Test Summary

Test Results

Expand All Collapse All
All times are UTC
2021-05-31 18:32:44 INFO
TEST-RUNNER
Test instance p9vhGTfdN5ntu3m created
baseUrl
https://www.certification.openid.net/test/a/Intuit_pauth_openid_hybrid_profile_plan_1
variant
{
  "client_auth_type": "client_secret_basic",
  "response_type": "code token",
  "request_type": "plain_http_request",
  "response_mode": "default",
  "client_registration": "static_client"
}
alias
Intuit_pauth_openid_hybrid_profile_plan_1
description
Test plan for OpenId with hybrid profile on Intuit PartnerAuth
planId
QIDfM7mwIPnrS
config
{
  "alias": "Intuit_pauth_openid_hybrid_profile_plan_1",
  "description": "Test plan for OpenId with hybrid profile on Intuit PartnerAuth",
  "client": {
    "client_secret_jwt_alg": "RS256",
    "client_id": "12345678-hybrid-profile-plain-private-key-clientid",
    "client_secret": "secret-hybrid-profile-plain-private-key-clientid",
    "redirect_uri": "https://partnerauth-e2e.platform.intuit.com/external_partner/openid_core_cert/callback",
    "scope": "openid accounts",
    "jwks": {
      "keys": [
        {
          "kty": "RSA",
          "e": "AQAB",
          "use": "sig",
          "kid": "keyid-to-fapi-plain-pauth",
          "alg": "PS256",
          "n": "urjyW-QSZIGGSe9kCUOnucEoQS28VhyL44VtyXhy0iuFgXnTRJxY6WnZP1yOcawCVRTdMkn6gGzZ2Mr7Lo1529gO6WyWV1Pl2CgjnUE4PNaIRSo_LpKVXZd7IycbRxg_UxrWo2rkpmUL5PzMYq9sGl7VfN-UpB7XcwMu7qRZd0LH_xWMThfuYHZRUxVt7V4Kw5xOID8wK8tSUbqf1kk9tAxyY8BHpFD3-bYQpHEYAx7OwdwW0UdBksItQNqOUdhB9kG89onYDe8uZvyxQqu8lpul_3snscIcDq0bxD83hVqL8E7SU7996poGWSKcoAWnBhUIzbPOcyfGFFw_RDK-Cw"
        }
      ]
    },
    "certificate": "-----BEGIN CERTIFICATE-----\nMIIFTTCCBDWgAwIBAgIQWSl/rqAik/ZS2bkCLQ7ZGzANBgkqhkiG9w0BAQsFADCB\nsDELMAkGA1UEBhMCQVUxNzA1BgNVBAoTLkF1c3RyYWxpYW4gQ29tcGV0aXRpb24g\nYW5kIENvbnN1bWVyIENvbW1pc3Npb24xHDAaBgNVBAsTE0NvbnN1bWVyIERhdGEg\nUmlnaHQxHzAdBgNVBAsTFkZvciBURVNUIFB1cnBvc2VzIE9OTFkxKTAnBgNVBAMT\nIENEUiBURVNUIEJhbmtpbmcgSW50ZXJtZWRpYXRlIENBMB4XDTIwMTExOTAwMDAw\nMFoXDTIxMTExOTIzNTk1OVowgZQxHDAaBgNVBAsME0NvbnN1bWVyIERhdGEgUmln\naHQxHzAdBgNVBAsMFkZvciBURVNUIFB1cnBvc2VzIE9OTFkxJTAjBgNVBAoMHElu\ndHVpdCBBdXN0cmFsaWEgUHR5IExpbWl0ZWQxLDAqBgNVBAMMI3BhcnRuZXJhdXRo\nLWUyZS5wbGF0Zm9ybS5pbnR1aXQuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A\nMIIBCgKCAQEAwkTTIUXBivenAAstBtWlNK/WJh62pQhVvmV5v/s30fTtp9Yaos8F\nQyP2kJUy0h/L5asdC0IIDonrLBDwi7zVCm/VsNr4Gx0DPng5yYSLRdNaxPk4S8ax\nPY8wwYYjeJuaV/DrvYneu40DZiJWTE8N3SpKZ+OSfxJlFtda2ejkfhNk0a0amIMr\nQ2YfanI/nVwk7/WWDfwqc2jMuI3WPZHt165+TDPb1qG1cXm5PoPJpD3srITvfJue\ns6nfI14wtGZu0IVlT9go7bJcMRNBb/C4EpDyfl3v3MExsqMe0TI5e7kTMgy5rjDG\n4s75GVaHpiWRw956sda8obv5Kb9gflpeYwIDAQABo4IBezCCAXcwDAYDVR0TAQH/\nBAIwADAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwIwHQYDVR0O\nBBYEFHVsct+KfWyMwdYa3jLcQw7NplPwMC4GCmCGSAGG+EUBEAMEIDAeBhNghkgB\nhvhFARABAwEEAYL4tIwYFgcxMTMwMjIwMDkGCmCGSAGG+EUBEAUEKzApAgEAFiRh\nSFIwY0hNNkx5OXdhMmt0Y21FdWMzbHRZWFYwYUM1amIyMD0wXQYDVR0fBFYwVDBS\noFCgToZMaHR0cDovL3BraS1jcmwuc3ltYXV0aC5jb20vY2FfZGY1ZDQ5M2Q1YjQ3\nODQ5MjZjZGZlNmFkZTllMDAzZmMvTGF0ZXN0Q1JMLmNybDA4BggrBgEFBQcBAQQs\nMCowKAYIKwYBBQUHMAGGHGh0dHA6Ly9wa2ktb2NzcC5kaWdpY2VydC5jb20wHwYD\nVR0jBBgwFoAUSTaRAgiZKmzkKWCekX67k63mXkswDQYJKoZIhvcNAQELBQADggEB\nAEnEvI5UJ2txz4oYJCqMCMNoHvapyW3dG7K+Lrjh+V+pwwASbGpX8KiyO7J+iWp/\n/ceQDMdTP0UFM1j5L8EePQ0hWOkJvWsVmo6GgS7zYPu+6id73P3cgLwqAWRrLBSk\nsNfdUQPY4lVaSiMDf3VzzqjMzdTGbNAzZmeJEszKI5fUEt+T47mtu2jFcMq9o1vw\ndxLjJ7BP1MIWsPNCzYazma2+Nfe3v/CzvsroyLiNywwaZn4D4r5VOofNrVM8UXpr\nRhn5pCEvDbbgr8Rd3k5zFq6LTbP1H6K47rs9MY+Edb/Uel/qhlx3RQBCy4ryR8Q6\nofDMEAPI9RcppT6elKQQ69M\u003d\n-----END CERTIFICATE-----\n-----BEGIN CERTIFICATE-----\nMIIFtzCCA5+gAwIBAgIQGhoSP4DqnQoUsNkehM6x2TANBgkqhkiG9w0BAQsFADCB\noDELMAkGA1UEBhMCQVUxNzA1BgNVBAoTLkF1c3RyYWxpYW4gQ29tcGV0aXRpb24g\nYW5kIENvbnN1bWVyIENvbW1pc3Npb24xHDAaBgNVBAsTE0NvbnN1bWVyIERhdGEg\nUmlnaHQxHzAdBgNVBAsTFkZvciBURVNUIFB1cnBvc2VzIE9OTFkxGTAXBgNVBAMT\nEENEUiBURVNUIFJvb3QgQ0EwHhcNMTkxMDE3MDAwMDAwWhcNMzQxMDE2MjM1OTU5\nWjCBsDELMAkGA1UEBhMCQVUxNzA1BgNVBAoTLkF1c3RyYWxpYW4gQ29tcGV0aXRp\nb24gYW5kIENvbnN1bWVyIENvbW1pc3Npb24xHDAaBgNVBAsTE0NvbnN1bWVyIERh\ndGEgUmlnaHQxHzAdBgNVBAsTFkZvciBURVNUIFB1cnBvc2VzIE9OTFkxKTAnBgNV\nBAMTIENEUiBURVNUIEJhbmtpbmcgSW50ZXJtZWRpYXRlIENBMIIBIjANBgkqhkiG\n9w0BAQEFAAOCAQ8AMIIBCgKCAQEAq6+NlPtZ4TPJrMRbvj7HkXBkEStfc1s+L8qd\nFX8BRnt/H9Ca+9BTLEiKj+jJ6J74yTLrK9g4y+hhaQZFFperMF0TUy+fU3nby6D8\njo6fMLr0O/W8MZ2LTk/6n1+FiZqUH8st3Nle9f4DdLY6BAR8HjCnikNYaxutBTYt\nGjkxOqogGFdwG+X0S0spKGDTq5UAp3Wc7D/fZRSeAfdTYO5FV9zhdTT6sbnrosQi\nobBuwqwLqZeeju6V5fogkhMu4tVE3GmiK/T5mGrBqqO2DIfI4t+1D/SBo4jZP2V/\nEl2CSRgKrlVMcWoOE3h9Aa20vliLsJgv/Zf9gH/5UhHV5KlegQIDAQABo4HaMIHX\nMCgGA1UdEQQhMB+kHTAbMRkwFwYDVQQDExBEaWdpQ2VydFBLSS0zLTY5MB0GA1Ud\nDgQWBBRJNpECCJkqbOQpYJ6RfruTreZeSzASBgNVHRMBAf8ECDAGAQH/AgEAMEcG\nA1UdHwRAMD4wPKA6oDiGNmh0dHA6Ly9jcmwuYXUuZGlnaWNlcnQuY29tL0NBL0FD\nQ0NfQ0RSX1RFU1RfUm9vdENBLmNybDAOBgNVHQ8BAf8EBAMCAQYwHwYDVR0jBBgw\nFoAU/shndz73CkDs3XVqioe1JoHU24wwDQYJKoZIhvcNAQELBQADggIBADQAYy6W\nKMFMyyOkW23kFMLu/ki66DfvusaNR++4tXUs4j6TSipEJ4weyKpMNcro+InGCaY3\n0X2fIzTa/L0PJlpo/cLuuGRpnx41I5dPjnltmwmZSXEJEYlIn0aQNy1luHfR76s+\nA44/DiquHVlI4t4fLcsuDUtVHcTlN59qY40GuWL/00y4IGWNbrXSSDLkRqWdeBF4\nA8XRoTLMmNuw4Mcm9Zpggc2K40GtFxCbxsDaw6NVZgGODnnSdmw5/gExWH1RIjYU\nJ7whYsnIIPxy8HmogGOhrvB36EtvS/BOeNwSyBNVoSTDoVLDeMxgO/9shH0Ytaew\nzsXAnfW5wUZiiAyqZOqN7gUZpo+aaZrC8sBo36B1RdLzEszs0GY3ohl/rUixr5jY\nnbC4mYTte4DNA6HSadBnHAmnyLX5oQvK+pE9eSaZVNvg09pDSPjRkuhYxPO5tHkr\nzrjAk3PNXKDddnSdMSXILbkPAEssBuC4vax1kd5o8grSFvidUQMr61paT5o17lxh\nY7z1Fav5bW65JFid1oR6OiEn+o3DNaYf22eaYJsZRcJ7Fio8CPoJnSq5NJC57KHq\nNYHMCwMdJkob2NNXJSmKA3FRxX2zhj6iehQT9p+N5HEngGJMGAv90MhIIWZcHuK5\nm/Egr0D/nA9GtlPyS0m2GkCkNqzyD2cyOilg\n-----END CERTIFICATE-----"
  },
  "server": {
    "jwks": {
      "keys": [
        {
          "p": "0X5a2vAXxfvavrqVOd9EaRGuZzbyQx4GjkI70K8CmW_SpGlNnfiMi-j9pfltfhOezBtbAnLzxikdlMiaIZGX0sfGs7z6l6Iq4fCbKgwGYjDjDj_oRGuZjB7NM_AHIsknjoxaoZrJAZz5xrdttimdkmA5psiSCDGAYLXQr8KAsL0",
          "kty": "RSA",
          "q": "wGy6Gz0YO3bWMpAdxG_iZkFkgvfAgRExE0zUnPKcOgjq3Ue1VeIdUV1639bTpXI80KNaAwKHeFp5M05lrZEzfSeM5HH9yYG0GgfmXx-RFrGa8DZpFQXmcunPu3Opl0cdxADPETZpfSYJ8npo5cBEJTokR7kXtU2eOCG5UGKuggs",
          "d": "RmA_szTS9cQdt5kuz529dvsOA9vrWDpFocU07Uk09JcFnlebXif-Ovr8apA44Yj0EnIUaT0eplNMM5O3yCd9K2Dobvkop30C1dLjUsEHOwn89rxMmxTg6qrnDMkMbWU-lKbTRjZ7F4L8j2ZHqh0nSmhGOawdDVjqDepgPy9cv0AtonAEDRVZiaUiOwie4vFYVy7ksoNvAsCs6Pl4bLaYXDoP7SmWUWeenODHyoMsUt0Z45-3ti_-di0qm7yQNgZ8NWLZNAd5T73qZm5zOwkRO6Tu8ZiWBeAV7t-wteKAaQ-KVLnLik4fRUUVWtS80prbz4b-I9kvNagmtef-GveqcQ",
          "e": "AQAB",
          "qi": "Sbg51OpF8E4zYaRAUjMrQ_DB6My9fZiJhQXF9nrJML1TF30k7SN8pHJ-N86WUweyvRTOm9wRb6CWHrwlpgBX1syaMAMOQPnHxv84e8emQQLl_mO0OUldb4Z53RM9z0DXoyKrgCsGS6B3D9GAX8AUFrsYJQDGNg5ib85aTqGhQG0",
          "dp": "cJyogDpBvUZ2PsKThulyn7xGcOtDbTrNsVj_SF1bW1mV9JU6iOlbu7XB659Z8UTgvr0Rvg5G5kWhxiHTYKof38lOEb5LQomE3bF15zNRlyTKWRWXaHgisQS5r-qeG1_gKKtf6LEIzhow1lYx3pMeRdn-A56biVX6uYHirSgz_00",
          "alg": "PS256",
          "dq": "qENrSj5WXklAbN6Q6SFdPEWaetvivfomi9X3ZXbRHf6GQhFehEdBk9DGjc3xLQ-EFn2BTHh9tcSHj1HSn8AE4kAfd_QmFHsS3mBiFnQoD0wnTD6IDRYnufyy5hvyBJLveGGssESAYitNL3fTGnTSIiuBZiZ4kNXasQLsZVqldpk",
          "n": "nXe9vqDEtjUQ3bYdMv67vtZ1Nr95Fnn1lQKO6ASiaIhL133AUSNmsC2De7_Fs2rEQ6r3KpzwEg6H4e7dFzCo0MTK11ZMHXyIcQsKRnviG_G8bV5EECoylY959TKvqgLd16rnqK70doAG34dglR1cn-gXpoVdM1tmTWgmQryT3y-jdNvtba9SE3-79e1FsfhbtsZ0YIS8gx7OVypPuVml7MvOkDbP8M-EaNB9YbwIdq4MK9DugaCxXI1U4naoXp47f8sl2iBeaAUuG4JWQ1Ct1sgiJOzRA1ts9WYYdu3pImXCviTb2C-6xD3DgeG5OPFQNcHG0ODQCHmEAX-DL72SHw"
        }
      ]
    }
  }
}
testName
oidcc-client-test-invalid-sig-rs256
2021-05-31 18:32:44 SUCCESS
OIDCCGenerateServerConfigurationIdTokenSigningAlgRS256Only
Generated default server configuration
server_configuration
{
  "issuer": "https://www.certification.openid.net/test/a/Intuit_pauth_openid_hybrid_profile_plan_1/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/Intuit_pauth_openid_hybrid_profile_plan_1/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/Intuit_pauth_openid_hybrid_profile_plan_1/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/Intuit_pauth_openid_hybrid_profile_plan_1/jwks",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/Intuit_pauth_openid_hybrid_profile_plan_1/userinfo",
  "registration_endpoint": "https://www.certification.openid.net/test/a/Intuit_pauth_openid_hybrid_profile_plan_1/register",
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access"
  ],
  "response_types_supported": [
    "code",
    "id_token code",
    "token code id_token",
    "id_token",
    "token id_token",
    "token code",
    "token"
  ],
  "response_modes_supported": [
    "query",
    "fragment",
    "form_post"
  ],
  "token_endpoint_auth_methods_supported": [
    "client_secret_basic",
    "client_secret_post",
    "client_secret_jwt",
    "private_key_jwt"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "RS256",
    "RS384",
    "RS512",
    "PS256",
    "PS384",
    "PS512",
    "ES256",
    "ES256K",
    "ES384",
    "ES512",
    "EdDSA"
  ],
  "grant_types_supported": [
    "authorization_code",
    "implicit"
  ],
  "claims_parameter_supported": true,
  "acr_values_supported": [
    "PASSWORD"
  ],
  "subject_types_supported": [
    "public",
    "pairwise"
  ],
  "claim_types_supported": [
    "normal",
    "aggregated",
    "distributed"
  ],
  "claims_supported": [
    "sub",
    "name",
    "given_name",
    "family_name",
    "middle_name",
    "nickname",
    "gender",
    "birthdate",
    "preferred_username",
    "profile",
    "website",
    "locale",
    "updated_at",
    "address",
    "zoneinfo",
    "phone_number",
    "phone_number_verified",
    "email",
    "email_verified"
  ],
  "id_token_signing_alg_values_supported": [
    "RS256"
  ],
  "id_token_encryption_alg_values_supported": [
    "RSA1_5",
    "RSA-OAEP",
    "RSA-OAEP-256",
    "ECDH-ES",
    "ECDH-ES+A128KW",
    "ECDH-ES+A192KW",
    "ECDH-ES+A256KW",
    "A128KW",
    "A192KW",
    "A256KW",
    "A128GCMKW",
    "A192GCMKW",
    "A256GCMKW",
    "dir"
  ],
  "id_token_encryption_enc_values_supported": [
    "A128CBC-HS256",
    "A192CBC-HS384",
    "A256CBC-HS512",
    "A128GCM",
    "A192GCM",
    "A256GCM"
  ],
  "request_object_signing_alg_values_supported": [
    "none",
    "RS256",
    "RS384",
    "RS512",
    "PS256",
    "PS384",
    "PS512",
    "ES256",
    "ES256K",
    "ES384",
    "ES512",
    "EdDSA"
  ],
  "request_object_encryption_alg_values_supported": [
    "RSA1_5",
    "RSA-OAEP",
    "RSA-OAEP-256",
    "ECDH-ES",
    "ECDH-ES+A128KW",
    "ECDH-ES+A192KW",
    "ECDH-ES+A256KW",
    "A128KW",
    "A192KW",
    "A256KW",
    "A128GCMKW",
    "A192GCMKW",
    "A256GCMKW",
    "dir"
  ],
  "request_object_encryption_enc_values_supported": [
    "A128CBC-HS256",
    "A192CBC-HS384",
    "A256CBC-HS512",
    "A128GCM",
    "A192GCM",
    "A256GCM"
  ],
  "userinfo_signing_alg_values_supported": [
    "RS256",
    "RS384",
    "RS512",
    "PS256",
    "PS384",
    "PS512",
    "ES256",
    "ES256K",
    "ES384",
    "ES512",
    "EdDSA"
  ],
  "userinfo_encryption_alg_values_supported": [
    "RSA1_5",
    "RSA-OAEP",
    "RSA-OAEP-256",
    "ECDH-ES",
    "ECDH-ES+A128KW",
    "ECDH-ES+A192KW",
    "ECDH-ES+A256KW",
    "A128KW",
    "A192KW",
    "A256KW",
    "A128GCMKW",
    "A192GCMKW",
    "A256GCMKW",
    "dir"
  ],
  "userinfo_encryption_enc_values_supported": [
    "A128CBC-HS256",
    "A192CBC-HS384",
    "A256CBC-HS512",
    "A128GCM",
    "A192GCM",
    "A256GCM"
  ]
}
2021-05-31 18:32:44
SetTokenEndpointAuthMethodsSupportedToClientSecretBasicOnly
Changed token_endpoint_auth_methods_supported to client_secret_basic only in server configuration
server_configuration
{
  "issuer": "https://www.certification.openid.net/test/a/Intuit_pauth_openid_hybrid_profile_plan_1/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/Intuit_pauth_openid_hybrid_profile_plan_1/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/Intuit_pauth_openid_hybrid_profile_plan_1/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/Intuit_pauth_openid_hybrid_profile_plan_1/jwks",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/Intuit_pauth_openid_hybrid_profile_plan_1/userinfo",
  "registration_endpoint": "https://www.certification.openid.net/test/a/Intuit_pauth_openid_hybrid_profile_plan_1/register",
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access"
  ],
  "response_types_supported": [
    "code",
    "id_token code",
    "token code id_token",
    "id_token",
    "token id_token",
    "token code",
    "token"
  ],
  "response_modes_supported": [
    "query",
    "fragment",
    "form_post"
  ],
  "token_endpoint_auth_methods_supported": [
    "client_secret_basic"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "RS256",
    "RS384",
    "RS512",
    "PS256",
    "PS384",
    "PS512",
    "ES256",
    "ES256K",
    "ES384",
    "ES512",
    "EdDSA"
  ],
  "grant_types_supported": [
    "authorization_code",
    "implicit"
  ],
  "claims_parameter_supported": true,
  "acr_values_supported": [
    "PASSWORD"
  ],
  "subject_types_supported": [
    "public",
    "pairwise"
  ],
  "claim_types_supported": [
    "normal",
    "aggregated",
    "distributed"
  ],
  "claims_supported": [
    "sub",
    "name",
    "given_name",
    "family_name",
    "middle_name",
    "nickname",
    "gender",
    "birthdate",
    "preferred_username",
    "profile",
    "website",
    "locale",
    "updated_at",
    "address",
    "zoneinfo",
    "phone_number",
    "phone_number_verified",
    "email",
    "email_verified"
  ],
  "id_token_signing_alg_values_supported": [
    "RS256"
  ],
  "id_token_encryption_alg_values_supported": [
    "RSA1_5",
    "RSA-OAEP",
    "RSA-OAEP-256",
    "ECDH-ES",
    "ECDH-ES+A128KW",
    "ECDH-ES+A192KW",
    "ECDH-ES+A256KW",
    "A128KW",
    "A192KW",
    "A256KW",
    "A128GCMKW",
    "A192GCMKW",
    "A256GCMKW",
    "dir"
  ],
  "id_token_encryption_enc_values_supported": [
    "A128CBC-HS256",
    "A192CBC-HS384",
    "A256CBC-HS512",
    "A128GCM",
    "A192GCM",
    "A256GCM"
  ],
  "request_object_signing_alg_values_supported": [
    "none",
    "RS256",
    "RS384",
    "RS512",
    "PS256",
    "PS384",
    "PS512",
    "ES256",
    "ES256K",
    "ES384",
    "ES512",
    "EdDSA"
  ],
  "request_object_encryption_alg_values_supported": [
    "RSA1_5",
    "RSA-OAEP",
    "RSA-OAEP-256",
    "ECDH-ES",
    "ECDH-ES+A128KW",
    "ECDH-ES+A192KW",
    "ECDH-ES+A256KW",
    "A128KW",
    "A192KW",
    "A256KW",
    "A128GCMKW",
    "A192GCMKW",
    "A256GCMKW",
    "dir"
  ],
  "request_object_encryption_enc_values_supported": [
    "A128CBC-HS256",
    "A192CBC-HS384",
    "A256CBC-HS512",
    "A128GCM",
    "A192GCM",
    "A256GCM"
  ],
  "userinfo_signing_alg_values_supported": [
    "RS256",
    "RS384",
    "RS512",
    "PS256",
    "PS384",
    "PS512",
    "ES256",
    "ES256K",
    "ES384",
    "ES512",
    "EdDSA"
  ],
  "userinfo_encryption_alg_values_supported": [
    "RSA1_5",
    "RSA-OAEP",
    "RSA-OAEP-256",
    "ECDH-ES",
    "ECDH-ES+A128KW",
    "ECDH-ES+A192KW",
    "ECDH-ES+A256KW",
    "A128KW",
    "A192KW",
    "A256KW",
    "A128GCMKW",
    "A192GCMKW",
    "A256GCMKW",
    "dir"
  ],
  "userinfo_encryption_enc_values_supported": [
    "A128CBC-HS256",
    "A192CBC-HS384",
    "A256CBC-HS512",
    "A128GCM",
    "A192GCM",
    "A256GCM"
  ]
}
2021-05-31 18:32:44
OIDCCGenerateServerJWKs
Generated server public private JWK sets
server_jwks
{
  "keys": [
    {
      "p": "6lPqKVVeQ0Q7UcMyWzncquphqWgf36RXKwiDNredWv6IlM-ljALMfEAkIluA_E1pmwSQPRdbZs7SHRPG2mYi69BCORaPyzowxTfg3D67mGTtCuV3z4FjGK1ZbZgMwOii_y8C-ENmDYJGktdRiDs6udqAton53CdrRFNJ7UtzDTs",
      "kty": "RSA",
      "q": "zw6BQxDih66ObMR8Lw4R7brdotKGhpO2iaOAbXEX2oSqMSmQ5bj2lv3ijhsRDZJW-Sf_m-xtzZHOgpHxuejpFRILuOm1NCkHnUW5zYyRF_BO2YyLC7sfxepzmYTmP6wKMwyPQhzzNZBrLFLxXZgZH2vietaAZlDjrzDX08-KhGM",
      "d": "j4UwrI8rGb4y_gPDT3zgfaqjD9ZlMn8bU0b8mBQq5mHzYi-wnTdrnD9QOZbSjKlAbSn05Oa61jkBWZOI0CiQNxJq3EtyVGy-wOVYHgGympYIAftREGzUQhR54VqQQF4bOEIegfuLwmaeJczeuQumUyQkP50F0sT6750V7G1d7coi8fIn_fOeZZOJCeP4jkby0IevRhkibnbm6xPk9WFUeR1odRRFCIGWQa1mDwKrz1Wbvxo3r4tkqYpbg_U_QQeNlQDMfLJqgeBv5F8kLyMdoS7VqZOPKCMr7SDDJ9uRnWSWrmzCqmcDtIrw8-VvBWVYVmY8edQpjlCGNwNZBsOAsQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "4b0f0a50-b91b-4a6e-b5d8-8fcdcd1beaa0",
      "qi": "F34XN3uJvS3vVsn-wT7FYMIR59JzKQuxFo7rMVaQ8V3ZpNoL3CV9-Md_zpXDU1OLDvKEsYS2BKVUhdMo0qQriUhILBKKZNIHMc0dCpnt007HrsGco2q7_eD4A3QMcvgcwwkXPT5UuEvxvO7Ted831ax1w5zjh7nt-BO-hC46M3A",
      "dp": "1uUaC8n0Zm_-jp8aYTsROdU0ty18fZazMg3ed6GwNzDShNZhFaPDb_dKrA-KnNdJkBaBSOVQt1nYqz3l0Yh1YhldgglE2bWF4He8SX9mfv2fvaxvUedwv8LKDo2wtIEkai3s5Uy6HI1qt2Orq-nVk3flLoIemF22K7TOSUY2Pt0",
      "dq": "cZiAnD3AOjYvF0c45kvu1CEoBXNAsMaLZ7nW9LQOJSmRgcVPJGk0iCQjzljVIz_9DVa_aljs6NIsnP_awWchsRika790VXiJH-SoCjgrRhnl-H6drkLsLJXy8--wrpABTH6AfgIKAIIJ-lhK6VFPvyheKYxTB08riureDeuYEAc",
      "n": "vYchP-azmUsG-ai6IY0SO4XvlqcdvMxX1BqTRvZruFgdPQd2kJmPEjF2AfnUz7dwAtwWcYDFvGIW6qDUdjIkMHYInkAUogJzfoZ0BNZtNvNIUg5V2s67DsxKzlEZFbf3XeOvOGboh3NdY7Ixl5tOIgRJ4ykxIJhDdDqLkqjLVsVf-thWTS5uRND1drnr_gUsyptXxb4cJH_17OE-0FNf3XWCni5twVNxBI9dRV0BHXlzSbTg7TAAd-WgplLE_rbnV7NocfRblGJsoDjiR6ItajMzH4EIu1DvzYi7eUxaXLWNnQqBo-QNy4W4-BKBr11-V3w8dRf_60S4QRoEVx6J0Q"
    },
    {
      "kty": "EC",
      "d": "TasiIyN2a3R39XKPj5miokX9rD15xXFdYoCMdHS8k4E",
      "use": "sig",
      "crv": "P-256",
      "kid": "1ac1c00f-ff9a-4702-8e07-a1c21faaabba",
      "x": "OMV0raVikFEFpGQ-L4pcpCWmPzo9UVfdXPS_AWlkZPo",
      "y": "w7EGozWB-nQQaZkv5bpwHPMBpR_IMV1HvXgETPjwfC0"
    },
    {
      "kty": "EC",
      "d": "m-o-1UrdKbFfj78p4XVwqdGhxWlK2TPoq0HBjZdnZQw",
      "use": "sig",
      "crv": "secp256k1",
      "kid": "eb4cd94d-33c1-492e-b839-b9a2808fdbff",
      "x": "l-ZynPiJ0TGd0vVjQJgUWOgDX3cC_pwdn6q9mtDuJ8E",
      "y": "YxrAtsf9fV_0b9lEh0x6RN1gEus3BkV4azaQAS3buBk"
    },
    {
      "kty": "OKP",
      "d": "aAG2fCMcQ56zs92-OxoPkVf6Hce1yJkUgO8AJwgCid4",
      "use": "sig",
      "crv": "Ed25519",
      "kid": "36e68b06-5f63-4ac6-8167-73e67b524ef3",
      "x": "IqgUE6wgdxedrPrl5KtQIOH6sHGReyO7dQYvGe5RFHE"
    }
  ]
}
server_encryption_keys
{
  "keys": [
    {
      "p": "yCAlBC4sazo_roXqr0eg-p1kInraYUTm_6mouQhbVrc5hYSMKuRHQ1_o0y0C_Y51wR8c-3IWvIGxnNYllQtO5xz4Cf3_nJUPCGybyq_AhXm53W7PitfH_2NU__LNTg8egniOuZOSEzGpa9dfR6UmCqtnRxswK6g_Wux7iWM_ez0",
      "kty": "RSA",
      "q": "vH5_agjPzDQRT8Q8fVy95n7OPhRKmFMOQEZ7rLNITn7JPIGM2aAq-Zz3-Y2UQjaONGBzyUGng4bzk7EfnwXohgrwMwaA80YvyvG-ZwP5H11FoQTjJ4kOGxMWc-aQ6-yh17xiA2iSnvJfuVurdAHoC2CaGsCm8-3V68Wisdndgcc",
      "d": "dOolcP1CJ8iF145KHwMmX6d7h6YIV28kecVLU1S7cMSQOVEt3xPNl_QgoISM26FiWaMFmnRkxx5F1ZHO9wTuhd74fRRASRBzo8bU0bj1_Cy-kQMDx_HfTIxD5-o7u7bJDiXnjgTOoC82qP0pE5O2W62SOANhqgQzl6LGfIyKT7NQcnUZH0aC2XqTxm4NoSAafYmbnuqtbo4j8HVPfllm4kHIGBpKqDFMiKWOYVleQGOE0Vl_3_x-4wBfEjopsv8GiU8i_bJftHEnXou55mergQy_JzCmM03ldbgZlbdAlR6scvYiWQTG-YySRbtgUufAAKow1bpTMJ-sX2Q-QZB4mQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "c576d748-464e-4fb6-b153-deb5d8b7b306",
      "qi": "q7LnPoSv1DRgx_vxXEmi0H8Yo2e9imTgTcy_Uaijoq8NyOC49bp_5FQAQXxqWjsWz8LQLee6yk1JjoY5-VzoWjDRWY0QJ1YWUy6SakbFhMZL-6MpNXBPlYoYTI4pBybSIb283Q0F68-tyle50S4Um4p3ETULHU15H5CrQamg1tM",
      "dp": "izuyBUKKrN-NxsJtER3opfQy4rpOjTX-8Qj81h82TRKU9ovNaVoBKqLjvWinl_kxe_dFlrs9jlE9XTywUQ3ZC3pgJ7OLz0j1eIr3qQC2FScnZSPfSV3vS4O0c45dwF1MgMGXqw08qBX5JYpmQ9ZmrS2rYRFNZlJcIco9-MwQMpE",
      "alg": "RSA-OAEP",
      "dq": "F_hGH6fLNP6SDQC5aH-4rm0FsSNHcSNutoHADHAoC8NXt9gJn0sc6-0oI5X7eogRgVuancc5lCI_K1Lk4IYR0anmbbawAz-zqC0ht1vr_C8SQa2rbUWig5Lj0g1J9JZ85kBQfnp32rqbraiYnwH3DitUrX4-PNrLz1WsoM1Bu9U",
      "n": "k1p-nCCHMgcWZ96mGrgpuRD00LDrRpc_zcrYUUCXRFQm195IOWSKFXu8p3jvRFwDlEmqpjnX7s25bjQUdvuSYnYAFr-qcRbA4ZJ7aC2bWK9HRYSej3Wira1wzjZwTqAnkTQt4jJoFy_19S2QdFQd8xdSD_L4wUr7n1wlyXTQ-uEKZVqikdNmLSfHHFycXAxEQZGuQ5_b6vhtebToMgGslY7bu2e_cVbVoqlUml9R5UBSsDkHWXgCt9ZtMxhX1HfYApK6sMkTyqYRjTnvTw3VqVtF0MKAiS1ilw7l_e6BpZylvH4xO0shizzpXVmVMvUIGgICjPjOrHaSoY9APBuJaw"
    },
    {
      "kty": "EC",
      "d": "ip4fmaJyWfpC2sUC3g7PAP-bALhlQ7wEVRC1_yLOpD0",
      "use": "enc",
      "crv": "P-256",
      "kid": "ea12f06b-2155-4e00-b31b-96121cbfc8ca",
      "x": "5yekmamaFwQV8tHRLjsEZ9CPQoecAZ5cAtOpCD8IGMA",
      "y": "bE6Lf34FI5JBbvGO_hM2p4ScfutAAJMGolbRXqSERgY",
      "alg": "ECDH-ES"
    }
  ]
}
server_public_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "4b0f0a50-b91b-4a6e-b5d8-8fcdcd1beaa0",
      "n": "vYchP-azmUsG-ai6IY0SO4XvlqcdvMxX1BqTRvZruFgdPQd2kJmPEjF2AfnUz7dwAtwWcYDFvGIW6qDUdjIkMHYInkAUogJzfoZ0BNZtNvNIUg5V2s67DsxKzlEZFbf3XeOvOGboh3NdY7Ixl5tOIgRJ4ykxIJhDdDqLkqjLVsVf-thWTS5uRND1drnr_gUsyptXxb4cJH_17OE-0FNf3XWCni5twVNxBI9dRV0BHXlzSbTg7TAAd-WgplLE_rbnV7NocfRblGJsoDjiR6ItajMzH4EIu1DvzYi7eUxaXLWNnQqBo-QNy4W4-BKBr11-V3w8dRf_60S4QRoEVx6J0Q"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "beccc197-2beb-44b5-8984-96f6d061feca",
      "n": "l-m6wkvbFxaxy5ajgMdsxwit-e-r_ANjy6rIGDHo2xdm-2HlE0FWWqCL1GL5r7GJV1aiyeiviXUb80Tif7pahjgRXV0GUQ7kvXRCmQEzg4LWt3CZq1jYtq2L6tGy_OjvnHIyk6lIqTijGKlL7KjMu66oCA81yZ5oiItZ_uLGS9LBvzjW3y26KSP8QI1jOP6wfLBvpbJ-Z_RnfxDwFrkgMKgqUIznMrH61YjMzSb_-EGw1dEDv8yzCvlaAFTBEpKSBx5aRXFCaBN_S59_UXPPX3BQH_UDnXl-NrV_JtSwzF1b_JVPKF9BHo8GMsCeRf7idtx8xIhVMtypnNKX1WdMgQ"
    },
    {
      "kty": "EC",
      "use": "sig",
      "crv": "P-256",
      "kid": "1ac1c00f-ff9a-4702-8e07-a1c21faaabba",
      "x": "OMV0raVikFEFpGQ-L4pcpCWmPzo9UVfdXPS_AWlkZPo",
      "y": "w7EGozWB-nQQaZkv5bpwHPMBpR_IMV1HvXgETPjwfC0"
    },
    {
      "kty": "EC",
      "use": "sig",
      "crv": "P-256",
      "kid": "002d1e45-9856-4ed8-b3a6-f77a1c776ada",
      "x": "vQqaTTxrKMXXGUkZHwVcYcG7tftOkN2Bi1mU5gVqfsw",
      "y": "29M85AMBIn2f5yVlrR5ur-YYUwxkkycP55ZLrPzUZA8"
    },
    {
      "kty": "EC",
      "use": "sig",
      "crv": "secp256k1",
      "kid": "eb4cd94d-33c1-492e-b839-b9a2808fdbff",
      "x": "l-ZynPiJ0TGd0vVjQJgUWOgDX3cC_pwdn6q9mtDuJ8E",
      "y": "YxrAtsf9fV_0b9lEh0x6RN1gEus3BkV4azaQAS3buBk"
    },
    {
      "kty": "OKP",
      "use": "sig",
      "crv": "Ed25519",
      "kid": "36e68b06-5f63-4ac6-8167-73e67b524ef3",
      "x": "IqgUE6wgdxedrPrl5KtQIOH6sHGReyO7dQYvGe5RFHE"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "c576d748-464e-4fb6-b153-deb5d8b7b306",
      "alg": "RSA-OAEP",
      "n": "k1p-nCCHMgcWZ96mGrgpuRD00LDrRpc_zcrYUUCXRFQm195IOWSKFXu8p3jvRFwDlEmqpjnX7s25bjQUdvuSYnYAFr-qcRbA4ZJ7aC2bWK9HRYSej3Wira1wzjZwTqAnkTQt4jJoFy_19S2QdFQd8xdSD_L4wUr7n1wlyXTQ-uEKZVqikdNmLSfHHFycXAxEQZGuQ5_b6vhtebToMgGslY7bu2e_cVbVoqlUml9R5UBSsDkHWXgCt9ZtMxhX1HfYApK6sMkTyqYRjTnvTw3VqVtF0MKAiS1ilw7l_e6BpZylvH4xO0shizzpXVmVMvUIGgICjPjOrHaSoY9APBuJaw"
    },
    {
      "kty": "EC",
      "use": "enc",
      "crv": "P-256",
      "kid": "ea12f06b-2155-4e00-b31b-96121cbfc8ca",
      "x": "5yekmamaFwQV8tHRLjsEZ9CPQoecAZ5cAtOpCD8IGMA",
      "y": "bE6Lf34FI5JBbvGO_hM2p4ScfutAAJMGolbRXqSERgY",
      "alg": "ECDH-ES"
    }
  ]
}
2021-05-31 18:32:44 SUCCESS
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2021-05-31 18:32:44 SUCCESS
CheckDistinctKeyIdValueInServerJWKs
Distinct 'kid' value in all keys of server_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2021-05-31 18:32:44 SUCCESS
OIDCCLoadUserInfo
Added user information
user_info
{
  "sub": "user-subject-1234531",
  "name": "Demo T. User",
  "given_name": "Demo",
  "family_name": "User",
  "middle_name": "Theresa",
  "nickname": "Dee",
  "preferred_username": "d.tu",
  "gender": "female",
  "birthdate": "2000-02-03",
  "address": {
    "street_address": "100 Universal City Plaza",
    "locality": "Hollywood",
    "region": "CA",
    "postal_code": "91608",
    "country": "USA"
  },
  "zoneinfo": "America/Los_Angeles",
  "locale": "en-US",
  "phone_number": "+1 555 5550000",
  "phone_number_verified": false,
  "email": "user@example.com",
  "email_verified": false,
  "website": "https://openid.net/",
  "updated_at": 1580000000
}
2021-05-31 18:32:44 SUCCESS
OIDCCGetStaticClientConfigurationForRPTests
Found a static client object
client_secret_jwt_alg
RS256
client_id
12345678-hybrid-profile-plain-private-key-clientid
client_secret
secret-hybrid-profile-plain-private-key-clientid
scope
openid accounts
jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "keyid-to-fapi-plain-pauth",
      "alg": "PS256",
      "n": "urjyW-QSZIGGSe9kCUOnucEoQS28VhyL44VtyXhy0iuFgXnTRJxY6WnZP1yOcawCVRTdMkn6gGzZ2Mr7Lo1529gO6WyWV1Pl2CgjnUE4PNaIRSo_LpKVXZd7IycbRxg_UxrWo2rkpmUL5PzMYq9sGl7VfN-UpB7XcwMu7qRZd0LH_xWMThfuYHZRUxVt7V4Kw5xOID8wK8tSUbqf1kk9tAxyY8BHpFD3-bYQpHEYAx7OwdwW0UdBksItQNqOUdhB9kG89onYDe8uZvyxQqu8lpul_3snscIcDq0bxD83hVqL8E7SU7996poGWSKcoAWnBhUIzbPOcyfGFFw_RDK-Cw"
    }
  ]
}
certificate
-----BEGIN CERTIFICATE-----
MIIFTTCCBDWgAwIBAgIQWSl/rqAik/ZS2bkCLQ7ZGzANBgkqhkiG9w0BAQsFADCB
sDELMAkGA1UEBhMCQVUxNzA1BgNVBAoTLkF1c3RyYWxpYW4gQ29tcGV0aXRpb24g
YW5kIENvbnN1bWVyIENvbW1pc3Npb24xHDAaBgNVBAsTE0NvbnN1bWVyIERhdGEg
UmlnaHQxHzAdBgNVBAsTFkZvciBURVNUIFB1cnBvc2VzIE9OTFkxKTAnBgNVBAMT
IENEUiBURVNUIEJhbmtpbmcgSW50ZXJtZWRpYXRlIENBMB4XDTIwMTExOTAwMDAw
MFoXDTIxMTExOTIzNTk1OVowgZQxHDAaBgNVBAsME0NvbnN1bWVyIERhdGEgUmln
aHQxHzAdBgNVBAsMFkZvciBURVNUIFB1cnBvc2VzIE9OTFkxJTAjBgNVBAoMHElu
dHVpdCBBdXN0cmFsaWEgUHR5IExpbWl0ZWQxLDAqBgNVBAMMI3BhcnRuZXJhdXRo
LWUyZS5wbGF0Zm9ybS5pbnR1aXQuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
MIIBCgKCAQEAwkTTIUXBivenAAstBtWlNK/WJh62pQhVvmV5v/s30fTtp9Yaos8F
QyP2kJUy0h/L5asdC0IIDonrLBDwi7zVCm/VsNr4Gx0DPng5yYSLRdNaxPk4S8ax
PY8wwYYjeJuaV/DrvYneu40DZiJWTE8N3SpKZ+OSfxJlFtda2ejkfhNk0a0amIMr
Q2YfanI/nVwk7/WWDfwqc2jMuI3WPZHt165+TDPb1qG1cXm5PoPJpD3srITvfJue
s6nfI14wtGZu0IVlT9go7bJcMRNBb/C4EpDyfl3v3MExsqMe0TI5e7kTMgy5rjDG
4s75GVaHpiWRw956sda8obv5Kb9gflpeYwIDAQABo4IBezCCAXcwDAYDVR0TAQH/
BAIwADAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwIwHQYDVR0O
BBYEFHVsct+KfWyMwdYa3jLcQw7NplPwMC4GCmCGSAGG+EUBEAMEIDAeBhNghkgB
hvhFARABAwEEAYL4tIwYFgcxMTMwMjIwMDkGCmCGSAGG+EUBEAUEKzApAgEAFiRh
SFIwY0hNNkx5OXdhMmt0Y21FdWMzbHRZWFYwYUM1amIyMD0wXQYDVR0fBFYwVDBS
oFCgToZMaHR0cDovL3BraS1jcmwuc3ltYXV0aC5jb20vY2FfZGY1ZDQ5M2Q1YjQ3
ODQ5MjZjZGZlNmFkZTllMDAzZmMvTGF0ZXN0Q1JMLmNybDA4BggrBgEFBQcBAQQs
MCowKAYIKwYBBQUHMAGGHGh0dHA6Ly9wa2ktb2NzcC5kaWdpY2VydC5jb20wHwYD
VR0jBBgwFoAUSTaRAgiZKmzkKWCekX67k63mXkswDQYJKoZIhvcNAQELBQADggEB
AEnEvI5UJ2txz4oYJCqMCMNoHvapyW3dG7K+Lrjh+V+pwwASbGpX8KiyO7J+iWp/
/ceQDMdTP0UFM1j5L8EePQ0hWOkJvWsVmo6GgS7zYPu+6id73P3cgLwqAWRrLBSk
sNfdUQPY4lVaSiMDf3VzzqjMzdTGbNAzZmeJEszKI5fUEt+T47mtu2jFcMq9o1vw
dxLjJ7BP1MIWsPNCzYazma2+Nfe3v/CzvsroyLiNywwaZn4D4r5VOofNrVM8UXpr
Rhn5pCEvDbbgr8Rd3k5zFq6LTbP1H6K47rs9MY+Edb/Uel/qhlx3RQBCy4ryR8Q6
ofDMEAPI9RcppT6elKQQ69M=
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIFtzCCA5+gAwIBAgIQGhoSP4DqnQoUsNkehM6x2TANBgkqhkiG9w0BAQsFADCB
oDELMAkGA1UEBhMCQVUxNzA1BgNVBAoTLkF1c3RyYWxpYW4gQ29tcGV0aXRpb24g
YW5kIENvbnN1bWVyIENvbW1pc3Npb24xHDAaBgNVBAsTE0NvbnN1bWVyIERhdGEg
UmlnaHQxHzAdBgNVBAsTFkZvciBURVNUIFB1cnBvc2VzIE9OTFkxGTAXBgNVBAMT
EENEUiBURVNUIFJvb3QgQ0EwHhcNMTkxMDE3MDAwMDAwWhcNMzQxMDE2MjM1OTU5
WjCBsDELMAkGA1UEBhMCQVUxNzA1BgNVBAoTLkF1c3RyYWxpYW4gQ29tcGV0aXRp
b24gYW5kIENvbnN1bWVyIENvbW1pc3Npb24xHDAaBgNVBAsTE0NvbnN1bWVyIERh
dGEgUmlnaHQxHzAdBgNVBAsTFkZvciBURVNUIFB1cnBvc2VzIE9OTFkxKTAnBgNV
BAMTIENEUiBURVNUIEJhbmtpbmcgSW50ZXJtZWRpYXRlIENBMIIBIjANBgkqhkiG
9w0BAQEFAAOCAQ8AMIIBCgKCAQEAq6+NlPtZ4TPJrMRbvj7HkXBkEStfc1s+L8qd
FX8BRnt/H9Ca+9BTLEiKj+jJ6J74yTLrK9g4y+hhaQZFFperMF0TUy+fU3nby6D8
jo6fMLr0O/W8MZ2LTk/6n1+FiZqUH8st3Nle9f4DdLY6BAR8HjCnikNYaxutBTYt
GjkxOqogGFdwG+X0S0spKGDTq5UAp3Wc7D/fZRSeAfdTYO5FV9zhdTT6sbnrosQi
obBuwqwLqZeeju6V5fogkhMu4tVE3GmiK/T5mGrBqqO2DIfI4t+1D/SBo4jZP2V/
El2CSRgKrlVMcWoOE3h9Aa20vliLsJgv/Zf9gH/5UhHV5KlegQIDAQABo4HaMIHX
MCgGA1UdEQQhMB+kHTAbMRkwFwYDVQQDExBEaWdpQ2VydFBLSS0zLTY5MB0GA1Ud
DgQWBBRJNpECCJkqbOQpYJ6RfruTreZeSzASBgNVHRMBAf8ECDAGAQH/AgEAMEcG
A1UdHwRAMD4wPKA6oDiGNmh0dHA6Ly9jcmwuYXUuZGlnaWNlcnQuY29tL0NBL0FD
Q0NfQ0RSX1RFU1RfUm9vdENBLmNybDAOBgNVHQ8BAf8EBAMCAQYwHwYDVR0jBBgw
FoAU/shndz73CkDs3XVqioe1JoHU24wwDQYJKoZIhvcNAQELBQADggIBADQAYy6W
KMFMyyOkW23kFMLu/ki66DfvusaNR++4tXUs4j6TSipEJ4weyKpMNcro+InGCaY3
0X2fIzTa/L0PJlpo/cLuuGRpnx41I5dPjnltmwmZSXEJEYlIn0aQNy1luHfR76s+
A44/DiquHVlI4t4fLcsuDUtVHcTlN59qY40GuWL/00y4IGWNbrXSSDLkRqWdeBF4
A8XRoTLMmNuw4Mcm9Zpggc2K40GtFxCbxsDaw6NVZgGODnnSdmw5/gExWH1RIjYU
J7whYsnIIPxy8HmogGOhrvB36EtvS/BOeNwSyBNVoSTDoVLDeMxgO/9shH0Ytaew
zsXAnfW5wUZiiAyqZOqN7gUZpo+aaZrC8sBo36B1RdLzEszs0GY3ohl/rUixr5jY
nbC4mYTte4DNA6HSadBnHAmnyLX5oQvK+pE9eSaZVNvg09pDSPjRkuhYxPO5tHkr
zrjAk3PNXKDddnSdMSXILbkPAEssBuC4vax1kd5o8grSFvidUQMr61paT5o17lxh
Y7z1Fav5bW65JFid1oR6OiEn+o3DNaYf22eaYJsZRcJ7Fio8CPoJnSq5NJC57KHq
NYHMCwMdJkob2NNXJSmKA3FRxX2zhj6iehQT9p+N5HEngGJMGAv90MhIIWZcHuK5
m/Egr0D/nA9GtlPyS0m2GkCkNqzyD2cyOilg
-----END CERTIFICATE-----
redirect_uris
[
  "https://partnerauth-e2e.platform.intuit.com/external_partner/openid_core_cert/callback"
]
2021-05-31 18:32:44 SUCCESS
EnsureClientDoesNotHaveBothJwksAndJwksUri
Client does not have both jwks and jwks_uri set
client
{
  "client_secret_jwt_alg": "RS256",
  "client_id": "12345678-hybrid-profile-plain-private-key-clientid",
  "client_secret": "secret-hybrid-profile-plain-private-key-clientid",
  "scope": "openid accounts",
  "jwks": {
    "keys": [
      {
        "kty": "RSA",
        "e": "AQAB",
        "use": "sig",
        "kid": "keyid-to-fapi-plain-pauth",
        "alg": "PS256",
        "n": "urjyW-QSZIGGSe9kCUOnucEoQS28VhyL44VtyXhy0iuFgXnTRJxY6WnZP1yOcawCVRTdMkn6gGzZ2Mr7Lo1529gO6WyWV1Pl2CgjnUE4PNaIRSo_LpKVXZd7IycbRxg_UxrWo2rkpmUL5PzMYq9sGl7VfN-UpB7XcwMu7qRZd0LH_xWMThfuYHZRUxVt7V4Kw5xOID8wK8tSUbqf1kk9tAxyY8BHpFD3-bYQpHEYAx7OwdwW0UdBksItQNqOUdhB9kG89onYDe8uZvyxQqu8lpul_3snscIcDq0bxD83hVqL8E7SU7996poGWSKcoAWnBhUIzbPOcyfGFFw_RDK-Cw"
      }
    ]
  },
  "certificate": "-----BEGIN CERTIFICATE-----\nMIIFTTCCBDWgAwIBAgIQWSl/rqAik/ZS2bkCLQ7ZGzANBgkqhkiG9w0BAQsFADCB\nsDELMAkGA1UEBhMCQVUxNzA1BgNVBAoTLkF1c3RyYWxpYW4gQ29tcGV0aXRpb24g\nYW5kIENvbnN1bWVyIENvbW1pc3Npb24xHDAaBgNVBAsTE0NvbnN1bWVyIERhdGEg\nUmlnaHQxHzAdBgNVBAsTFkZvciBURVNUIFB1cnBvc2VzIE9OTFkxKTAnBgNVBAMT\nIENEUiBURVNUIEJhbmtpbmcgSW50ZXJtZWRpYXRlIENBMB4XDTIwMTExOTAwMDAw\nMFoXDTIxMTExOTIzNTk1OVowgZQxHDAaBgNVBAsME0NvbnN1bWVyIERhdGEgUmln\naHQxHzAdBgNVBAsMFkZvciBURVNUIFB1cnBvc2VzIE9OTFkxJTAjBgNVBAoMHElu\ndHVpdCBBdXN0cmFsaWEgUHR5IExpbWl0ZWQxLDAqBgNVBAMMI3BhcnRuZXJhdXRo\nLWUyZS5wbGF0Zm9ybS5pbnR1aXQuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A\nMIIBCgKCAQEAwkTTIUXBivenAAstBtWlNK/WJh62pQhVvmV5v/s30fTtp9Yaos8F\nQyP2kJUy0h/L5asdC0IIDonrLBDwi7zVCm/VsNr4Gx0DPng5yYSLRdNaxPk4S8ax\nPY8wwYYjeJuaV/DrvYneu40DZiJWTE8N3SpKZ+OSfxJlFtda2ejkfhNk0a0amIMr\nQ2YfanI/nVwk7/WWDfwqc2jMuI3WPZHt165+TDPb1qG1cXm5PoPJpD3srITvfJue\ns6nfI14wtGZu0IVlT9go7bJcMRNBb/C4EpDyfl3v3MExsqMe0TI5e7kTMgy5rjDG\n4s75GVaHpiWRw956sda8obv5Kb9gflpeYwIDAQABo4IBezCCAXcwDAYDVR0TAQH/\nBAIwADAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwIwHQYDVR0O\nBBYEFHVsct+KfWyMwdYa3jLcQw7NplPwMC4GCmCGSAGG+EUBEAMEIDAeBhNghkgB\nhvhFARABAwEEAYL4tIwYFgcxMTMwMjIwMDkGCmCGSAGG+EUBEAUEKzApAgEAFiRh\nSFIwY0hNNkx5OXdhMmt0Y21FdWMzbHRZWFYwYUM1amIyMD0wXQYDVR0fBFYwVDBS\noFCgToZMaHR0cDovL3BraS1jcmwuc3ltYXV0aC5jb20vY2FfZGY1ZDQ5M2Q1YjQ3\nODQ5MjZjZGZlNmFkZTllMDAzZmMvTGF0ZXN0Q1JMLmNybDA4BggrBgEFBQcBAQQs\nMCowKAYIKwYBBQUHMAGGHGh0dHA6Ly9wa2ktb2NzcC5kaWdpY2VydC5jb20wHwYD\nVR0jBBgwFoAUSTaRAgiZKmzkKWCekX67k63mXkswDQYJKoZIhvcNAQELBQADggEB\nAEnEvI5UJ2txz4oYJCqMCMNoHvapyW3dG7K+Lrjh+V+pwwASbGpX8KiyO7J+iWp/\n/ceQDMdTP0UFM1j5L8EePQ0hWOkJvWsVmo6GgS7zYPu+6id73P3cgLwqAWRrLBSk\nsNfdUQPY4lVaSiMDf3VzzqjMzdTGbNAzZmeJEszKI5fUEt+T47mtu2jFcMq9o1vw\ndxLjJ7BP1MIWsPNCzYazma2+Nfe3v/CzvsroyLiNywwaZn4D4r5VOofNrVM8UXpr\nRhn5pCEvDbbgr8Rd3k5zFq6LTbP1H6K47rs9MY+Edb/Uel/qhlx3RQBCy4ryR8Q6\nofDMEAPI9RcppT6elKQQ69M\u003d\n-----END CERTIFICATE-----\n-----BEGIN CERTIFICATE-----\nMIIFtzCCA5+gAwIBAgIQGhoSP4DqnQoUsNkehM6x2TANBgkqhkiG9w0BAQsFADCB\noDELMAkGA1UEBhMCQVUxNzA1BgNVBAoTLkF1c3RyYWxpYW4gQ29tcGV0aXRpb24g\nYW5kIENvbnN1bWVyIENvbW1pc3Npb24xHDAaBgNVBAsTE0NvbnN1bWVyIERhdGEg\nUmlnaHQxHzAdBgNVBAsTFkZvciBURVNUIFB1cnBvc2VzIE9OTFkxGTAXBgNVBAMT\nEENEUiBURVNUIFJvb3QgQ0EwHhcNMTkxMDE3MDAwMDAwWhcNMzQxMDE2MjM1OTU5\nWjCBsDELMAkGA1UEBhMCQVUxNzA1BgNVBAoTLkF1c3RyYWxpYW4gQ29tcGV0aXRp\nb24gYW5kIENvbnN1bWVyIENvbW1pc3Npb24xHDAaBgNVBAsTE0NvbnN1bWVyIERh\ndGEgUmlnaHQxHzAdBgNVBAsTFkZvciBURVNUIFB1cnBvc2VzIE9OTFkxKTAnBgNV\nBAMTIENEUiBURVNUIEJhbmtpbmcgSW50ZXJtZWRpYXRlIENBMIIBIjANBgkqhkiG\n9w0BAQEFAAOCAQ8AMIIBCgKCAQEAq6+NlPtZ4TPJrMRbvj7HkXBkEStfc1s+L8qd\nFX8BRnt/H9Ca+9BTLEiKj+jJ6J74yTLrK9g4y+hhaQZFFperMF0TUy+fU3nby6D8\njo6fMLr0O/W8MZ2LTk/6n1+FiZqUH8st3Nle9f4DdLY6BAR8HjCnikNYaxutBTYt\nGjkxOqogGFdwG+X0S0spKGDTq5UAp3Wc7D/fZRSeAfdTYO5FV9zhdTT6sbnrosQi\nobBuwqwLqZeeju6V5fogkhMu4tVE3GmiK/T5mGrBqqO2DIfI4t+1D/SBo4jZP2V/\nEl2CSRgKrlVMcWoOE3h9Aa20vliLsJgv/Zf9gH/5UhHV5KlegQIDAQABo4HaMIHX\nMCgGA1UdEQQhMB+kHTAbMRkwFwYDVQQDExBEaWdpQ2VydFBLSS0zLTY5MB0GA1Ud\nDgQWBBRJNpECCJkqbOQpYJ6RfruTreZeSzASBgNVHRMBAf8ECDAGAQH/AgEAMEcG\nA1UdHwRAMD4wPKA6oDiGNmh0dHA6Ly9jcmwuYXUuZGlnaWNlcnQuY29tL0NBL0FD\nQ0NfQ0RSX1RFU1RfUm9vdENBLmNybDAOBgNVHQ8BAf8EBAMCAQYwHwYDVR0jBBgw\nFoAU/shndz73CkDs3XVqioe1JoHU24wwDQYJKoZIhvcNAQELBQADggIBADQAYy6W\nKMFMyyOkW23kFMLu/ki66DfvusaNR++4tXUs4j6TSipEJ4weyKpMNcro+InGCaY3\n0X2fIzTa/L0PJlpo/cLuuGRpnx41I5dPjnltmwmZSXEJEYlIn0aQNy1luHfR76s+\nA44/DiquHVlI4t4fLcsuDUtVHcTlN59qY40GuWL/00y4IGWNbrXSSDLkRqWdeBF4\nA8XRoTLMmNuw4Mcm9Zpggc2K40GtFxCbxsDaw6NVZgGODnnSdmw5/gExWH1RIjYU\nJ7whYsnIIPxy8HmogGOhrvB36EtvS/BOeNwSyBNVoSTDoVLDeMxgO/9shH0Ytaew\nzsXAnfW5wUZiiAyqZOqN7gUZpo+aaZrC8sBo36B1RdLzEszs0GY3ohl/rUixr5jY\nnbC4mYTte4DNA6HSadBnHAmnyLX5oQvK+pE9eSaZVNvg09pDSPjRkuhYxPO5tHkr\nzrjAk3PNXKDddnSdMSXILbkPAEssBuC4vax1kd5o8grSFvidUQMr61paT5o17lxh\nY7z1Fav5bW65JFid1oR6OiEn+o3DNaYf22eaYJsZRcJ7Fio8CPoJnSq5NJC57KHq\nNYHMCwMdJkob2NNXJSmKA3FRxX2zhj6iehQT9p+N5HEngGJMGAv90MhIIWZcHuK5\nm/Egr0D/nA9GtlPyS0m2GkCkNqzyD2cyOilg\n-----END CERTIFICATE-----",
  "redirect_uris": [
    "https://partnerauth-e2e.platform.intuit.com/external_partner/openid_core_cert/callback"
  ]
}
2021-05-31 18:32:44 INFO
FetchClientKeys
Skipped evaluation due to missing required element: client jwks_uri
path
jwks_uri
mapped
object
client
2021-05-31 18:32:44 SUCCESS
ValidateClientGrantTypes
grant_types match response_types
grant_types
[
  "authorization_code"
]
response_types
[
  "code"
]
2021-05-31 18:32:44 SUCCESS
OIDCCValidateClientRedirectUris
Valid redirect_uri(s) provided in registration request
redirect_uris
[
  "https://partnerauth-e2e.platform.intuit.com/external_partner/openid_core_cert/callback"
]
2021-05-31 18:32:44 SUCCESS
ValidateClientLogoUris
Client does not contain any logo_uri
2021-05-31 18:32:44 SUCCESS
ValidateClientUris
Client does not contain any client_uri
2021-05-31 18:32:44 SUCCESS
ValidateClientPolicyUris
Client does not contain any policy_uri
2021-05-31 18:32:44 SUCCESS
ValidateClientTosUris
Client does not contain any tos_uri
2021-05-31 18:32:44 SUCCESS
ValidateClientSubjectType
A subject_type was not provided
2021-05-31 18:32:44 INFO
ValidateIdTokenSignedResponseAlg
Skipped evaluation due to missing required element: client id_token_signed_response_alg
path
id_token_signed_response_alg
mapped
object
client
2021-05-31 18:32:44 SUCCESS
EnsureIdTokenEncryptedResponseAlgIsSetIfEncIsSet
id_token_encrypted_response_enc is not set
2021-05-31 18:32:44 INFO
ValidateUserinfoSignedResponseAlg
Skipped evaluation due to missing required element: client userinfo_signed_response_alg
path
userinfo_signed_response_alg
mapped
object
client
2021-05-31 18:32:44 SUCCESS
EnsureUserinfoEncryptedResponseAlgIsSetIfEncIsSet
userinfo_encrypted_response_enc is not set
2021-05-31 18:32:44 INFO
ValidateRequestObjectSigningAlg
Skipped evaluation due to missing required element: client request_object_signing_alg
path
request_object_signing_alg
mapped
object
client
2021-05-31 18:32:44 SUCCESS
EnsureRequestObjectEncryptionAlgIsSetIfEncIsSet
request_object_encryption_enc is not set
2021-05-31 18:32:44 INFO
ValidateTokenEndpointAuthSigningAlg
Skipped evaluation due to missing required element: client token_endpoint_auth_signing_alg
path
token_endpoint_auth_signing_alg
mapped
object
client
2021-05-31 18:32:44 SUCCESS
ValidateDefaultMaxAge
default_max_age is not set
2021-05-31 18:32:44 INFO
ValidateRequireAuthTime
Skipped evaluation due to missing required element: client require_auth_time
path
require_auth_time
mapped
object
client
2021-05-31 18:32:44 INFO
ValidateDefaultAcrValues
Skipped evaluation due to missing required element: client default_acr_values
path
default_acr_values
mapped
object
client
2021-05-31 18:32:44 INFO
ValidateInitiateLoginUri
Skipped evaluation due to missing required element: client initiate_login_uri
path
initiate_login_uri
mapped
object
client
2021-05-31 18:32:44 INFO
ValidateRequestUris
Skipped evaluation due to missing required element: client request_uris
path
request_uris
mapped
object
client
2021-05-31 18:32:44
SetServerSigningAlgToRS256
Successfully set signing algorithm to RS256
2021-05-31 18:32:44
SetClientIdTokenSignedResponseAlgToServerSigningAlg
Set id_token_signed_response_alg for the registered client
id_token_signed_response_alg
RS256
2021-05-31 18:32:44
oidcc-client-test-invalid-sig-rs256
Setup Done
2021-05-31 18:33:07 INCOMING
oidcc-client-test-invalid-sig-rs256
Incoming HTTP request to test instance p9vhGTfdN5ntu3m
incoming_headers
{
  "host": "www.certification.openid.net",
  "upgrade-insecure-requests": "1",
  "user-agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.212 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "none",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "sec-ch-ua": "\" Not A;Brand\";v\u003d\"99\", \"Chromium\";v\u003d\"90\", \"Google Chrome\";v\u003d\"90\"",
  "sec-ch-ua-mobile": "?0",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9,hi;q\u003d0.8",
  "cookie": "__utmz\u003d201319536.1621283291.13.3.utmcsr\u003dgoogle|utmccn\u003d(organic)|utmcmd\u003dorganic|utmctr\u003d(not%20provided); __utma\u003d201319536.30309185.1617009267.1621283291.1621288066.14; JSESSIONID\u003dC1F265DB38EAC21443DF2685B404DECE",
  "x-ssl-cipher": "ECDHE-RSA-AES128-GCM-SHA256",
  "x-ssl-protocol": "TLSv1.2",
  "connection": "close",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net"
}
incoming_path
authorize
incoming_body_form_params
incoming_method
GET
incoming_body_json
incoming_query_string_params
{
  "scope": "openid phone profile email address offline_access",
  "response_type": "code token",
  "redirect_uri": "https://partnerauth-e2e.platform.intuit.com/external_partner/openid_core_cert/callback",
  "client_id": "12345678-hybrid-profile-plain-private-key-clientid",
  "nonce": "awb.4fd76a5e-4225-46e6-ba27-668788a29f77",
  "state": "awb.4fd76a5e-4225-46e6-ba27-668788a29f77"
}
incoming_body
Authorization endpoint
2021-05-31 18:33:07 SUCCESS
EnsureRequestDoesNotContainRequestObject
Request does not contain a request parameter
2021-05-31 18:33:07 SUCCESS
OIDCCEnsureAuthorizationHttpRequestContainsOpenIDScope
Found 'openid' in scope http request parameter
actual
[
  "openid",
  "phone",
  "profile",
  "email",
  "address",
  "offline_access"
]
expected
openid
2021-05-31 18:33:07 SUCCESS
CreateEffectiveAuthorizationRequestParameters
Merged http request parameters with request object claims
effective_authorization_endpoint_request
{
  "scope": "openid phone profile email address offline_access",
  "response_type": "code token",
  "redirect_uri": "https://partnerauth-e2e.platform.intuit.com/external_partner/openid_core_cert/callback",
  "client_id": "12345678-hybrid-profile-plain-private-key-clientid",
  "nonce": "awb.4fd76a5e-4225-46e6-ba27-668788a29f77",
  "state": "awb.4fd76a5e-4225-46e6-ba27-668788a29f77"
}
2021-05-31 18:33:07 SUCCESS
ExtractRequestedScopes
Requested scopes
scope
openid phone profile email address offline_access
2021-05-31 18:33:07 SUCCESS
ExtractNonceFromAuthorizationRequest
Extracted nonce
nonce
awb.4fd76a5e-4225-46e6-ba27-668788a29f77
2021-05-31 18:33:07 SUCCESS
EnsureResponseTypeIsCodeToken
Response type is expected value
expected
code token
2021-05-31 18:33:07 SUCCESS
EnsureMatchingClientId
Client ID matched
client_id
12345678-hybrid-profile-plain-private-key-clientid
2021-05-31 18:33:07 SUCCESS
EnsureValidRedirectUriForAuthorizationEndpointRequest
redirect_uri is one of the allowed redirect uris
actual
https://partnerauth-e2e.platform.intuit.com/external_partner/openid_core_cert/callback
expected
[
  "https://partnerauth-e2e.platform.intuit.com/external_partner/openid_core_cert/callback"
]
2021-05-31 18:33:07 SUCCESS
EnsureOpenIDInScopeRequest
Found 'openid' scope in request
actual
[
  "openid",
  "phone",
  "profile",
  "email",
  "address",
  "offline_access"
]
expected
openid
2021-05-31 18:33:07 SUCCESS
DisallowMaxAgeEqualsZeroAndPromptNone
The client did not send max_age=0 and prompt=none parameters as expected
2021-05-31 18:33:07 SUCCESS
CreateAuthorizationCode
Created authorization code
authorization_code
v6EuqTwuyB
2021-05-31 18:33:07 SUCCESS
CalculateCHash
Successful c_hash encoding
c_hash
sIeMc_CxGPXtsVjS_A9qwQ
2021-05-31 18:33:07 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
YAETIcgau7xdU3x7oHc84Ub57jeebWUiV9ssQNyePU8I8EXAxh
2021-05-31 18:33:07 SUCCESS
CalculateAtHash
Successful at_hash encoding
at_hash
uS7oCambdVw6wcfvSLb10Q
2021-05-31 18:33:07 SUCCESS
CreateAuthorizationEndpointResponseParams
Added authorization_endpoint_response_params to environment
params
{
  "redirect_uri": "https://partnerauth-e2e.platform.intuit.com/external_partner/openid_core_cert/callback",
  "state": "awb.4fd76a5e-4225-46e6-ba27-668788a29f77"
}
2021-05-31 18:33:07 SUCCESS
AddCodeToAuthorizationEndpointResponseParams
Added code to authorization endpoint response params
authorization_endpoint_response_params
{
  "redirect_uri": "https://partnerauth-e2e.platform.intuit.com/external_partner/openid_core_cert/callback",
  "state": "awb.4fd76a5e-4225-46e6-ba27-668788a29f77",
  "code": "v6EuqTwuyB"
}
2021-05-31 18:33:07
AddTokenToAuthorizationEndpointResponseParams
Added token and token_type to authorization endpoint response params
authorization_endpoint_response_params
{
  "redirect_uri": "https://partnerauth-e2e.platform.intuit.com/external_partner/openid_core_cert/callback",
  "state": "awb.4fd76a5e-4225-46e6-ba27-668788a29f77",
  "code": "v6EuqTwuyB",
  "access_token": "YAETIcgau7xdU3x7oHc84Ub57jeebWUiV9ssQNyePU8I8EXAxh",
  "token_type": "Bearer"
}
2021-05-31 18:33:07
SendAuthorizationResponseWithResponseModeFragment
Redirecting back to client
uri
https://partnerauth-e2e.platform.intuit.com/external_partner/openid_core_cert/callback#state=awb.4fd76a5e-4225-46e6-ba27-668788a29f77&code=v6EuqTwuyB&access_token=YAETIcgau7xdU3x7oHc84Ub57jeebWUiV9ssQNyePU8I8EXAxh&token_type=Bearer
2021-05-31 18:33:07 OUTGOING
oidcc-client-test-invalid-sig-rs256
Response to HTTP request to test instance p9vhGTfdN5ntu3m
outgoing
org.springframework.web.servlet.view.RedirectView: [RedirectView]; URL [https://partnerauth-e2e.platform.intuit.com/external_partner/openid_core_cert/callback#state=awb.4fd76a5e-4225-46e6-ba27-668788a29f77&code=v6EuqTwuyB&access_token=YAETIcgau7xdU3x7oHc84Ub57jeebWUiV9ssQNyePU8I8EXAxh&token_type=Bearer]
outgoing_path
authorize
2021-05-31 18:33:09 INCOMING
oidcc-client-test-invalid-sig-rs256
Incoming HTTP request to test instance p9vhGTfdN5ntu3m
incoming_headers
{
  "host": "www.certification.openid.net",
  "authorization": "Basic MTIzNDU2NzgtaHlicmlkLXByb2ZpbGUtcGxhaW4tcHJpdmF0ZS1rZXktY2xpZW50aWQ6c2VjcmV0LWh5YnJpZC1wcm9maWxlLXBsYWluLXByaXZhdGUta2V5LWNsaWVudGlk",
  "content-type": "application/x-www-form-urlencoded; charset\u003dUTF-8",
  "user-agent": "Apache-HttpClient/4.5.6 (Java/1.8.0_241)",
  "accept-encoding": "gzip,deflate",
  "x-ssl-cipher": "ECDHE-RSA-AES256-GCM-SHA384",
  "x-ssl-protocol": "TLSv1.2",
  "content-length": "281",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net",
  "connection": "close"
}
incoming_path
token
incoming_body_form_params
{
  "code": "v6EuqTwuyB",
  "grant_type": "authorization_code",
  "redirect_uri": "https://partnerauth-e2e.platform.intuit.com/external_partner/openid_core_cert/callback",
  "client_id": "12345678-hybrid-profile-plain-private-key-clientid",
  "client_secret": "secret-hybrid-profile-plain-private-key-clientid"
}
incoming_method
POST
incoming_body_json
incoming_query_string_params
{}
incoming_body
code=v6EuqTwuyB&grant_type=authorization_code&redirect_uri=https%3A%2F%2Fpartnerauth-e2e.platform.intuit.com%2Fexternal_partner%2Fopenid_core_cert%2Fcallback&client_id=12345678-hybrid-profile-plain-private-key-clientid&client_secret=secret-hybrid-profile-plain-private-key-clientid
Token endpoint
2021-05-31 18:33:09 SUCCESS
ExtractClientCredentialsFromBasicAuthorizationHeader
Extracted client authentication
client_id
12345678-hybrid-profile-plain-private-key-clientid
client_secret
secret-hybrid-profile-plain-private-key-clientid
method
client_secret_basic
2021-05-31 18:33:09 SUCCESS
ValidateClientIdAndSecret
Client id and secret match
2021-05-31 18:33:09 SUCCESS
ValidateAuthorizationCode
Found authorization code
authorization_code
v6EuqTwuyB
2021-05-31 18:33:09 SUCCESS
ValidateRedirectUriForTokenEndpointRequest
redirect_uri is the same as the one used in the authorization request
actual
https://partnerauth-e2e.platform.intuit.com/external_partner/openid_core_cert/callback
2021-05-31 18:33:09 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
aDcBkN4vQ4bfV4V5JgcenwMkySjShum3noAH7CqfMgGzQ6Mh7J
2021-05-31 18:33:09 SUCCESS
CalculateAtHash
Successful at_hash encoding
at_hash
EBJBlyY8i-o0tqd3vnENHg
2021-05-31 18:33:09 SUCCESS
GenerateIdTokenClaims
Created ID Token Claims
iss
https://www.certification.openid.net/test/a/Intuit_pauth_openid_hybrid_profile_plan_1/
sub
user-subject-1234531
aud
12345678-hybrid-profile-plain-private-key-clientid
nonce
awb.4fd76a5e-4225-46e6-ba27-668788a29f77
iat
1622485989
exp
1622486289
2021-05-31 18:33:09 SUCCESS
AddAtHashToIdTokenClaims
Added at_hash to ID token claims
at_hash
EBJBlyY8i-o0tqd3vnENHg
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/Intuit_pauth_openid_hybrid_profile_plan_1/",
  "sub": "user-subject-1234531",
  "aud": "12345678-hybrid-profile-plain-private-key-clientid",
  "nonce": "awb.4fd76a5e-4225-46e6-ba27-668788a29f77",
  "iat": 1622485989,
  "exp": 1622486289,
  "at_hash": "EBJBlyY8i-o0tqd3vnENHg"
}
2021-05-31 18:33:09 SUCCESS
OIDCCSignIdToken
Signed the ID token
id_token
eyJraWQiOiI0YjBmMGE1MC1iOTFiLTRhNmUtYjVkOC04ZmNkY2QxYmVhYTAiLCJhbGciOiJSUzI1NiJ9.eyJhdF9oYXNoIjoiRUJKQmx5WThpLW8wdHFkM3ZuRU5IZyIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoiMTIzNDU2NzgtaHlicmlkLXByb2ZpbGUtcGxhaW4tcHJpdmF0ZS1rZXktY2xpZW50aWQiLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvSW50dWl0X3BhdXRoX29wZW5pZF9oeWJyaWRfcHJvZmlsZV9wbGFuXzFcLyIsImV4cCI6MTYyMjQ4NjI4OSwibm9uY2UiOiJhd2IuNGZkNzZhNWUtNDIyNS00NmU2LWJhMjctNjY4Nzg4YTI5Zjc3IiwiaWF0IjoxNjIyNDg1OTg5fQ.sahL-ajeGXQ4XkjDyfytYTQm8nKjrhHiJqMM8ajoevkucm5ZCXfgxYpZQ9zR0B6kx3M8w9r4vAeFDVeIQCHmCW7W0RslzqgzLhV13id6qYNLdG1p_yXJcl-22WBpu3VROMPmRSvX0YtJytciWkmLz8liwi7UJyi69bYFvpcz90prF5CWhvGOYTRXmfJnFzErh2wImo8cBfOAvmqKDWA1qyr1lpcVrKZkS55WxiIb2mdc-NRLNhYPicfxq1QijYA-q7_ONY2RMZWkAjLrVWWWVsIsJD1QcnOL4fLiEoIUSiBas6Z28fVn1Fm-krXrCJ8F9D8PDrFmjcJs3KYfhnay5Q
key
{"p":"6lPqKVVeQ0Q7UcMyWzncquphqWgf36RXKwiDNredWv6IlM-ljALMfEAkIluA_E1pmwSQPRdbZs7SHRPG2mYi69BCORaPyzowxTfg3D67mGTtCuV3z4FjGK1ZbZgMwOii_y8C-ENmDYJGktdRiDs6udqAton53CdrRFNJ7UtzDTs","kty":"RSA","q":"zw6BQxDih66ObMR8Lw4R7brdotKGhpO2iaOAbXEX2oSqMSmQ5bj2lv3ijhsRDZJW-Sf_m-xtzZHOgpHxuejpFRILuOm1NCkHnUW5zYyRF_BO2YyLC7sfxepzmYTmP6wKMwyPQhzzNZBrLFLxXZgZH2vietaAZlDjrzDX08-KhGM","d":"j4UwrI8rGb4y_gPDT3zgfaqjD9ZlMn8bU0b8mBQq5mHzYi-wnTdrnD9QOZbSjKlAbSn05Oa61jkBWZOI0CiQNxJq3EtyVGy-wOVYHgGympYIAftREGzUQhR54VqQQF4bOEIegfuLwmaeJczeuQumUyQkP50F0sT6750V7G1d7coi8fIn_fOeZZOJCeP4jkby0IevRhkibnbm6xPk9WFUeR1odRRFCIGWQa1mDwKrz1Wbvxo3r4tkqYpbg_U_QQeNlQDMfLJqgeBv5F8kLyMdoS7VqZOPKCMr7SDDJ9uRnWSWrmzCqmcDtIrw8-VvBWVYVmY8edQpjlCGNwNZBsOAsQ","e":"AQAB","use":"sig","kid":"4b0f0a50-b91b-4a6e-b5d8-8fcdcd1beaa0","qi":"F34XN3uJvS3vVsn-wT7FYMIR59JzKQuxFo7rMVaQ8V3ZpNoL3CV9-Md_zpXDU1OLDvKEsYS2BKVUhdMo0qQriUhILBKKZNIHMc0dCpnt007HrsGco2q7_eD4A3QMcvgcwwkXPT5UuEvxvO7Ted831ax1w5zjh7nt-BO-hC46M3A","dp":"1uUaC8n0Zm_-jp8aYTsROdU0ty18fZazMg3ed6GwNzDShNZhFaPDb_dKrA-KnNdJkBaBSOVQt1nYqz3l0Yh1YhldgglE2bWF4He8SX9mfv2fvaxvUedwv8LKDo2wtIEkai3s5Uy6HI1qt2Orq-nVk3flLoIemF22K7TOSUY2Pt0","dq":"cZiAnD3AOjYvF0c45kvu1CEoBXNAsMaLZ7nW9LQOJSmRgcVPJGk0iCQjzljVIz_9DVa_aljs6NIsnP_awWchsRika790VXiJH-SoCjgrRhnl-H6drkLsLJXy8--wrpABTH6AfgIKAIIJ-lhK6VFPvyheKYxTB08riureDeuYEAc","n":"vYchP-azmUsG-ai6IY0SO4XvlqcdvMxX1BqTRvZruFgdPQd2kJmPEjF2AfnUz7dwAtwWcYDFvGIW6qDUdjIkMHYInkAUogJzfoZ0BNZtNvNIUg5V2s67DsxKzlEZFbf3XeOvOGboh3NdY7Ixl5tOIgRJ4ykxIJhDdDqLkqjLVsVf-thWTS5uRND1drnr_gUsyptXxb4cJH_17OE-0FNf3XWCni5twVNxBI9dRV0BHXlzSbTg7TAAd-WgplLE_rbnV7NocfRblGJsoDjiR6ItajMzH4EIu1DvzYi7eUxaXLWNnQqBo-QNy4W4-BKBr11-V3w8dRf_60S4QRoEVx6J0Q"}
algorithm
RS256
2021-05-31 18:33:09 SUCCESS
SignIdTokenInvalid
Made the id_token signature invalid
id_token
eyJraWQiOiI0YjBmMGE1MC1iOTFiLTRhNmUtYjVkOC04ZmNkY2QxYmVhYTAiLCJhbGciOiJSUzI1NiJ9.eyJhdF9oYXNoIjoiRUJKQmx5WThpLW8wdHFkM3ZuRU5IZyIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoiMTIzNDU2NzgtaHlicmlkLXByb2ZpbGUtcGxhaW4tcHJpdmF0ZS1rZXktY2xpZW50aWQiLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvSW50dWl0X3BhdXRoX29wZW5pZF9oeWJyaWRfcHJvZmlsZV9wbGFuXzFcLyIsImV4cCI6MTYyMjQ4NjI4OSwibm9uY2UiOiJhd2IuNGZkNzZhNWUtNDIyNS00NmU2LWJhMjctNjY4Nzg4YTI5Zjc3IiwiaWF0IjoxNjIyNDg1OTg5fQ.6_IRo_KEQy5iBBKZk6b3O258qCj59Eu4fPlWq_KyIKN0KDQDUy26n9ADGYaLikT-nSlmmYCi5l3fVw3SGnu8UzSMi0F_lPJpdE8vhH0g89kRLjczpX-TKAXsgzoz4S8LYpm8H3GNi9ETkI14ABPRlZM4mHSOfXLgr-xf5M1prRAxTcrM3KvUO24Nw6g9TWtx3TZSwNVGX6na5DDQVzpv8XCvzM1P9vw-EcQMnHhBgD0Goo4RbExV052r8Q5419pk8eWUb9fLa8_-WGixDz_MDJh2fmcKKCnRu6i4SNhOEHoA6fwsq689jgPkyO-xUsVfrmVVVOs815g2hvxF3Czovw
2021-05-31 18:33:09 INFO
EncryptIdToken
Skipped evaluation due to missing required element: client id_token_encrypted_response_alg
path
id_token_encrypted_response_alg
mapped
object
client
2021-05-31 18:33:09 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
aDcBkN4vQ4bfV4V5JgcenwMkySjShum3noAH7CqfMgGzQ6Mh7J
token_type
Bearer
id_token
eyJraWQiOiI0YjBmMGE1MC1iOTFiLTRhNmUtYjVkOC04ZmNkY2QxYmVhYTAiLCJhbGciOiJSUzI1NiJ9.eyJhdF9oYXNoIjoiRUJKQmx5WThpLW8wdHFkM3ZuRU5IZyIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoiMTIzNDU2NzgtaHlicmlkLXByb2ZpbGUtcGxhaW4tcHJpdmF0ZS1rZXktY2xpZW50aWQiLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvSW50dWl0X3BhdXRoX29wZW5pZF9oeWJyaWRfcHJvZmlsZV9wbGFuXzFcLyIsImV4cCI6MTYyMjQ4NjI4OSwibm9uY2UiOiJhd2IuNGZkNzZhNWUtNDIyNS00NmU2LWJhMjctNjY4Nzg4YTI5Zjc3IiwiaWF0IjoxNjIyNDg1OTg5fQ.6_IRo_KEQy5iBBKZk6b3O258qCj59Eu4fPlWq_KyIKN0KDQDUy26n9ADGYaLikT-nSlmmYCi5l3fVw3SGnu8UzSMi0F_lPJpdE8vhH0g89kRLjczpX-TKAXsgzoz4S8LYpm8H3GNi9ETkI14ABPRlZM4mHSOfXLgr-xf5M1prRAxTcrM3KvUO24Nw6g9TWtx3TZSwNVGX6na5DDQVzpv8XCvzM1P9vw-EcQMnHhBgD0Goo4RbExV052r8Q5419pk8eWUb9fLa8_-WGixDz_MDJh2fmcKKCnRu6i4SNhOEHoA6fwsq689jgPkyO-xUsVfrmVVVOs815g2hvxF3Czovw
scope
openid phone profile email address offline_access
2021-05-31 18:33:09 OUTGOING
oidcc-client-test-invalid-sig-rs256
Response to HTTP request to test instance p9vhGTfdN5ntu3m
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "aDcBkN4vQ4bfV4V5JgcenwMkySjShum3noAH7CqfMgGzQ6Mh7J",
  "token_type": "Bearer",
  "id_token": "eyJraWQiOiI0YjBmMGE1MC1iOTFiLTRhNmUtYjVkOC04ZmNkY2QxYmVhYTAiLCJhbGciOiJSUzI1NiJ9.eyJhdF9oYXNoIjoiRUJKQmx5WThpLW8wdHFkM3ZuRU5IZyIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoiMTIzNDU2NzgtaHlicmlkLXByb2ZpbGUtcGxhaW4tcHJpdmF0ZS1rZXktY2xpZW50aWQiLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvSW50dWl0X3BhdXRoX29wZW5pZF9oeWJyaWRfcHJvZmlsZV9wbGFuXzFcLyIsImV4cCI6MTYyMjQ4NjI4OSwibm9uY2UiOiJhd2IuNGZkNzZhNWUtNDIyNS00NmU2LWJhMjctNjY4Nzg4YTI5Zjc3IiwiaWF0IjoxNjIyNDg1OTg5fQ.6_IRo_KEQy5iBBKZk6b3O258qCj59Eu4fPlWq_KyIKN0KDQDUy26n9ADGYaLikT-nSlmmYCi5l3fVw3SGnu8UzSMi0F_lPJpdE8vhH0g89kRLjczpX-TKAXsgzoz4S8LYpm8H3GNi9ETkI14ABPRlZM4mHSOfXLgr-xf5M1prRAxTcrM3KvUO24Nw6g9TWtx3TZSwNVGX6na5DDQVzpv8XCvzM1P9vw-EcQMnHhBgD0Goo4RbExV052r8Q5419pk8eWUb9fLa8_-WGixDz_MDJh2fmcKKCnRu6i4SNhOEHoA6fwsq689jgPkyO-xUsVfrmVVVOs815g2hvxF3Czovw",
  "scope": "openid phone profile email address offline_access"
}
outgoing_path
token
2021-05-31 18:33:09 INCOMING
oidcc-client-test-invalid-sig-rs256
Incoming HTTP request to test instance p9vhGTfdN5ntu3m
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "Apache-HttpClient/4.5.6 (Java/1.8.0_241)",
  "accept-encoding": "gzip,deflate",
  "x-ssl-cipher": "ECDHE-RSA-AES256-GCM-SHA384",
  "x-ssl-protocol": "TLSv1.2",
  "connection": "close",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net"
}
incoming_path
jwks
incoming_body_form_params
incoming_method
GET
incoming_body_json
incoming_query_string_params
{}
incoming_body
Jwks endpoint
2021-05-31 18:33:09 OUTGOING
oidcc-client-test-invalid-sig-rs256
Response to HTTP request to test instance p9vhGTfdN5ntu3m
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "4b0f0a50-b91b-4a6e-b5d8-8fcdcd1beaa0",
      "n": "vYchP-azmUsG-ai6IY0SO4XvlqcdvMxX1BqTRvZruFgdPQd2kJmPEjF2AfnUz7dwAtwWcYDFvGIW6qDUdjIkMHYInkAUogJzfoZ0BNZtNvNIUg5V2s67DsxKzlEZFbf3XeOvOGboh3NdY7Ixl5tOIgRJ4ykxIJhDdDqLkqjLVsVf-thWTS5uRND1drnr_gUsyptXxb4cJH_17OE-0FNf3XWCni5twVNxBI9dRV0BHXlzSbTg7TAAd-WgplLE_rbnV7NocfRblGJsoDjiR6ItajMzH4EIu1DvzYi7eUxaXLWNnQqBo-QNy4W4-BKBr11-V3w8dRf_60S4QRoEVx6J0Q"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "beccc197-2beb-44b5-8984-96f6d061feca",
      "n": "l-m6wkvbFxaxy5ajgMdsxwit-e-r_ANjy6rIGDHo2xdm-2HlE0FWWqCL1GL5r7GJV1aiyeiviXUb80Tif7pahjgRXV0GUQ7kvXRCmQEzg4LWt3CZq1jYtq2L6tGy_OjvnHIyk6lIqTijGKlL7KjMu66oCA81yZ5oiItZ_uLGS9LBvzjW3y26KSP8QI1jOP6wfLBvpbJ-Z_RnfxDwFrkgMKgqUIznMrH61YjMzSb_-EGw1dEDv8yzCvlaAFTBEpKSBx5aRXFCaBN_S59_UXPPX3BQH_UDnXl-NrV_JtSwzF1b_JVPKF9BHo8GMsCeRf7idtx8xIhVMtypnNKX1WdMgQ"
    },
    {
      "kty": "EC",
      "use": "sig",
      "crv": "P-256",
      "kid": "1ac1c00f-ff9a-4702-8e07-a1c21faaabba",
      "x": "OMV0raVikFEFpGQ-L4pcpCWmPzo9UVfdXPS_AWlkZPo",
      "y": "w7EGozWB-nQQaZkv5bpwHPMBpR_IMV1HvXgETPjwfC0"
    },
    {
      "kty": "EC",
      "use": "sig",
      "crv": "P-256",
      "kid": "002d1e45-9856-4ed8-b3a6-f77a1c776ada",
      "x": "vQqaTTxrKMXXGUkZHwVcYcG7tftOkN2Bi1mU5gVqfsw",
      "y": "29M85AMBIn2f5yVlrR5ur-YYUwxkkycP55ZLrPzUZA8"
    },
    {
      "kty": "EC",
      "use": "sig",
      "crv": "secp256k1",
      "kid": "eb4cd94d-33c1-492e-b839-b9a2808fdbff",
      "x": "l-ZynPiJ0TGd0vVjQJgUWOgDX3cC_pwdn6q9mtDuJ8E",
      "y": "YxrAtsf9fV_0b9lEh0x6RN1gEus3BkV4azaQAS3buBk"
    },
    {
      "kty": "OKP",
      "use": "sig",
      "crv": "Ed25519",
      "kid": "36e68b06-5f63-4ac6-8167-73e67b524ef3",
      "x": "IqgUE6wgdxedrPrl5KtQIOH6sHGReyO7dQYvGe5RFHE"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "c576d748-464e-4fb6-b153-deb5d8b7b306",
      "alg": "RSA-OAEP",
      "n": "k1p-nCCHMgcWZ96mGrgpuRD00LDrRpc_zcrYUUCXRFQm195IOWSKFXu8p3jvRFwDlEmqpjnX7s25bjQUdvuSYnYAFr-qcRbA4ZJ7aC2bWK9HRYSej3Wira1wzjZwTqAnkTQt4jJoFy_19S2QdFQd8xdSD_L4wUr7n1wlyXTQ-uEKZVqikdNmLSfHHFycXAxEQZGuQ5_b6vhtebToMgGslY7bu2e_cVbVoqlUml9R5UBSsDkHWXgCt9ZtMxhX1HfYApK6sMkTyqYRjTnvTw3VqVtF0MKAiS1ilw7l_e6BpZylvH4xO0shizzpXVmVMvUIGgICjPjOrHaSoY9APBuJaw"
    },
    {
      "kty": "EC",
      "use": "enc",
      "crv": "P-256",
      "kid": "ea12f06b-2155-4e00-b31b-96121cbfc8ca",
      "x": "5yekmamaFwQV8tHRLjsEZ9CPQoecAZ5cAtOpCD8IGMA",
      "y": "bE6Lf34FI5JBbvGO_hM2p4ScfutAAJMGolbRXqSERgY",
      "alg": "ECDH-ES"
    }
  ]
}
outgoing_path
jwks
2021-05-31 18:33:14 FINISHED
oidcc-client-test-invalid-sig-rs256
Test has run to completion
testmodule_result
PASSED
2021-05-31 18:34:05
TEST-RUNNER
Alias has now been claimed by another test
alias
Intuit_pauth_openid_hybrid_profile_plan_1
new_test_id
cUDmKMqkIikmrlL
Test Results