",
    "A192CBC-HS384",
    "A256CBC-HS512",
    "A128GCM",
    "A192GCM",
    "A256GCM"
  ],
  "userinfo_signing_alg_values_supported": [
    "RS256",
    "RS384",
    "RS512",
    "PS256",
    "PS384",
    "PS512",
    "ES256",
    "ES256K",
    "ES384",
    "ES512",
    "EdDSA"
  ],
  "userinfo_encryption_alg_values_supported": [
    "RSA1_5",
    "RSA-OAEP",
    "RSA-OAEP-256",
    "ECDH-ES",
    "ECDH-ES+A128KW",
    "ECDH-ES+A192KW",
    "ECDH-ES+A256KW",
    "A128KW",
    "A192KW",
    "A256KW",
    "A128GCMKW",
    "A192GCMKW",
    "A256GCMKW",
    "dir"
  ],
  "userinfo_encryption_enc_values_supported": [
    "A128CBC-HS256",
    "A192CBC-HS384",
    "A256CBC-HS512",
    "A128GCM",
    "A192GCM",
    "A256GCM"
  ]
}
outgoing_path
.well-known/openid-configuration
2020-09-01 12:50:54 INCOMING
oidcc-client-test-invalid-sig-rs256
Incoming HTTP request to test instance GXsduuuUgWmCmPQ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/3.15.9 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate",
  "content-type": "application/json",
  "x-ssl-cipher": "ECDHE-RSA-AES128-GCM-SHA256",
  "x-ssl-protocol": "TLSv1.2",
  "content-length": "194",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net",
  "connection": "close"
}
incoming_path
register
incoming_body_form_params
incoming_method
POST
incoming_body_json
{
  "token_endpoint_auth_method": "client_secret_basic",
  "response_types": [
    "id_token"
  ],
  "grant_types": [
    "implicit"
  ],
  "redirect_uris": [
    "https://rp.example.com/cb"
  ],
  "id_token_signed_response_alg": "RS256"
}
incoming_query_string_params
{}
incoming_body
{"token_endpoint_auth_method":"client_secret_basic","response_types":["id_token"],"grant_types":["implicit"],"redirect_uris":["https://rp.example.com/cb"],"id_token_signed_response_alg":"RS256"}
Registration endpoint
2020-09-01 12:50:54 SUCCESS
OIDCCExtractDynamicRegistrationRequest
Extracted dynamic client registration request
request
{
  "token_endpoint_auth_method": "client_secret_basic",
  "response_types": [
    "id_token"
  ],
  "grant_types": [
    "implicit"
  ],
  "redirect_uris": [
    "https://rp.example.com/cb"
  ],
  "id_token_signed_response_alg": "RS256"
}
2020-09-01 12:50:54 INFO
EnsureRegistrationRequestContainsAtLeastOneContact
This application requires that registration requests contain at least one contact.
2020-09-01 12:50:54 SUCCESS
ValidateClientGrantTypes
grant_types match response_types
grant_types
[
  "implicit"
]
response_types
[
  "id_token"
]
2020-09-01 12:50:54 SUCCESS
OIDCCValidateClientRedirectUris
Valid redirect_uri(s) provided in registration request
redirect_uris
[
  "https://rp.example.com/cb"
]
2020-09-01 12:50:54 SUCCESS
ValidateClientLogoUris
Client does not contain any logo_uri
2020-09-01 12:50:54 SUCCESS
ValidateClientUris
Client does not contain any client_uri
2020-09-01 12:50:54 SUCCESS
ValidateClientPolicyUris
Client does not contain any policy_uri
2020-09-01 12:50:54 SUCCESS
ValidateClientTosUris
Client does not contain any tos_uri
2020-09-01 12:50:54 SUCCESS
ValidateClientSubjectType
A subject_type was not provided
2020-09-01 12:50:54 SUCCESS
ValidateIdTokenSignedResponseAlg
id_token_signed_response_alg is one of the known algorithms
alg
RS256
2020-09-01 12:50:54 SUCCESS
EnsureIdTokenEncryptedResponseAlgIsSetIfEncIsSet
id_token_encrypted_response_enc is not set
2020-09-01 12:50:54 INFO
ValidateUserinfoSignedResponseAlg
Skipped evaluation due to missing required element: client userinfo_signed_response_alg
path
userinfo_signed_response_alg
mapped
object
client
2020-09-01 12:50:54 SUCCESS
EnsureUserinfoEncryptedResponseAlgIsSetIfEncIsSet
userinfo_encrypted_response_enc is not set
2020-09-01 12:50:54 INFO
ValidateRequestObjectSigningAlg
Skipped evaluation due to missing required element: client request_object_signing_alg
path
request_object_signing_alg
mapped
object
client
2020-09-01 12:50:54 SUCCESS
EnsureRequestObjectEncryptionAlgIsSetIfEncIsSet
request_object_encryption_enc is not set
2020-09-01 12:50:54 INFO
ValidateTokenEndpointAuthSigningAlg
Skipped evaluation due to missing required element: client token_endpoint_auth_signing_alg
path
token_endpoint_auth_signing_alg
mapped
object
client
2020-09-01 12:50:54 SUCCESS
ValidateDefaultMaxAge
default_max_age is not set
2020-09-01 12:50:54 INFO
ValidateRequireAuthTime
Skipped evaluation due to missing required element: client require_auth_time
path
require_auth_time
mapped
object
client
2020-09-01 12:50:54 INFO
ValidateDefaultAcrValues
Skipped evaluation due to missing required element: client default_acr_values
path
default_acr_values
mapped
object
client
2020-09-01 12:50:54 INFO
ValidateInitiateLoginUri
Skipped evaluation due to missing required element: client initiate_login_uri
path
initiate_login_uri
mapped
object
client
2020-09-01 12:50:54 INFO
ValidateRequestUris
Skipped evaluation due to missing required element: client request_uris
path
request_uris
mapped
object
client
2020-09-01 12:50:54 SUCCESS
ValidateClientRegistrationRequestSectorIdentifierUri
A sector_identifier_uri was not provided
2020-09-01 12:50:54 SUCCESS
OIDCCRegisterClient
Registered client
client
{
  "token_endpoint_auth_method": "client_secret_basic",
  "response_types": [
    "id_token"
  ],
  "grant_types": [
    "implicit"
  ],
  "redirect_uris": [
    "https://rp.example.com/cb"
  ],
  "id_token_signed_response_alg": "RS256",
  "client_id": "client_XRZUbEMKgwSEsvm36284\u003e:/|:"
}
2020-09-01 12:50:54
OIDCCCreateClientSecretForDynamicClient
Set the secret for registered client
client_secret
secret_RjuzHRfldwalkUPqfSuXZCMfAegLaBnZqVSYBXlQZnVGoBGDrF0544946823?};_#
2020-09-01 12:50:54 SUCCESS
EnsureTokenEndPointAuthMethodIsClientSecretBasic
token_endpoint_auth_method is 'client_secret_basic' as expected
2020-09-01 12:50:54
SetClientIdTokenSignedResponseAlgToRS256
Set id_token_signed_response_alg to RS256 for the registered client
client
{
  "token_endpoint_auth_method": "client_secret_basic",
  "response_types": [
    "id_token"
  ],
  "grant_types": [
    "implicit"
  ],
  "redirect_uris": [
    "https://rp.example.com/cb"
  ],
  "id_token_signed_response_alg": "RS256",
  "client_id": "client_XRZUbEMKgwSEsvm36284\u003e:/|:",
  "client_secret": "secret_RjuzHRfldwalkUPqfSuXZCMfAegLaBnZqVSYBXlQZnVGoBGDrF0544946823?};_#"
}
2020-09-01 12:50:54 SUCCESS
EnsureClientDoesNotHaveBothJwksAndJwksUri
Client does not have both jwks and jwks_uri set
client
{
  "token_endpoint_auth_method": "client_secret_basic",
  "response_types": [
    "id_token"
  ],
  "grant_types": [
    "implicit"
  ],
  "redirect_uris": [
    "https://rp.example.com/cb"
  ],
  "id_token_signed_response_alg": "RS256",
  "client_id": "client_XRZUbEMKgwSEsvm36284\u003e:/|:",
  "client_secret": "secret_RjuzHRfldwalkUPqfSuXZCMfAegLaBnZqVSYBXlQZnVGoBGDrF0544946823?};_#"
}
2020-09-01 12:50:54 INFO
FetchClientKeys
Skipped evaluation due to missing required element: client jwks_uri
path
jwks_uri
mapped
object
client
2020-09-01 12:50:54
SetServerSigningAlgToRS256
Successfully set signing algorithm to RS256
2020-09-01 12:50:54
SetClientIdTokenSignedResponseAlgToServerSigningAlg
Set id_token_signed_response_alg for the registered client
id_token_signed_response_alg
RS256
2020-09-01 12:50:54 OUTGOING
oidcc-client-test-invalid-sig-rs256
Response to HTTP request to test instance GXsduuuUgWmCmPQ
outgoing_status_code
201
outgoing_headers
{}
outgoing_body
{
  "token_endpoint_auth_method": "client_secret_basic",
  "response_types": [
    "id_token"
  ],
  "grant_types": [
    "implicit"
  ],
  "redirect_uris": [
    "https://rp.example.com/cb"
  ],
  "id_token_signed_response_alg": "RS256",
  "client_id": "client_XRZUbEMKgwSEsvm36284\u003e:/|:",
  "client_secret": "secret_RjuzHRfldwalkUPqfSuXZCMfAegLaBnZqVSYBXlQZnVGoBGDrF0544946823?};_#"
}
outgoing_path
register
2020-09-01 12:50:55 INCOMING
oidcc-client-test-invalid-sig-rs256
Incoming HTTP request to test instance GXsduuuUgWmCmPQ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "got/9.6.0 (https://github.com/sindresorhus/got)",
  "accept-encoding": "gzip, deflate",
  "x-ssl-cipher": "ECDHE-RSA-AES128-GCM-SHA256",
  "x-ssl-protocol": "TLSv1.2",
  "connection": "close",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net"
}
incoming_path
authorize
incoming_body_form_params
incoming_method
GET
incoming_body_json
incoming_query_string_params
{
  "client_id": "client_XRZUbEMKgwSEsvm36284\u003e:/|:",
  "scope": "openid",
  "response_type": "id_token",
  "redirect_uri": "https://rp.example.com/cb",
  "state": "bo9-xMHWPpHCApIND1QlC0UgsNgQnCSrgRFSqig_zz0",
  "nonce": "E2DlsKqZjiyTBmOo5X1oHOUQyKqTK68DHlBlSFkAhMk",
  "response_mode": "form_post"
}
incoming_body
Authorization endpoint
2020-09-01 12:50:55 SUCCESS
EnsureRequestDoesNotContainRequestObject
Request does not contain a request parameter
2020-09-01 12:50:55 SUCCESS
OIDCCEnsureAuthorizationHttpRequestContainsOpenIDScope
Found 'openid' in scope http request parameter
actual
[
  "openid"
]
expected
openid
2020-09-01 12:50:55 SUCCESS
CreateEffectiveAuthorizationRequestParameters
Merged http request parameters with request object claims
effective_authorization_endpoint_request
{
  "client_id": "client_XRZUbEMKgwSEsvm36284\u003e:/|:",
  "scope": "openid",
  "response_type": "id_token",
  "redirect_uri": "https://rp.example.com/cb",
  "state": "bo9-xMHWPpHCApIND1QlC0UgsNgQnCSrgRFSqig_zz0",
  "nonce": "E2DlsKqZjiyTBmOo5X1oHOUQyKqTK68DHlBlSFkAhMk",
  "response_mode": "form_post"
}
2020-09-01 12:50:55 SUCCESS
ExtractRequestedScopes
Requested scopes
scope
openid
2020-09-01 12:50:55 SUCCESS
ExtractNonceFromAuthorizationRequest
Extracted nonce
nonce
E2DlsKqZjiyTBmOo5X1oHOUQyKqTK68DHlBlSFkAhMk
2020-09-01 12:50:55 SUCCESS
EnsureResponseTypeIsIdToken
Response type is expected value
expected
id_token
2020-09-01 12:50:55 SUCCESS
EnsureMatchingClientId
Client ID matched
client_id
client_XRZUbEMKgwSEsvm36284>:/|:
2020-09-01 12:50:55 SUCCESS
EnsureValidRedirectUriForAuthorizationEndpointRequest
redirect_uri is one of the allowed redirect uris
actual
https://rp.example.com/cb
expected
[
  "https://rp.example.com/cb"
]
2020-09-01 12:50:55 SUCCESS
EnsureOpenIDInScopeRequest
Found 'openid' scope in request
actual
[
  "openid"
]
expected
openid
2020-09-01 12:50:55 SUCCESS
DisallowMaxAgeEqualsZeroAndPromptNone
The client did not send max_age=0 and prompt=none parameters as expected
2020-09-01 12:50:55 SUCCESS
GenerateIdTokenClaims
Created ID Token Claims
iss
https://www.certification.openid.net/test/GXsduuuUgWmCmPQ/
sub
user-subject-1234531
aud
client_XRZUbEMKgwSEsvm36284>:/|:
nonce
E2DlsKqZjiyTBmOo5X1oHOUQyKqTK68DHlBlSFkAhMk
iat
1598964655
exp
1598964955
2020-09-01 12:50:55 INFO
AddCHashToIdTokenClaims
Skipped evaluation due to missing required string: c_hash
expected
c_hash
2020-09-01 12:50:55 INFO
AddAtHashToIdTokenClaims
Skipped evaluation due to missing required string: at_hash
expected
at_hash
2020-09-01 12:50:55 SUCCESS
OIDCCSignIdToken
Signed the ID token
id_token
eyJraWQiOiJkOTZjNTBkYi0wNGY0LTRhNDUtOGI2Yy00NzM5ZDU1NzQxMDkiLCJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6ImNsaWVudF9YUlpVYkVNS2d3U0Vzdm0zNjI4ND46XC98OiIsImlzcyI6Imh0dHBzOlwvXC93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0XC90ZXN0XC9HWHNkdXV1VWdXbUNtUFFcLyIsImV4cCI6MTU5ODk2NDk1NSwibm9uY2UiOiJFMkRsc0txWmppeVRCbU9vNVgxb0hPVVF5S3FUSzY4REhsQmxTRmtBaE1rIiwiaWF0IjoxNTk4OTY0NjU1fQ.VWN-ZCYKhMoIJQrFiA-ClutMBKMfMQ5e_nq2KSha4jRgEPiqsFHR6FORBB6B5txg2bUWmtyv1mJ5J0kShEo_9NAoGC82BVPugvfFrGiP7YGojwNeJ7E8DpboG6MuZX_Gq9gPD9hdGZuvWC4wSLDer2haXlWN-gFso0lwYi-BfhKoJ9niDJ-mqftHxtnlRRM1QX6h8GrYNXTTblQ30PUUjQLeyv2m8k-ibIoryOBtMslNpMslvIMUXaQvybKSjArtRrlRkOb-aQCdWZFWZFI_XKa7wYXh1Yx5mL6V8Ky72iMKMNT0jfYkDYxxKB0VtUpOwpX7h8yPeBLV0L6T1RKrsg
key
{"p":"3KCEbfPKnc7-gbPD6S6FG46uh-ee_MaL0e53j7VxzvvC5XwsTcv5ggAprG8-QSAmc2X8egx139zSfYQ8g0Z8wDgqLeJLtkEfScLD91IQhWxpFgSiXsz2DZv_dm19yOmPs_ySwHpmrGhWmQgvfMK7yGhbmxDFrtmg-aryQqRC5G8","kty":"RSA","q":"xXucxMJqMS66UhSwSv833pn-_22Ee1rWCAO0Q4ZwqyYz4yijTknMcUiqK1IqzWQbLz3rIOJrwD9uDZmA1BSQXUc0htxJLYOSmYXFwjODwp_Xj0shHvEOEII-P5vOmUCUMVfSbp6y1IPpHTmxcXWL7E_VYcHa6dDFFb_ROUVzlf0","d":"yhqmr6gA0PAUMl9RprcpbsceKi3GhTkbyc0gHPqMadsDGlh-Rfk4PdUxNcKPmM3nXkjiRIQZyEQ82eVTb6Tu6uAm-nbNHwHhdUCEIcMVN6Q9YwbmhSSWZq7KDlPTRjA7DkhhBgSkABR4KaA8l-UlAbO9juJOSjbPaQjeYADVr5F8E48cGPqC4VqtyJ3pI94MitkTFtweJ_uP2bEYMQcLgwoW_kYjUL9DtzfRw4MC6Yra3D5_qJB_bnCTK27PIxXe2vaWyaGmIm8YmhvZ3mvDN31hhnE9tjGh7AtsY_sXRoQB56cFngWtV1gQ6X1I7RzhKONuadJz0jqv5GNLq7WB","e":"AQAB","use":"sig","kid":"d96c50db-04f4-4a45-8b6c-4739d5574109","qi":"kCWGawAwK269o4H50jJtr6ihLsRwU7QDTC37ANXy3QZu4g3bynrzv0UjwlghlJteJhtW-AQJAM85cFc1-oJLdqpwtRiTblZipu8pCw9lLyK-Dl4Vm99swXz-7Z5RIdqEqf5-f-gHe-hnO9hZ77mk7avuUL-YMGyUwfspPJGDiV8","dp":"zk88ByWGPvOlgtv7Qz5BMnfGNUgen_l6HiGEpFnjxs4efkITm9w1wZ8tWRXdfUD3M8oWwnqMb34rRzw06f0sAwOCTc3jRta2z17VqZyP3nR2ACTtQQEgxbEuviu9B_eAbaquAFd1U5tt_0RsQ5pFxy3vG54ffVX89fso97Bq7Pk","dq":"STntxnPEhpoqEneDazu5jrwRdss4PblP9cbR19wI-R2ATfHqpAPvX-4u00NzhZdiESFnh1kN1Upv13Ec-QbrBPt7OaqDI_JOsMiOrNUHPWqhtouIK3381hhFVrbCY8czbByBde04qF6FWQXkiwqoKKbtm4MTVnHIMqlevlrHYk0","n":"qjIOI6CUm71io7-XmUrKOuWEKYNRblCHlqkwxSPs9jwl3Bc9JyFB3YSTZ4npkE68xuVD1WOtuZKLC-bizkpqlAywuBkT3HhsLm1zsROMnT3b0DmBTYKd7osbkchSMNqHyNp4rc7gA_mooBSL-V_HfwddsV4zg85ma6in7IYSQ7bUVkWQvQR6qWXuAR-8ZSFY0dquBD2_uQu4HwQzIrlpvqqoq9qq5a0s7_iBANjeCBdVgXY5KrlWAGj4Qsx7NDnA0OoHD5v-hMPEJ95RFPdW5pH9vsXSFR6DRLS9I755HgT55PNwKtIsLRvYKD26W_vAvQxuwtc4XX_AXILMze1csw"}
algorithm
RS256
2020-09-01 12:50:55 SUCCESS
SignIdTokenInvalid
Made the id_token signature invalid
id_token
eyJraWQiOiJkOTZjNTBkYi0wNGY0LTRhNDUtOGI2Yy00NzM5ZDU1NzQxMDkiLCJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6ImNsaWVudF9YUlpVYkVNS2d3U0Vzdm0zNjI4ND46XC98OiIsImlzcyI6Imh0dHBzOlwvXC93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0XC90ZXN0XC9HWHNkdXV1VWdXbUNtUFFcLyIsImV4cCI6MTU5ODk2NDk1NSwibm9uY2UiOiJFMkRsc0txWmppeVRCbU9vNVgxb0hPVVF5S3FUSzY4REhsQmxTRmtBaE1rIiwiaWF0IjoxNTk4OTY0NjU1fQ.DzkkPnxQ3pBSf1Cf0lXYzLEWXvlFa1QEpCDsc3IAuG46SqLw6guLsgnLXkTbvIY6g-9MwIb1jDgjfRNI3hBlropyQnVsXwm02K2f9jLVt9vy1VkEfetmVMyyQfl0PyWc8YJVVYIHQ8H1AnRqEuqE9TIABA_XoFs2-RMqOHXbJEjyfYO4VsX886EdnIO_H0lvGyT7qjCCby6JNA5tiq9O11iEkKf8qBX4NtBxkro3aJMX_pF_5tlOB_51k-jI1lC3HOMLyrykM1rHA8sMPghlBvzhm9-7j9YjwuTPqvbhgHlQao6u16x-V9YrckdP7xAUmM-h3ZbVIkiPiuTJj0jx6A
2020-09-01 12:50:55 INFO
EncryptIdToken
Skipped evaluation due to missing required element: client id_token_encrypted_response_alg
path
id_token_encrypted_response_alg
mapped
object
client
2020-09-01 12:50:55 SUCCESS
CreateAuthorizationEndpointResponseParams
Added authorization_endpoint_response_params to environment
params
{
  "redirect_uri": "https://rp.example.com/cb",
  "state": "bo9-xMHWPpHCApIND1QlC0UgsNgQnCSrgRFSqig_zz0"
}
2020-09-01 12:50:55 SUCCESS
AddIdTokenToAuthorizationEndpointResponseParams
Added id_token to authorization endpoint response params
authorization_endpoint_response_params
{
  "redirect_uri": "https://rp.example.com/cb",
  "state": "bo9-xMHWPpHCApIND1QlC0UgsNgQnCSrgRFSqig_zz0",
  "id_token": "eyJraWQiOiJkOTZjNTBkYi0wNGY0LTRhNDUtOGI2Yy00NzM5ZDU1NzQxMDkiLCJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6ImNsaWVudF9YUlpVYkVNS2d3U0Vzdm0zNjI4ND46XC98OiIsImlzcyI6Imh0dHBzOlwvXC93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0XC90ZXN0XC9HWHNkdXV1VWdXbUNtUFFcLyIsImV4cCI6MTU5ODk2NDk1NSwibm9uY2UiOiJFMkRsc0txWmppeVRCbU9vNVgxb0hPVVF5S3FUSzY4REhsQmxTRmtBaE1rIiwiaWF0IjoxNTk4OTY0NjU1fQ.DzkkPnxQ3pBSf1Cf0lXYzLEWXvlFa1QEpCDsc3IAuG46SqLw6guLsgnLXkTbvIY6g-9MwIb1jDgjfRNI3hBlropyQnVsXwm02K2f9jLVt9vy1VkEfetmVMyyQfl0PyWc8YJVVYIHQ8H1AnRqEuqE9TIABA_XoFs2-RMqOHXbJEjyfYO4VsX886EdnIO_H0lvGyT7qjCCby6JNA5tiq9O11iEkKf8qBX4NtBxkro3aJMX_pF_5tlOB_51k-jI1lC3HOMLyrykM1rHA8sMPghlBvzhm9-7j9YjwuTPqvbhgHlQao6u16x-V9YrckdP7xAUmM-h3ZbVIkiPiuTJj0jx6A"
}
2020-09-01 12:50:55 OUTGOING
oidcc-client-test-invalid-sig-rs256
Response to HTTP request to test instance GXsduuuUgWmCmPQ
outgoing
ModelAndView [view="formPostResponseMode"; model={formAction=https://rp.example.com/cb, formParameters={"state":"bo9-xMHWPpHCApIND1QlC0UgsNgQnCSrgRFSqig_zz0","id_token":"eyJraWQiOiJkOTZjNTBkYi0wNGY0LTRhNDUtOGI2Yy00NzM5ZDU1NzQxMDkiLCJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6ImNsaWVudF9YUlpVYkVNS2d3U0Vzdm0zNjI4ND46XC98OiIsImlzcyI6Imh0dHBzOlwvXC93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0XC90ZXN0XC9HWHNkdXV1VWdXbUNtUFFcLyIsImV4cCI6MTU5ODk2NDk1NSwibm9uY2UiOiJFMkRsc0txWmppeVRCbU9vNVgxb0hPVVF5S3FUSzY4REhsQmxTRmtBaE1rIiwiaWF0IjoxNTk4OTY0NjU1fQ.DzkkPnxQ3pBSf1Cf0lXYzLEWXvlFa1QEpCDsc3IAuG46SqLw6guLsgnLXkTbvIY6g-9MwIb1jDgjfRNI3hBlropyQnVsXwm02K2f9jLVt9vy1VkEfetmVMyyQfl0PyWc8YJVVYIHQ8H1AnRqEuqE9TIABA_XoFs2-RMqOHXbJEjyfYO4VsX886EdnIO_H0lvGyT7qjCCby6JNA5tiq9O11iEkKf8qBX4NtBxkro3aJMX_pF_5tlOB_51k-jI1lC3HOMLyrykM1rHA8sMPghlBvzhm9-7j9YjwuTPqvbhgHlQao6u16x-V9YrckdP7xAUmM-h3ZbVIkiPiuTJj0jx6A"}}]
outgoing_path
authorize
2020-09-01 12:50:55 INCOMING
oidcc-client-test-invalid-sig-rs256
Incoming HTTP request to test instance GXsduuuUgWmCmPQ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/3.15.9 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate",
  "x-ssl-cipher": "ECDHE-RSA-AES128-GCM-SHA256",
  "x-ssl-protocol": "TLSv1.2",
  "connection": "close",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net"
}
incoming_path
jwks
incoming_body_form_params
incoming_method
GET
incoming_body_json
incoming_query_string_params
{}
incoming_body
Jwks endpoint
2020-09-01 12:50:55 OUTGOING
oidcc-client-test-invalid-sig-rs256
Response to HTTP request to test instance GXsduuuUgWmCmPQ
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "d96c50db-04f4-4a45-8b6c-4739d5574109",
      "n": "qjIOI6CUm71io7-XmUrKOuWEKYNRblCHlqkwxSPs9jwl3Bc9JyFB3YSTZ4npkE68xuVD1WOtuZKLC-bizkpqlAywuBkT3HhsLm1zsROMnT3b0DmBTYKd7osbkchSMNqHyNp4rc7gA_mooBSL-V_HfwddsV4zg85ma6in7IYSQ7bUVkWQvQR6qWXuAR-8ZSFY0dquBD2_uQu4HwQzIrlpvqqoq9qq5a0s7_iBANjeCBdVgXY5KrlWAGj4Qsx7NDnA0OoHD5v-hMPEJ95RFPdW5pH9vsXSFR6DRLS9I755HgT55PNwKtIsLRvYKD26W_vAvQxuwtc4XX_AXILMze1csw"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "8ddad6d5-9fac-454a-9bc0-a66ff5a2a004",
      "n": "jPyUwnH42UjMbyhhqbvXARYJuZLnr7MXyHQ0kmjBrBImU1BeE_WzoqjkLXRFWHQtF9RZI8Xch30wwtvs7w5X0r9V6Hslxl9jfk6qSQBYPH22kuRClBmW9cSF0uAuA1-WorLhbxN8wiAoRBkgDYo6Z-X2T3GX1yI_Yac6MNLZvR5tvu1JZEv72yUj43o07U9N_fo4P0EXl635j26ZvEYe0VkB4hL4J2wQXZUrhaKqLWa0BulKrwyqggMIvhUehZEX3bHk8tSkzG6OdBA7heAZIC2YnWrDlL5JTsijqNPZv1_bMmkvjwmt25v4opWUXNyGXUE0tzDqkYGfLzcos99WYw"
    },
    {
      "kty": "EC",
      "use": "sig",
      "crv": "P-256",
      "kid": "9ff67717-69cc-45f3-84a6-63cbedcbdc33",
      "x": "MJdvm3w6qbkPFAhXCsSrku41Z6YqgixH8N7aw95TCAE",
      "y": "MzjExnt1cABaif9X5p3Z--07xjuVC-eG7FTzV9GBo5I"
    },
    {
      "kty": "EC",
      "use": "sig",
      "crv": "P-256",
      "kid": "b49a31c0-7b88-4af8-a0f1-75e815d98e96",
      "x": "ttL5LOcVh1W7NFIEOkh38Ohy1Br6jJiuH0GdwthLQJw",
      "y": "C3pZICT3lZzJSRF6gNaEmj8rCNnkLIfx0lTKPRx2RYo"
    },
    {
      "kty": "EC",
      "use": "sig",
      "crv": "secp256k1",
      "kid": "6e2fdea0-d70f-4c5f-a91e-7f528fa0cae7",
      "x": "GblGBRW9tMaAEGcjl1eUAaAW0BiubgAtqiq4K_DcMsA",
      "y": "ZeqtWw-DsZLF3W4OZDF1Q7tx2TOfqXhusE8DLAHVyGw"
    },
    {
      "kty": "OKP",
      "use": "sig",
      "crv": "Ed25519",
      "kid": "f2b47240-7fd5-4d77-9722-f47dc51c242f",
      "x": "cuPTXi7mz_5pKTdEXT_SBQlAZBkafisQ3vD55ft9sxA"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "2ff7f73b-7403-4b8b-9678-6c4424b1c97a",
      "alg": "RSA-OAEP",
      "n": "lCb4XuQgYV-b382pLtn6UvoGuQi4byuOXrXIGh-bJw1jUheMsBa8yseOj43uD27GNYqIaZLMxLcD4BgPKamDVA3UiahZjPvZMXDFCH1aYJY2dYTZDIGfIkOx-EtroJUZDnAIfhuvVJMv96BO0m3os6I-9In4N2C0SdPMAYZtCPXXIrMlkGq28fcoUD22KyyVzZ0c858fHwYkf0BcvO5Ak9H_1Gr6QMXP_AwWxmcu1dPcrmpREyNVS4lSbTn-kEl1aeMVfaSki8XuXZXm--Pp3MJSJ7U5_8fi58M7YzJ2ZNR2yBYLErrgCjeI-RoKNZSIzJwkzgx0e-BYhYj_al9_QQ"
    },
    {
      "kty": "EC",
      "use": "enc",
      "crv": "P-256",
      "kid": "078846eb-fc61-4ada-be15-c9df9c3da9fa",
      "x": "RNy5H4yNgoFjVh2bg6TV9Wx4xIFkqUyFfwwLvFUuZkA",
      "y": "fjJcF9BLvhFALHBPtNnuwrU9k9oUq5mGczYV9PLGSZw",
      "alg": "ECDH-ES"
    }
  ]
}
outgoing_path
jwks
2020-09-01 12:50:55 FINISHED
oidcc-client-test-invalid-sig-rs256
Test has run to completion
testmodule_result
PASSED
Test Results