Test Summary

Test Results

Expand All Collapse All
All times are UTC
2021-08-13 15:59:19 INFO
TEST-RUNNER
Test instance wCkrQW9Zx2JRQay created
baseUrl
https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain
variant
{
  "client_auth_type": "private_key_jwt",
  "fapi_auth_request_method": "pushed",
  "fapi_profile": "plain_fapi",
  "fapi_response_mode": "plain_response"
}
alias
pingidentity-pingfederate-fapi-adv-op-private-key-par-plain
description
planId
JjlKFwygCKdKi
config
{
  "alias": "pingidentity-pingfederate-fapi-adv-op-private-key-par-plain",
  "browser": [
    {
      "match": "https://idp.conf.ping-eng.com:9031/as/authorization.oauth2*",
      "tasks": [
        {
          "task": "Initial Login",
          "match": "https://idp.conf.ping-eng.com:9031/as/authorization.oauth2*",
          "optional": true,
          "commands": [
            [
              "wait",
              "id",
              "username",
              10
            ],
            [
              "text",
              "id",
              "username",
              "joe"
            ],
            [
              "text",
              "id",
              "password",
              "2Federate"
            ],
            [
              "click",
              "id",
              "signOnButton"
            ]
          ]
        },
        {
          "task": "Authorize Client",
          "match": "https://idp.conf.ping-eng.com:9031/as/*/resume/as/authorization.ping*",
          "optional": true,
          "commands": [
            [
              "click",
              "css",
              "a.ping-button.normal.allow"
            ]
          ]
        },
        {
          "task": "Verify Complete",
          "optional": true,
          "match": "https://www.certification.openid.net/test/a/*/callback*"
        }
      ]
    }
  ],
  "server": {
    "discoveryUrl": "https://idp.conf.ping-eng.com:9031/.well-known/openid-configuration"
  },
  "client": {
    "client_id": "fapi_adv_op_w_private_key_par_first_client",
    "scope": "openid payments",
    "jwks": {
      "keys": [
        {
          "p": "7Iiv4eby1Ubo_U9uzWEa8OlUQoBz4vjPtB7MWQ6dlM7ajD9IjhjwwE8e1d_fE22DW4bEjHb1ls6_wbEm07PusUuMyHtWzW1sNWnpCh0xgDsEnLZwmtdXhPDHJlbRXHXAqcTVTUIJNMUSa8Mj9MXs33u1mkMD-hYWJfDHNCrDUAc",
          "kty": "RSA",
          "q": "msxkZpdafUHdoC-S5QrAHZ8z0NrQNFjn2yFcpznZ0zjXK83QH-jbBHCcTDBkF7xpatG61SbEznYxYaDEFR4xzuyy0WOYtoIk5IukygdvZhMkAXDNl5rNvF770Fnv8gwpoxZqlpb18kWtP2gk-ebJK2YHKjhl-pHDOrbzubkRdOE",
          "d": "AXvpT93_Y-hQYTCk95gHj6BinFTppIaTZhgJWvnDY-Bz1NhUZ7fz-RjePxQBEuRv3DUk6nEmT8CivxJKZdql9AR9UjHz_ANOH6mAwHxkE2bcEKEsJFGTkaDJhVqmwukYwfKfGpkeNuD2r5rhNdl3XNUQ6VdTkUokmZM3KNrLhks3NtPL3xEMqK5KAYJbJuS8AQoOI5scRTJZYcS63KK9WwBoOFwbz3PFHJb2lffTOH_tnqgSvm9chb7y1CaarSJuFSVTjkjMyk2rBOr4bu5YRtxzH1dAa3Dd5n9XzVwN_q0dIitTh7Vro2JcSU24O1n-XR4WGzCCiarMxPKc8SWyAQ",
          "e": "AQAB",
          "use": "sig",
          "kid": "pingfederate-fapi-jwt-assertion-client1",
          "qi": "De5E3i5KIQ88R7jYZDWEsVonhPPGcWksWXC-s4frJ0tISk5-zlCdP6eitstJTaB1i7bkCW4R7iXufgXqW2WCRK2IXXjwItZo1zEpuAZJnKFwDPxXt5pLoc_sDjarMRENxdx_spyiFIxejLvvDmKGxs7vt3LDm_ytvJXfsymzjqM",
          "dp": "z80l9-jV3dl2R1TJm1V8Pbo_dE01gmnkz_Fexb65Ykp4Zk4SiAQRPmJETNFpQcAsbvRvKJg6Gkt428muur6RLOGaxWbWU5OWRTbOrTwIiQdQff0p4F7fXMPLsjsDo58vq_ZpDn69Z8ba8CF4LUrVV2Fvoh7OF5_fxWVLHOGUxXE",
          "alg": "PS256",
          "dq": "JRS_HEA3YffsMhoTUyB_ItlnHSm9ZDzD1Z8pRbm67zkXehvENlCeXnLnTeztnS36BqeU3Mh7roVrkNpk_jYMcmgK8dOs2lNUqRa2c9rSGZ6OKnYuGZnwnKYYJjHVI6M8Oh_9inNBGTcNqDm3WdGp8OZw4vE9pIdUP_VhbuThRKE",
          "n": "jwcTfjv0q48qux1sg2MR8OvCh1mXITYu7zkEJVCz0UImIrIqLtEzmGkqJP0LobK6-NlFHWOsAp2NcVTh79RBwawsrmi59rJ_nHigX00C7wjVpJtldJmOwmSS4HD8EgRkiM0yJzyKijtRiB5ssrOoBK3VPFMqZYm_JBJY35s_qDDHWTlwuWDLqADZp809btMcwQZCqgrSKgtalspeKXIh6Lv3lkFnELJhfwGZYPtVc2SJk91F8tmgamPNJUfVJV3ygdBuDcB8EZ8m-tIaISghfR1RRkEeYI8r_Wf4dfjIAZRkrj8GHqAJOi762rjyFvXvcPc0Zc-ABDYnVi4WdWOCJw"
        }
      ]
    }
  },
  "resource": {
    "resourceUrl": "https://idp.conf.ping-eng.com:3000/get"
  },
  "client2": {
    "client_id": "fapi_adv_op_w_private_key_par_second_client",
    "scope": "openid payments",
    "jwks": {
      "keys": [
        {
          "p": "43lqQE0EN1LJ_jdqHq56hNFjErKfcrwJnVpIVRsXCZWboV4MSfLzGGEyePPs6SxV6-l_txQY-M2dW6xLaedRUlaFT89r10cIm136ecYUzs51iX_GZW_AvohaXSmAbZKpjLmsHIDelgggQKjDQxGGbmAAQojnqzorpVrfz-8aUNc",
          "kty": "RSA",
          "q": "q1t1ErKAx06nV7ohJ4zlo3xUeMA3rO7HLmK6Eh460DsiX80AsCxyw1AsQy0N1W8u_RgkA3y_p_5Nf7K1KLLa9mduIBWyUFEim1EneviM4m3q7e2UtQ7iezh6FatYFZD5c_v_CH2gV0bhxZrMzNc8ubL46OXo5h1WycY1iAqsjNs",
          "d": "ElS590xAIy7zN4KHKmq2rLnAg1TJ9kODaUrb98X3gCGuTOLBAtFzUqjPyBF8rqXAtkgl8inec6GwY6gmB9p53quJfKSunnN7CbU3Qe37f8HBgS95vFsmJtbctbJ43XKlwo0imYbIeBYLmxKUJt5BKSnUYWWv4EI2AVE_LrqecL-QaNLH2IxY1JVLvR8WhP7wzjTHIsGjaQGn7199eVBaHZ7KTC-bFaEWnPgklR0e8t8TdICUqJudCqTEuoEBFYXRdqi_3betdNZHtJdcwfk9VEXTYTnjzw0fJ7RoFyVE1_1-wMULnEYk5SyfSYfYsBq_V25e-TUSLxB3IXgzBmJVOQ",
          "e": "AQAB",
          "use": "sig",
          "kid": "pingfederate-fapi-jwt-assertion-client2",
          "qi": "rBDWPBNof1ZrvpqRqpPIf-hn6jmOmLN5mzv8ArwfYEuoIPo9Ltzta1m42A6KQAAsHfXUaKtihSXnVopYtYcxguVNCi2qbDh4nx7ZZNCcQsKSkUOw-hgm4vHZJMOJ-4jh6jthUeLTRmCpEZAHQrtmnpQ1tC1g3g2VCDH48p8cLzo",
          "dp": "BrSxmSusECV0pvXjPvxNyFST4x047hz0-5qJv1iJGVM7v0oSequa1wEmh8JJHaac8dN0XGVPRyZomSc_IeQb1Z2PWIb42uPRMSNYGvbn7iDP_jmyE5Nzzyod39k1XAWS0f83P6_c3_dlXAKdnwCJQf-6gjue-MFCQCGpr2uRDwk",
          "alg": "PS256",
          "dq": "GyE3v-YTDXsec308ko50LRYaKaQFLJQBZQ6sdwHiPeWe45wJZ9shsFqZJ2mSryATSG7yBLtTfL1-d6FLnU3z7N8jSGEnAiBWYlDO92EyrQbKEzFyQdhBc1DVw2iFYaS6WeqjzixVnnvScv63Phc1vhDf57--x_ANNZT0FL3b49E",
          "n": "mENeKNMC5ttp60qEq6LZoWaihn-__Ei70wnW8Zd_-ILFnYcaM90oTTnl8R2uHD4EJ3t_VCjFteXIwWV7OwDmRmOMwda0X1R5IKYn0O2ujT8NI4citj8G4NHY0r5Y5loLdb5dynGgT-YpsnWwfTC8Ky98gNA3OLf6Z2n8PEdKJr818RMAC0Vx6NQMHBNG4jI1D0bvbrZbx0XkXan7h2Elm9HLRjzHar5Qb5gFLGQRFdeHVHF5lRKyAFgdeQPvBqMiRsAwcgyKxDjbzF5qHPwhKMB-7IVhxuSULMvgSkesIIhrylzU9bo2KRhcxTB7oPkhAbPgumpoVZV0ME-ypiy77Q"
        }
      ]
    }
  },
  "mtls": {
    "cert": "-----BEGIN CERTIFICATE-----\nMIID3TCCAsWgAwIBAgIUIi7yAbDDmWkZjI8CwjLBVkswVkIwDQYJKoZIhvcNAQEL\nBQAwfTELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAkNPMQ8wDQYDVQQHDAZEZW52ZXIx\nFTATBgNVBAoMDFBpbmdJZGVudGl0eTEUMBIGA1UECwwLRGV2ZWxvcG1lbnQxIzAh\nBgNVBAMMGkZBUEkgQWR2IE9QIHcgRmlyc3QgQ2xpZW50MCAXDTIxMDcyNjIyMzQz\nN1oYDzIxMjEwNzAyMjIzNDM3WjB9MQswCQYDVQQGEwJVUzELMAkGA1UECAwCQ08x\nDzANBgNVBAcMBkRlbnZlcjEVMBMGA1UECgwMUGluZ0lkZW50aXR5MRQwEgYDVQQL\nDAtEZXZlbG9wbWVudDEjMCEGA1UEAwwaRkFQSSBBZHYgT1AgdyBGaXJzdCBDbGll\nbnQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCa91hiBBEaNcRdvQ0G\nvg06mzaIQpa17vgtP77HwtV0FvH+3imrnqmaCcpEnWGMv/udX8S5r/VAeUPB2Q31\n187vKDLKxbadWTKuSNQajOkRyiXZzutbEQbN/t7JAz7oETujYoOTlMNT4N9twYvK\nEvxTeZAWNUCQHXZcESKYXhph0eZaaOvNo7WqQ+ygGBzgTVev6tXr/Q2+M3NkBnSv\nRYegSN5ZtmIXMrNVaH7D+SC8QUPWxsB8ZVIENzBhCI8+brrPjyLNqVKoI9O7Hjdg\nzb8Xs+gC98ATmsbQrE/8pRdYYCPkEoETAWRq2T/dEf7NE+AMerttKk9TdNwvbB1W\nbAoHAgMBAAGjUzBRMB0GA1UdDgQWBBTr8p3YWM2Rtw/BAQaellNa1RUKSTAfBgNV\nHSMEGDAWgBTr8p3YWM2Rtw/BAQaellNa1RUKSTAPBgNVHRMBAf8EBTADAQH/MA0G\nCSqGSIb3DQEBCwUAA4IBAQB17ygVKcEpZxP4XML98KyUycNxsyHcKdIo2GZCRsmw\njDR5nRcdWlE+tI50sduSaAR+gSbDFR/dqBxl0lBEMLj6Rqpson+z17jv68fU9H7l\n7JLfI5xAXuW4s1Kg/xBcYBy7QJkU9CTMIb6TBQESCbTUq89aCX4fT8WQleCflRJj\nSuzzdpVWd0PIhcxCoxpa/BcXtK0gf/z0rimF4jJKv40rqdf0LGsVzKQ9TxQIDWk0\ntov4FkvBw63VUp6b7PWdEHi4E9uKgHxh2Pj+VykK33nCmUsGXENfj4SSkY2O00iD\nw3oHfC8xmWvgqsTdlzJm1qhZCZGNOsdWLEv6hGl4XLyr\n-----END CERTIFICATE-----",
    "key": "-----BEGIN PRIVATE KEY-----\nMIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQCa91hiBBEaNcRd\nvQ0Gvg06mzaIQpa17vgtP77HwtV0FvH+3imrnqmaCcpEnWGMv/udX8S5r/VAeUPB\n2Q31187vKDLKxbadWTKuSNQajOkRyiXZzutbEQbN/t7JAz7oETujYoOTlMNT4N9t\nwYvKEvxTeZAWNUCQHXZcESKYXhph0eZaaOvNo7WqQ+ygGBzgTVev6tXr/Q2+M3Nk\nBnSvRYegSN5ZtmIXMrNVaH7D+SC8QUPWxsB8ZVIENzBhCI8+brrPjyLNqVKoI9O7\nHjdgzb8Xs+gC98ATmsbQrE/8pRdYYCPkEoETAWRq2T/dEf7NE+AMerttKk9TdNwv\nbB1WbAoHAgMBAAECggEAf4aFKUQHfvY4PpvRGHdWE6CfY8rIk7ewbCxFJ8biOcKY\nKxFQYXcUQztDROvu1xE2Uu/4yIZQ4VnptKCWqHWMSatfARdrjFlXJ62vPpovQwCD\n3ZY2gJ6mZucTF4CgSAHGflIXzV9izqgDtiLMkuLE2zzyohP4qaBVQranLZRjSZNW\neGvEpkcf7Nv7FlfZaOJ/FkcGwyFn7iSzX/KRL/1TA6zDlreA3PGJr96i9SmFHQsu\nrFv7quRxEUFoSVxVtn5IiOJji45Evte8KAhMzlau1MuAlKxiIJAMIPN2l1nTRTRZ\nUybDBoLp9CkkAmvp75krld9NB/hbWaeRsxhgVPXYwQKBgQDMsai5QHJAFZ5P31LN\n0dvlvcj0X2dPS0hEd6NsIf5DkbQKHQuVlxdIGhChLhVBdkGUt9ZYSflxlUtc8GUG\n3+e0TKg+ZAHNakueV73TGZy3BAzQBxwQBMqUltcXWMjWBaDnbQH+TrtYP0A+ZdHd\n4gnBNuSUuv5R7IxGWHgfcvtnuQKBgQDBzt2kGjDXXPV4qrtmGl4KaCAvsFr76VsV\nr8879MhrVgevI5vbsBNWQ3yvykXLr5B6s0VaqibvgDTcchQvqwtoEeDQfHsSHnAg\nlGYCAi06hwGArTW/hxW0L7IivB+laFsbPY2HbnGZ6WUOjMNTgGAihbbLd6+IvLJE\nVdn7gjxfvwKBgD/DS9rBP5XE5jbdS08AA27yiqnNGkJyIgXp+sdRY4Iq3hmUaKpl\nkYQNUobS8x4cN1ubVLLWAFUoe3xtCht1HhllE7ezsXgKl5mwnVooDVBZe6BFxrEa\nvPxCbKhCKPW6dSACLe/JGMTplxqY3yIuKnm8nsHR6i0c8alsH6c0SypJAoGBALcV\nCn+5ViY8ZI9nCby8b9X4417phCmxGiB0gpoq9SGglYW3Z8ayoLG+8wzFUgXGhf/D\nVmL9leZuAIG3KqaVOCNJsEyDK2fEZTwBtBN1pvBBFQRPnBSgMbqTy/3QJT0GRfqH\nvSkRBjPVLWf/RY2eGjLCihnPqHzNdMHlMBTNxObVAoGAMRDZNtM0vIUNbjY5YFK0\nAoetPqR1mS2fWOFdCVnyHYBOJmmUZbU4oNZk5HmHBOC8N7aOELyXu56I4yEw0KUj\nOphKGfA9b2553q1A6t1x1oHBIwVuj1W3sEpUOtj2fWwmmdqjEyRsdzEJWfOuOEFz\nbfaw1pClq9IbngVcDGfzg74\u003d\n-----END PRIVATE KEY-----"
  },
  "mtls2": {
    "cert": "-----BEGIN CERTIFICATE-----\nMIID3zCCAsegAwIBAgIUUbO7wc+DFfteEqK0M1D+iRwKDOkwDQYJKoZIhvcNAQEL\nBQAwfjELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAkNPMQ8wDQYDVQQHDAZEZW52ZXIx\nFTATBgNVBAoMDFBpbmdJZGVudGl0eTEUMBIGA1UECwwLRGV2ZWxvcG1lbnQxJDAi\nBgNVBAMMG0ZBUEkgQWR2IE9QIHcgU2Vjb25kIENsaWVudDAgFw0yMTA3MjYyMjM0\nNDFaGA8yMTIxMDcwMjIyMzQ0MVowfjELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAkNP\nMQ8wDQYDVQQHDAZEZW52ZXIxFTATBgNVBAoMDFBpbmdJZGVudGl0eTEUMBIGA1UE\nCwwLRGV2ZWxvcG1lbnQxJDAiBgNVBAMMG0ZBUEkgQWR2IE9QIHcgU2Vjb25kIENs\naWVudDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALASMA/8vTQ+vFqs\nR7UBSG5cldHwJ5SGvoHpGqhdv6xSXHUi8bp0Ob927l93bdkk1YnWqYQbmtmwlfqR\nFyxXYAvNXoIrFY86gBOg4O9vkCeVSMK1l7CdSps3ypXR4p7Fy1eERIN4fTwUS5wR\nu0bpcG4kocShcoxYu5A30s8k6onYVafO0ZfrbKEfnEJY74f8A3v8ns2Nr5AasPqZ\nsz3g5TiyVygRG6+D6yrhORvW33roDEYnrwompE6UUkjVXNhoBoXvohLhf3Zh7kEp\nVQjXjD/rMlj5NFSFXLW4RXDokruapCyY3Q66OoAO5SYBpKtfxHiAp28ooUSmmwpx\nd39voaUCAwEAAaNTMFEwHQYDVR0OBBYEFFGFWe386uahXiBMwViRnP9t210BMB8G\nA1UdIwQYMBaAFFGFWe386uahXiBMwViRnP9t210BMA8GA1UdEwEB/wQFMAMBAf8w\nDQYJKoZIhvcNAQELBQADggEBAJ346s52BzNNZU9Sc6qUnG68yjZxCadEgijudr5h\nILhkLYsLy6HOdnirsakqdc/KhbRQPm+TbuUT94bahigOM1QuCGa8XjewTdmXGDdR\nxFTHNMLc+SopCuInXeNlBO8tekbWSglGaP742240gERzXHaGyqrSzXeL2yosY2ev\ntqbMB9i+d8uMhTYniwP3Isbbld2lCCF/Cw7flVzXnWItU0pGVj8U9qIW874eMDss\n+dxq6WfwaVzyXqH7k59xI/37zxWdRa1zNIwyi8H1dkl0vsoJSrrIGPCJpq+snT+6\n+xrUbrRn4H+K0eQSLE+LmmxuOaE4WgdK4ln9ZUXQC90R1aM\u003d\n-----END CERTIFICATE-----",
    "key": "-----BEGIN PRIVATE KEY-----\nMIIEwAIBADANBgkqhkiG9w0BAQEFAASCBKowggSmAgEAAoIBAQCwEjAP/L00Prxa\nrEe1AUhuXJXR8CeUhr6B6RqoXb+sUlx1IvG6dDm/du5fd23ZJNWJ1qmEG5rZsJX6\nkRcsV2ALzV6CKxWPOoAToODvb5AnlUjCtZewnUqbN8qV0eKexctXhESDeH08FEuc\nEbtG6XBuJKHEoXKMWLuQN9LPJOqJ2FWnztGX62yhH5xCWO+H/AN7/J7Nja+QGrD6\nmbM94OU4slcoERuvg+sq4Tkb1t966AxGJ68KJqROlFJI1VzYaAaF76IS4X92Ye5B\nKVUI14w/6zJY+TRUhVy1uEVw6JK7mqQsmN0OujqADuUmAaSrX8R4gKdvKKFEppsK\ncXd/b6GlAgMBAAECggEBAIxtlSPLImR+/N8ctPxqj4hmE6AjeI3/ggY/EuHiE7Ou\n5MsQGdfqRvysMKa3rEcaF64eJYmWMsUZECWOfvsAnTwMiiorjsBzmh8Nmxmc006e\nxC93ggp9CToPH2aqxaJ4gxvEBJkPCmNWlI9fnQyLtv5B/TvEwIWrZ704qMxJ1z4k\nlxZgPvRAa5lCRIs1BAwkvtgkc9S2nTzJqO7tfHpXk1tCMxkHyqMlfpBfWxgysPQB\nueju/IFXw3IoO80uOCZYnHagMmZeSdomlCQmX+5UjanVt4TFFppIQxKXjrkJ0Q0X\ncnboNs+VsKZgvFdVAKFXHZY5BtaQaC8U8vPKDH2SSikCgYEA5z6fgw7T9etmkqsm\nc+cAt6LH/NspMOH92Ot7IPgjZIiODx1AIPIQXM6/DzJuntyYtMk+ZJ06q/h7C8Zk\ndAQX1z3M6maD2y8vVVIMh1yjd2el7CvAc3fejEbliKKK2R9RSGB8udNcGVyNbsjT\nTLJb2mx89JFI2yGA0gXyVTbT7CsCgYEAwuuBMF0THYZ4kNi62MvF/EblkKwKY1+v\n6XFdOZiyQljClNdT8bRFxjkdnIxaXemm6X5MPtsKBKY+0ix3uHKXdglzycCth/Ku\nhqmItT1gitPEjq3Ut5Q9liWPpKNhuJjdlUi97Yj7r4NRBWeCLAUBh4n1lpl3rPxI\nvBMJqFgIMW8CgYEAinFPhmMmOyDHtB+LUfCG2Wo3WQbMzls+YtP4T3C/n7yxcBMP\nBapmaWnNsQd8etePBQ1GsW4AZlzJLe+EzIB21YJGYD8nyd2h9O6+WXv40c/X4mD/\nQyIMtubrHLZTclHxk+dQROBpTzW95wmMl2pg24//71vbxnV0bkjpIGNG1SkCgYEA\nkvnTsy0rgcLo3Ief9GNLCdxHs9wWBTKcyZDis9Bw8dhN+L+ZG5NMXZipvGaUqWXK\npxvF0EuH9VOJ4R8Iszss/CNKfOHdt7oFYaMqY0dBqcze1Js836RXAAWYl5Ne1zvl\nMXDlTdxRs9l32XRgUmL/8TzUw1c7R2QAUFimmpquqt8CgYEAjtIr2L2llacZi7vB\nfFwgvjVVg7vuAvGpRokC4m6OzfjcO7fPVJa9f8IZLSQU6E2VM//dbuAHbPC2iIGn\nQn848cwF2rhXrY0VvqfpTuxQCdiW+TGwukLxW0AHWeiD5YauGqtz4+ZC6DWGyFZQ\nSPB0OxcyG9wu0OBKbG70lP6scQE\u003d\n-----END PRIVATE KEY-----"
  }
}
testName
fapi1-advanced-final
2021-08-13 15:59:19 SUCCESS
CreateRedirectUri
Created redirect URI
redirect_uri
https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback
2021-08-13 15:59:19
GetDynamicServerConfiguration
HTTP request
request_uri
https://idp.conf.ping-eng.com:9031/.well-known/openid-configuration
request_method
GET
request_headers
{
  "accept": "text/plain, application/json, application/cbor, application/*+json, */*",
  "content-length": "0"
}
request_body

                                
2021-08-13 15:59:19 RESPONSE
GetDynamicServerConfiguration
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "date": "Fri, 13 Aug 2021 15:59:19 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003db8DCc9THPc0cf6fsUmVk6m; Path\u003d/; Secure; HttpOnly; SameSite\u003dNone",
  "content-length": "3783"
}
response_body
{
  "issuer": "https://idp.conf.ping-eng.com:9031",
  "authorization_endpoint": "https://idp.conf.ping-eng.com:9031/as/authorization.oauth2",
  "token_endpoint": "https://idp.conf.ping-eng.com:9032/as/token.oauth2",
  "revocation_endpoint": "https://idp.conf.ping-eng.com:9031/as/revoke_token.oauth2",
  "userinfo_endpoint": "https://idp.conf.ping-eng.com:9031/idp/userinfo.openid",
  "introspection_endpoint": "https://idp.conf.ping-eng.com:9031/as/introspect.oauth2",
  "jwks_uri": "https://idp.conf.ping-eng.com:9031/pf/JWKS",
  "registration_endpoint": "https://idp.conf.ping-eng.com:9031/as/clients.oauth2",
  "ping_revoked_sris_endpoint": "https://idp.conf.ping-eng.com:9031/pf-ws/rest/sessionMgmt/revokedSris",
  "ping_session_management_sris_endpoint": "https://idp.conf.ping-eng.com:9031/pf-ws/rest/sessionMgmt/sessions",
  "ping_session_management_users_endpoint": "https://idp.conf.ping-eng.com:9031/pf-ws/rest/sessionMgmt/users",
  "ping_end_session_endpoint": "https://idp.conf.ping-eng.com:9031/idp/startSLO.ping",
  "device_authorization_endpoint": "https://idp.conf.ping-eng.com:9031/as/device_authz.oauth2",
  "scopes_supported": [ "openid", "payments" ],
  "claims_supported": [ "acr", "sub" ],
  "response_types_supported": [ "code", "token", "id_token", "code token", "code id_token", "token id_token", "code token id_token" ],
  "response_modes_supported": [ "fragment", "query", "form_post" ],
  "grant_types_supported": [ "implicit", "authorization_code", "refresh_token", "password", "client_credentials", "urn:pingidentity.com:oauth2:grant_type:validate_bearer", "urn:ietf:params:oauth:grant-type:jwt-bearer", "urn:ietf:params:oauth:grant-type:saml2-bearer", "urn:ietf:params:oauth:grant-type:device_code", "urn:ietf:params:oauth:grant-type:token-exchange", "urn:openid:params:grant-type:ciba" ],
  "subject_types_supported": [ "public", "pairwise" ],
  "id_token_signing_alg_values_supported": [ "none", "HS256", "HS384", "HS512", "RS256", "RS384", "RS512", "ES256", "ES384", "ES512", "PS256", "PS384", "PS512" ],
  
"token_endpoint_auth_methods_supported": ["client_secret_basic","client_secret_post","private_key_jwt","tls_client_auth"],

  "token_endpoint_auth_signing_alg_values_supported":  [ "RS256", "RS384", "RS512", "ES256", "ES384", "ES512", "PS256", "PS384", "PS512" ],
  
"tls_client_certificate_bound_access_tokens":true,
"claim_types_supported": 
[ "normal" ],
  "claims_parameter_supported": false,
  "request_parameter_supported": true,
  "request_uri_parameter_supported": false,
  
"request_object_signing_alg_values_supported": [ "RS256", "RS384", "RS512", "ES256", "ES384", "ES512", "PS256", "PS384", "PS512", "none" ],

  "id_token_encryption_alg_values_supported": [ "dir", "A128KW", "A192KW", "A256KW", "A128GCMKW", "A192GCMKW", "A256GCMKW", "ECDH-ES", "ECDH-ES+A128KW", "ECDH-ES+A192KW", "ECDH-ES+A256KW", "RSA-OAEP" ],
  "id_token_encryption_enc_values_supported": [ "A128CBC-HS256", "A192CBC-HS384", "A256CBC-HS512", "A128GCM", "A192GCM", "A256GCM" ],
  "pushed_authorization_request_endpoint": "https://idp.conf.ping-eng.com:9031/as/par.oauth2",
  "require_pushed_authorization_requests": false,
  "backchannel_authentication_endpoint": "https://idp.conf.ping-eng.com:9031/as/bc-auth.ciba",
  "backchannel_token_delivery_modes_supported": [ "poll", "ping" ],
  "backchannel_authentication_request_signing_alg_values_supported": [ "RS256", "RS384", "RS512", "ES256", "ES384", "ES512", "PS256", "PS384", "PS512" ],
  "backchannel_user_code_parameter_supported": false,
  "code_challenge_methods_supported": [ "S256" ]

,
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://idp.conf.ping-eng.com:9032/as/token.oauth2",
    "pushed_authorization_request_endpoint": "https://idp.conf.ping-eng.com:9032/as/par.oauth2"
    }
}

2021-08-13 15:59:19
GetDynamicServerConfiguration
Downloaded server configuration
server_config_string
{
  "issuer": "https://idp.conf.ping-eng.com:9031",
  "authorization_endpoint": "https://idp.conf.ping-eng.com:9031/as/authorization.oauth2",
  "token_endpoint": "https://idp.conf.ping-eng.com:9032/as/token.oauth2",
  "revocation_endpoint": "https://idp.conf.ping-eng.com:9031/as/revoke_token.oauth2",
  "userinfo_endpoint": "https://idp.conf.ping-eng.com:9031/idp/userinfo.openid",
  "introspection_endpoint": "https://idp.conf.ping-eng.com:9031/as/introspect.oauth2",
  "jwks_uri": "https://idp.conf.ping-eng.com:9031/pf/JWKS",
  "registration_endpoint": "https://idp.conf.ping-eng.com:9031/as/clients.oauth2",
  "ping_revoked_sris_endpoint": "https://idp.conf.ping-eng.com:9031/pf-ws/rest/sessionMgmt/revokedSris",
  "ping_session_management_sris_endpoint": "https://idp.conf.ping-eng.com:9031/pf-ws/rest/sessionMgmt/sessions",
  "ping_session_management_users_endpoint": "https://idp.conf.ping-eng.com:9031/pf-ws/rest/sessionMgmt/users",
  "ping_end_session_endpoint": "https://idp.conf.ping-eng.com:9031/idp/startSLO.ping",
  "device_authorization_endpoint": "https://idp.conf.ping-eng.com:9031/as/device_authz.oauth2",
  "scopes_supported": [ "openid", "payments" ],
  "claims_supported": [ "acr", "sub" ],
  "response_types_supported": [ "code", "token", "id_token", "code token", "code id_token", "token id_token", "code token id_token" ],
  "response_modes_supported": [ "fragment", "query", "form_post" ],
  "grant_types_supported": [ "implicit", "authorization_code", "refresh_token", "password", "client_credentials", "urn:pingidentity.com:oauth2:grant_type:validate_bearer", "urn:ietf:params:oauth:grant-type:jwt-bearer", "urn:ietf:params:oauth:grant-type:saml2-bearer", "urn:ietf:params:oauth:grant-type:device_code", "urn:ietf:params:oauth:grant-type:token-exchange", "urn:openid:params:grant-type:ciba" ],
  "subject_types_supported": [ "public", "pairwise" ],
  "id_token_signing_alg_values_supported": [ "none", "HS256", "HS384", "HS512", "RS256", "RS384", "RS512", "ES256", "ES384", "ES512", "PS256", "PS384", "PS512" ],
  
"token_endpoint_auth_methods_supported": ["client_secret_basic","client_secret_post","private_key_jwt","tls_client_auth"],

  "token_endpoint_auth_signing_alg_values_supported":  [ "RS256", "RS384", "RS512", "ES256", "ES384", "ES512", "PS256", "PS384", "PS512" ],
  
"tls_client_certificate_bound_access_tokens":true,
"claim_types_supported": 
[ "normal" ],
  "claims_parameter_supported": false,
  "request_parameter_supported": true,
  "request_uri_parameter_supported": false,
  
"request_object_signing_alg_values_supported": [ "RS256", "RS384", "RS512", "ES256", "ES384", "ES512", "PS256", "PS384", "PS512", "none" ],

  "id_token_encryption_alg_values_supported": [ "dir", "A128KW", "A192KW", "A256KW", "A128GCMKW", "A192GCMKW", "A256GCMKW", "ECDH-ES", "ECDH-ES+A128KW", "ECDH-ES+A192KW", "ECDH-ES+A256KW", "RSA-OAEP" ],
  "id_token_encryption_enc_values_supported": [ "A128CBC-HS256", "A192CBC-HS384", "A256CBC-HS512", "A128GCM", "A192GCM", "A256GCM" ],
  "pushed_authorization_request_endpoint": "https://idp.conf.ping-eng.com:9031/as/par.oauth2",
  "require_pushed_authorization_requests": false,
  "backchannel_authentication_endpoint": "https://idp.conf.ping-eng.com:9031/as/bc-auth.ciba",
  "backchannel_token_delivery_modes_supported": [ "poll", "ping" ],
  "backchannel_authentication_request_signing_alg_values_supported": [ "RS256", "RS384", "RS512", "ES256", "ES384", "ES512", "PS256", "PS384", "PS512" ],
  "backchannel_user_code_parameter_supported": false,
  "code_challenge_methods_supported": [ "S256" ]

,
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://idp.conf.ping-eng.com:9032/as/token.oauth2",
    "pushed_authorization_request_endpoint": "https://idp.conf.ping-eng.com:9032/as/par.oauth2"
    }
}

2021-08-13 15:59:19 SUCCESS
GetDynamicServerConfiguration
Successfully parsed server configuration
issuer
https://idp.conf.ping-eng.com:9031
authorization_endpoint
https://idp.conf.ping-eng.com:9031/as/authorization.oauth2
token_endpoint
https://idp.conf.ping-eng.com:9032/as/token.oauth2
revocation_endpoint
https://idp.conf.ping-eng.com:9031/as/revoke_token.oauth2
userinfo_endpoint
https://idp.conf.ping-eng.com:9031/idp/userinfo.openid
introspection_endpoint
https://idp.conf.ping-eng.com:9031/as/introspect.oauth2
jwks_uri
https://idp.conf.ping-eng.com:9031/pf/JWKS
registration_endpoint
https://idp.conf.ping-eng.com:9031/as/clients.oauth2
ping_revoked_sris_endpoint
https://idp.conf.ping-eng.com:9031/pf-ws/rest/sessionMgmt/revokedSris
ping_session_management_sris_endpoint
https://idp.conf.ping-eng.com:9031/pf-ws/rest/sessionMgmt/sessions
ping_session_management_users_endpoint
https://idp.conf.ping-eng.com:9031/pf-ws/rest/sessionMgmt/users
ping_end_session_endpoint
https://idp.conf.ping-eng.com:9031/idp/startSLO.ping
device_authorization_endpoint
https://idp.conf.ping-eng.com:9031/as/device_authz.oauth2
scopes_supported
[
  "openid",
  "payments"
]
claims_supported
[
  "acr",
  "sub"
]
response_types_supported
[
  "code",
  "token",
  "id_token",
  "code token",
  "code id_token",
  "token id_token",
  "code token id_token"
]
response_modes_supported
[
  "fragment",
  "query",
  "form_post"
]
grant_types_supported
[
  "implicit",
  "authorization_code",
  "refresh_token",
  "password",
  "client_credentials",
  "urn:pingidentity.com:oauth2:grant_type:validate_bearer",
  "urn:ietf:params:oauth:grant-type:jwt-bearer",
  "urn:ietf:params:oauth:grant-type:saml2-bearer",
  "urn:ietf:params:oauth:grant-type:device_code",
  "urn:ietf:params:oauth:grant-type:token-exchange",
  "urn:openid:params:grant-type:ciba"
]
subject_types_supported
[
  "public",
  "pairwise"
]
id_token_signing_alg_values_supported
[
  "none",
  "HS256",
  "HS384",
  "HS512",
  "RS256",
  "RS384",
  "RS512",
  "ES256",
  "ES384",
  "ES512",
  "PS256",
  "PS384",
  "PS512"
]
token_endpoint_auth_methods_supported
[
  "client_secret_basic",
  "client_secret_post",
  "private_key_jwt",
  "tls_client_auth"
]
token_endpoint_auth_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "ES256",
  "ES384",
  "ES512",
  "PS256",
  "PS384",
  "PS512"
]
tls_client_certificate_bound_access_tokens
true
claim_types_supported
[
  "normal"
]
claims_parameter_supported
false
request_parameter_supported
true
request_uri_parameter_supported
false
request_object_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "ES256",
  "ES384",
  "ES512",
  "PS256",
  "PS384",
  "PS512",
  "none"
]
id_token_encryption_alg_values_supported
[
  "dir",
  "A128KW",
  "A192KW",
  "A256KW",
  "A128GCMKW",
  "A192GCMKW",
  "A256GCMKW",
  "ECDH-ES",
  "ECDH-ES+A128KW",
  "ECDH-ES+A192KW",
  "ECDH-ES+A256KW",
  "RSA-OAEP"
]
id_token_encryption_enc_values_supported
[
  "A128CBC-HS256",
  "A192CBC-HS384",
  "A256CBC-HS512",
  "A128GCM",
  "A192GCM",
  "A256GCM"
]
pushed_authorization_request_endpoint
https://idp.conf.ping-eng.com:9031/as/par.oauth2
require_pushed_authorization_requests
false
backchannel_authentication_endpoint
https://idp.conf.ping-eng.com:9031/as/bc-auth.ciba
backchannel_token_delivery_modes_supported
[
  "poll",
  "ping"
]
backchannel_authentication_request_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "ES256",
  "ES384",
  "ES512",
  "PS256",
  "PS384",
  "PS512"
]
backchannel_user_code_parameter_supported
false
code_challenge_methods_supported
[
  "S256"
]
mtls_endpoint_aliases
{
  "token_endpoint": "https://idp.conf.ping-eng.com:9032/as/token.oauth2",
  "pushed_authorization_request_endpoint": "https://idp.conf.ping-eng.com:9032/as/par.oauth2"
}
2021-08-13 15:59:19 SUCCESS
AddMTLSEndpointAliasesToEnvironment
Added mtls_endpoint_aliases to environment
2021-08-13 15:59:19 SUCCESS
CheckServerConfiguration
Found required server configuration keys
required
[
  "authorization_endpoint",
  "token_endpoint",
  "issuer"
]
2021-08-13 15:59:19
FetchServerKeys
Fetching server key
jwks_uri
https://idp.conf.ping-eng.com:9031/pf/JWKS
2021-08-13 15:59:19
FetchServerKeys
HTTP request
request_uri
https://idp.conf.ping-eng.com:9031/pf/JWKS
request_method
GET
request_headers
{
  "accept": "text/plain, application/json, application/cbor, application/*+json, */*",
  "content-length": "0"
}
request_body

                                
2021-08-13 15:59:20 RESPONSE
FetchServerKeys
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "date": "Fri, 13 Aug 2021 15:59:20 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003dfAWc09VSbDwxrU4pHScurS; Path\u003d/; Secure; HttpOnly; SameSite\u003dNone",
  "transfer-encoding": "chunked"
}
response_body
{"keys":[{"kty":"RSA","kid":"2CmYYedTMgSg_B2IEBeQc3c_JY0","use":"sig","n":"3bdVMnUR62v8t0UFsyg3lITTNCS6M1qgVimdBHmhHmU_mK4brurPe3v3BDhWvRvCV4ZxLBvvxj3jEQawmz-XviBb6q0ox_PwzrUAb-qP6efmKuAfNKTGzhEqSzkxZMWqACbL_BL4Hw5WmSxaPtRky678AbCzLVBa6E9nfpldgUa0-lukdR-JMF9VyAtlyTuN-0Sc9abGObLCoM0k-b_3DLLvKFlUmBc7G2M0bCYA_2L92nmDDAMLaPMUeyHoUrNR5f5divBt0SrRpPuvNp5gMlhSdea4oacurnjSbjI0OIY9yjihmVNCnyRTojJGU8zHuTcbTn_xQA_6gE3Xi45Gww","e":"AQAB"},{"kty":"EC","kid":"8xsYE4Tn3xDqzfp84Bvy2EjAfnA","use":"sig","x":"1cnxOz2zPjxTNl87EP0natwkjsY21sZtTrVjFCwSlKqBZP_9-vAF71pd5d0C_AVg","y":"dTMtn07V5Bxhg_lct0FOgNmP2MumHxd4DvCQ5z-11ISEkZzm4R0nw3-SpKz1z4jp","crv":"P-384"},{"kty":"EC","kid":"LT5rdwU8SbVJar_J7x6zw42TZm4","use":"sig","x":"AbZvDXykFQorO0FKXZT6ch123qOw_P2hdDLT8EGu7fmEzy2KwiXKgxD3ToTwBXQh1xVIDASTVyk8ULifcPyCrzVg","y":"AfS_WYn_POzpZaZ7CK4-NXdCKoIdSjRpLidr1gPulIs0CjU04cGB6lzY_M2z9P9fDlwdxMJsB7WzzqFYLhyD-hxG","crv":"P-521"},{"kty":"EC","kid":"OWOHC2Lhg2V9Z2OP3AeTnsIqfcU","use":"sig","x":"RUEyPQeEHjIR6E6Js6MGzZnrzBKkoyLP0dZve4ZdThk","y":"Q_sV8s67YTUp1IkK5DrD2Od2JW7wKkOm334yX5m4xJY","crv":"P-256"},{"kty":"EC","kid":"Jvt8Q_a_g_tybc1my9tocjX-c4A","use":"sig","x":"F4vJqpd243lWKo7uDKSrggXwuDYAOSXHcBfDBfYOYt0","y":"QAMHyzLnQRKrUqF8ycAFrQ3Cg9Its3xOQ_r9PO0X5GY","crv":"P-256"},{"kty":"EC","kid":"K1pu5hRTBR4Z_L9DabJ6z8UYNC8","use":"sig","x":"Pf9yQal5uYkLe37xaybqwmQEkYPcwW-6Eg6-jiXU2mJi4RY_DU2A7ghHpiUjX56i","y":"S6KXvLguETXRx8suIvV05i8p29cpCW9W_tgsaBKT6qI62parFenA2VSvhf_8U8FO","crv":"P-384"},{"kty":"RSA","kid":"NfGZj3wtxSjC-G5ZOsy0GIrGqwU","use":"sig","n":"kL1Bq2Eo1i1qLrwK6XLmCyFf3WNbKqTJfilwntH-Voy_qgprhprcv8BpQtD8SdkAvrpeLcZLYg4yUbFSumxJC9DXNNkJkIl21tJZAxm-ism8dp-80T2_J-fXwI_h6jw_PK2JwZKBl6mKRvrM3VwEdVHYWLb7uII2Khsa-QE0T3EOYAZKASlitKYgD1GEtlq0DNhJ6q6IVEtGnuvTbyOmF_mD-50CcwxoBdy-6m_ue3-YbgYGL6yd0pP5KMiw3BOO1In7Mb8Yg7akJcfjnnqihBgWuDVkr0_usoBZ8mjqYm_zSBsXpGiKIGpV_UVej4o5zMEsnkMe36s02ocvDOWBHQ","e":"AQAB"},{"kty":"EC","kid":"RdEAGU6yqPfkvo6OjXVFeed1wuI","use":"sig","x":"AZuOUs9iispneV185uu2qVslK0pTHaN5sWj4XuwEFJ0qBm_LFSJFXAUy20uasUK4KI6mmezPZZs0ZWsDjcRILMJB","y":"AKDnQNp2KypK6uYe0YIHL-UTJhVxhl9qJNOLFFDy3gcHIzSMvMeexuJpvr-wzOi9gzHTHs-lyRf-7I-l59bjyWKG","crv":"P-521"},{"kty":"EC","kid":"BwvCR6iBoOhSint4SwviYtdL35o","use":"enc","x":"AH_JYF0Kw-g6kbb1m0MB9Vkck-TGiHfrn8_UNWvD_l4VdqGGt1-EhA8nrfolZVsHeNaQM06lRhlyHqyIOaHN-yJy","y":"AIvuF575rqT-3sq_ja97840a-J7P93K3dr92YnJo6c5dl0prPyafIG3BNm9PfuhvcA2spVJw4t4rjtNekgyUeVX3","crv":"P-521"},{"kty":"EC","kid":"EDuQgEuWy4bDB4VEI2WhdqgzKzQ","use":"enc","x":"2hxj_wZFyRXuYxn4RDpnn2eE7VeVSTzsULm_qTkVcua-pv68qfL5eWTu2hsnMgmg","y":"ahx3r1rDzsQNUXnfH6ukWQGdC132E9FuF5py8ZdwAS2YImecC7MrAb4dJeowrX-h","crv":"P-384"},{"kty":"RSA","kid":"oAgFKBn4jaaiisguObdKPSgxBDw","use":"enc","n":"otYWk0hVkhhtCKGNT33RgXENFaZFJXjZ9jSJxyikceMyG3RKPnULtRQ7lKkIGpC8V_OJRl6MPp6wOU8SJZFqvsy2LCECejjUCMSzyJ1IJVJcicZ3E-Ru_vPs9lrT9ey3vgvdAPWxvRykPGPlgj5OMTmPRJx4-IDJ7XRXYREFjskGV7cECLd1AhptYyMyw_anUCKzhANMk_v4QG5q9poSuXPEAAYqnZsVpkoW5fAZAUdSAsrCP8q3Q1hcTUIjeRy-xcuGuMpWtq740ggt19Sz9PkpDg3NSiwZHDIybgyCbXKZkLIU6-Uu1wKhSVdBhTWtwtRgRVo6-GuODg3EFpSqbw","e":"AQAB"},{"kty":"EC","kid":"zcKSoQqEAJ6TCUFIKqmKyh32_cw","use":"enc","x":"czEXTyQiOF2-N8wxBgzcAYSWCZTe048YGAFhQ5qGEKo","y":"ZSDzPSI1Qr4s-D7y0TvFgy6Jc5jEkx-DzY_SK4JOMvk","crv":"P-256"}]}
2021-08-13 15:59:20
FetchServerKeys
Found JWK set string
jwk_string
{"keys":[{"kty":"RSA","kid":"2CmYYedTMgSg_B2IEBeQc3c_JY0","use":"sig","n":"3bdVMnUR62v8t0UFsyg3lITTNCS6M1qgVimdBHmhHmU_mK4brurPe3v3BDhWvRvCV4ZxLBvvxj3jEQawmz-XviBb6q0ox_PwzrUAb-qP6efmKuAfNKTGzhEqSzkxZMWqACbL_BL4Hw5WmSxaPtRky678AbCzLVBa6E9nfpldgUa0-lukdR-JMF9VyAtlyTuN-0Sc9abGObLCoM0k-b_3DLLvKFlUmBc7G2M0bCYA_2L92nmDDAMLaPMUeyHoUrNR5f5divBt0SrRpPuvNp5gMlhSdea4oacurnjSbjI0OIY9yjihmVNCnyRTojJGU8zHuTcbTn_xQA_6gE3Xi45Gww","e":"AQAB"},{"kty":"EC","kid":"8xsYE4Tn3xDqzfp84Bvy2EjAfnA","use":"sig","x":"1cnxOz2zPjxTNl87EP0natwkjsY21sZtTrVjFCwSlKqBZP_9-vAF71pd5d0C_AVg","y":"dTMtn07V5Bxhg_lct0FOgNmP2MumHxd4DvCQ5z-11ISEkZzm4R0nw3-SpKz1z4jp","crv":"P-384"},{"kty":"EC","kid":"LT5rdwU8SbVJar_J7x6zw42TZm4","use":"sig","x":"AbZvDXykFQorO0FKXZT6ch123qOw_P2hdDLT8EGu7fmEzy2KwiXKgxD3ToTwBXQh1xVIDASTVyk8ULifcPyCrzVg","y":"AfS_WYn_POzpZaZ7CK4-NXdCKoIdSjRpLidr1gPulIs0CjU04cGB6lzY_M2z9P9fDlwdxMJsB7WzzqFYLhyD-hxG","crv":"P-521"},{"kty":"EC","kid":"OWOHC2Lhg2V9Z2OP3AeTnsIqfcU","use":"sig","x":"RUEyPQeEHjIR6E6Js6MGzZnrzBKkoyLP0dZve4ZdThk","y":"Q_sV8s67YTUp1IkK5DrD2Od2JW7wKkOm334yX5m4xJY","crv":"P-256"},{"kty":"EC","kid":"Jvt8Q_a_g_tybc1my9tocjX-c4A","use":"sig","x":"F4vJqpd243lWKo7uDKSrggXwuDYAOSXHcBfDBfYOYt0","y":"QAMHyzLnQRKrUqF8ycAFrQ3Cg9Its3xOQ_r9PO0X5GY","crv":"P-256"},{"kty":"EC","kid":"K1pu5hRTBR4Z_L9DabJ6z8UYNC8","use":"sig","x":"Pf9yQal5uYkLe37xaybqwmQEkYPcwW-6Eg6-jiXU2mJi4RY_DU2A7ghHpiUjX56i","y":"S6KXvLguETXRx8suIvV05i8p29cpCW9W_tgsaBKT6qI62parFenA2VSvhf_8U8FO","crv":"P-384"},{"kty":"RSA","kid":"NfGZj3wtxSjC-G5ZOsy0GIrGqwU","use":"sig","n":"kL1Bq2Eo1i1qLrwK6XLmCyFf3WNbKqTJfilwntH-Voy_qgprhprcv8BpQtD8SdkAvrpeLcZLYg4yUbFSumxJC9DXNNkJkIl21tJZAxm-ism8dp-80T2_J-fXwI_h6jw_PK2JwZKBl6mKRvrM3VwEdVHYWLb7uII2Khsa-QE0T3EOYAZKASlitKYgD1GEtlq0DNhJ6q6IVEtGnuvTbyOmF_mD-50CcwxoBdy-6m_ue3-YbgYGL6yd0pP5KMiw3BOO1In7Mb8Yg7akJcfjnnqihBgWuDVkr0_usoBZ8mjqYm_zSBsXpGiKIGpV_UVej4o5zMEsnkMe36s02ocvDOWBHQ","e":"AQAB"},{"kty":"EC","kid":"RdEAGU6yqPfkvo6OjXVFeed1wuI","use":"sig","x":"AZuOUs9iispneV185uu2qVslK0pTHaN5sWj4XuwEFJ0qBm_LFSJFXAUy20uasUK4KI6mmezPZZs0ZWsDjcRILMJB","y":"AKDnQNp2KypK6uYe0YIHL-UTJhVxhl9qJNOLFFDy3gcHIzSMvMeexuJpvr-wzOi9gzHTHs-lyRf-7I-l59bjyWKG","crv":"P-521"},{"kty":"EC","kid":"BwvCR6iBoOhSint4SwviYtdL35o","use":"enc","x":"AH_JYF0Kw-g6kbb1m0MB9Vkck-TGiHfrn8_UNWvD_l4VdqGGt1-EhA8nrfolZVsHeNaQM06lRhlyHqyIOaHN-yJy","y":"AIvuF575rqT-3sq_ja97840a-J7P93K3dr92YnJo6c5dl0prPyafIG3BNm9PfuhvcA2spVJw4t4rjtNekgyUeVX3","crv":"P-521"},{"kty":"EC","kid":"EDuQgEuWy4bDB4VEI2WhdqgzKzQ","use":"enc","x":"2hxj_wZFyRXuYxn4RDpnn2eE7VeVSTzsULm_qTkVcua-pv68qfL5eWTu2hsnMgmg","y":"ahx3r1rDzsQNUXnfH6ukWQGdC132E9FuF5py8ZdwAS2YImecC7MrAb4dJeowrX-h","crv":"P-384"},{"kty":"RSA","kid":"oAgFKBn4jaaiisguObdKPSgxBDw","use":"enc","n":"otYWk0hVkhhtCKGNT33RgXENFaZFJXjZ9jSJxyikceMyG3RKPnULtRQ7lKkIGpC8V_OJRl6MPp6wOU8SJZFqvsy2LCECejjUCMSzyJ1IJVJcicZ3E-Ru_vPs9lrT9ey3vgvdAPWxvRykPGPlgj5OMTmPRJx4-IDJ7XRXYREFjskGV7cECLd1AhptYyMyw_anUCKzhANMk_v4QG5q9poSuXPEAAYqnZsVpkoW5fAZAUdSAsrCP8q3Q1hcTUIjeRy-xcuGuMpWtq740ggt19Sz9PkpDg3NSiwZHDIybgyCbXKZkLIU6-Uu1wKhSVdBhTWtwtRgRVo6-GuODg3EFpSqbw","e":"AQAB"},{"kty":"EC","kid":"zcKSoQqEAJ6TCUFIKqmKyh32_cw","use":"enc","x":"czEXTyQiOF2-N8wxBgzcAYSWCZTe048YGAFhQ5qGEKo","y":"ZSDzPSI1Qr4s-D7y0TvFgy6Jc5jEkx-DzY_SK4JOMvk","crv":"P-256"}]}
2021-08-13 15:59:20 SUCCESS
FetchServerKeys
Found server JWK set
server_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "kid": "2CmYYedTMgSg_B2IEBeQc3c_JY0",
      "use": "sig",
      "n": "3bdVMnUR62v8t0UFsyg3lITTNCS6M1qgVimdBHmhHmU_mK4brurPe3v3BDhWvRvCV4ZxLBvvxj3jEQawmz-XviBb6q0ox_PwzrUAb-qP6efmKuAfNKTGzhEqSzkxZMWqACbL_BL4Hw5WmSxaPtRky678AbCzLVBa6E9nfpldgUa0-lukdR-JMF9VyAtlyTuN-0Sc9abGObLCoM0k-b_3DLLvKFlUmBc7G2M0bCYA_2L92nmDDAMLaPMUeyHoUrNR5f5divBt0SrRpPuvNp5gMlhSdea4oacurnjSbjI0OIY9yjihmVNCnyRTojJGU8zHuTcbTn_xQA_6gE3Xi45Gww",
      "e": "AQAB"
    },
    {
      "kty": "EC",
      "kid": "8xsYE4Tn3xDqzfp84Bvy2EjAfnA",
      "use": "sig",
      "x": "1cnxOz2zPjxTNl87EP0natwkjsY21sZtTrVjFCwSlKqBZP_9-vAF71pd5d0C_AVg",
      "y": "dTMtn07V5Bxhg_lct0FOgNmP2MumHxd4DvCQ5z-11ISEkZzm4R0nw3-SpKz1z4jp",
      "crv": "P-384"
    },
    {
      "kty": "EC",
      "kid": "LT5rdwU8SbVJar_J7x6zw42TZm4",
      "use": "sig",
      "x": "AbZvDXykFQorO0FKXZT6ch123qOw_P2hdDLT8EGu7fmEzy2KwiXKgxD3ToTwBXQh1xVIDASTVyk8ULifcPyCrzVg",
      "y": "AfS_WYn_POzpZaZ7CK4-NXdCKoIdSjRpLidr1gPulIs0CjU04cGB6lzY_M2z9P9fDlwdxMJsB7WzzqFYLhyD-hxG",
      "crv": "P-521"
    },
    {
      "kty": "EC",
      "kid": "OWOHC2Lhg2V9Z2OP3AeTnsIqfcU",
      "use": "sig",
      "x": "RUEyPQeEHjIR6E6Js6MGzZnrzBKkoyLP0dZve4ZdThk",
      "y": "Q_sV8s67YTUp1IkK5DrD2Od2JW7wKkOm334yX5m4xJY",
      "crv": "P-256"
    },
    {
      "kty": "EC",
      "kid": "Jvt8Q_a_g_tybc1my9tocjX-c4A",
      "use": "sig",
      "x": "F4vJqpd243lWKo7uDKSrggXwuDYAOSXHcBfDBfYOYt0",
      "y": "QAMHyzLnQRKrUqF8ycAFrQ3Cg9Its3xOQ_r9PO0X5GY",
      "crv": "P-256"
    },
    {
      "kty": "EC",
      "kid": "K1pu5hRTBR4Z_L9DabJ6z8UYNC8",
      "use": "sig",
      "x": "Pf9yQal5uYkLe37xaybqwmQEkYPcwW-6Eg6-jiXU2mJi4RY_DU2A7ghHpiUjX56i",
      "y": "S6KXvLguETXRx8suIvV05i8p29cpCW9W_tgsaBKT6qI62parFenA2VSvhf_8U8FO",
      "crv": "P-384"
    },
    {
      "kty": "RSA",
      "kid": "NfGZj3wtxSjC-G5ZOsy0GIrGqwU",
      "use": "sig",
      "n": "kL1Bq2Eo1i1qLrwK6XLmCyFf3WNbKqTJfilwntH-Voy_qgprhprcv8BpQtD8SdkAvrpeLcZLYg4yUbFSumxJC9DXNNkJkIl21tJZAxm-ism8dp-80T2_J-fXwI_h6jw_PK2JwZKBl6mKRvrM3VwEdVHYWLb7uII2Khsa-QE0T3EOYAZKASlitKYgD1GEtlq0DNhJ6q6IVEtGnuvTbyOmF_mD-50CcwxoBdy-6m_ue3-YbgYGL6yd0pP5KMiw3BOO1In7Mb8Yg7akJcfjnnqihBgWuDVkr0_usoBZ8mjqYm_zSBsXpGiKIGpV_UVej4o5zMEsnkMe36s02ocvDOWBHQ",
      "e": "AQAB"
    },
    {
      "kty": "EC",
      "kid": "RdEAGU6yqPfkvo6OjXVFeed1wuI",
      "use": "sig",
      "x": "AZuOUs9iispneV185uu2qVslK0pTHaN5sWj4XuwEFJ0qBm_LFSJFXAUy20uasUK4KI6mmezPZZs0ZWsDjcRILMJB",
      "y": "AKDnQNp2KypK6uYe0YIHL-UTJhVxhl9qJNOLFFDy3gcHIzSMvMeexuJpvr-wzOi9gzHTHs-lyRf-7I-l59bjyWKG",
      "crv": "P-521"
    },
    {
      "kty": "EC",
      "kid": "BwvCR6iBoOhSint4SwviYtdL35o",
      "use": "enc",
      "x": "AH_JYF0Kw-g6kbb1m0MB9Vkck-TGiHfrn8_UNWvD_l4VdqGGt1-EhA8nrfolZVsHeNaQM06lRhlyHqyIOaHN-yJy",
      "y": "AIvuF575rqT-3sq_ja97840a-J7P93K3dr92YnJo6c5dl0prPyafIG3BNm9PfuhvcA2spVJw4t4rjtNekgyUeVX3",
      "crv": "P-521"
    },
    {
      "kty": "EC",
      "kid": "EDuQgEuWy4bDB4VEI2WhdqgzKzQ",
      "use": "enc",
      "x": "2hxj_wZFyRXuYxn4RDpnn2eE7VeVSTzsULm_qTkVcua-pv68qfL5eWTu2hsnMgmg",
      "y": "ahx3r1rDzsQNUXnfH6ukWQGdC132E9FuF5py8ZdwAS2YImecC7MrAb4dJeowrX-h",
      "crv": "P-384"
    },
    {
      "kty": "RSA",
      "kid": "oAgFKBn4jaaiisguObdKPSgxBDw",
      "use": "enc",
      "n": "otYWk0hVkhhtCKGNT33RgXENFaZFJXjZ9jSJxyikceMyG3RKPnULtRQ7lKkIGpC8V_OJRl6MPp6wOU8SJZFqvsy2LCECejjUCMSzyJ1IJVJcicZ3E-Ru_vPs9lrT9ey3vgvdAPWxvRykPGPlgj5OMTmPRJx4-IDJ7XRXYREFjskGV7cECLd1AhptYyMyw_anUCKzhANMk_v4QG5q9poSuXPEAAYqnZsVpkoW5fAZAUdSAsrCP8q3Q1hcTUIjeRy-xcuGuMpWtq740ggt19Sz9PkpDg3NSiwZHDIybgyCbXKZkLIU6-Uu1wKhSVdBhTWtwtRgRVo6-GuODg3EFpSqbw",
      "e": "AQAB"
    },
    {
      "kty": "EC",
      "kid": "zcKSoQqEAJ6TCUFIKqmKyh32_cw",
      "use": "enc",
      "x": "czEXTyQiOF2-N8wxBgzcAYSWCZTe048YGAFhQ5qGEKo",
      "y": "ZSDzPSI1Qr4s-D7y0TvFgy6Jc5jEkx-DzY_SK4JOMvk",
      "crv": "P-256"
    }
  ]
}
2021-08-13 15:59:20 SUCCESS
CheckServerKeysIsValid
Server JWKs is valid
server_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "kid": "2CmYYedTMgSg_B2IEBeQc3c_JY0",
      "use": "sig",
      "n": "3bdVMnUR62v8t0UFsyg3lITTNCS6M1qgVimdBHmhHmU_mK4brurPe3v3BDhWvRvCV4ZxLBvvxj3jEQawmz-XviBb6q0ox_PwzrUAb-qP6efmKuAfNKTGzhEqSzkxZMWqACbL_BL4Hw5WmSxaPtRky678AbCzLVBa6E9nfpldgUa0-lukdR-JMF9VyAtlyTuN-0Sc9abGObLCoM0k-b_3DLLvKFlUmBc7G2M0bCYA_2L92nmDDAMLaPMUeyHoUrNR5f5divBt0SrRpPuvNp5gMlhSdea4oacurnjSbjI0OIY9yjihmVNCnyRTojJGU8zHuTcbTn_xQA_6gE3Xi45Gww",
      "e": "AQAB"
    },
    {
      "kty": "EC",
      "kid": "8xsYE4Tn3xDqzfp84Bvy2EjAfnA",
      "use": "sig",
      "x": "1cnxOz2zPjxTNl87EP0natwkjsY21sZtTrVjFCwSlKqBZP_9-vAF71pd5d0C_AVg",
      "y": "dTMtn07V5Bxhg_lct0FOgNmP2MumHxd4DvCQ5z-11ISEkZzm4R0nw3-SpKz1z4jp",
      "crv": "P-384"
    },
    {
      "kty": "EC",
      "kid": "LT5rdwU8SbVJar_J7x6zw42TZm4",
      "use": "sig",
      "x": "AbZvDXykFQorO0FKXZT6ch123qOw_P2hdDLT8EGu7fmEzy2KwiXKgxD3ToTwBXQh1xVIDASTVyk8ULifcPyCrzVg",
      "y": "AfS_WYn_POzpZaZ7CK4-NXdCKoIdSjRpLidr1gPulIs0CjU04cGB6lzY_M2z9P9fDlwdxMJsB7WzzqFYLhyD-hxG",
      "crv": "P-521"
    },
    {
      "kty": "EC",
      "kid": "OWOHC2Lhg2V9Z2OP3AeTnsIqfcU",
      "use": "sig",
      "x": "RUEyPQeEHjIR6E6Js6MGzZnrzBKkoyLP0dZve4ZdThk",
      "y": "Q_sV8s67YTUp1IkK5DrD2Od2JW7wKkOm334yX5m4xJY",
      "crv": "P-256"
    },
    {
      "kty": "EC",
      "kid": "Jvt8Q_a_g_tybc1my9tocjX-c4A",
      "use": "sig",
      "x": "F4vJqpd243lWKo7uDKSrggXwuDYAOSXHcBfDBfYOYt0",
      "y": "QAMHyzLnQRKrUqF8ycAFrQ3Cg9Its3xOQ_r9PO0X5GY",
      "crv": "P-256"
    },
    {
      "kty": "EC",
      "kid": "K1pu5hRTBR4Z_L9DabJ6z8UYNC8",
      "use": "sig",
      "x": "Pf9yQal5uYkLe37xaybqwmQEkYPcwW-6Eg6-jiXU2mJi4RY_DU2A7ghHpiUjX56i",
      "y": "S6KXvLguETXRx8suIvV05i8p29cpCW9W_tgsaBKT6qI62parFenA2VSvhf_8U8FO",
      "crv": "P-384"
    },
    {
      "kty": "RSA",
      "kid": "NfGZj3wtxSjC-G5ZOsy0GIrGqwU",
      "use": "sig",
      "n": "kL1Bq2Eo1i1qLrwK6XLmCyFf3WNbKqTJfilwntH-Voy_qgprhprcv8BpQtD8SdkAvrpeLcZLYg4yUbFSumxJC9DXNNkJkIl21tJZAxm-ism8dp-80T2_J-fXwI_h6jw_PK2JwZKBl6mKRvrM3VwEdVHYWLb7uII2Khsa-QE0T3EOYAZKASlitKYgD1GEtlq0DNhJ6q6IVEtGnuvTbyOmF_mD-50CcwxoBdy-6m_ue3-YbgYGL6yd0pP5KMiw3BOO1In7Mb8Yg7akJcfjnnqihBgWuDVkr0_usoBZ8mjqYm_zSBsXpGiKIGpV_UVej4o5zMEsnkMe36s02ocvDOWBHQ",
      "e": "AQAB"
    },
    {
      "kty": "EC",
      "kid": "RdEAGU6yqPfkvo6OjXVFeed1wuI",
      "use": "sig",
      "x": "AZuOUs9iispneV185uu2qVslK0pTHaN5sWj4XuwEFJ0qBm_LFSJFXAUy20uasUK4KI6mmezPZZs0ZWsDjcRILMJB",
      "y": "AKDnQNp2KypK6uYe0YIHL-UTJhVxhl9qJNOLFFDy3gcHIzSMvMeexuJpvr-wzOi9gzHTHs-lyRf-7I-l59bjyWKG",
      "crv": "P-521"
    },
    {
      "kty": "EC",
      "kid": "BwvCR6iBoOhSint4SwviYtdL35o",
      "use": "enc",
      "x": "AH_JYF0Kw-g6kbb1m0MB9Vkck-TGiHfrn8_UNWvD_l4VdqGGt1-EhA8nrfolZVsHeNaQM06lRhlyHqyIOaHN-yJy",
      "y": "AIvuF575rqT-3sq_ja97840a-J7P93K3dr92YnJo6c5dl0prPyafIG3BNm9PfuhvcA2spVJw4t4rjtNekgyUeVX3",
      "crv": "P-521"
    },
    {
      "kty": "EC",
      "kid": "EDuQgEuWy4bDB4VEI2WhdqgzKzQ",
      "use": "enc",
      "x": "2hxj_wZFyRXuYxn4RDpnn2eE7VeVSTzsULm_qTkVcua-pv68qfL5eWTu2hsnMgmg",
      "y": "ahx3r1rDzsQNUXnfH6ukWQGdC132E9FuF5py8ZdwAS2YImecC7MrAb4dJeowrX-h",
      "crv": "P-384"
    },
    {
      "kty": "RSA",
      "kid": "oAgFKBn4jaaiisguObdKPSgxBDw",
      "use": "enc",
      "n": "otYWk0hVkhhtCKGNT33RgXENFaZFJXjZ9jSJxyikceMyG3RKPnULtRQ7lKkIGpC8V_OJRl6MPp6wOU8SJZFqvsy2LCECejjUCMSzyJ1IJVJcicZ3E-Ru_vPs9lrT9ey3vgvdAPWxvRykPGPlgj5OMTmPRJx4-IDJ7XRXYREFjskGV7cECLd1AhptYyMyw_anUCKzhANMk_v4QG5q9poSuXPEAAYqnZsVpkoW5fAZAUdSAsrCP8q3Q1hcTUIjeRy-xcuGuMpWtq740ggt19Sz9PkpDg3NSiwZHDIybgyCbXKZkLIU6-Uu1wKhSVdBhTWtwtRgRVo6-GuODg3EFpSqbw",
      "e": "AQAB"
    },
    {
      "kty": "EC",
      "kid": "zcKSoQqEAJ6TCUFIKqmKyh32_cw",
      "use": "enc",
      "x": "czEXTyQiOF2-N8wxBgzcAYSWCZTe048YGAFhQ5qGEKo",
      "y": "ZSDzPSI1Qr4s-D7y0TvFgy6Jc5jEkx-DzY_SK4JOMvk",
      "crv": "P-256"
    }
  ]
}
2021-08-13 15:59:20 SUCCESS
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2021-08-13 15:59:20 SUCCESS
CheckForKeyIdInServerJWKs
All keys contain kids
2021-08-13 15:59:20 SUCCESS
EnsureServerJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2021-08-13 15:59:20 SUCCESS
FAPIEnsureMinimumServerKeyLength
Validated minimum key lengths for server_jwks
server_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "kid": "2CmYYedTMgSg_B2IEBeQc3c_JY0",
      "use": "sig",
      "n": "3bdVMnUR62v8t0UFsyg3lITTNCS6M1qgVimdBHmhHmU_mK4brurPe3v3BDhWvRvCV4ZxLBvvxj3jEQawmz-XviBb6q0ox_PwzrUAb-qP6efmKuAfNKTGzhEqSzkxZMWqACbL_BL4Hw5WmSxaPtRky678AbCzLVBa6E9nfpldgUa0-lukdR-JMF9VyAtlyTuN-0Sc9abGObLCoM0k-b_3DLLvKFlUmBc7G2M0bCYA_2L92nmDDAMLaPMUeyHoUrNR5f5divBt0SrRpPuvNp5gMlhSdea4oacurnjSbjI0OIY9yjihmVNCnyRTojJGU8zHuTcbTn_xQA_6gE3Xi45Gww",
      "e": "AQAB"
    },
    {
      "kty": "EC",
      "kid": "8xsYE4Tn3xDqzfp84Bvy2EjAfnA",
      "use": "sig",
      "x": "1cnxOz2zPjxTNl87EP0natwkjsY21sZtTrVjFCwSlKqBZP_9-vAF71pd5d0C_AVg",
      "y": "dTMtn07V5Bxhg_lct0FOgNmP2MumHxd4DvCQ5z-11ISEkZzm4R0nw3-SpKz1z4jp",
      "crv": "P-384"
    },
    {
      "kty": "EC",
      "kid": "LT5rdwU8SbVJar_J7x6zw42TZm4",
      "use": "sig",
      "x": "AbZvDXykFQorO0FKXZT6ch123qOw_P2hdDLT8EGu7fmEzy2KwiXKgxD3ToTwBXQh1xVIDASTVyk8ULifcPyCrzVg",
      "y": "AfS_WYn_POzpZaZ7CK4-NXdCKoIdSjRpLidr1gPulIs0CjU04cGB6lzY_M2z9P9fDlwdxMJsB7WzzqFYLhyD-hxG",
      "crv": "P-521"
    },
    {
      "kty": "EC",
      "kid": "OWOHC2Lhg2V9Z2OP3AeTnsIqfcU",
      "use": "sig",
      "x": "RUEyPQeEHjIR6E6Js6MGzZnrzBKkoyLP0dZve4ZdThk",
      "y": "Q_sV8s67YTUp1IkK5DrD2Od2JW7wKkOm334yX5m4xJY",
      "crv": "P-256"
    },
    {
      "kty": "EC",
      "kid": "Jvt8Q_a_g_tybc1my9tocjX-c4A",
      "use": "sig",
      "x": "F4vJqpd243lWKo7uDKSrggXwuDYAOSXHcBfDBfYOYt0",
      "y": "QAMHyzLnQRKrUqF8ycAFrQ3Cg9Its3xOQ_r9PO0X5GY",
      "crv": "P-256"
    },
    {
      "kty": "EC",
      "kid": "K1pu5hRTBR4Z_L9DabJ6z8UYNC8",
      "use": "sig",
      "x": "Pf9yQal5uYkLe37xaybqwmQEkYPcwW-6Eg6-jiXU2mJi4RY_DU2A7ghHpiUjX56i",
      "y": "S6KXvLguETXRx8suIvV05i8p29cpCW9W_tgsaBKT6qI62parFenA2VSvhf_8U8FO",
      "crv": "P-384"
    },
    {
      "kty": "RSA",
      "kid": "NfGZj3wtxSjC-G5ZOsy0GIrGqwU",
      "use": "sig",
      "n": "kL1Bq2Eo1i1qLrwK6XLmCyFf3WNbKqTJfilwntH-Voy_qgprhprcv8BpQtD8SdkAvrpeLcZLYg4yUbFSumxJC9DXNNkJkIl21tJZAxm-ism8dp-80T2_J-fXwI_h6jw_PK2JwZKBl6mKRvrM3VwEdVHYWLb7uII2Khsa-QE0T3EOYAZKASlitKYgD1GEtlq0DNhJ6q6IVEtGnuvTbyOmF_mD-50CcwxoBdy-6m_ue3-YbgYGL6yd0pP5KMiw3BOO1In7Mb8Yg7akJcfjnnqihBgWuDVkr0_usoBZ8mjqYm_zSBsXpGiKIGpV_UVej4o5zMEsnkMe36s02ocvDOWBHQ",
      "e": "AQAB"
    },
    {
      "kty": "EC",
      "kid": "RdEAGU6yqPfkvo6OjXVFeed1wuI",
      "use": "sig",
      "x": "AZuOUs9iispneV185uu2qVslK0pTHaN5sWj4XuwEFJ0qBm_LFSJFXAUy20uasUK4KI6mmezPZZs0ZWsDjcRILMJB",
      "y": "AKDnQNp2KypK6uYe0YIHL-UTJhVxhl9qJNOLFFDy3gcHIzSMvMeexuJpvr-wzOi9gzHTHs-lyRf-7I-l59bjyWKG",
      "crv": "P-521"
    },
    {
      "kty": "EC",
      "kid": "BwvCR6iBoOhSint4SwviYtdL35o",
      "use": "enc",
      "x": "AH_JYF0Kw-g6kbb1m0MB9Vkck-TGiHfrn8_UNWvD_l4VdqGGt1-EhA8nrfolZVsHeNaQM06lRhlyHqyIOaHN-yJy",
      "y": "AIvuF575rqT-3sq_ja97840a-J7P93K3dr92YnJo6c5dl0prPyafIG3BNm9PfuhvcA2spVJw4t4rjtNekgyUeVX3",
      "crv": "P-521"
    },
    {
      "kty": "EC",
      "kid": "EDuQgEuWy4bDB4VEI2WhdqgzKzQ",
      "use": "enc",
      "x": "2hxj_wZFyRXuYxn4RDpnn2eE7VeVSTzsULm_qTkVcua-pv68qfL5eWTu2hsnMgmg",
      "y": "ahx3r1rDzsQNUXnfH6ukWQGdC132E9FuF5py8ZdwAS2YImecC7MrAb4dJeowrX-h",
      "crv": "P-384"
    },
    {
      "kty": "RSA",
      "kid": "oAgFKBn4jaaiisguObdKPSgxBDw",
      "use": "enc",
      "n": "otYWk0hVkhhtCKGNT33RgXENFaZFJXjZ9jSJxyikceMyG3RKPnULtRQ7lKkIGpC8V_OJRl6MPp6wOU8SJZFqvsy2LCECejjUCMSzyJ1IJVJcicZ3E-Ru_vPs9lrT9ey3vgvdAPWxvRykPGPlgj5OMTmPRJx4-IDJ7XRXYREFjskGV7cECLd1AhptYyMyw_anUCKzhANMk_v4QG5q9poSuXPEAAYqnZsVpkoW5fAZAUdSAsrCP8q3Q1hcTUIjeRy-xcuGuMpWtq740ggt19Sz9PkpDg3NSiwZHDIybgyCbXKZkLIU6-Uu1wKhSVdBhTWtwtRgRVo6-GuODg3EFpSqbw",
      "e": "AQAB"
    },
    {
      "kty": "EC",
      "kid": "zcKSoQqEAJ6TCUFIKqmKyh32_cw",
      "use": "enc",
      "x": "czEXTyQiOF2-N8wxBgzcAYSWCZTe048YGAFhQ5qGEKo",
      "y": "ZSDzPSI1Qr4s-D7y0TvFgy6Jc5jEkx-DzY_SK4JOMvk",
      "crv": "P-256"
    }
  ]
}
2021-08-13 15:59:20 SUCCESS
GetStaticClientConfiguration
Found a static client object
client_id
fapi_adv_op_w_private_key_par_first_client
scope
openid payments
jwks
{
  "keys": [
    {
      "p": "7Iiv4eby1Ubo_U9uzWEa8OlUQoBz4vjPtB7MWQ6dlM7ajD9IjhjwwE8e1d_fE22DW4bEjHb1ls6_wbEm07PusUuMyHtWzW1sNWnpCh0xgDsEnLZwmtdXhPDHJlbRXHXAqcTVTUIJNMUSa8Mj9MXs33u1mkMD-hYWJfDHNCrDUAc",
      "kty": "RSA",
      "q": "msxkZpdafUHdoC-S5QrAHZ8z0NrQNFjn2yFcpznZ0zjXK83QH-jbBHCcTDBkF7xpatG61SbEznYxYaDEFR4xzuyy0WOYtoIk5IukygdvZhMkAXDNl5rNvF770Fnv8gwpoxZqlpb18kWtP2gk-ebJK2YHKjhl-pHDOrbzubkRdOE",
      "d": "AXvpT93_Y-hQYTCk95gHj6BinFTppIaTZhgJWvnDY-Bz1NhUZ7fz-RjePxQBEuRv3DUk6nEmT8CivxJKZdql9AR9UjHz_ANOH6mAwHxkE2bcEKEsJFGTkaDJhVqmwukYwfKfGpkeNuD2r5rhNdl3XNUQ6VdTkUokmZM3KNrLhks3NtPL3xEMqK5KAYJbJuS8AQoOI5scRTJZYcS63KK9WwBoOFwbz3PFHJb2lffTOH_tnqgSvm9chb7y1CaarSJuFSVTjkjMyk2rBOr4bu5YRtxzH1dAa3Dd5n9XzVwN_q0dIitTh7Vro2JcSU24O1n-XR4WGzCCiarMxPKc8SWyAQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "pingfederate-fapi-jwt-assertion-client1",
      "qi": "De5E3i5KIQ88R7jYZDWEsVonhPPGcWksWXC-s4frJ0tISk5-zlCdP6eitstJTaB1i7bkCW4R7iXufgXqW2WCRK2IXXjwItZo1zEpuAZJnKFwDPxXt5pLoc_sDjarMRENxdx_spyiFIxejLvvDmKGxs7vt3LDm_ytvJXfsymzjqM",
      "dp": "z80l9-jV3dl2R1TJm1V8Pbo_dE01gmnkz_Fexb65Ykp4Zk4SiAQRPmJETNFpQcAsbvRvKJg6Gkt428muur6RLOGaxWbWU5OWRTbOrTwIiQdQff0p4F7fXMPLsjsDo58vq_ZpDn69Z8ba8CF4LUrVV2Fvoh7OF5_fxWVLHOGUxXE",
      "alg": "PS256",
      "dq": "JRS_HEA3YffsMhoTUyB_ItlnHSm9ZDzD1Z8pRbm67zkXehvENlCeXnLnTeztnS36BqeU3Mh7roVrkNpk_jYMcmgK8dOs2lNUqRa2c9rSGZ6OKnYuGZnwnKYYJjHVI6M8Oh_9inNBGTcNqDm3WdGp8OZw4vE9pIdUP_VhbuThRKE",
      "n": "jwcTfjv0q48qux1sg2MR8OvCh1mXITYu7zkEJVCz0UImIrIqLtEzmGkqJP0LobK6-NlFHWOsAp2NcVTh79RBwawsrmi59rJ_nHigX00C7wjVpJtldJmOwmSS4HD8EgRkiM0yJzyKijtRiB5ssrOoBK3VPFMqZYm_JBJY35s_qDDHWTlwuWDLqADZp809btMcwQZCqgrSKgtalspeKXIh6Lv3lkFnELJhfwGZYPtVc2SJk91F8tmgamPNJUfVJV3ygdBuDcB8EZ8m-tIaISghfR1RRkEeYI8r_Wf4dfjIAZRkrj8GHqAJOi762rjyFvXvcPc0Zc-ABDYnVi4WdWOCJw"
    }
  ]
}
2021-08-13 15:59:20
ValidateMTLSCertificatesHeader
No certificate authority found for MTLS
2021-08-13 15:59:20 SUCCESS
ValidateMTLSCertificatesHeader
MTLS certificates header is valid
2021-08-13 15:59:20
ExtractMTLSCertificatesFromConfiguration
No certificate authority found for MTLS
2021-08-13 15:59:20 SUCCESS
ExtractMTLSCertificatesFromConfiguration
Mutual TLS authentication credentials loaded
cert
MIID3TCCAsWgAwIBAgIUIi7yAbDDmWkZjI8CwjLBVkswVkIwDQYJKoZIhvcNAQELBQAwfTELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAkNPMQ8wDQYDVQQHDAZEZW52ZXIxFTATBgNVBAoMDFBpbmdJZGVudGl0eTEUMBIGA1UECwwLRGV2ZWxvcG1lbnQxIzAhBgNVBAMMGkZBUEkgQWR2IE9QIHcgRmlyc3QgQ2xpZW50MCAXDTIxMDcyNjIyMzQzN1oYDzIxMjEwNzAyMjIzNDM3WjB9MQswCQYDVQQGEwJVUzELMAkGA1UECAwCQ08xDzANBgNVBAcMBkRlbnZlcjEVMBMGA1UECgwMUGluZ0lkZW50aXR5MRQwEgYDVQQLDAtEZXZlbG9wbWVudDEjMCEGA1UEAwwaRkFQSSBBZHYgT1AgdyBGaXJzdCBDbGllbnQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCa91hiBBEaNcRdvQ0Gvg06mzaIQpa17vgtP77HwtV0FvH+3imrnqmaCcpEnWGMv/udX8S5r/VAeUPB2Q31187vKDLKxbadWTKuSNQajOkRyiXZzutbEQbN/t7JAz7oETujYoOTlMNT4N9twYvKEvxTeZAWNUCQHXZcESKYXhph0eZaaOvNo7WqQ+ygGBzgTVev6tXr/Q2+M3NkBnSvRYegSN5ZtmIXMrNVaH7D+SC8QUPWxsB8ZVIENzBhCI8+brrPjyLNqVKoI9O7Hjdgzb8Xs+gC98ATmsbQrE/8pRdYYCPkEoETAWRq2T/dEf7NE+AMerttKk9TdNwvbB1WbAoHAgMBAAGjUzBRMB0GA1UdDgQWBBTr8p3YWM2Rtw/BAQaellNa1RUKSTAfBgNVHSMEGDAWgBTr8p3YWM2Rtw/BAQaellNa1RUKSTAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQB17ygVKcEpZxP4XML98KyUycNxsyHcKdIo2GZCRsmwjDR5nRcdWlE+tI50sduSaAR+gSbDFR/dqBxl0lBEMLj6Rqpson+z17jv68fU9H7l7JLfI5xAXuW4s1Kg/xBcYBy7QJkU9CTMIb6TBQESCbTUq89aCX4fT8WQleCflRJjSuzzdpVWd0PIhcxCoxpa/BcXtK0gf/z0rimF4jJKv40rqdf0LGsVzKQ9TxQIDWk0tov4FkvBw63VUp6b7PWdEHi4E9uKgHxh2Pj+VykK33nCmUsGXENfj4SSkY2O00iDw3oHfC8xmWvgqsTdlzJm1qhZCZGNOsdWLEv6hGl4XLyr
key
MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQCa91hiBBEaNcRdvQ0Gvg06mzaIQpa17vgtP77HwtV0FvH+3imrnqmaCcpEnWGMv/udX8S5r/VAeUPB2Q31187vKDLKxbadWTKuSNQajOkRyiXZzutbEQbN/t7JAz7oETujYoOTlMNT4N9twYvKEvxTeZAWNUCQHXZcESKYXhph0eZaaOvNo7WqQ+ygGBzgTVev6tXr/Q2+M3NkBnSvRYegSN5ZtmIXMrNVaH7D+SC8QUPWxsB8ZVIENzBhCI8+brrPjyLNqVKoI9O7Hjdgzb8Xs+gC98ATmsbQrE/8pRdYYCPkEoETAWRq2T/dEf7NE+AMerttKk9TdNwvbB1WbAoHAgMBAAECggEAf4aFKUQHfvY4PpvRGHdWE6CfY8rIk7ewbCxFJ8biOcKYKxFQYXcUQztDROvu1xE2Uu/4yIZQ4VnptKCWqHWMSatfARdrjFlXJ62vPpovQwCD3ZY2gJ6mZucTF4CgSAHGflIXzV9izqgDtiLMkuLE2zzyohP4qaBVQranLZRjSZNWeGvEpkcf7Nv7FlfZaOJ/FkcGwyFn7iSzX/KRL/1TA6zDlreA3PGJr96i9SmFHQsurFv7quRxEUFoSVxVtn5IiOJji45Evte8KAhMzlau1MuAlKxiIJAMIPN2l1nTRTRZUybDBoLp9CkkAmvp75krld9NB/hbWaeRsxhgVPXYwQKBgQDMsai5QHJAFZ5P31LN0dvlvcj0X2dPS0hEd6NsIf5DkbQKHQuVlxdIGhChLhVBdkGUt9ZYSflxlUtc8GUG3+e0TKg+ZAHNakueV73TGZy3BAzQBxwQBMqUltcXWMjWBaDnbQH+TrtYP0A+ZdHd4gnBNuSUuv5R7IxGWHgfcvtnuQKBgQDBzt2kGjDXXPV4qrtmGl4KaCAvsFr76VsVr8879MhrVgevI5vbsBNWQ3yvykXLr5B6s0VaqibvgDTcchQvqwtoEeDQfHsSHnAglGYCAi06hwGArTW/hxW0L7IivB+laFsbPY2HbnGZ6WUOjMNTgGAihbbLd6+IvLJEVdn7gjxfvwKBgD/DS9rBP5XE5jbdS08AA27yiqnNGkJyIgXp+sdRY4Iq3hmUaKplkYQNUobS8x4cN1ubVLLWAFUoe3xtCht1HhllE7ezsXgKl5mwnVooDVBZe6BFxrEavPxCbKhCKPW6dSACLe/JGMTplxqY3yIuKnm8nsHR6i0c8alsH6c0SypJAoGBALcVCn+5ViY8ZI9nCby8b9X4417phCmxGiB0gpoq9SGglYW3Z8ayoLG+8wzFUgXGhf/DVmL9leZuAIG3KqaVOCNJsEyDK2fEZTwBtBN1pvBBFQRPnBSgMbqTy/3QJT0GRfqHvSkRBjPVLWf/RY2eGjLCihnPqHzNdMHlMBTNxObVAoGAMRDZNtM0vIUNbjY5YFK0AoetPqR1mS2fWOFdCVnyHYBOJmmUZbU4oNZk5HmHBOC8N7aOELyXu56I4yEw0KUjOphKGfA9b2553q1A6t1x1oHBIwVuj1W3sEpUOtj2fWwmmdqjEyRsdzEJWfOuOEFzbfaw1pClq9IbngVcDGfzg74=
2021-08-13 15:59:20 SUCCESS
ValidateClientJWKsPrivatePart
Valid client JWKs: keys are valid JSON, contain the required fields, the private/public exponents match and are correctly encoded using unpadded base64url
2021-08-13 15:59:20 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "p": "7Iiv4eby1Ubo_U9uzWEa8OlUQoBz4vjPtB7MWQ6dlM7ajD9IjhjwwE8e1d_fE22DW4bEjHb1ls6_wbEm07PusUuMyHtWzW1sNWnpCh0xgDsEnLZwmtdXhPDHJlbRXHXAqcTVTUIJNMUSa8Mj9MXs33u1mkMD-hYWJfDHNCrDUAc",
      "kty": "RSA",
      "q": "msxkZpdafUHdoC-S5QrAHZ8z0NrQNFjn2yFcpznZ0zjXK83QH-jbBHCcTDBkF7xpatG61SbEznYxYaDEFR4xzuyy0WOYtoIk5IukygdvZhMkAXDNl5rNvF770Fnv8gwpoxZqlpb18kWtP2gk-ebJK2YHKjhl-pHDOrbzubkRdOE",
      "d": "AXvpT93_Y-hQYTCk95gHj6BinFTppIaTZhgJWvnDY-Bz1NhUZ7fz-RjePxQBEuRv3DUk6nEmT8CivxJKZdql9AR9UjHz_ANOH6mAwHxkE2bcEKEsJFGTkaDJhVqmwukYwfKfGpkeNuD2r5rhNdl3XNUQ6VdTkUokmZM3KNrLhks3NtPL3xEMqK5KAYJbJuS8AQoOI5scRTJZYcS63KK9WwBoOFwbz3PFHJb2lffTOH_tnqgSvm9chb7y1CaarSJuFSVTjkjMyk2rBOr4bu5YRtxzH1dAa3Dd5n9XzVwN_q0dIitTh7Vro2JcSU24O1n-XR4WGzCCiarMxPKc8SWyAQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "pingfederate-fapi-jwt-assertion-client1",
      "qi": "De5E3i5KIQ88R7jYZDWEsVonhPPGcWksWXC-s4frJ0tISk5-zlCdP6eitstJTaB1i7bkCW4R7iXufgXqW2WCRK2IXXjwItZo1zEpuAZJnKFwDPxXt5pLoc_sDjarMRENxdx_spyiFIxejLvvDmKGxs7vt3LDm_ytvJXfsymzjqM",
      "dp": "z80l9-jV3dl2R1TJm1V8Pbo_dE01gmnkz_Fexb65Ykp4Zk4SiAQRPmJETNFpQcAsbvRvKJg6Gkt428muur6RLOGaxWbWU5OWRTbOrTwIiQdQff0p4F7fXMPLsjsDo58vq_ZpDn69Z8ba8CF4LUrVV2Fvoh7OF5_fxWVLHOGUxXE",
      "alg": "PS256",
      "dq": "JRS_HEA3YffsMhoTUyB_ItlnHSm9ZDzD1Z8pRbm67zkXehvENlCeXnLnTeztnS36BqeU3Mh7roVrkNpk_jYMcmgK8dOs2lNUqRa2c9rSGZ6OKnYuGZnwnKYYJjHVI6M8Oh_9inNBGTcNqDm3WdGp8OZw4vE9pIdUP_VhbuThRKE",
      "n": "jwcTfjv0q48qux1sg2MR8OvCh1mXITYu7zkEJVCz0UImIrIqLtEzmGkqJP0LobK6-NlFHWOsAp2NcVTh79RBwawsrmi59rJ_nHigX00C7wjVpJtldJmOwmSS4HD8EgRkiM0yJzyKijtRiB5ssrOoBK3VPFMqZYm_JBJY35s_qDDHWTlwuWDLqADZp809btMcwQZCqgrSKgtalspeKXIh6Lv3lkFnELJhfwGZYPtVc2SJk91F8tmgamPNJUfVJV3ygdBuDcB8EZ8m-tIaISghfR1RRkEeYI8r_Wf4dfjIAZRkrj8GHqAJOi762rjyFvXvcPc0Zc-ABDYnVi4WdWOCJw"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "pingfederate-fapi-jwt-assertion-client1",
      "alg": "PS256",
      "n": "jwcTfjv0q48qux1sg2MR8OvCh1mXITYu7zkEJVCz0UImIrIqLtEzmGkqJP0LobK6-NlFHWOsAp2NcVTh79RBwawsrmi59rJ_nHigX00C7wjVpJtldJmOwmSS4HD8EgRkiM0yJzyKijtRiB5ssrOoBK3VPFMqZYm_JBJY35s_qDDHWTlwuWDLqADZp809btMcwQZCqgrSKgtalspeKXIh6Lv3lkFnELJhfwGZYPtVc2SJk91F8tmgamPNJUfVJV3ygdBuDcB8EZ8m-tIaISghfR1RRkEeYI8r_Wf4dfjIAZRkrj8GHqAJOi762rjyFvXvcPc0Zc-ABDYnVi4WdWOCJw"
    }
  ]
}
2021-08-13 15:59:20 SUCCESS
CheckForKeyIdInClientJWKs
All keys contain kids
2021-08-13 15:59:20 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2021-08-13 15:59:20 SUCCESS
FAPICheckKeyAlgInClientJWKs
Keys in client JWKS all have permitted 'alg'
permitted
[
  "ES256",
  "PS256"
]
2021-08-13 15:59:20 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "p": "7Iiv4eby1Ubo_U9uzWEa8OlUQoBz4vjPtB7MWQ6dlM7ajD9IjhjwwE8e1d_fE22DW4bEjHb1ls6_wbEm07PusUuMyHtWzW1sNWnpCh0xgDsEnLZwmtdXhPDHJlbRXHXAqcTVTUIJNMUSa8Mj9MXs33u1mkMD-hYWJfDHNCrDUAc",
      "kty": "RSA",
      "q": "msxkZpdafUHdoC-S5QrAHZ8z0NrQNFjn2yFcpznZ0zjXK83QH-jbBHCcTDBkF7xpatG61SbEznYxYaDEFR4xzuyy0WOYtoIk5IukygdvZhMkAXDNl5rNvF770Fnv8gwpoxZqlpb18kWtP2gk-ebJK2YHKjhl-pHDOrbzubkRdOE",
      "d": "AXvpT93_Y-hQYTCk95gHj6BinFTppIaTZhgJWvnDY-Bz1NhUZ7fz-RjePxQBEuRv3DUk6nEmT8CivxJKZdql9AR9UjHz_ANOH6mAwHxkE2bcEKEsJFGTkaDJhVqmwukYwfKfGpkeNuD2r5rhNdl3XNUQ6VdTkUokmZM3KNrLhks3NtPL3xEMqK5KAYJbJuS8AQoOI5scRTJZYcS63KK9WwBoOFwbz3PFHJb2lffTOH_tnqgSvm9chb7y1CaarSJuFSVTjkjMyk2rBOr4bu5YRtxzH1dAa3Dd5n9XzVwN_q0dIitTh7Vro2JcSU24O1n-XR4WGzCCiarMxPKc8SWyAQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "pingfederate-fapi-jwt-assertion-client1",
      "qi": "De5E3i5KIQ88R7jYZDWEsVonhPPGcWksWXC-s4frJ0tISk5-zlCdP6eitstJTaB1i7bkCW4R7iXufgXqW2WCRK2IXXjwItZo1zEpuAZJnKFwDPxXt5pLoc_sDjarMRENxdx_spyiFIxejLvvDmKGxs7vt3LDm_ytvJXfsymzjqM",
      "dp": "z80l9-jV3dl2R1TJm1V8Pbo_dE01gmnkz_Fexb65Ykp4Zk4SiAQRPmJETNFpQcAsbvRvKJg6Gkt428muur6RLOGaxWbWU5OWRTbOrTwIiQdQff0p4F7fXMPLsjsDo58vq_ZpDn69Z8ba8CF4LUrVV2Fvoh7OF5_fxWVLHOGUxXE",
      "alg": "PS256",
      "dq": "JRS_HEA3YffsMhoTUyB_ItlnHSm9ZDzD1Z8pRbm67zkXehvENlCeXnLnTeztnS36BqeU3Mh7roVrkNpk_jYMcmgK8dOs2lNUqRa2c9rSGZ6OKnYuGZnwnKYYJjHVI6M8Oh_9inNBGTcNqDm3WdGp8OZw4vE9pIdUP_VhbuThRKE",
      "n": "jwcTfjv0q48qux1sg2MR8OvCh1mXITYu7zkEJVCz0UImIrIqLtEzmGkqJP0LobK6-NlFHWOsAp2NcVTh79RBwawsrmi59rJ_nHigX00C7wjVpJtldJmOwmSS4HD8EgRkiM0yJzyKijtRiB5ssrOoBK3VPFMqZYm_JBJY35s_qDDHWTlwuWDLqADZp809btMcwQZCqgrSKgtalspeKXIh6Lv3lkFnELJhfwGZYPtVc2SJk91F8tmgamPNJUfVJV3ygdBuDcB8EZ8m-tIaISghfR1RRkEeYI8r_Wf4dfjIAZRkrj8GHqAJOi762rjyFvXvcPc0Zc-ABDYnVi4WdWOCJw"
    }
  ]
}
2021-08-13 15:59:20 SUCCESS
ValidateMTLSCertificatesAsX509
Mutual TLS authentication cert validated as X.509
Verify configuration of second client
2021-08-13 15:59:20 SUCCESS
GetStaticClient2Configuration
Found a static second client object
client_id
fapi_adv_op_w_private_key_par_second_client
scope
openid payments
jwks
{
  "keys": [
    {
      "p": "43lqQE0EN1LJ_jdqHq56hNFjErKfcrwJnVpIVRsXCZWboV4MSfLzGGEyePPs6SxV6-l_txQY-M2dW6xLaedRUlaFT89r10cIm136ecYUzs51iX_GZW_AvohaXSmAbZKpjLmsHIDelgggQKjDQxGGbmAAQojnqzorpVrfz-8aUNc",
      "kty": "RSA",
      "q": "q1t1ErKAx06nV7ohJ4zlo3xUeMA3rO7HLmK6Eh460DsiX80AsCxyw1AsQy0N1W8u_RgkA3y_p_5Nf7K1KLLa9mduIBWyUFEim1EneviM4m3q7e2UtQ7iezh6FatYFZD5c_v_CH2gV0bhxZrMzNc8ubL46OXo5h1WycY1iAqsjNs",
      "d": "ElS590xAIy7zN4KHKmq2rLnAg1TJ9kODaUrb98X3gCGuTOLBAtFzUqjPyBF8rqXAtkgl8inec6GwY6gmB9p53quJfKSunnN7CbU3Qe37f8HBgS95vFsmJtbctbJ43XKlwo0imYbIeBYLmxKUJt5BKSnUYWWv4EI2AVE_LrqecL-QaNLH2IxY1JVLvR8WhP7wzjTHIsGjaQGn7199eVBaHZ7KTC-bFaEWnPgklR0e8t8TdICUqJudCqTEuoEBFYXRdqi_3betdNZHtJdcwfk9VEXTYTnjzw0fJ7RoFyVE1_1-wMULnEYk5SyfSYfYsBq_V25e-TUSLxB3IXgzBmJVOQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "pingfederate-fapi-jwt-assertion-client2",
      "qi": "rBDWPBNof1ZrvpqRqpPIf-hn6jmOmLN5mzv8ArwfYEuoIPo9Ltzta1m42A6KQAAsHfXUaKtihSXnVopYtYcxguVNCi2qbDh4nx7ZZNCcQsKSkUOw-hgm4vHZJMOJ-4jh6jthUeLTRmCpEZAHQrtmnpQ1tC1g3g2VCDH48p8cLzo",
      "dp": "BrSxmSusECV0pvXjPvxNyFST4x047hz0-5qJv1iJGVM7v0oSequa1wEmh8JJHaac8dN0XGVPRyZomSc_IeQb1Z2PWIb42uPRMSNYGvbn7iDP_jmyE5Nzzyod39k1XAWS0f83P6_c3_dlXAKdnwCJQf-6gjue-MFCQCGpr2uRDwk",
      "alg": "PS256",
      "dq": "GyE3v-YTDXsec308ko50LRYaKaQFLJQBZQ6sdwHiPeWe45wJZ9shsFqZJ2mSryATSG7yBLtTfL1-d6FLnU3z7N8jSGEnAiBWYlDO92EyrQbKEzFyQdhBc1DVw2iFYaS6WeqjzixVnnvScv63Phc1vhDf57--x_ANNZT0FL3b49E",
      "n": "mENeKNMC5ttp60qEq6LZoWaihn-__Ei70wnW8Zd_-ILFnYcaM90oTTnl8R2uHD4EJ3t_VCjFteXIwWV7OwDmRmOMwda0X1R5IKYn0O2ujT8NI4citj8G4NHY0r5Y5loLdb5dynGgT-YpsnWwfTC8Ky98gNA3OLf6Z2n8PEdKJr818RMAC0Vx6NQMHBNG4jI1D0bvbrZbx0XkXan7h2Elm9HLRjzHar5Qb5gFLGQRFdeHVHF5lRKyAFgdeQPvBqMiRsAwcgyKxDjbzF5qHPwhKMB-7IVhxuSULMvgSkesIIhrylzU9bo2KRhcxTB7oPkhAbPgumpoVZV0ME-ypiy77Q"
    }
  ]
}
2021-08-13 15:59:20
ValidateMTLSCertificates2Header
No certificate authority found for MTLS
2021-08-13 15:59:20 SUCCESS
ValidateMTLSCertificates2Header
MTLS certificates header is valid
2021-08-13 15:59:20
ExtractMTLSCertificates2FromConfiguration
No certificate authority found for MTLS
2021-08-13 15:59:20 SUCCESS
ExtractMTLSCertificates2FromConfiguration
Mutual TLS authentication credentials loaded
cert
MIID3zCCAsegAwIBAgIUUbO7wc+DFfteEqK0M1D+iRwKDOkwDQYJKoZIhvcNAQELBQAwfjELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAkNPMQ8wDQYDVQQHDAZEZW52ZXIxFTATBgNVBAoMDFBpbmdJZGVudGl0eTEUMBIGA1UECwwLRGV2ZWxvcG1lbnQxJDAiBgNVBAMMG0ZBUEkgQWR2IE9QIHcgU2Vjb25kIENsaWVudDAgFw0yMTA3MjYyMjM0NDFaGA8yMTIxMDcwMjIyMzQ0MVowfjELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAkNPMQ8wDQYDVQQHDAZEZW52ZXIxFTATBgNVBAoMDFBpbmdJZGVudGl0eTEUMBIGA1UECwwLRGV2ZWxvcG1lbnQxJDAiBgNVBAMMG0ZBUEkgQWR2IE9QIHcgU2Vjb25kIENsaWVudDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALASMA/8vTQ+vFqsR7UBSG5cldHwJ5SGvoHpGqhdv6xSXHUi8bp0Ob927l93bdkk1YnWqYQbmtmwlfqRFyxXYAvNXoIrFY86gBOg4O9vkCeVSMK1l7CdSps3ypXR4p7Fy1eERIN4fTwUS5wRu0bpcG4kocShcoxYu5A30s8k6onYVafO0ZfrbKEfnEJY74f8A3v8ns2Nr5AasPqZsz3g5TiyVygRG6+D6yrhORvW33roDEYnrwompE6UUkjVXNhoBoXvohLhf3Zh7kEpVQjXjD/rMlj5NFSFXLW4RXDokruapCyY3Q66OoAO5SYBpKtfxHiAp28ooUSmmwpxd39voaUCAwEAAaNTMFEwHQYDVR0OBBYEFFGFWe386uahXiBMwViRnP9t210BMB8GA1UdIwQYMBaAFFGFWe386uahXiBMwViRnP9t210BMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAJ346s52BzNNZU9Sc6qUnG68yjZxCadEgijudr5hILhkLYsLy6HOdnirsakqdc/KhbRQPm+TbuUT94bahigOM1QuCGa8XjewTdmXGDdRxFTHNMLc+SopCuInXeNlBO8tekbWSglGaP742240gERzXHaGyqrSzXeL2yosY2evtqbMB9i+d8uMhTYniwP3Isbbld2lCCF/Cw7flVzXnWItU0pGVj8U9qIW874eMDss+dxq6WfwaVzyXqH7k59xI/37zxWdRa1zNIwyi8H1dkl0vsoJSrrIGPCJpq+snT+6+xrUbrRn4H+K0eQSLE+LmmxuOaE4WgdK4ln9ZUXQC90R1aM=
key
MIIEwAIBADANBgkqhkiG9w0BAQEFAASCBKowggSmAgEAAoIBAQCwEjAP/L00PrxarEe1AUhuXJXR8CeUhr6B6RqoXb+sUlx1IvG6dDm/du5fd23ZJNWJ1qmEG5rZsJX6kRcsV2ALzV6CKxWPOoAToODvb5AnlUjCtZewnUqbN8qV0eKexctXhESDeH08FEucEbtG6XBuJKHEoXKMWLuQN9LPJOqJ2FWnztGX62yhH5xCWO+H/AN7/J7Nja+QGrD6mbM94OU4slcoERuvg+sq4Tkb1t966AxGJ68KJqROlFJI1VzYaAaF76IS4X92Ye5BKVUI14w/6zJY+TRUhVy1uEVw6JK7mqQsmN0OujqADuUmAaSrX8R4gKdvKKFEppsKcXd/b6GlAgMBAAECggEBAIxtlSPLImR+/N8ctPxqj4hmE6AjeI3/ggY/EuHiE7Ou5MsQGdfqRvysMKa3rEcaF64eJYmWMsUZECWOfvsAnTwMiiorjsBzmh8Nmxmc006exC93ggp9CToPH2aqxaJ4gxvEBJkPCmNWlI9fnQyLtv5B/TvEwIWrZ704qMxJ1z4klxZgPvRAa5lCRIs1BAwkvtgkc9S2nTzJqO7tfHpXk1tCMxkHyqMlfpBfWxgysPQBueju/IFXw3IoO80uOCZYnHagMmZeSdomlCQmX+5UjanVt4TFFppIQxKXjrkJ0Q0XcnboNs+VsKZgvFdVAKFXHZY5BtaQaC8U8vPKDH2SSikCgYEA5z6fgw7T9etmkqsmc+cAt6LH/NspMOH92Ot7IPgjZIiODx1AIPIQXM6/DzJuntyYtMk+ZJ06q/h7C8ZkdAQX1z3M6maD2y8vVVIMh1yjd2el7CvAc3fejEbliKKK2R9RSGB8udNcGVyNbsjTTLJb2mx89JFI2yGA0gXyVTbT7CsCgYEAwuuBMF0THYZ4kNi62MvF/EblkKwKY1+v6XFdOZiyQljClNdT8bRFxjkdnIxaXemm6X5MPtsKBKY+0ix3uHKXdglzycCth/KuhqmItT1gitPEjq3Ut5Q9liWPpKNhuJjdlUi97Yj7r4NRBWeCLAUBh4n1lpl3rPxIvBMJqFgIMW8CgYEAinFPhmMmOyDHtB+LUfCG2Wo3WQbMzls+YtP4T3C/n7yxcBMPBapmaWnNsQd8etePBQ1GsW4AZlzJLe+EzIB21YJGYD8nyd2h9O6+WXv40c/X4mD/QyIMtubrHLZTclHxk+dQROBpTzW95wmMl2pg24//71vbxnV0bkjpIGNG1SkCgYEAkvnTsy0rgcLo3Ief9GNLCdxHs9wWBTKcyZDis9Bw8dhN+L+ZG5NMXZipvGaUqWXKpxvF0EuH9VOJ4R8Iszss/CNKfOHdt7oFYaMqY0dBqcze1Js836RXAAWYl5Ne1zvlMXDlTdxRs9l32XRgUmL/8TzUw1c7R2QAUFimmpquqt8CgYEAjtIr2L2llacZi7vBfFwgvjVVg7vuAvGpRokC4m6OzfjcO7fPVJa9f8IZLSQU6E2VM//dbuAHbPC2iIGnQn848cwF2rhXrY0VvqfpTuxQCdiW+TGwukLxW0AHWeiD5YauGqtz4+ZC6DWGyFZQSPB0OxcyG9wu0OBKbG70lP6scQE=
2021-08-13 15:59:20 SUCCESS
ValidateClientJWKsPrivatePart
Valid client JWKs: keys are valid JSON, contain the required fields, the private/public exponents match and are correctly encoded using unpadded base64url
2021-08-13 15:59:20 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "p": "43lqQE0EN1LJ_jdqHq56hNFjErKfcrwJnVpIVRsXCZWboV4MSfLzGGEyePPs6SxV6-l_txQY-M2dW6xLaedRUlaFT89r10cIm136ecYUzs51iX_GZW_AvohaXSmAbZKpjLmsHIDelgggQKjDQxGGbmAAQojnqzorpVrfz-8aUNc",
      "kty": "RSA",
      "q": "q1t1ErKAx06nV7ohJ4zlo3xUeMA3rO7HLmK6Eh460DsiX80AsCxyw1AsQy0N1W8u_RgkA3y_p_5Nf7K1KLLa9mduIBWyUFEim1EneviM4m3q7e2UtQ7iezh6FatYFZD5c_v_CH2gV0bhxZrMzNc8ubL46OXo5h1WycY1iAqsjNs",
      "d": "ElS590xAIy7zN4KHKmq2rLnAg1TJ9kODaUrb98X3gCGuTOLBAtFzUqjPyBF8rqXAtkgl8inec6GwY6gmB9p53quJfKSunnN7CbU3Qe37f8HBgS95vFsmJtbctbJ43XKlwo0imYbIeBYLmxKUJt5BKSnUYWWv4EI2AVE_LrqecL-QaNLH2IxY1JVLvR8WhP7wzjTHIsGjaQGn7199eVBaHZ7KTC-bFaEWnPgklR0e8t8TdICUqJudCqTEuoEBFYXRdqi_3betdNZHtJdcwfk9VEXTYTnjzw0fJ7RoFyVE1_1-wMULnEYk5SyfSYfYsBq_V25e-TUSLxB3IXgzBmJVOQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "pingfederate-fapi-jwt-assertion-client2",
      "qi": "rBDWPBNof1ZrvpqRqpPIf-hn6jmOmLN5mzv8ArwfYEuoIPo9Ltzta1m42A6KQAAsHfXUaKtihSXnVopYtYcxguVNCi2qbDh4nx7ZZNCcQsKSkUOw-hgm4vHZJMOJ-4jh6jthUeLTRmCpEZAHQrtmnpQ1tC1g3g2VCDH48p8cLzo",
      "dp": "BrSxmSusECV0pvXjPvxNyFST4x047hz0-5qJv1iJGVM7v0oSequa1wEmh8JJHaac8dN0XGVPRyZomSc_IeQb1Z2PWIb42uPRMSNYGvbn7iDP_jmyE5Nzzyod39k1XAWS0f83P6_c3_dlXAKdnwCJQf-6gjue-MFCQCGpr2uRDwk",
      "alg": "PS256",
      "dq": "GyE3v-YTDXsec308ko50LRYaKaQFLJQBZQ6sdwHiPeWe45wJZ9shsFqZJ2mSryATSG7yBLtTfL1-d6FLnU3z7N8jSGEnAiBWYlDO92EyrQbKEzFyQdhBc1DVw2iFYaS6WeqjzixVnnvScv63Phc1vhDf57--x_ANNZT0FL3b49E",
      "n": "mENeKNMC5ttp60qEq6LZoWaihn-__Ei70wnW8Zd_-ILFnYcaM90oTTnl8R2uHD4EJ3t_VCjFteXIwWV7OwDmRmOMwda0X1R5IKYn0O2ujT8NI4citj8G4NHY0r5Y5loLdb5dynGgT-YpsnWwfTC8Ky98gNA3OLf6Z2n8PEdKJr818RMAC0Vx6NQMHBNG4jI1D0bvbrZbx0XkXan7h2Elm9HLRjzHar5Qb5gFLGQRFdeHVHF5lRKyAFgdeQPvBqMiRsAwcgyKxDjbzF5qHPwhKMB-7IVhxuSULMvgSkesIIhrylzU9bo2KRhcxTB7oPkhAbPgumpoVZV0ME-ypiy77Q"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "pingfederate-fapi-jwt-assertion-client2",
      "alg": "PS256",
      "n": "mENeKNMC5ttp60qEq6LZoWaihn-__Ei70wnW8Zd_-ILFnYcaM90oTTnl8R2uHD4EJ3t_VCjFteXIwWV7OwDmRmOMwda0X1R5IKYn0O2ujT8NI4citj8G4NHY0r5Y5loLdb5dynGgT-YpsnWwfTC8Ky98gNA3OLf6Z2n8PEdKJr818RMAC0Vx6NQMHBNG4jI1D0bvbrZbx0XkXan7h2Elm9HLRjzHar5Qb5gFLGQRFdeHVHF5lRKyAFgdeQPvBqMiRsAwcgyKxDjbzF5qHPwhKMB-7IVhxuSULMvgSkesIIhrylzU9bo2KRhcxTB7oPkhAbPgumpoVZV0ME-ypiy77Q"
    }
  ]
}
2021-08-13 15:59:20 SUCCESS
CheckForKeyIdInClientJWKs
All keys contain kids
2021-08-13 15:59:20 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2021-08-13 15:59:20 SUCCESS
FAPICheckKeyAlgInClientJWKs
Keys in client JWKS all have permitted 'alg'
permitted
[
  "ES256",
  "PS256"
]
2021-08-13 15:59:20 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "p": "43lqQE0EN1LJ_jdqHq56hNFjErKfcrwJnVpIVRsXCZWboV4MSfLzGGEyePPs6SxV6-l_txQY-M2dW6xLaedRUlaFT89r10cIm136ecYUzs51iX_GZW_AvohaXSmAbZKpjLmsHIDelgggQKjDQxGGbmAAQojnqzorpVrfz-8aUNc",
      "kty": "RSA",
      "q": "q1t1ErKAx06nV7ohJ4zlo3xUeMA3rO7HLmK6Eh460DsiX80AsCxyw1AsQy0N1W8u_RgkA3y_p_5Nf7K1KLLa9mduIBWyUFEim1EneviM4m3q7e2UtQ7iezh6FatYFZD5c_v_CH2gV0bhxZrMzNc8ubL46OXo5h1WycY1iAqsjNs",
      "d": "ElS590xAIy7zN4KHKmq2rLnAg1TJ9kODaUrb98X3gCGuTOLBAtFzUqjPyBF8rqXAtkgl8inec6GwY6gmB9p53quJfKSunnN7CbU3Qe37f8HBgS95vFsmJtbctbJ43XKlwo0imYbIeBYLmxKUJt5BKSnUYWWv4EI2AVE_LrqecL-QaNLH2IxY1JVLvR8WhP7wzjTHIsGjaQGn7199eVBaHZ7KTC-bFaEWnPgklR0e8t8TdICUqJudCqTEuoEBFYXRdqi_3betdNZHtJdcwfk9VEXTYTnjzw0fJ7RoFyVE1_1-wMULnEYk5SyfSYfYsBq_V25e-TUSLxB3IXgzBmJVOQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "pingfederate-fapi-jwt-assertion-client2",
      "qi": "rBDWPBNof1ZrvpqRqpPIf-hn6jmOmLN5mzv8ArwfYEuoIPo9Ltzta1m42A6KQAAsHfXUaKtihSXnVopYtYcxguVNCi2qbDh4nx7ZZNCcQsKSkUOw-hgm4vHZJMOJ-4jh6jthUeLTRmCpEZAHQrtmnpQ1tC1g3g2VCDH48p8cLzo",
      "dp": "BrSxmSusECV0pvXjPvxNyFST4x047hz0-5qJv1iJGVM7v0oSequa1wEmh8JJHaac8dN0XGVPRyZomSc_IeQb1Z2PWIb42uPRMSNYGvbn7iDP_jmyE5Nzzyod39k1XAWS0f83P6_c3_dlXAKdnwCJQf-6gjue-MFCQCGpr2uRDwk",
      "alg": "PS256",
      "dq": "GyE3v-YTDXsec308ko50LRYaKaQFLJQBZQ6sdwHiPeWe45wJZ9shsFqZJ2mSryATSG7yBLtTfL1-d6FLnU3z7N8jSGEnAiBWYlDO92EyrQbKEzFyQdhBc1DVw2iFYaS6WeqjzixVnnvScv63Phc1vhDf57--x_ANNZT0FL3b49E",
      "n": "mENeKNMC5ttp60qEq6LZoWaihn-__Ei70wnW8Zd_-ILFnYcaM90oTTnl8R2uHD4EJ3t_VCjFteXIwWV7OwDmRmOMwda0X1R5IKYn0O2ujT8NI4citj8G4NHY0r5Y5loLdb5dynGgT-YpsnWwfTC8Ky98gNA3OLf6Z2n8PEdKJr818RMAC0Vx6NQMHBNG4jI1D0bvbrZbx0XkXan7h2Elm9HLRjzHar5Qb5gFLGQRFdeHVHF5lRKyAFgdeQPvBqMiRsAwcgyKxDjbzF5qHPwhKMB-7IVhxuSULMvgSkesIIhrylzU9bo2KRhcxTB7oPkhAbPgumpoVZV0ME-ypiy77Q"
    }
  ]
}
2021-08-13 15:59:20 SUCCESS
ValidateMTLSCertificatesAsX509
Mutual TLS authentication cert validated as X.509
2021-08-13 15:59:20 SUCCESS
GetResourceEndpointConfiguration
Found a resource endpoint object
resourceUrl
https://idp.conf.ping-eng.com:3000/get
2021-08-13 15:59:20 SUCCESS
SetProtectedResourceUrlToSingleResourceEndpoint
Set protected resource URL
protected_resource_url
https://idp.conf.ping-eng.com:3000/get
2021-08-13 15:59:20 SUCCESS
ExtractTLSTestValuesFromResourceConfiguration
Extracted TLS information from resource endpoint
resource_endpoint
{
  "testHost": "idp.conf.ping-eng.com",
  "testPort": 3000
}
2021-08-13 15:59:20 SUCCESS
ExtractTLSTestValuesFromOBResourceConfiguration
Extracted TLS information from resource endpoint
accounts_resource_endpoint
{
  "testHost": "idp.conf.ping-eng.com",
  "testPort": 3000
}
accounts_request_endpoint
{
  "testHost": "idp.conf.ping-eng.com",
  "testPort": 3000
}
2021-08-13 15:59:20
fapi1-advanced-final
Setup Done
Make request to authorization endpoint
2021-08-13 15:59:20 SUCCESS
CreateAuthorizationEndpointRequestFromClientInformation
Created authorization endpoint request
client_id
fapi_adv_op_w_private_key_par_first_client
redirect_uri
https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback
scope
openid payments
2021-08-13 15:59:20 SUCCESS
AddAcrClaimToAuthorizationEndpointRequest
Added acr claim to authorization_endpoint_request
authorization_endpoint_request
{
  "client_id": "fapi_adv_op_w_private_key_par_first_client",
  "redirect_uri": "https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback",
  "scope": "openid payments",
  "claims": {
    "id_token": {
      "acr": {
        "value": "urn:mace:incommon:iap:silver",
        "essential": true
      }
    }
  }
}
2021-08-13 15:59:20
CreateRandomStateValue
Created state value
requested_state_length
10
state
t51zdo4fFG
2021-08-13 15:59:20 SUCCESS
AddStateToAuthorizationEndpointRequest
Added state parameter to request
client_id
fapi_adv_op_w_private_key_par_first_client
redirect_uri
https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback
scope
openid payments
claims
{
  "id_token": {
    "acr": {
      "value": "urn:mace:incommon:iap:silver",
      "essential": true
    }
  }
}
state
t51zdo4fFG
2021-08-13 15:59:20
CreateRandomNonceValue
Created nonce value
requested_nonce_length
10
nonce
iMxjPefa2G
2021-08-13 15:59:20 SUCCESS
AddNonceToAuthorizationEndpointRequest
Added nonce parameter to request
client_id
fapi_adv_op_w_private_key_par_first_client
redirect_uri
https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback
scope
openid payments
claims
{
  "id_token": {
    "acr": {
      "value": "urn:mace:incommon:iap:silver",
      "essential": true
    }
  }
}
state
t51zdo4fFG
nonce
iMxjPefa2G
2021-08-13 15:59:20 SUCCESS
SetAuthorizationEndpointRequestResponseTypeToCodeIdtoken
Added response_type parameter to request
client_id
fapi_adv_op_w_private_key_par_first_client
redirect_uri
https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback
scope
openid payments
claims
{
  "id_token": {
    "acr": {
      "value": "urn:mace:incommon:iap:silver",
      "essential": true
    }
  }
}
state
t51zdo4fFG
nonce
iMxjPefa2G
response_type
code id_token
2021-08-13 15:59:20
CreateRandomCodeVerifier
Created code_verifier value
code_verifier
D9uW9olR-KvJs9CrBQ8J3YntSTFcdMcIRLyt53B-t_Q5ooIwvL-1WEFgsTwd1zOJSwtf8wwidzhqzo6rwWXFKT3Cx1BPd8NZv6PLZahxr3HRH~cAhzu9rPK2z5K-LRMI
2021-08-13 15:59:20
CreateS256CodeChallenge
Created code_challenge value
code_challenge
7yuljf8DVa6VMsQcF57UxONhPUlrPD_5oWO52OY8sPs
2021-08-13 15:59:20 SUCCESS
AddCodeChallengeToAuthorizationEndpointRequest
Added code_challenge and code_challenge_method parameters to request
client_id
fapi_adv_op_w_private_key_par_first_client
redirect_uri
https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback
scope
openid payments
claims
{
  "id_token": {
    "acr": {
      "value": "urn:mace:incommon:iap:silver",
      "essential": true
    }
  }
}
state
t51zdo4fFG
nonce
iMxjPefa2G
response_type
code id_token
code_challenge
7yuljf8DVa6VMsQcF57UxONhPUlrPD_5oWO52OY8sPs
code_challenge_method
S256
2021-08-13 15:59:20 SUCCESS
ConvertAuthorizationEndpointRequestToRequestObject
Created request object claims
request_object_claims
{
  "client_id": "fapi_adv_op_w_private_key_par_first_client",
  "redirect_uri": "https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback",
  "scope": "openid payments",
  "claims": {
    "id_token": {
      "acr": {
        "value": "urn:mace:incommon:iap:silver",
        "essential": true
      }
    }
  },
  "state": "t51zdo4fFG",
  "nonce": "iMxjPefa2G",
  "response_type": "code id_token",
  "code_challenge": "7yuljf8DVa6VMsQcF57UxONhPUlrPD_5oWO52OY8sPs",
  "code_challenge_method": "S256"
}
2021-08-13 15:59:20 SUCCESS
AddNbfToRequestObject
Added nbf to request object claims
nbf
1.62887036E9
2021-08-13 15:59:20 SUCCESS
AddExpToRequestObject
Added exp to request object claims
exp
1.62887066E9
2021-08-13 15:59:20 SUCCESS
AddAudToRequestObject
Added aud to request object claims
aud
https://idp.conf.ping-eng.com:9031
2021-08-13 15:59:20 SUCCESS
AddIssToRequestObject
Added iss to request object claims
iss
fapi_adv_op_w_private_key_par_first_client
2021-08-13 15:59:20 SUCCESS
AddClientIdToRequestObject
Added client_id to request object claims
client_id
fapi_adv_op_w_private_key_par_first_client
2021-08-13 15:59:20 SUCCESS
SignRequestObject
Signed the request object
claims
{"iss":"fapi_adv_op_w_private_key_par_first_client","response_type":"code id_token","code_challenge_method":"S256","nonce":"iMxjPefa2G","client_id":"fapi_adv_op_w_private_key_par_first_client","aud":"https:\/\/idp.conf.ping-eng.com:9031","nbf":1628870360,"scope":"openid payments","claims":{"id_token":{"acr":{"value":"urn:mace:incommon:iap:silver","essential":true}}},"redirect_uri":"https:\/\/www.certification.openid.net\/test\/a\/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain\/callback","state":"t51zdo4fFG","exp":1628870660,"code_challenge":"7yuljf8DVa6VMsQcF57UxONhPUlrPD_5oWO52OY8sPs"}
header
{"kid":"pingfederate-fapi-jwt-assertion-client1","alg":"PS256"}
request_object
eyJraWQiOiJwaW5nZmVkZXJhdGUtZmFwaS1qd3QtYXNzZXJ0aW9uLWNsaWVudDEiLCJhbGciOiJQUzI1NiJ9.eyJpc3MiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJyZXNwb25zZV90eXBlIjoiY29kZSBpZF90b2tlbiIsImNvZGVfY2hhbGxlbmdlX21ldGhvZCI6IlMyNTYiLCJub25jZSI6ImlNeGpQZWZhMkciLCJjbGllbnRfaWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJhdWQiOiJodHRwczpcL1wvaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzEiLCJuYmYiOjE2Mjg4NzAzNjAsInNjb3BlIjoib3BlbmlkIHBheW1lbnRzIiwiY2xhaW1zIjp7ImlkX3Rva2VuIjp7ImFjciI6eyJ2YWx1ZSI6InVybjptYWNlOmluY29tbW9uOmlhcDpzaWx2ZXIiLCJlc3NlbnRpYWwiOnRydWV9fX0sInJlZGlyZWN0X3VyaSI6Imh0dHBzOlwvXC93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0XC90ZXN0XC9hXC9waW5naWRlbnRpdHktcGluZ2ZlZGVyYXRlLWZhcGktYWR2LW9wLXByaXZhdGUta2V5LXBhci1wbGFpblwvY2FsbGJhY2siLCJzdGF0ZSI6InQ1MXpkbzRmRkciLCJleHAiOjE2Mjg4NzA2NjAsImNvZGVfY2hhbGxlbmdlIjoiN3l1bGpmOERWYTZWTXNRY0Y1N1V4T05oUFVsclBEXzVvV081Mk9ZOHNQcyJ9.CKLsfTMLA5A5yoJ1kJFlKlATP1rtkyoX1r9Ximwg4UbF0APwQNjuzgwe7qGG6fD1g_CvikbwKfwKpJ7yfL-LKPvwsh95H7JhYbOfja2RXppyANKS3unpEukJy5Y3adUniQTosydEXKzy7ifBlL8k6tqOKljkiFUMkeADw9GfjQCS0rpG7fZNTlnRTDUD6MGDAQ2glZGTXDFSMQo8ZDihq6Ff1FvQ97Xxl9vf19OVbmY15s1SSzdVoGHGEm_vRF-_hnItlgfFKzalf5UPOnAM5-meBTZOJnWUKJ9T_vN2Z1RzsUhAqhioEuS0nbMYn1yCJYo9re4Lsu9Fu22GIGjURw
key
{"p":"7Iiv4eby1Ubo_U9uzWEa8OlUQoBz4vjPtB7MWQ6dlM7ajD9IjhjwwE8e1d_fE22DW4bEjHb1ls6_wbEm07PusUuMyHtWzW1sNWnpCh0xgDsEnLZwmtdXhPDHJlbRXHXAqcTVTUIJNMUSa8Mj9MXs33u1mkMD-hYWJfDHNCrDUAc","kty":"RSA","q":"msxkZpdafUHdoC-S5QrAHZ8z0NrQNFjn2yFcpznZ0zjXK83QH-jbBHCcTDBkF7xpatG61SbEznYxYaDEFR4xzuyy0WOYtoIk5IukygdvZhMkAXDNl5rNvF770Fnv8gwpoxZqlpb18kWtP2gk-ebJK2YHKjhl-pHDOrbzubkRdOE","d":"AXvpT93_Y-hQYTCk95gHj6BinFTppIaTZhgJWvnDY-Bz1NhUZ7fz-RjePxQBEuRv3DUk6nEmT8CivxJKZdql9AR9UjHz_ANOH6mAwHxkE2bcEKEsJFGTkaDJhVqmwukYwfKfGpkeNuD2r5rhNdl3XNUQ6VdTkUokmZM3KNrLhks3NtPL3xEMqK5KAYJbJuS8AQoOI5scRTJZYcS63KK9WwBoOFwbz3PFHJb2lffTOH_tnqgSvm9chb7y1CaarSJuFSVTjkjMyk2rBOr4bu5YRtxzH1dAa3Dd5n9XzVwN_q0dIitTh7Vro2JcSU24O1n-XR4WGzCCiarMxPKc8SWyAQ","e":"AQAB","use":"sig","kid":"pingfederate-fapi-jwt-assertion-client1","qi":"De5E3i5KIQ88R7jYZDWEsVonhPPGcWksWXC-s4frJ0tISk5-zlCdP6eitstJTaB1i7bkCW4R7iXufgXqW2WCRK2IXXjwItZo1zEpuAZJnKFwDPxXt5pLoc_sDjarMRENxdx_spyiFIxejLvvDmKGxs7vt3LDm_ytvJXfsymzjqM","dp":"z80l9-jV3dl2R1TJm1V8Pbo_dE01gmnkz_Fexb65Ykp4Zk4SiAQRPmJETNFpQcAsbvRvKJg6Gkt428muur6RLOGaxWbWU5OWRTbOrTwIiQdQff0p4F7fXMPLsjsDo58vq_ZpDn69Z8ba8CF4LUrVV2Fvoh7OF5_fxWVLHOGUxXE","alg":"PS256","dq":"JRS_HEA3YffsMhoTUyB_ItlnHSm9ZDzD1Z8pRbm67zkXehvENlCeXnLnTeztnS36BqeU3Mh7roVrkNpk_jYMcmgK8dOs2lNUqRa2c9rSGZ6OKnYuGZnwnKYYJjHVI6M8Oh_9inNBGTcNqDm3WdGp8OZw4vE9pIdUP_VhbuThRKE","n":"jwcTfjv0q48qux1sg2MR8OvCh1mXITYu7zkEJVCz0UImIrIqLtEzmGkqJP0LobK6-NlFHWOsAp2NcVTh79RBwawsrmi59rJ_nHigX00C7wjVpJtldJmOwmSS4HD8EgRkiM0yJzyKijtRiB5ssrOoBK3VPFMqZYm_JBJY35s_qDDHWTlwuWDLqADZp809btMcwQZCqgrSKgtalspeKXIh6Lv3lkFnELJhfwGZYPtVc2SJk91F8tmgamPNJUfVJV3ygdBuDcB8EZ8m-tIaISghfR1RRkEeYI8r_Wf4dfjIAZRkrj8GHqAJOi762rjyFvXvcPc0Zc-ABDYnVi4WdWOCJw"}
2021-08-13 15:59:20 SUCCESS
BuildRequestObjectPostToPAREndpoint
request
eyJraWQiOiJwaW5nZmVkZXJhdGUtZmFwaS1qd3QtYXNzZXJ0aW9uLWNsaWVudDEiLCJhbGciOiJQUzI1NiJ9.eyJpc3MiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJyZXNwb25zZV90eXBlIjoiY29kZSBpZF90b2tlbiIsImNvZGVfY2hhbGxlbmdlX21ldGhvZCI6IlMyNTYiLCJub25jZSI6ImlNeGpQZWZhMkciLCJjbGllbnRfaWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJhdWQiOiJodHRwczpcL1wvaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzEiLCJuYmYiOjE2Mjg4NzAzNjAsInNjb3BlIjoib3BlbmlkIHBheW1lbnRzIiwiY2xhaW1zIjp7ImlkX3Rva2VuIjp7ImFjciI6eyJ2YWx1ZSI6InVybjptYWNlOmluY29tbW9uOmlhcDpzaWx2ZXIiLCJlc3NlbnRpYWwiOnRydWV9fX0sInJlZGlyZWN0X3VyaSI6Imh0dHBzOlwvXC93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0XC90ZXN0XC9hXC9waW5naWRlbnRpdHktcGluZ2ZlZGVyYXRlLWZhcGktYWR2LW9wLXByaXZhdGUta2V5LXBhci1wbGFpblwvY2FsbGJhY2siLCJzdGF0ZSI6InQ1MXpkbzRmRkciLCJleHAiOjE2Mjg4NzA2NjAsImNvZGVfY2hhbGxlbmdlIjoiN3l1bGpmOERWYTZWTXNRY0Y1N1V4T05oUFVsclBEXzVvV081Mk9ZOHNQcyJ9.CKLsfTMLA5A5yoJ1kJFlKlATP1rtkyoX1r9Ximwg4UbF0APwQNjuzgwe7qGG6fD1g_CvikbwKfwKpJ7yfL-LKPvwsh95H7JhYbOfja2RXppyANKS3unpEukJy5Y3adUniQTosydEXKzy7ifBlL8k6tqOKljkiFUMkeADw9GfjQCS0rpG7fZNTlnRTDUD6MGDAQ2glZGTXDFSMQo8ZDihq6Ff1FvQ97Xxl9vf19OVbmY15s1SSzdVoGHGEm_vRF-_hnItlgfFKzalf5UPOnAM5-meBTZOJnWUKJ9T_vN2Z1RzsUhAqhioEuS0nbMYn1yCJYo9re4Lsu9Fu22GIGjURw
2021-08-13 15:59:20 SUCCESS
CreateClientAuthenticationAssertionClaims
Created client assertion claims
iss
fapi_adv_op_w_private_key_par_first_client
sub
fapi_adv_op_w_private_key_par_first_client
aud
https://idp.conf.ping-eng.com:9032/as/token.oauth2
jti
XOpX6Sl45UuGSBTE9VEJ
iat
1628870360
exp
1628870420
2021-08-13 15:59:20 SUCCESS
UpdateClientAuthenticationAssertionClaimsWithISSAud
Updated audience in client assertion claims
iss
fapi_adv_op_w_private_key_par_first_client
sub
fapi_adv_op_w_private_key_par_first_client
jti
XOpX6Sl45UuGSBTE9VEJ
iat
1628870360
exp
1628870420
aud
https://idp.conf.ping-eng.com:9031
2021-08-13 15:59:20 SUCCESS
SignClientAuthenticationAssertion
Signed the client assertion
client_assertion
eyJraWQiOiJwaW5nZmVkZXJhdGUtZmFwaS1qd3QtYXNzZXJ0aW9uLWNsaWVudDEiLCJhbGciOiJQUzI1NiJ9.eyJzdWIiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJhdWQiOiJodHRwczpcL1wvaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzEiLCJpc3MiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJleHAiOjE2Mjg4NzA0MjAsImlhdCI6MTYyODg3MDM2MCwianRpIjoiWE9wWDZTbDQ1VXVHU0JURTlWRUoifQ.elG8ZsWR8a7PfHOxAY3vFFLem85TCQ2KP9rHZwYeIPmWwnA9TVgTV8VyVYy2yf2BZxr-BQE5n2wfngrxoJzihqy9RIcwEOImyCK1tCF49ynfECPEQEaVk-WkERhT8OEFzvdPrCyRY_-QcvsC1lM7QBvmjlzIneuzqSJ1aReGz2UMFVtPMrILQEO5NP4XZjSS_1sptf0492mQrRUKT_Ib8_CIRt-G4KrEa_kOPOiZnCsR86PocpyWMm9xdnsrUGL4CHg1ti6CyNE_1YfnaTfqAlwdHWTHMSnpGiS21NcZ3o_TEqmOMPBW2sV5-eHpEyyUoHEQFCnSa4zgd9AkSdd1rA
2021-08-13 15:59:20 SUCCESS
AddClientAssertionToPAREndpointParameters
Added client assertion to request
request
{
  "request": "eyJraWQiOiJwaW5nZmVkZXJhdGUtZmFwaS1qd3QtYXNzZXJ0aW9uLWNsaWVudDEiLCJhbGciOiJQUzI1NiJ9.eyJpc3MiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJyZXNwb25zZV90eXBlIjoiY29kZSBpZF90b2tlbiIsImNvZGVfY2hhbGxlbmdlX21ldGhvZCI6IlMyNTYiLCJub25jZSI6ImlNeGpQZWZhMkciLCJjbGllbnRfaWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJhdWQiOiJodHRwczpcL1wvaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzEiLCJuYmYiOjE2Mjg4NzAzNjAsInNjb3BlIjoib3BlbmlkIHBheW1lbnRzIiwiY2xhaW1zIjp7ImlkX3Rva2VuIjp7ImFjciI6eyJ2YWx1ZSI6InVybjptYWNlOmluY29tbW9uOmlhcDpzaWx2ZXIiLCJlc3NlbnRpYWwiOnRydWV9fX0sInJlZGlyZWN0X3VyaSI6Imh0dHBzOlwvXC93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0XC90ZXN0XC9hXC9waW5naWRlbnRpdHktcGluZ2ZlZGVyYXRlLWZhcGktYWR2LW9wLXByaXZhdGUta2V5LXBhci1wbGFpblwvY2FsbGJhY2siLCJzdGF0ZSI6InQ1MXpkbzRmRkciLCJleHAiOjE2Mjg4NzA2NjAsImNvZGVfY2hhbGxlbmdlIjoiN3l1bGpmOERWYTZWTXNRY0Y1N1V4T05oUFVsclBEXzVvV081Mk9ZOHNQcyJ9.CKLsfTMLA5A5yoJ1kJFlKlATP1rtkyoX1r9Ximwg4UbF0APwQNjuzgwe7qGG6fD1g_CvikbwKfwKpJ7yfL-LKPvwsh95H7JhYbOfja2RXppyANKS3unpEukJy5Y3adUniQTosydEXKzy7ifBlL8k6tqOKljkiFUMkeADw9GfjQCS0rpG7fZNTlnRTDUD6MGDAQ2glZGTXDFSMQo8ZDihq6Ff1FvQ97Xxl9vf19OVbmY15s1SSzdVoGHGEm_vRF-_hnItlgfFKzalf5UPOnAM5-meBTZOJnWUKJ9T_vN2Z1RzsUhAqhioEuS0nbMYn1yCJYo9re4Lsu9Fu22GIGjURw",
  "client_assertion": "eyJraWQiOiJwaW5nZmVkZXJhdGUtZmFwaS1qd3QtYXNzZXJ0aW9uLWNsaWVudDEiLCJhbGciOiJQUzI1NiJ9.eyJzdWIiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJhdWQiOiJodHRwczpcL1wvaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzEiLCJpc3MiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJleHAiOjE2Mjg4NzA0MjAsImlhdCI6MTYyODg3MDM2MCwianRpIjoiWE9wWDZTbDQ1VXVHU0JURTlWRUoifQ.elG8ZsWR8a7PfHOxAY3vFFLem85TCQ2KP9rHZwYeIPmWwnA9TVgTV8VyVYy2yf2BZxr-BQE5n2wfngrxoJzihqy9RIcwEOImyCK1tCF49ynfECPEQEaVk-WkERhT8OEFzvdPrCyRY_-QcvsC1lM7QBvmjlzIneuzqSJ1aReGz2UMFVtPMrILQEO5NP4XZjSS_1sptf0492mQrRUKT_Ib8_CIRt-G4KrEa_kOPOiZnCsR86PocpyWMm9xdnsrUGL4CHg1ti6CyNE_1YfnaTfqAlwdHWTHMSnpGiS21NcZ3o_TEqmOMPBW2sV5-eHpEyyUoHEQFCnSa4zgd9AkSdd1rA",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
2021-08-13 15:59:20
CallPAREndpoint
HTTP request
request_uri
https://idp.conf.ping-eng.com:9031/as/par.oauth2
request_method
POST
request_headers
{
  "accept": "application/json;charset\u003dUTF-8",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "accept-charset": "utf-8",
  "content-length": "2059"
}
request_body
request=eyJraWQiOiJwaW5nZmVkZXJhdGUtZmFwaS1qd3QtYXNzZXJ0aW9uLWNsaWVudDEiLCJhbGciOiJQUzI1NiJ9.eyJpc3MiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJyZXNwb25zZV90eXBlIjoiY29kZSBpZF90b2tlbiIsImNvZGVfY2hhbGxlbmdlX21ldGhvZCI6IlMyNTYiLCJub25jZSI6ImlNeGpQZWZhMkciLCJjbGllbnRfaWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJhdWQiOiJodHRwczpcL1wvaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzEiLCJuYmYiOjE2Mjg4NzAzNjAsInNjb3BlIjoib3BlbmlkIHBheW1lbnRzIiwiY2xhaW1zIjp7ImlkX3Rva2VuIjp7ImFjciI6eyJ2YWx1ZSI6InVybjptYWNlOmluY29tbW9uOmlhcDpzaWx2ZXIiLCJlc3NlbnRpYWwiOnRydWV9fX0sInJlZGlyZWN0X3VyaSI6Imh0dHBzOlwvXC93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0XC90ZXN0XC9hXC9waW5naWRlbnRpdHktcGluZ2ZlZGVyYXRlLWZhcGktYWR2LW9wLXByaXZhdGUta2V5LXBhci1wbGFpblwvY2FsbGJhY2siLCJzdGF0ZSI6InQ1MXpkbzRmRkciLCJleHAiOjE2Mjg4NzA2NjAsImNvZGVfY2hhbGxlbmdlIjoiN3l1bGpmOERWYTZWTXNRY0Y1N1V4T05oUFVsclBEXzVvV081Mk9ZOHNQcyJ9.CKLsfTMLA5A5yoJ1kJFlKlATP1rtkyoX1r9Ximwg4UbF0APwQNjuzgwe7qGG6fD1g_CvikbwKfwKpJ7yfL-LKPvwsh95H7JhYbOfja2RXppyANKS3unpEukJy5Y3adUniQTosydEXKzy7ifBlL8k6tqOKljkiFUMkeADw9GfjQCS0rpG7fZNTlnRTDUD6MGDAQ2glZGTXDFSMQo8ZDihq6Ff1FvQ97Xxl9vf19OVbmY15s1SSzdVoGHGEm_vRF-_hnItlgfFKzalf5UPOnAM5-meBTZOJnWUKJ9T_vN2Z1RzsUhAqhioEuS0nbMYn1yCJYo9re4Lsu9Fu22GIGjURw&client_assertion=eyJraWQiOiJwaW5nZmVkZXJhdGUtZmFwaS1qd3QtYXNzZXJ0aW9uLWNsaWVudDEiLCJhbGciOiJQUzI1NiJ9.eyJzdWIiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJhdWQiOiJodHRwczpcL1wvaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzEiLCJpc3MiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJleHAiOjE2Mjg4NzA0MjAsImlhdCI6MTYyODg3MDM2MCwianRpIjoiWE9wWDZTbDQ1VXVHU0JURTlWRUoifQ.elG8ZsWR8a7PfHOxAY3vFFLem85TCQ2KP9rHZwYeIPmWwnA9TVgTV8VyVYy2yf2BZxr-BQE5n2wfngrxoJzihqy9RIcwEOImyCK1tCF49ynfECPEQEaVk-WkERhT8OEFzvdPrCyRY_-QcvsC1lM7QBvmjlzIneuzqSJ1aReGz2UMFVtPMrILQEO5NP4XZjSS_1sptf0492mQrRUKT_Ib8_CIRt-G4KrEa_kOPOiZnCsR86PocpyWMm9xdnsrUGL4CHg1ti6CyNE_1YfnaTfqAlwdHWTHMSnpGiS21NcZ3o_TEqmOMPBW2sV5-eHpEyyUoHEQFCnSa4zgd9AkSdd1rA&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
request_mutual_tls
{
  "cert": "MIID3TCCAsWgAwIBAgIUIi7yAbDDmWkZjI8CwjLBVkswVkIwDQYJKoZIhvcNAQELBQAwfTELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAkNPMQ8wDQYDVQQHDAZEZW52ZXIxFTATBgNVBAoMDFBpbmdJZGVudGl0eTEUMBIGA1UECwwLRGV2ZWxvcG1lbnQxIzAhBgNVBAMMGkZBUEkgQWR2IE9QIHcgRmlyc3QgQ2xpZW50MCAXDTIxMDcyNjIyMzQzN1oYDzIxMjEwNzAyMjIzNDM3WjB9MQswCQYDVQQGEwJVUzELMAkGA1UECAwCQ08xDzANBgNVBAcMBkRlbnZlcjEVMBMGA1UECgwMUGluZ0lkZW50aXR5MRQwEgYDVQQLDAtEZXZlbG9wbWVudDEjMCEGA1UEAwwaRkFQSSBBZHYgT1AgdyBGaXJzdCBDbGllbnQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCa91hiBBEaNcRdvQ0Gvg06mzaIQpa17vgtP77HwtV0FvH+3imrnqmaCcpEnWGMv/udX8S5r/VAeUPB2Q31187vKDLKxbadWTKuSNQajOkRyiXZzutbEQbN/t7JAz7oETujYoOTlMNT4N9twYvKEvxTeZAWNUCQHXZcESKYXhph0eZaaOvNo7WqQ+ygGBzgTVev6tXr/Q2+M3NkBnSvRYegSN5ZtmIXMrNVaH7D+SC8QUPWxsB8ZVIENzBhCI8+brrPjyLNqVKoI9O7Hjdgzb8Xs+gC98ATmsbQrE/8pRdYYCPkEoETAWRq2T/dEf7NE+AMerttKk9TdNwvbB1WbAoHAgMBAAGjUzBRMB0GA1UdDgQWBBTr8p3YWM2Rtw/BAQaellNa1RUKSTAfBgNVHSMEGDAWgBTr8p3YWM2Rtw/BAQaellNa1RUKSTAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQB17ygVKcEpZxP4XML98KyUycNxsyHcKdIo2GZCRsmwjDR5nRcdWlE+tI50sduSaAR+gSbDFR/dqBxl0lBEMLj6Rqpson+z17jv68fU9H7l7JLfI5xAXuW4s1Kg/xBcYBy7QJkU9CTMIb6TBQESCbTUq89aCX4fT8WQleCflRJjSuzzdpVWd0PIhcxCoxpa/BcXtK0gf/z0rimF4jJKv40rqdf0LGsVzKQ9TxQIDWk0tov4FkvBw63VUp6b7PWdEHi4E9uKgHxh2Pj+VykK33nCmUsGXENfj4SSkY2O00iDw3oHfC8xmWvgqsTdlzJm1qhZCZGNOsdWLEv6hGl4XLyr",
  "key": "MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQCa91hiBBEaNcRdvQ0Gvg06mzaIQpa17vgtP77HwtV0FvH+3imrnqmaCcpEnWGMv/udX8S5r/VAeUPB2Q31187vKDLKxbadWTKuSNQajOkRyiXZzutbEQbN/t7JAz7oETujYoOTlMNT4N9twYvKEvxTeZAWNUCQHXZcESKYXhph0eZaaOvNo7WqQ+ygGBzgTVev6tXr/Q2+M3NkBnSvRYegSN5ZtmIXMrNVaH7D+SC8QUPWxsB8ZVIENzBhCI8+brrPjyLNqVKoI9O7Hjdgzb8Xs+gC98ATmsbQrE/8pRdYYCPkEoETAWRq2T/dEf7NE+AMerttKk9TdNwvbB1WbAoHAgMBAAECggEAf4aFKUQHfvY4PpvRGHdWE6CfY8rIk7ewbCxFJ8biOcKYKxFQYXcUQztDROvu1xE2Uu/4yIZQ4VnptKCWqHWMSatfARdrjFlXJ62vPpovQwCD3ZY2gJ6mZucTF4CgSAHGflIXzV9izqgDtiLMkuLE2zzyohP4qaBVQranLZRjSZNWeGvEpkcf7Nv7FlfZaOJ/FkcGwyFn7iSzX/KRL/1TA6zDlreA3PGJr96i9SmFHQsurFv7quRxEUFoSVxVtn5IiOJji45Evte8KAhMzlau1MuAlKxiIJAMIPN2l1nTRTRZUybDBoLp9CkkAmvp75krld9NB/hbWaeRsxhgVPXYwQKBgQDMsai5QHJAFZ5P31LN0dvlvcj0X2dPS0hEd6NsIf5DkbQKHQuVlxdIGhChLhVBdkGUt9ZYSflxlUtc8GUG3+e0TKg+ZAHNakueV73TGZy3BAzQBxwQBMqUltcXWMjWBaDnbQH+TrtYP0A+ZdHd4gnBNuSUuv5R7IxGWHgfcvtnuQKBgQDBzt2kGjDXXPV4qrtmGl4KaCAvsFr76VsVr8879MhrVgevI5vbsBNWQ3yvykXLr5B6s0VaqibvgDTcchQvqwtoEeDQfHsSHnAglGYCAi06hwGArTW/hxW0L7IivB+laFsbPY2HbnGZ6WUOjMNTgGAihbbLd6+IvLJEVdn7gjxfvwKBgD/DS9rBP5XE5jbdS08AA27yiqnNGkJyIgXp+sdRY4Iq3hmUaKplkYQNUobS8x4cN1ubVLLWAFUoe3xtCht1HhllE7ezsXgKl5mwnVooDVBZe6BFxrEavPxCbKhCKPW6dSACLe/JGMTplxqY3yIuKnm8nsHR6i0c8alsH6c0SypJAoGBALcVCn+5ViY8ZI9nCby8b9X4417phCmxGiB0gpoq9SGglYW3Z8ayoLG+8wzFUgXGhf/DVmL9leZuAIG3KqaVOCNJsEyDK2fEZTwBtBN1pvBBFQRPnBSgMbqTy/3QJT0GRfqHvSkRBjPVLWf/RY2eGjLCihnPqHzNdMHlMBTNxObVAoGAMRDZNtM0vIUNbjY5YFK0AoetPqR1mS2fWOFdCVnyHYBOJmmUZbU4oNZk5HmHBOC8N7aOELyXu56I4yEw0KUjOphKGfA9b2553q1A6t1x1oHBIwVuj1W3sEpUOtj2fWwmmdqjEyRsdzEJWfOuOEFzbfaw1pClq9IbngVcDGfzg74\u003d"
}
2021-08-13 15:59:20 RESPONSE
CallPAREndpoint
HTTP response
response_status_code
201 CREATED
response_status_text
Created
response_headers
{
  "date": "Fri, 13 Aug 2021 15:59:20 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003dWKeag3QKIskaODBvcXSCvx; Path\u003d/; Secure; HttpOnly; SameSite\u003dNone",
  "transfer-encoding": "chunked"
}
response_body
{"expires_in":60,"request_uri":"urn:ietf:params:oauth:request_uri:qg7cr7mX2J951GybJcnapexWxNzM16gt"}
2021-08-13 15:59:20 SUCCESS
CallPAREndpoint
Storing pushed_authorization_endpoint_response_http_status 201
2021-08-13 15:59:20 SUCCESS
CallPAREndpoint
Parsed pushed authorization request endpoint response
expires_in
60
request_uri
urn:ietf:params:oauth:request_uri:qg7cr7mX2J951GybJcnapexWxNzM16gt
2021-08-13 15:59:20 SUCCESS
CheckIfPAREndpointResponseError
pushed authorization request endpoint correct response.
2021-08-13 15:59:20 SUCCESS
CheckForRequestUriValue
Found valid request_uri
request_uri
urn:ietf:params:oauth:request_uri:qg7cr7mX2J951GybJcnapexWxNzM16gt
2021-08-13 15:59:20 SUCCESS
CheckForPARResponseExpiresIn
Found expires_in
expires_in
60
2021-08-13 15:59:20 SUCCESS
ExtractRequestUriFromPARResponse
Extracted the request_uri: urn:ietf:params:oauth:request_uri:qg7cr7mX2J951GybJcnapexWxNzM16gt
2021-08-13 15:59:20 SUCCESS
EnsureMinimumRequestUriEntropy
Calculated shannon entropy seems sufficient
actual
319.71073092878447
expected
128.0
2021-08-13 15:59:20 SUCCESS
BuildRequestObjectByReferenceRedirectToAuthorizationEndpoint
Sending to authorization endpoint
redirect_to_authorization_endpoint
https://idp.conf.ping-eng.com:9031/as/authorization.oauth2?request_uri=urn:ietf:params:oauth:request_uri:qg7cr7mX2J951GybJcnapexWxNzM16gt&client_id=fapi_adv_op_w_private_key_par_first_client&redirect_uri=https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback&scope=openid%20payments&response_type=code%20id_token
2021-08-13 15:59:20 REDIRECT
fapi1-advanced-final
Redirecting to authorization endpoint
redirect_to
https://idp.conf.ping-eng.com:9031/as/authorization.oauth2?request_uri=urn:ietf:params:oauth:request_uri:qg7cr7mX2J951GybJcnapexWxNzM16gt&client_id=fapi_adv_op_w_private_key_par_first_client&redirect_uri=https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback&scope=openid%20payments&response_type=code%20id_token
2021-08-13 15:59:20
WebRunner
Scripted browser HTTP request
browser
goToUrl
request_method
GET
request_uri
https://idp.conf.ping-eng.com:9031/as/authorization.oauth2?request_uri=urn:ietf:params:oauth:request_uri:qg7cr7mX2J951GybJcnapexWxNzM16gt&client_id=fapi_adv_op_w_private_key_par_first_client&redirect_uri=https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback&scope=openid%20payments&response_type=code%20id_token
2021-08-13 15:59:22 RESPONSE
WebRunner
Scripted browser HTTP response
response_content
<!DOCTYPE html>


<!-- template name: html.form.login.template.html -->


<!-- Configurable default behavior for the Remember Username checkbox -->
            <!-- set the checkbox to unchecked -->
            

<html lang="en" dir="ltr">
<head>
    <title>Sign On</title>
    <base href="https://idp.conf.ping-eng.com:9031/"/>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"/>
    <meta name="viewport" content="width=device-width, initial-scale=1.0, minimum-scale=1.0, maximum-scale=1.0, user-scalable=no"/>
    <meta http-equiv="x-ua-compatible" content="IE=edge" />
    <link rel="stylesheet" type="text/css" href="assets/css/main.css"/>
    </head>

<body onload="setFocus();">

<div class="ping-container ping-signin login-template">

    <!--
    if there is a logo present in the 'company-logo' container,
    then 'has-logo' class should be added to 'ping-header' container.
    -->
    <div class="ping-header">
        <span class="company-logo"><!-- client company logo here --></span>
        Sign On
    </div>
    <!-- .ping-header -->

    <div class="ping-body-container">

        <div>
            <form method="POST" action="/as/ugqqv/resume/as/authorization.ping" autocomplete="off">

                <div class="ping-messages">
                                        
                                        
                </div>

                
                        <div class="ping-input-label">
                            Username
                        </div>
                        <div class="ping-input-container">
                                                            <input id="username" type="text" size="36" name="pf.username" value="" autocorrect="off" autocapitalize="off" onKeyPress="return postOnReturn(event)"  /><!---->
                                                        <div class="place-bottom type-alert tooltip-text" id="username-text">
                                <div class="icon">!</div>
                                Please fill out this field.
                            </div>
                        </div>

                        <div class="ping-input-label">
                            Password
                        </div>
                        <div class="ping-input-container password-container">
                            <input id="password" type="password" size="36" name="pf.pass" onKeyPress="return postOnReturn(event)" />
                            <div class="place-bottom type-alert tooltip-text" id="password-text">
                                <div class="icon">!</div>
                                Please fill out this field.
                            </div>
                        </div>

                        
                        
                        <div class="ping-buttons">
                            <input type="hidden" name="pf.ok" value="" />
                            <input type="hidden" name="pf.cancel" value="" />
                            <span id="signOnButtonSpan">
                                <a onclick="postOk();" class="ping-button normal allow" id="signOnButton" title="Sign On">
                                Sign On
                                </a>
                            </span>
                        </div><!-- .ping-buttons -->

                        
                        
                                    
                <!-- #recaptcha -->
                
                <input type="hidden" name="pf.adapterId" id="pf.adapterId" value="HTMLFormSimplePCV" />
            </form>
        </div><!-- .ping-body// blank div -->
        
    </div><!-- .ping-body-container -->

    <div class="ping-footer-container">
        <div class="ping-footer">
            <div class="ping-credits"></div>
            <div class="ping-copyright">© Copyright 2021 Ping Identity. All rights reserved.</div>
        </div>
        <!-- .ping-footer -->
    </div>
    <!-- .ping-footer-container -->

</div><!-- .ping-container -->

<script type="text/javascript">

	function postForgotPassword() {

		document.forms[0]['pf.passwordreset'].value = 'clicked';
		document.forms[0].submit();
	}

	function postRecoverUsername() {
        document.forms[0]['pf.usernamerecovery'].value = 'clicked';
		document.forms[0].submit();
	}

	function postAlternateAuthnSystem(system) {
	    var variants = ["Biometrics", "Windows Hello", "Face ID",  "Touch ID"];
	    for (i = 0; i < variants.length; i++) {
	        if(variants[i] == system) {
	            system = "FIDO";
	        }
	    }
	    document.forms[0]['$alternateAuthnSystem'].value = system;
	    document.forms[0].submit();
	}


	function postRegistration()
    {
        document.forms[0]['$registrationValue'].value = true;
        document.forms[0].submit();
    }

    function postOk() {
        if (false) {
            grecaptcha.execute();
        }
        else {
            // remove error tips
            if (document.forms[0]['pf.username'].value !== '') {
                document.getElementById('username-text').className = 'place-bottom type-alert tooltip-text';
            }
            if (document.forms[0]['pf.pass'].value !== '') {
                document.getElementById('password-text').className = 'place-bottom type-alert tooltip-text';
            }
            // Add back
            if (document.forms[0]['pf.username'].value === '') {
                document.getElementById('username-text').className += ' show';
            }
            else if (document.forms[0]['pf.pass'].value === '') {
                document.getElementById('password-text').className += ' show';
            }
            else {
                submitForm()
            }
        }
    }

    function submitForm()
    {
        var signOnButtonSpan = document.getElementById('signOnButtonSpan');
        signOnButtonSpan.classList.add('content-columns', 'disabled');
        signOnButtonSpan.style = "pointer-events: none;";

        var signOnButton = document.getElementById('signOnButton');
        signOnButton.innerHTML = 'Signing on...';

        document.forms[0]['pf.ok'].value = 'clicked';
        document.forms[0].submit();
        if(false) {
            grecaptcha.reset();
        }
    }

    function postCancel() {
        document.forms[0]['pf.cancel'].value = 'clicked';
        document.forms[0].submit();
    }

    function postOnReturn(e) {
        var keycode;
        if (window.event) keycode = window.event.keyCode;
        else if (e) keycode = e.which;
        else return true;

        if (keycode == 13) {
            postOk();
            return false;
        } else {
            return true;
        }
    }

    function setFocus() {
        var platform = navigator.platform;
        if (platform != null && platform.indexOf("iPhone") == -1) {
                            document.getElementById('username').focus();
                    }
    }

    function setMobile(mobile) {
        var className = ' mobile',
            hasClass = (bodyTag.className.indexOf(className) !== -1);

        if (mobile && !hasClass) {
            bodyTag.className += className;

        } else if (!mobile && hasClass) {
            bodyTag.className = bodyTag.className.replace(className, '');
        }

        
        <!-- Check if this is the PingOne Mobile App -->
            }

    function getScreenWidth() {
        return (window.outerHeight) ? window.outerWidth : document.body.clientWidth;
    }

    var bodyTag = document.getElementsByTagName('body')[0],
        width = getScreenWidth(),
        remember = false && false;

    
    if (/Android|webOS|iPhone|iPod|BlackBerry|IEMobile|Opera Mini/i.test(navigator.userAgent)) {
        setMobile(true);
    } else {
        setMobile((width <= 480));
        window.onresize = function() {
            width = getScreenWidth();
            setMobile((width <= 480));
        }
    }
   


</script>

</body>
</html>
response_content_type
text/html
response_status_text
200-OK
response_status_code
200
2021-08-13 15:59:22 INFO
WebRunner
Waiting
regexp
seconds
10
task
Initial Login
browser
wait
action
element_type
id
url
https://idp.conf.ping-eng.com:9031/as/authorization.oauth2?request_uri=urn:ietf:params:oauth:request_uri:qg7cr7mX2J951GybJcnapexWxNzM16gt&client_id=fapi_adv_op_w_private_key_par_first_client&redirect_uri=https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback&scope=openid%20payments&response_type=code%20id_token
target
username
2021-08-13 15:59:22 INFO
WebRunner
Entering text
task
Initial Login
browser
text
element_type
id
value
joe
url
https://idp.conf.ping-eng.com:9031/as/authorization.oauth2?request_uri=urn:ietf:params:oauth:request_uri:qg7cr7mX2J951GybJcnapexWxNzM16gt&client_id=fapi_adv_op_w_private_key_par_first_client&redirect_uri=https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback&scope=openid%20payments&response_type=code%20id_token
target
username
2021-08-13 15:59:22 INFO
WebRunner
Entering text
task
Initial Login
browser
text
element_type
id
value
2Federate
url
https://idp.conf.ping-eng.com:9031/as/authorization.oauth2?request_uri=urn:ietf:params:oauth:request_uri:qg7cr7mX2J951GybJcnapexWxNzM16gt&client_id=fapi_adv_op_w_private_key_par_first_client&redirect_uri=https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback&scope=openid%20payments&response_type=code%20id_token
target
password
2021-08-13 15:59:22 INFO
WebRunner
Clicking an element
task
Initial Login
browser
click
element_type
id
url
https://idp.conf.ping-eng.com:9031/as/authorization.oauth2?request_uri=urn:ietf:params:oauth:request_uri:qg7cr7mX2J951GybJcnapexWxNzM16gt&client_id=fapi_adv_op_w_private_key_par_first_client&redirect_uri=https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback&scope=openid%20payments&response_type=code%20id_token
target
signOnButton
2021-08-13 15:59:22 INFO
WebRunner
Completed processing of webpage
task
Initial Login
browser
complete
response_status_text
200-OK
match
https://idp.conf.ping-eng.com:9031/as/authorization.oauth2*
url
https://idp.conf.ping-eng.com:9031/as/ugqqv/resume/as/authorization.ping
response_status_code
200
2021-08-13 15:59:22 INFO
WebRunner
Clicking an element
task
Authorize Client
browser
click
element_type
css
url
https://idp.conf.ping-eng.com:9031/as/ugqqv/resume/as/authorization.ping
target
a.ping-button.normal.allow
2021-08-13 15:59:22 INCOMING
fapi1-advanced-final
Incoming HTTP request to test instance wCkrQW9Zx2JRQay
incoming_headers
{
  "host": "www.certification.openid.net",
  "upgrade-insecure-requests": "1",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.72 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "same-origin",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "referer": "https://idp.conf.ping-eng.com:9031/as/ugqqv/resume/as/authorization.ping",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9",
  "origin": "https://idp.conf.ping-eng.com:9031",
  "cache-control": "max-age\u003d0",
  "x-ssl-cipher": "ECDHE-RSA-AES256-GCM-SHA384",
  "x-ssl-protocol": "TLSv1.2",
  "connection": "close",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net"
}
incoming_path
callback
incoming_body_form_params
incoming_method
GET
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-08-13 15:59:22 SUCCESS
CreateRandomImplicitSubmitUrl
Created random implicit submission URL
implicit_submit
{
  "path": "implicit/0QRPw4AM2auAPTFodq91",
  "fullUrl": "https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/implicit/0QRPw4AM2auAPTFodq91"
}
2021-08-13 15:59:22 OUTGOING
fapi1-advanced-final
Response to HTTP request to test instance wCkrQW9Zx2JRQay
outgoing
ModelAndView [view="implicitCallback"; model={implicitSubmitUrl=https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/implicit/0QRPw4AM2auAPTFodq91, returnUrl=/log-detail.html?log=wCkrQW9Zx2JRQay}]
outgoing_path
callback
2021-08-13 15:59:23 INFO
WebRunner
Completed processing of webpage
task
Authorize Client
browser
complete
response_status_text
200-
match
https://idp.conf.ping-eng.com:9031/as/*/resume/as/authorization.ping*
url
https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback#code=6yqwMKk5gKH0biUZFr1vSf6mCvdkN-aGgS4s68Eh&id_token=eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJqdGkiOiJ5RnZHWjF6OFA1bGdxckJyc3BHTG9vIiwiaXNzIjoiaHR0cHM6Ly9pZHAuY29uZi5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTYyODg3MDM2MiwiZXhwIjoxNjI4ODcwNjYyLCJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYXV0aF90aW1lIjoxNjI4ODcwMzYyLCJub25jZSI6ImlNeGpQZWZhMkciLCJjX2hhc2giOiJMUVBTeE1XZGxOUXZxazJyVElhQVJRIiwic19oYXNoIjoid0U0TFBNWEJmQXBmUXFsblFBYUdLdyJ9.jCoe7u7iw8CszZ7IAt58n7edYwI0zqc7baBXkv11Gmv9paOaTgKizqbulTqLq0yATtGxMZuExa_N3VqNiJ8zp__zuGvINUrKcZk28pWrfR2ZPatc0mQ0MkUS34bIahbounu1zI4JRYHD1B7ewCQSkHu_ox-h-PLDIuu1Xtmx22v6WnABhTvbJ9Iphe8llP5wjHKLrXgZFMhuq6rYjYFPnwtkwvVvd4QJqzWiA9N7kIkqdhgPKh45Ia9Mss-DKir6rtiOltmEPSZ15POXelcF_yQHwS0szERINg3m8GqzSdmFzc4FumWFa5WUXyNcVkyONGVPMWzJ4BGuaTCV8nm9Rg&state=t51zdo4fFG
response_status_code
200
2021-08-13 15:59:23 INFO
WebRunner
Completed processing of webpage
task
Verify Complete
browser
complete
response_status_text
200-
match
https://www.certification.openid.net/test/a/*/callback*
url
https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback#code=6yqwMKk5gKH0biUZFr1vSf6mCvdkN-aGgS4s68Eh&id_token=eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJqdGkiOiJ5RnZHWjF6OFA1bGdxckJyc3BHTG9vIiwiaXNzIjoiaHR0cHM6Ly9pZHAuY29uZi5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTYyODg3MDM2MiwiZXhwIjoxNjI4ODcwNjYyLCJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYXV0aF90aW1lIjoxNjI4ODcwMzYyLCJub25jZSI6ImlNeGpQZWZhMkciLCJjX2hhc2giOiJMUVBTeE1XZGxOUXZxazJyVElhQVJRIiwic19oYXNoIjoid0U0TFBNWEJmQXBmUXFsblFBYUdLdyJ9.jCoe7u7iw8CszZ7IAt58n7edYwI0zqc7baBXkv11Gmv9paOaTgKizqbulTqLq0yATtGxMZuExa_N3VqNiJ8zp__zuGvINUrKcZk28pWrfR2ZPatc0mQ0MkUS34bIahbounu1zI4JRYHD1B7ewCQSkHu_ox-h-PLDIuu1Xtmx22v6WnABhTvbJ9Iphe8llP5wjHKLrXgZFMhuq6rYjYFPnwtkwvVvd4QJqzWiA9N7kIkqdhgPKh45Ia9Mss-DKir6rtiOltmEPSZ15POXelcF_yQHwS0szERINg3m8GqzSdmFzc4FumWFa5WUXyNcVkyONGVPMWzJ4BGuaTCV8nm9Rg&state=t51zdo4fFG
response_status_code
200
2021-08-13 15:59:23 INCOMING
fapi1-advanced-final
Incoming HTTP request to test instance wCkrQW9Zx2JRQay
incoming_headers
{
  "host": "www.certification.openid.net",
  "upgrade-insecure-requests": "1",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.72 Safari/537.36",
  "accept": "*/*",
  "sec-fetch-site": "same-origin",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "referer": "https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9",
  "cookie": "JSESSIONID\u003d9BC84D4D9F29B61A4F14362976BABA39",
  "x-requested-with": "XMLHttpRequest",
  "content-type": "text/plain",
  "x-ssl-cipher": "ECDHE-RSA-AES256-GCM-SHA384",
  "x-ssl-protocol": "TLSv1.2",
  "content-length": "913",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net",
  "connection": "close"
}
incoming_path
implicit/0QRPw4AM2auAPTFodq91
incoming_body_form_params
incoming_method
POST
incoming_body_json
incoming_query_string_params
{}
incoming_body
#code=6yqwMKk5gKH0biUZFr1vSf6mCvdkN-aGgS4s68Eh&id_token=eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJqdGkiOiJ5RnZHWjF6OFA1bGdxckJyc3BHTG9vIiwiaXNzIjoiaHR0cHM6Ly9pZHAuY29uZi5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTYyODg3MDM2MiwiZXhwIjoxNjI4ODcwNjYyLCJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYXV0aF90aW1lIjoxNjI4ODcwMzYyLCJub25jZSI6ImlNeGpQZWZhMkciLCJjX2hhc2giOiJMUVBTeE1XZGxOUXZxazJyVElhQVJRIiwic19oYXNoIjoid0U0TFBNWEJmQXBmUXFsblFBYUdLdyJ9.jCoe7u7iw8CszZ7IAt58n7edYwI0zqc7baBXkv11Gmv9paOaTgKizqbulTqLq0yATtGxMZuExa_N3VqNiJ8zp__zuGvINUrKcZk28pWrfR2ZPatc0mQ0MkUS34bIahbounu1zI4JRYHD1B7ewCQSkHu_ox-h-PLDIuu1Xtmx22v6WnABhTvbJ9Iphe8llP5wjHKLrXgZFMhuq6rYjYFPnwtkwvVvd4QJqzWiA9N7kIkqdhgPKh45Ia9Mss-DKir6rtiOltmEPSZ15POXelcF_yQHwS0szERINg3m8GqzSdmFzc4FumWFa5WUXyNcVkyONGVPMWzJ4BGuaTCV8nm9Rg&state=t51zdo4fFG
2021-08-13 15:59:23 OUTGOING
fapi1-advanced-final
Response to HTTP request to test instance wCkrQW9Zx2JRQay
outgoing_status_code
204
outgoing_headers
{}
outgoing_body

                                
outgoing_path
implicit/0QRPw4AM2auAPTFodq91
2021-08-13 15:59:23
ExtractImplicitHashToCallbackResponse
Extracted response from URL fragment
parameters
[
  {
    "name": "code",
    "value": "6yqwMKk5gKH0biUZFr1vSf6mCvdkN-aGgS4s68Eh"
  },
  {
    "name": "id_token",
    "value": "eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJqdGkiOiJ5RnZHWjF6OFA1bGdxckJyc3BHTG9vIiwiaXNzIjoiaHR0cHM6Ly9pZHAuY29uZi5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTYyODg3MDM2MiwiZXhwIjoxNjI4ODcwNjYyLCJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYXV0aF90aW1lIjoxNjI4ODcwMzYyLCJub25jZSI6ImlNeGpQZWZhMkciLCJjX2hhc2giOiJMUVBTeE1XZGxOUXZxazJyVElhQVJRIiwic19oYXNoIjoid0U0TFBNWEJmQXBmUXFsblFBYUdLdyJ9.jCoe7u7iw8CszZ7IAt58n7edYwI0zqc7baBXkv11Gmv9paOaTgKizqbulTqLq0yATtGxMZuExa_N3VqNiJ8zp__zuGvINUrKcZk28pWrfR2ZPatc0mQ0MkUS34bIahbounu1zI4JRYHD1B7ewCQSkHu_ox-h-PLDIuu1Xtmx22v6WnABhTvbJ9Iphe8llP5wjHKLrXgZFMhuq6rYjYFPnwtkwvVvd4QJqzWiA9N7kIkqdhgPKh45Ia9Mss-DKir6rtiOltmEPSZ15POXelcF_yQHwS0szERINg3m8GqzSdmFzc4FumWFa5WUXyNcVkyONGVPMWzJ4BGuaTCV8nm9Rg"
  },
  {
    "name": "state",
    "value": "t51zdo4fFG"
  }
]
2021-08-13 15:59:23 SUCCESS
ExtractImplicitHashToCallbackResponse
Extracted the hash values
code
6yqwMKk5gKH0biUZFr1vSf6mCvdkN-aGgS4s68Eh
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJqdGkiOiJ5RnZHWjF6OFA1bGdxckJyc3BHTG9vIiwiaXNzIjoiaHR0cHM6Ly9pZHAuY29uZi5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTYyODg3MDM2MiwiZXhwIjoxNjI4ODcwNjYyLCJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYXV0aF90aW1lIjoxNjI4ODcwMzYyLCJub25jZSI6ImlNeGpQZWZhMkciLCJjX2hhc2giOiJMUVBTeE1XZGxOUXZxazJyVElhQVJRIiwic19oYXNoIjoid0U0TFBNWEJmQXBmUXFsblFBYUdLdyJ9.jCoe7u7iw8CszZ7IAt58n7edYwI0zqc7baBXkv11Gmv9paOaTgKizqbulTqLq0yATtGxMZuExa_N3VqNiJ8zp__zuGvINUrKcZk28pWrfR2ZPatc0mQ0MkUS34bIahbounu1zI4JRYHD1B7ewCQSkHu_ox-h-PLDIuu1Xtmx22v6WnABhTvbJ9Iphe8llP5wjHKLrXgZFMhuq6rYjYFPnwtkwvVvd4QJqzWiA9N7kIkqdhgPKh45Ia9Mss-DKir6rtiOltmEPSZ15POXelcF_yQHwS0szERINg3m8GqzSdmFzc4FumWFa5WUXyNcVkyONGVPMWzJ4BGuaTCV8nm9Rg
state
t51zdo4fFG
2021-08-13 15:59:23 REDIRECT-IN
fapi1-advanced-final
Authorization endpoint response captured
url_query
{}
headers
{
  "host": "www.certification.openid.net",
  "upgrade-insecure-requests": "1",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.72 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "same-origin",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "referer": "https://idp.conf.ping-eng.com:9031/as/ugqqv/resume/as/authorization.ping",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9",
  "origin": "https://idp.conf.ping-eng.com:9031",
  "cache-control": "max-age\u003d0",
  "x-ssl-cipher": "ECDHE-RSA-AES256-GCM-SHA384",
  "x-ssl-protocol": "TLSv1.2",
  "connection": "close",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net"
}
http_method
GET
url_fragment
{
  "code": "6yqwMKk5gKH0biUZFr1vSf6mCvdkN-aGgS4s68Eh",
  "id_token": "eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJqdGkiOiJ5RnZHWjF6OFA1bGdxckJyc3BHTG9vIiwiaXNzIjoiaHR0cHM6Ly9pZHAuY29uZi5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTYyODg3MDM2MiwiZXhwIjoxNjI4ODcwNjYyLCJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYXV0aF90aW1lIjoxNjI4ODcwMzYyLCJub25jZSI6ImlNeGpQZWZhMkciLCJjX2hhc2giOiJMUVBTeE1XZGxOUXZxazJyVElhQVJRIiwic19oYXNoIjoid0U0TFBNWEJmQXBmUXFsblFBYUdLdyJ9.jCoe7u7iw8CszZ7IAt58n7edYwI0zqc7baBXkv11Gmv9paOaTgKizqbulTqLq0yATtGxMZuExa_N3VqNiJ8zp__zuGvINUrKcZk28pWrfR2ZPatc0mQ0MkUS34bIahbounu1zI4JRYHD1B7ewCQSkHu_ox-h-PLDIuu1Xtmx22v6WnABhTvbJ9Iphe8llP5wjHKLrXgZFMhuq6rYjYFPnwtkwvVvd4QJqzWiA9N7kIkqdhgPKh45Ia9Mss-DKir6rtiOltmEPSZ15POXelcF_yQHwS0szERINg3m8GqzSdmFzc4FumWFa5WUXyNcVkyONGVPMWzJ4BGuaTCV8nm9Rg",
  "state": "t51zdo4fFG"
}
post_body
Verify authorization endpoint response
2021-08-13 15:59:23 SUCCESS
RejectErrorInUrlQuery
'error' is not present in URL query returned from authorization endpoint
2021-08-13 15:59:23 SUCCESS
RejectAuthCodeInUrlQuery
Authorization code is not present in URL query returned from authorization endpoint
2021-08-13 15:59:23 SUCCESS
CheckMatchingCallbackParameters
Callback parameters successfully verified
2021-08-13 15:59:23 SUCCESS
RejectStateInUrlQueryForHybridFlow
state is correctly not present in URL query returned from authorization endpoint (as in the hybrid flow it must be returned in the URL fragment/hash only)
2021-08-13 15:59:23 SUCCESS
CheckIfAuthorizationEndpointError
No error from authorization endpoint
2021-08-13 15:59:23 SUCCESS
ValidateSuccessfulHybridResponseFromAuthorizationEndpoint
authorization endpoint response does not include unexpected parameters
code
6yqwMKk5gKH0biUZFr1vSf6mCvdkN-aGgS4s68Eh
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJqdGkiOiJ5RnZHWjF6OFA1bGdxckJyc3BHTG9vIiwiaXNzIjoiaHR0cHM6Ly9pZHAuY29uZi5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTYyODg3MDM2MiwiZXhwIjoxNjI4ODcwNjYyLCJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYXV0aF90aW1lIjoxNjI4ODcwMzYyLCJub25jZSI6ImlNeGpQZWZhMkciLCJjX2hhc2giOiJMUVBTeE1XZGxOUXZxazJyVElhQVJRIiwic19oYXNoIjoid0U0TFBNWEJmQXBmUXFsblFBYUdLdyJ9.jCoe7u7iw8CszZ7IAt58n7edYwI0zqc7baBXkv11Gmv9paOaTgKizqbulTqLq0yATtGxMZuExa_N3VqNiJ8zp__zuGvINUrKcZk28pWrfR2ZPatc0mQ0MkUS34bIahbounu1zI4JRYHD1B7ewCQSkHu_ox-h-PLDIuu1Xtmx22v6WnABhTvbJ9Iphe8llP5wjHKLrXgZFMhuq6rYjYFPnwtkwvVvd4QJqzWiA9N7kIkqdhgPKh45Ia9Mss-DKir6rtiOltmEPSZ15POXelcF_yQHwS0szERINg3m8GqzSdmFzc4FumWFa5WUXyNcVkyONGVPMWzJ4BGuaTCV8nm9Rg
state
t51zdo4fFG
2021-08-13 15:59:23 SUCCESS
CheckStateInAuthorizationResponse
State in response correctly returned
state
t51zdo4fFG
2021-08-13 15:59:23
ValidateIssInAuthorizationResponse
No 'iss' value in authorization response.
2021-08-13 15:59:23 SUCCESS
ExtractAuthorizationCodeFromAuthorizationResponse
Found authorization code
code
6yqwMKk5gKH0biUZFr1vSf6mCvdkN-aGgS4s68Eh
2021-08-13 15:59:23 SUCCESS
EnsureMinimumAuthorizationCodeLength
Authorization code is of sufficient length
actual
320
required
128
2021-08-13 15:59:23 SUCCESS
EnsureMinimumAuthorizationCodeEntropy
Calculated shannon entropy seems sufficient
actual
198.122236293331
expected
96.0
2021-08-13 15:59:23 SUCCESS
ExtractIdTokenFromAuthorizationResponse
Found and parsed the id_token from authorization_endpoint_response
value
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJqdGkiOiJ5RnZHWjF6OFA1bGdxckJyc3BHTG9vIiwiaXNzIjoiaHR0cHM6Ly9pZHAuY29uZi5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTYyODg3MDM2MiwiZXhwIjoxNjI4ODcwNjYyLCJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYXV0aF90aW1lIjoxNjI4ODcwMzYyLCJub25jZSI6ImlNeGpQZWZhMkciLCJjX2hhc2giOiJMUVBTeE1XZGxOUXZxazJyVElhQVJRIiwic19oYXNoIjoid0U0TFBNWEJmQXBmUXFsblFBYUdLdyJ9.jCoe7u7iw8CszZ7IAt58n7edYwI0zqc7baBXkv11Gmv9paOaTgKizqbulTqLq0yATtGxMZuExa_N3VqNiJ8zp__zuGvINUrKcZk28pWrfR2ZPatc0mQ0MkUS34bIahbounu1zI4JRYHD1B7ewCQSkHu_ox-h-PLDIuu1Xtmx22v6WnABhTvbJ9Iphe8llP5wjHKLrXgZFMhuq6rYjYFPnwtkwvVvd4QJqzWiA9N7kIkqdhgPKh45Ia9Mss-DKir6rtiOltmEPSZ15POXelcF_yQHwS0szERINg3m8GqzSdmFzc4FumWFa5WUXyNcVkyONGVPMWzJ4BGuaTCV8nm9Rg
header
{
  "kid": "NfGZj3wtxSjC-G5ZOsy0GIrGqwU",
  "alg": "PS256"
}
claims
{
  "sub": "joe",
  "aud": "fapi_adv_op_w_private_key_par_first_client",
  "acr": "urn:mace:incommon:iap:silver",
  "c_hash": "LQPSxMWdlNQvqk2rTIaARQ",
  "s_hash": "wE4LPMXBfApfQqlnQAaGKw",
  "auth_time": 1628870362,
  "iss": "https://idp.conf.ping-eng.com:9031",
  "exp": 1628870662,
  "iat": 1628870362,
  "nonce": "iMxjPefa2G",
  "jti": "yFvGZ1z8P5lgqrBrspGLoo"
}
2021-08-13 15:59:23 SUCCESS
ValidateIdToken
ID token iss, aud, exp, iat, auth_time, acr & nbf claims passed validation checks
2021-08-13 15:59:23 SUCCESS
EnsureIdTokenContainsKid
kid was found in the ID token header
kid
NfGZj3wtxSjC-G5ZOsy0GIrGqwU
2021-08-13 15:59:23 SUCCESS
ValidateIdTokenNonce
Nonce values match
nonce
iMxjPefa2G
2021-08-13 15:59:23 SUCCESS
ValidateIdTokenACRClaimAgainstRequest
acr value in id_token is (one of) the requested values
actual
urn:mace:incommon:iap:silver
requested
[
  "urn:mace:incommon:iap:silver"
]
2021-08-13 15:59:23 SUCCESS
ValidateIdTokenSignature
id_token signature validated
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJqdGkiOiJ5RnZHWjF6OFA1bGdxckJyc3BHTG9vIiwiaXNzIjoiaHR0cHM6Ly9pZHAuY29uZi5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTYyODg3MDM2MiwiZXhwIjoxNjI4ODcwNjYyLCJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYXV0aF90aW1lIjoxNjI4ODcwMzYyLCJub25jZSI6ImlNeGpQZWZhMkciLCJjX2hhc2giOiJMUVBTeE1XZGxOUXZxazJyVElhQVJRIiwic19oYXNoIjoid0U0TFBNWEJmQXBmUXFsblFBYUdLdyJ9.jCoe7u7iw8CszZ7IAt58n7edYwI0zqc7baBXkv11Gmv9paOaTgKizqbulTqLq0yATtGxMZuExa_N3VqNiJ8zp__zuGvINUrKcZk28pWrfR2ZPatc0mQ0MkUS34bIahbounu1zI4JRYHD1B7ewCQSkHu_ox-h-PLDIuu1Xtmx22v6WnABhTvbJ9Iphe8llP5wjHKLrXgZFMhuq6rYjYFPnwtkwvVvd4QJqzWiA9N7kIkqdhgPKh45Ia9Mss-DKir6rtiOltmEPSZ15POXelcF_yQHwS0szERINg3m8GqzSdmFzc4FumWFa5WUXyNcVkyONGVPMWzJ4BGuaTCV8nm9Rg
2021-08-13 15:59:23 SUCCESS
ValidateIdTokenSignatureUsingKid
id_token signature validated
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJqdGkiOiJ5RnZHWjF6OFA1bGdxckJyc3BHTG9vIiwiaXNzIjoiaHR0cHM6Ly9pZHAuY29uZi5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTYyODg3MDM2MiwiZXhwIjoxNjI4ODcwNjYyLCJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYXV0aF90aW1lIjoxNjI4ODcwMzYyLCJub25jZSI6ImlNeGpQZWZhMkciLCJjX2hhc2giOiJMUVBTeE1XZGxOUXZxazJyVElhQVJRIiwic19oYXNoIjoid0U0TFBNWEJmQXBmUXFsblFBYUdLdyJ9.jCoe7u7iw8CszZ7IAt58n7edYwI0zqc7baBXkv11Gmv9paOaTgKizqbulTqLq0yATtGxMZuExa_N3VqNiJ8zp__zuGvINUrKcZk28pWrfR2ZPatc0mQ0MkUS34bIahbounu1zI4JRYHD1B7ewCQSkHu_ox-h-PLDIuu1Xtmx22v6WnABhTvbJ9Iphe8llP5wjHKLrXgZFMhuq6rYjYFPnwtkwvVvd4QJqzWiA9N7kIkqdhgPKh45Ia9Mss-DKir6rtiOltmEPSZ15POXelcF_yQHwS0szERINg3m8GqzSdmFzc4FumWFa5WUXyNcVkyONGVPMWzJ4BGuaTCV8nm9Rg
2021-08-13 15:59:23 SUCCESS
CheckForSubjectInIdToken
Found 'sub' in id_token
sub
joe
2021-08-13 15:59:23 SUCCESS
FAPIValidateIdTokenSigningAlg
id_token was signed with a permitted algorithm
permitted
[
  "ES256",
  "PS256"
]
alg
PS256
2021-08-13 15:59:23 INFO
FAPIValidateIdTokenEncryptionAlg
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2021-08-13 15:59:23 INFO
FAPIValidateEncryptedIdTokenHasKid
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2021-08-13 15:59:23 SUCCESS
ExtractSHash
Extracted s_hash from ID Token
s_hash
wE4LPMXBfApfQqlnQAaGKw
alg
PS256
2021-08-13 15:59:23 SUCCESS
ValidateSHash
s_hash validated successfully
expected_hash
wE4LPMXBfApfQqlnQAaGKw
unhashed_value
t51zdo4fFG
id_token_hash
wE4LPMXBfApfQqlnQAaGKw
2021-08-13 15:59:23 SUCCESS
ExtractCHash
Extracted c_hash from ID Token
c_hash
LQPSxMWdlNQvqk2rTIaARQ
alg
PS256
2021-08-13 15:59:23 SUCCESS
ValidateCHash
c_hash validated successfully
expected_hash
LQPSxMWdlNQvqk2rTIaARQ
unhashed_value
6yqwMKk5gKH0biUZFr1vSf6mCvdkN-aGgS4s68Eh
id_token_hash
LQPSxMWdlNQvqk2rTIaARQ
Call token endpoint
2021-08-13 15:59:23 SUCCESS
CreateTokenEndpointRequestForAuthorizationCodeGrant
grant_type
authorization_code
code
6yqwMKk5gKH0biUZFr1vSf6mCvdkN-aGgS4s68Eh
redirect_uri
https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback
2021-08-13 15:59:23 SUCCESS
CreateClientAuthenticationAssertionClaims
Created client assertion claims
iss
fapi_adv_op_w_private_key_par_first_client
sub
fapi_adv_op_w_private_key_par_first_client
aud
https://idp.conf.ping-eng.com:9032/as/token.oauth2
jti
GP2ERt8azDYBHwddGks1
iat
1628870363
exp
1628870423
2021-08-13 15:59:23 SUCCESS
SignClientAuthenticationAssertion
Signed the client assertion
client_assertion
eyJraWQiOiJwaW5nZmVkZXJhdGUtZmFwaS1qd3QtYXNzZXJ0aW9uLWNsaWVudDEiLCJhbGciOiJQUzI1NiJ9.eyJzdWIiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJhdWQiOiJodHRwczpcL1wvaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJleHAiOjE2Mjg4NzA0MjMsImlhdCI6MTYyODg3MDM2MywianRpIjoiR1AyRVJ0OGF6RFlCSHdkZEdrczEifQ.SUIIy1FFUIYQ2cilbUyz77MJI102hnnfAaGcJZAq0tUCqB9QOFPn7XP8XYgZhM6Z9Fm6GpXSnyfa6lvIVMF_iGlTe70tbw0Tek-fAV-gsgtagxbBnwAJovA39duypoSww5nMxzHll-3aIm5MiOr8PqWzNQ8u809mFwYXB4uOLR7fMQEebdwBr6JG_GAmydMKImMO-VrTrDam5Ufgvg0cmXq4lMC5PgiUlBgBe6eNJBNvs01Pfg1K9odi2vQ_vYKCzqLaQ2WpIRhON1uv9CENbpou5npNjISMaqEUgbKmzG7ljyjaD9CmOMv2F8q1Bru5ZBLiqgwdqHFdV8N2Q25ecQ
2021-08-13 15:59:23
AddClientAssertionToTokenEndpointRequest
Added client assertion
grant_type
authorization_code
code
6yqwMKk5gKH0biUZFr1vSf6mCvdkN-aGgS4s68Eh
redirect_uri
https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback
client_assertion
eyJraWQiOiJwaW5nZmVkZXJhdGUtZmFwaS1qd3QtYXNzZXJ0aW9uLWNsaWVudDEiLCJhbGciOiJQUzI1NiJ9.eyJzdWIiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJhdWQiOiJodHRwczpcL1wvaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJleHAiOjE2Mjg4NzA0MjMsImlhdCI6MTYyODg3MDM2MywianRpIjoiR1AyRVJ0OGF6RFlCSHdkZEdrczEifQ.SUIIy1FFUIYQ2cilbUyz77MJI102hnnfAaGcJZAq0tUCqB9QOFPn7XP8XYgZhM6Z9Fm6GpXSnyfa6lvIVMF_iGlTe70tbw0Tek-fAV-gsgtagxbBnwAJovA39duypoSww5nMxzHll-3aIm5MiOr8PqWzNQ8u809mFwYXB4uOLR7fMQEebdwBr6JG_GAmydMKImMO-VrTrDam5Ufgvg0cmXq4lMC5PgiUlBgBe6eNJBNvs01Pfg1K9odi2vQ_vYKCzqLaQ2WpIRhON1uv9CENbpou5npNjISMaqEUgbKmzG7ljyjaD9CmOMv2F8q1Bru5ZBLiqgwdqHFdV8N2Q25ecQ
client_assertion_type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-08-13 15:59:23
AddCodeVerifierToTokenEndpointRequest
grant_type
authorization_code
code
6yqwMKk5gKH0biUZFr1vSf6mCvdkN-aGgS4s68Eh
redirect_uri
https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback
client_assertion
eyJraWQiOiJwaW5nZmVkZXJhdGUtZmFwaS1qd3QtYXNzZXJ0aW9uLWNsaWVudDEiLCJhbGciOiJQUzI1NiJ9.eyJzdWIiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJhdWQiOiJodHRwczpcL1wvaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJleHAiOjE2Mjg4NzA0MjMsImlhdCI6MTYyODg3MDM2MywianRpIjoiR1AyRVJ0OGF6RFlCSHdkZEdrczEifQ.SUIIy1FFUIYQ2cilbUyz77MJI102hnnfAaGcJZAq0tUCqB9QOFPn7XP8XYgZhM6Z9Fm6GpXSnyfa6lvIVMF_iGlTe70tbw0Tek-fAV-gsgtagxbBnwAJovA39duypoSww5nMxzHll-3aIm5MiOr8PqWzNQ8u809mFwYXB4uOLR7fMQEebdwBr6JG_GAmydMKImMO-VrTrDam5Ufgvg0cmXq4lMC5PgiUlBgBe6eNJBNvs01Pfg1K9odi2vQ_vYKCzqLaQ2WpIRhON1uv9CENbpou5npNjISMaqEUgbKmzG7ljyjaD9CmOMv2F8q1Bru5ZBLiqgwdqHFdV8N2Q25ecQ
client_assertion_type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
code_verifier
D9uW9olR-KvJs9CrBQ8J3YntSTFcdMcIRLyt53B-t_Q5ooIwvL-1WEFgsTwd1zOJSwtf8wwidzhqzo6rwWXFKT3Cx1BPd8NZv6PLZahxr3HRH~cAhzu9rPK2z5K-LRMI
2021-08-13 15:59:23
CallTokenEndpoint
HTTP request
request_uri
https://idp.conf.ping-eng.com:9032/as/token.oauth2
request_method
POST
request_headers
{
  "accept": "application/json;charset\u003dUTF-8",
  "accept-charset": "utf-8",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "1199"
}
request_body
grant_type=authorization_code&code=6yqwMKk5gKH0biUZFr1vSf6mCvdkN-aGgS4s68Eh&redirect_uri=https%3A%2F%2Fwww.certification.openid.net%2Ftest%2Fa%2Fpingidentity-pingfederate-fapi-adv-op-private-key-par-plain%2Fcallback&client_assertion=eyJraWQiOiJwaW5nZmVkZXJhdGUtZmFwaS1qd3QtYXNzZXJ0aW9uLWNsaWVudDEiLCJhbGciOiJQUzI1NiJ9.eyJzdWIiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJhdWQiOiJodHRwczpcL1wvaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzJcL2FzXC90b2tlbi5vYXV0aDIiLCJpc3MiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJleHAiOjE2Mjg4NzA0MjMsImlhdCI6MTYyODg3MDM2MywianRpIjoiR1AyRVJ0OGF6RFlCSHdkZEdrczEifQ.SUIIy1FFUIYQ2cilbUyz77MJI102hnnfAaGcJZAq0tUCqB9QOFPn7XP8XYgZhM6Z9Fm6GpXSnyfa6lvIVMF_iGlTe70tbw0Tek-fAV-gsgtagxbBnwAJovA39duypoSww5nMxzHll-3aIm5MiOr8PqWzNQ8u809mFwYXB4uOLR7fMQEebdwBr6JG_GAmydMKImMO-VrTrDam5Ufgvg0cmXq4lMC5PgiUlBgBe6eNJBNvs01Pfg1K9odi2vQ_vYKCzqLaQ2WpIRhON1uv9CENbpou5npNjISMaqEUgbKmzG7ljyjaD9CmOMv2F8q1Bru5ZBLiqgwdqHFdV8N2Q25ecQ&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer&code_verifier=D9uW9olR-KvJs9CrBQ8J3YntSTFcdMcIRLyt53B-t_Q5ooIwvL-1WEFgsTwd1zOJSwtf8wwidzhqzo6rwWXFKT3Cx1BPd8NZv6PLZahxr3HRH%7EcAhzu9rPK2z5K-LRMI
request_mutual_tls
{
  "cert": "MIID3TCCAsWgAwIBAgIUIi7yAbDDmWkZjI8CwjLBVkswVkIwDQYJKoZIhvcNAQELBQAwfTELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAkNPMQ8wDQYDVQQHDAZEZW52ZXIxFTATBgNVBAoMDFBpbmdJZGVudGl0eTEUMBIGA1UECwwLRGV2ZWxvcG1lbnQxIzAhBgNVBAMMGkZBUEkgQWR2IE9QIHcgRmlyc3QgQ2xpZW50MCAXDTIxMDcyNjIyMzQzN1oYDzIxMjEwNzAyMjIzNDM3WjB9MQswCQYDVQQGEwJVUzELMAkGA1UECAwCQ08xDzANBgNVBAcMBkRlbnZlcjEVMBMGA1UECgwMUGluZ0lkZW50aXR5MRQwEgYDVQQLDAtEZXZlbG9wbWVudDEjMCEGA1UEAwwaRkFQSSBBZHYgT1AgdyBGaXJzdCBDbGllbnQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCa91hiBBEaNcRdvQ0Gvg06mzaIQpa17vgtP77HwtV0FvH+3imrnqmaCcpEnWGMv/udX8S5r/VAeUPB2Q31187vKDLKxbadWTKuSNQajOkRyiXZzutbEQbN/t7JAz7oETujYoOTlMNT4N9twYvKEvxTeZAWNUCQHXZcESKYXhph0eZaaOvNo7WqQ+ygGBzgTVev6tXr/Q2+M3NkBnSvRYegSN5ZtmIXMrNVaH7D+SC8QUPWxsB8ZVIENzBhCI8+brrPjyLNqVKoI9O7Hjdgzb8Xs+gC98ATmsbQrE/8pRdYYCPkEoETAWRq2T/dEf7NE+AMerttKk9TdNwvbB1WbAoHAgMBAAGjUzBRMB0GA1UdDgQWBBTr8p3YWM2Rtw/BAQaellNa1RUKSTAfBgNVHSMEGDAWgBTr8p3YWM2Rtw/BAQaellNa1RUKSTAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQB17ygVKcEpZxP4XML98KyUycNxsyHcKdIo2GZCRsmwjDR5nRcdWlE+tI50sduSaAR+gSbDFR/dqBxl0lBEMLj6Rqpson+z17jv68fU9H7l7JLfI5xAXuW4s1Kg/xBcYBy7QJkU9CTMIb6TBQESCbTUq89aCX4fT8WQleCflRJjSuzzdpVWd0PIhcxCoxpa/BcXtK0gf/z0rimF4jJKv40rqdf0LGsVzKQ9TxQIDWk0tov4FkvBw63VUp6b7PWdEHi4E9uKgHxh2Pj+VykK33nCmUsGXENfj4SSkY2O00iDw3oHfC8xmWvgqsTdlzJm1qhZCZGNOsdWLEv6hGl4XLyr",
  "key": "MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQCa91hiBBEaNcRdvQ0Gvg06mzaIQpa17vgtP77HwtV0FvH+3imrnqmaCcpEnWGMv/udX8S5r/VAeUPB2Q31187vKDLKxbadWTKuSNQajOkRyiXZzutbEQbN/t7JAz7oETujYoOTlMNT4N9twYvKEvxTeZAWNUCQHXZcESKYXhph0eZaaOvNo7WqQ+ygGBzgTVev6tXr/Q2+M3NkBnSvRYegSN5ZtmIXMrNVaH7D+SC8QUPWxsB8ZVIENzBhCI8+brrPjyLNqVKoI9O7Hjdgzb8Xs+gC98ATmsbQrE/8pRdYYCPkEoETAWRq2T/dEf7NE+AMerttKk9TdNwvbB1WbAoHAgMBAAECggEAf4aFKUQHfvY4PpvRGHdWE6CfY8rIk7ewbCxFJ8biOcKYKxFQYXcUQztDROvu1xE2Uu/4yIZQ4VnptKCWqHWMSatfARdrjFlXJ62vPpovQwCD3ZY2gJ6mZucTF4CgSAHGflIXzV9izqgDtiLMkuLE2zzyohP4qaBVQranLZRjSZNWeGvEpkcf7Nv7FlfZaOJ/FkcGwyFn7iSzX/KRL/1TA6zDlreA3PGJr96i9SmFHQsurFv7quRxEUFoSVxVtn5IiOJji45Evte8KAhMzlau1MuAlKxiIJAMIPN2l1nTRTRZUybDBoLp9CkkAmvp75krld9NB/hbWaeRsxhgVPXYwQKBgQDMsai5QHJAFZ5P31LN0dvlvcj0X2dPS0hEd6NsIf5DkbQKHQuVlxdIGhChLhVBdkGUt9ZYSflxlUtc8GUG3+e0TKg+ZAHNakueV73TGZy3BAzQBxwQBMqUltcXWMjWBaDnbQH+TrtYP0A+ZdHd4gnBNuSUuv5R7IxGWHgfcvtnuQKBgQDBzt2kGjDXXPV4qrtmGl4KaCAvsFr76VsVr8879MhrVgevI5vbsBNWQ3yvykXLr5B6s0VaqibvgDTcchQvqwtoEeDQfHsSHnAglGYCAi06hwGArTW/hxW0L7IivB+laFsbPY2HbnGZ6WUOjMNTgGAihbbLd6+IvLJEVdn7gjxfvwKBgD/DS9rBP5XE5jbdS08AA27yiqnNGkJyIgXp+sdRY4Iq3hmUaKplkYQNUobS8x4cN1ubVLLWAFUoe3xtCht1HhllE7ezsXgKl5mwnVooDVBZe6BFxrEavPxCbKhCKPW6dSACLe/JGMTplxqY3yIuKnm8nsHR6i0c8alsH6c0SypJAoGBALcVCn+5ViY8ZI9nCby8b9X4417phCmxGiB0gpoq9SGglYW3Z8ayoLG+8wzFUgXGhf/DVmL9leZuAIG3KqaVOCNJsEyDK2fEZTwBtBN1pvBBFQRPnBSgMbqTy/3QJT0GRfqHvSkRBjPVLWf/RY2eGjLCihnPqHzNdMHlMBTNxObVAoGAMRDZNtM0vIUNbjY5YFK0AoetPqR1mS2fWOFdCVnyHYBOJmmUZbU4oNZk5HmHBOC8N7aOELyXu56I4yEw0KUjOphKGfA9b2553q1A6t1x1oHBIwVuj1W3sEpUOtj2fWwmmdqjEyRsdzEJWfOuOEFzbfaw1pClq9IbngVcDGfzg74\u003d"
}
2021-08-13 15:59:23 RESPONSE
CallTokenEndpoint
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "date": "Fri, 13 Aug 2021 15:59:23 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003dzQAoTwzrzrpbIXsS5zp7Nk; Path\u003d/; Secure; HttpOnly; SameSite\u003dNone",
  "transfer-encoding": "chunked"
}
response_body
{"access_token":"eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSIsInBpLmF0bSI6ImE5Z2kifQ.eyJzY29wZSI6Im9wZW5pZCBwYXltZW50cyIsImNsaWVudF9pZCI6ImZhcGlfYWR2X29wX3dfcHJpdmF0ZV9rZXlfcGFyX2ZpcnN0X2NsaWVudCIsInN1YiI6ImpvZSIsInBpLnVrIjoiam9lIiwiY25mIjp7Ing1dCNTMjU2IjoianIyRnRSWWFmb2hiQ1oyelAtN2lpSTUzUXlDRXBNeFBtb19sN2hCSEdaSSJ9LCJleHAiOjE2Mjg4Nzc1NjN9.jRt2961Rfutwd5CC9LTZcWJq88PEZ_wcSqaTAdPoIAbiIm_V3fWk_nHsiD8B7iT4BMIjz6f7cti2YNHzeyTHXwG1X0jskwDZHeMB7iBzKVpqteRNs8RgX5_nYL_2OQQZft2jm6uFIJXtw6mZZ4huKljXdQi4qzHHT4R43bFF61JSuEvYr2X69a4vveJvmF6AwT5JkOYR6dRextgI3oe56R_hIshD4LR4vV03ouA-EGuWokZALwgSaHzX_3hEr2OSf8_9FbWbmpjcb0dW1eZVI0tLCmm2TxlphVzll0zmWZC44M7q5NZa-lstbrGj2MP0OxV2p6hUjrFCY2H6l_jy9w","refresh_token":"lVDNCPUXcSUTmwdvmf7DVy19PH0Sqp27JHyuv6CJ80","id_token":"eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJqdGkiOiJ5RnZHWjF6OFA1bGdxckJyc3BHTG9vIiwiaXNzIjoiaHR0cHM6Ly9pZHAuY29uZi5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTYyODg3MDM2MiwiZXhwIjoxNjI4ODcwNjYyLCJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYXV0aF90aW1lIjoxNjI4ODcwMzYyLCJub25jZSI6ImlNeGpQZWZhMkciLCJjX2hhc2giOiJMUVBTeE1XZGxOUXZxazJyVElhQVJRIiwic19oYXNoIjoid0U0TFBNWEJmQXBmUXFsblFBYUdLdyJ9.jCoe7u7iw8CszZ7IAt58n7edYwI0zqc7baBXkv11Gmv9paOaTgKizqbulTqLq0yATtGxMZuExa_N3VqNiJ8zp__zuGvINUrKcZk28pWrfR2ZPatc0mQ0MkUS34bIahbounu1zI4JRYHD1B7ewCQSkHu_ox-h-PLDIuu1Xtmx22v6WnABhTvbJ9Iphe8llP5wjHKLrXgZFMhuq6rYjYFPnwtkwvVvd4QJqzWiA9N7kIkqdhgPKh45Ia9Mss-DKir6rtiOltmEPSZ15POXelcF_yQHwS0szERINg3m8GqzSdmFzc4FumWFa5WUXyNcVkyONGVPMWzJ4BGuaTCV8nm9Rg","token_type":"Bearer","expires_in":7199}
2021-08-13 15:59:23
CallTokenEndpoint
Token endpoint response
token_endpoint_response
{"access_token":"eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSIsInBpLmF0bSI6ImE5Z2kifQ.eyJzY29wZSI6Im9wZW5pZCBwYXltZW50cyIsImNsaWVudF9pZCI6ImZhcGlfYWR2X29wX3dfcHJpdmF0ZV9rZXlfcGFyX2ZpcnN0X2NsaWVudCIsInN1YiI6ImpvZSIsInBpLnVrIjoiam9lIiwiY25mIjp7Ing1dCNTMjU2IjoianIyRnRSWWFmb2hiQ1oyelAtN2lpSTUzUXlDRXBNeFBtb19sN2hCSEdaSSJ9LCJleHAiOjE2Mjg4Nzc1NjN9.jRt2961Rfutwd5CC9LTZcWJq88PEZ_wcSqaTAdPoIAbiIm_V3fWk_nHsiD8B7iT4BMIjz6f7cti2YNHzeyTHXwG1X0jskwDZHeMB7iBzKVpqteRNs8RgX5_nYL_2OQQZft2jm6uFIJXtw6mZZ4huKljXdQi4qzHHT4R43bFF61JSuEvYr2X69a4vveJvmF6AwT5JkOYR6dRextgI3oe56R_hIshD4LR4vV03ouA-EGuWokZALwgSaHzX_3hEr2OSf8_9FbWbmpjcb0dW1eZVI0tLCmm2TxlphVzll0zmWZC44M7q5NZa-lstbrGj2MP0OxV2p6hUjrFCY2H6l_jy9w","refresh_token":"lVDNCPUXcSUTmwdvmf7DVy19PH0Sqp27JHyuv6CJ80","id_token":"eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJqdGkiOiJ5RnZHWjF6OFA1bGdxckJyc3BHTG9vIiwiaXNzIjoiaHR0cHM6Ly9pZHAuY29uZi5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTYyODg3MDM2MiwiZXhwIjoxNjI4ODcwNjYyLCJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYXV0aF90aW1lIjoxNjI4ODcwMzYyLCJub25jZSI6ImlNeGpQZWZhMkciLCJjX2hhc2giOiJMUVBTeE1XZGxOUXZxazJyVElhQVJRIiwic19oYXNoIjoid0U0TFBNWEJmQXBmUXFsblFBYUdLdyJ9.jCoe7u7iw8CszZ7IAt58n7edYwI0zqc7baBXkv11Gmv9paOaTgKizqbulTqLq0yATtGxMZuExa_N3VqNiJ8zp__zuGvINUrKcZk28pWrfR2ZPatc0mQ0MkUS34bIahbounu1zI4JRYHD1B7ewCQSkHu_ox-h-PLDIuu1Xtmx22v6WnABhTvbJ9Iphe8llP5wjHKLrXgZFMhuq6rYjYFPnwtkwvVvd4QJqzWiA9N7kIkqdhgPKh45Ia9Mss-DKir6rtiOltmEPSZ15POXelcF_yQHwS0szERINg3m8GqzSdmFzc4FumWFa5WUXyNcVkyONGVPMWzJ4BGuaTCV8nm9Rg","token_type":"Bearer","expires_in":7199}
2021-08-13 15:59:23 SUCCESS
CallTokenEndpoint
Parsed token endpoint response
access_token
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSIsInBpLmF0bSI6ImE5Z2kifQ.eyJzY29wZSI6Im9wZW5pZCBwYXltZW50cyIsImNsaWVudF9pZCI6ImZhcGlfYWR2X29wX3dfcHJpdmF0ZV9rZXlfcGFyX2ZpcnN0X2NsaWVudCIsInN1YiI6ImpvZSIsInBpLnVrIjoiam9lIiwiY25mIjp7Ing1dCNTMjU2IjoianIyRnRSWWFmb2hiQ1oyelAtN2lpSTUzUXlDRXBNeFBtb19sN2hCSEdaSSJ9LCJleHAiOjE2Mjg4Nzc1NjN9.jRt2961Rfutwd5CC9LTZcWJq88PEZ_wcSqaTAdPoIAbiIm_V3fWk_nHsiD8B7iT4BMIjz6f7cti2YNHzeyTHXwG1X0jskwDZHeMB7iBzKVpqteRNs8RgX5_nYL_2OQQZft2jm6uFIJXtw6mZZ4huKljXdQi4qzHHT4R43bFF61JSuEvYr2X69a4vveJvmF6AwT5JkOYR6dRextgI3oe56R_hIshD4LR4vV03ouA-EGuWokZALwgSaHzX_3hEr2OSf8_9FbWbmpjcb0dW1eZVI0tLCmm2TxlphVzll0zmWZC44M7q5NZa-lstbrGj2MP0OxV2p6hUjrFCY2H6l_jy9w
refresh_token
lVDNCPUXcSUTmwdvmf7DVy19PH0Sqp27JHyuv6CJ80
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJqdGkiOiJ5RnZHWjF6OFA1bGdxckJyc3BHTG9vIiwiaXNzIjoiaHR0cHM6Ly9pZHAuY29uZi5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTYyODg3MDM2MiwiZXhwIjoxNjI4ODcwNjYyLCJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYXV0aF90aW1lIjoxNjI4ODcwMzYyLCJub25jZSI6ImlNeGpQZWZhMkciLCJjX2hhc2giOiJMUVBTeE1XZGxOUXZxazJyVElhQVJRIiwic19oYXNoIjoid0U0TFBNWEJmQXBmUXFsblFBYUdLdyJ9.jCoe7u7iw8CszZ7IAt58n7edYwI0zqc7baBXkv11Gmv9paOaTgKizqbulTqLq0yATtGxMZuExa_N3VqNiJ8zp__zuGvINUrKcZk28pWrfR2ZPatc0mQ0MkUS34bIahbounu1zI4JRYHD1B7ewCQSkHu_ox-h-PLDIuu1Xtmx22v6WnABhTvbJ9Iphe8llP5wjHKLrXgZFMhuq6rYjYFPnwtkwvVvd4QJqzWiA9N7kIkqdhgPKh45Ia9Mss-DKir6rtiOltmEPSZ15POXelcF_yQHwS0szERINg3m8GqzSdmFzc4FumWFa5WUXyNcVkyONGVPMWzJ4BGuaTCV8nm9Rg
token_type
Bearer
expires_in
7199
Verify token endpoint response
2021-08-13 15:59:23 SUCCESS
CheckIfTokenEndpointResponseError
No error from token endpoint
2021-08-13 15:59:23 SUCCESS
CheckForAccessTokenValue
Found an access token
access_token
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSIsInBpLmF0bSI6ImE5Z2kifQ.eyJzY29wZSI6Im9wZW5pZCBwYXltZW50cyIsImNsaWVudF9pZCI6ImZhcGlfYWR2X29wX3dfcHJpdmF0ZV9rZXlfcGFyX2ZpcnN0X2NsaWVudCIsInN1YiI6ImpvZSIsInBpLnVrIjoiam9lIiwiY25mIjp7Ing1dCNTMjU2IjoianIyRnRSWWFmb2hiQ1oyelAtN2lpSTUzUXlDRXBNeFBtb19sN2hCSEdaSSJ9LCJleHAiOjE2Mjg4Nzc1NjN9.jRt2961Rfutwd5CC9LTZcWJq88PEZ_wcSqaTAdPoIAbiIm_V3fWk_nHsiD8B7iT4BMIjz6f7cti2YNHzeyTHXwG1X0jskwDZHeMB7iBzKVpqteRNs8RgX5_nYL_2OQQZft2jm6uFIJXtw6mZZ4huKljXdQi4qzHHT4R43bFF61JSuEvYr2X69a4vveJvmF6AwT5JkOYR6dRextgI3oe56R_hIshD4LR4vV03ouA-EGuWokZALwgSaHzX_3hEr2OSf8_9FbWbmpjcb0dW1eZVI0tLCmm2TxlphVzll0zmWZC44M7q5NZa-lstbrGj2MP0OxV2p6hUjrFCY2H6l_jy9w
2021-08-13 15:59:23 SUCCESS
ExtractAccessTokenFromTokenResponse
Extracted the access token
value
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSIsInBpLmF0bSI6ImE5Z2kifQ.eyJzY29wZSI6Im9wZW5pZCBwYXltZW50cyIsImNsaWVudF9pZCI6ImZhcGlfYWR2X29wX3dfcHJpdmF0ZV9rZXlfcGFyX2ZpcnN0X2NsaWVudCIsInN1YiI6ImpvZSIsInBpLnVrIjoiam9lIiwiY25mIjp7Ing1dCNTMjU2IjoianIyRnRSWWFmb2hiQ1oyelAtN2lpSTUzUXlDRXBNeFBtb19sN2hCSEdaSSJ9LCJleHAiOjE2Mjg4Nzc1NjN9.jRt2961Rfutwd5CC9LTZcWJq88PEZ_wcSqaTAdPoIAbiIm_V3fWk_nHsiD8B7iT4BMIjz6f7cti2YNHzeyTHXwG1X0jskwDZHeMB7iBzKVpqteRNs8RgX5_nYL_2OQQZft2jm6uFIJXtw6mZZ4huKljXdQi4qzHHT4R43bFF61JSuEvYr2X69a4vveJvmF6AwT5JkOYR6dRextgI3oe56R_hIshD4LR4vV03ouA-EGuWokZALwgSaHzX_3hEr2OSf8_9FbWbmpjcb0dW1eZVI0tLCmm2TxlphVzll0zmWZC44M7q5NZa-lstbrGj2MP0OxV2p6hUjrFCY2H6l_jy9w
type
Bearer
2021-08-13 15:59:23 SUCCESS
ExtractExpiresInFromTokenEndpointResponse
Extracted 'expires_in'
expires_in
7199
2021-08-13 15:59:23 SUCCESS
ValidateExpiresIn
expires_in passed all validation checks
expires_in
7199
2021-08-13 15:59:23 SUCCESS
CheckForRefreshTokenValue
Found a refresh token
refresh_token
lVDNCPUXcSUTmwdvmf7DVy19PH0Sqp27JHyuv6CJ80
2021-08-13 15:59:23 SUCCESS
EnsureMinimumRefreshTokenLength
Refresh token is of sufficient length
actual
336
required
128
2021-08-13 15:59:23 SUCCESS
EnsureMinimumRefreshTokenEntropy
Calculated shannon entropy seems sufficient
actual
200.477331756708
expected
96.0
2021-08-13 15:59:23 SUCCESS
EnsureMinimumAccessTokenLength
Access token is of sufficient length
actual
5520
required
128
2021-08-13 15:59:23 SUCCESS
EnsureMinimumAccessTokenEntropy
Calculated shannon entropy seems sufficient
actual
4032.460204475536
expected
96.0
2021-08-13 15:59:23 SUCCESS
ExtractIdTokenFromTokenResponse
Found and parsed the id_token from token_endpoint_response
value
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJqdGkiOiJ5RnZHWjF6OFA1bGdxckJyc3BHTG9vIiwiaXNzIjoiaHR0cHM6Ly9pZHAuY29uZi5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTYyODg3MDM2MiwiZXhwIjoxNjI4ODcwNjYyLCJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYXV0aF90aW1lIjoxNjI4ODcwMzYyLCJub25jZSI6ImlNeGpQZWZhMkciLCJjX2hhc2giOiJMUVBTeE1XZGxOUXZxazJyVElhQVJRIiwic19oYXNoIjoid0U0TFBNWEJmQXBmUXFsblFBYUdLdyJ9.jCoe7u7iw8CszZ7IAt58n7edYwI0zqc7baBXkv11Gmv9paOaTgKizqbulTqLq0yATtGxMZuExa_N3VqNiJ8zp__zuGvINUrKcZk28pWrfR2ZPatc0mQ0MkUS34bIahbounu1zI4JRYHD1B7ewCQSkHu_ox-h-PLDIuu1Xtmx22v6WnABhTvbJ9Iphe8llP5wjHKLrXgZFMhuq6rYjYFPnwtkwvVvd4QJqzWiA9N7kIkqdhgPKh45Ia9Mss-DKir6rtiOltmEPSZ15POXelcF_yQHwS0szERINg3m8GqzSdmFzc4FumWFa5WUXyNcVkyONGVPMWzJ4BGuaTCV8nm9Rg
header
{
  "kid": "NfGZj3wtxSjC-G5ZOsy0GIrGqwU",
  "alg": "PS256"
}
claims
{
  "sub": "joe",
  "aud": "fapi_adv_op_w_private_key_par_first_client",
  "acr": "urn:mace:incommon:iap:silver",
  "c_hash": "LQPSxMWdlNQvqk2rTIaARQ",
  "s_hash": "wE4LPMXBfApfQqlnQAaGKw",
  "auth_time": 1628870362,
  "iss": "https://idp.conf.ping-eng.com:9031",
  "exp": 1628870662,
  "iat": 1628870362,
  "nonce": "iMxjPefa2G",
  "jti": "yFvGZ1z8P5lgqrBrspGLoo"
}
2021-08-13 15:59:23 SUCCESS
ValidateIdToken
ID token iss, aud, exp, iat, auth_time, acr & nbf claims passed validation checks
2021-08-13 15:59:23 SUCCESS
EnsureIdTokenContainsKid
kid was found in the ID token header
kid
NfGZj3wtxSjC-G5ZOsy0GIrGqwU
2021-08-13 15:59:23 SUCCESS
ValidateIdTokenNonce
Nonce values match
nonce
iMxjPefa2G
2021-08-13 15:59:23 SUCCESS
ValidateIdTokenACRClaimAgainstRequest
acr value in id_token is (one of) the requested values
actual
urn:mace:incommon:iap:silver
requested
[
  "urn:mace:incommon:iap:silver"
]
2021-08-13 15:59:23 SUCCESS
ValidateIdTokenSignature
id_token signature validated
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJqdGkiOiJ5RnZHWjF6OFA1bGdxckJyc3BHTG9vIiwiaXNzIjoiaHR0cHM6Ly9pZHAuY29uZi5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTYyODg3MDM2MiwiZXhwIjoxNjI4ODcwNjYyLCJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYXV0aF90aW1lIjoxNjI4ODcwMzYyLCJub25jZSI6ImlNeGpQZWZhMkciLCJjX2hhc2giOiJMUVBTeE1XZGxOUXZxazJyVElhQVJRIiwic19oYXNoIjoid0U0TFBNWEJmQXBmUXFsblFBYUdLdyJ9.jCoe7u7iw8CszZ7IAt58n7edYwI0zqc7baBXkv11Gmv9paOaTgKizqbulTqLq0yATtGxMZuExa_N3VqNiJ8zp__zuGvINUrKcZk28pWrfR2ZPatc0mQ0MkUS34bIahbounu1zI4JRYHD1B7ewCQSkHu_ox-h-PLDIuu1Xtmx22v6WnABhTvbJ9Iphe8llP5wjHKLrXgZFMhuq6rYjYFPnwtkwvVvd4QJqzWiA9N7kIkqdhgPKh45Ia9Mss-DKir6rtiOltmEPSZ15POXelcF_yQHwS0szERINg3m8GqzSdmFzc4FumWFa5WUXyNcVkyONGVPMWzJ4BGuaTCV8nm9Rg
2021-08-13 15:59:23 SUCCESS
ValidateIdTokenSignatureUsingKid
id_token signature validated
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9maXJzdF9jbGllbnQiLCJqdGkiOiJ5RnZHWjF6OFA1bGdxckJyc3BHTG9vIiwiaXNzIjoiaHR0cHM6Ly9pZHAuY29uZi5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTYyODg3MDM2MiwiZXhwIjoxNjI4ODcwNjYyLCJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYXV0aF90aW1lIjoxNjI4ODcwMzYyLCJub25jZSI6ImlNeGpQZWZhMkciLCJjX2hhc2giOiJMUVBTeE1XZGxOUXZxazJyVElhQVJRIiwic19oYXNoIjoid0U0TFBNWEJmQXBmUXFsblFBYUdLdyJ9.jCoe7u7iw8CszZ7IAt58n7edYwI0zqc7baBXkv11Gmv9paOaTgKizqbulTqLq0yATtGxMZuExa_N3VqNiJ8zp__zuGvINUrKcZk28pWrfR2ZPatc0mQ0MkUS34bIahbounu1zI4JRYHD1B7ewCQSkHu_ox-h-PLDIuu1Xtmx22v6WnABhTvbJ9Iphe8llP5wjHKLrXgZFMhuq6rYjYFPnwtkwvVvd4QJqzWiA9N7kIkqdhgPKh45Ia9Mss-DKir6rtiOltmEPSZ15POXelcF_yQHwS0szERINg3m8GqzSdmFzc4FumWFa5WUXyNcVkyONGVPMWzJ4BGuaTCV8nm9Rg
2021-08-13 15:59:23 SUCCESS
CheckForSubjectInIdToken
Found 'sub' in id_token
sub
joe
2021-08-13 15:59:23 SUCCESS
FAPIValidateIdTokenSigningAlg
id_token was signed with a permitted algorithm
permitted
[
  "ES256",
  "PS256"
]
alg
PS256
2021-08-13 15:59:23 INFO
FAPIValidateIdTokenEncryptionAlg
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2021-08-13 15:59:23 INFO
FAPIValidateEncryptedIdTokenHasKid
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2021-08-13 15:59:23 SUCCESS
ExtractCHash
Extracted c_hash from ID Token
c_hash
LQPSxMWdlNQvqk2rTIaARQ
alg
PS256
2021-08-13 15:59:23 SUCCESS
ExtractSHash
Extracted s_hash from ID Token
s_hash
wE4LPMXBfApfQqlnQAaGKw
alg
PS256
2021-08-13 15:59:23 INFO
ExtractAtHash
Couldn't find at_hash in ID token
2021-08-13 15:59:23 SUCCESS
ValidateCHash
c_hash validated successfully
expected_hash
LQPSxMWdlNQvqk2rTIaARQ
unhashed_value
6yqwMKk5gKH0biUZFr1vSf6mCvdkN-aGgS4s68Eh
id_token_hash
LQPSxMWdlNQvqk2rTIaARQ
2021-08-13 15:59:23 SUCCESS
ValidateSHash
s_hash validated successfully
expected_hash
wE4LPMXBfApfQqlnQAaGKw
unhashed_value
t51zdo4fFG
id_token_hash
wE4LPMXBfApfQqlnQAaGKw
2021-08-13 15:59:23 INFO
ValidateAtHash
Skipped evaluation due to missing required object: at_hash
expected
at_hash
mapped
Verify at_hash in the authorization endpoint id_token
2021-08-13 15:59:23 INFO
ExtractAtHash
Couldn't find at_hash in ID token
2021-08-13 15:59:23 INFO
ValidateAtHash
Skipped evaluation due to missing required object: at_hash
expected
at_hash
mapped
Accounts request endpoint TLS test
2021-08-13 15:59:23 SUCCESS
EnsureTLS12WithFAPICiphers
Server agreed to TLS 1.2
port
3000
host
idp.conf.ping-eng.com
2021-08-13 15:59:24 SUCCESS
DisallowTLS10
Server refused TLS 1.0 handshake
port
3000
host
idp.conf.ping-eng.com
2021-08-13 15:59:24 SUCCESS
DisallowTLS11
Server refused TLS 1.1 handshake
port
3000
host
idp.conf.ping-eng.com
2021-08-13 15:59:24
DisallowInsecureCipher
Trying to connect with a non-permitted cipher (this is not exhaustive: check the server configuration manually to verify conformance)
port
3000
host
idp.conf.ping-eng.com
2021-08-13 15:59:24 SUCCESS
DisallowInsecureCipher
The TLS handshake was rejected when trying to connect with disallowed ciphers.
port
3000
host
idp.conf.ping-eng.com
Accounts resource endpoint TLS test
2021-08-13 15:59:24 SUCCESS
EnsureTLS12WithFAPICiphers
Server agreed to TLS 1.2
port
3000
host
idp.conf.ping-eng.com
2021-08-13 15:59:24 SUCCESS
DisallowTLS10
Server refused TLS 1.0 handshake
port
3000
host
idp.conf.ping-eng.com
2021-08-13 15:59:24 SUCCESS
DisallowTLS11
Server refused TLS 1.1 handshake
port
3000
host
idp.conf.ping-eng.com
2021-08-13 15:59:24
DisallowInsecureCipher
Trying to connect with a non-permitted cipher (this is not exhaustive: check the server configuration manually to verify conformance)
port
3000
host
idp.conf.ping-eng.com
2021-08-13 15:59:25 SUCCESS
DisallowInsecureCipher
The TLS handshake was rejected when trying to connect with disallowed ciphers.
port
3000
host
idp.conf.ping-eng.com
Resource server endpoint tests
2021-08-13 15:59:25
CreateEmptyResourceEndpointRequestHeaders
Created empty headers
resource_endpoint_request_headers
{}
2021-08-13 15:59:25 SUCCESS
AddFAPIAuthDateToResourceEndpointRequest
Added x-fapi-auth-date to resource endpoint request headers
resource_endpoint_request_headers
{
  "x-fapi-auth-date": "Fri, 13 Aug 2021 15:59:25 GMT"
}
2021-08-13 15:59:25
AddIpV4FapiCustomerIpAddressToResourceEndpointRequest
Added x-fapi-customer-ip-address containing IPv4 address to resource endpoint request headers
resource_endpoint_request_headers
{
  "x-fapi-auth-date": "Fri, 13 Aug 2021 15:59:25 GMT",
  "x-fapi-customer-ip-address": "198.51.100.119"
}
2021-08-13 15:59:25
CreateRandomFAPIInteractionId
Created interaction ID
fapi_interaction_id
2f042afe-cdcc-46fa-a65e-0f7597884c2a
2021-08-13 15:59:25 SUCCESS
AddFAPIInteractionIdToResourceEndpointRequest
Added x-fapi-interaction-id to resource endpoint request headers
resource_endpoint_request_headers
{
  "x-fapi-auth-date": "Fri, 13 Aug 2021 15:59:25 GMT",
  "x-fapi-customer-ip-address": "198.51.100.119",
  "x-fapi-interaction-id": "2f042afe-cdcc-46fa-a65e-0f7597884c2a"
}
2021-08-13 15:59:25
CallProtectedResourceWithBearerTokenAndCustomHeaders
HTTP request
request_uri
https://idp.conf.ping-eng.com:3000/get
request_method
GET
request_headers
{
  "accept": "application/json;charset\u003dUTF-8",
  "x-fapi-auth-date": "Fri, 13 Aug 2021 15:59:25 GMT",
  "x-fapi-customer-ip-address": "198.51.100.119",
  "x-fapi-interaction-id": "2f042afe-cdcc-46fa-a65e-0f7597884c2a",
  "authorization": "Bearer eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSIsInBpLmF0bSI6ImE5Z2kifQ.eyJzY29wZSI6Im9wZW5pZCBwYXltZW50cyIsImNsaWVudF9pZCI6ImZhcGlfYWR2X29wX3dfcHJpdmF0ZV9rZXlfcGFyX2ZpcnN0X2NsaWVudCIsInN1YiI6ImpvZSIsInBpLnVrIjoiam9lIiwiY25mIjp7Ing1dCNTMjU2IjoianIyRnRSWWFmb2hiQ1oyelAtN2lpSTUzUXlDRXBNeFBtb19sN2hCSEdaSSJ9LCJleHAiOjE2Mjg4Nzc1NjN9.jRt2961Rfutwd5CC9LTZcWJq88PEZ_wcSqaTAdPoIAbiIm_V3fWk_nHsiD8B7iT4BMIjz6f7cti2YNHzeyTHXwG1X0jskwDZHeMB7iBzKVpqteRNs8RgX5_nYL_2OQQZft2jm6uFIJXtw6mZZ4huKljXdQi4qzHHT4R43bFF61JSuEvYr2X69a4vveJvmF6AwT5JkOYR6dRextgI3oe56R_hIshD4LR4vV03ouA-EGuWokZALwgSaHzX_3hEr2OSf8_9FbWbmpjcb0dW1eZVI0tLCmm2TxlphVzll0zmWZC44M7q5NZa-lstbrGj2MP0OxV2p6hUjrFCY2H6l_jy9w",
  "accept-charset": "utf-8",
  "content-length": "0"
}
request_body

                                
request_mutual_tls
{
  "cert": "MIID3TCCAsWgAwIBAgIUIi7yAbDDmWkZjI8CwjLBVkswVkIwDQYJKoZIhvcNAQELBQAwfTELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAkNPMQ8wDQYDVQQHDAZEZW52ZXIxFTATBgNVBAoMDFBpbmdJZGVudGl0eTEUMBIGA1UECwwLRGV2ZWxvcG1lbnQxIzAhBgNVBAMMGkZBUEkgQWR2IE9QIHcgRmlyc3QgQ2xpZW50MCAXDTIxMDcyNjIyMzQzN1oYDzIxMjEwNzAyMjIzNDM3WjB9MQswCQYDVQQGEwJVUzELMAkGA1UECAwCQ08xDzANBgNVBAcMBkRlbnZlcjEVMBMGA1UECgwMUGluZ0lkZW50aXR5MRQwEgYDVQQLDAtEZXZlbG9wbWVudDEjMCEGA1UEAwwaRkFQSSBBZHYgT1AgdyBGaXJzdCBDbGllbnQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCa91hiBBEaNcRdvQ0Gvg06mzaIQpa17vgtP77HwtV0FvH+3imrnqmaCcpEnWGMv/udX8S5r/VAeUPB2Q31187vKDLKxbadWTKuSNQajOkRyiXZzutbEQbN/t7JAz7oETujYoOTlMNT4N9twYvKEvxTeZAWNUCQHXZcESKYXhph0eZaaOvNo7WqQ+ygGBzgTVev6tXr/Q2+M3NkBnSvRYegSN5ZtmIXMrNVaH7D+SC8QUPWxsB8ZVIENzBhCI8+brrPjyLNqVKoI9O7Hjdgzb8Xs+gC98ATmsbQrE/8pRdYYCPkEoETAWRq2T/dEf7NE+AMerttKk9TdNwvbB1WbAoHAgMBAAGjUzBRMB0GA1UdDgQWBBTr8p3YWM2Rtw/BAQaellNa1RUKSTAfBgNVHSMEGDAWgBTr8p3YWM2Rtw/BAQaellNa1RUKSTAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQB17ygVKcEpZxP4XML98KyUycNxsyHcKdIo2GZCRsmwjDR5nRcdWlE+tI50sduSaAR+gSbDFR/dqBxl0lBEMLj6Rqpson+z17jv68fU9H7l7JLfI5xAXuW4s1Kg/xBcYBy7QJkU9CTMIb6TBQESCbTUq89aCX4fT8WQleCflRJjSuzzdpVWd0PIhcxCoxpa/BcXtK0gf/z0rimF4jJKv40rqdf0LGsVzKQ9TxQIDWk0tov4FkvBw63VUp6b7PWdEHi4E9uKgHxh2Pj+VykK33nCmUsGXENfj4SSkY2O00iDw3oHfC8xmWvgqsTdlzJm1qhZCZGNOsdWLEv6hGl4XLyr",
  "key": "MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQCa91hiBBEaNcRdvQ0Gvg06mzaIQpa17vgtP77HwtV0FvH+3imrnqmaCcpEnWGMv/udX8S5r/VAeUPB2Q31187vKDLKxbadWTKuSNQajOkRyiXZzutbEQbN/t7JAz7oETujYoOTlMNT4N9twYvKEvxTeZAWNUCQHXZcESKYXhph0eZaaOvNo7WqQ+ygGBzgTVev6tXr/Q2+M3NkBnSvRYegSN5ZtmIXMrNVaH7D+SC8QUPWxsB8ZVIENzBhCI8+brrPjyLNqVKoI9O7Hjdgzb8Xs+gC98ATmsbQrE/8pRdYYCPkEoETAWRq2T/dEf7NE+AMerttKk9TdNwvbB1WbAoHAgMBAAECggEAf4aFKUQHfvY4PpvRGHdWE6CfY8rIk7ewbCxFJ8biOcKYKxFQYXcUQztDROvu1xE2Uu/4yIZQ4VnptKCWqHWMSatfARdrjFlXJ62vPpovQwCD3ZY2gJ6mZucTF4CgSAHGflIXzV9izqgDtiLMkuLE2zzyohP4qaBVQranLZRjSZNWeGvEpkcf7Nv7FlfZaOJ/FkcGwyFn7iSzX/KRL/1TA6zDlreA3PGJr96i9SmFHQsurFv7quRxEUFoSVxVtn5IiOJji45Evte8KAhMzlau1MuAlKxiIJAMIPN2l1nTRTRZUybDBoLp9CkkAmvp75krld9NB/hbWaeRsxhgVPXYwQKBgQDMsai5QHJAFZ5P31LN0dvlvcj0X2dPS0hEd6NsIf5DkbQKHQuVlxdIGhChLhVBdkGUt9ZYSflxlUtc8GUG3+e0TKg+ZAHNakueV73TGZy3BAzQBxwQBMqUltcXWMjWBaDnbQH+TrtYP0A+ZdHd4gnBNuSUuv5R7IxGWHgfcvtnuQKBgQDBzt2kGjDXXPV4qrtmGl4KaCAvsFr76VsVr8879MhrVgevI5vbsBNWQ3yvykXLr5B6s0VaqibvgDTcchQvqwtoEeDQfHsSHnAglGYCAi06hwGArTW/hxW0L7IivB+laFsbPY2HbnGZ6WUOjMNTgGAihbbLd6+IvLJEVdn7gjxfvwKBgD/DS9rBP5XE5jbdS08AA27yiqnNGkJyIgXp+sdRY4Iq3hmUaKplkYQNUobS8x4cN1ubVLLWAFUoe3xtCht1HhllE7ezsXgKl5mwnVooDVBZe6BFxrEavPxCbKhCKPW6dSACLe/JGMTplxqY3yIuKnm8nsHR6i0c8alsH6c0SypJAoGBALcVCn+5ViY8ZI9nCby8b9X4417phCmxGiB0gpoq9SGglYW3Z8ayoLG+8wzFUgXGhf/DVmL9leZuAIG3KqaVOCNJsEyDK2fEZTwBtBN1pvBBFQRPnBSgMbqTy/3QJT0GRfqHvSkRBjPVLWf/RY2eGjLCihnPqHzNdMHlMBTNxObVAoGAMRDZNtM0vIUNbjY5YFK0AoetPqR1mS2fWOFdCVnyHYBOJmmUZbU4oNZk5HmHBOC8N7aOELyXu56I4yEw0KUjOphKGfA9b2553q1A6t1x1oHBIwVuj1W3sEpUOtj2fWwmmdqjEyRsdzEJWfOuOEFzbfaw1pClq9IbngVcDGfzg74\u003d"
}
2021-08-13 15:59:25 RESPONSE
CallProtectedResourceWithBearerTokenAndCustomHeaders
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "date": "Fri, 13 Aug 2021 15:59:25 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003dw2wyxYqoGTShIzLIZxD9hw; Path\u003d/; Secure; HttpOnly; SameSite\u003dNone",
  "transfer-encoding": "chunked",
  "x-fapi-interaction-id": "2f042afe-cdcc-46fa-a65e-0f7597884c2a"
}
response_body
{"sub":"joe"}
2021-08-13 15:59:25 SUCCESS
CallProtectedResourceWithBearerTokenAndCustomHeaders
Got a response from the resource endpoint
headers
{
  "date": "Fri, 13 Aug 2021 15:59:25 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003dw2wyxYqoGTShIzLIZxD9hw; Path\u003d/; Secure; HttpOnly; SameSite\u003dNone",
  "transfer-encoding": "chunked",
  "x-fapi-interaction-id": "2f042afe-cdcc-46fa-a65e-0f7597884c2a"
}
status_code
{
  "code": 200
}
body
{"sub":"joe"}
2021-08-13 15:59:25 SUCCESS
CheckForDateHeaderInResourceResponse
Date header present and validated
date
Fri, 13 Aug 2021 15:59:25 GMT
skew
443
2021-08-13 15:59:25 SUCCESS
CheckForFAPIInteractionIdInResourceResponse
Found x-fapi-interaction-id
interaction_id
2f042afe-cdcc-46fa-a65e-0f7597884c2a
2021-08-13 15:59:25 SUCCESS
EnsureMatchingFAPIInteractionId
Interaction ID matched
fapi_interaction_id
2f042afe-cdcc-46fa-a65e-0f7597884c2a
2021-08-13 15:59:25 SUCCESS
EnsureResourceResponseReturnedJsonContentType
Response content type is JSON
content_type
application/json;charset=utf-8
2021-08-13 15:59:25
DisallowAccessTokenInQuery
HTTP request
request_uri
https://idp.conf.ping-eng.com:3000/get?access_token=eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSIsInBpLmF0bSI6ImE5Z2kifQ.eyJzY29wZSI6Im9wZW5pZCBwYXltZW50cyIsImNsaWVudF9pZCI6ImZhcGlfYWR2X29wX3dfcHJpdmF0ZV9rZXlfcGFyX2ZpcnN0X2NsaWVudCIsInN1YiI6ImpvZSIsInBpLnVrIjoiam9lIiwiY25mIjp7Ing1dCNTMjU2IjoianIyRnRSWWFmb2hiQ1oyelAtN2lpSTUzUXlDRXBNeFBtb19sN2hCSEdaSSJ9LCJleHAiOjE2Mjg4Nzc1NjN9.jRt2961Rfutwd5CC9LTZcWJq88PEZ_wcSqaTAdPoIAbiIm_V3fWk_nHsiD8B7iT4BMIjz6f7cti2YNHzeyTHXwG1X0jskwDZHeMB7iBzKVpqteRNs8RgX5_nYL_2OQQZft2jm6uFIJXtw6mZZ4huKljXdQi4qzHHT4R43bFF61JSuEvYr2X69a4vveJvmF6AwT5JkOYR6dRextgI3oe56R_hIshD4LR4vV03ouA-EGuWokZALwgSaHzX_3hEr2OSf8_9FbWbmpjcb0dW1eZVI0tLCmm2TxlphVzll0zmWZC44M7q5NZa-lstbrGj2MP0OxV2p6hUjrFCY2H6l_jy9w
request_method
GET
request_headers
{
  "accept": "application/json;charset\u003dUTF-8",
  "x-fapi-auth-date": "Fri, 13 Aug 2021 15:59:25 GMT",
  "x-fapi-customer-ip-address": "198.51.100.119",
  "x-fapi-interaction-id": "2f042afe-cdcc-46fa-a65e-0f7597884c2a",
  "accept-charset": "utf-8",
  "content-length": "0"
}
request_body

                                
request_mutual_tls
{
  "cert": "MIID3TCCAsWgAwIBAgIUIi7yAbDDmWkZjI8CwjLBVkswVkIwDQYJKoZIhvcNAQELBQAwfTELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAkNPMQ8wDQYDVQQHDAZEZW52ZXIxFTATBgNVBAoMDFBpbmdJZGVudGl0eTEUMBIGA1UECwwLRGV2ZWxvcG1lbnQxIzAhBgNVBAMMGkZBUEkgQWR2IE9QIHcgRmlyc3QgQ2xpZW50MCAXDTIxMDcyNjIyMzQzN1oYDzIxMjEwNzAyMjIzNDM3WjB9MQswCQYDVQQGEwJVUzELMAkGA1UECAwCQ08xDzANBgNVBAcMBkRlbnZlcjEVMBMGA1UECgwMUGluZ0lkZW50aXR5MRQwEgYDVQQLDAtEZXZlbG9wbWVudDEjMCEGA1UEAwwaRkFQSSBBZHYgT1AgdyBGaXJzdCBDbGllbnQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCa91hiBBEaNcRdvQ0Gvg06mzaIQpa17vgtP77HwtV0FvH+3imrnqmaCcpEnWGMv/udX8S5r/VAeUPB2Q31187vKDLKxbadWTKuSNQajOkRyiXZzutbEQbN/t7JAz7oETujYoOTlMNT4N9twYvKEvxTeZAWNUCQHXZcESKYXhph0eZaaOvNo7WqQ+ygGBzgTVev6tXr/Q2+M3NkBnSvRYegSN5ZtmIXMrNVaH7D+SC8QUPWxsB8ZVIENzBhCI8+brrPjyLNqVKoI9O7Hjdgzb8Xs+gC98ATmsbQrE/8pRdYYCPkEoETAWRq2T/dEf7NE+AMerttKk9TdNwvbB1WbAoHAgMBAAGjUzBRMB0GA1UdDgQWBBTr8p3YWM2Rtw/BAQaellNa1RUKSTAfBgNVHSMEGDAWgBTr8p3YWM2Rtw/BAQaellNa1RUKSTAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQB17ygVKcEpZxP4XML98KyUycNxsyHcKdIo2GZCRsmwjDR5nRcdWlE+tI50sduSaAR+gSbDFR/dqBxl0lBEMLj6Rqpson+z17jv68fU9H7l7JLfI5xAXuW4s1Kg/xBcYBy7QJkU9CTMIb6TBQESCbTUq89aCX4fT8WQleCflRJjSuzzdpVWd0PIhcxCoxpa/BcXtK0gf/z0rimF4jJKv40rqdf0LGsVzKQ9TxQIDWk0tov4FkvBw63VUp6b7PWdEHi4E9uKgHxh2Pj+VykK33nCmUsGXENfj4SSkY2O00iDw3oHfC8xmWvgqsTdlzJm1qhZCZGNOsdWLEv6hGl4XLyr",
  "key": "MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQCa91hiBBEaNcRdvQ0Gvg06mzaIQpa17vgtP77HwtV0FvH+3imrnqmaCcpEnWGMv/udX8S5r/VAeUPB2Q31187vKDLKxbadWTKuSNQajOkRyiXZzutbEQbN/t7JAz7oETujYoOTlMNT4N9twYvKEvxTeZAWNUCQHXZcESKYXhph0eZaaOvNo7WqQ+ygGBzgTVev6tXr/Q2+M3NkBnSvRYegSN5ZtmIXMrNVaH7D+SC8QUPWxsB8ZVIENzBhCI8+brrPjyLNqVKoI9O7Hjdgzb8Xs+gC98ATmsbQrE/8pRdYYCPkEoETAWRq2T/dEf7NE+AMerttKk9TdNwvbB1WbAoHAgMBAAECggEAf4aFKUQHfvY4PpvRGHdWE6CfY8rIk7ewbCxFJ8biOcKYKxFQYXcUQztDROvu1xE2Uu/4yIZQ4VnptKCWqHWMSatfARdrjFlXJ62vPpovQwCD3ZY2gJ6mZucTF4CgSAHGflIXzV9izqgDtiLMkuLE2zzyohP4qaBVQranLZRjSZNWeGvEpkcf7Nv7FlfZaOJ/FkcGwyFn7iSzX/KRL/1TA6zDlreA3PGJr96i9SmFHQsurFv7quRxEUFoSVxVtn5IiOJji45Evte8KAhMzlau1MuAlKxiIJAMIPN2l1nTRTRZUybDBoLp9CkkAmvp75krld9NB/hbWaeRsxhgVPXYwQKBgQDMsai5QHJAFZ5P31LN0dvlvcj0X2dPS0hEd6NsIf5DkbQKHQuVlxdIGhChLhVBdkGUt9ZYSflxlUtc8GUG3+e0TKg+ZAHNakueV73TGZy3BAzQBxwQBMqUltcXWMjWBaDnbQH+TrtYP0A+ZdHd4gnBNuSUuv5R7IxGWHgfcvtnuQKBgQDBzt2kGjDXXPV4qrtmGl4KaCAvsFr76VsVr8879MhrVgevI5vbsBNWQ3yvykXLr5B6s0VaqibvgDTcchQvqwtoEeDQfHsSHnAglGYCAi06hwGArTW/hxW0L7IivB+laFsbPY2HbnGZ6WUOjMNTgGAihbbLd6+IvLJEVdn7gjxfvwKBgD/DS9rBP5XE5jbdS08AA27yiqnNGkJyIgXp+sdRY4Iq3hmUaKplkYQNUobS8x4cN1ubVLLWAFUoe3xtCht1HhllE7ezsXgKl5mwnVooDVBZe6BFxrEavPxCbKhCKPW6dSACLe/JGMTplxqY3yIuKnm8nsHR6i0c8alsH6c0SypJAoGBALcVCn+5ViY8ZI9nCby8b9X4417phCmxGiB0gpoq9SGglYW3Z8ayoLG+8wzFUgXGhf/DVmL9leZuAIG3KqaVOCNJsEyDK2fEZTwBtBN1pvBBFQRPnBSgMbqTy/3QJT0GRfqHvSkRBjPVLWf/RY2eGjLCihnPqHzNdMHlMBTNxObVAoGAMRDZNtM0vIUNbjY5YFK0AoetPqR1mS2fWOFdCVnyHYBOJmmUZbU4oNZk5HmHBOC8N7aOELyXu56I4yEw0KUjOphKGfA9b2553q1A6t1x1oHBIwVuj1W3sEpUOtj2fWwmmdqjEyRsdzEJWfOuOEFzbfaw1pClq9IbngVcDGfzg74\u003d"
}
2021-08-13 15:59:25 RESPONSE
DisallowAccessTokenInQuery
HTTP response
response_status_code
401 UNAUTHORIZED
response_status_text
Unauthorized
response_headers
{
  "date": "Fri, 13 Aug 2021 15:59:25 GMT",
  "content-length": "51",
  "www-authenticate": "Bearer realm\u003d\"idp.conf.ping-eng.com:3000/\"",
  "cache-control": "no-cache,no-store,max-age\u003d0",
  "pragma": "no-cache",
  "expires": "0",
  "content-type": "application/json; charset\u003dUTF-8"
}
response_body
{"www-authenticate": "idp.conf.ping-eng.com:3000/"}
2021-08-13 15:59:25 SUCCESS
DisallowAccessTokenInQuery
Resource server refused request
code
401
status
Unauthorized
2021-08-13 15:59:25
AddIpV6FapiCustomerIpAddressToResourceEndpointRequest
Added x-fapi-customer-ip-address containing IPv6 address to resource endpoint request headers
resource_endpoint_request_headers
{
  "x-fapi-auth-date": "Fri, 13 Aug 2021 15:59:25 GMT",
  "x-fapi-customer-ip-address": "2001:DB8::1893:25c8:1946",
  "x-fapi-interaction-id": "2f042afe-cdcc-46fa-a65e-0f7597884c2a"
}
2021-08-13 15:59:25 SUCCESS
SetPlainJsonAcceptHeaderForResourceEndpointRequest
Set Accept header
Accept
application/json
2021-08-13 15:59:25
CallProtectedResourceWithBearerTokenAndCustomHeaders
HTTP request
request_uri
https://idp.conf.ping-eng.com:3000/get
request_method
GET
request_headers
{
  "accept": "application/json",
  "x-fapi-auth-date": "Fri, 13 Aug 2021 15:59:25 GMT",
  "x-fapi-customer-ip-address": "2001:DB8::1893:25c8:1946",
  "x-fapi-interaction-id": "2f042afe-cdcc-46fa-a65e-0f7597884c2a",
  "authorization": "Bearer eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSIsInBpLmF0bSI6ImE5Z2kifQ.eyJzY29wZSI6Im9wZW5pZCBwYXltZW50cyIsImNsaWVudF9pZCI6ImZhcGlfYWR2X29wX3dfcHJpdmF0ZV9rZXlfcGFyX2ZpcnN0X2NsaWVudCIsInN1YiI6ImpvZSIsInBpLnVrIjoiam9lIiwiY25mIjp7Ing1dCNTMjU2IjoianIyRnRSWWFmb2hiQ1oyelAtN2lpSTUzUXlDRXBNeFBtb19sN2hCSEdaSSJ9LCJleHAiOjE2Mjg4Nzc1NjN9.jRt2961Rfutwd5CC9LTZcWJq88PEZ_wcSqaTAdPoIAbiIm_V3fWk_nHsiD8B7iT4BMIjz6f7cti2YNHzeyTHXwG1X0jskwDZHeMB7iBzKVpqteRNs8RgX5_nYL_2OQQZft2jm6uFIJXtw6mZZ4huKljXdQi4qzHHT4R43bFF61JSuEvYr2X69a4vveJvmF6AwT5JkOYR6dRextgI3oe56R_hIshD4LR4vV03ouA-EGuWokZALwgSaHzX_3hEr2OSf8_9FbWbmpjcb0dW1eZVI0tLCmm2TxlphVzll0zmWZC44M7q5NZa-lstbrGj2MP0OxV2p6hUjrFCY2H6l_jy9w",
  "content-length": "0"
}
request_body

                                
request_mutual_tls
{
  "cert": "MIID3TCCAsWgAwIBAgIUIi7yAbDDmWkZjI8CwjLBVkswVkIwDQYJKoZIhvcNAQELBQAwfTELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAkNPMQ8wDQYDVQQHDAZEZW52ZXIxFTATBgNVBAoMDFBpbmdJZGVudGl0eTEUMBIGA1UECwwLRGV2ZWxvcG1lbnQxIzAhBgNVBAMMGkZBUEkgQWR2IE9QIHcgRmlyc3QgQ2xpZW50MCAXDTIxMDcyNjIyMzQzN1oYDzIxMjEwNzAyMjIzNDM3WjB9MQswCQYDVQQGEwJVUzELMAkGA1UECAwCQ08xDzANBgNVBAcMBkRlbnZlcjEVMBMGA1UECgwMUGluZ0lkZW50aXR5MRQwEgYDVQQLDAtEZXZlbG9wbWVudDEjMCEGA1UEAwwaRkFQSSBBZHYgT1AgdyBGaXJzdCBDbGllbnQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCa91hiBBEaNcRdvQ0Gvg06mzaIQpa17vgtP77HwtV0FvH+3imrnqmaCcpEnWGMv/udX8S5r/VAeUPB2Q31187vKDLKxbadWTKuSNQajOkRyiXZzutbEQbN/t7JAz7oETujYoOTlMNT4N9twYvKEvxTeZAWNUCQHXZcESKYXhph0eZaaOvNo7WqQ+ygGBzgTVev6tXr/Q2+M3NkBnSvRYegSN5ZtmIXMrNVaH7D+SC8QUPWxsB8ZVIENzBhCI8+brrPjyLNqVKoI9O7Hjdgzb8Xs+gC98ATmsbQrE/8pRdYYCPkEoETAWRq2T/dEf7NE+AMerttKk9TdNwvbB1WbAoHAgMBAAGjUzBRMB0GA1UdDgQWBBTr8p3YWM2Rtw/BAQaellNa1RUKSTAfBgNVHSMEGDAWgBTr8p3YWM2Rtw/BAQaellNa1RUKSTAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQB17ygVKcEpZxP4XML98KyUycNxsyHcKdIo2GZCRsmwjDR5nRcdWlE+tI50sduSaAR+gSbDFR/dqBxl0lBEMLj6Rqpson+z17jv68fU9H7l7JLfI5xAXuW4s1Kg/xBcYBy7QJkU9CTMIb6TBQESCbTUq89aCX4fT8WQleCflRJjSuzzdpVWd0PIhcxCoxpa/BcXtK0gf/z0rimF4jJKv40rqdf0LGsVzKQ9TxQIDWk0tov4FkvBw63VUp6b7PWdEHi4E9uKgHxh2Pj+VykK33nCmUsGXENfj4SSkY2O00iDw3oHfC8xmWvgqsTdlzJm1qhZCZGNOsdWLEv6hGl4XLyr",
  "key": "MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQCa91hiBBEaNcRdvQ0Gvg06mzaIQpa17vgtP77HwtV0FvH+3imrnqmaCcpEnWGMv/udX8S5r/VAeUPB2Q31187vKDLKxbadWTKuSNQajOkRyiXZzutbEQbN/t7JAz7oETujYoOTlMNT4N9twYvKEvxTeZAWNUCQHXZcESKYXhph0eZaaOvNo7WqQ+ygGBzgTVev6tXr/Q2+M3NkBnSvRYegSN5ZtmIXMrNVaH7D+SC8QUPWxsB8ZVIENzBhCI8+brrPjyLNqVKoI9O7Hjdgzb8Xs+gC98ATmsbQrE/8pRdYYCPkEoETAWRq2T/dEf7NE+AMerttKk9TdNwvbB1WbAoHAgMBAAECggEAf4aFKUQHfvY4PpvRGHdWE6CfY8rIk7ewbCxFJ8biOcKYKxFQYXcUQztDROvu1xE2Uu/4yIZQ4VnptKCWqHWMSatfARdrjFlXJ62vPpovQwCD3ZY2gJ6mZucTF4CgSAHGflIXzV9izqgDtiLMkuLE2zzyohP4qaBVQranLZRjSZNWeGvEpkcf7Nv7FlfZaOJ/FkcGwyFn7iSzX/KRL/1TA6zDlreA3PGJr96i9SmFHQsurFv7quRxEUFoSVxVtn5IiOJji45Evte8KAhMzlau1MuAlKxiIJAMIPN2l1nTRTRZUybDBoLp9CkkAmvp75krld9NB/hbWaeRsxhgVPXYwQKBgQDMsai5QHJAFZ5P31LN0dvlvcj0X2dPS0hEd6NsIf5DkbQKHQuVlxdIGhChLhVBdkGUt9ZYSflxlUtc8GUG3+e0TKg+ZAHNakueV73TGZy3BAzQBxwQBMqUltcXWMjWBaDnbQH+TrtYP0A+ZdHd4gnBNuSUuv5R7IxGWHgfcvtnuQKBgQDBzt2kGjDXXPV4qrtmGl4KaCAvsFr76VsVr8879MhrVgevI5vbsBNWQ3yvykXLr5B6s0VaqibvgDTcchQvqwtoEeDQfHsSHnAglGYCAi06hwGArTW/hxW0L7IivB+laFsbPY2HbnGZ6WUOjMNTgGAihbbLd6+IvLJEVdn7gjxfvwKBgD/DS9rBP5XE5jbdS08AA27yiqnNGkJyIgXp+sdRY4Iq3hmUaKplkYQNUobS8x4cN1ubVLLWAFUoe3xtCht1HhllE7ezsXgKl5mwnVooDVBZe6BFxrEavPxCbKhCKPW6dSACLe/JGMTplxqY3yIuKnm8nsHR6i0c8alsH6c0SypJAoGBALcVCn+5ViY8ZI9nCby8b9X4417phCmxGiB0gpoq9SGglYW3Z8ayoLG+8wzFUgXGhf/DVmL9leZuAIG3KqaVOCNJsEyDK2fEZTwBtBN1pvBBFQRPnBSgMbqTy/3QJT0GRfqHvSkRBjPVLWf/RY2eGjLCihnPqHzNdMHlMBTNxObVAoGAMRDZNtM0vIUNbjY5YFK0AoetPqR1mS2fWOFdCVnyHYBOJmmUZbU4oNZk5HmHBOC8N7aOELyXu56I4yEw0KUjOphKGfA9b2553q1A6t1x1oHBIwVuj1W3sEpUOtj2fWwmmdqjEyRsdzEJWfOuOEFzbfaw1pClq9IbngVcDGfzg74\u003d"
}
2021-08-13 15:59:26 RESPONSE
CallProtectedResourceWithBearerTokenAndCustomHeaders
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "date": "Fri, 13 Aug 2021 15:59:26 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003dnnvjziZmh1hBOpXvdMnpod; Path\u003d/; Secure; HttpOnly; SameSite\u003dNone",
  "transfer-encoding": "chunked",
  "x-fapi-interaction-id": "2f042afe-cdcc-46fa-a65e-0f7597884c2a"
}
response_body
{"sub":"joe"}
2021-08-13 15:59:26 SUCCESS
CallProtectedResourceWithBearerTokenAndCustomHeaders
Got a response from the resource endpoint
headers
{
  "date": "Fri, 13 Aug 2021 15:59:26 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003dnnvjziZmh1hBOpXvdMnpod; Path\u003d/; Secure; HttpOnly; SameSite\u003dNone",
  "transfer-encoding": "chunked",
  "x-fapi-interaction-id": "2f042afe-cdcc-46fa-a65e-0f7597884c2a"
}
status_code
{
  "code": 200
}
body
{"sub":"joe"}
2021-08-13 15:59:26 SUCCESS
SetPermissiveAcceptHeaderForResourceEndpointRequest
Set Accept header
Accept
application/json, application/*+json, */*
2021-08-13 15:59:26
CallProtectedResourceWithBearerTokenAndCustomHeaders
HTTP request
request_uri
https://idp.conf.ping-eng.com:3000/get
request_method
GET
request_headers
{
  "accept": "application/json, application/*+json, */*",
  "x-fapi-auth-date": "Fri, 13 Aug 2021 15:59:25 GMT",
  "x-fapi-customer-ip-address": "2001:DB8::1893:25c8:1946",
  "x-fapi-interaction-id": "2f042afe-cdcc-46fa-a65e-0f7597884c2a",
  "authorization": "Bearer eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSIsInBpLmF0bSI6ImE5Z2kifQ.eyJzY29wZSI6Im9wZW5pZCBwYXltZW50cyIsImNsaWVudF9pZCI6ImZhcGlfYWR2X29wX3dfcHJpdmF0ZV9rZXlfcGFyX2ZpcnN0X2NsaWVudCIsInN1YiI6ImpvZSIsInBpLnVrIjoiam9lIiwiY25mIjp7Ing1dCNTMjU2IjoianIyRnRSWWFmb2hiQ1oyelAtN2lpSTUzUXlDRXBNeFBtb19sN2hCSEdaSSJ9LCJleHAiOjE2Mjg4Nzc1NjN9.jRt2961Rfutwd5CC9LTZcWJq88PEZ_wcSqaTAdPoIAbiIm_V3fWk_nHsiD8B7iT4BMIjz6f7cti2YNHzeyTHXwG1X0jskwDZHeMB7iBzKVpqteRNs8RgX5_nYL_2OQQZft2jm6uFIJXtw6mZZ4huKljXdQi4qzHHT4R43bFF61JSuEvYr2X69a4vveJvmF6AwT5JkOYR6dRextgI3oe56R_hIshD4LR4vV03ouA-EGuWokZALwgSaHzX_3hEr2OSf8_9FbWbmpjcb0dW1eZVI0tLCmm2TxlphVzll0zmWZC44M7q5NZa-lstbrGj2MP0OxV2p6hUjrFCY2H6l_jy9w",
  "content-length": "0"
}
request_body

                                
request_mutual_tls
{
  "cert": "MIID3TCCAsWgAwIBAgIUIi7yAbDDmWkZjI8CwjLBVkswVkIwDQYJKoZIhvcNAQELBQAwfTELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAkNPMQ8wDQYDVQQHDAZEZW52ZXIxFTATBgNVBAoMDFBpbmdJZGVudGl0eTEUMBIGA1UECwwLRGV2ZWxvcG1lbnQxIzAhBgNVBAMMGkZBUEkgQWR2IE9QIHcgRmlyc3QgQ2xpZW50MCAXDTIxMDcyNjIyMzQzN1oYDzIxMjEwNzAyMjIzNDM3WjB9MQswCQYDVQQGEwJVUzELMAkGA1UECAwCQ08xDzANBgNVBAcMBkRlbnZlcjEVMBMGA1UECgwMUGluZ0lkZW50aXR5MRQwEgYDVQQLDAtEZXZlbG9wbWVudDEjMCEGA1UEAwwaRkFQSSBBZHYgT1AgdyBGaXJzdCBDbGllbnQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCa91hiBBEaNcRdvQ0Gvg06mzaIQpa17vgtP77HwtV0FvH+3imrnqmaCcpEnWGMv/udX8S5r/VAeUPB2Q31187vKDLKxbadWTKuSNQajOkRyiXZzutbEQbN/t7JAz7oETujYoOTlMNT4N9twYvKEvxTeZAWNUCQHXZcESKYXhph0eZaaOvNo7WqQ+ygGBzgTVev6tXr/Q2+M3NkBnSvRYegSN5ZtmIXMrNVaH7D+SC8QUPWxsB8ZVIENzBhCI8+brrPjyLNqVKoI9O7Hjdgzb8Xs+gC98ATmsbQrE/8pRdYYCPkEoETAWRq2T/dEf7NE+AMerttKk9TdNwvbB1WbAoHAgMBAAGjUzBRMB0GA1UdDgQWBBTr8p3YWM2Rtw/BAQaellNa1RUKSTAfBgNVHSMEGDAWgBTr8p3YWM2Rtw/BAQaellNa1RUKSTAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQB17ygVKcEpZxP4XML98KyUycNxsyHcKdIo2GZCRsmwjDR5nRcdWlE+tI50sduSaAR+gSbDFR/dqBxl0lBEMLj6Rqpson+z17jv68fU9H7l7JLfI5xAXuW4s1Kg/xBcYBy7QJkU9CTMIb6TBQESCbTUq89aCX4fT8WQleCflRJjSuzzdpVWd0PIhcxCoxpa/BcXtK0gf/z0rimF4jJKv40rqdf0LGsVzKQ9TxQIDWk0tov4FkvBw63VUp6b7PWdEHi4E9uKgHxh2Pj+VykK33nCmUsGXENfj4SSkY2O00iDw3oHfC8xmWvgqsTdlzJm1qhZCZGNOsdWLEv6hGl4XLyr",
  "key": "MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQCa91hiBBEaNcRdvQ0Gvg06mzaIQpa17vgtP77HwtV0FvH+3imrnqmaCcpEnWGMv/udX8S5r/VAeUPB2Q31187vKDLKxbadWTKuSNQajOkRyiXZzutbEQbN/t7JAz7oETujYoOTlMNT4N9twYvKEvxTeZAWNUCQHXZcESKYXhph0eZaaOvNo7WqQ+ygGBzgTVev6tXr/Q2+M3NkBnSvRYegSN5ZtmIXMrNVaH7D+SC8QUPWxsB8ZVIENzBhCI8+brrPjyLNqVKoI9O7Hjdgzb8Xs+gC98ATmsbQrE/8pRdYYCPkEoETAWRq2T/dEf7NE+AMerttKk9TdNwvbB1WbAoHAgMBAAECggEAf4aFKUQHfvY4PpvRGHdWE6CfY8rIk7ewbCxFJ8biOcKYKxFQYXcUQztDROvu1xE2Uu/4yIZQ4VnptKCWqHWMSatfARdrjFlXJ62vPpovQwCD3ZY2gJ6mZucTF4CgSAHGflIXzV9izqgDtiLMkuLE2zzyohP4qaBVQranLZRjSZNWeGvEpkcf7Nv7FlfZaOJ/FkcGwyFn7iSzX/KRL/1TA6zDlreA3PGJr96i9SmFHQsurFv7quRxEUFoSVxVtn5IiOJji45Evte8KAhMzlau1MuAlKxiIJAMIPN2l1nTRTRZUybDBoLp9CkkAmvp75krld9NB/hbWaeRsxhgVPXYwQKBgQDMsai5QHJAFZ5P31LN0dvlvcj0X2dPS0hEd6NsIf5DkbQKHQuVlxdIGhChLhVBdkGUt9ZYSflxlUtc8GUG3+e0TKg+ZAHNakueV73TGZy3BAzQBxwQBMqUltcXWMjWBaDnbQH+TrtYP0A+ZdHd4gnBNuSUuv5R7IxGWHgfcvtnuQKBgQDBzt2kGjDXXPV4qrtmGl4KaCAvsFr76VsVr8879MhrVgevI5vbsBNWQ3yvykXLr5B6s0VaqibvgDTcchQvqwtoEeDQfHsSHnAglGYCAi06hwGArTW/hxW0L7IivB+laFsbPY2HbnGZ6WUOjMNTgGAihbbLd6+IvLJEVdn7gjxfvwKBgD/DS9rBP5XE5jbdS08AA27yiqnNGkJyIgXp+sdRY4Iq3hmUaKplkYQNUobS8x4cN1ubVLLWAFUoe3xtCht1HhllE7ezsXgKl5mwnVooDVBZe6BFxrEavPxCbKhCKPW6dSACLe/JGMTplxqY3yIuKnm8nsHR6i0c8alsH6c0SypJAoGBALcVCn+5ViY8ZI9nCby8b9X4417phCmxGiB0gpoq9SGglYW3Z8ayoLG+8wzFUgXGhf/DVmL9leZuAIG3KqaVOCNJsEyDK2fEZTwBtBN1pvBBFQRPnBSgMbqTy/3QJT0GRfqHvSkRBjPVLWf/RY2eGjLCihnPqHzNdMHlMBTNxObVAoGAMRDZNtM0vIUNbjY5YFK0AoetPqR1mS2fWOFdCVnyHYBOJmmUZbU4oNZk5HmHBOC8N7aOELyXu56I4yEw0KUjOphKGfA9b2553q1A6t1x1oHBIwVuj1W3sEpUOtj2fWwmmdqjEyRsdzEJWfOuOEFzbfaw1pClq9IbngVcDGfzg74\u003d"
}
2021-08-13 15:59:26 RESPONSE
CallProtectedResourceWithBearerTokenAndCustomHeaders
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "date": "Fri, 13 Aug 2021 15:59:26 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003dtDJKRuhMHSTN31XpdgqW4H; Path\u003d/; Secure; HttpOnly; SameSite\u003dNone",
  "transfer-encoding": "chunked",
  "x-fapi-interaction-id": "2f042afe-cdcc-46fa-a65e-0f7597884c2a"
}
response_body
{"sub":"joe"}
2021-08-13 15:59:26 SUCCESS
CallProtectedResourceWithBearerTokenAndCustomHeaders
Got a response from the resource endpoint
headers
{
  "date": "Fri, 13 Aug 2021 15:59:26 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003dtDJKRuhMHSTN31XpdgqW4H; Path\u003d/; Secure; HttpOnly; SameSite\u003dNone",
  "transfer-encoding": "chunked",
  "x-fapi-interaction-id": "2f042afe-cdcc-46fa-a65e-0f7597884c2a"
}
status_code
{
  "code": 200
}
body
{"sub":"joe"}
2021-08-13 15:59:26 SUCCESS
ClearAcceptHeaderForResourceEndpointRequest
Cleared custom Accept header
Second client: Setup
2021-08-13 15:59:26 SUCCESS
AddRedirectUriQuerySuffix
Created redirect URI query suffix to test that query sections in the registered redirect url are handled correctly. The redirect url, including this suffix, must be registered for the client as per http://openid.net/certification/fapi_op_testing/
redirect_uri_suffix
?dummy1=lorem&dummy2=ipsum
2021-08-13 15:59:26
CreateRedirectUri
Appending suffix to redirect URI
suffix
?dummy1=lorem&dummy2=ipsum
2021-08-13 15:59:26 SUCCESS
CreateRedirectUri
Created redirect URI
redirect_uri
https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback?dummy1=lorem&dummy2=ipsum
Second client: Make request to authorization endpoint
2021-08-13 15:59:26 SUCCESS
CreateAuthorizationEndpointRequestFromClientInformation
Created authorization endpoint request
client_id
fapi_adv_op_w_private_key_par_second_client
redirect_uri
https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback?dummy1=lorem&dummy2=ipsum
scope
openid payments
2021-08-13 15:59:26 SUCCESS
AddAcrClaimToAuthorizationEndpointRequest
Added acr claim to authorization_endpoint_request
authorization_endpoint_request
{
  "client_id": "fapi_adv_op_w_private_key_par_second_client",
  "redirect_uri": "https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback?dummy1\u003dlorem\u0026dummy2\u003dipsum",
  "scope": "openid payments",
  "claims": {
    "id_token": {
      "acr": {
        "value": "urn:mace:incommon:iap:silver",
        "essential": true
      }
    }
  }
}
2021-08-13 15:59:26
CreateRandomStateValue
Created state value
requested_state_length
10
state
AGdEitpyfR
2021-08-13 15:59:26 SUCCESS
AddStateToAuthorizationEndpointRequest
Added state parameter to request
client_id
fapi_adv_op_w_private_key_par_second_client
redirect_uri
https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback?dummy1=lorem&dummy2=ipsum
scope
openid payments
claims
{
  "id_token": {
    "acr": {
      "value": "urn:mace:incommon:iap:silver",
      "essential": true
    }
  }
}
state
AGdEitpyfR
2021-08-13 15:59:26
CreateRandomNonceValue
Created nonce value
requested_nonce_length
10
nonce
3dgF1FG7GK
2021-08-13 15:59:26 SUCCESS
AddNonceToAuthorizationEndpointRequest
Added nonce parameter to request
client_id
fapi_adv_op_w_private_key_par_second_client
redirect_uri
https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback?dummy1=lorem&dummy2=ipsum
scope
openid payments
claims
{
  "id_token": {
    "acr": {
      "value": "urn:mace:incommon:iap:silver",
      "essential": true
    }
  }
}
state
AGdEitpyfR
nonce
3dgF1FG7GK
2021-08-13 15:59:26 SUCCESS
SetAuthorizationEndpointRequestResponseTypeToCodeIdtoken
Added response_type parameter to request
client_id
fapi_adv_op_w_private_key_par_second_client
redirect_uri
https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback?dummy1=lorem&dummy2=ipsum
scope
openid payments
claims
{
  "id_token": {
    "acr": {
      "value": "urn:mace:incommon:iap:silver",
      "essential": true
    }
  }
}
state
AGdEitpyfR
nonce
3dgF1FG7GK
response_type
code id_token
2021-08-13 15:59:26
CreateRandomCodeVerifier
Created code_verifier value
code_verifier
DMCQSvXSVCWfc_MDVI-9sjCQdh_kl_K9-09eChDdK3qAJ4cvU0lQhrV6w7Egl9KApa3mbud0xns.cyULys1lwKRaX8lfnP-lPn0~A8gj-r4YjSUg~Tu~Evvtztu50L8Y
2021-08-13 15:59:26
CreateS256CodeChallenge
Created code_challenge value
code_challenge
9HFSocOaCPlmPV1D5O10RfF8YYWyeXiCSc0R1Fnsk_Q
2021-08-13 15:59:26 SUCCESS
AddCodeChallengeToAuthorizationEndpointRequest
Added code_challenge and code_challenge_method parameters to request
client_id
fapi_adv_op_w_private_key_par_second_client
redirect_uri
https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback?dummy1=lorem&dummy2=ipsum
scope
openid payments
claims
{
  "id_token": {
    "acr": {
      "value": "urn:mace:incommon:iap:silver",
      "essential": true
    }
  }
}
state
AGdEitpyfR
nonce
3dgF1FG7GK
response_type
code id_token
code_challenge
9HFSocOaCPlmPV1D5O10RfF8YYWyeXiCSc0R1Fnsk_Q
code_challenge_method
S256
2021-08-13 15:59:26 SUCCESS
ConvertAuthorizationEndpointRequestToRequestObject
Created request object claims
request_object_claims
{
  "client_id": "fapi_adv_op_w_private_key_par_second_client",
  "redirect_uri": "https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback?dummy1\u003dlorem\u0026dummy2\u003dipsum",
  "scope": "openid payments",
  "claims": {
    "id_token": {
      "acr": {
        "value": "urn:mace:incommon:iap:silver",
        "essential": true
      }
    }
  },
  "state": "AGdEitpyfR",
  "nonce": "3dgF1FG7GK",
  "response_type": "code id_token",
  "code_challenge": "9HFSocOaCPlmPV1D5O10RfF8YYWyeXiCSc0R1Fnsk_Q",
  "code_challenge_method": "S256"
}
2021-08-13 15:59:26 SUCCESS
AddIatToRequestObject
Added iat to request object claims
iat
1.628870366E9
2021-08-13 15:59:26 SUCCESS
AddNbfToRequestObject
Added nbf to request object claims
nbf
1.628870366E9
2021-08-13 15:59:26 SUCCESS
AddExpToRequestObject
Added exp to request object claims
exp
1.628870666E9
2021-08-13 15:59:26 SUCCESS
AddAudToRequestObject
Added aud to request object claims
aud
https://idp.conf.ping-eng.com:9031
2021-08-13 15:59:26 SUCCESS
AddIssToRequestObject
Added iss to request object claims
iss
fapi_adv_op_w_private_key_par_second_client
2021-08-13 15:59:26 SUCCESS
AddClientIdToRequestObject
Added client_id to request object claims
client_id
fapi_adv_op_w_private_key_par_second_client
2021-08-13 15:59:26 SUCCESS
SignRequestObject
Signed the request object
claims
{"iss":"fapi_adv_op_w_private_key_par_second_client","response_type":"code id_token","code_challenge_method":"S256","nonce":"3dgF1FG7GK","client_id":"fapi_adv_op_w_private_key_par_second_client","aud":"https:\/\/idp.conf.ping-eng.com:9031","nbf":1628870366,"scope":"openid payments","claims":{"id_token":{"acr":{"value":"urn:mace:incommon:iap:silver","essential":true}}},"redirect_uri":"https:\/\/www.certification.openid.net\/test\/a\/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain\/callback?dummy1=lorem&dummy2=ipsum","state":"AGdEitpyfR","exp":1628870666,"iat":1628870366,"code_challenge":"9HFSocOaCPlmPV1D5O10RfF8YYWyeXiCSc0R1Fnsk_Q"}
header
{"kid":"pingfederate-fapi-jwt-assertion-client2","alg":"PS256"}
request_object
eyJraWQiOiJwaW5nZmVkZXJhdGUtZmFwaS1qd3QtYXNzZXJ0aW9uLWNsaWVudDIiLCJhbGciOiJQUzI1NiJ9.eyJpc3MiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwicmVzcG9uc2VfdHlwZSI6ImNvZGUgaWRfdG9rZW4iLCJjb2RlX2NoYWxsZW5nZV9tZXRob2QiOiJTMjU2Iiwibm9uY2UiOiIzZGdGMUZHN0dLIiwiY2xpZW50X2lkIjoiZmFwaV9hZHZfb3Bfd19wcml2YXRlX2tleV9wYXJfc2Vjb25kX2NsaWVudCIsImF1ZCI6Imh0dHBzOlwvXC9pZHAuY29uZi5waW5nLWVuZy5jb206OTAzMSIsIm5iZiI6MTYyODg3MDM2Niwic2NvcGUiOiJvcGVuaWQgcGF5bWVudHMiLCJjbGFpbXMiOnsiaWRfdG9rZW4iOnsiYWNyIjp7InZhbHVlIjoidXJuOm1hY2U6aW5jb21tb246aWFwOnNpbHZlciIsImVzc2VudGlhbCI6dHJ1ZX19fSwicmVkaXJlY3RfdXJpIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL3BpbmdpZGVudGl0eS1waW5nZmVkZXJhdGUtZmFwaS1hZHYtb3AtcHJpdmF0ZS1rZXktcGFyLXBsYWluXC9jYWxsYmFjaz9kdW1teTE9bG9yZW0mZHVtbXkyPWlwc3VtIiwic3RhdGUiOiJBR2RFaXRweWZSIiwiZXhwIjoxNjI4ODcwNjY2LCJpYXQiOjE2Mjg4NzAzNjYsImNvZGVfY2hhbGxlbmdlIjoiOUhGU29jT2FDUGxtUFYxRDVPMTBSZkY4WVlXeWVYaUNTYzBSMUZuc2tfUSJ9.ktjE26d0C0BXKkfPQgBuD_5ShoeyaboJ-NjOFAa4XGJsJHt7XS08rYb8JnpbrwnxySPzUOLOmepMLQrk0QdtyHed40eJz7v4ZfethrVY2W9AF0CP9B1NuOfklt1dOhlXJBhVS4gdfFSe0wWzoGpSQLjkxByoV1dz7m5W4t3RBPLaonJfUmVjcrScO4zgSiykmzr_NW5bFpI2cEemG0AkvJITZyNvalj7QHIX_TGH25L1GjdTicjRpUcakpyuToQIWd5t33i0slHRd9ese-ohjHcQv3zsJ_mCWZ2QPHq6MEjdxwq92i5Ujx-nLY_9LDjfK9Umuz7-Z0BAHbvpAg0QxQ
key
{"p":"43lqQE0EN1LJ_jdqHq56hNFjErKfcrwJnVpIVRsXCZWboV4MSfLzGGEyePPs6SxV6-l_txQY-M2dW6xLaedRUlaFT89r10cIm136ecYUzs51iX_GZW_AvohaXSmAbZKpjLmsHIDelgggQKjDQxGGbmAAQojnqzorpVrfz-8aUNc","kty":"RSA","q":"q1t1ErKAx06nV7ohJ4zlo3xUeMA3rO7HLmK6Eh460DsiX80AsCxyw1AsQy0N1W8u_RgkA3y_p_5Nf7K1KLLa9mduIBWyUFEim1EneviM4m3q7e2UtQ7iezh6FatYFZD5c_v_CH2gV0bhxZrMzNc8ubL46OXo5h1WycY1iAqsjNs","d":"ElS590xAIy7zN4KHKmq2rLnAg1TJ9kODaUrb98X3gCGuTOLBAtFzUqjPyBF8rqXAtkgl8inec6GwY6gmB9p53quJfKSunnN7CbU3Qe37f8HBgS95vFsmJtbctbJ43XKlwo0imYbIeBYLmxKUJt5BKSnUYWWv4EI2AVE_LrqecL-QaNLH2IxY1JVLvR8WhP7wzjTHIsGjaQGn7199eVBaHZ7KTC-bFaEWnPgklR0e8t8TdICUqJudCqTEuoEBFYXRdqi_3betdNZHtJdcwfk9VEXTYTnjzw0fJ7RoFyVE1_1-wMULnEYk5SyfSYfYsBq_V25e-TUSLxB3IXgzBmJVOQ","e":"AQAB","use":"sig","kid":"pingfederate-fapi-jwt-assertion-client2","qi":"rBDWPBNof1ZrvpqRqpPIf-hn6jmOmLN5mzv8ArwfYEuoIPo9Ltzta1m42A6KQAAsHfXUaKtihSXnVopYtYcxguVNCi2qbDh4nx7ZZNCcQsKSkUOw-hgm4vHZJMOJ-4jh6jthUeLTRmCpEZAHQrtmnpQ1tC1g3g2VCDH48p8cLzo","dp":"BrSxmSusECV0pvXjPvxNyFST4x047hz0-5qJv1iJGVM7v0oSequa1wEmh8JJHaac8dN0XGVPRyZomSc_IeQb1Z2PWIb42uPRMSNYGvbn7iDP_jmyE5Nzzyod39k1XAWS0f83P6_c3_dlXAKdnwCJQf-6gjue-MFCQCGpr2uRDwk","alg":"PS256","dq":"GyE3v-YTDXsec308ko50LRYaKaQFLJQBZQ6sdwHiPeWe45wJZ9shsFqZJ2mSryATSG7yBLtTfL1-d6FLnU3z7N8jSGEnAiBWYlDO92EyrQbKEzFyQdhBc1DVw2iFYaS6WeqjzixVnnvScv63Phc1vhDf57--x_ANNZT0FL3b49E","n":"mENeKNMC5ttp60qEq6LZoWaihn-__Ei70wnW8Zd_-ILFnYcaM90oTTnl8R2uHD4EJ3t_VCjFteXIwWV7OwDmRmOMwda0X1R5IKYn0O2ujT8NI4citj8G4NHY0r5Y5loLdb5dynGgT-YpsnWwfTC8Ky98gNA3OLf6Z2n8PEdKJr818RMAC0Vx6NQMHBNG4jI1D0bvbrZbx0XkXan7h2Elm9HLRjzHar5Qb5gFLGQRFdeHVHF5lRKyAFgdeQPvBqMiRsAwcgyKxDjbzF5qHPwhKMB-7IVhxuSULMvgSkesIIhrylzU9bo2KRhcxTB7oPkhAbPgumpoVZV0ME-ypiy77Q"}
2021-08-13 15:59:26 SUCCESS
BuildRequestObjectPostToPAREndpoint
request
eyJraWQiOiJwaW5nZmVkZXJhdGUtZmFwaS1qd3QtYXNzZXJ0aW9uLWNsaWVudDIiLCJhbGciOiJQUzI1NiJ9.eyJpc3MiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwicmVzcG9uc2VfdHlwZSI6ImNvZGUgaWRfdG9rZW4iLCJjb2RlX2NoYWxsZW5nZV9tZXRob2QiOiJTMjU2Iiwibm9uY2UiOiIzZGdGMUZHN0dLIiwiY2xpZW50X2lkIjoiZmFwaV9hZHZfb3Bfd19wcml2YXRlX2tleV9wYXJfc2Vjb25kX2NsaWVudCIsImF1ZCI6Imh0dHBzOlwvXC9pZHAuY29uZi5waW5nLWVuZy5jb206OTAzMSIsIm5iZiI6MTYyODg3MDM2Niwic2NvcGUiOiJvcGVuaWQgcGF5bWVudHMiLCJjbGFpbXMiOnsiaWRfdG9rZW4iOnsiYWNyIjp7InZhbHVlIjoidXJuOm1hY2U6aW5jb21tb246aWFwOnNpbHZlciIsImVzc2VudGlhbCI6dHJ1ZX19fSwicmVkaXJlY3RfdXJpIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL3BpbmdpZGVudGl0eS1waW5nZmVkZXJhdGUtZmFwaS1hZHYtb3AtcHJpdmF0ZS1rZXktcGFyLXBsYWluXC9jYWxsYmFjaz9kdW1teTE9bG9yZW0mZHVtbXkyPWlwc3VtIiwic3RhdGUiOiJBR2RFaXRweWZSIiwiZXhwIjoxNjI4ODcwNjY2LCJpYXQiOjE2Mjg4NzAzNjYsImNvZGVfY2hhbGxlbmdlIjoiOUhGU29jT2FDUGxtUFYxRDVPMTBSZkY4WVlXeWVYaUNTYzBSMUZuc2tfUSJ9.ktjE26d0C0BXKkfPQgBuD_5ShoeyaboJ-NjOFAa4XGJsJHt7XS08rYb8JnpbrwnxySPzUOLOmepMLQrk0QdtyHed40eJz7v4ZfethrVY2W9AF0CP9B1NuOfklt1dOhlXJBhVS4gdfFSe0wWzoGpSQLjkxByoV1dz7m5W4t3RBPLaonJfUmVjcrScO4zgSiykmzr_NW5bFpI2cEemG0AkvJITZyNvalj7QHIX_TGH25L1GjdTicjRpUcakpyuToQIWd5t33i0slHRd9ese-ohjHcQv3zsJ_mCWZ2QPHq6MEjdxwq92i5Ujx-nLY_9LDjfK9Umuz7-Z0BAHbvpAg0QxQ
2021-08-13 15:59:26 SUCCESS
CreateClientAuthenticationAssertionClaims
Created client assertion claims
iss
fapi_adv_op_w_private_key_par_second_client
sub
fapi_adv_op_w_private_key_par_second_client
aud
https://idp.conf.ping-eng.com:9032/as/token.oauth2
jti
mMfZNDlMNUjeruQjXZWc
iat
1628870366
exp
1628870426
2021-08-13 15:59:26 SUCCESS
UpdateClientAuthenticationAssertionClaimsWithISSAud
Updated audience in client assertion claims
iss
fapi_adv_op_w_private_key_par_second_client
sub
fapi_adv_op_w_private_key_par_second_client
jti
mMfZNDlMNUjeruQjXZWc
iat
1628870366
exp
1628870426
aud
https://idp.conf.ping-eng.com:9031
2021-08-13 15:59:26 SUCCESS
SignClientAuthenticationAssertion
Signed the client assertion
client_assertion
eyJraWQiOiJwaW5nZmVkZXJhdGUtZmFwaS1qd3QtYXNzZXJ0aW9uLWNsaWVudDIiLCJhbGciOiJQUzI1NiJ9.eyJzdWIiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwiYXVkIjoiaHR0cHM6XC9cL2lkcC5jb25mLnBpbmctZW5nLmNvbTo5MDMxIiwiaXNzIjoiZmFwaV9hZHZfb3Bfd19wcml2YXRlX2tleV9wYXJfc2Vjb25kX2NsaWVudCIsImV4cCI6MTYyODg3MDQyNiwiaWF0IjoxNjI4ODcwMzY2LCJqdGkiOiJtTWZaTkRsTU5VamVydVFqWFpXYyJ9.APD9JPBRN4ynJHV0-mTHv2jzcqWgpUVabQKxQdThlYJoMRB3035AYn_Xc2mKsOQ1-fJFofIZSLEuMoqTRFxJedGP6ekwan6en0NiUGsYrmM2B8L5XuTqX4TQ3tVurYcgjc5Bo7JLFHqLeT_H-iU1a2TKlm7GxIAgUslVWpphkMNwaSL5bD1dBNg4D_n_t3xyJwJXVBckT94hOGhhUOypLtXfvoIy8oKXG2veZGWuI6JhqWFO_HM7bX-rKIQVyTop06_DvpWWBWSnpNSqDte02iKAsKVwjhmpgUJ3vS73HhwF4CRhRWjnnpnUzgn9SzFjJsnFMePild57nDuUozVj9Q
2021-08-13 15:59:26 SUCCESS
AddClientAssertionToPAREndpointParameters
Added client assertion to request
request
{
  "request": "eyJraWQiOiJwaW5nZmVkZXJhdGUtZmFwaS1qd3QtYXNzZXJ0aW9uLWNsaWVudDIiLCJhbGciOiJQUzI1NiJ9.eyJpc3MiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwicmVzcG9uc2VfdHlwZSI6ImNvZGUgaWRfdG9rZW4iLCJjb2RlX2NoYWxsZW5nZV9tZXRob2QiOiJTMjU2Iiwibm9uY2UiOiIzZGdGMUZHN0dLIiwiY2xpZW50X2lkIjoiZmFwaV9hZHZfb3Bfd19wcml2YXRlX2tleV9wYXJfc2Vjb25kX2NsaWVudCIsImF1ZCI6Imh0dHBzOlwvXC9pZHAuY29uZi5waW5nLWVuZy5jb206OTAzMSIsIm5iZiI6MTYyODg3MDM2Niwic2NvcGUiOiJvcGVuaWQgcGF5bWVudHMiLCJjbGFpbXMiOnsiaWRfdG9rZW4iOnsiYWNyIjp7InZhbHVlIjoidXJuOm1hY2U6aW5jb21tb246aWFwOnNpbHZlciIsImVzc2VudGlhbCI6dHJ1ZX19fSwicmVkaXJlY3RfdXJpIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL3BpbmdpZGVudGl0eS1waW5nZmVkZXJhdGUtZmFwaS1hZHYtb3AtcHJpdmF0ZS1rZXktcGFyLXBsYWluXC9jYWxsYmFjaz9kdW1teTE9bG9yZW0mZHVtbXkyPWlwc3VtIiwic3RhdGUiOiJBR2RFaXRweWZSIiwiZXhwIjoxNjI4ODcwNjY2LCJpYXQiOjE2Mjg4NzAzNjYsImNvZGVfY2hhbGxlbmdlIjoiOUhGU29jT2FDUGxtUFYxRDVPMTBSZkY4WVlXeWVYaUNTYzBSMUZuc2tfUSJ9.ktjE26d0C0BXKkfPQgBuD_5ShoeyaboJ-NjOFAa4XGJsJHt7XS08rYb8JnpbrwnxySPzUOLOmepMLQrk0QdtyHed40eJz7v4ZfethrVY2W9AF0CP9B1NuOfklt1dOhlXJBhVS4gdfFSe0wWzoGpSQLjkxByoV1dz7m5W4t3RBPLaonJfUmVjcrScO4zgSiykmzr_NW5bFpI2cEemG0AkvJITZyNvalj7QHIX_TGH25L1GjdTicjRpUcakpyuToQIWd5t33i0slHRd9ese-ohjHcQv3zsJ_mCWZ2QPHq6MEjdxwq92i5Ujx-nLY_9LDjfK9Umuz7-Z0BAHbvpAg0QxQ",
  "client_assertion": "eyJraWQiOiJwaW5nZmVkZXJhdGUtZmFwaS1qd3QtYXNzZXJ0aW9uLWNsaWVudDIiLCJhbGciOiJQUzI1NiJ9.eyJzdWIiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwiYXVkIjoiaHR0cHM6XC9cL2lkcC5jb25mLnBpbmctZW5nLmNvbTo5MDMxIiwiaXNzIjoiZmFwaV9hZHZfb3Bfd19wcml2YXRlX2tleV9wYXJfc2Vjb25kX2NsaWVudCIsImV4cCI6MTYyODg3MDQyNiwiaWF0IjoxNjI4ODcwMzY2LCJqdGkiOiJtTWZaTkRsTU5VamVydVFqWFpXYyJ9.APD9JPBRN4ynJHV0-mTHv2jzcqWgpUVabQKxQdThlYJoMRB3035AYn_Xc2mKsOQ1-fJFofIZSLEuMoqTRFxJedGP6ekwan6en0NiUGsYrmM2B8L5XuTqX4TQ3tVurYcgjc5Bo7JLFHqLeT_H-iU1a2TKlm7GxIAgUslVWpphkMNwaSL5bD1dBNg4D_n_t3xyJwJXVBckT94hOGhhUOypLtXfvoIy8oKXG2veZGWuI6JhqWFO_HM7bX-rKIQVyTop06_DvpWWBWSnpNSqDte02iKAsKVwjhmpgUJ3vS73HhwF4CRhRWjnnpnUzgn9SzFjJsnFMePild57nDuUozVj9Q",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
2021-08-13 15:59:26
CallPAREndpoint
HTTP request
request_uri
https://idp.conf.ping-eng.com:9031/as/par.oauth2
request_method
POST
request_headers
{
  "accept": "application/json;charset\u003dUTF-8",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "accept-charset": "utf-8",
  "content-length": "2121"
}
request_body
request=eyJraWQiOiJwaW5nZmVkZXJhdGUtZmFwaS1qd3QtYXNzZXJ0aW9uLWNsaWVudDIiLCJhbGciOiJQUzI1NiJ9.eyJpc3MiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwicmVzcG9uc2VfdHlwZSI6ImNvZGUgaWRfdG9rZW4iLCJjb2RlX2NoYWxsZW5nZV9tZXRob2QiOiJTMjU2Iiwibm9uY2UiOiIzZGdGMUZHN0dLIiwiY2xpZW50X2lkIjoiZmFwaV9hZHZfb3Bfd19wcml2YXRlX2tleV9wYXJfc2Vjb25kX2NsaWVudCIsImF1ZCI6Imh0dHBzOlwvXC9pZHAuY29uZi5waW5nLWVuZy5jb206OTAzMSIsIm5iZiI6MTYyODg3MDM2Niwic2NvcGUiOiJvcGVuaWQgcGF5bWVudHMiLCJjbGFpbXMiOnsiaWRfdG9rZW4iOnsiYWNyIjp7InZhbHVlIjoidXJuOm1hY2U6aW5jb21tb246aWFwOnNpbHZlciIsImVzc2VudGlhbCI6dHJ1ZX19fSwicmVkaXJlY3RfdXJpIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL3BpbmdpZGVudGl0eS1waW5nZmVkZXJhdGUtZmFwaS1hZHYtb3AtcHJpdmF0ZS1rZXktcGFyLXBsYWluXC9jYWxsYmFjaz9kdW1teTE9bG9yZW0mZHVtbXkyPWlwc3VtIiwic3RhdGUiOiJBR2RFaXRweWZSIiwiZXhwIjoxNjI4ODcwNjY2LCJpYXQiOjE2Mjg4NzAzNjYsImNvZGVfY2hhbGxlbmdlIjoiOUhGU29jT2FDUGxtUFYxRDVPMTBSZkY4WVlXeWVYaUNTYzBSMUZuc2tfUSJ9.ktjE26d0C0BXKkfPQgBuD_5ShoeyaboJ-NjOFAa4XGJsJHt7XS08rYb8JnpbrwnxySPzUOLOmepMLQrk0QdtyHed40eJz7v4ZfethrVY2W9AF0CP9B1NuOfklt1dOhlXJBhVS4gdfFSe0wWzoGpSQLjkxByoV1dz7m5W4t3RBPLaonJfUmVjcrScO4zgSiykmzr_NW5bFpI2cEemG0AkvJITZyNvalj7QHIX_TGH25L1GjdTicjRpUcakpyuToQIWd5t33i0slHRd9ese-ohjHcQv3zsJ_mCWZ2QPHq6MEjdxwq92i5Ujx-nLY_9LDjfK9Umuz7-Z0BAHbvpAg0QxQ&client_assertion=eyJraWQiOiJwaW5nZmVkZXJhdGUtZmFwaS1qd3QtYXNzZXJ0aW9uLWNsaWVudDIiLCJhbGciOiJQUzI1NiJ9.eyJzdWIiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwiYXVkIjoiaHR0cHM6XC9cL2lkcC5jb25mLnBpbmctZW5nLmNvbTo5MDMxIiwiaXNzIjoiZmFwaV9hZHZfb3Bfd19wcml2YXRlX2tleV9wYXJfc2Vjb25kX2NsaWVudCIsImV4cCI6MTYyODg3MDQyNiwiaWF0IjoxNjI4ODcwMzY2LCJqdGkiOiJtTWZaTkRsTU5VamVydVFqWFpXYyJ9.APD9JPBRN4ynJHV0-mTHv2jzcqWgpUVabQKxQdThlYJoMRB3035AYn_Xc2mKsOQ1-fJFofIZSLEuMoqTRFxJedGP6ekwan6en0NiUGsYrmM2B8L5XuTqX4TQ3tVurYcgjc5Bo7JLFHqLeT_H-iU1a2TKlm7GxIAgUslVWpphkMNwaSL5bD1dBNg4D_n_t3xyJwJXVBckT94hOGhhUOypLtXfvoIy8oKXG2veZGWuI6JhqWFO_HM7bX-rKIQVyTop06_DvpWWBWSnpNSqDte02iKAsKVwjhmpgUJ3vS73HhwF4CRhRWjnnpnUzgn9SzFjJsnFMePild57nDuUozVj9Q&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
request_mutual_tls
{
  "cert": "MIID3zCCAsegAwIBAgIUUbO7wc+DFfteEqK0M1D+iRwKDOkwDQYJKoZIhvcNAQELBQAwfjELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAkNPMQ8wDQYDVQQHDAZEZW52ZXIxFTATBgNVBAoMDFBpbmdJZGVudGl0eTEUMBIGA1UECwwLRGV2ZWxvcG1lbnQxJDAiBgNVBAMMG0ZBUEkgQWR2IE9QIHcgU2Vjb25kIENsaWVudDAgFw0yMTA3MjYyMjM0NDFaGA8yMTIxMDcwMjIyMzQ0MVowfjELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAkNPMQ8wDQYDVQQHDAZEZW52ZXIxFTATBgNVBAoMDFBpbmdJZGVudGl0eTEUMBIGA1UECwwLRGV2ZWxvcG1lbnQxJDAiBgNVBAMMG0ZBUEkgQWR2IE9QIHcgU2Vjb25kIENsaWVudDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALASMA/8vTQ+vFqsR7UBSG5cldHwJ5SGvoHpGqhdv6xSXHUi8bp0Ob927l93bdkk1YnWqYQbmtmwlfqRFyxXYAvNXoIrFY86gBOg4O9vkCeVSMK1l7CdSps3ypXR4p7Fy1eERIN4fTwUS5wRu0bpcG4kocShcoxYu5A30s8k6onYVafO0ZfrbKEfnEJY74f8A3v8ns2Nr5AasPqZsz3g5TiyVygRG6+D6yrhORvW33roDEYnrwompE6UUkjVXNhoBoXvohLhf3Zh7kEpVQjXjD/rMlj5NFSFXLW4RXDokruapCyY3Q66OoAO5SYBpKtfxHiAp28ooUSmmwpxd39voaUCAwEAAaNTMFEwHQYDVR0OBBYEFFGFWe386uahXiBMwViRnP9t210BMB8GA1UdIwQYMBaAFFGFWe386uahXiBMwViRnP9t210BMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAJ346s52BzNNZU9Sc6qUnG68yjZxCadEgijudr5hILhkLYsLy6HOdnirsakqdc/KhbRQPm+TbuUT94bahigOM1QuCGa8XjewTdmXGDdRxFTHNMLc+SopCuInXeNlBO8tekbWSglGaP742240gERzXHaGyqrSzXeL2yosY2evtqbMB9i+d8uMhTYniwP3Isbbld2lCCF/Cw7flVzXnWItU0pGVj8U9qIW874eMDss+dxq6WfwaVzyXqH7k59xI/37zxWdRa1zNIwyi8H1dkl0vsoJSrrIGPCJpq+snT+6+xrUbrRn4H+K0eQSLE+LmmxuOaE4WgdK4ln9ZUXQC90R1aM\u003d",
  "key": "MIIEwAIBADANBgkqhkiG9w0BAQEFAASCBKowggSmAgEAAoIBAQCwEjAP/L00PrxarEe1AUhuXJXR8CeUhr6B6RqoXb+sUlx1IvG6dDm/du5fd23ZJNWJ1qmEG5rZsJX6kRcsV2ALzV6CKxWPOoAToODvb5AnlUjCtZewnUqbN8qV0eKexctXhESDeH08FEucEbtG6XBuJKHEoXKMWLuQN9LPJOqJ2FWnztGX62yhH5xCWO+H/AN7/J7Nja+QGrD6mbM94OU4slcoERuvg+sq4Tkb1t966AxGJ68KJqROlFJI1VzYaAaF76IS4X92Ye5BKVUI14w/6zJY+TRUhVy1uEVw6JK7mqQsmN0OujqADuUmAaSrX8R4gKdvKKFEppsKcXd/b6GlAgMBAAECggEBAIxtlSPLImR+/N8ctPxqj4hmE6AjeI3/ggY/EuHiE7Ou5MsQGdfqRvysMKa3rEcaF64eJYmWMsUZECWOfvsAnTwMiiorjsBzmh8Nmxmc006exC93ggp9CToPH2aqxaJ4gxvEBJkPCmNWlI9fnQyLtv5B/TvEwIWrZ704qMxJ1z4klxZgPvRAa5lCRIs1BAwkvtgkc9S2nTzJqO7tfHpXk1tCMxkHyqMlfpBfWxgysPQBueju/IFXw3IoO80uOCZYnHagMmZeSdomlCQmX+5UjanVt4TFFppIQxKXjrkJ0Q0XcnboNs+VsKZgvFdVAKFXHZY5BtaQaC8U8vPKDH2SSikCgYEA5z6fgw7T9etmkqsmc+cAt6LH/NspMOH92Ot7IPgjZIiODx1AIPIQXM6/DzJuntyYtMk+ZJ06q/h7C8ZkdAQX1z3M6maD2y8vVVIMh1yjd2el7CvAc3fejEbliKKK2R9RSGB8udNcGVyNbsjTTLJb2mx89JFI2yGA0gXyVTbT7CsCgYEAwuuBMF0THYZ4kNi62MvF/EblkKwKY1+v6XFdOZiyQljClNdT8bRFxjkdnIxaXemm6X5MPtsKBKY+0ix3uHKXdglzycCth/KuhqmItT1gitPEjq3Ut5Q9liWPpKNhuJjdlUi97Yj7r4NRBWeCLAUBh4n1lpl3rPxIvBMJqFgIMW8CgYEAinFPhmMmOyDHtB+LUfCG2Wo3WQbMzls+YtP4T3C/n7yxcBMPBapmaWnNsQd8etePBQ1GsW4AZlzJLe+EzIB21YJGYD8nyd2h9O6+WXv40c/X4mD/QyIMtubrHLZTclHxk+dQROBpTzW95wmMl2pg24//71vbxnV0bkjpIGNG1SkCgYEAkvnTsy0rgcLo3Ief9GNLCdxHs9wWBTKcyZDis9Bw8dhN+L+ZG5NMXZipvGaUqWXKpxvF0EuH9VOJ4R8Iszss/CNKfOHdt7oFYaMqY0dBqcze1Js836RXAAWYl5Ne1zvlMXDlTdxRs9l32XRgUmL/8TzUw1c7R2QAUFimmpquqt8CgYEAjtIr2L2llacZi7vBfFwgvjVVg7vuAvGpRokC4m6OzfjcO7fPVJa9f8IZLSQU6E2VM//dbuAHbPC2iIGnQn848cwF2rhXrY0VvqfpTuxQCdiW+TGwukLxW0AHWeiD5YauGqtz4+ZC6DWGyFZQSPB0OxcyG9wu0OBKbG70lP6scQE\u003d"
}
2021-08-13 15:59:27 RESPONSE
CallPAREndpoint
HTTP response
response_status_code
201 CREATED
response_status_text
Created
response_headers
{
  "date": "Fri, 13 Aug 2021 15:59:27 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003dZTMQH9CSoepejjGLtlrVQW; Path\u003d/; Secure; HttpOnly; SameSite\u003dNone",
  "transfer-encoding": "chunked"
}
response_body
{"expires_in":60,"request_uri":"urn:ietf:params:oauth:request_uri:vdDWi7ucccgoFf0ymo_GM1xYo-IIjvKz"}
2021-08-13 15:59:27 SUCCESS
CallPAREndpoint
Storing pushed_authorization_endpoint_response_http_status 201
2021-08-13 15:59:27 SUCCESS
CallPAREndpoint
Parsed pushed authorization request endpoint response
expires_in
60
request_uri
urn:ietf:params:oauth:request_uri:vdDWi7ucccgoFf0ymo_GM1xYo-IIjvKz
2021-08-13 15:59:27 SUCCESS
CheckIfPAREndpointResponseError
pushed authorization request endpoint correct response.
2021-08-13 15:59:27 SUCCESS
CheckForRequestUriValue
Found valid request_uri
request_uri
urn:ietf:params:oauth:request_uri:vdDWi7ucccgoFf0ymo_GM1xYo-IIjvKz
2021-08-13 15:59:27 SUCCESS
CheckForPARResponseExpiresIn
Found expires_in
expires_in
60
2021-08-13 15:59:27 SUCCESS
ExtractRequestUriFromPARResponse
Extracted the request_uri: urn:ietf:params:oauth:request_uri:vdDWi7ucccgoFf0ymo_GM1xYo-IIjvKz
2021-08-13 15:59:27 SUCCESS
EnsureMinimumRequestUriEntropy
Calculated shannon entropy seems sufficient
actual
323.93629341796714
expected
128.0
2021-08-13 15:59:27 SUCCESS
BuildRequestObjectByReferenceRedirectToAuthorizationEndpoint
Sending to authorization endpoint
redirect_to_authorization_endpoint
https://idp.conf.ping-eng.com:9031/as/authorization.oauth2?request_uri=urn:ietf:params:oauth:request_uri:vdDWi7ucccgoFf0ymo_GM1xYo-IIjvKz&client_id=fapi_adv_op_w_private_key_par_second_client&redirect_uri=https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback?dummy1%3Dlorem%26dummy2%3Dipsum&scope=openid%20payments&response_type=code%20id_token
2021-08-13 15:59:27 REDIRECT
fapi1-advanced-final
Redirecting to authorization endpoint
redirect_to
https://idp.conf.ping-eng.com:9031/as/authorization.oauth2?request_uri=urn:ietf:params:oauth:request_uri:vdDWi7ucccgoFf0ymo_GM1xYo-IIjvKz&client_id=fapi_adv_op_w_private_key_par_second_client&redirect_uri=https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback?dummy1%3Dlorem%26dummy2%3Dipsum&scope=openid%20payments&response_type=code%20id_token
2021-08-13 15:59:27
WebRunner
Scripted browser HTTP request
browser
goToUrl
request_method
GET
request_uri
https://idp.conf.ping-eng.com:9031/as/authorization.oauth2?request_uri=urn:ietf:params:oauth:request_uri:vdDWi7ucccgoFf0ymo_GM1xYo-IIjvKz&client_id=fapi_adv_op_w_private_key_par_second_client&redirect_uri=https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback?dummy1%3Dlorem%26dummy2%3Dipsum&scope=openid%20payments&response_type=code%20id_token
2021-08-13 15:59:28 RESPONSE
WebRunner
Scripted browser HTTP response
response_content
<!DOCTYPE html>


<!-- template name: html.form.login.template.html -->


<!-- Configurable default behavior for the Remember Username checkbox -->
            <!-- set the checkbox to unchecked -->
            

<html lang="en" dir="ltr">
<head>
    <title>Sign On</title>
    <base href="https://idp.conf.ping-eng.com:9031/"/>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"/>
    <meta name="viewport" content="width=device-width, initial-scale=1.0, minimum-scale=1.0, maximum-scale=1.0, user-scalable=no"/>
    <meta http-equiv="x-ua-compatible" content="IE=edge" />
    <link rel="stylesheet" type="text/css" href="assets/css/main.css"/>
    </head>

<body onload="setFocus();">

<div class="ping-container ping-signin login-template">

    <!--
    if there is a logo present in the 'company-logo' container,
    then 'has-logo' class should be added to 'ping-header' container.
    -->
    <div class="ping-header">
        <span class="company-logo"><!-- client company logo here --></span>
        Sign On
    </div>
    <!-- .ping-header -->

    <div class="ping-body-container">

        <div>
            <form method="POST" action="/as/WnjDv/resume/as/authorization.ping" autocomplete="off">

                <div class="ping-messages">
                                        
                                        
                </div>

                
                        <div class="ping-input-label">
                            Username
                        </div>
                        <div class="ping-input-container">
                                                            <input id="username" type="text" size="36" name="pf.username" value="" autocorrect="off" autocapitalize="off" onKeyPress="return postOnReturn(event)"  /><!---->
                                                        <div class="place-bottom type-alert tooltip-text" id="username-text">
                                <div class="icon">!</div>
                                Please fill out this field.
                            </div>
                        </div>

                        <div class="ping-input-label">
                            Password
                        </div>
                        <div class="ping-input-container password-container">
                            <input id="password" type="password" size="36" name="pf.pass" onKeyPress="return postOnReturn(event)" />
                            <div class="place-bottom type-alert tooltip-text" id="password-text">
                                <div class="icon">!</div>
                                Please fill out this field.
                            </div>
                        </div>

                        
                        
                        <div class="ping-buttons">
                            <input type="hidden" name="pf.ok" value="" />
                            <input type="hidden" name="pf.cancel" value="" />
                            <span id="signOnButtonSpan">
                                <a onclick="postOk();" class="ping-button normal allow" id="signOnButton" title="Sign On">
                                Sign On
                                </a>
                            </span>
                        </div><!-- .ping-buttons -->

                        
                        
                                    
                <!-- #recaptcha -->
                
                <input type="hidden" name="pf.adapterId" id="pf.adapterId" value="HTMLFormSimplePCV" />
            </form>
        </div><!-- .ping-body// blank div -->
        
    </div><!-- .ping-body-container -->

    <div class="ping-footer-container">
        <div class="ping-footer">
            <div class="ping-credits"></div>
            <div class="ping-copyright">© Copyright 2021 Ping Identity. All rights reserved.</div>
        </div>
        <!-- .ping-footer -->
    </div>
    <!-- .ping-footer-container -->

</div><!-- .ping-container -->

<script type="text/javascript">

	function postForgotPassword() {

		document.forms[0]['pf.passwordreset'].value = 'clicked';
		document.forms[0].submit();
	}

	function postRecoverUsername() {
        document.forms[0]['pf.usernamerecovery'].value = 'clicked';
		document.forms[0].submit();
	}

	function postAlternateAuthnSystem(system) {
	    var variants = ["Biometrics", "Windows Hello", "Face ID",  "Touch ID"];
	    for (i = 0; i < variants.length; i++) {
	        if(variants[i] == system) {
	            system = "FIDO";
	        }
	    }
	    document.forms[0]['$alternateAuthnSystem'].value = system;
	    document.forms[0].submit();
	}


	function postRegistration()
    {
        document.forms[0]['$registrationValue'].value = true;
        document.forms[0].submit();
    }

    function postOk() {
        if (false) {
            grecaptcha.execute();
        }
        else {
            // remove error tips
            if (document.forms[0]['pf.username'].value !== '') {
                document.getElementById('username-text').className = 'place-bottom type-alert tooltip-text';
            }
            if (document.forms[0]['pf.pass'].value !== '') {
                document.getElementById('password-text').className = 'place-bottom type-alert tooltip-text';
            }
            // Add back
            if (document.forms[0]['pf.username'].value === '') {
                document.getElementById('username-text').className += ' show';
            }
            else if (document.forms[0]['pf.pass'].value === '') {
                document.getElementById('password-text').className += ' show';
            }
            else {
                submitForm()
            }
        }
    }

    function submitForm()
    {
        var signOnButtonSpan = document.getElementById('signOnButtonSpan');
        signOnButtonSpan.classList.add('content-columns', 'disabled');
        signOnButtonSpan.style = "pointer-events: none;";

        var signOnButton = document.getElementById('signOnButton');
        signOnButton.innerHTML = 'Signing on...';

        document.forms[0]['pf.ok'].value = 'clicked';
        document.forms[0].submit();
        if(false) {
            grecaptcha.reset();
        }
    }

    function postCancel() {
        document.forms[0]['pf.cancel'].value = 'clicked';
        document.forms[0].submit();
    }

    function postOnReturn(e) {
        var keycode;
        if (window.event) keycode = window.event.keyCode;
        else if (e) keycode = e.which;
        else return true;

        if (keycode == 13) {
            postOk();
            return false;
        } else {
            return true;
        }
    }

    function setFocus() {
        var platform = navigator.platform;
        if (platform != null && platform.indexOf("iPhone") == -1) {
                            document.getElementById('username').focus();
                    }
    }

    function setMobile(mobile) {
        var className = ' mobile',
            hasClass = (bodyTag.className.indexOf(className) !== -1);

        if (mobile && !hasClass) {
            bodyTag.className += className;

        } else if (!mobile && hasClass) {
            bodyTag.className = bodyTag.className.replace(className, '');
        }

        
        <!-- Check if this is the PingOne Mobile App -->
            }

    function getScreenWidth() {
        return (window.outerHeight) ? window.outerWidth : document.body.clientWidth;
    }

    var bodyTag = document.getElementsByTagName('body')[0],
        width = getScreenWidth(),
        remember = false && false;

    
    if (/Android|webOS|iPhone|iPod|BlackBerry|IEMobile|Opera Mini/i.test(navigator.userAgent)) {
        setMobile(true);
    } else {
        setMobile((width <= 480));
        window.onresize = function() {
            width = getScreenWidth();
            setMobile((width <= 480));
        }
    }
   


</script>

</body>
</html>
response_content_type
text/html
response_status_text
200-OK
response_status_code
200
2021-08-13 15:59:28 INFO
WebRunner
Waiting
regexp
seconds
10
task
Initial Login
browser
wait
action
element_type
id
url
https://idp.conf.ping-eng.com:9031/as/authorization.oauth2?request_uri=urn:ietf:params:oauth:request_uri:vdDWi7ucccgoFf0ymo_GM1xYo-IIjvKz&client_id=fapi_adv_op_w_private_key_par_second_client&redirect_uri=https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback?dummy1%3Dlorem%26dummy2%3Dipsum&scope=openid%20payments&response_type=code%20id_token
target
username
2021-08-13 15:59:28 INFO
WebRunner
Entering text
task
Initial Login
browser
text
element_type
id
value
joe
url
https://idp.conf.ping-eng.com:9031/as/authorization.oauth2?request_uri=urn:ietf:params:oauth:request_uri:vdDWi7ucccgoFf0ymo_GM1xYo-IIjvKz&client_id=fapi_adv_op_w_private_key_par_second_client&redirect_uri=https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback?dummy1%3Dlorem%26dummy2%3Dipsum&scope=openid%20payments&response_type=code%20id_token
target
username
2021-08-13 15:59:28 INFO
WebRunner
Entering text
task
Initial Login
browser
text
element_type
id
value
2Federate
url
https://idp.conf.ping-eng.com:9031/as/authorization.oauth2?request_uri=urn:ietf:params:oauth:request_uri:vdDWi7ucccgoFf0ymo_GM1xYo-IIjvKz&client_id=fapi_adv_op_w_private_key_par_second_client&redirect_uri=https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback?dummy1%3Dlorem%26dummy2%3Dipsum&scope=openid%20payments&response_type=code%20id_token
target
password
2021-08-13 15:59:28 INFO
WebRunner
Clicking an element
task
Initial Login
browser
click
element_type
id
url
https://idp.conf.ping-eng.com:9031/as/authorization.oauth2?request_uri=urn:ietf:params:oauth:request_uri:vdDWi7ucccgoFf0ymo_GM1xYo-IIjvKz&client_id=fapi_adv_op_w_private_key_par_second_client&redirect_uri=https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback?dummy1%3Dlorem%26dummy2%3Dipsum&scope=openid%20payments&response_type=code%20id_token
target
signOnButton
2021-08-13 15:59:28 INFO
WebRunner
Completed processing of webpage
task
Initial Login
browser
complete
response_status_text
200-OK
match
https://idp.conf.ping-eng.com:9031/as/authorization.oauth2*
url
https://idp.conf.ping-eng.com:9031/as/WnjDv/resume/as/authorization.ping
response_status_code
200
2021-08-13 15:59:28 INFO
WebRunner
Clicking an element
task
Authorize Client
browser
click
element_type
css
url
https://idp.conf.ping-eng.com:9031/as/WnjDv/resume/as/authorization.ping
target
a.ping-button.normal.allow
2021-08-13 15:59:28 INCOMING
fapi1-advanced-final
Incoming HTTP request to test instance wCkrQW9Zx2JRQay
incoming_headers
{
  "host": "www.certification.openid.net",
  "upgrade-insecure-requests": "1",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.72 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "same-origin",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "referer": "https://idp.conf.ping-eng.com:9031/as/WnjDv/resume/as/authorization.ping",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9",
  "cookie": "JSESSIONID\u003d9BC84D4D9F29B61A4F14362976BABA39",
  "origin": "https://idp.conf.ping-eng.com:9031",
  "cache-control": "max-age\u003d0",
  "x-ssl-cipher": "ECDHE-RSA-AES256-GCM-SHA384",
  "x-ssl-protocol": "TLSv1.2",
  "connection": "close",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net"
}
incoming_path
callback
incoming_body_form_params
incoming_method
GET
incoming_body_json
incoming_query_string_params
{
  "dummy1": "lorem",
  "dummy2": "ipsum"
}
incoming_body
2021-08-13 15:59:28 SUCCESS
CreateRandomImplicitSubmitUrl
Created random implicit submission URL
implicit_submit
{
  "path": "implicit/hCcTnsPCB7qb04m2zbeL",
  "fullUrl": "https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/implicit/hCcTnsPCB7qb04m2zbeL"
}
2021-08-13 15:59:28 OUTGOING
fapi1-advanced-final
Response to HTTP request to test instance wCkrQW9Zx2JRQay
outgoing
ModelAndView [view="implicitCallback"; model={implicitSubmitUrl=https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/implicit/hCcTnsPCB7qb04m2zbeL, returnUrl=/log-detail.html?log=wCkrQW9Zx2JRQay}]
outgoing_path
callback
2021-08-13 15:59:29 INFO
WebRunner
Completed processing of webpage
task
Authorize Client
browser
complete
response_status_text
200-
match
https://idp.conf.ping-eng.com:9031/as/*/resume/as/authorization.ping*
url
https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback?dummy1=lorem&dummy2=ipsum#code=7lVMuhLe_kF0muJoXaFBZrT59jP_cn6A73U8gMbw&id_token=eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwianRpIjoiZ2YwRFFqcWlBT1M0QzdhZUlVVjkxZiIsImlzcyI6Imh0dHBzOi8vaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2Mjg4NzAzNjgsImV4cCI6MTYyODg3MDY2OCwiYWNyIjoidXJuOm1hY2U6aW5jb21tb246aWFwOnNpbHZlciIsImF1dGhfdGltZSI6MTYyODg3MDM2OCwibm9uY2UiOiIzZGdGMUZHN0dLIiwiY19oYXNoIjoiVEJHa0M4YzNJaHlidVU0RXQwRjNYUSIsInNfaGFzaCI6IklGZjBhdFI1eVAyZ1FYYy15YjRmSUEifQ.S0kHNKDyyyE9XbSC21A5dzzQkAXHDO7WXIyeZlrnr4ZduWY1o2t0zqWhYZE8C7xBA76BHz77EkC54hAt5d-NkpItCa-u9a8v4zlzWC1crAvOSwQ0sUf612PEh9r220pDMxXG8EYFTiQMgTdeWhFKJ_F18G9UfnP0r-WFDXD5cHu9qDfWdqW0w_Ag-IE8EhapjCqZCjdnQuDhYPdx959GwU_6QpXlVdf-Uivc_6pMbj9JhUwrPRJyKXGJdvlhXf0X7vfT2fCBhq_cu4VT6ktWmM0fRqZ-9rf9K7ZUn6O0DA4YOww4Hk2frk6-HWb9EJ4FjTGWJdeHLoTYPFt3-f778A&state=AGdEitpyfR
response_status_code
200
2021-08-13 15:59:29 INFO
WebRunner
Completed processing of webpage
task
Verify Complete
browser
complete
response_status_text
200-
match
https://www.certification.openid.net/test/a/*/callback*
url
https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback?dummy1=lorem&dummy2=ipsum#code=7lVMuhLe_kF0muJoXaFBZrT59jP_cn6A73U8gMbw&id_token=eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwianRpIjoiZ2YwRFFqcWlBT1M0QzdhZUlVVjkxZiIsImlzcyI6Imh0dHBzOi8vaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2Mjg4NzAzNjgsImV4cCI6MTYyODg3MDY2OCwiYWNyIjoidXJuOm1hY2U6aW5jb21tb246aWFwOnNpbHZlciIsImF1dGhfdGltZSI6MTYyODg3MDM2OCwibm9uY2UiOiIzZGdGMUZHN0dLIiwiY19oYXNoIjoiVEJHa0M4YzNJaHlidVU0RXQwRjNYUSIsInNfaGFzaCI6IklGZjBhdFI1eVAyZ1FYYy15YjRmSUEifQ.S0kHNKDyyyE9XbSC21A5dzzQkAXHDO7WXIyeZlrnr4ZduWY1o2t0zqWhYZE8C7xBA76BHz77EkC54hAt5d-NkpItCa-u9a8v4zlzWC1crAvOSwQ0sUf612PEh9r220pDMxXG8EYFTiQMgTdeWhFKJ_F18G9UfnP0r-WFDXD5cHu9qDfWdqW0w_Ag-IE8EhapjCqZCjdnQuDhYPdx959GwU_6QpXlVdf-Uivc_6pMbj9JhUwrPRJyKXGJdvlhXf0X7vfT2fCBhq_cu4VT6ktWmM0fRqZ-9rf9K7ZUn6O0DA4YOww4Hk2frk6-HWb9EJ4FjTGWJdeHLoTYPFt3-f778A&state=AGdEitpyfR
response_status_code
200
2021-08-13 15:59:29 INCOMING
fapi1-advanced-final
Incoming HTTP request to test instance wCkrQW9Zx2JRQay
incoming_headers
{
  "host": "www.certification.openid.net",
  "upgrade-insecure-requests": "1",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.72 Safari/537.36",
  "accept": "*/*",
  "sec-fetch-site": "same-origin",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "referer": "https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback?dummy1\u003dlorem\u0026dummy2\u003dipsum",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9",
  "cookie": "JSESSIONID\u003d9BC84D4D9F29B61A4F14362976BABA39",
  "x-requested-with": "XMLHttpRequest",
  "content-type": "text/plain",
  "x-ssl-cipher": "ECDHE-RSA-AES256-GCM-SHA384",
  "x-ssl-protocol": "TLSv1.2",
  "content-length": "915",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net",
  "connection": "close"
}
incoming_path
implicit/hCcTnsPCB7qb04m2zbeL
incoming_body_form_params
incoming_method
POST
incoming_body_json
incoming_query_string_params
{}
incoming_body
#code=7lVMuhLe_kF0muJoXaFBZrT59jP_cn6A73U8gMbw&id_token=eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwianRpIjoiZ2YwRFFqcWlBT1M0QzdhZUlVVjkxZiIsImlzcyI6Imh0dHBzOi8vaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2Mjg4NzAzNjgsImV4cCI6MTYyODg3MDY2OCwiYWNyIjoidXJuOm1hY2U6aW5jb21tb246aWFwOnNpbHZlciIsImF1dGhfdGltZSI6MTYyODg3MDM2OCwibm9uY2UiOiIzZGdGMUZHN0dLIiwiY19oYXNoIjoiVEJHa0M4YzNJaHlidVU0RXQwRjNYUSIsInNfaGFzaCI6IklGZjBhdFI1eVAyZ1FYYy15YjRmSUEifQ.S0kHNKDyyyE9XbSC21A5dzzQkAXHDO7WXIyeZlrnr4ZduWY1o2t0zqWhYZE8C7xBA76BHz77EkC54hAt5d-NkpItCa-u9a8v4zlzWC1crAvOSwQ0sUf612PEh9r220pDMxXG8EYFTiQMgTdeWhFKJ_F18G9UfnP0r-WFDXD5cHu9qDfWdqW0w_Ag-IE8EhapjCqZCjdnQuDhYPdx959GwU_6QpXlVdf-Uivc_6pMbj9JhUwrPRJyKXGJdvlhXf0X7vfT2fCBhq_cu4VT6ktWmM0fRqZ-9rf9K7ZUn6O0DA4YOww4Hk2frk6-HWb9EJ4FjTGWJdeHLoTYPFt3-f778A&state=AGdEitpyfR
2021-08-13 15:59:29 OUTGOING
fapi1-advanced-final
Response to HTTP request to test instance wCkrQW9Zx2JRQay
outgoing_status_code
204
outgoing_headers
{}
outgoing_body

                                
outgoing_path
implicit/hCcTnsPCB7qb04m2zbeL
2021-08-13 15:59:29
ExtractImplicitHashToCallbackResponse
Extracted response from URL fragment
parameters
[
  {
    "name": "code",
    "value": "7lVMuhLe_kF0muJoXaFBZrT59jP_cn6A73U8gMbw"
  },
  {
    "name": "id_token",
    "value": "eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwianRpIjoiZ2YwRFFqcWlBT1M0QzdhZUlVVjkxZiIsImlzcyI6Imh0dHBzOi8vaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2Mjg4NzAzNjgsImV4cCI6MTYyODg3MDY2OCwiYWNyIjoidXJuOm1hY2U6aW5jb21tb246aWFwOnNpbHZlciIsImF1dGhfdGltZSI6MTYyODg3MDM2OCwibm9uY2UiOiIzZGdGMUZHN0dLIiwiY19oYXNoIjoiVEJHa0M4YzNJaHlidVU0RXQwRjNYUSIsInNfaGFzaCI6IklGZjBhdFI1eVAyZ1FYYy15YjRmSUEifQ.S0kHNKDyyyE9XbSC21A5dzzQkAXHDO7WXIyeZlrnr4ZduWY1o2t0zqWhYZE8C7xBA76BHz77EkC54hAt5d-NkpItCa-u9a8v4zlzWC1crAvOSwQ0sUf612PEh9r220pDMxXG8EYFTiQMgTdeWhFKJ_F18G9UfnP0r-WFDXD5cHu9qDfWdqW0w_Ag-IE8EhapjCqZCjdnQuDhYPdx959GwU_6QpXlVdf-Uivc_6pMbj9JhUwrPRJyKXGJdvlhXf0X7vfT2fCBhq_cu4VT6ktWmM0fRqZ-9rf9K7ZUn6O0DA4YOww4Hk2frk6-HWb9EJ4FjTGWJdeHLoTYPFt3-f778A"
  },
  {
    "name": "state",
    "value": "AGdEitpyfR"
  }
]
2021-08-13 15:59:29 SUCCESS
ExtractImplicitHashToCallbackResponse
Extracted the hash values
code
7lVMuhLe_kF0muJoXaFBZrT59jP_cn6A73U8gMbw
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwianRpIjoiZ2YwRFFqcWlBT1M0QzdhZUlVVjkxZiIsImlzcyI6Imh0dHBzOi8vaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2Mjg4NzAzNjgsImV4cCI6MTYyODg3MDY2OCwiYWNyIjoidXJuOm1hY2U6aW5jb21tb246aWFwOnNpbHZlciIsImF1dGhfdGltZSI6MTYyODg3MDM2OCwibm9uY2UiOiIzZGdGMUZHN0dLIiwiY19oYXNoIjoiVEJHa0M4YzNJaHlidVU0RXQwRjNYUSIsInNfaGFzaCI6IklGZjBhdFI1eVAyZ1FYYy15YjRmSUEifQ.S0kHNKDyyyE9XbSC21A5dzzQkAXHDO7WXIyeZlrnr4ZduWY1o2t0zqWhYZE8C7xBA76BHz77EkC54hAt5d-NkpItCa-u9a8v4zlzWC1crAvOSwQ0sUf612PEh9r220pDMxXG8EYFTiQMgTdeWhFKJ_F18G9UfnP0r-WFDXD5cHu9qDfWdqW0w_Ag-IE8EhapjCqZCjdnQuDhYPdx959GwU_6QpXlVdf-Uivc_6pMbj9JhUwrPRJyKXGJdvlhXf0X7vfT2fCBhq_cu4VT6ktWmM0fRqZ-9rf9K7ZUn6O0DA4YOww4Hk2frk6-HWb9EJ4FjTGWJdeHLoTYPFt3-f778A
state
AGdEitpyfR
2021-08-13 15:59:29 REDIRECT-IN
fapi1-advanced-final
Authorization endpoint response captured
url_query
{
  "dummy1": "lorem",
  "dummy2": "ipsum"
}
headers
{
  "host": "www.certification.openid.net",
  "upgrade-insecure-requests": "1",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.72 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "same-origin",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "referer": "https://idp.conf.ping-eng.com:9031/as/WnjDv/resume/as/authorization.ping",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9",
  "cookie": "JSESSIONID\u003d9BC84D4D9F29B61A4F14362976BABA39",
  "origin": "https://idp.conf.ping-eng.com:9031",
  "cache-control": "max-age\u003d0",
  "x-ssl-cipher": "ECDHE-RSA-AES256-GCM-SHA384",
  "x-ssl-protocol": "TLSv1.2",
  "connection": "close",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net"
}
http_method
GET
url_fragment
{
  "code": "7lVMuhLe_kF0muJoXaFBZrT59jP_cn6A73U8gMbw",
  "id_token": "eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwianRpIjoiZ2YwRFFqcWlBT1M0QzdhZUlVVjkxZiIsImlzcyI6Imh0dHBzOi8vaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2Mjg4NzAzNjgsImV4cCI6MTYyODg3MDY2OCwiYWNyIjoidXJuOm1hY2U6aW5jb21tb246aWFwOnNpbHZlciIsImF1dGhfdGltZSI6MTYyODg3MDM2OCwibm9uY2UiOiIzZGdGMUZHN0dLIiwiY19oYXNoIjoiVEJHa0M4YzNJaHlidVU0RXQwRjNYUSIsInNfaGFzaCI6IklGZjBhdFI1eVAyZ1FYYy15YjRmSUEifQ.S0kHNKDyyyE9XbSC21A5dzzQkAXHDO7WXIyeZlrnr4ZduWY1o2t0zqWhYZE8C7xBA76BHz77EkC54hAt5d-NkpItCa-u9a8v4zlzWC1crAvOSwQ0sUf612PEh9r220pDMxXG8EYFTiQMgTdeWhFKJ_F18G9UfnP0r-WFDXD5cHu9qDfWdqW0w_Ag-IE8EhapjCqZCjdnQuDhYPdx959GwU_6QpXlVdf-Uivc_6pMbj9JhUwrPRJyKXGJdvlhXf0X7vfT2fCBhq_cu4VT6ktWmM0fRqZ-9rf9K7ZUn6O0DA4YOww4Hk2frk6-HWb9EJ4FjTGWJdeHLoTYPFt3-f778A",
  "state": "AGdEitpyfR"
}
post_body
Second client: Verify authorization endpoint response
2021-08-13 15:59:29 SUCCESS
RejectErrorInUrlQuery
'error' is not present in URL query returned from authorization endpoint
2021-08-13 15:59:29 SUCCESS
RejectAuthCodeInUrlQuery
Authorization code is not present in URL query returned from authorization endpoint
2021-08-13 15:59:29 SUCCESS
CheckMatchingCallbackParameters
Callback parameters successfully verified
dummy1
lorem
dummy2
ipsum
2021-08-13 15:59:29 SUCCESS
RejectStateInUrlQueryForHybridFlow
state is correctly not present in URL query returned from authorization endpoint (as in the hybrid flow it must be returned in the URL fragment/hash only)
2021-08-13 15:59:29 SUCCESS
CheckIfAuthorizationEndpointError
No error from authorization endpoint
2021-08-13 15:59:29 SUCCESS
ValidateSuccessfulHybridResponseFromAuthorizationEndpoint
authorization endpoint response does not include unexpected parameters
code
7lVMuhLe_kF0muJoXaFBZrT59jP_cn6A73U8gMbw
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwianRpIjoiZ2YwRFFqcWlBT1M0QzdhZUlVVjkxZiIsImlzcyI6Imh0dHBzOi8vaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2Mjg4NzAzNjgsImV4cCI6MTYyODg3MDY2OCwiYWNyIjoidXJuOm1hY2U6aW5jb21tb246aWFwOnNpbHZlciIsImF1dGhfdGltZSI6MTYyODg3MDM2OCwibm9uY2UiOiIzZGdGMUZHN0dLIiwiY19oYXNoIjoiVEJHa0M4YzNJaHlidVU0RXQwRjNYUSIsInNfaGFzaCI6IklGZjBhdFI1eVAyZ1FYYy15YjRmSUEifQ.S0kHNKDyyyE9XbSC21A5dzzQkAXHDO7WXIyeZlrnr4ZduWY1o2t0zqWhYZE8C7xBA76BHz77EkC54hAt5d-NkpItCa-u9a8v4zlzWC1crAvOSwQ0sUf612PEh9r220pDMxXG8EYFTiQMgTdeWhFKJ_F18G9UfnP0r-WFDXD5cHu9qDfWdqW0w_Ag-IE8EhapjCqZCjdnQuDhYPdx959GwU_6QpXlVdf-Uivc_6pMbj9JhUwrPRJyKXGJdvlhXf0X7vfT2fCBhq_cu4VT6ktWmM0fRqZ-9rf9K7ZUn6O0DA4YOww4Hk2frk6-HWb9EJ4FjTGWJdeHLoTYPFt3-f778A
state
AGdEitpyfR
2021-08-13 15:59:29 SUCCESS
CheckStateInAuthorizationResponse
State in response correctly returned
state
AGdEitpyfR
2021-08-13 15:59:29
ValidateIssInAuthorizationResponse
No 'iss' value in authorization response.
2021-08-13 15:59:29 SUCCESS
ExtractAuthorizationCodeFromAuthorizationResponse
Found authorization code
code
7lVMuhLe_kF0muJoXaFBZrT59jP_cn6A73U8gMbw
2021-08-13 15:59:29 SUCCESS
EnsureMinimumAuthorizationCodeLength
Authorization code is of sufficient length
actual
320
required
128
2021-08-13 15:59:29 SUCCESS
EnsureMinimumAuthorizationCodeEntropy
Calculated shannon entropy seems sufficient
actual
202.8771237954945
expected
96.0
2021-08-13 15:59:29 SUCCESS
ExtractIdTokenFromAuthorizationResponse
Found and parsed the id_token from authorization_endpoint_response
value
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwianRpIjoiZ2YwRFFqcWlBT1M0QzdhZUlVVjkxZiIsImlzcyI6Imh0dHBzOi8vaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2Mjg4NzAzNjgsImV4cCI6MTYyODg3MDY2OCwiYWNyIjoidXJuOm1hY2U6aW5jb21tb246aWFwOnNpbHZlciIsImF1dGhfdGltZSI6MTYyODg3MDM2OCwibm9uY2UiOiIzZGdGMUZHN0dLIiwiY19oYXNoIjoiVEJHa0M4YzNJaHlidVU0RXQwRjNYUSIsInNfaGFzaCI6IklGZjBhdFI1eVAyZ1FYYy15YjRmSUEifQ.S0kHNKDyyyE9XbSC21A5dzzQkAXHDO7WXIyeZlrnr4ZduWY1o2t0zqWhYZE8C7xBA76BHz77EkC54hAt5d-NkpItCa-u9a8v4zlzWC1crAvOSwQ0sUf612PEh9r220pDMxXG8EYFTiQMgTdeWhFKJ_F18G9UfnP0r-WFDXD5cHu9qDfWdqW0w_Ag-IE8EhapjCqZCjdnQuDhYPdx959GwU_6QpXlVdf-Uivc_6pMbj9JhUwrPRJyKXGJdvlhXf0X7vfT2fCBhq_cu4VT6ktWmM0fRqZ-9rf9K7ZUn6O0DA4YOww4Hk2frk6-HWb9EJ4FjTGWJdeHLoTYPFt3-f778A
header
{
  "kid": "NfGZj3wtxSjC-G5ZOsy0GIrGqwU",
  "alg": "PS256"
}
claims
{
  "sub": "joe",
  "aud": "fapi_adv_op_w_private_key_par_second_client",
  "acr": "urn:mace:incommon:iap:silver",
  "c_hash": "TBGkC8c3IhybuU4Et0F3XQ",
  "s_hash": "IFf0atR5yP2gQXc-yb4fIA",
  "auth_time": 1628870368,
  "iss": "https://idp.conf.ping-eng.com:9031",
  "exp": 1628870668,
  "iat": 1628870368,
  "nonce": "3dgF1FG7GK",
  "jti": "gf0DQjqiAOS4C7aeIUV91f"
}
2021-08-13 15:59:29 SUCCESS
ValidateIdToken
ID token iss, aud, exp, iat, auth_time, acr & nbf claims passed validation checks
2021-08-13 15:59:29 SUCCESS
EnsureIdTokenContainsKid
kid was found in the ID token header
kid
NfGZj3wtxSjC-G5ZOsy0GIrGqwU
2021-08-13 15:59:29 SUCCESS
ValidateIdTokenNonce
Nonce values match
nonce
3dgF1FG7GK
2021-08-13 15:59:29 SUCCESS
ValidateIdTokenACRClaimAgainstRequest
acr value in id_token is (one of) the requested values
actual
urn:mace:incommon:iap:silver
requested
[
  "urn:mace:incommon:iap:silver"
]
2021-08-13 15:59:29 SUCCESS
ValidateIdTokenSignature
id_token signature validated
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwianRpIjoiZ2YwRFFqcWlBT1M0QzdhZUlVVjkxZiIsImlzcyI6Imh0dHBzOi8vaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2Mjg4NzAzNjgsImV4cCI6MTYyODg3MDY2OCwiYWNyIjoidXJuOm1hY2U6aW5jb21tb246aWFwOnNpbHZlciIsImF1dGhfdGltZSI6MTYyODg3MDM2OCwibm9uY2UiOiIzZGdGMUZHN0dLIiwiY19oYXNoIjoiVEJHa0M4YzNJaHlidVU0RXQwRjNYUSIsInNfaGFzaCI6IklGZjBhdFI1eVAyZ1FYYy15YjRmSUEifQ.S0kHNKDyyyE9XbSC21A5dzzQkAXHDO7WXIyeZlrnr4ZduWY1o2t0zqWhYZE8C7xBA76BHz77EkC54hAt5d-NkpItCa-u9a8v4zlzWC1crAvOSwQ0sUf612PEh9r220pDMxXG8EYFTiQMgTdeWhFKJ_F18G9UfnP0r-WFDXD5cHu9qDfWdqW0w_Ag-IE8EhapjCqZCjdnQuDhYPdx959GwU_6QpXlVdf-Uivc_6pMbj9JhUwrPRJyKXGJdvlhXf0X7vfT2fCBhq_cu4VT6ktWmM0fRqZ-9rf9K7ZUn6O0DA4YOww4Hk2frk6-HWb9EJ4FjTGWJdeHLoTYPFt3-f778A
2021-08-13 15:59:29 SUCCESS
ValidateIdTokenSignatureUsingKid
id_token signature validated
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwianRpIjoiZ2YwRFFqcWlBT1M0QzdhZUlVVjkxZiIsImlzcyI6Imh0dHBzOi8vaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2Mjg4NzAzNjgsImV4cCI6MTYyODg3MDY2OCwiYWNyIjoidXJuOm1hY2U6aW5jb21tb246aWFwOnNpbHZlciIsImF1dGhfdGltZSI6MTYyODg3MDM2OCwibm9uY2UiOiIzZGdGMUZHN0dLIiwiY19oYXNoIjoiVEJHa0M4YzNJaHlidVU0RXQwRjNYUSIsInNfaGFzaCI6IklGZjBhdFI1eVAyZ1FYYy15YjRmSUEifQ.S0kHNKDyyyE9XbSC21A5dzzQkAXHDO7WXIyeZlrnr4ZduWY1o2t0zqWhYZE8C7xBA76BHz77EkC54hAt5d-NkpItCa-u9a8v4zlzWC1crAvOSwQ0sUf612PEh9r220pDMxXG8EYFTiQMgTdeWhFKJ_F18G9UfnP0r-WFDXD5cHu9qDfWdqW0w_Ag-IE8EhapjCqZCjdnQuDhYPdx959GwU_6QpXlVdf-Uivc_6pMbj9JhUwrPRJyKXGJdvlhXf0X7vfT2fCBhq_cu4VT6ktWmM0fRqZ-9rf9K7ZUn6O0DA4YOww4Hk2frk6-HWb9EJ4FjTGWJdeHLoTYPFt3-f778A
2021-08-13 15:59:29 SUCCESS
CheckForSubjectInIdToken
Found 'sub' in id_token
sub
joe
2021-08-13 15:59:29 SUCCESS
FAPIValidateIdTokenSigningAlg
id_token was signed with a permitted algorithm
permitted
[
  "ES256",
  "PS256"
]
alg
PS256
2021-08-13 15:59:29 INFO
FAPIValidateIdTokenEncryptionAlg
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2021-08-13 15:59:29 INFO
FAPIValidateEncryptedIdTokenHasKid
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2021-08-13 15:59:29 SUCCESS
ExtractSHash
Extracted s_hash from ID Token
s_hash
IFf0atR5yP2gQXc-yb4fIA
alg
PS256
2021-08-13 15:59:29 SUCCESS
ValidateSHash
s_hash validated successfully
expected_hash
IFf0atR5yP2gQXc-yb4fIA
unhashed_value
AGdEitpyfR
id_token_hash
IFf0atR5yP2gQXc-yb4fIA
2021-08-13 15:59:29 SUCCESS
ExtractCHash
Extracted c_hash from ID Token
c_hash
TBGkC8c3IhybuU4Et0F3XQ
alg
PS256
2021-08-13 15:59:29 SUCCESS
ValidateCHash
c_hash validated successfully
expected_hash
TBGkC8c3IhybuU4Et0F3XQ
unhashed_value
7lVMuhLe_kF0muJoXaFBZrT59jP_cn6A73U8gMbw
id_token_hash
TBGkC8c3IhybuU4Et0F3XQ
Second client: Call token endpoint
2021-08-13 15:59:29 SUCCESS
CreateTokenEndpointRequestForAuthorizationCodeGrant
grant_type
authorization_code
code
7lVMuhLe_kF0muJoXaFBZrT59jP_cn6A73U8gMbw
redirect_uri
https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback?dummy1=lorem&dummy2=ipsum
2021-08-13 15:59:29 SUCCESS
CreateClientAuthenticationAssertionClaims
Created client assertion claims
iss
fapi_adv_op_w_private_key_par_second_client
sub
fapi_adv_op_w_private_key_par_second_client
aud
https://idp.conf.ping-eng.com:9032/as/token.oauth2
jti
Sal6mVoP5O5ggVlD9BAU
iat
1628870369
exp
1628870429
2021-08-13 15:59:29 SUCCESS
SignClientAuthenticationAssertion
Signed the client assertion
client_assertion
eyJraWQiOiJwaW5nZmVkZXJhdGUtZmFwaS1qd3QtYXNzZXJ0aW9uLWNsaWVudDIiLCJhbGciOiJQUzI1NiJ9.eyJzdWIiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwiYXVkIjoiaHR0cHM6XC9cL2lkcC5jb25mLnBpbmctZW5nLmNvbTo5MDMyXC9hc1wvdG9rZW4ub2F1dGgyIiwiaXNzIjoiZmFwaV9hZHZfb3Bfd19wcml2YXRlX2tleV9wYXJfc2Vjb25kX2NsaWVudCIsImV4cCI6MTYyODg3MDQyOSwiaWF0IjoxNjI4ODcwMzY5LCJqdGkiOiJTYWw2bVZvUDVPNWdnVmxEOUJBVSJ9.QXV1PCOsvxLJZSQnAAYoq15F1cJDdy3M5zsBqS2H9L4ESSqf288u_YE0byrIe14t92iiBC9U45zSPtw1YIwcHVBnvP3NECHk9u-_UvaxUKnIqzkurfvJ84dx0SS5MGXVs1qNQBYZ9izEGvOHln4IIfVbocjGKZkt_uwKyGqMb3m72hlyKA4dHtJuD0-GvB6HjDiSblo3LGaDlXqTS9J-vwYYHOFFv19pTHFBcI2clgDTPBc-4qo1DUTzjh1rAISu6a0l5lkYc-Q5WOiURoS-udO_hSVeYPXr3-xJ0IYm4IaX2h5ao7phDJ8SFSUdEk1vsMKWaM_215MycDvS0VQEyQ
2021-08-13 15:59:29
AddClientAssertionToTokenEndpointRequest
Added client assertion
grant_type
authorization_code
code
7lVMuhLe_kF0muJoXaFBZrT59jP_cn6A73U8gMbw
redirect_uri
https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback?dummy1=lorem&dummy2=ipsum
client_assertion
eyJraWQiOiJwaW5nZmVkZXJhdGUtZmFwaS1qd3QtYXNzZXJ0aW9uLWNsaWVudDIiLCJhbGciOiJQUzI1NiJ9.eyJzdWIiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwiYXVkIjoiaHR0cHM6XC9cL2lkcC5jb25mLnBpbmctZW5nLmNvbTo5MDMyXC9hc1wvdG9rZW4ub2F1dGgyIiwiaXNzIjoiZmFwaV9hZHZfb3Bfd19wcml2YXRlX2tleV9wYXJfc2Vjb25kX2NsaWVudCIsImV4cCI6MTYyODg3MDQyOSwiaWF0IjoxNjI4ODcwMzY5LCJqdGkiOiJTYWw2bVZvUDVPNWdnVmxEOUJBVSJ9.QXV1PCOsvxLJZSQnAAYoq15F1cJDdy3M5zsBqS2H9L4ESSqf288u_YE0byrIe14t92iiBC9U45zSPtw1YIwcHVBnvP3NECHk9u-_UvaxUKnIqzkurfvJ84dx0SS5MGXVs1qNQBYZ9izEGvOHln4IIfVbocjGKZkt_uwKyGqMb3m72hlyKA4dHtJuD0-GvB6HjDiSblo3LGaDlXqTS9J-vwYYHOFFv19pTHFBcI2clgDTPBc-4qo1DUTzjh1rAISu6a0l5lkYc-Q5WOiURoS-udO_hSVeYPXr3-xJ0IYm4IaX2h5ao7phDJ8SFSUdEk1vsMKWaM_215MycDvS0VQEyQ
client_assertion_type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-08-13 15:59:29
AddCodeVerifierToTokenEndpointRequest
grant_type
authorization_code
code
7lVMuhLe_kF0muJoXaFBZrT59jP_cn6A73U8gMbw
redirect_uri
https://www.certification.openid.net/test/a/pingidentity-pingfederate-fapi-adv-op-private-key-par-plain/callback?dummy1=lorem&dummy2=ipsum
client_assertion
eyJraWQiOiJwaW5nZmVkZXJhdGUtZmFwaS1qd3QtYXNzZXJ0aW9uLWNsaWVudDIiLCJhbGciOiJQUzI1NiJ9.eyJzdWIiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwiYXVkIjoiaHR0cHM6XC9cL2lkcC5jb25mLnBpbmctZW5nLmNvbTo5MDMyXC9hc1wvdG9rZW4ub2F1dGgyIiwiaXNzIjoiZmFwaV9hZHZfb3Bfd19wcml2YXRlX2tleV9wYXJfc2Vjb25kX2NsaWVudCIsImV4cCI6MTYyODg3MDQyOSwiaWF0IjoxNjI4ODcwMzY5LCJqdGkiOiJTYWw2bVZvUDVPNWdnVmxEOUJBVSJ9.QXV1PCOsvxLJZSQnAAYoq15F1cJDdy3M5zsBqS2H9L4ESSqf288u_YE0byrIe14t92iiBC9U45zSPtw1YIwcHVBnvP3NECHk9u-_UvaxUKnIqzkurfvJ84dx0SS5MGXVs1qNQBYZ9izEGvOHln4IIfVbocjGKZkt_uwKyGqMb3m72hlyKA4dHtJuD0-GvB6HjDiSblo3LGaDlXqTS9J-vwYYHOFFv19pTHFBcI2clgDTPBc-4qo1DUTzjh1rAISu6a0l5lkYc-Q5WOiURoS-udO_hSVeYPXr3-xJ0IYm4IaX2h5ao7phDJ8SFSUdEk1vsMKWaM_215MycDvS0VQEyQ
client_assertion_type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
code_verifier
DMCQSvXSVCWfc_MDVI-9sjCQdh_kl_K9-09eChDdK3qAJ4cvU0lQhrV6w7Egl9KApa3mbud0xns.cyULys1lwKRaX8lfnP-lPn0~A8gj-r4YjSUg~Tu~Evvtztu50L8Y
2021-08-13 15:59:29
CallTokenEndpoint
HTTP request
request_uri
https://idp.conf.ping-eng.com:9032/as/token.oauth2
request_method
POST
request_headers
{
  "accept": "application/json;charset\u003dUTF-8",
  "accept-charset": "utf-8",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "1239"
}
request_body
grant_type=authorization_code&code=7lVMuhLe_kF0muJoXaFBZrT59jP_cn6A73U8gMbw&redirect_uri=https%3A%2F%2Fwww.certification.openid.net%2Ftest%2Fa%2Fpingidentity-pingfederate-fapi-adv-op-private-key-par-plain%2Fcallback%3Fdummy1%3Dlorem%26dummy2%3Dipsum&client_assertion=eyJraWQiOiJwaW5nZmVkZXJhdGUtZmFwaS1qd3QtYXNzZXJ0aW9uLWNsaWVudDIiLCJhbGciOiJQUzI1NiJ9.eyJzdWIiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwiYXVkIjoiaHR0cHM6XC9cL2lkcC5jb25mLnBpbmctZW5nLmNvbTo5MDMyXC9hc1wvdG9rZW4ub2F1dGgyIiwiaXNzIjoiZmFwaV9hZHZfb3Bfd19wcml2YXRlX2tleV9wYXJfc2Vjb25kX2NsaWVudCIsImV4cCI6MTYyODg3MDQyOSwiaWF0IjoxNjI4ODcwMzY5LCJqdGkiOiJTYWw2bVZvUDVPNWdnVmxEOUJBVSJ9.QXV1PCOsvxLJZSQnAAYoq15F1cJDdy3M5zsBqS2H9L4ESSqf288u_YE0byrIe14t92iiBC9U45zSPtw1YIwcHVBnvP3NECHk9u-_UvaxUKnIqzkurfvJ84dx0SS5MGXVs1qNQBYZ9izEGvOHln4IIfVbocjGKZkt_uwKyGqMb3m72hlyKA4dHtJuD0-GvB6HjDiSblo3LGaDlXqTS9J-vwYYHOFFv19pTHFBcI2clgDTPBc-4qo1DUTzjh1rAISu6a0l5lkYc-Q5WOiURoS-udO_hSVeYPXr3-xJ0IYm4IaX2h5ao7phDJ8SFSUdEk1vsMKWaM_215MycDvS0VQEyQ&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer&code_verifier=DMCQSvXSVCWfc_MDVI-9sjCQdh_kl_K9-09eChDdK3qAJ4cvU0lQhrV6w7Egl9KApa3mbud0xns.cyULys1lwKRaX8lfnP-lPn0%7EA8gj-r4YjSUg%7ETu%7EEvvtztu50L8Y
request_mutual_tls
{
  "cert": "MIID3zCCAsegAwIBAgIUUbO7wc+DFfteEqK0M1D+iRwKDOkwDQYJKoZIhvcNAQELBQAwfjELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAkNPMQ8wDQYDVQQHDAZEZW52ZXIxFTATBgNVBAoMDFBpbmdJZGVudGl0eTEUMBIGA1UECwwLRGV2ZWxvcG1lbnQxJDAiBgNVBAMMG0ZBUEkgQWR2IE9QIHcgU2Vjb25kIENsaWVudDAgFw0yMTA3MjYyMjM0NDFaGA8yMTIxMDcwMjIyMzQ0MVowfjELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAkNPMQ8wDQYDVQQHDAZEZW52ZXIxFTATBgNVBAoMDFBpbmdJZGVudGl0eTEUMBIGA1UECwwLRGV2ZWxvcG1lbnQxJDAiBgNVBAMMG0ZBUEkgQWR2IE9QIHcgU2Vjb25kIENsaWVudDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALASMA/8vTQ+vFqsR7UBSG5cldHwJ5SGvoHpGqhdv6xSXHUi8bp0Ob927l93bdkk1YnWqYQbmtmwlfqRFyxXYAvNXoIrFY86gBOg4O9vkCeVSMK1l7CdSps3ypXR4p7Fy1eERIN4fTwUS5wRu0bpcG4kocShcoxYu5A30s8k6onYVafO0ZfrbKEfnEJY74f8A3v8ns2Nr5AasPqZsz3g5TiyVygRG6+D6yrhORvW33roDEYnrwompE6UUkjVXNhoBoXvohLhf3Zh7kEpVQjXjD/rMlj5NFSFXLW4RXDokruapCyY3Q66OoAO5SYBpKtfxHiAp28ooUSmmwpxd39voaUCAwEAAaNTMFEwHQYDVR0OBBYEFFGFWe386uahXiBMwViRnP9t210BMB8GA1UdIwQYMBaAFFGFWe386uahXiBMwViRnP9t210BMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAJ346s52BzNNZU9Sc6qUnG68yjZxCadEgijudr5hILhkLYsLy6HOdnirsakqdc/KhbRQPm+TbuUT94bahigOM1QuCGa8XjewTdmXGDdRxFTHNMLc+SopCuInXeNlBO8tekbWSglGaP742240gERzXHaGyqrSzXeL2yosY2evtqbMB9i+d8uMhTYniwP3Isbbld2lCCF/Cw7flVzXnWItU0pGVj8U9qIW874eMDss+dxq6WfwaVzyXqH7k59xI/37zxWdRa1zNIwyi8H1dkl0vsoJSrrIGPCJpq+snT+6+xrUbrRn4H+K0eQSLE+LmmxuOaE4WgdK4ln9ZUXQC90R1aM\u003d",
  "key": "MIIEwAIBADANBgkqhkiG9w0BAQEFAASCBKowggSmAgEAAoIBAQCwEjAP/L00PrxarEe1AUhuXJXR8CeUhr6B6RqoXb+sUlx1IvG6dDm/du5fd23ZJNWJ1qmEG5rZsJX6kRcsV2ALzV6CKxWPOoAToODvb5AnlUjCtZewnUqbN8qV0eKexctXhESDeH08FEucEbtG6XBuJKHEoXKMWLuQN9LPJOqJ2FWnztGX62yhH5xCWO+H/AN7/J7Nja+QGrD6mbM94OU4slcoERuvg+sq4Tkb1t966AxGJ68KJqROlFJI1VzYaAaF76IS4X92Ye5BKVUI14w/6zJY+TRUhVy1uEVw6JK7mqQsmN0OujqADuUmAaSrX8R4gKdvKKFEppsKcXd/b6GlAgMBAAECggEBAIxtlSPLImR+/N8ctPxqj4hmE6AjeI3/ggY/EuHiE7Ou5MsQGdfqRvysMKa3rEcaF64eJYmWMsUZECWOfvsAnTwMiiorjsBzmh8Nmxmc006exC93ggp9CToPH2aqxaJ4gxvEBJkPCmNWlI9fnQyLtv5B/TvEwIWrZ704qMxJ1z4klxZgPvRAa5lCRIs1BAwkvtgkc9S2nTzJqO7tfHpXk1tCMxkHyqMlfpBfWxgysPQBueju/IFXw3IoO80uOCZYnHagMmZeSdomlCQmX+5UjanVt4TFFppIQxKXjrkJ0Q0XcnboNs+VsKZgvFdVAKFXHZY5BtaQaC8U8vPKDH2SSikCgYEA5z6fgw7T9etmkqsmc+cAt6LH/NspMOH92Ot7IPgjZIiODx1AIPIQXM6/DzJuntyYtMk+ZJ06q/h7C8ZkdAQX1z3M6maD2y8vVVIMh1yjd2el7CvAc3fejEbliKKK2R9RSGB8udNcGVyNbsjTTLJb2mx89JFI2yGA0gXyVTbT7CsCgYEAwuuBMF0THYZ4kNi62MvF/EblkKwKY1+v6XFdOZiyQljClNdT8bRFxjkdnIxaXemm6X5MPtsKBKY+0ix3uHKXdglzycCth/KuhqmItT1gitPEjq3Ut5Q9liWPpKNhuJjdlUi97Yj7r4NRBWeCLAUBh4n1lpl3rPxIvBMJqFgIMW8CgYEAinFPhmMmOyDHtB+LUfCG2Wo3WQbMzls+YtP4T3C/n7yxcBMPBapmaWnNsQd8etePBQ1GsW4AZlzJLe+EzIB21YJGYD8nyd2h9O6+WXv40c/X4mD/QyIMtubrHLZTclHxk+dQROBpTzW95wmMl2pg24//71vbxnV0bkjpIGNG1SkCgYEAkvnTsy0rgcLo3Ief9GNLCdxHs9wWBTKcyZDis9Bw8dhN+L+ZG5NMXZipvGaUqWXKpxvF0EuH9VOJ4R8Iszss/CNKfOHdt7oFYaMqY0dBqcze1Js836RXAAWYl5Ne1zvlMXDlTdxRs9l32XRgUmL/8TzUw1c7R2QAUFimmpquqt8CgYEAjtIr2L2llacZi7vBfFwgvjVVg7vuAvGpRokC4m6OzfjcO7fPVJa9f8IZLSQU6E2VM//dbuAHbPC2iIGnQn848cwF2rhXrY0VvqfpTuxQCdiW+TGwukLxW0AHWeiD5YauGqtz4+ZC6DWGyFZQSPB0OxcyG9wu0OBKbG70lP6scQE\u003d"
}
2021-08-13 15:59:29 RESPONSE
CallTokenEndpoint
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "date": "Fri, 13 Aug 2021 15:59:29 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003dLJdDzqjw1M8RjtBAtc8D3o; Path\u003d/; Secure; HttpOnly; SameSite\u003dNone",
  "transfer-encoding": "chunked"
}
response_body
{"access_token":"eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSIsInBpLmF0bSI6ImE5Z2kifQ.eyJzY29wZSI6Im9wZW5pZCBwYXltZW50cyIsImNsaWVudF9pZCI6ImZhcGlfYWR2X29wX3dfcHJpdmF0ZV9rZXlfcGFyX3NlY29uZF9jbGllbnQiLCJzdWIiOiJqb2UiLCJwaS51ayI6ImpvZSIsImNuZiI6eyJ4NXQjUzI1NiI6Il9jeFA5TjlLVWtmbWd3MmhYY0x1OFZWYmFneDlkWmJzN3JybkxCVkc1OFUifSwiZXhwIjoxNjI4ODc3NTY5fQ.N0iLEFR80iXP0ksFSFR9U7Yy_lq8zCy63wmo1clVG0Htqn8j37oCQlL0_jDboLZH99SJo8fEe7IP40JWlZxmW7NutnfWkmF36eOoEg-S9jrIQYpKhMwYLNnK0wItzTy7BZc41t_7aZRlb_RTyb_4hOiXr4rxYf5xGTgctF3uyh6LUrGWFRVYIe6LVzMROsz8ghH46dT5K9Bwibz9koiE6JhgOIrucaFiD2b29vK6MLavrbWX6rZ5eIaze7BbpNVj_14GqV3o36Eydiu7FpBBX2lbyB8Ru6KV-kKwhvdbTIhiIYevR8ten22mHl8EnOY4cIQ3KCoYIGdERK7m8UfWzA","refresh_token":"bZePf8wkxmqzkB2TYDUIYF2q1AHtLfjzrfDVsKXbsK","id_token":"eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwianRpIjoiZ2YwRFFqcWlBT1M0QzdhZUlVVjkxZiIsImlzcyI6Imh0dHBzOi8vaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2Mjg4NzAzNjgsImV4cCI6MTYyODg3MDY2OCwiYWNyIjoidXJuOm1hY2U6aW5jb21tb246aWFwOnNpbHZlciIsImF1dGhfdGltZSI6MTYyODg3MDM2OCwibm9uY2UiOiIzZGdGMUZHN0dLIiwiY19oYXNoIjoiVEJHa0M4YzNJaHlidVU0RXQwRjNYUSIsInNfaGFzaCI6IklGZjBhdFI1eVAyZ1FYYy15YjRmSUEifQ.S0kHNKDyyyE9XbSC21A5dzzQkAXHDO7WXIyeZlrnr4ZduWY1o2t0zqWhYZE8C7xBA76BHz77EkC54hAt5d-NkpItCa-u9a8v4zlzWC1crAvOSwQ0sUf612PEh9r220pDMxXG8EYFTiQMgTdeWhFKJ_F18G9UfnP0r-WFDXD5cHu9qDfWdqW0w_Ag-IE8EhapjCqZCjdnQuDhYPdx959GwU_6QpXlVdf-Uivc_6pMbj9JhUwrPRJyKXGJdvlhXf0X7vfT2fCBhq_cu4VT6ktWmM0fRqZ-9rf9K7ZUn6O0DA4YOww4Hk2frk6-HWb9EJ4FjTGWJdeHLoTYPFt3-f778A","token_type":"Bearer","expires_in":7199}
2021-08-13 15:59:29
CallTokenEndpoint
Token endpoint response
token_endpoint_response
{"access_token":"eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSIsInBpLmF0bSI6ImE5Z2kifQ.eyJzY29wZSI6Im9wZW5pZCBwYXltZW50cyIsImNsaWVudF9pZCI6ImZhcGlfYWR2X29wX3dfcHJpdmF0ZV9rZXlfcGFyX3NlY29uZF9jbGllbnQiLCJzdWIiOiJqb2UiLCJwaS51ayI6ImpvZSIsImNuZiI6eyJ4NXQjUzI1NiI6Il9jeFA5TjlLVWtmbWd3MmhYY0x1OFZWYmFneDlkWmJzN3JybkxCVkc1OFUifSwiZXhwIjoxNjI4ODc3NTY5fQ.N0iLEFR80iXP0ksFSFR9U7Yy_lq8zCy63wmo1clVG0Htqn8j37oCQlL0_jDboLZH99SJo8fEe7IP40JWlZxmW7NutnfWkmF36eOoEg-S9jrIQYpKhMwYLNnK0wItzTy7BZc41t_7aZRlb_RTyb_4hOiXr4rxYf5xGTgctF3uyh6LUrGWFRVYIe6LVzMROsz8ghH46dT5K9Bwibz9koiE6JhgOIrucaFiD2b29vK6MLavrbWX6rZ5eIaze7BbpNVj_14GqV3o36Eydiu7FpBBX2lbyB8Ru6KV-kKwhvdbTIhiIYevR8ten22mHl8EnOY4cIQ3KCoYIGdERK7m8UfWzA","refresh_token":"bZePf8wkxmqzkB2TYDUIYF2q1AHtLfjzrfDVsKXbsK","id_token":"eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwianRpIjoiZ2YwRFFqcWlBT1M0QzdhZUlVVjkxZiIsImlzcyI6Imh0dHBzOi8vaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2Mjg4NzAzNjgsImV4cCI6MTYyODg3MDY2OCwiYWNyIjoidXJuOm1hY2U6aW5jb21tb246aWFwOnNpbHZlciIsImF1dGhfdGltZSI6MTYyODg3MDM2OCwibm9uY2UiOiIzZGdGMUZHN0dLIiwiY19oYXNoIjoiVEJHa0M4YzNJaHlidVU0RXQwRjNYUSIsInNfaGFzaCI6IklGZjBhdFI1eVAyZ1FYYy15YjRmSUEifQ.S0kHNKDyyyE9XbSC21A5dzzQkAXHDO7WXIyeZlrnr4ZduWY1o2t0zqWhYZE8C7xBA76BHz77EkC54hAt5d-NkpItCa-u9a8v4zlzWC1crAvOSwQ0sUf612PEh9r220pDMxXG8EYFTiQMgTdeWhFKJ_F18G9UfnP0r-WFDXD5cHu9qDfWdqW0w_Ag-IE8EhapjCqZCjdnQuDhYPdx959GwU_6QpXlVdf-Uivc_6pMbj9JhUwrPRJyKXGJdvlhXf0X7vfT2fCBhq_cu4VT6ktWmM0fRqZ-9rf9K7ZUn6O0DA4YOww4Hk2frk6-HWb9EJ4FjTGWJdeHLoTYPFt3-f778A","token_type":"Bearer","expires_in":7199}
2021-08-13 15:59:29 SUCCESS
CallTokenEndpoint
Parsed token endpoint response
access_token
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSIsInBpLmF0bSI6ImE5Z2kifQ.eyJzY29wZSI6Im9wZW5pZCBwYXltZW50cyIsImNsaWVudF9pZCI6ImZhcGlfYWR2X29wX3dfcHJpdmF0ZV9rZXlfcGFyX3NlY29uZF9jbGllbnQiLCJzdWIiOiJqb2UiLCJwaS51ayI6ImpvZSIsImNuZiI6eyJ4NXQjUzI1NiI6Il9jeFA5TjlLVWtmbWd3MmhYY0x1OFZWYmFneDlkWmJzN3JybkxCVkc1OFUifSwiZXhwIjoxNjI4ODc3NTY5fQ.N0iLEFR80iXP0ksFSFR9U7Yy_lq8zCy63wmo1clVG0Htqn8j37oCQlL0_jDboLZH99SJo8fEe7IP40JWlZxmW7NutnfWkmF36eOoEg-S9jrIQYpKhMwYLNnK0wItzTy7BZc41t_7aZRlb_RTyb_4hOiXr4rxYf5xGTgctF3uyh6LUrGWFRVYIe6LVzMROsz8ghH46dT5K9Bwibz9koiE6JhgOIrucaFiD2b29vK6MLavrbWX6rZ5eIaze7BbpNVj_14GqV3o36Eydiu7FpBBX2lbyB8Ru6KV-kKwhvdbTIhiIYevR8ten22mHl8EnOY4cIQ3KCoYIGdERK7m8UfWzA
refresh_token
bZePf8wkxmqzkB2TYDUIYF2q1AHtLfjzrfDVsKXbsK
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwianRpIjoiZ2YwRFFqcWlBT1M0QzdhZUlVVjkxZiIsImlzcyI6Imh0dHBzOi8vaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2Mjg4NzAzNjgsImV4cCI6MTYyODg3MDY2OCwiYWNyIjoidXJuOm1hY2U6aW5jb21tb246aWFwOnNpbHZlciIsImF1dGhfdGltZSI6MTYyODg3MDM2OCwibm9uY2UiOiIzZGdGMUZHN0dLIiwiY19oYXNoIjoiVEJHa0M4YzNJaHlidVU0RXQwRjNYUSIsInNfaGFzaCI6IklGZjBhdFI1eVAyZ1FYYy15YjRmSUEifQ.S0kHNKDyyyE9XbSC21A5dzzQkAXHDO7WXIyeZlrnr4ZduWY1o2t0zqWhYZE8C7xBA76BHz77EkC54hAt5d-NkpItCa-u9a8v4zlzWC1crAvOSwQ0sUf612PEh9r220pDMxXG8EYFTiQMgTdeWhFKJ_F18G9UfnP0r-WFDXD5cHu9qDfWdqW0w_Ag-IE8EhapjCqZCjdnQuDhYPdx959GwU_6QpXlVdf-Uivc_6pMbj9JhUwrPRJyKXGJdvlhXf0X7vfT2fCBhq_cu4VT6ktWmM0fRqZ-9rf9K7ZUn6O0DA4YOww4Hk2frk6-HWb9EJ4FjTGWJdeHLoTYPFt3-f778A
token_type
Bearer
expires_in
7199
Second client: Verify token endpoint response
2021-08-13 15:59:29 SUCCESS
CheckIfTokenEndpointResponseError
No error from token endpoint
2021-08-13 15:59:29 SUCCESS
CheckForAccessTokenValue
Found an access token
access_token
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSIsInBpLmF0bSI6ImE5Z2kifQ.eyJzY29wZSI6Im9wZW5pZCBwYXltZW50cyIsImNsaWVudF9pZCI6ImZhcGlfYWR2X29wX3dfcHJpdmF0ZV9rZXlfcGFyX3NlY29uZF9jbGllbnQiLCJzdWIiOiJqb2UiLCJwaS51ayI6ImpvZSIsImNuZiI6eyJ4NXQjUzI1NiI6Il9jeFA5TjlLVWtmbWd3MmhYY0x1OFZWYmFneDlkWmJzN3JybkxCVkc1OFUifSwiZXhwIjoxNjI4ODc3NTY5fQ.N0iLEFR80iXP0ksFSFR9U7Yy_lq8zCy63wmo1clVG0Htqn8j37oCQlL0_jDboLZH99SJo8fEe7IP40JWlZxmW7NutnfWkmF36eOoEg-S9jrIQYpKhMwYLNnK0wItzTy7BZc41t_7aZRlb_RTyb_4hOiXr4rxYf5xGTgctF3uyh6LUrGWFRVYIe6LVzMROsz8ghH46dT5K9Bwibz9koiE6JhgOIrucaFiD2b29vK6MLavrbWX6rZ5eIaze7BbpNVj_14GqV3o36Eydiu7FpBBX2lbyB8Ru6KV-kKwhvdbTIhiIYevR8ten22mHl8EnOY4cIQ3KCoYIGdERK7m8UfWzA
2021-08-13 15:59:29 SUCCESS
ExtractAccessTokenFromTokenResponse
Extracted the access token
value
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSIsInBpLmF0bSI6ImE5Z2kifQ.eyJzY29wZSI6Im9wZW5pZCBwYXltZW50cyIsImNsaWVudF9pZCI6ImZhcGlfYWR2X29wX3dfcHJpdmF0ZV9rZXlfcGFyX3NlY29uZF9jbGllbnQiLCJzdWIiOiJqb2UiLCJwaS51ayI6ImpvZSIsImNuZiI6eyJ4NXQjUzI1NiI6Il9jeFA5TjlLVWtmbWd3MmhYY0x1OFZWYmFneDlkWmJzN3JybkxCVkc1OFUifSwiZXhwIjoxNjI4ODc3NTY5fQ.N0iLEFR80iXP0ksFSFR9U7Yy_lq8zCy63wmo1clVG0Htqn8j37oCQlL0_jDboLZH99SJo8fEe7IP40JWlZxmW7NutnfWkmF36eOoEg-S9jrIQYpKhMwYLNnK0wItzTy7BZc41t_7aZRlb_RTyb_4hOiXr4rxYf5xGTgctF3uyh6LUrGWFRVYIe6LVzMROsz8ghH46dT5K9Bwibz9koiE6JhgOIrucaFiD2b29vK6MLavrbWX6rZ5eIaze7BbpNVj_14GqV3o36Eydiu7FpBBX2lbyB8Ru6KV-kKwhvdbTIhiIYevR8ten22mHl8EnOY4cIQ3KCoYIGdERK7m8UfWzA
type
Bearer
2021-08-13 15:59:29 SUCCESS
ExtractExpiresInFromTokenEndpointResponse
Extracted 'expires_in'
expires_in
7199
2021-08-13 15:59:29 SUCCESS
ValidateExpiresIn
expires_in passed all validation checks
expires_in
7199
2021-08-13 15:59:29 SUCCESS
CheckForRefreshTokenValue
Found a refresh token
refresh_token
bZePf8wkxmqzkB2TYDUIYF2q1AHtLfjzrfDVsKXbsK
2021-08-13 15:59:29 SUCCESS
EnsureMinimumRefreshTokenLength
Refresh token is of sufficient length
actual
336
required
128
2021-08-13 15:59:29 SUCCESS
EnsureMinimumRefreshTokenEntropy
Calculated shannon entropy seems sufficient
actual
203.7224442545445
expected
96.0
2021-08-13 15:59:29 SUCCESS
EnsureMinimumAccessTokenLength
Access token is of sufficient length
actual
5536
required
128
2021-08-13 15:59:29 SUCCESS
EnsureMinimumAccessTokenEntropy
Calculated shannon entropy seems sufficient
actual
4048.70301565918
expected
96.0
2021-08-13 15:59:29 SUCCESS
ExtractIdTokenFromTokenResponse
Found and parsed the id_token from token_endpoint_response
value
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwianRpIjoiZ2YwRFFqcWlBT1M0QzdhZUlVVjkxZiIsImlzcyI6Imh0dHBzOi8vaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2Mjg4NzAzNjgsImV4cCI6MTYyODg3MDY2OCwiYWNyIjoidXJuOm1hY2U6aW5jb21tb246aWFwOnNpbHZlciIsImF1dGhfdGltZSI6MTYyODg3MDM2OCwibm9uY2UiOiIzZGdGMUZHN0dLIiwiY19oYXNoIjoiVEJHa0M4YzNJaHlidVU0RXQwRjNYUSIsInNfaGFzaCI6IklGZjBhdFI1eVAyZ1FYYy15YjRmSUEifQ.S0kHNKDyyyE9XbSC21A5dzzQkAXHDO7WXIyeZlrnr4ZduWY1o2t0zqWhYZE8C7xBA76BHz77EkC54hAt5d-NkpItCa-u9a8v4zlzWC1crAvOSwQ0sUf612PEh9r220pDMxXG8EYFTiQMgTdeWhFKJ_F18G9UfnP0r-WFDXD5cHu9qDfWdqW0w_Ag-IE8EhapjCqZCjdnQuDhYPdx959GwU_6QpXlVdf-Uivc_6pMbj9JhUwrPRJyKXGJdvlhXf0X7vfT2fCBhq_cu4VT6ktWmM0fRqZ-9rf9K7ZUn6O0DA4YOww4Hk2frk6-HWb9EJ4FjTGWJdeHLoTYPFt3-f778A
header
{
  "kid": "NfGZj3wtxSjC-G5ZOsy0GIrGqwU",
  "alg": "PS256"
}
claims
{
  "sub": "joe",
  "aud": "fapi_adv_op_w_private_key_par_second_client",
  "acr": "urn:mace:incommon:iap:silver",
  "c_hash": "TBGkC8c3IhybuU4Et0F3XQ",
  "s_hash": "IFf0atR5yP2gQXc-yb4fIA",
  "auth_time": 1628870368,
  "iss": "https://idp.conf.ping-eng.com:9031",
  "exp": 1628870668,
  "iat": 1628870368,
  "nonce": "3dgF1FG7GK",
  "jti": "gf0DQjqiAOS4C7aeIUV91f"
}
2021-08-13 15:59:29 SUCCESS
ValidateIdToken
ID token iss, aud, exp, iat, auth_time, acr & nbf claims passed validation checks
2021-08-13 15:59:29 SUCCESS
EnsureIdTokenContainsKid
kid was found in the ID token header
kid
NfGZj3wtxSjC-G5ZOsy0GIrGqwU
2021-08-13 15:59:29 SUCCESS
ValidateIdTokenNonce
Nonce values match
nonce
3dgF1FG7GK
2021-08-13 15:59:29 SUCCESS
ValidateIdTokenACRClaimAgainstRequest
acr value in id_token is (one of) the requested values
actual
urn:mace:incommon:iap:silver
requested
[
  "urn:mace:incommon:iap:silver"
]
2021-08-13 15:59:29 SUCCESS
ValidateIdTokenSignature
id_token signature validated
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwianRpIjoiZ2YwRFFqcWlBT1M0QzdhZUlVVjkxZiIsImlzcyI6Imh0dHBzOi8vaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2Mjg4NzAzNjgsImV4cCI6MTYyODg3MDY2OCwiYWNyIjoidXJuOm1hY2U6aW5jb21tb246aWFwOnNpbHZlciIsImF1dGhfdGltZSI6MTYyODg3MDM2OCwibm9uY2UiOiIzZGdGMUZHN0dLIiwiY19oYXNoIjoiVEJHa0M4YzNJaHlidVU0RXQwRjNYUSIsInNfaGFzaCI6IklGZjBhdFI1eVAyZ1FYYy15YjRmSUEifQ.S0kHNKDyyyE9XbSC21A5dzzQkAXHDO7WXIyeZlrnr4ZduWY1o2t0zqWhYZE8C7xBA76BHz77EkC54hAt5d-NkpItCa-u9a8v4zlzWC1crAvOSwQ0sUf612PEh9r220pDMxXG8EYFTiQMgTdeWhFKJ_F18G9UfnP0r-WFDXD5cHu9qDfWdqW0w_Ag-IE8EhapjCqZCjdnQuDhYPdx959GwU_6QpXlVdf-Uivc_6pMbj9JhUwrPRJyKXGJdvlhXf0X7vfT2fCBhq_cu4VT6ktWmM0fRqZ-9rf9K7ZUn6O0DA4YOww4Hk2frk6-HWb9EJ4FjTGWJdeHLoTYPFt3-f778A
2021-08-13 15:59:29 SUCCESS
ValidateIdTokenSignatureUsingKid
id_token signature validated
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJmYXBpX2Fkdl9vcF93X3ByaXZhdGVfa2V5X3Bhcl9zZWNvbmRfY2xpZW50IiwianRpIjoiZ2YwRFFqcWlBT1M0QzdhZUlVVjkxZiIsImlzcyI6Imh0dHBzOi8vaWRwLmNvbmYucGluZy1lbmcuY29tOjkwMzEiLCJpYXQiOjE2Mjg4NzAzNjgsImV4cCI6MTYyODg3MDY2OCwiYWNyIjoidXJuOm1hY2U6aW5jb21tb246aWFwOnNpbHZlciIsImF1dGhfdGltZSI6MTYyODg3MDM2OCwibm9uY2UiOiIzZGdGMUZHN0dLIiwiY19oYXNoIjoiVEJHa0M4YzNJaHlidVU0RXQwRjNYUSIsInNfaGFzaCI6IklGZjBhdFI1eVAyZ1FYYy15YjRmSUEifQ.S0kHNKDyyyE9XbSC21A5dzzQkAXHDO7WXIyeZlrnr4ZduWY1o2t0zqWhYZE8C7xBA76BHz77EkC54hAt5d-NkpItCa-u9a8v4zlzWC1crAvOSwQ0sUf612PEh9r220pDMxXG8EYFTiQMgTdeWhFKJ_F18G9UfnP0r-WFDXD5cHu9qDfWdqW0w_Ag-IE8EhapjCqZCjdnQuDhYPdx959GwU_6QpXlVdf-Uivc_6pMbj9JhUwrPRJyKXGJdvlhXf0X7vfT2fCBhq_cu4VT6ktWmM0fRqZ-9rf9K7ZUn6O0DA4YOww4Hk2frk6-HWb9EJ4FjTGWJdeHLoTYPFt3-f778A
2021-08-13 15:59:29 SUCCESS
CheckForSubjectInIdToken
Found 'sub' in id_token
sub
joe
2021-08-13 15:59:29 SUCCESS
FAPIValidateIdTokenSigningAlg
id_token was signed with a permitted algorithm
permitted
[
  "ES256",
  "PS256"
]
alg
PS256
2021-08-13 15:59:29 INFO
FAPIValidateIdTokenEncryptionAlg
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2021-08-13 15:59:29 INFO
FAPIValidateEncryptedIdTokenHasKid
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2021-08-13 15:59:29 SUCCESS
ExtractCHash
Extracted c_hash from ID Token
c_hash
TBGkC8c3IhybuU4Et0F3XQ
alg
PS256
2021-08-13 15:59:29 SUCCESS
ExtractSHash
Extracted s_hash from ID Token
s_hash
IFf0atR5yP2gQXc-yb4fIA
alg
PS256
2021-08-13 15:59:29 INFO
ExtractAtHash
Couldn't find at_hash in ID token
2021-08-13 15:59:29 SUCCESS
ValidateCHash
c_hash validated successfully
expected_hash
TBGkC8c3IhybuU4Et0F3XQ
unhashed_value
7lVMuhLe_kF0muJoXaFBZrT59jP_cn6A73U8gMbw
id_token_hash
TBGkC8c3IhybuU4Et0F3XQ
2021-08-13 15:59:29 SUCCESS
ValidateSHash
s_hash validated successfully
expected_hash
IFf0atR5yP2gQXc-yb4fIA
unhashed_value
AGdEitpyfR
id_token_hash
IFf0atR5yP2gQXc-yb4fIA
2021-08-13 15:59:29 INFO
ValidateAtHash
Skipped evaluation due to missing required object: at_hash
expected
at_hash
mapped
Second client: Verify at_hash in the authorization endpoint id_token
2021-08-13 15:59:29 INFO
ExtractAtHash
Couldn't find at_hash in ID token
2021-08-13 15:59:29 INFO
ValidateAtHash
Skipped evaluation due to missing required object: at_hash
expected
at_hash
mapped
Second client: Resource server endpoint tests
2021-08-13 15:59:29
CreateEmptyResourceEndpointRequestHeaders
Created empty headers
resource_endpoint_request_headers
{}
2021-08-13 15:59:29
CallProtectedResourceWithBearerTokenAndCustomHeaders
HTTP request
request_uri
https://idp.conf.ping-eng.com:3000/get
request_method
GET
request_headers
{
  "accept": "application/json;charset\u003dUTF-8",
  "authorization": "Bearer eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSIsInBpLmF0bSI6ImE5Z2kifQ.eyJzY29wZSI6Im9wZW5pZCBwYXltZW50cyIsImNsaWVudF9pZCI6ImZhcGlfYWR2X29wX3dfcHJpdmF0ZV9rZXlfcGFyX3NlY29uZF9jbGllbnQiLCJzdWIiOiJqb2UiLCJwaS51ayI6ImpvZSIsImNuZiI6eyJ4NXQjUzI1NiI6Il9jeFA5TjlLVWtmbWd3MmhYY0x1OFZWYmFneDlkWmJzN3JybkxCVkc1OFUifSwiZXhwIjoxNjI4ODc3NTY5fQ.N0iLEFR80iXP0ksFSFR9U7Yy_lq8zCy63wmo1clVG0Htqn8j37oCQlL0_jDboLZH99SJo8fEe7IP40JWlZxmW7NutnfWkmF36eOoEg-S9jrIQYpKhMwYLNnK0wItzTy7BZc41t_7aZRlb_RTyb_4hOiXr4rxYf5xGTgctF3uyh6LUrGWFRVYIe6LVzMROsz8ghH46dT5K9Bwibz9koiE6JhgOIrucaFiD2b29vK6MLavrbWX6rZ5eIaze7BbpNVj_14GqV3o36Eydiu7FpBBX2lbyB8Ru6KV-kKwhvdbTIhiIYevR8ten22mHl8EnOY4cIQ3KCoYIGdERK7m8UfWzA",
  "accept-charset": "utf-8",
  "content-length": "0"
}
request_body

                                
request_mutual_tls
{
  "cert": "MIID3zCCAsegAwIBAgIUUbO7wc+DFfteEqK0M1D+iRwKDOkwDQYJKoZIhvcNAQELBQAwfjELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAkNPMQ8wDQYDVQQHDAZEZW52ZXIxFTATBgNVBAoMDFBpbmdJZGVudGl0eTEUMBIGA1UECwwLRGV2ZWxvcG1lbnQxJDAiBgNVBAMMG0ZBUEkgQWR2IE9QIHcgU2Vjb25kIENsaWVudDAgFw0yMTA3MjYyMjM0NDFaGA8yMTIxMDcwMjIyMzQ0MVowfjELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAkNPMQ8wDQYDVQQHDAZEZW52ZXIxFTATBgNVBAoMDFBpbmdJZGVudGl0eTEUMBIGA1UECwwLRGV2ZWxvcG1lbnQxJDAiBgNVBAMMG0ZBUEkgQWR2IE9QIHcgU2Vjb25kIENsaWVudDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALASMA/8vTQ+vFqsR7UBSG5cldHwJ5SGvoHpGqhdv6xSXHUi8bp0Ob927l93bdkk1YnWqYQbmtmwlfqRFyxXYAvNXoIrFY86gBOg4O9vkCeVSMK1l7CdSps3ypXR4p7Fy1eERIN4fTwUS5wRu0bpcG4kocShcoxYu5A30s8k6onYVafO0ZfrbKEfnEJY74f8A3v8ns2Nr5AasPqZsz3g5TiyVygRG6+D6yrhORvW33roDEYnrwompE6UUkjVXNhoBoXvohLhf3Zh7kEpVQjXjD/rMlj5NFSFXLW4RXDokruapCyY3Q66OoAO5SYBpKtfxHiAp28ooUSmmwpxd39voaUCAwEAAaNTMFEwHQYDVR0OBBYEFFGFWe386uahXiBMwViRnP9t210BMB8GA1UdIwQYMBaAFFGFWe386uahXiBMwViRnP9t210BMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAJ346s52BzNNZU9Sc6qUnG68yjZxCadEgijudr5hILhkLYsLy6HOdnirsakqdc/KhbRQPm+TbuUT94bahigOM1QuCGa8XjewTdmXGDdRxFTHNMLc+SopCuInXeNlBO8tekbWSglGaP742240gERzXHaGyqrSzXeL2yosY2evtqbMB9i+d8uMhTYniwP3Isbbld2lCCF/Cw7flVzXnWItU0pGVj8U9qIW874eMDss+dxq6WfwaVzyXqH7k59xI/37zxWdRa1zNIwyi8H1dkl0vsoJSrrIGPCJpq+snT+6+xrUbrRn4H+K0eQSLE+LmmxuOaE4WgdK4ln9ZUXQC90R1aM\u003d",
  "key": "MIIEwAIBADANBgkqhkiG9w0BAQEFAASCBKowggSmAgEAAoIBAQCwEjAP/L00PrxarEe1AUhuXJXR8CeUhr6B6RqoXb+sUlx1IvG6dDm/du5fd23ZJNWJ1qmEG5rZsJX6kRcsV2ALzV6CKxWPOoAToODvb5AnlUjCtZewnUqbN8qV0eKexctXhESDeH08FEucEbtG6XBuJKHEoXKMWLuQN9LPJOqJ2FWnztGX62yhH5xCWO+H/AN7/J7Nja+QGrD6mbM94OU4slcoERuvg+sq4Tkb1t966AxGJ68KJqROlFJI1VzYaAaF76IS4X92Ye5BKVUI14w/6zJY+TRUhVy1uEVw6JK7mqQsmN0OujqADuUmAaSrX8R4gKdvKKFEppsKcXd/b6GlAgMBAAECggEBAIxtlSPLImR+/N8ctPxqj4hmE6AjeI3/ggY/EuHiE7Ou5MsQGdfqRvysMKa3rEcaF64eJYmWMsUZECWOfvsAnTwMiiorjsBzmh8Nmxmc006exC93ggp9CToPH2aqxaJ4gxvEBJkPCmNWlI9fnQyLtv5B/TvEwIWrZ704qMxJ1z4klxZgPvRAa5lCRIs1BAwkvtgkc9S2nTzJqO7tfHpXk1tCMxkHyqMlfpBfWxgysPQBueju/IFXw3IoO80uOCZYnHagMmZeSdomlCQmX+5UjanVt4TFFppIQxKXjrkJ0Q0XcnboNs+VsKZgvFdVAKFXHZY5BtaQaC8U8vPKDH2SSikCgYEA5z6fgw7T9etmkqsmc+cAt6LH/NspMOH92Ot7IPgjZIiODx1AIPIQXM6/DzJuntyYtMk+ZJ06q/h7C8ZkdAQX1z3M6maD2y8vVVIMh1yjd2el7CvAc3fejEbliKKK2R9RSGB8udNcGVyNbsjTTLJb2mx89JFI2yGA0gXyVTbT7CsCgYEAwuuBMF0THYZ4kNi62MvF/EblkKwKY1+v6XFdOZiyQljClNdT8bRFxjkdnIxaXemm6X5MPtsKBKY+0ix3uHKXdglzycCth/KuhqmItT1gitPEjq3Ut5Q9liWPpKNhuJjdlUi97Yj7r4NRBWeCLAUBh4n1lpl3rPxIvBMJqFgIMW8CgYEAinFPhmMmOyDHtB+LUfCG2Wo3WQbMzls+YtP4T3C/n7yxcBMPBapmaWnNsQd8etePBQ1GsW4AZlzJLe+EzIB21YJGYD8nyd2h9O6+WXv40c/X4mD/QyIMtubrHLZTclHxk+dQROBpTzW95wmMl2pg24//71vbxnV0bkjpIGNG1SkCgYEAkvnTsy0rgcLo3Ief9GNLCdxHs9wWBTKcyZDis9Bw8dhN+L+ZG5NMXZipvGaUqWXKpxvF0EuH9VOJ4R8Iszss/CNKfOHdt7oFYaMqY0dBqcze1Js836RXAAWYl5Ne1zvlMXDlTdxRs9l32XRgUmL/8TzUw1c7R2QAUFimmpquqt8CgYEAjtIr2L2llacZi7vBfFwgvjVVg7vuAvGpRokC4m6OzfjcO7fPVJa9f8IZLSQU6E2VM//dbuAHbPC2iIGnQn848cwF2rhXrY0VvqfpTuxQCdiW+TGwukLxW0AHWeiD5YauGqtz4+ZC6DWGyFZQSPB0OxcyG9wu0OBKbG70lP6scQE\u003d"
}
2021-08-13 15:59:30 RESPONSE
CallProtectedResourceWithBearerTokenAndCustomHeaders
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "date": "Fri, 13 Aug 2021 15:59:30 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003dgKP07TwnGstentWIIEF0hI; Path\u003d/; Secure; HttpOnly; SameSite\u003dNone",
  "transfer-encoding": "chunked",
  "x-fapi-interaction-id": "5862c4cc-76e6-4361-a5da-69d58fa9ac48"
}
response_body
{"sub":"joe"}
2021-08-13 15:59:30 SUCCESS
CallProtectedResourceWithBearerTokenAndCustomHeaders
Got a response from the resource endpoint
headers
{
  "date": "Fri, 13 Aug 2021 15:59:30 GMT",
  "x-frame-options": "SAMEORIGIN",
  "referrer-policy": "origin",
  "cache-control": "no-cache, no-store",
  "pragma": "no-cache",
  "expires": "Thu, 01 Jan 1970 00:00:00 GMT",
  "content-type": "application/json;charset\u003dutf-8",
  "set-cookie": "PF\u003dgKP07TwnGstentWIIEF0hI; Path\u003d/; Secure; HttpOnly; SameSite\u003dNone",
  "transfer-encoding": "chunked",
  "x-fapi-interaction-id": "5862c4cc-76e6-4361-a5da-69d58fa9ac48"
}
status_code
{
  "code": 200
}
body
{"sub":"joe"}
2021-08-13 15:59:30 SUCCESS
CheckForDateHeaderInResourceResponse
Date header present and validated
date
Fri, 13 Aug 2021 15:59:30 GMT
skew
190
2021-08-13 15:59:30 SUCCESS
CheckForFAPIInteractionIdInResourceResponse
Found x-fapi-interaction-id
interaction_id
5862c4cc-76e6-4361-a5da-69d58fa9ac48
2021-08-13 15:59:30 SUCCESS
EnsureResourceResponseReturnedJsonContentType
Response content type is JSON
content_type
application/json;charset=utf-8
Try Client1's MTLS client certificate with Client2's access token
2021-08-13 15:59:30
CallProtectedResourceWithBearerTokenExpectingError
HTTP request
request_uri
https://idp.conf.ping-eng.com:3000/get
request_method
GET
request_headers
{
  "accept": "application/json;charset\u003dUTF-8",
  "authorization": "Bearer eyJhbGciOiJQUzI1NiIsImtpZCI6Ik5mR1pqM3d0eFNqQy1HNVpPc3kwR0lyR3F3VSIsInBpLmF0bSI6ImE5Z2kifQ.eyJzY29wZSI6Im9wZW5pZCBwYXltZW50cyIsImNsaWVudF9pZCI6ImZhcGlfYWR2X29wX3dfcHJpdmF0ZV9rZXlfcGFyX3NlY29uZF9jbGllbnQiLCJzdWIiOiJqb2UiLCJwaS51ayI6ImpvZSIsImNuZiI6eyJ4NXQjUzI1NiI6Il9jeFA5TjlLVWtmbWd3MmhYY0x1OFZWYmFneDlkWmJzN3JybkxCVkc1OFUifSwiZXhwIjoxNjI4ODc3NTY5fQ.N0iLEFR80iXP0ksFSFR9U7Yy_lq8zCy63wmo1clVG0Htqn8j37oCQlL0_jDboLZH99SJo8fEe7IP40JWlZxmW7NutnfWkmF36eOoEg-S9jrIQYpKhMwYLNnK0wItzTy7BZc41t_7aZRlb_RTyb_4hOiXr4rxYf5xGTgctF3uyh6LUrGWFRVYIe6LVzMROsz8ghH46dT5K9Bwibz9koiE6JhgOIrucaFiD2b29vK6MLavrbWX6rZ5eIaze7BbpNVj_14GqV3o36Eydiu7FpBBX2lbyB8Ru6KV-kKwhvdbTIhiIYevR8ten22mHl8EnOY4cIQ3KCoYIGdERK7m8UfWzA",
  "accept-charset": "utf-8",
  "content-length": "0"
}
request_body

                                
request_mutual_tls
{
  "cert": "MIID3TCCAsWgAwIBAgIUIi7yAbDDmWkZjI8CwjLBVkswVkIwDQYJKoZIhvcNAQELBQAwfTELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAkNPMQ8wDQYDVQQHDAZEZW52ZXIxFTATBgNVBAoMDFBpbmdJZGVudGl0eTEUMBIGA1UECwwLRGV2ZWxvcG1lbnQxIzAhBgNVBAMMGkZBUEkgQWR2IE9QIHcgRmlyc3QgQ2xpZW50MCAXDTIxMDcyNjIyMzQzN1oYDzIxMjEwNzAyMjIzNDM3WjB9MQswCQYDVQQGEwJVUzELMAkGA1UECAwCQ08xDzANBgNVBAcMBkRlbnZlcjEVMBMGA1UECgwMUGluZ0lkZW50aXR5MRQwEgYDVQQLDAtEZXZlbG9wbWVudDEjMCEGA1UEAwwaRkFQSSBBZHYgT1AgdyBGaXJzdCBDbGllbnQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCa91hiBBEaNcRdvQ0Gvg06mzaIQpa17vgtP77HwtV0FvH+3imrnqmaCcpEnWGMv/udX8S5r/VAeUPB2Q31187vKDLKxbadWTKuSNQajOkRyiXZzutbEQbN/t7JAz7oETujYoOTlMNT4N9twYvKEvxTeZAWNUCQHXZcESKYXhph0eZaaOvNo7WqQ+ygGBzgTVev6tXr/Q2+M3NkBnSvRYegSN5ZtmIXMrNVaH7D+SC8QUPWxsB8ZVIENzBhCI8+brrPjyLNqVKoI9O7Hjdgzb8Xs+gC98ATmsbQrE/8pRdYYCPkEoETAWRq2T/dEf7NE+AMerttKk9TdNwvbB1WbAoHAgMBAAGjUzBRMB0GA1UdDgQWBBTr8p3YWM2Rtw/BAQaellNa1RUKSTAfBgNVHSMEGDAWgBTr8p3YWM2Rtw/BAQaellNa1RUKSTAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQB17ygVKcEpZxP4XML98KyUycNxsyHcKdIo2GZCRsmwjDR5nRcdWlE+tI50sduSaAR+gSbDFR/dqBxl0lBEMLj6Rqpson+z17jv68fU9H7l7JLfI5xAXuW4s1Kg/xBcYBy7QJkU9CTMIb6TBQESCbTUq89aCX4fT8WQleCflRJjSuzzdpVWd0PIhcxCoxpa/BcXtK0gf/z0rimF4jJKv40rqdf0LGsVzKQ9TxQIDWk0tov4FkvBw63VUp6b7PWdEHi4E9uKgHxh2Pj+VykK33nCmUsGXENfj4SSkY2O00iDw3oHfC8xmWvgqsTdlzJm1qhZCZGNOsdWLEv6hGl4XLyr",
  "key": "MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQCa91hiBBEaNcRdvQ0Gvg06mzaIQpa17vgtP77HwtV0FvH+3imrnqmaCcpEnWGMv/udX8S5r/VAeUPB2Q31187vKDLKxbadWTKuSNQajOkRyiXZzutbEQbN/t7JAz7oETujYoOTlMNT4N9twYvKEvxTeZAWNUCQHXZcESKYXhph0eZaaOvNo7WqQ+ygGBzgTVev6tXr/Q2+M3NkBnSvRYegSN5ZtmIXMrNVaH7D+SC8QUPWxsB8ZVIENzBhCI8+brrPjyLNqVKoI9O7Hjdgzb8Xs+gC98ATmsbQrE/8pRdYYCPkEoETAWRq2T/dEf7NE+AMerttKk9TdNwvbB1WbAoHAgMBAAECggEAf4aFKUQHfvY4PpvRGHdWE6CfY8rIk7ewbCxFJ8biOcKYKxFQYXcUQztDROvu1xE2Uu/4yIZQ4VnptKCWqHWMSatfARdrjFlXJ62vPpovQwCD3ZY2gJ6mZucTF4CgSAHGflIXzV9izqgDtiLMkuLE2zzyohP4qaBVQranLZRjSZNWeGvEpkcf7Nv7FlfZaOJ/FkcGwyFn7iSzX/KRL/1TA6zDlreA3PGJr96i9SmFHQsurFv7quRxEUFoSVxVtn5IiOJji45Evte8KAhMzlau1MuAlKxiIJAMIPN2l1nTRTRZUybDBoLp9CkkAmvp75krld9NB/hbWaeRsxhgVPXYwQKBgQDMsai5QHJAFZ5P31LN0dvlvcj0X2dPS0hEd6NsIf5DkbQKHQuVlxdIGhChLhVBdkGUt9ZYSflxlUtc8GUG3+e0TKg+ZAHNakueV73TGZy3BAzQBxwQBMqUltcXWMjWBaDnbQH+TrtYP0A+ZdHd4gnBNuSUuv5R7IxGWHgfcvtnuQKBgQDBzt2kGjDXXPV4qrtmGl4KaCAvsFr76VsVr8879MhrVgevI5vbsBNWQ3yvykXLr5B6s0VaqibvgDTcchQvqwtoEeDQfHsSHnAglGYCAi06hwGArTW/hxW0L7IivB+laFsbPY2HbnGZ6WUOjMNTgGAihbbLd6+IvLJEVdn7gjxfvwKBgD/DS9rBP5XE5jbdS08AA27yiqnNGkJyIgXp+sdRY4Iq3hmUaKplkYQNUobS8x4cN1ubVLLWAFUoe3xtCht1HhllE7ezsXgKl5mwnVooDVBZe6BFxrEavPxCbKhCKPW6dSACLe/JGMTplxqY3yIuKnm8nsHR6i0c8alsH6c0SypJAoGBALcVCn+5ViY8ZI9nCby8b9X4417phCmxGiB0gpoq9SGglYW3Z8ayoLG+8wzFUgXGhf/DVmL9leZuAIG3KqaVOCNJsEyDK2fEZTwBtBN1pvBBFQRPnBSgMbqTy/3QJT0GRfqHvSkRBjPVLWf/RY2eGjLCihnPqHzNdMHlMBTNxObVAoGAMRDZNtM0vIUNbjY5YFK0AoetPqR1mS2fWOFdCVnyHYBOJmmUZbU4oNZk5HmHBOC8N7aOELyXu56I4yEw0KUjOphKGfA9b2553q1A6t1x1oHBIwVuj1W3sEpUOtj2fWwmmdqjEyRsdzEJWfOuOEFzbfaw1pClq9IbngVcDGfzg74\u003d"
}
2021-08-13 15:59:30 RESPONSE
CallProtectedResourceWithBearerTokenExpectingError
HTTP response
response_status_code
403 FORBIDDEN
response_status_text
Forbidden
response_headers
{
  "date": "Fri, 13 Aug 2021 15:59:30 GMT",
  "content-length": "23",
  "cache-control": "no-cache,no-store,max-age\u003d0",
  "pragma": "no-cache",
  "expires": "0",
  "content-type": "application/json; charset\u003dUTF-8"
}
response_body

{"Access Denied":""}
2021-08-13 15:59:30 SUCCESS
CallProtectedResourceWithBearerTokenExpectingError
Resource endpoint returned error
code
403
body

{"Access Denied":""}
status
Forbidden
2021-08-13 15:59:31 FINISHED
fapi1-advanced-final
Test has run to completion
testmodule_result
PASSED
2021-08-13 15:59:31
TEST-RUNNER
Alias has now been claimed by another test
alias
pingidentity-pingfederate-fapi-adv-op-private-key-par-plain
new_test_id
EoVXnyasYrnPrW3
Test Results