Test Summary

Test Results

Expand All Collapse All
All times are UTC
2021-10-22 15:35:02 INFO
TEST-RUNNER
Test instance dIGcuAAjwdRiOb6 created
baseUrl
https://www.certification.openid.net/test/a/openid-client-nJ8NNhpNiPqaUPXccBg7y
variant
{
  "client_auth_type": "mtls",
  "fapi_auth_request_method": "by_value",
  "fapi_jarm_type": "plain_oauth",
  "fapi_profile": "plain_fapi",
  "fapi_response_mode": "jarm"
}
alias
openid-client-nJ8NNhpNiPqaUPXccBg7y
description
openid-client v5.x FAPI1 Adv. MTLS, JARM (OAUTH2) RP
planId
KbowpthB928My
config
{
  "alias": "openid-client-nJ8NNhpNiPqaUPXccBg7y",
  "description": "openid-client v5.x FAPI1 Adv. MTLS, JARM (OAUTH2) RP",
  "server": {
    "jwks": {
      "keys": [
        {
          "e": "AQAB",
          "n": "ykr3M3bqT5-pTJUgYHKPRiyvGwu1VcZWThjVspDOtHXDxcEjM-qi2E_J5mA2esJy54WwcvR9v9SdGqMWmW51gm7xJ2uH4amN3ImfbXHvusef-RiaPUgatIvFWU8jeQ61YrC9dcNdBVyfluCFVaQa0Bj-_pKTjambyLVKlzIf3BHjRU7vs_Wl3VXWavqzs_CsIlc9bVm-fmLa4tva_VgtESEbkFdfcU9qtGvb11fpmv5zCsDydsZXb08-NpmQup-11sBVKiEyM0AdH5TtXX1W5A_f6-1wa7OyFyS4q9va0kkgciuf_OuJTUwQxFtBFUIv5aDao_JqAAgyXZ2YMs96ZQ",
          "d": "AaxJCxXqrinl3opFMEcCRFRORmz8XO88-3xdGBL2gquOqO4F-oHwQtW2F7-n86_z_1ItuWWoPJPnkLbUkwRE2IVOXUMYZpdeYvqIZQFSODs6aXb4n5UfE2ssgKaU5oVmnqBTkMvC0y6G61qD_8dRqXLrePOBYOSMM0a8jS-O7-T6No84kjtvetzBLpIpRyYpm7sGObyZ8vmei7lc5RveCm7h_6xoz-Rpy63axSrMOF6wQYABGjio-Y45y6QB9Z5S4eWz-fEyiJzIPPExfJxERHZD49Qniw56YHWWaSL795gDBTkVqOSWB3ccWheAurskT6gyGxvr_UKeEY3wVzC6QQ",
          "p": "5WxqxCxzy9VcNxhzIzpIhrOnnUK7DlVIQl6M_s0UijfsHaQxOKm3jmqLJR7vj8S9cBa6YjpYjlGbXptSoStE8oVZNW_mtHP_U_7DUUmr3L8YlV7x68td5bgOXv5ncpzJFfFb8bN62OVEGtOX9ZSKnu8O3RbIL4YFyl4mll6jNkk",
          "q": "4bn8MmZw--XbX2efQIF6cf_c_VPLPCsycDUAKW1Obc5hL7njy_NpuFkoS34LHreYkYGZpOlpcSlqf1C-Joa4C_ObI6xy8gdenNwgwfTC5IuuYxE2YgwD4afXl66vZgvyDbLT_LQRyeM95F5pKlRhHGTa1yYvYKYfEBB3DoVDMz0",
          "dp": "Gn1VKodza1KcTiQ9jxC4tQzjSo4c6P_B0x_1qanmODtSwO1nXYKDFieJH2UeBfySXvHQ3WydMvmLNfY7KS7EzDfHYBsmiSlnjrw4sxcNh_RskzqeNjqKAe8pgaBgM2SU9zqiAhtWENsP7QUHY6yeANHbZn2t6YbQ_le2nuAYejk",
          "dq": "lYoaGuWk6ixgBbdnWFuu28EvDSCrHoRbmNxz6_3_HF3CItUapa3vlvJx8HljMolc6OCcAhWkBhTy-b9rCajsWvabC6oeSFs7gd2PUg8t4izrbbQkfBYLqD4CZPmUN52oUQzsxZghxMbn5NfrAeD-qMnj9O7WKkhDgef2h8cfOt0",
          "qi": "FqO6HvMq-xZ0OpxOpfBfGMjPr-lJUbDZgLF9DIOyGskFbWURD24_HrCppmC07O1oOEIbpEijoyg83_TzVo9Cr5mwoQoMg-cHUxRXTTW3eqjX810neC0IyJhD_ArBojugz29z7DNLcmhzenAzu732geSOQgfeJC6dX1o4opd7Eb8",
          "kty": "RSA",
          "kid": "GEYoS_MAnxmaMCmCWEPv2J4RLa2CZXbtUpczqxBOL98",
          "alg": "PS256",
          "use": "sig"
        }
      ]
    }
  },
  "waitTimeoutSeconds": 2,
  "client": {
    "client_id": "client-id-openid-client-nJ8NNhpNiPqaUPXccBg7y",
    "scope": "All your base are belong to us",
    "redirect_uri": "https://openid-client.local/cb",
    "jwks": {
      "keys": [
        {
          "e": "AQAB",
          "n": "zyk5MmQQFHvIlGDEJuCmIQfNrIhsd_nIyQpobvtu9r7T1XJtmwyhH5ZQ1222JNklS_TjxHEsYA8Q7FtRHiAlJaRMt2eFghdculQMWUpe9wiDH8oNjJxJv8wT3O1lHa48cVnpPvcnDnDB2YN27mftMYwhoiVrc_ZyRzMgi4qiQwAFC7yRTNiL2EX60c1DPmcUyB6hynPZkuA0wC3_0xRsOuMROdan0LtpA3a7ZDVCtqaTxKG4IO6ra7bCE78VYjPV4BTT7eygwtTbzMXisXfbTd_3gxnx6kKHJX2_lpPeS9ara1yRHO8prxDQl9eD7u1NzlKkT8dEgNcoZNt8PGXogQ",
          "kty": "RSA",
          "kid": "Q62TrTV1haEzTUs31MSv5ukhyHNYF5hBgq8dEBYB_dA",
          "x5c": [
            "MIIDmjCCAoKgAwIBAgIJV1pBjrkdmPCLMA0GCSqGSIb3DQEBBQUAMGkxFDASBgNVBAMTC2V4YW1wbGUub3JnMQswCQYDVQQGEwJVUzERMA8GA1UECBMIVmlyZ2luaWExEzARBgNVBAcTCkJsYWNrc2J1cmcxDTALBgNVBAoTBFRlc3QxDTALBgNVBAsTBFRlc3QwHhcNMjExMDIyMTUzNDQ5WhcNMjIxMDIyMTUzNDQ5WjBpMRQwEgYDVQQDEwtleGFtcGxlLm9yZzELMAkGA1UEBhMCVVMxETAPBgNVBAgTCFZpcmdpbmlhMRMwEQYDVQQHEwpCbGFja3NidXJnMQ0wCwYDVQQKEwRUZXN0MQ0wCwYDVQQLEwRUZXN0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzyk5MmQQFHvIlGDEJuCmIQfNrIhsd/nIyQpobvtu9r7T1XJtmwyhH5ZQ1222JNklS/TjxHEsYA8Q7FtRHiAlJaRMt2eFghdculQMWUpe9wiDH8oNjJxJv8wT3O1lHa48cVnpPvcnDnDB2YN27mftMYwhoiVrc/ZyRzMgi4qiQwAFC7yRTNiL2EX60c1DPmcUyB6hynPZkuA0wC3/0xRsOuMROdan0LtpA3a7ZDVCtqaTxKG4IO6ra7bCE78VYjPV4BTT7eygwtTbzMXisXfbTd/3gxnx6kKHJX2/lpPeS9ara1yRHO8prxDQl9eD7u1NzlKkT8dEgNcoZNt8PGXogQIDAQABo0UwQzAMBgNVHRMEBTADAQH/MAsGA1UdDwQEAwIC9DAmBgNVHREEHzAdhhtodHRwOi8vZXhhbXBsZS5vcmcvd2ViaWQjbWUwDQYJKoZIhvcNAQEFBQADggEBAGB52WD6aqDKDz2AxlXvDgb0kzT/TjUJGQ3fzWDClbHVOffwPgr6UFk5t+GB0Mmzprhmy+FqxMqzzAmzSxLgUWJPrK/bvvMLVOn/s7zbUomXcxvN3MSNnadsQ7Sp1ooTutzCXvGsubtd5/lqwGF9w2H0SDWbSnv1B9Ydfmz1u4lQgF48OAVg8NG4ddaLHF5OcsBIjKkaZ19yTm1A3ZpX3gXBZ3EE+AQAgViS5PsxNGJmddoU1AmVx6WEveCSz24EEvVe3QzGY3tXsPC5x0OWg/HXNTvTaopyD32OHe0eA849bH/AzCTeJoHUmmwrrmndVV2EW19RIE3TsGcYSvbhOq8\u003d"
          ],
          "x5t": "iVvstkR20UA6zEz7PjtErwkfaNA",
          "x5t#S256": "NaxsVymqelsvmgnJFMcg9NmXEKjpsFBzFFT1OM5KG3Q"
        }
      ]
    },
    "certificate": "-----BEGIN CERTIFICATE-----\r\nMIIDmjCCAoKgAwIBAgIJV1pBjrkdmPCLMA0GCSqGSIb3DQEBBQUAMGkxFDASBgNV\r\nBAMTC2V4YW1wbGUub3JnMQswCQYDVQQGEwJVUzERMA8GA1UECBMIVmlyZ2luaWEx\r\nEzARBgNVBAcTCkJsYWNrc2J1cmcxDTALBgNVBAoTBFRlc3QxDTALBgNVBAsTBFRl\r\nc3QwHhcNMjExMDIyMTUzNDQ5WhcNMjIxMDIyMTUzNDQ5WjBpMRQwEgYDVQQDEwtl\r\neGFtcGxlLm9yZzELMAkGA1UEBhMCVVMxETAPBgNVBAgTCFZpcmdpbmlhMRMwEQYD\r\nVQQHEwpCbGFja3NidXJnMQ0wCwYDVQQKEwRUZXN0MQ0wCwYDVQQLEwRUZXN0MIIB\r\nIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzyk5MmQQFHvIlGDEJuCmIQfN\r\nrIhsd/nIyQpobvtu9r7T1XJtmwyhH5ZQ1222JNklS/TjxHEsYA8Q7FtRHiAlJaRM\r\nt2eFghdculQMWUpe9wiDH8oNjJxJv8wT3O1lHa48cVnpPvcnDnDB2YN27mftMYwh\r\noiVrc/ZyRzMgi4qiQwAFC7yRTNiL2EX60c1DPmcUyB6hynPZkuA0wC3/0xRsOuMR\r\nOdan0LtpA3a7ZDVCtqaTxKG4IO6ra7bCE78VYjPV4BTT7eygwtTbzMXisXfbTd/3\r\ngxnx6kKHJX2/lpPeS9ara1yRHO8prxDQl9eD7u1NzlKkT8dEgNcoZNt8PGXogQID\r\nAQABo0UwQzAMBgNVHRMEBTADAQH/MAsGA1UdDwQEAwIC9DAmBgNVHREEHzAdhhto\r\ndHRwOi8vZXhhbXBsZS5vcmcvd2ViaWQjbWUwDQYJKoZIhvcNAQEFBQADggEBAGB5\r\n2WD6aqDKDz2AxlXvDgb0kzT/TjUJGQ3fzWDClbHVOffwPgr6UFk5t+GB0Mmzprhm\r\ny+FqxMqzzAmzSxLgUWJPrK/bvvMLVOn/s7zbUomXcxvN3MSNnadsQ7Sp1ooTutzC\r\nXvGsubtd5/lqwGF9w2H0SDWbSnv1B9Ydfmz1u4lQgF48OAVg8NG4ddaLHF5OcsBI\r\njKkaZ19yTm1A3ZpX3gXBZ3EE+AQAgViS5PsxNGJmddoU1AmVx6WEveCSz24EEvVe\r\n3QzGY3tXsPC5x0OWg/HXNTvTaopyD32OHe0eA849bH/AzCTeJoHUmmwrrmndVV2E\r\nW19RIE3TsGcYSvbhOq8\u003d\r\n-----END CERTIFICATE-----\r\n"
  },
  "client2": {
    "client_id": "client2-id-openid-client-nJ8NNhpNiPqaUPXccBg7y",
    "scope": "All your base are belong to us",
    "redirect_uri": "https://openid-client2.local/cb",
    "jwks": {
      "keys": [
        {
          "e": "AQAB",
          "n": "6QfeiHIs4p8duv6ctawji6bsi4aVKccLFDKRHoplVWE6vKZvrPToJmQ9eZMTQxELAU077C3W1L2I_JXGTaY-reyUA1RU0bJTW2XYy_ALJfBeCvXaesBukrlQ1pjNjx3ApQzwMtj8_U3JzSuYuclGGH-sRxmLbTaOtNFtZ7DCVFzmCTzWjNVVLWIlIznAIMSZFQ8Wj0rGgA-_P_qxHXv2vNGa_j5no1AAdswIj0EyIbn2E_NEb2JwFKPWNUQB3Dfekoo1RGBTjOUE-ZrLmPn2uZaJ8_n8uUwAs6sm2fd8rK0-y6LAFWN_47NGK1IJi7Ij6y3O3L-p-YWkMuJHvikX4Q",
          "kty": "RSA",
          "kid": "mhM18AHctbsjFyV4R6gpkelxzY_tyKUy2E20MrqqoJg",
          "use": "sig",
          "x5c": [
            "MIIDmjCCAoKgAwIBAgIJNpiKefP7Uy/8MA0GCSqGSIb3DQEBBQUAMGkxFDASBgNVBAMTC2V4YW1wbGUub3JnMQswCQYDVQQGEwJVUzERMA8GA1UECBMIVmlyZ2luaWExEzARBgNVBAcTCkJsYWNrc2J1cmcxDTALBgNVBAoTBFRlc3QxDTALBgNVBAsTBFRlc3QwHhcNMjExMDIyMTUzNDUwWhcNMjIxMDIyMTUzNDUwWjBpMRQwEgYDVQQDEwtleGFtcGxlLm9yZzELMAkGA1UEBhMCVVMxETAPBgNVBAgTCFZpcmdpbmlhMRMwEQYDVQQHEwpCbGFja3NidXJnMQ0wCwYDVQQKEwRUZXN0MQ0wCwYDVQQLEwRUZXN0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6QfeiHIs4p8duv6ctawji6bsi4aVKccLFDKRHoplVWE6vKZvrPToJmQ9eZMTQxELAU077C3W1L2I/JXGTaY+reyUA1RU0bJTW2XYy/ALJfBeCvXaesBukrlQ1pjNjx3ApQzwMtj8/U3JzSuYuclGGH+sRxmLbTaOtNFtZ7DCVFzmCTzWjNVVLWIlIznAIMSZFQ8Wj0rGgA+/P/qxHXv2vNGa/j5no1AAdswIj0EyIbn2E/NEb2JwFKPWNUQB3Dfekoo1RGBTjOUE+ZrLmPn2uZaJ8/n8uUwAs6sm2fd8rK0+y6LAFWN/47NGK1IJi7Ij6y3O3L+p+YWkMuJHvikX4QIDAQABo0UwQzAMBgNVHRMEBTADAQH/MAsGA1UdDwQEAwIC9DAmBgNVHREEHzAdhhtodHRwOi8vZXhhbXBsZS5vcmcvd2ViaWQjbWUwDQYJKoZIhvcNAQEFBQADggEBAIEhVwhqTlQoOtihBd2WQhLBjpdp/XIeybWZbJ51TWGGF1xk8utMqe6p0stQT81QRbKinRqeB6o6gXKqEw+kTds/6W6dRuDSh0RQMANw8eWqEvLMD/B2u05Wb8WJ+ris3x4dxwiI9wCH4JmeUbnJQe19L/lTFDokPudbK/87EZ3+JnGmnoOdiJjNpHrXxtEb9pNwnXgRJ9lbv7q496lk3fW6YN/4rAhIdZaQzC2H48K1PL93ReY0Psy0L2zsLsl6jR46oIJXKsk/yBpY2eP/kGZ38P3fq8TeUY17CLilh8sKg6XPXzoU6AmiGNrWFA9olPW1NERCcR5Zpd+UhSAiBNo\u003d"
          ],
          "x5t": "xe8W-c0GUfCiYeLudXpSV12t7l0",
          "x5t#S256": "Lgq8nl7u_IyQntmJ5wBPYDt6rrUCmqTh_N2annN2978"
        },
        {
          "e": "AQAB",
          "n": "lgb1wKVE2cBm_sikgbO0te2JKLoA8p3_XUesDG3LYwHQ2Wx8RnkkY203C7jxWiWvLGYeF5XIYopVK-E4Oj83BWDEfrZ4k5oEBSXD-XTgcVM14uCEA7LMGHoGDwV_CTN_4soEt5xNOcxlAW4X34hjdktfunzM0eOHkZBx7qToZqrqYG4JPWeFvovHIBG-l29aVg5RnW_2A5nhDVbyPDLS6Hg0OvGvmjmPvuqdunOYQC3aNB_qs0wgMFPuQ9MN38M1K-yRUd1blTKvTC3hA66_mj23WBbanJ5leUHAzsVdLa6UURhEukbYi0BJjhizRdMpOa8NiO2QKhfs9vKWHbQ45w",
          "kty": "RSA",
          "kid": "yJ3bIx20571oaxlX0DVk1xExDu8UrzAmRb8TxvXDfpQ",
          "alg": "RSA-OAEP-256",
          "use": "enc"
        }
      ]
    },
    "id_token_encrypted_response_alg": "RSA-OAEP-256",
    "certificate": "-----BEGIN CERTIFICATE-----\r\nMIIDmjCCAoKgAwIBAgIJNpiKefP7Uy/8MA0GCSqGSIb3DQEBBQUAMGkxFDASBgNV\r\nBAMTC2V4YW1wbGUub3JnMQswCQYDVQQGEwJVUzERMA8GA1UECBMIVmlyZ2luaWEx\r\nEzARBgNVBAcTCkJsYWNrc2J1cmcxDTALBgNVBAoTBFRlc3QxDTALBgNVBAsTBFRl\r\nc3QwHhcNMjExMDIyMTUzNDUwWhcNMjIxMDIyMTUzNDUwWjBpMRQwEgYDVQQDEwtl\r\neGFtcGxlLm9yZzELMAkGA1UEBhMCVVMxETAPBgNVBAgTCFZpcmdpbmlhMRMwEQYD\r\nVQQHEwpCbGFja3NidXJnMQ0wCwYDVQQKEwRUZXN0MQ0wCwYDVQQLEwRUZXN0MIIB\r\nIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6QfeiHIs4p8duv6ctawji6bs\r\ni4aVKccLFDKRHoplVWE6vKZvrPToJmQ9eZMTQxELAU077C3W1L2I/JXGTaY+reyU\r\nA1RU0bJTW2XYy/ALJfBeCvXaesBukrlQ1pjNjx3ApQzwMtj8/U3JzSuYuclGGH+s\r\nRxmLbTaOtNFtZ7DCVFzmCTzWjNVVLWIlIznAIMSZFQ8Wj0rGgA+/P/qxHXv2vNGa\r\n/j5no1AAdswIj0EyIbn2E/NEb2JwFKPWNUQB3Dfekoo1RGBTjOUE+ZrLmPn2uZaJ\r\n8/n8uUwAs6sm2fd8rK0+y6LAFWN/47NGK1IJi7Ij6y3O3L+p+YWkMuJHvikX4QID\r\nAQABo0UwQzAMBgNVHRMEBTADAQH/MAsGA1UdDwQEAwIC9DAmBgNVHREEHzAdhhto\r\ndHRwOi8vZXhhbXBsZS5vcmcvd2ViaWQjbWUwDQYJKoZIhvcNAQEFBQADggEBAIEh\r\nVwhqTlQoOtihBd2WQhLBjpdp/XIeybWZbJ51TWGGF1xk8utMqe6p0stQT81QRbKi\r\nnRqeB6o6gXKqEw+kTds/6W6dRuDSh0RQMANw8eWqEvLMD/B2u05Wb8WJ+ris3x4d\r\nxwiI9wCH4JmeUbnJQe19L/lTFDokPudbK/87EZ3+JnGmnoOdiJjNpHrXxtEb9pNw\r\nnXgRJ9lbv7q496lk3fW6YN/4rAhIdZaQzC2H48K1PL93ReY0Psy0L2zsLsl6jR46\r\noIJXKsk/yBpY2eP/kGZ38P3fq8TeUY17CLilh8sKg6XPXzoU6AmiGNrWFA9olPW1\r\nNERCcR5Zpd+UhSAiBNo\u003d\r\n-----END CERTIFICATE-----\r\n"
  }
}
testName
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
2021-10-22 15:35:02 SUCCESS
GenerateServerConfigurationMTLS
Created server configuration
server
{
  "issuer": "https://www.certification.openid.net/test/a/openid-client-nJ8NNhpNiPqaUPXccBg7y/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/openid-client-nJ8NNhpNiPqaUPXccBg7y/authorize",
  "token_endpoint": "https://www.certification.openid.net/test-mtls/a/openid-client-nJ8NNhpNiPqaUPXccBg7y/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/openid-client-nJ8NNhpNiPqaUPXccBg7y/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/openid-client-nJ8NNhpNiPqaUPXccBg7y/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/openid-client-nJ8NNhpNiPqaUPXccBg7y/userinfo"
}
issuer
https://www.certification.openid.net/test/a/openid-client-nJ8NNhpNiPqaUPXccBg7y/
discoveryUrl
https://www.certification.openid.net/test/a/openid-client-nJ8NNhpNiPqaUPXccBg7y/.well-known/openid-configuration
2021-10-22 15:35:02 SUCCESS
LoadServerJWKs
Parsed public and private JWK sets
server_jwks
{
  "keys": [
    {
      "p": "5WxqxCxzy9VcNxhzIzpIhrOnnUK7DlVIQl6M_s0UijfsHaQxOKm3jmqLJR7vj8S9cBa6YjpYjlGbXptSoStE8oVZNW_mtHP_U_7DUUmr3L8YlV7x68td5bgOXv5ncpzJFfFb8bN62OVEGtOX9ZSKnu8O3RbIL4YFyl4mll6jNkk",
      "kty": "RSA",
      "q": "4bn8MmZw--XbX2efQIF6cf_c_VPLPCsycDUAKW1Obc5hL7njy_NpuFkoS34LHreYkYGZpOlpcSlqf1C-Joa4C_ObI6xy8gdenNwgwfTC5IuuYxE2YgwD4afXl66vZgvyDbLT_LQRyeM95F5pKlRhHGTa1yYvYKYfEBB3DoVDMz0",
      "d": "AaxJCxXqrinl3opFMEcCRFRORmz8XO88-3xdGBL2gquOqO4F-oHwQtW2F7-n86_z_1ItuWWoPJPnkLbUkwRE2IVOXUMYZpdeYvqIZQFSODs6aXb4n5UfE2ssgKaU5oVmnqBTkMvC0y6G61qD_8dRqXLrePOBYOSMM0a8jS-O7-T6No84kjtvetzBLpIpRyYpm7sGObyZ8vmei7lc5RveCm7h_6xoz-Rpy63axSrMOF6wQYABGjio-Y45y6QB9Z5S4eWz-fEyiJzIPPExfJxERHZD49Qniw56YHWWaSL795gDBTkVqOSWB3ccWheAurskT6gyGxvr_UKeEY3wVzC6QQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "GEYoS_MAnxmaMCmCWEPv2J4RLa2CZXbtUpczqxBOL98",
      "qi": "FqO6HvMq-xZ0OpxOpfBfGMjPr-lJUbDZgLF9DIOyGskFbWURD24_HrCppmC07O1oOEIbpEijoyg83_TzVo9Cr5mwoQoMg-cHUxRXTTW3eqjX810neC0IyJhD_ArBojugz29z7DNLcmhzenAzu732geSOQgfeJC6dX1o4opd7Eb8",
      "dp": "Gn1VKodza1KcTiQ9jxC4tQzjSo4c6P_B0x_1qanmODtSwO1nXYKDFieJH2UeBfySXvHQ3WydMvmLNfY7KS7EzDfHYBsmiSlnjrw4sxcNh_RskzqeNjqKAe8pgaBgM2SU9zqiAhtWENsP7QUHY6yeANHbZn2t6YbQ_le2nuAYejk",
      "alg": "PS256",
      "dq": "lYoaGuWk6ixgBbdnWFuu28EvDSCrHoRbmNxz6_3_HF3CItUapa3vlvJx8HljMolc6OCcAhWkBhTy-b9rCajsWvabC6oeSFs7gd2PUg8t4izrbbQkfBYLqD4CZPmUN52oUQzsxZghxMbn5NfrAeD-qMnj9O7WKkhDgef2h8cfOt0",
      "n": "ykr3M3bqT5-pTJUgYHKPRiyvGwu1VcZWThjVspDOtHXDxcEjM-qi2E_J5mA2esJy54WwcvR9v9SdGqMWmW51gm7xJ2uH4amN3ImfbXHvusef-RiaPUgatIvFWU8jeQ61YrC9dcNdBVyfluCFVaQa0Bj-_pKTjambyLVKlzIf3BHjRU7vs_Wl3VXWavqzs_CsIlc9bVm-fmLa4tva_VgtESEbkFdfcU9qtGvb11fpmv5zCsDydsZXb08-NpmQup-11sBVKiEyM0AdH5TtXX1W5A_f6-1wa7OyFyS4q9va0kkgciuf_OuJTUwQxFtBFUIv5aDao_JqAAgyXZ2YMs96ZQ"
    }
  ]
}
server_encryption_keys
{}
server_public_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "GEYoS_MAnxmaMCmCWEPv2J4RLa2CZXbtUpczqxBOL98",
      "alg": "PS256",
      "n": "ykr3M3bqT5-pTJUgYHKPRiyvGwu1VcZWThjVspDOtHXDxcEjM-qi2E_J5mA2esJy54WwcvR9v9SdGqMWmW51gm7xJ2uH4amN3ImfbXHvusef-RiaPUgatIvFWU8jeQ61YrC9dcNdBVyfluCFVaQa0Bj-_pKTjambyLVKlzIf3BHjRU7vs_Wl3VXWavqzs_CsIlc9bVm-fmLa4tva_VgtESEbkFdfcU9qtGvb11fpmv5zCsDydsZXb08-NpmQup-11sBVKiEyM0AdH5TtXX1W5A_f6-1wa7OyFyS4q9va0kkgciuf_OuJTUwQxFtBFUIv5aDao_JqAAgyXZ2YMs96ZQ"
    }
  ]
}
2021-10-22 15:35:02 SUCCESS
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2021-10-22 15:35:02 SUCCESS
ExtractServerSigningAlg
Successfully extracted algorithm
signing_algorithm
PS256
2021-10-22 15:35:02 SUCCESS
AddTLSClientAuthToServerConfiguration
Added tls_client_auth for token_endpoint_auth_methods_supported
2021-10-22 15:35:02 SUCCESS
AddResponseTypeCodeToServerConfiguration
Added code as response type supported
response_types_supported
[
  "code"
]
2021-10-22 15:35:02 SUCCESS
AddJARMResponseModeToServerConfiguration
Added jwt as response_modes_supported
response_modes_supported
[
  "jwt"
]
2021-10-22 15:35:02 SUCCESS
AddAuthorizationSigningAlgValuesSupportedToServerConfiguration
Added authorization_signing_alg_values_supported to server configuration
alg_values
[
  "PS256"
]
2021-10-22 15:35:02 SUCCESS
FAPIAddTokenEndpointAuthSigningAlgValuesSupportedToServer
Set token_endpoint_auth_signing_alg_values_supported
values
[
  "PS256",
  "ES256"
]
2021-10-22 15:35:02 SUCCESS
CheckServerConfiguration
Found required server configuration keys
required
[
  "authorization_endpoint",
  "token_endpoint",
  "issuer"
]
2021-10-22 15:35:02 SUCCESS
FAPIEnsureMinimumServerKeyLength
Validated minimum key lengths for server_jwks
server_jwks
{
  "keys": [
    {
      "p": "5WxqxCxzy9VcNxhzIzpIhrOnnUK7DlVIQl6M_s0UijfsHaQxOKm3jmqLJR7vj8S9cBa6YjpYjlGbXptSoStE8oVZNW_mtHP_U_7DUUmr3L8YlV7x68td5bgOXv5ncpzJFfFb8bN62OVEGtOX9ZSKnu8O3RbIL4YFyl4mll6jNkk",
      "kty": "RSA",
      "q": "4bn8MmZw--XbX2efQIF6cf_c_VPLPCsycDUAKW1Obc5hL7njy_NpuFkoS34LHreYkYGZpOlpcSlqf1C-Joa4C_ObI6xy8gdenNwgwfTC5IuuYxE2YgwD4afXl66vZgvyDbLT_LQRyeM95F5pKlRhHGTa1yYvYKYfEBB3DoVDMz0",
      "d": "AaxJCxXqrinl3opFMEcCRFRORmz8XO88-3xdGBL2gquOqO4F-oHwQtW2F7-n86_z_1ItuWWoPJPnkLbUkwRE2IVOXUMYZpdeYvqIZQFSODs6aXb4n5UfE2ssgKaU5oVmnqBTkMvC0y6G61qD_8dRqXLrePOBYOSMM0a8jS-O7-T6No84kjtvetzBLpIpRyYpm7sGObyZ8vmei7lc5RveCm7h_6xoz-Rpy63axSrMOF6wQYABGjio-Y45y6QB9Z5S4eWz-fEyiJzIPPExfJxERHZD49Qniw56YHWWaSL795gDBTkVqOSWB3ccWheAurskT6gyGxvr_UKeEY3wVzC6QQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "GEYoS_MAnxmaMCmCWEPv2J4RLa2CZXbtUpczqxBOL98",
      "qi": "FqO6HvMq-xZ0OpxOpfBfGMjPr-lJUbDZgLF9DIOyGskFbWURD24_HrCppmC07O1oOEIbpEijoyg83_TzVo9Cr5mwoQoMg-cHUxRXTTW3eqjX810neC0IyJhD_ArBojugz29z7DNLcmhzenAzu732geSOQgfeJC6dX1o4opd7Eb8",
      "dp": "Gn1VKodza1KcTiQ9jxC4tQzjSo4c6P_B0x_1qanmODtSwO1nXYKDFieJH2UeBfySXvHQ3WydMvmLNfY7KS7EzDfHYBsmiSlnjrw4sxcNh_RskzqeNjqKAe8pgaBgM2SU9zqiAhtWENsP7QUHY6yeANHbZn2t6YbQ_le2nuAYejk",
      "alg": "PS256",
      "dq": "lYoaGuWk6ixgBbdnWFuu28EvDSCrHoRbmNxz6_3_HF3CItUapa3vlvJx8HljMolc6OCcAhWkBhTy-b9rCajsWvabC6oeSFs7gd2PUg8t4izrbbQkfBYLqD4CZPmUN52oUQzsxZghxMbn5NfrAeD-qMnj9O7WKkhDgef2h8cfOt0",
      "n": "ykr3M3bqT5-pTJUgYHKPRiyvGwu1VcZWThjVspDOtHXDxcEjM-qi2E_J5mA2esJy54WwcvR9v9SdGqMWmW51gm7xJ2uH4amN3ImfbXHvusef-RiaPUgatIvFWU8jeQ61YrC9dcNdBVyfluCFVaQa0Bj-_pKTjambyLVKlzIf3BHjRU7vs_Wl3VXWavqzs_CsIlc9bVm-fmLa4tva_VgtESEbkFdfcU9qtGvb11fpmv5zCsDydsZXb08-NpmQup-11sBVKiEyM0AdH5TtXX1W5A_f6-1wa7OyFyS4q9va0kkgciuf_OuJTUwQxFtBFUIv5aDao_JqAAgyXZ2YMs96ZQ"
    }
  ]
}
2021-10-22 15:35:02 SUCCESS
LoadUserInfo
Added user information
user_info
{
  "sub": "user-subject-1234531",
  "name": "Demo T. User",
  "email": "user@example.com",
  "email_verified": false
}
Verify configuration of first client
2021-10-22 15:35:02 SUCCESS
GetStaticClientConfiguration
Found a static client object
client_id
client-id-openid-client-nJ8NNhpNiPqaUPXccBg7y
scope
All your base are belong to us
redirect_uri
https://openid-client.local/cb
jwks
{
  "keys": [
    {
      "e": "AQAB",
      "n": "zyk5MmQQFHvIlGDEJuCmIQfNrIhsd_nIyQpobvtu9r7T1XJtmwyhH5ZQ1222JNklS_TjxHEsYA8Q7FtRHiAlJaRMt2eFghdculQMWUpe9wiDH8oNjJxJv8wT3O1lHa48cVnpPvcnDnDB2YN27mftMYwhoiVrc_ZyRzMgi4qiQwAFC7yRTNiL2EX60c1DPmcUyB6hynPZkuA0wC3_0xRsOuMROdan0LtpA3a7ZDVCtqaTxKG4IO6ra7bCE78VYjPV4BTT7eygwtTbzMXisXfbTd_3gxnx6kKHJX2_lpPeS9ara1yRHO8prxDQl9eD7u1NzlKkT8dEgNcoZNt8PGXogQ",
      "kty": "RSA",
      "kid": "Q62TrTV1haEzTUs31MSv5ukhyHNYF5hBgq8dEBYB_dA",
      "x5c": [
        "MIIDmjCCAoKgAwIBAgIJV1pBjrkdmPCLMA0GCSqGSIb3DQEBBQUAMGkxFDASBgNVBAMTC2V4YW1wbGUub3JnMQswCQYDVQQGEwJVUzERMA8GA1UECBMIVmlyZ2luaWExEzARBgNVBAcTCkJsYWNrc2J1cmcxDTALBgNVBAoTBFRlc3QxDTALBgNVBAsTBFRlc3QwHhcNMjExMDIyMTUzNDQ5WhcNMjIxMDIyMTUzNDQ5WjBpMRQwEgYDVQQDEwtleGFtcGxlLm9yZzELMAkGA1UEBhMCVVMxETAPBgNVBAgTCFZpcmdpbmlhMRMwEQYDVQQHEwpCbGFja3NidXJnMQ0wCwYDVQQKEwRUZXN0MQ0wCwYDVQQLEwRUZXN0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzyk5MmQQFHvIlGDEJuCmIQfNrIhsd/nIyQpobvtu9r7T1XJtmwyhH5ZQ1222JNklS/TjxHEsYA8Q7FtRHiAlJaRMt2eFghdculQMWUpe9wiDH8oNjJxJv8wT3O1lHa48cVnpPvcnDnDB2YN27mftMYwhoiVrc/ZyRzMgi4qiQwAFC7yRTNiL2EX60c1DPmcUyB6hynPZkuA0wC3/0xRsOuMROdan0LtpA3a7ZDVCtqaTxKG4IO6ra7bCE78VYjPV4BTT7eygwtTbzMXisXfbTd/3gxnx6kKHJX2/lpPeS9ara1yRHO8prxDQl9eD7u1NzlKkT8dEgNcoZNt8PGXogQIDAQABo0UwQzAMBgNVHRMEBTADAQH/MAsGA1UdDwQEAwIC9DAmBgNVHREEHzAdhhtodHRwOi8vZXhhbXBsZS5vcmcvd2ViaWQjbWUwDQYJKoZIhvcNAQEFBQADggEBAGB52WD6aqDKDz2AxlXvDgb0kzT/TjUJGQ3fzWDClbHVOffwPgr6UFk5t+GB0Mmzprhmy+FqxMqzzAmzSxLgUWJPrK/bvvMLVOn/s7zbUomXcxvN3MSNnadsQ7Sp1ooTutzCXvGsubtd5/lqwGF9w2H0SDWbSnv1B9Ydfmz1u4lQgF48OAVg8NG4ddaLHF5OcsBIjKkaZ19yTm1A3ZpX3gXBZ3EE+AQAgViS5PsxNGJmddoU1AmVx6WEveCSz24EEvVe3QzGY3tXsPC5x0OWg/HXNTvTaopyD32OHe0eA849bH/AzCTeJoHUmmwrrmndVV2EW19RIE3TsGcYSvbhOq8\u003d"
      ],
      "x5t": "iVvstkR20UA6zEz7PjtErwkfaNA",
      "x5t#S256": "NaxsVymqelsvmgnJFMcg9NmXEKjpsFBzFFT1OM5KG3Q"
    }
  ]
}
certificate
-----BEGIN CERTIFICATE-----
MIIDmjCCAoKgAwIBAgIJV1pBjrkdmPCLMA0GCSqGSIb3DQEBBQUAMGkxFDASBgNV
BAMTC2V4YW1wbGUub3JnMQswCQYDVQQGEwJVUzERMA8GA1UECBMIVmlyZ2luaWEx
EzARBgNVBAcTCkJsYWNrc2J1cmcxDTALBgNVBAoTBFRlc3QxDTALBgNVBAsTBFRl
c3QwHhcNMjExMDIyMTUzNDQ5WhcNMjIxMDIyMTUzNDQ5WjBpMRQwEgYDVQQDEwtl
eGFtcGxlLm9yZzELMAkGA1UEBhMCVVMxETAPBgNVBAgTCFZpcmdpbmlhMRMwEQYD
VQQHEwpCbGFja3NidXJnMQ0wCwYDVQQKEwRUZXN0MQ0wCwYDVQQLEwRUZXN0MIIB
IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzyk5MmQQFHvIlGDEJuCmIQfN
rIhsd/nIyQpobvtu9r7T1XJtmwyhH5ZQ1222JNklS/TjxHEsYA8Q7FtRHiAlJaRM
t2eFghdculQMWUpe9wiDH8oNjJxJv8wT3O1lHa48cVnpPvcnDnDB2YN27mftMYwh
oiVrc/ZyRzMgi4qiQwAFC7yRTNiL2EX60c1DPmcUyB6hynPZkuA0wC3/0xRsOuMR
Odan0LtpA3a7ZDVCtqaTxKG4IO6ra7bCE78VYjPV4BTT7eygwtTbzMXisXfbTd/3
gxnx6kKHJX2/lpPeS9ara1yRHO8prxDQl9eD7u1NzlKkT8dEgNcoZNt8PGXogQID
AQABo0UwQzAMBgNVHRMEBTADAQH/MAsGA1UdDwQEAwIC9DAmBgNVHREEHzAdhhto
dHRwOi8vZXhhbXBsZS5vcmcvd2ViaWQjbWUwDQYJKoZIhvcNAQEFBQADggEBAGB5
2WD6aqDKDz2AxlXvDgb0kzT/TjUJGQ3fzWDClbHVOffwPgr6UFk5t+GB0Mmzprhm
y+FqxMqzzAmzSxLgUWJPrK/bvvMLVOn/s7zbUomXcxvN3MSNnadsQ7Sp1ooTutzC
XvGsubtd5/lqwGF9w2H0SDWbSnv1B9Ydfmz1u4lQgF48OAVg8NG4ddaLHF5OcsBI
jKkaZ19yTm1A3ZpX3gXBZ3EE+AQAgViS5PsxNGJmddoU1AmVx6WEveCSz24EEvVe
3QzGY3tXsPC5x0OWg/HXNTvTaopyD32OHe0eA849bH/AzCTeJoHUmmwrrmndVV2E
W19RIE3TsGcYSvbhOq8=
-----END CERTIFICATE-----
2021-10-22 15:35:02 SUCCESS
ValidateClientJWKsPublicPart
Valid client JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2021-10-22 15:35:02 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "e": "AQAB",
      "n": "zyk5MmQQFHvIlGDEJuCmIQfNrIhsd_nIyQpobvtu9r7T1XJtmwyhH5ZQ1222JNklS_TjxHEsYA8Q7FtRHiAlJaRMt2eFghdculQMWUpe9wiDH8oNjJxJv8wT3O1lHa48cVnpPvcnDnDB2YN27mftMYwhoiVrc_ZyRzMgi4qiQwAFC7yRTNiL2EX60c1DPmcUyB6hynPZkuA0wC3_0xRsOuMROdan0LtpA3a7ZDVCtqaTxKG4IO6ra7bCE78VYjPV4BTT7eygwtTbzMXisXfbTd_3gxnx6kKHJX2_lpPeS9ara1yRHO8prxDQl9eD7u1NzlKkT8dEgNcoZNt8PGXogQ",
      "kty": "RSA",
      "kid": "Q62TrTV1haEzTUs31MSv5ukhyHNYF5hBgq8dEBYB_dA",
      "x5c": [
        "MIIDmjCCAoKgAwIBAgIJV1pBjrkdmPCLMA0GCSqGSIb3DQEBBQUAMGkxFDASBgNVBAMTC2V4YW1wbGUub3JnMQswCQYDVQQGEwJVUzERMA8GA1UECBMIVmlyZ2luaWExEzARBgNVBAcTCkJsYWNrc2J1cmcxDTALBgNVBAoTBFRlc3QxDTALBgNVBAsTBFRlc3QwHhcNMjExMDIyMTUzNDQ5WhcNMjIxMDIyMTUzNDQ5WjBpMRQwEgYDVQQDEwtleGFtcGxlLm9yZzELMAkGA1UEBhMCVVMxETAPBgNVBAgTCFZpcmdpbmlhMRMwEQYDVQQHEwpCbGFja3NidXJnMQ0wCwYDVQQKEwRUZXN0MQ0wCwYDVQQLEwRUZXN0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzyk5MmQQFHvIlGDEJuCmIQfNrIhsd/nIyQpobvtu9r7T1XJtmwyhH5ZQ1222JNklS/TjxHEsYA8Q7FtRHiAlJaRMt2eFghdculQMWUpe9wiDH8oNjJxJv8wT3O1lHa48cVnpPvcnDnDB2YN27mftMYwhoiVrc/ZyRzMgi4qiQwAFC7yRTNiL2EX60c1DPmcUyB6hynPZkuA0wC3/0xRsOuMROdan0LtpA3a7ZDVCtqaTxKG4IO6ra7bCE78VYjPV4BTT7eygwtTbzMXisXfbTd/3gxnx6kKHJX2/lpPeS9ara1yRHO8prxDQl9eD7u1NzlKkT8dEgNcoZNt8PGXogQIDAQABo0UwQzAMBgNVHRMEBTADAQH/MAsGA1UdDwQEAwIC9DAmBgNVHREEHzAdhhtodHRwOi8vZXhhbXBsZS5vcmcvd2ViaWQjbWUwDQYJKoZIhvcNAQEFBQADggEBAGB52WD6aqDKDz2AxlXvDgb0kzT/TjUJGQ3fzWDClbHVOffwPgr6UFk5t+GB0Mmzprhmy+FqxMqzzAmzSxLgUWJPrK/bvvMLVOn/s7zbUomXcxvN3MSNnadsQ7Sp1ooTutzCXvGsubtd5/lqwGF9w2H0SDWbSnv1B9Ydfmz1u4lQgF48OAVg8NG4ddaLHF5OcsBIjKkaZ19yTm1A3ZpX3gXBZ3EE+AQAgViS5PsxNGJmddoU1AmVx6WEveCSz24EEvVe3QzGY3tXsPC5x0OWg/HXNTvTaopyD32OHe0eA849bH/AzCTeJoHUmmwrrmndVV2EW19RIE3TsGcYSvbhOq8\u003d"
      ],
      "x5t": "iVvstkR20UA6zEz7PjtErwkfaNA",
      "x5t#S256": "NaxsVymqelsvmgnJFMcg9NmXEKjpsFBzFFT1OM5KG3Q"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "x5t#S256": "NaxsVymqelsvmgnJFMcg9NmXEKjpsFBzFFT1OM5KG3Q",
      "e": "AQAB",
      "x5t": "iVvstkR20UA6zEz7PjtErwkfaNA",
      "kid": "Q62TrTV1haEzTUs31MSv5ukhyHNYF5hBgq8dEBYB_dA",
      "x5c": [
        "MIIDmjCCAoKgAwIBAgIJV1pBjrkdmPCLMA0GCSqGSIb3DQEBBQUAMGkxFDASBgNVBAMTC2V4YW1wbGUub3JnMQswCQYDVQQGEwJVUzERMA8GA1UECBMIVmlyZ2luaWExEzARBgNVBAcTCkJsYWNrc2J1cmcxDTALBgNVBAoTBFRlc3QxDTALBgNVBAsTBFRlc3QwHhcNMjExMDIyMTUzNDQ5WhcNMjIxMDIyMTUzNDQ5WjBpMRQwEgYDVQQDEwtleGFtcGxlLm9yZzELMAkGA1UEBhMCVVMxETAPBgNVBAgTCFZpcmdpbmlhMRMwEQYDVQQHEwpCbGFja3NidXJnMQ0wCwYDVQQKEwRUZXN0MQ0wCwYDVQQLEwRUZXN0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzyk5MmQQFHvIlGDEJuCmIQfNrIhsd/nIyQpobvtu9r7T1XJtmwyhH5ZQ1222JNklS/TjxHEsYA8Q7FtRHiAlJaRMt2eFghdculQMWUpe9wiDH8oNjJxJv8wT3O1lHa48cVnpPvcnDnDB2YN27mftMYwhoiVrc/ZyRzMgi4qiQwAFC7yRTNiL2EX60c1DPmcUyB6hynPZkuA0wC3/0xRsOuMROdan0LtpA3a7ZDVCtqaTxKG4IO6ra7bCE78VYjPV4BTT7eygwtTbzMXisXfbTd/3gxnx6kKHJX2/lpPeS9ara1yRHO8prxDQl9eD7u1NzlKkT8dEgNcoZNt8PGXogQIDAQABo0UwQzAMBgNVHRMEBTADAQH/MAsGA1UdDwQEAwIC9DAmBgNVHREEHzAdhhtodHRwOi8vZXhhbXBsZS5vcmcvd2ViaWQjbWUwDQYJKoZIhvcNAQEFBQADggEBAGB52WD6aqDKDz2AxlXvDgb0kzT/TjUJGQ3fzWDClbHVOffwPgr6UFk5t+GB0Mmzprhmy+FqxMqzzAmzSxLgUWJPrK/bvvMLVOn/s7zbUomXcxvN3MSNnadsQ7Sp1ooTutzCXvGsubtd5/lqwGF9w2H0SDWbSnv1B9Ydfmz1u4lQgF48OAVg8NG4ddaLHF5OcsBIjKkaZ19yTm1A3ZpX3gXBZ3EE+AQAgViS5PsxNGJmddoU1AmVx6WEveCSz24EEvVe3QzGY3tXsPC5x0OWg/HXNTvTaopyD32OHe0eA849bH/AzCTeJoHUmmwrrmndVV2EW19RIE3TsGcYSvbhOq8\u003d"
      ],
      "n": "zyk5MmQQFHvIlGDEJuCmIQfNrIhsd_nIyQpobvtu9r7T1XJtmwyhH5ZQ1222JNklS_TjxHEsYA8Q7FtRHiAlJaRMt2eFghdculQMWUpe9wiDH8oNjJxJv8wT3O1lHa48cVnpPvcnDnDB2YN27mftMYwhoiVrc_ZyRzMgi4qiQwAFC7yRTNiL2EX60c1DPmcUyB6hynPZkuA0wC3_0xRsOuMROdan0LtpA3a7ZDVCtqaTxKG4IO6ra7bCE78VYjPV4BTT7eygwtTbzMXisXfbTd_3gxnx6kKHJX2_lpPeS9ara1yRHO8prxDQl9eD7u1NzlKkT8dEgNcoZNt8PGXogQ"
    }
  ]
}
2021-10-22 15:35:02 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2021-10-22 15:35:02 SUCCESS
EnsureClientJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2021-10-22 15:35:02 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "e": "AQAB",
      "n": "zyk5MmQQFHvIlGDEJuCmIQfNrIhsd_nIyQpobvtu9r7T1XJtmwyhH5ZQ1222JNklS_TjxHEsYA8Q7FtRHiAlJaRMt2eFghdculQMWUpe9wiDH8oNjJxJv8wT3O1lHa48cVnpPvcnDnDB2YN27mftMYwhoiVrc_ZyRzMgi4qiQwAFC7yRTNiL2EX60c1DPmcUyB6hynPZkuA0wC3_0xRsOuMROdan0LtpA3a7ZDVCtqaTxKG4IO6ra7bCE78VYjPV4BTT7eygwtTbzMXisXfbTd_3gxnx6kKHJX2_lpPeS9ara1yRHO8prxDQl9eD7u1NzlKkT8dEgNcoZNt8PGXogQ",
      "kty": "RSA",
      "kid": "Q62TrTV1haEzTUs31MSv5ukhyHNYF5hBgq8dEBYB_dA",
      "x5c": [
        "MIIDmjCCAoKgAwIBAgIJV1pBjrkdmPCLMA0GCSqGSIb3DQEBBQUAMGkxFDASBgNVBAMTC2V4YW1wbGUub3JnMQswCQYDVQQGEwJVUzERMA8GA1UECBMIVmlyZ2luaWExEzARBgNVBAcTCkJsYWNrc2J1cmcxDTALBgNVBAoTBFRlc3QxDTALBgNVBAsTBFRlc3QwHhcNMjExMDIyMTUzNDQ5WhcNMjIxMDIyMTUzNDQ5WjBpMRQwEgYDVQQDEwtleGFtcGxlLm9yZzELMAkGA1UEBhMCVVMxETAPBgNVBAgTCFZpcmdpbmlhMRMwEQYDVQQHEwpCbGFja3NidXJnMQ0wCwYDVQQKEwRUZXN0MQ0wCwYDVQQLEwRUZXN0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzyk5MmQQFHvIlGDEJuCmIQfNrIhsd/nIyQpobvtu9r7T1XJtmwyhH5ZQ1222JNklS/TjxHEsYA8Q7FtRHiAlJaRMt2eFghdculQMWUpe9wiDH8oNjJxJv8wT3O1lHa48cVnpPvcnDnDB2YN27mftMYwhoiVrc/ZyRzMgi4qiQwAFC7yRTNiL2EX60c1DPmcUyB6hynPZkuA0wC3/0xRsOuMROdan0LtpA3a7ZDVCtqaTxKG4IO6ra7bCE78VYjPV4BTT7eygwtTbzMXisXfbTd/3gxnx6kKHJX2/lpPeS9ara1yRHO8prxDQl9eD7u1NzlKkT8dEgNcoZNt8PGXogQIDAQABo0UwQzAMBgNVHRMEBTADAQH/MAsGA1UdDwQEAwIC9DAmBgNVHREEHzAdhhtodHRwOi8vZXhhbXBsZS5vcmcvd2ViaWQjbWUwDQYJKoZIhvcNAQEFBQADggEBAGB52WD6aqDKDz2AxlXvDgb0kzT/TjUJGQ3fzWDClbHVOffwPgr6UFk5t+GB0Mmzprhmy+FqxMqzzAmzSxLgUWJPrK/bvvMLVOn/s7zbUomXcxvN3MSNnadsQ7Sp1ooTutzCXvGsubtd5/lqwGF9w2H0SDWbSnv1B9Ydfmz1u4lQgF48OAVg8NG4ddaLHF5OcsBIjKkaZ19yTm1A3ZpX3gXBZ3EE+AQAgViS5PsxNGJmddoU1AmVx6WEveCSz24EEvVe3QzGY3tXsPC5x0OWg/HXNTvTaopyD32OHe0eA849bH/AzCTeJoHUmmwrrmndVV2EW19RIE3TsGcYSvbhOq8\u003d"
      ],
      "x5t": "iVvstkR20UA6zEz7PjtErwkfaNA",
      "x5t#S256": "NaxsVymqelsvmgnJFMcg9NmXEKjpsFBzFFT1OM5KG3Q"
    }
  ]
}
Verify configuration of second client
2021-10-22 15:35:02 SUCCESS
GetStaticClient2Configuration
Found a static second client object
client_id
client2-id-openid-client-nJ8NNhpNiPqaUPXccBg7y
scope
All your base are belong to us
redirect_uri
https://openid-client2.local/cb
jwks
{
  "keys": [
    {
      "e": "AQAB",
      "n": "6QfeiHIs4p8duv6ctawji6bsi4aVKccLFDKRHoplVWE6vKZvrPToJmQ9eZMTQxELAU077C3W1L2I_JXGTaY-reyUA1RU0bJTW2XYy_ALJfBeCvXaesBukrlQ1pjNjx3ApQzwMtj8_U3JzSuYuclGGH-sRxmLbTaOtNFtZ7DCVFzmCTzWjNVVLWIlIznAIMSZFQ8Wj0rGgA-_P_qxHXv2vNGa_j5no1AAdswIj0EyIbn2E_NEb2JwFKPWNUQB3Dfekoo1RGBTjOUE-ZrLmPn2uZaJ8_n8uUwAs6sm2fd8rK0-y6LAFWN_47NGK1IJi7Ij6y3O3L-p-YWkMuJHvikX4Q",
      "kty": "RSA",
      "kid": "mhM18AHctbsjFyV4R6gpkelxzY_tyKUy2E20MrqqoJg",
      "use": "sig",
      "x5c": [
        "MIIDmjCCAoKgAwIBAgIJNpiKefP7Uy/8MA0GCSqGSIb3DQEBBQUAMGkxFDASBgNVBAMTC2V4YW1wbGUub3JnMQswCQYDVQQGEwJVUzERMA8GA1UECBMIVmlyZ2luaWExEzARBgNVBAcTCkJsYWNrc2J1cmcxDTALBgNVBAoTBFRlc3QxDTALBgNVBAsTBFRlc3QwHhcNMjExMDIyMTUzNDUwWhcNMjIxMDIyMTUzNDUwWjBpMRQwEgYDVQQDEwtleGFtcGxlLm9yZzELMAkGA1UEBhMCVVMxETAPBgNVBAgTCFZpcmdpbmlhMRMwEQYDVQQHEwpCbGFja3NidXJnMQ0wCwYDVQQKEwRUZXN0MQ0wCwYDVQQLEwRUZXN0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6QfeiHIs4p8duv6ctawji6bsi4aVKccLFDKRHoplVWE6vKZvrPToJmQ9eZMTQxELAU077C3W1L2I/JXGTaY+reyUA1RU0bJTW2XYy/ALJfBeCvXaesBukrlQ1pjNjx3ApQzwMtj8/U3JzSuYuclGGH+sRxmLbTaOtNFtZ7DCVFzmCTzWjNVVLWIlIznAIMSZFQ8Wj0rGgA+/P/qxHXv2vNGa/j5no1AAdswIj0EyIbn2E/NEb2JwFKPWNUQB3Dfekoo1RGBTjOUE+ZrLmPn2uZaJ8/n8uUwAs6sm2fd8rK0+y6LAFWN/47NGK1IJi7Ij6y3O3L+p+YWkMuJHvikX4QIDAQABo0UwQzAMBgNVHRMEBTADAQH/MAsGA1UdDwQEAwIC9DAmBgNVHREEHzAdhhtodHRwOi8vZXhhbXBsZS5vcmcvd2ViaWQjbWUwDQYJKoZIhvcNAQEFBQADggEBAIEhVwhqTlQoOtihBd2WQhLBjpdp/XIeybWZbJ51TWGGF1xk8utMqe6p0stQT81QRbKinRqeB6o6gXKqEw+kTds/6W6dRuDSh0RQMANw8eWqEvLMD/B2u05Wb8WJ+ris3x4dxwiI9wCH4JmeUbnJQe19L/lTFDokPudbK/87EZ3+JnGmnoOdiJjNpHrXxtEb9pNwnXgRJ9lbv7q496lk3fW6YN/4rAhIdZaQzC2H48K1PL93ReY0Psy0L2zsLsl6jR46oIJXKsk/yBpY2eP/kGZ38P3fq8TeUY17CLilh8sKg6XPXzoU6AmiGNrWFA9olPW1NERCcR5Zpd+UhSAiBNo\u003d"
      ],
      "x5t": "xe8W-c0GUfCiYeLudXpSV12t7l0",
      "x5t#S256": "Lgq8nl7u_IyQntmJ5wBPYDt6rrUCmqTh_N2annN2978"
    },
    {
      "e": "AQAB",
      "n": "lgb1wKVE2cBm_sikgbO0te2JKLoA8p3_XUesDG3LYwHQ2Wx8RnkkY203C7jxWiWvLGYeF5XIYopVK-E4Oj83BWDEfrZ4k5oEBSXD-XTgcVM14uCEA7LMGHoGDwV_CTN_4soEt5xNOcxlAW4X34hjdktfunzM0eOHkZBx7qToZqrqYG4JPWeFvovHIBG-l29aVg5RnW_2A5nhDVbyPDLS6Hg0OvGvmjmPvuqdunOYQC3aNB_qs0wgMFPuQ9MN38M1K-yRUd1blTKvTC3hA66_mj23WBbanJ5leUHAzsVdLa6UURhEukbYi0BJjhizRdMpOa8NiO2QKhfs9vKWHbQ45w",
      "kty": "RSA",
      "kid": "yJ3bIx20571oaxlX0DVk1xExDu8UrzAmRb8TxvXDfpQ",
      "alg": "RSA-OAEP-256",
      "use": "enc"
    }
  ]
}
id_token_encrypted_response_alg
RSA-OAEP-256
certificate
-----BEGIN CERTIFICATE-----
MIIDmjCCAoKgAwIBAgIJNpiKefP7Uy/8MA0GCSqGSIb3DQEBBQUAMGkxFDASBgNV
BAMTC2V4YW1wbGUub3JnMQswCQYDVQQGEwJVUzERMA8GA1UECBMIVmlyZ2luaWEx
EzARBgNVBAcTCkJsYWNrc2J1cmcxDTALBgNVBAoTBFRlc3QxDTALBgNVBAsTBFRl
c3QwHhcNMjExMDIyMTUzNDUwWhcNMjIxMDIyMTUzNDUwWjBpMRQwEgYDVQQDEwtl
eGFtcGxlLm9yZzELMAkGA1UEBhMCVVMxETAPBgNVBAgTCFZpcmdpbmlhMRMwEQYD
VQQHEwpCbGFja3NidXJnMQ0wCwYDVQQKEwRUZXN0MQ0wCwYDVQQLEwRUZXN0MIIB
IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6QfeiHIs4p8duv6ctawji6bs
i4aVKccLFDKRHoplVWE6vKZvrPToJmQ9eZMTQxELAU077C3W1L2I/JXGTaY+reyU
A1RU0bJTW2XYy/ALJfBeCvXaesBukrlQ1pjNjx3ApQzwMtj8/U3JzSuYuclGGH+s
RxmLbTaOtNFtZ7DCVFzmCTzWjNVVLWIlIznAIMSZFQ8Wj0rGgA+/P/qxHXv2vNGa
/j5no1AAdswIj0EyIbn2E/NEb2JwFKPWNUQB3Dfekoo1RGBTjOUE+ZrLmPn2uZaJ
8/n8uUwAs6sm2fd8rK0+y6LAFWN/47NGK1IJi7Ij6y3O3L+p+YWkMuJHvikX4QID
AQABo0UwQzAMBgNVHRMEBTADAQH/MAsGA1UdDwQEAwIC9DAmBgNVHREEHzAdhhto
dHRwOi8vZXhhbXBsZS5vcmcvd2ViaWQjbWUwDQYJKoZIhvcNAQEFBQADggEBAIEh
VwhqTlQoOtihBd2WQhLBjpdp/XIeybWZbJ51TWGGF1xk8utMqe6p0stQT81QRbKi
nRqeB6o6gXKqEw+kTds/6W6dRuDSh0RQMANw8eWqEvLMD/B2u05Wb8WJ+ris3x4d
xwiI9wCH4JmeUbnJQe19L/lTFDokPudbK/87EZ3+JnGmnoOdiJjNpHrXxtEb9pNw
nXgRJ9lbv7q496lk3fW6YN/4rAhIdZaQzC2H48K1PL93ReY0Psy0L2zsLsl6jR46
oIJXKsk/yBpY2eP/kGZ38P3fq8TeUY17CLilh8sKg6XPXzoU6AmiGNrWFA9olPW1
NERCcR5Zpd+UhSAiBNo=
-----END CERTIFICATE-----
2021-10-22 15:35:02 SUCCESS
ValidateClientJWKsPublicPart
Valid client JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2021-10-22 15:35:02 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "e": "AQAB",
      "n": "6QfeiHIs4p8duv6ctawji6bsi4aVKccLFDKRHoplVWE6vKZvrPToJmQ9eZMTQxELAU077C3W1L2I_JXGTaY-reyUA1RU0bJTW2XYy_ALJfBeCvXaesBukrlQ1pjNjx3ApQzwMtj8_U3JzSuYuclGGH-sRxmLbTaOtNFtZ7DCVFzmCTzWjNVVLWIlIznAIMSZFQ8Wj0rGgA-_P_qxHXv2vNGa_j5no1AAdswIj0EyIbn2E_NEb2JwFKPWNUQB3Dfekoo1RGBTjOUE-ZrLmPn2uZaJ8_n8uUwAs6sm2fd8rK0-y6LAFWN_47NGK1IJi7Ij6y3O3L-p-YWkMuJHvikX4Q",
      "kty": "RSA",
      "kid": "mhM18AHctbsjFyV4R6gpkelxzY_tyKUy2E20MrqqoJg",
      "use": "sig",
      "x5c": [
        "MIIDmjCCAoKgAwIBAgIJNpiKefP7Uy/8MA0GCSqGSIb3DQEBBQUAMGkxFDASBgNVBAMTC2V4YW1wbGUub3JnMQswCQYDVQQGEwJVUzERMA8GA1UECBMIVmlyZ2luaWExEzARBgNVBAcTCkJsYWNrc2J1cmcxDTALBgNVBAoTBFRlc3QxDTALBgNVBAsTBFRlc3QwHhcNMjExMDIyMTUzNDUwWhcNMjIxMDIyMTUzNDUwWjBpMRQwEgYDVQQDEwtleGFtcGxlLm9yZzELMAkGA1UEBhMCVVMxETAPBgNVBAgTCFZpcmdpbmlhMRMwEQYDVQQHEwpCbGFja3NidXJnMQ0wCwYDVQQKEwRUZXN0MQ0wCwYDVQQLEwRUZXN0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6QfeiHIs4p8duv6ctawji6bsi4aVKccLFDKRHoplVWE6vKZvrPToJmQ9eZMTQxELAU077C3W1L2I/JXGTaY+reyUA1RU0bJTW2XYy/ALJfBeCvXaesBukrlQ1pjNjx3ApQzwMtj8/U3JzSuYuclGGH+sRxmLbTaOtNFtZ7DCVFzmCTzWjNVVLWIlIznAIMSZFQ8Wj0rGgA+/P/qxHXv2vNGa/j5no1AAdswIj0EyIbn2E/NEb2JwFKPWNUQB3Dfekoo1RGBTjOUE+ZrLmPn2uZaJ8/n8uUwAs6sm2fd8rK0+y6LAFWN/47NGK1IJi7Ij6y3O3L+p+YWkMuJHvikX4QIDAQABo0UwQzAMBgNVHRMEBTADAQH/MAsGA1UdDwQEAwIC9DAmBgNVHREEHzAdhhtodHRwOi8vZXhhbXBsZS5vcmcvd2ViaWQjbWUwDQYJKoZIhvcNAQEFBQADggEBAIEhVwhqTlQoOtihBd2WQhLBjpdp/XIeybWZbJ51TWGGF1xk8utMqe6p0stQT81QRbKinRqeB6o6gXKqEw+kTds/6W6dRuDSh0RQMANw8eWqEvLMD/B2u05Wb8WJ+ris3x4dxwiI9wCH4JmeUbnJQe19L/lTFDokPudbK/87EZ3+JnGmnoOdiJjNpHrXxtEb9pNwnXgRJ9lbv7q496lk3fW6YN/4rAhIdZaQzC2H48K1PL93ReY0Psy0L2zsLsl6jR46oIJXKsk/yBpY2eP/kGZ38P3fq8TeUY17CLilh8sKg6XPXzoU6AmiGNrWFA9olPW1NERCcR5Zpd+UhSAiBNo\u003d"
      ],
      "x5t": "xe8W-c0GUfCiYeLudXpSV12t7l0",
      "x5t#S256": "Lgq8nl7u_IyQntmJ5wBPYDt6rrUCmqTh_N2annN2978"
    },
    {
      "e": "AQAB",
      "n": "lgb1wKVE2cBm_sikgbO0te2JKLoA8p3_XUesDG3LYwHQ2Wx8RnkkY203C7jxWiWvLGYeF5XIYopVK-E4Oj83BWDEfrZ4k5oEBSXD-XTgcVM14uCEA7LMGHoGDwV_CTN_4soEt5xNOcxlAW4X34hjdktfunzM0eOHkZBx7qToZqrqYG4JPWeFvovHIBG-l29aVg5RnW_2A5nhDVbyPDLS6Hg0OvGvmjmPvuqdunOYQC3aNB_qs0wgMFPuQ9MN38M1K-yRUd1blTKvTC3hA66_mj23WBbanJ5leUHAzsVdLa6UURhEukbYi0BJjhizRdMpOa8NiO2QKhfs9vKWHbQ45w",
      "kty": "RSA",
      "kid": "yJ3bIx20571oaxlX0DVk1xExDu8UrzAmRb8TxvXDfpQ",
      "alg": "RSA-OAEP-256",
      "use": "enc"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "x5t#S256": "Lgq8nl7u_IyQntmJ5wBPYDt6rrUCmqTh_N2annN2978",
      "e": "AQAB",
      "use": "sig",
      "x5t": "xe8W-c0GUfCiYeLudXpSV12t7l0",
      "kid": "mhM18AHctbsjFyV4R6gpkelxzY_tyKUy2E20MrqqoJg",
      "x5c": [
        "MIIDmjCCAoKgAwIBAgIJNpiKefP7Uy/8MA0GCSqGSIb3DQEBBQUAMGkxFDASBgNVBAMTC2V4YW1wbGUub3JnMQswCQYDVQQGEwJVUzERMA8GA1UECBMIVmlyZ2luaWExEzARBgNVBAcTCkJsYWNrc2J1cmcxDTALBgNVBAoTBFRlc3QxDTALBgNVBAsTBFRlc3QwHhcNMjExMDIyMTUzNDUwWhcNMjIxMDIyMTUzNDUwWjBpMRQwEgYDVQQDEwtleGFtcGxlLm9yZzELMAkGA1UEBhMCVVMxETAPBgNVBAgTCFZpcmdpbmlhMRMwEQYDVQQHEwpCbGFja3NidXJnMQ0wCwYDVQQKEwRUZXN0MQ0wCwYDVQQLEwRUZXN0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6QfeiHIs4p8duv6ctawji6bsi4aVKccLFDKRHoplVWE6vKZvrPToJmQ9eZMTQxELAU077C3W1L2I/JXGTaY+reyUA1RU0bJTW2XYy/ALJfBeCvXaesBukrlQ1pjNjx3ApQzwMtj8/U3JzSuYuclGGH+sRxmLbTaOtNFtZ7DCVFzmCTzWjNVVLWIlIznAIMSZFQ8Wj0rGgA+/P/qxHXv2vNGa/j5no1AAdswIj0EyIbn2E/NEb2JwFKPWNUQB3Dfekoo1RGBTjOUE+ZrLmPn2uZaJ8/n8uUwAs6sm2fd8rK0+y6LAFWN/47NGK1IJi7Ij6y3O3L+p+YWkMuJHvikX4QIDAQABo0UwQzAMBgNVHRMEBTADAQH/MAsGA1UdDwQEAwIC9DAmBgNVHREEHzAdhhtodHRwOi8vZXhhbXBsZS5vcmcvd2ViaWQjbWUwDQYJKoZIhvcNAQEFBQADggEBAIEhVwhqTlQoOtihBd2WQhLBjpdp/XIeybWZbJ51TWGGF1xk8utMqe6p0stQT81QRbKinRqeB6o6gXKqEw+kTds/6W6dRuDSh0RQMANw8eWqEvLMD/B2u05Wb8WJ+ris3x4dxwiI9wCH4JmeUbnJQe19L/lTFDokPudbK/87EZ3+JnGmnoOdiJjNpHrXxtEb9pNwnXgRJ9lbv7q496lk3fW6YN/4rAhIdZaQzC2H48K1PL93ReY0Psy0L2zsLsl6jR46oIJXKsk/yBpY2eP/kGZ38P3fq8TeUY17CLilh8sKg6XPXzoU6AmiGNrWFA9olPW1NERCcR5Zpd+UhSAiBNo\u003d"
      ],
      "n": "6QfeiHIs4p8duv6ctawji6bsi4aVKccLFDKRHoplVWE6vKZvrPToJmQ9eZMTQxELAU077C3W1L2I_JXGTaY-reyUA1RU0bJTW2XYy_ALJfBeCvXaesBukrlQ1pjNjx3ApQzwMtj8_U3JzSuYuclGGH-sRxmLbTaOtNFtZ7DCVFzmCTzWjNVVLWIlIznAIMSZFQ8Wj0rGgA-_P_qxHXv2vNGa_j5no1AAdswIj0EyIbn2E_NEb2JwFKPWNUQB3Dfekoo1RGBTjOUE-ZrLmPn2uZaJ8_n8uUwAs6sm2fd8rK0-y6LAFWN_47NGK1IJi7Ij6y3O3L-p-YWkMuJHvikX4Q"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "yJ3bIx20571oaxlX0DVk1xExDu8UrzAmRb8TxvXDfpQ",
      "alg": "RSA-OAEP-256",
      "n": "lgb1wKVE2cBm_sikgbO0te2JKLoA8p3_XUesDG3LYwHQ2Wx8RnkkY203C7jxWiWvLGYeF5XIYopVK-E4Oj83BWDEfrZ4k5oEBSXD-XTgcVM14uCEA7LMGHoGDwV_CTN_4soEt5xNOcxlAW4X34hjdktfunzM0eOHkZBx7qToZqrqYG4JPWeFvovHIBG-l29aVg5RnW_2A5nhDVbyPDLS6Hg0OvGvmjmPvuqdunOYQC3aNB_qs0wgMFPuQ9MN38M1K-yRUd1blTKvTC3hA66_mj23WBbanJ5leUHAzsVdLa6UURhEukbYi0BJjhizRdMpOa8NiO2QKhfs9vKWHbQ45w"
    }
  ]
}
2021-10-22 15:35:02 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2021-10-22 15:35:02 SUCCESS
EnsureClientJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2021-10-22 15:35:02 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "e": "AQAB",
      "n": "6QfeiHIs4p8duv6ctawji6bsi4aVKccLFDKRHoplVWE6vKZvrPToJmQ9eZMTQxELAU077C3W1L2I_JXGTaY-reyUA1RU0bJTW2XYy_ALJfBeCvXaesBukrlQ1pjNjx3ApQzwMtj8_U3JzSuYuclGGH-sRxmLbTaOtNFtZ7DCVFzmCTzWjNVVLWIlIznAIMSZFQ8Wj0rGgA-_P_qxHXv2vNGa_j5no1AAdswIj0EyIbn2E_NEb2JwFKPWNUQB3Dfekoo1RGBTjOUE-ZrLmPn2uZaJ8_n8uUwAs6sm2fd8rK0-y6LAFWN_47NGK1IJi7Ij6y3O3L-p-YWkMuJHvikX4Q",
      "kty": "RSA",
      "kid": "mhM18AHctbsjFyV4R6gpkelxzY_tyKUy2E20MrqqoJg",
      "use": "sig",
      "x5c": [
        "MIIDmjCCAoKgAwIBAgIJNpiKefP7Uy/8MA0GCSqGSIb3DQEBBQUAMGkxFDASBgNVBAMTC2V4YW1wbGUub3JnMQswCQYDVQQGEwJVUzERMA8GA1UECBMIVmlyZ2luaWExEzARBgNVBAcTCkJsYWNrc2J1cmcxDTALBgNVBAoTBFRlc3QxDTALBgNVBAsTBFRlc3QwHhcNMjExMDIyMTUzNDUwWhcNMjIxMDIyMTUzNDUwWjBpMRQwEgYDVQQDEwtleGFtcGxlLm9yZzELMAkGA1UEBhMCVVMxETAPBgNVBAgTCFZpcmdpbmlhMRMwEQYDVQQHEwpCbGFja3NidXJnMQ0wCwYDVQQKEwRUZXN0MQ0wCwYDVQQLEwRUZXN0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6QfeiHIs4p8duv6ctawji6bsi4aVKccLFDKRHoplVWE6vKZvrPToJmQ9eZMTQxELAU077C3W1L2I/JXGTaY+reyUA1RU0bJTW2XYy/ALJfBeCvXaesBukrlQ1pjNjx3ApQzwMtj8/U3JzSuYuclGGH+sRxmLbTaOtNFtZ7DCVFzmCTzWjNVVLWIlIznAIMSZFQ8Wj0rGgA+/P/qxHXv2vNGa/j5no1AAdswIj0EyIbn2E/NEb2JwFKPWNUQB3Dfekoo1RGBTjOUE+ZrLmPn2uZaJ8/n8uUwAs6sm2fd8rK0+y6LAFWN/47NGK1IJi7Ij6y3O3L+p+YWkMuJHvikX4QIDAQABo0UwQzAMBgNVHRMEBTADAQH/MAsGA1UdDwQEAwIC9DAmBgNVHREEHzAdhhtodHRwOi8vZXhhbXBsZS5vcmcvd2ViaWQjbWUwDQYJKoZIhvcNAQEFBQADggEBAIEhVwhqTlQoOtihBd2WQhLBjpdp/XIeybWZbJ51TWGGF1xk8utMqe6p0stQT81QRbKinRqeB6o6gXKqEw+kTds/6W6dRuDSh0RQMANw8eWqEvLMD/B2u05Wb8WJ+ris3x4dxwiI9wCH4JmeUbnJQe19L/lTFDokPudbK/87EZ3+JnGmnoOdiJjNpHrXxtEb9pNwnXgRJ9lbv7q496lk3fW6YN/4rAhIdZaQzC2H48K1PL93ReY0Psy0L2zsLsl6jR46oIJXKsk/yBpY2eP/kGZ38P3fq8TeUY17CLilh8sKg6XPXzoU6AmiGNrWFA9olPW1NERCcR5Zpd+UhSAiBNo\u003d"
      ],
      "x5t": "xe8W-c0GUfCiYeLudXpSV12t7l0",
      "x5t#S256": "Lgq8nl7u_IyQntmJ5wBPYDt6rrUCmqTh_N2annN2978"
    },
    {
      "e": "AQAB",
      "n": "lgb1wKVE2cBm_sikgbO0te2JKLoA8p3_XUesDG3LYwHQ2Wx8RnkkY203C7jxWiWvLGYeF5XIYopVK-E4Oj83BWDEfrZ4k5oEBSXD-XTgcVM14uCEA7LMGHoGDwV_CTN_4soEt5xNOcxlAW4X34hjdktfunzM0eOHkZBx7qToZqrqYG4JPWeFvovHIBG-l29aVg5RnW_2A5nhDVbyPDLS6Hg0OvGvmjmPvuqdunOYQC3aNB_qs0wgMFPuQ9MN38M1K-yRUd1blTKvTC3hA66_mj23WBbanJ5leUHAzsVdLa6UURhEukbYi0BJjhizRdMpOa8NiO2QKhfs9vKWHbQ45w",
      "kty": "RSA",
      "kid": "yJ3bIx20571oaxlX0DVk1xExDu8UrzAmRb8TxvXDfpQ",
      "alg": "RSA-OAEP-256",
      "use": "enc"
    }
  ]
}
2021-10-22 15:35:02
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Setup Done
2021-10-22 15:35:03 INCOMING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Incoming HTTP request to test instance dIGcuAAjwdRiOb6
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "x-ssl-cipher": "ECDHE-RSA-AES128-GCM-SHA256",
  "x-ssl-protocol": "TLSv1.2",
  "connection": "close",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net"
}
incoming_path
.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-10-22 15:35:03 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-10-22 15:35:03 OUTGOING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Response to HTTP request to test instance dIGcuAAjwdRiOb6
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/openid-client-nJ8NNhpNiPqaUPXccBg7y/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/openid-client-nJ8NNhpNiPqaUPXccBg7y/authorize",
  "token_endpoint": "https://www.certification.openid.net/test-mtls/a/openid-client-nJ8NNhpNiPqaUPXccBg7y/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/openid-client-nJ8NNhpNiPqaUPXccBg7y/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/openid-client-nJ8NNhpNiPqaUPXccBg7y/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/openid-client-nJ8NNhpNiPqaUPXccBg7y/userinfo",
  "token_endpoint_auth_methods_supported": [
    "tls_client_auth"
  ],
  "response_types_supported": [
    "code"
  ],
  "response_modes_supported": [
    "jwt"
  ],
  "authorization_signing_alg_values_supported": [
    "PS256"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256",
    "ES256"
  ]
}
outgoing_path
.well-known/openid-configuration
2021-10-22 15:35:03 INCOMING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Incoming HTTP request to test instance dIGcuAAjwdRiOb6
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "got (https://github.com/sindresorhus/got)",
  "accept-encoding": "gzip, deflate, br",
  "x-ssl-cipher": "ECDHE-RSA-AES128-GCM-SHA256",
  "x-ssl-protocol": "TLSv1.2",
  "connection": "close",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net"
}
incoming_path
authorize
incoming_body_form_params
incoming_method
GET
incoming_body_json
incoming_query_string_params
{
  "client_id": "client-id-openid-client-nJ8NNhpNiPqaUPXccBg7y",
  "scope": "openid",
  "response_type": "code",
  "redirect_uri": "https://openid-client.local/cb",
  "state": "RLxfaFIT5jN2WP0aG-TMhyoVo0mvAsujipoJk2HsNpg",
  "request": "eyJhbGciOiJQUzI1NiIsInR5cCI6Im9hdXRoLWF1dGh6LXJlcStqd3QiLCJraWQiOiJRNjJUclRWMWhhRXpUVXMzMU1TdjV1a2h5SE5ZRjVoQmdxOGRFQllCX2RBIn0.eyJyZWRpcmVjdF91cmkiOiJodHRwczovL29wZW5pZC1jbGllbnQubG9jYWwvY2IiLCJzY29wZSI6IkFsbCB5b3VyIGJhc2UgYXJlIGJlbG9uZyB0byB1cyIsInJlc3BvbnNlX3R5cGUiOiJjb2RlIiwic3RhdGUiOiJSTHhmYUZJVDVqTjJXUDBhRy1UTWh5b1ZvMG12QXN1amlwb0prMkhzTnBnIiwiaXNzIjoiY2xpZW50LWlkLW9wZW5pZC1jbGllbnQtbko4Tk5ocE5pUHFhVVBYY2NCZzd5IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9vcGVuaWQtY2xpZW50LW5KOE5OaHBOaVBxYVVQWGNjQmc3eS8iLCJjbGllbnRfaWQiOiJjbGllbnQtaWQtb3BlbmlkLWNsaWVudC1uSjhOTmhwTmlQcWFVUFhjY0JnN3kiLCJqdGkiOiJaeVppSmRDM3JzMHdlUmFGV2FWTGNpRDRNQWVnRWdpYmpwdVptZHZQNldJIiwiaWF0IjoxNjM0OTE2OTAzLCJleHAiOjE2MzQ5MTcyMDMsIm5iZiI6MTYzNDkxNjkwM30.maA4MbBRAF0lkkyJDbo51HDSixhjxo86x6ZCFRqV2PCQjN86lFFAXF9ZnolkIb2xnKJZTie1KG3iw5JsdPvWpagZkIRBLYtCn5o-dhbeOCml9e5j-kPUyTlrMSdVtBo-1oYKaSDMWNOPHh0Drk3pMpj2q6td5c_r5qLDVJsa_hBqklomsaF-9ZQl2Fh_PsxYqf4kkNvzEyHvdh6OekE8btN-Y2Igzzju30Yw_ZU5sR9ElO42y1157Kbv6O_1xJ9ld4FqhbgZ23l1Pp2q5RcUon9dHcpFIk79Qslo3K2rTvYVkIavdLQMeSCQpterCGwqA0Kewp4OoXUy6NQahtAKng"
}
incoming_body
2021-10-22 15:35:03 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Authorization endpoint
2021-10-22 15:35:03 SUCCESS
ExtractRequestObject
Parsed request object
request_object
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6Im9hdXRoLWF1dGh6LXJlcStqd3QiLCJraWQiOiJRNjJUclRWMWhhRXpUVXMzMU1TdjV1a2h5SE5ZRjVoQmdxOGRFQllCX2RBIn0.eyJyZWRpcmVjdF91cmkiOiJodHRwczovL29wZW5pZC1jbGllbnQubG9jYWwvY2IiLCJzY29wZSI6IkFsbCB5b3VyIGJhc2UgYXJlIGJlbG9uZyB0byB1cyIsInJlc3BvbnNlX3R5cGUiOiJjb2RlIiwic3RhdGUiOiJSTHhmYUZJVDVqTjJXUDBhRy1UTWh5b1ZvMG12QXN1amlwb0prMkhzTnBnIiwiaXNzIjoiY2xpZW50LWlkLW9wZW5pZC1jbGllbnQtbko4Tk5ocE5pUHFhVVBYY2NCZzd5IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9vcGVuaWQtY2xpZW50LW5KOE5OaHBOaVBxYVVQWGNjQmc3eS8iLCJjbGllbnRfaWQiOiJjbGllbnQtaWQtb3BlbmlkLWNsaWVudC1uSjhOTmhwTmlQcWFVUFhjY0JnN3kiLCJqdGkiOiJaeVppSmRDM3JzMHdlUmFGV2FWTGNpRDRNQWVnRWdpYmpwdVptZHZQNldJIiwiaWF0IjoxNjM0OTE2OTAzLCJleHAiOjE2MzQ5MTcyMDMsIm5iZiI6MTYzNDkxNjkwM30.maA4MbBRAF0lkkyJDbo51HDSixhjxo86x6ZCFRqV2PCQjN86lFFAXF9ZnolkIb2xnKJZTie1KG3iw5JsdPvWpagZkIRBLYtCn5o-dhbeOCml9e5j-kPUyTlrMSdVtBo-1oYKaSDMWNOPHh0Drk3pMpj2q6td5c_r5qLDVJsa_hBqklomsaF-9ZQl2Fh_PsxYqf4kkNvzEyHvdh6OekE8btN-Y2Igzzju30Yw_ZU5sR9ElO42y1157Kbv6O_1xJ9ld4FqhbgZ23l1Pp2q5RcUon9dHcpFIk79Qslo3K2rTvYVkIavdLQMeSCQpterCGwqA0Kewp4OoXUy6NQahtAKng",
  "header": {
    "kid": "Q62TrTV1haEzTUs31MSv5ukhyHNYF5hBgq8dEBYB_dA",
    "typ": "oauth-authz-req+jwt",
    "alg": "PS256"
  },
  "claims": {
    "aud": "https://www.certification.openid.net/test/a/openid-client-nJ8NNhpNiPqaUPXccBg7y/",
    "nbf": 1634916903,
    "scope": "All your base are belong to us",
    "iss": "client-id-openid-client-nJ8NNhpNiPqaUPXccBg7y",
    "response_type": "code",
    "redirect_uri": "https://openid-client.local/cb",
    "state": "RLxfaFIT5jN2WP0aG-TMhyoVo0mvAsujipoJk2HsNpg",
    "exp": 1634917203,
    "iat": 1634916903,
    "client_id": "client-id-openid-client-nJ8NNhpNiPqaUPXccBg7y",
    "jti": "ZyZiJdC3rs0weRaFWaVLciD4MAegEgibjpuZmdvP6WI"
  }
}
2021-10-22 15:35:03 INFO
ValidateEncryptedRequestObjectHasKid
Skipped evaluation due to missing required element: authorization_request_object jwe_header
path
jwe_header
mapped
object
authorization_request_object
2021-10-22 15:35:03 SUCCESS
CreateEffectiveAuthorizationRequestParameters
Merged http request parameters with request object claims
effective_authorization_endpoint_request
{
  "client_id": "client-id-openid-client-nJ8NNhpNiPqaUPXccBg7y",
  "scope": "All your base are belong to us",
  "response_type": "code",
  "redirect_uri": "https://openid-client.local/cb",
  "state": "RLxfaFIT5jN2WP0aG-TMhyoVo0mvAsujipoJk2HsNpg",
  "request": "eyJhbGciOiJQUzI1NiIsInR5cCI6Im9hdXRoLWF1dGh6LXJlcStqd3QiLCJraWQiOiJRNjJUclRWMWhhRXpUVXMzMU1TdjV1a2h5SE5ZRjVoQmdxOGRFQllCX2RBIn0.eyJyZWRpcmVjdF91cmkiOiJodHRwczovL29wZW5pZC1jbGllbnQubG9jYWwvY2IiLCJzY29wZSI6IkFsbCB5b3VyIGJhc2UgYXJlIGJlbG9uZyB0byB1cyIsInJlc3BvbnNlX3R5cGUiOiJjb2RlIiwic3RhdGUiOiJSTHhmYUZJVDVqTjJXUDBhRy1UTWh5b1ZvMG12QXN1amlwb0prMkhzTnBnIiwiaXNzIjoiY2xpZW50LWlkLW9wZW5pZC1jbGllbnQtbko4Tk5ocE5pUHFhVVBYY2NCZzd5IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9vcGVuaWQtY2xpZW50LW5KOE5OaHBOaVBxYVVQWGNjQmc3eS8iLCJjbGllbnRfaWQiOiJjbGllbnQtaWQtb3BlbmlkLWNsaWVudC1uSjhOTmhwTmlQcWFVUFhjY0JnN3kiLCJqdGkiOiJaeVppSmRDM3JzMHdlUmFGV2FWTGNpRDRNQWVnRWdpYmpwdVptZHZQNldJIiwiaWF0IjoxNjM0OTE2OTAzLCJleHAiOjE2MzQ5MTcyMDMsIm5iZiI6MTYzNDkxNjkwM30.maA4MbBRAF0lkkyJDbo51HDSixhjxo86x6ZCFRqV2PCQjN86lFFAXF9ZnolkIb2xnKJZTie1KG3iw5JsdPvWpagZkIRBLYtCn5o-dhbeOCml9e5j-kPUyTlrMSdVtBo-1oYKaSDMWNOPHh0Drk3pMpj2q6td5c_r5qLDVJsa_hBqklomsaF-9ZQl2Fh_PsxYqf4kkNvzEyHvdh6OekE8btN-Y2Igzzju30Yw_ZU5sR9ElO42y1157Kbv6O_1xJ9ld4FqhbgZ23l1Pp2q5RcUon9dHcpFIk79Qslo3K2rTvYVkIavdLQMeSCQpterCGwqA0Kewp4OoXUy6NQahtAKng",
  "aud": "https://www.certification.openid.net/test/a/openid-client-nJ8NNhpNiPqaUPXccBg7y/",
  "nbf": 1634916903,
  "iss": "client-id-openid-client-nJ8NNhpNiPqaUPXccBg7y",
  "exp": 1634917203,
  "iat": 1634916903,
  "jti": "ZyZiJdC3rs0weRaFWaVLciD4MAegEgibjpuZmdvP6WI"
}
2021-10-22 15:35:03 SUCCESS
FAPIValidateRequestObjectSigningAlg
Request object was signed with a permitted algorithm
alg
PS256
2021-10-22 15:35:03 SUCCESS
FAPIValidateRequestObjectExp
Request object contains a valid exp claim, expiry time
exp
"Oct 22, 2021, 3:40:03 PM"
2021-10-22 15:35:03 SUCCESS
FAPI1AdvancedValidateRequestObjectNBFClaim
nbf claim is valid
nbf
"Oct 22, 2021, 3:35:03 PM"
now
"Oct 22, 2021, 3:35:03 PM"
2021-10-22 15:35:03
ValidateRequestObjectClaims
Request object does not contain a max_age claim
2021-10-22 15:35:03 SUCCESS
ValidateRequestObjectClaims
Request object claims passed all validation checks
2021-10-22 15:35:03 SUCCESS
EnsureNumericRequestObjectClaimsAreNotNull
None of the claims expected to have numeric values, have null values
numeric_claims
[
  "max_age"
]
2021-10-22 15:35:03 SUCCESS
EnsureRequestObjectDoesNotContainRequestOrRequestUri
Request object does not contain request or request_uri
2021-10-22 15:35:03 SUCCESS
EnsureRequestObjectDoesNotContainSubWithClientId
Request object does not contain Client Id in sub
2021-10-22 15:35:03 SUCCESS
ValidateRequestObjectSignature
Request object signature validated using a key in the client's JWKS and using the client's registered request_object_signing_alg
request_object
eyJhbGciOiJQUzI1NiIsInR5cCI6Im9hdXRoLWF1dGh6LXJlcStqd3QiLCJraWQiOiJRNjJUclRWMWhhRXpUVXMzMU1TdjV1a2h5SE5ZRjVoQmdxOGRFQllCX2RBIn0.eyJyZWRpcmVjdF91cmkiOiJodHRwczovL29wZW5pZC1jbGllbnQubG9jYWwvY2IiLCJzY29wZSI6IkFsbCB5b3VyIGJhc2UgYXJlIGJlbG9uZyB0byB1cyIsInJlc3BvbnNlX3R5cGUiOiJjb2RlIiwic3RhdGUiOiJSTHhmYUZJVDVqTjJXUDBhRy1UTWh5b1ZvMG12QXN1amlwb0prMkhzTnBnIiwiaXNzIjoiY2xpZW50LWlkLW9wZW5pZC1jbGllbnQtbko4Tk5ocE5pUHFhVVBYY2NCZzd5IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9vcGVuaWQtY2xpZW50LW5KOE5OaHBOaVBxYVVQWGNjQmc3eS8iLCJjbGllbnRfaWQiOiJjbGllbnQtaWQtb3BlbmlkLWNsaWVudC1uSjhOTmhwTmlQcWFVUFhjY0JnN3kiLCJqdGkiOiJaeVppSmRDM3JzMHdlUmFGV2FWTGNpRDRNQWVnRWdpYmpwdVptZHZQNldJIiwiaWF0IjoxNjM0OTE2OTAzLCJleHAiOjE2MzQ5MTcyMDMsIm5iZiI6MTYzNDkxNjkwM30.maA4MbBRAF0lkkyJDbo51HDSixhjxo86x6ZCFRqV2PCQjN86lFFAXF9ZnolkIb2xnKJZTie1KG3iw5JsdPvWpagZkIRBLYtCn5o-dhbeOCml9e5j-kPUyTlrMSdVtBo-1oYKaSDMWNOPHh0Drk3pMpj2q6td5c_r5qLDVJsa_hBqklomsaF-9ZQl2Fh_PsxYqf4kkNvzEyHvdh6OekE8btN-Y2Igzzju30Yw_ZU5sR9ElO42y1157Kbv6O_1xJ9ld4FqhbgZ23l1Pp2q5RcUon9dHcpFIk79Qslo3K2rTvYVkIavdLQMeSCQpterCGwqA0Kewp4OoXUy6NQahtAKng
request_object_signing_alg
PS256
jwk
Sun RSA public key, 2048 bits
  params: null
  modulus: 26151657156553405963075919618721722127995249423813475433405557575796890215256574077320333119809107817239475600027421650461216731005565735215767818143423614539716972380800209006077596540238924431492226127544232399566714085034445852774355467553543210522212906620631159039620070107874736809059841556304992146128430795704368348142145754089537715001635027138180732634633708580664108335613955890539314725212603424011727091028824543238437305928536229753156082186692056815876785027758277837939365894959639613121170012354515191508804469210977775017768497311508327661615400596331673926970452861566467546664138725217745469040769
  public exponent: 65537
2021-10-22 15:35:03 SUCCESS
EnsureMatchingRedirectUriInRequestObject
Redirect URI matched
actual
https://openid-client.local/cb
2021-10-22 15:35:03 SUCCESS
EnsureRequiredAuthorizationRequestParametersMatchRequestObject
Required http request parameters match request object claims
response_type
code
client_id
client-id-openid-client-nJ8NNhpNiPqaUPXccBg7y
2021-10-22 15:35:03 SUCCESS
EnsureOptionalAuthorizationRequestParametersMatchRequestObject
All http request parameters and request object claims match
2021-10-22 15:35:03 SUCCESS
ExtractRequestedScopes
Requested scopes
scope
All your base are belong to us
2021-10-22 15:35:03 SUCCESS
EnsureRequestedScopeIsEqualToConfiguredScope
Requested scopes match configured scopes
scope
All your base are belong to us
2021-10-22 15:35:03 SUCCESS
EnsureResponseTypeIsCode
Response type is expected value
expected
code
2021-10-22 15:35:03 SUCCESS
EnsureMatchingClientId
Client ID matched
client_id
client-id-openid-client-nJ8NNhpNiPqaUPXccBg7y
2021-10-22 15:35:03 SUCCESS
CreateAuthorizationCode
Created authorization code
authorization_code
0OBFtEZXqVMpPzbZAJzJ3GvXhkCiaXst
2021-10-22 15:35:03 SUCCESS
EnsureAuthorizationRequestContainsStateParameter
Found state parameter
state
RLxfaFIT5jN2WP0aG-TMhyoVo0mvAsujipoJk2HsNpg
2021-10-22 15:35:03 SUCCESS
CreateAuthorizationEndpointResponseParams
Added authorization_endpoint_response_params to environment
params
{
  "redirect_uri": "https://openid-client.local/cb",
  "state": "RLxfaFIT5jN2WP0aG-TMhyoVo0mvAsujipoJk2HsNpg"
}
2021-10-22 15:35:03 SUCCESS
AddCodeToAuthorizationEndpointResponseParams
Added code to authorization endpoint response params
authorization_endpoint_response_params
{
  "redirect_uri": "https://openid-client.local/cb",
  "state": "RLxfaFIT5jN2WP0aG-TMhyoVo0mvAsujipoJk2HsNpg",
  "code": "0OBFtEZXqVMpPzbZAJzJ3GvXhkCiaXst"
}
2021-10-22 15:35:03
GenerateJARMResponseClaims
Created JARM response claims
iss
https://www.certification.openid.net/test/a/openid-client-nJ8NNhpNiPqaUPXccBg7y/
aud
client-id-openid-client-nJ8NNhpNiPqaUPXccBg7y
code
0OBFtEZXqVMpPzbZAJzJ3GvXhkCiaXst
state
RLxfaFIT5jN2WP0aG-TMhyoVo0mvAsujipoJk2HsNpg
exp
1634917503
2021-10-22 15:35:03 SUCCESS
SignJARMResponse
Signed the JARM response
jarm_response
eyJraWQiOiJHRVlvU19NQW54bWFNQ21DV0VQdjJKNFJMYTJDWlhidFVwY3pxeEJPTDk4IiwiYWxnIjoiUFMyNTYifQ.eyJhdWQiOiJjbGllbnQtaWQtb3BlbmlkLWNsaWVudC1uSjhOTmhwTmlQcWFVUFhjY0JnN3kiLCJjb2RlIjoiME9CRnRFWlhxVk1wUHpiWkFKekozR3ZYaGtDaWFYc3QiLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvb3BlbmlkLWNsaWVudC1uSjhOTmhwTmlQcWFVUFhjY0JnN3lcLyIsInN0YXRlIjoiUkx4ZmFGSVQ1ak4yV1AwYUctVE1oeW9WbzBtdkFzdWppcG9KazJIc05wZyIsImV4cCI6MTYzNDkxNzUwM30.cR_PnNci0gMJAPd_3ehEpzWVhpstjeyv__q10D2wh1D_7fxABMVzyf50P-ibELiNRWcoC4ULWrAD2FgHby-6Yz2l1WijC_5me1iZfZWjBeHGNlhK8t0FrgThhTHHKn4jXLhs8CxHEmpSlFpApq1XfHA_rOmCvNyWH3DGF9kj3VoNWXWnhPXWrjL-npiF29wNgjvHKoaqI-mhvGGZq2DVqznBAPzr7QjOIOGI0NLkBYROJJ93d3ZKLVymD31TQ-76sG_iF6GVjz9DBTeZzTdoK2JvJQSmCnNtswLq6_zxeQHpYok_B5iS_CUZ1OvJsBeMscFNSzaXhpm36FFqWHyUWw
2021-10-22 15:35:03 INFO
EncryptJARMResponse
Skipped evaluation due to missing required element: client authorization_encrypted_response_alg
path
authorization_encrypted_response_alg
mapped
object
client
2021-10-22 15:35:03
SendJARMResponseWitResponseModeQuery
Redirecting back to client
uri
https://openid-client.local/cb?response=eyJraWQiOiJHRVlvU19NQW54bWFNQ21DV0VQdjJKNFJMYTJDWlhidFVwY3pxeEJPTDk4IiwiYWxnIjoiUFMyNTYifQ.eyJhdWQiOiJjbGllbnQtaWQtb3BlbmlkLWNsaWVudC1uSjhOTmhwTmlQcWFVUFhjY0JnN3kiLCJjb2RlIjoiME9CRnRFWlhxVk1wUHpiWkFKekozR3ZYaGtDaWFYc3QiLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvb3BlbmlkLWNsaWVudC1uSjhOTmhwTmlQcWFVUFhjY0JnN3lcLyIsInN0YXRlIjoiUkx4ZmFGSVQ1ak4yV1AwYUctVE1oeW9WbzBtdkFzdWppcG9KazJIc05wZyIsImV4cCI6MTYzNDkxNzUwM30.cR_PnNci0gMJAPd_3ehEpzWVhpstjeyv__q10D2wh1D_7fxABMVzyf50P-ibELiNRWcoC4ULWrAD2FgHby-6Yz2l1WijC_5me1iZfZWjBeHGNlhK8t0FrgThhTHHKn4jXLhs8CxHEmpSlFpApq1XfHA_rOmCvNyWH3DGF9kj3VoNWXWnhPXWrjL-npiF29wNgjvHKoaqI-mhvGGZq2DVqznBAPzr7QjOIOGI0NLkBYROJJ93d3ZKLVymD31TQ-76sG_iF6GVjz9DBTeZzTdoK2JvJQSmCnNtswLq6_zxeQHpYok_B5iS_CUZ1OvJsBeMscFNSzaXhpm36FFqWHyUWw
2021-10-22 15:35:03 OUTGOING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Response to HTTP request to test instance dIGcuAAjwdRiOb6
outgoing
org.springframework.web.servlet.view.RedirectView: [RedirectView]; URL [https://openid-client.local/cb?response=eyJraWQiOiJHRVlvU19NQW54bWFNQ21DV0VQdjJKNFJMYTJDWlhidFVwY3pxeEJPTDk4IiwiYWxnIjoiUFMyNTYifQ.eyJhdWQiOiJjbGllbnQtaWQtb3BlbmlkLWNsaWVudC1uSjhOTmhwTmlQcWFVUFhjY0JnN3kiLCJjb2RlIjoiME9CRnRFWlhxVk1wUHpiWkFKekozR3ZYaGtDaWFYc3QiLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvb3BlbmlkLWNsaWVudC1uSjhOTmhwTmlQcWFVUFhjY0JnN3lcLyIsInN0YXRlIjoiUkx4ZmFGSVQ1ak4yV1AwYUctVE1oeW9WbzBtdkFzdWppcG9KazJIc05wZyIsImV4cCI6MTYzNDkxNzUwM30.cR_PnNci0gMJAPd_3ehEpzWVhpstjeyv__q10D2wh1D_7fxABMVzyf50P-ibELiNRWcoC4ULWrAD2FgHby-6Yz2l1WijC_5me1iZfZWjBeHGNlhK8t0FrgThhTHHKn4jXLhs8CxHEmpSlFpApq1XfHA_rOmCvNyWH3DGF9kj3VoNWXWnhPXWrjL-npiF29wNgjvHKoaqI-mhvGGZq2DVqznBAPzr7QjOIOGI0NLkBYROJJ93d3ZKLVymD31TQ-76sG_iF6GVjz9DBTeZzTdoK2JvJQSmCnNtswLq6_zxeQHpYok_B5iS_CUZ1OvJsBeMscFNSzaXhpm36FFqWHyUWw]
outgoing_path
authorize
2021-10-22 15:35:04 INCOMING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Incoming HTTP request to test instance dIGcuAAjwdRiOb6
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "x-ssl-cipher": "ECDHE-RSA-AES128-GCM-SHA256",
  "x-ssl-protocol": "TLSv1.2",
  "connection": "close",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net"
}
incoming_path
jwks
incoming_body_form_params
incoming_method
GET
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-10-22 15:35:04 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-10-22 15:35:04 OUTGOING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Response to HTTP request to test instance dIGcuAAjwdRiOb6
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "GEYoS_MAnxmaMCmCWEPv2J4RLa2CZXbtUpczqxBOL98",
      "alg": "PS256",
      "n": "ykr3M3bqT5-pTJUgYHKPRiyvGwu1VcZWThjVspDOtHXDxcEjM-qi2E_J5mA2esJy54WwcvR9v9SdGqMWmW51gm7xJ2uH4amN3ImfbXHvusef-RiaPUgatIvFWU8jeQ61YrC9dcNdBVyfluCFVaQa0Bj-_pKTjambyLVKlzIf3BHjRU7vs_Wl3VXWavqzs_CsIlc9bVm-fmLa4tva_VgtESEbkFdfcU9qtGvb11fpmv5zCsDydsZXb08-NpmQup-11sBVKiEyM0AdH5TtXX1W5A_f6-1wa7OyFyS4q9va0kkgciuf_OuJTUwQxFtBFUIv5aDao_JqAAgyXZ2YMs96ZQ"
    }
  ]
}
outgoing_path
jwks
2021-10-22 15:35:04 INCOMING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Incoming HTTP request to test instance dIGcuAAjwdRiOb6
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "content-type": "application/x-www-form-urlencoded",
  "x-ssl-cipher": "ECDHE-RSA-AES128-GCM-SHA256",
  "x-ssl-protocol": "TLSv1.2",
  "x-ssl-cert": "-----BEGIN CERTIFICATE----- MIIDmjCCAoKgAwIBAgIJV1pBjrkdmPCLMA0GCSqGSIb3DQEBBQUAMGkxFDASBgNV BAMTC2V4YW1wbGUub3JnMQswCQYDVQQGEwJVUzERMA8GA1UECBMIVmlyZ2luaWEx EzARBgNVBAcTCkJsYWNrc2J1cmcxDTALBgNVBAoTBFRlc3QxDTALBgNVBAsTBFRl c3QwHhcNMjExMDIyMTUzNDQ5WhcNMjIxMDIyMTUzNDQ5WjBpMRQwEgYDVQQDEwtl eGFtcGxlLm9yZzELMAkGA1UEBhMCVVMxETAPBgNVBAgTCFZpcmdpbmlhMRMwEQYD VQQHEwpCbGFja3NidXJnMQ0wCwYDVQQKEwRUZXN0MQ0wCwYDVQQLEwRUZXN0MIIB IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzyk5MmQQFHvIlGDEJuCmIQfN rIhsd/nIyQpobvtu9r7T1XJtmwyhH5ZQ1222JNklS/TjxHEsYA8Q7FtRHiAlJaRM t2eFghdculQMWUpe9wiDH8oNjJxJv8wT3O1lHa48cVnpPvcnDnDB2YN27mftMYwh oiVrc/ZyRzMgi4qiQwAFC7yRTNiL2EX60c1DPmcUyB6hynPZkuA0wC3/0xRsOuMR Odan0LtpA3a7ZDVCtqaTxKG4IO6ra7bCE78VYjPV4BTT7eygwtTbzMXisXfbTd/3 gxnx6kKHJX2/lpPeS9ara1yRHO8prxDQl9eD7u1NzlKkT8dEgNcoZNt8PGXogQID AQABo0UwQzAMBgNVHRMEBTADAQH/MAsGA1UdDwQEAwIC9DAmBgNVHREEHzAdhhto dHRwOi8vZXhhbXBsZS5vcmcvd2ViaWQjbWUwDQYJKoZIhvcNAQEFBQADggEBAGB5 2WD6aqDKDz2AxlXvDgb0kzT/TjUJGQ3fzWDClbHVOffwPgr6UFk5t+GB0Mmzprhm y+FqxMqzzAmzSxLgUWJPrK/bvvMLVOn/s7zbUomXcxvN3MSNnadsQ7Sp1ooTutzC XvGsubtd5/lqwGF9w2H0SDWbSnv1B9Ydfmz1u4lQgF48OAVg8NG4ddaLHF5OcsBI jKkaZ19yTm1A3ZpX3gXBZ3EE+AQAgViS5PsxNGJmddoU1AmVx6WEveCSz24EEvVe 3QzGY3tXsPC5x0OWg/HXNTvTaopyD32OHe0eA849bH/AzCTeJoHUmmwrrmndVV2E W19RIE3TsGcYSvbhOq8\u003d -----END CERTIFICATE-----",
  "x-ssl-verify": "FAILED:self signed certificate",
  "content-length": "175",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net",
  "connection": "close"
}
incoming_path
token
incoming_body_form_params
{
  "grant_type": "authorization_code",
  "code": "0OBFtEZXqVMpPzbZAJzJ3GvXhkCiaXst",
  "redirect_uri": "https://openid-client.local/cb",
  "client_id": "client-id-openid-client-nJ8NNhpNiPqaUPXccBg7y"
}
incoming_method
POST
incoming_body_json
incoming_query_string_params
{}
incoming_body
grant_type=authorization_code&code=0OBFtEZXqVMpPzbZAJzJ3GvXhkCiaXst&redirect_uri=https%3A%2F%2Fopenid-client.local%2Fcb&client_id=client-id-openid-client-nJ8NNhpNiPqaUPXccBg7y
2021-10-22 15:35:04 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2021-10-22 15:35:04 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIDmjCCAoKgAwIBAgIJV1pBjrkdmPCLMA0GCSqGSIb3DQEBBQUAMGkxFDASBgNV BAMTC2V4YW1wbGUub3JnMQswCQYDVQQGEwJVUzERMA8GA1UECBMIVmlyZ2luaWEx EzARBgNVBAcTCkJsYWNrc2J1cmcxDTALBgNVBAoTBFRlc3QxDTALBgNVBAsTBFRl c3QwHhcNMjExMDIyMTUzNDQ5WhcNMjIxMDIyMTUzNDQ5WjBpMRQwEgYDVQQDEwtl eGFtcGxlLm9yZzELMAkGA1UEBhMCVVMxETAPBgNVBAgTCFZpcmdpbmlhMRMwEQYD VQQHEwpCbGFja3NidXJnMQ0wCwYDVQQKEwRUZXN0MQ0wCwYDVQQLEwRUZXN0MIIB IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzyk5MmQQFHvIlGDEJuCmIQfN rIhsd/nIyQpobvtu9r7T1XJtmwyhH5ZQ1222JNklS/TjxHEsYA8Q7FtRHiAlJaRM t2eFghdculQMWUpe9wiDH8oNjJxJv8wT3O1lHa48cVnpPvcnDnDB2YN27mftMYwh oiVrc/ZyRzMgi4qiQwAFC7yRTNiL2EX60c1DPmcUyB6hynPZkuA0wC3/0xRsOuMR Odan0LtpA3a7ZDVCtqaTxKG4IO6ra7bCE78VYjPV4BTT7eygwtTbzMXisXfbTd/3 gxnx6kKHJX2/lpPeS9ara1yRHO8prxDQl9eD7u1NzlKkT8dEgNcoZNt8PGXogQID AQABo0UwQzAMBgNVHRMEBTADAQH/MAsGA1UdDwQEAwIC9DAmBgNVHREEHzAdhhto dHRwOi8vZXhhbXBsZS5vcmcvd2ViaWQjbWUwDQYJKoZIhvcNAQEFBQADggEBAGB5 2WD6aqDKDz2AxlXvDgb0kzT/TjUJGQ3fzWDClbHVOffwPgr6UFk5t+GB0Mmzprhm y+FqxMqzzAmzSxLgUWJPrK/bvvMLVOn/s7zbUomXcxvN3MSNnadsQ7Sp1ooTutzC XvGsubtd5/lqwGF9w2H0SDWbSnv1B9Ydfmz1u4lQgF48OAVg8NG4ddaLHF5OcsBI jKkaZ19yTm1A3ZpX3gXBZ3EE+AQAgViS5PsxNGJmddoU1AmVx6WEveCSz24EEvVe 3QzGY3tXsPC5x0OWg/HXNTvTaopyD32OHe0eA849bH/AzCTeJoHUmmwrrmndVV2E W19RIE3TsGcYSvbhOq8\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIDmjCCAoKgAwIBAgIJV1pBjrkdmPCLMA0GCSqGSIb3DQEBBQUAMGkxFDASBgNV\nBAMTC2V4YW1wbGUub3JnMQswCQYDVQQGEwJVUzERMA8GA1UECBMIVmlyZ2luaWEx\nEzARBgNVBAcTCkJsYWNrc2J1cmcxDTALBgNVBAoTBFRlc3QxDTALBgNVBAsTBFRl\nc3QwHhcNMjExMDIyMTUzNDQ5WhcNMjIxMDIyMTUzNDQ5WjBpMRQwEgYDVQQDEwtl\neGFtcGxlLm9yZzELMAkGA1UEBhMCVVMxETAPBgNVBAgTCFZpcmdpbmlhMRMwEQYD\nVQQHEwpCbGFja3NidXJnMQ0wCwYDVQQKEwRUZXN0MQ0wCwYDVQQLEwRUZXN0MIIB\nIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzyk5MmQQFHvIlGDEJuCmIQfN\nrIhsd/nIyQpobvtu9r7T1XJtmwyhH5ZQ1222JNklS/TjxHEsYA8Q7FtRHiAlJaRM\nt2eFghdculQMWUpe9wiDH8oNjJxJv8wT3O1lHa48cVnpPvcnDnDB2YN27mftMYwh\noiVrc/ZyRzMgi4qiQwAFC7yRTNiL2EX60c1DPmcUyB6hynPZkuA0wC3/0xRsOuMR\nOdan0LtpA3a7ZDVCtqaTxKG4IO6ra7bCE78VYjPV4BTT7eygwtTbzMXisXfbTd/3\ngxnx6kKHJX2/lpPeS9ara1yRHO8prxDQl9eD7u1NzlKkT8dEgNcoZNt8PGXogQID\nAQABo0UwQzAMBgNVHRMEBTADAQH/MAsGA1UdDwQEAwIC9DAmBgNVHREEHzAdhhto\ndHRwOi8vZXhhbXBsZS5vcmcvd2ViaWQjbWUwDQYJKoZIhvcNAQEFBQADggEBAGB5\n2WD6aqDKDz2AxlXvDgb0kzT/TjUJGQ3fzWDClbHVOffwPgr6UFk5t+GB0Mmzprhm\ny+FqxMqzzAmzSxLgUWJPrK/bvvMLVOn/s7zbUomXcxvN3MSNnadsQ7Sp1ooTutzC\nXvGsubtd5/lqwGF9w2H0SDWbSnv1B9Ydfmz1u4lQgF48OAVg8NG4ddaLHF5OcsBI\njKkaZ19yTm1A3ZpX3gXBZ3EE+AQAgViS5PsxNGJmddoU1AmVx6WEveCSz24EEvVe\n3QzGY3tXsPC5x0OWg/HXNTvTaopyD32OHe0eA849bH/AzCTeJoHUmmwrrmndVV2E\nW19RIE3TsGcYSvbhOq8\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "OU\u003dTest,O\u003dTest,L\u003dBlacksburg,ST\u003dVirginia,C\u003dUS,CN\u003dexample.org"
  },
  "sanDnsNames": [],
  "sanUris": [
    "http://example.org/webid#me"
  ],
  "sanIPs": [],
  "sanEmails": []
}
2021-10-22 15:35:04 SUCCESS
CheckForClientCertificate
Found client certificate
2021-10-22 15:35:04 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIDmjCCAoKgAwIBAgIJV1pBjrkdmPCLMA0GCSqGSIb3DQEBBQUAMGkxFDASBgNV
BAMTC2V4YW1wbGUub3JnMQswCQYDVQQGEwJVUzERMA8GA1UECBMIVmlyZ2luaWEx
EzARBgNVBAcTCkJsYWNrc2J1cmcxDTALBgNVBAoTBFRlc3QxDTALBgNVBAsTBFRl
c3QwHhcNMjExMDIyMTUzNDQ5WhcNMjIxMDIyMTUzNDQ5WjBpMRQwEgYDVQQDEwtl
eGFtcGxlLm9yZzELMAkGA1UEBhMCVVMxETAPBgNVBAgTCFZpcmdpbmlhMRMwEQYD
VQQHEwpCbGFja3NidXJnMQ0wCwYDVQQKEwRUZXN0MQ0wCwYDVQQLEwRUZXN0MIIB
IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzyk5MmQQFHvIlGDEJuCmIQfN
rIhsd/nIyQpobvtu9r7T1XJtmwyhH5ZQ1222JNklS/TjxHEsYA8Q7FtRHiAlJaRM
t2eFghdculQMWUpe9wiDH8oNjJxJv8wT3O1lHa48cVnpPvcnDnDB2YN27mftMYwh
oiVrc/ZyRzMgi4qiQwAFC7yRTNiL2EX60c1DPmcUyB6hynPZkuA0wC3/0xRsOuMR
Odan0LtpA3a7ZDVCtqaTxKG4IO6ra7bCE78VYjPV4BTT7eygwtTbzMXisXfbTd/3
gxnx6kKHJX2/lpPeS9ara1yRHO8prxDQl9eD7u1NzlKkT8dEgNcoZNt8PGXogQID
AQABo0UwQzAMBgNVHRMEBTADAQH/MAsGA1UdDwQEAwIC9DAmBgNVHREEHzAdhhto
dHRwOi8vZXhhbXBsZS5vcmcvd2ViaWQjbWUwDQYJKoZIhvcNAQEFBQADggEBAGB5
2WD6aqDKDz2AxlXvDgb0kzT/TjUJGQ3fzWDClbHVOffwPgr6UFk5t+GB0Mmzprhm
y+FqxMqzzAmzSxLgUWJPrK/bvvMLVOn/s7zbUomXcxvN3MSNnadsQ7Sp1ooTutzC
XvGsubtd5/lqwGF9w2H0SDWbSnv1B9Ydfmz1u4lQgF48OAVg8NG4ddaLHF5OcsBI
jKkaZ19yTm1A3ZpX3gXBZ3EE+AQAgViS5PsxNGJmddoU1AmVx6WEveCSz24EEvVe
3QzGY3tXsPC5x0OWg/HXNTvTaopyD32OHe0eA849bH/AzCTeJoHUmmwrrmndVV2E
W19RIE3TsGcYSvbhOq8=
-----END CERTIFICATE-----
2021-10-22 15:35:04 SUCCESS
EnsureNoClientAssertionSentToTokenEndpoint
Client did not send a client_assertion to token endpoint
2021-10-22 15:35:04 SUCCESS
ValidateAuthorizationCode
Found authorization code
authorization_code
0OBFtEZXqVMpPzbZAJzJ3GvXhkCiaXst
2021-10-22 15:35:04 SUCCESS
ValidateRedirectUri
Found redirect uri
redirect_uri
https://openid-client.local/cb
2021-10-22 15:35:04 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
8Bs8aEOQoHE3r36mNsMBWRss8MAMkY7O9IPF8OnCJgwD8HMRpk
2021-10-22 15:35:04 SUCCESS
CalculateAtHash
Successful at_hash encoding
at_hash
vsIeZ0QODStM97CqHezvUQ
2021-10-22 15:35:04
CreateRefreshToken
Created refresh token
refresh_token
IlHJBuLdfKrsESDOqMVtOPNcrhxTJAanURcCuOxBJFCmIjZhqa8720665478?\'@#
2021-10-22 15:35:04 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
8Bs8aEOQoHE3r36mNsMBWRss8MAMkY7O9IPF8OnCJgwD8HMRpk
token_type
Bearer
refresh_token
IlHJBuLdfKrsESDOqMVtOPNcrhxTJAanURcCuOxBJFCmIjZhqa8720665478?\'@#
scope
All your base are belong to us 8ddafacc-02ca-47d5-a608-13131b5e3b66
2021-10-22 15:35:04 OUTGOING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Response to HTTP request to test instance dIGcuAAjwdRiOb6
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "8Bs8aEOQoHE3r36mNsMBWRss8MAMkY7O9IPF8OnCJgwD8HMRpk",
  "token_type": "Bearer",
  "refresh_token": "IlHJBuLdfKrsESDOqMVtOPNcrhxTJAanURcCuOxBJFCmIjZhqa8720665478?\\\u0027@#",
  "scope": "All your base are belong to us 8ddafacc-02ca-47d5-a608-13131b5e3b66"
}
outgoing_path
token
2021-10-22 15:35:09 FINISHED
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Test has run to completion
testmodule_result
PASSED
Test Results