Test Summary

Test Results

Expand All Collapse All
All times are UTC
2021-12-16 19:18:59 INFO
TEST-RUNNER
Test instance wBVidr0t2MGeTMJ created
baseUrl
https://www.certification.openid.net/test/a/RP-Security-Test-PAN
variant
{
  "client_auth_type": "private_key_jwt",
  "fapi_auth_request_method": "pushed",
  "fapi_profile": "openbanking_brazil",
  "fapi_jarm_type": "oidc",
  "fapi_response_mode": "plain_response"
}
alias
RP-Security-Test-PAN
description
Teste de Segurança de RP do Ambiente de Homologação do PAN para o Open Banking
planId
TQoMgbFqkMMZ0
config
{
  "alias": "RP-Security-Test-PAN",
  "description": "Teste de Segurança de RP do Ambiente de Homologação do PAN para o Open Banking",
  "server": {
    "jwks": {
      "keys": [
        {
          "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
          "kty": "RSA",
          "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
          "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
          "e": "AQAB",
          "alg": "PS256",
          "use": "sig",
          "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
          "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
          "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
          "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
          "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
          "x5c": [
            "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
          ]
        },
        {
          "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
          "kty": "RSA",
          "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
          "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
          "e": "AQAB",
          "use": "enc",
          "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
          "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
          "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
          "alg": "RSA-OAEP",
          "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
          "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
        }
      ]
    }
  },
  "client": {
    "client_id": "SBSfBTOJMVQBBL848VGXI",
    "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
    "certificate": "-----BEGIN CERTIFICATE-----\nMIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz\nMjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct\nNjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j\nb20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk\nYWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ\ncml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ\nKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4\n9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r\niu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6\ni56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV\nCLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3\n5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC\nAtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO\nEUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA\noD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v\ncmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB\nBQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC\nD2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k\nATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz\nb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg\nb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g\nU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg\ncmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j\nZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5\nIGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0\ncDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s\naWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL\n8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs\nZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0\nQZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY\nYFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG\nOZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d\n-----END CERTIFICATE-----",
    "jwks": {
      "keys": [
        {
          "alg": "PS256",
          "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
          "kty": "RSA",
          "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
          "e": "AQAB"
        }
      ]
    }
  },
  "client2": {
    "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
    "id_token_encrypted_response_alg": "RSA-OAEP",
    "id_token_encrypted_response_enc": "A256GCM",
    "client_id": "Lk4dFn0ve0wnQiN37NSDR",
    "jwks": {
      "keys": [
        {
          "alg": "PS256",
          "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
          "kty": "RSA",
          "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
          "e": "AQAB"
        },
        {
          "kty": "RSA",
          "use": "enc",
          "alg": "PS256",
          "n": "xY64ckpxUTXk7Q9e_ulwxLogYEzJ7tZswwGt7EesKk8E_Sq9o4ybEq-tWL2l_h_Q38Y8MkyxPsiKQqzwXdb5npvtZ5fv-QF3u2eqryqWm3ialiWZtIG48ia__ApswN1JZUX_3YdrzwdxJjc-SeSR0eTXB21WvJ5DxhfX8aiU8p93oHP_K7nqjUAr241XNYK119KvDI0pVbaJuwXqWJvLXWnLLfWyZXCsuoMc0yU9yEeos2CkJlEyslNF37q2M_rv-52yrevzhJ_OJjxc2As-U2EpoKAOfhqa-sVSEGEaa-YApVNV-KmEE3nw-6T7sqBBvp7sbtXuKq8RoFaQkA2kzQ",
          "e": "AQAB",
          "kid": "5997c113bd799f7e61039be31353e4e5917c28a3536ee7d0f44d5bfbf301cc55"
        }
      ]
    },
    "certificate": "-----BEGIN CERTIFICATE-----\nMIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz\nMjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct\nNjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j\nb20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk\nYWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ\ncml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ\nKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4\n9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r\niu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6\ni56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV\nCLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3\n5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC\nAtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO\nEUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA\noD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v\ncmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB\nBQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC\nD2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k\nATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz\nb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg\nb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g\nU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg\ncmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j\nZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5\nIGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0\ncDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s\naWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL\n8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs\nZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0\nQZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY\nYFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG\nOZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d\n-----END CERTIFICATE-----"
  },
  "directory": {
    "keystore": "https://keystore.sandbox.directory.openbankingbrasil.org.br/"
  }
}
testName
fapi1-advanced-final-client-test-valid-aud-as-array
2021-12-16 19:18:59 SUCCESS
FAPIBrazilGenerateServerConfiguration
Created server configuration
server
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true
}
issuer
https://www.certification.openid.net/test/a/RP-Security-Test-PAN/
discoveryUrl
https://www.certification.openid.net/test/a/RP-Security-Test-PAN/.well-known/openid-configuration
2021-12-16 19:18:59 SUCCESS
LoadServerJWKs
Parsed public and private JWK sets
server_jwks
{
  "keys": [
    {
      "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
      "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
      "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
      "kty": "RSA",
      "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
      "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
      "alg": "PS256"
    },
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
server_encryption_keys
{
  "keys": [
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
server_public_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "alg": "PS256",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "alg": "RSA-OAEP",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
2021-12-16 19:18:59 SUCCESS
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2021-12-16 19:18:59
SetServerSigningAlgToPS256
Successfully set signing algorithm to PS256
2021-12-16 19:18:59
FAPIBrazilSetGrantTypesSupportedInServerConfiguration
Successfully set grant_types_supported
server
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ]
}
2021-12-16 19:18:59
AddClaimsParameterSupportedTrueToServerConfiguration
Successfully added claims_parameter_supported to server configuration
server
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true
}
2021-12-16 19:18:59
FAPIBrazilAddBrazilSpecificSettingsToServerConfiguration
Added open banking Brazil specific server settings
server
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ]
}
2021-12-16 19:18:59
SetTokenEndpointAuthMethodsSupportedToPrivateKeyJWTOnly
Changed token_endpoint_auth_methods_supported to private_key_jwt only in server configuration
server_configuration
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ]
}
2021-12-16 19:18:59
AddPushedAuthorizationRequestEndpointToServerConfig
Added pushed_authorization_request_endpoint to server configuration
endpoint
https://www.certification.openid.net/test/a/RP-Security-Test-PAN/par
2021-12-16 19:18:59
AddRequirePushedAuthorizationRequestsToServerConfig
Added require_pushed_authorization_requests to server configuration
value
true
2021-12-16 19:18:59 SUCCESS
AddResponseTypeCodeIdTokenToServerConfiguration
Added code id_token as response type supported
response_types_supported
[
  "code id_token"
]
2021-12-16 19:18:59 SUCCESS
FAPIBrazilAddTokenEndpointAuthSigningAlgValuesSupportedToServer
Set token_endpoint_auth_signing_alg_values_supported
values
[
  "PS256"
]
2021-12-16 19:18:59 SUCCESS
CheckServerConfiguration
Found required server configuration keys
required
[
  "authorization_endpoint",
  "token_endpoint",
  "issuer"
]
2021-12-16 19:18:59 SUCCESS
FAPIEnsureMinimumServerKeyLength
Validated minimum key lengths for server_jwks
server_jwks
{
  "keys": [
    {
      "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
      "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
      "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
      "kty": "RSA",
      "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
      "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
      "alg": "PS256"
    },
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
2021-12-16 19:18:59 SUCCESS
LoadUserInfo
Added user information
user_info
{
  "sub": "user-subject-1234531",
  "name": "Demo T. User",
  "email": "user@example.com",
  "email_verified": false
}
Verify configuration of first client
2021-12-16 19:18:59 SUCCESS
GetStaticClientConfiguration
Found a static client object
client_id
SBSfBTOJMVQBBL848VGXI
redirect_uri
https://api-openbanking-hml.bancopan.com.br/tpp/callback
certificate
-----BEGIN CERTIFICATE-----
MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz
MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct
NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j
b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk
YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ
cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4
9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r
iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6
i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV
CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3
5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC
AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO
EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA
oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v
cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB
BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC
D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k
ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz
b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg
b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g
U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg
cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j
ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5
IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0
cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s
aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL
8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs
ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0
QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY
YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG
OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks=
-----END CERTIFICATE-----
jwks
{
  "keys": [
    {
      "alg": "PS256",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "kty": "RSA",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
      "e": "AQAB"
    }
  ]
}
2021-12-16 19:18:59 SUCCESS
ValidateClientJWKsPublicPart
Valid client JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2021-12-16 19:18:59 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "alg": "PS256",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "kty": "RSA",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
      "e": "AQAB"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "alg": "PS256",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew"
    }
  ]
}
2021-12-16 19:18:59 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2021-12-16 19:18:59 SUCCESS
EnsureClientJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2021-12-16 19:18:59 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "alg": "PS256",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "kty": "RSA",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
      "e": "AQAB"
    }
  ]
}
Verify configuration of second client
2021-12-16 19:18:59 SUCCESS
GetStaticClient2Configuration
Found a static second client object
redirect_uri
https://api-openbanking-hml.bancopan.com.br/tpp/callback
id_token_encrypted_response_alg
RSA-OAEP
id_token_encrypted_response_enc
A256GCM
client_id
Lk4dFn0ve0wnQiN37NSDR
jwks
{
  "keys": [
    {
      "alg": "PS256",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "kty": "RSA",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
      "e": "AQAB"
    },
    {
      "kty": "RSA",
      "use": "enc",
      "alg": "PS256",
      "n": "xY64ckpxUTXk7Q9e_ulwxLogYEzJ7tZswwGt7EesKk8E_Sq9o4ybEq-tWL2l_h_Q38Y8MkyxPsiKQqzwXdb5npvtZ5fv-QF3u2eqryqWm3ialiWZtIG48ia__ApswN1JZUX_3YdrzwdxJjc-SeSR0eTXB21WvJ5DxhfX8aiU8p93oHP_K7nqjUAr241XNYK119KvDI0pVbaJuwXqWJvLXWnLLfWyZXCsuoMc0yU9yEeos2CkJlEyslNF37q2M_rv-52yrevzhJ_OJjxc2As-U2EpoKAOfhqa-sVSEGEaa-YApVNV-KmEE3nw-6T7sqBBvp7sbtXuKq8RoFaQkA2kzQ",
      "e": "AQAB",
      "kid": "5997c113bd799f7e61039be31353e4e5917c28a3536ee7d0f44d5bfbf301cc55"
    }
  ]
}
certificate
-----BEGIN CERTIFICATE-----
MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz
MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct
NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j
b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk
YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ
cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4
9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r
iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6
i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV
CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3
5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC
AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO
EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA
oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v
cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB
BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC
D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k
ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz
b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg
b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g
U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg
cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j
ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5
IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0
cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s
aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL
8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs
ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0
QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY
YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG
OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks=
-----END CERTIFICATE-----
2021-12-16 19:18:59 SUCCESS
ValidateClientJWKsPublicPart
Valid client JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2021-12-16 19:18:59 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "alg": "PS256",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "kty": "RSA",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
      "e": "AQAB"
    },
    {
      "kty": "RSA",
      "use": "enc",
      "alg": "PS256",
      "n": "xY64ckpxUTXk7Q9e_ulwxLogYEzJ7tZswwGt7EesKk8E_Sq9o4ybEq-tWL2l_h_Q38Y8MkyxPsiKQqzwXdb5npvtZ5fv-QF3u2eqryqWm3ialiWZtIG48ia__ApswN1JZUX_3YdrzwdxJjc-SeSR0eTXB21WvJ5DxhfX8aiU8p93oHP_K7nqjUAr241XNYK119KvDI0pVbaJuwXqWJvLXWnLLfWyZXCsuoMc0yU9yEeos2CkJlEyslNF37q2M_rv-52yrevzhJ_OJjxc2As-U2EpoKAOfhqa-sVSEGEaa-YApVNV-KmEE3nw-6T7sqBBvp7sbtXuKq8RoFaQkA2kzQ",
      "e": "AQAB",
      "kid": "5997c113bd799f7e61039be31353e4e5917c28a3536ee7d0f44d5bfbf301cc55"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "alg": "PS256",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "5997c113bd799f7e61039be31353e4e5917c28a3536ee7d0f44d5bfbf301cc55",
      "alg": "PS256",
      "n": "xY64ckpxUTXk7Q9e_ulwxLogYEzJ7tZswwGt7EesKk8E_Sq9o4ybEq-tWL2l_h_Q38Y8MkyxPsiKQqzwXdb5npvtZ5fv-QF3u2eqryqWm3ialiWZtIG48ia__ApswN1JZUX_3YdrzwdxJjc-SeSR0eTXB21WvJ5DxhfX8aiU8p93oHP_K7nqjUAr241XNYK119KvDI0pVbaJuwXqWJvLXWnLLfWyZXCsuoMc0yU9yEeos2CkJlEyslNF37q2M_rv-52yrevzhJ_OJjxc2As-U2EpoKAOfhqa-sVSEGEaa-YApVNV-KmEE3nw-6T7sqBBvp7sbtXuKq8RoFaQkA2kzQ"
    }
  ]
}
2021-12-16 19:18:59 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2021-12-16 19:18:59 SUCCESS
EnsureClientJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2021-12-16 19:18:59 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "alg": "PS256",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "kty": "RSA",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
      "e": "AQAB"
    },
    {
      "kty": "RSA",
      "use": "enc",
      "alg": "PS256",
      "n": "xY64ckpxUTXk7Q9e_ulwxLogYEzJ7tZswwGt7EesKk8E_Sq9o4ybEq-tWL2l_h_Q38Y8MkyxPsiKQqzwXdb5npvtZ5fv-QF3u2eqryqWm3ialiWZtIG48ia__ApswN1JZUX_3YdrzwdxJjc-SeSR0eTXB21WvJ5DxhfX8aiU8p93oHP_K7nqjUAr241XNYK119KvDI0pVbaJuwXqWJvLXWnLLfWyZXCsuoMc0yU9yEeos2CkJlEyslNF37q2M_rv-52yrevzhJ_OJjxc2As-U2EpoKAOfhqa-sVSEGEaa-YApVNV-KmEE3nw-6T7sqBBvp7sbtXuKq8RoFaQkA2kzQ",
      "e": "AQAB",
      "kid": "5997c113bd799f7e61039be31353e4e5917c28a3536ee7d0f44d5bfbf301cc55"
    }
  ]
}
2021-12-16 19:18:59
fapi1-advanced-final-client-test-valid-aud-as-array
Setup Done
2021-12-16 19:19:06 INCOMING
fapi1-advanced-final-client-test-valid-aud-as-array
Incoming HTTP request to test instance wBVidr0t2MGeTMJ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/RP-Security-Test-PAN/.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-16 19:19:06 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-16 19:19:06 OUTGOING
fapi1-advanced-final-client-test-valid-aud-as-array
Response to HTTP request to test instance wBVidr0t2MGeTMJ
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo",
    "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/par"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ],
  "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/par",
  "require_pushed_authorization_requests": true,
  "response_types_supported": [
    "code id_token"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256"
  ]
}
outgoing_path
.well-known/openid-configuration
2021-12-16 19:19:06 INCOMING
fapi1-advanced-final-client-test-valid-aud-as-array
Incoming HTTP request to test instance wBVidr0t2MGeTMJ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded",
  "accept-encoding": "gzip, deflate, br",
  "content-length": "1210",
  "connection": "close"
}
incoming_path
/test-mtls/a/RP-Security-Test-PAN/token
incoming_body_form_params
{
  "scope": "consents",
  "grant_type": "client_credentials",
  "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
  "client_id": "SBSfBTOJMVQBBL848VGXI",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNDYsImV4cCI6MTYzOTY4MjQwNiwianRpIjoiRnp0MkJ2ZlEwTEtSLTlEbGVuUTNzNVF4VmdaMkFCbnF4YUJscjItaWhKVSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.Ps6A5gOLzYmmdArOKMtKcnsDhSQq7-bD7tDkd68kgQu0AUMEppSBqxUNbADD6qAKewHoNWzKadPdsP4ZHXJDk82zR--o0j5a7ePEXf7yO6YOXgLXs121kSktolh2_MEpuQ-Lkz9G6zLPNHJ5boW4v_S6NaQWRMlTQzvx7cvSnhtiYcI8sQV3FKXOJ0TicK9gJmdIJbunJ0MBiSUY-OQmWvomBj8pfOkmu61mmBC6_K70NzDjYPrPCTd8yeTs07sgOoL0SvLSsv-wTsCjxfyvekw82U4DO0f2CZrHWKgDoGmoThjyYrqS6ctKNTIMRMzgh811q5T5eZfR14JvLCo86A",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
scope=consents&grant_type=client_credentials&redirect_uri=https%3A%2F%2Fapi-openbanking-hml.bancopan.com.br%2Ftpp%2Fcallback&client_id=SBSfBTOJMVQBBL848VGXI&client_assertion=eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNDYsImV4cCI6MTYzOTY4MjQwNiwianRpIjoiRnp0MkJ2ZlEwTEtSLTlEbGVuUTNzNVF4VmdaMkFCbnF4YUJscjItaWhKVSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.Ps6A5gOLzYmmdArOKMtKcnsDhSQq7-bD7tDkd68kgQu0AUMEppSBqxUNbADD6qAKewHoNWzKadPdsP4ZHXJDk82zR--o0j5a7ePEXf7yO6YOXgLXs121kSktolh2_MEpuQ-Lkz9G6zLPNHJ5boW4v_S6NaQWRMlTQzvx7cvSnhtiYcI8sQV3FKXOJ0TicK9gJmdIJbunJ0MBiSUY-OQmWvomBj8pfOkmu61mmBC6_K70NzDjYPrPCTd8yeTs07sgOoL0SvLSsv-wTsCjxfyvekw82U4DO0f2CZrHWKgDoGmoThjyYrqS6ctKNTIMRMzgh811q5T5eZfR14JvLCo86A&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2021-12-16 19:19:06 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2021-12-16 19:19:06 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz\nMjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct\nNjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j\nb20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk\nYWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ\ncml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ\nKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4\n9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r\niu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6\ni56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV\nCLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3\n5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC\nAtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO\nEUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA\noD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v\ncmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB\nBQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC\nD2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k\nATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz\nb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg\nb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g\nU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg\ncmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j\nZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5\nIGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0\ncDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s\naWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL\n8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs\nZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0\nQZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY\nYFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG\nOZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,UID\u003dac60fe65-58ca-44c3-9352-6f556c5cb98e,2.5.4.5\u003d#130e3539323835343131303030313133,CN\u003dbancopan.com.br,OU\u003db6a214c7-6332-5a41-8464-a281fb9a4ca0,O\u003dBANCO PAN,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "bancopan.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2021-12-16 19:19:06 SUCCESS
CheckForClientCertificate
Found client certificate
2021-12-16 19:19:06 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz
MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct
NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j
b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk
YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ
cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4
9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r
iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6
i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV
CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3
5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC
AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO
EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA
oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v
cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB
BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC
D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k
ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz
b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg
b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g
U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg
cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j
ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5
IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0
cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s
aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL
8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs
ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0
QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY
YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG
OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks=
-----END CERTIFICATE-----
2021-12-16 19:19:06 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNDYsImV4cCI6MTYzOTY4MjQwNiwianRpIjoiRnp0MkJ2ZlEwTEtSLTlEbGVuUTNzNVF4VmdaMkFCbnF4YUJscjItaWhKVSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.Ps6A5gOLzYmmdArOKMtKcnsDhSQq7-bD7tDkd68kgQu0AUMEppSBqxUNbADD6qAKewHoNWzKadPdsP4ZHXJDk82zR--o0j5a7ePEXf7yO6YOXgLXs121kSktolh2_MEpuQ-Lkz9G6zLPNHJ5boW4v_S6NaQWRMlTQzvx7cvSnhtiYcI8sQV3FKXOJ0TicK9gJmdIJbunJ0MBiSUY-OQmWvomBj8pfOkmu61mmBC6_K70NzDjYPrPCTd8yeTs07sgOoL0SvLSsv-wTsCjxfyvekw82U4DO0f2CZrHWKgDoGmoThjyYrqS6ctKNTIMRMzgh811q5T5eZfR14JvLCo86A",
  "header": {
    "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "SBSfBTOJMVQBBL848VGXI",
    "aud": [
      "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
      "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
      "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token"
    ],
    "iss": "SBSfBTOJMVQBBL848VGXI",
    "exp": 1639682406,
    "iat": 1639682346,
    "jti": "Fzt2BvfQ0LKR-9DlenQ3s5QxVgZ2ABnqxaBlr2-ihJU"
  }
}
2021-12-16 19:19:06
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2021-12-16 19:19:06 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNDYsImV4cCI6MTYzOTY4MjQwNiwianRpIjoiRnp0MkJ2ZlEwTEtSLTlEbGVuUTNzNVF4VmdaMkFCbnF4YUJscjItaWhKVSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.Ps6A5gOLzYmmdArOKMtKcnsDhSQq7-bD7tDkd68kgQu0AUMEppSBqxUNbADD6qAKewHoNWzKadPdsP4ZHXJDk82zR--o0j5a7ePEXf7yO6YOXgLXs121kSktolh2_MEpuQ-Lkz9G6zLPNHJ5boW4v_S6NaQWRMlTQzvx7cvSnhtiYcI8sQV3FKXOJ0TicK9gJmdIJbunJ0MBiSUY-OQmWvomBj8pfOkmu61mmBC6_K70NzDjYPrPCTd8yeTs07sgOoL0SvLSsv-wTsCjxfyvekw82U4DO0f2CZrHWKgDoGmoThjyYrqS6ctKNTIMRMzgh811q5T5eZfR14JvLCo86A
2021-12-16 19:19:06 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-12-16 19:19:06 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2021-12-16 19:19:06 SUCCESS
FAPIBrazilExtractRequestedScopeFromClientCredentialsGrant
Found 'consents' scope in request
actual
[
  "consents"
]
expected
consents
2021-12-16 19:19:06 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
HYWmMc34LzSCu0reNR3nUCDNevhyBxAlPTj3ZwGLikRNNbNEk5
2021-12-16 19:19:06 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
HYWmMc34LzSCu0reNR3nUCDNevhyBxAlPTj3ZwGLikRNNbNEk5
token_type
Bearer
2021-12-16 19:19:06
CopyAccessTokenToClientCredentialsField
Condition ran but did not log anything
2021-12-16 19:19:06 OUTGOING
fapi1-advanced-final-client-test-valid-aud-as-array
Response to HTTP request to test instance wBVidr0t2MGeTMJ
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "HYWmMc34LzSCu0reNR3nUCDNevhyBxAlPTj3ZwGLikRNNbNEk5",
  "token_type": "Bearer"
}
outgoing_path
token
2021-12-16 19:19:06 INCOMING
fapi1-advanced-final-client-test-valid-aud-as-array
Incoming HTTP request to test instance wBVidr0t2MGeTMJ
incoming_headers
{
  "host": "www.certification.openid.net",
  "accept": "application/json, text/plain, */*",
  "content-type": "application/json",
  "authorization": "Bearer HYWmMc34LzSCu0reNR3nUCDNevhyBxAlPTj3ZwGLikRNNbNEk5",
  "user-agent": "axios/0.21.4",
  "content-length": "261",
  "connection": "close"
}
incoming_path
/test-mtls/a/RP-Security-Test-PAN/consents/v1/consents
incoming_body_form_params
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks= -----END CERTIFICATE-----
incoming_body_json
{
  "data": {
    "loggedUser": {
      "document": {
        "identification": "44257214899",
        "rel": "CPF"
      }
    },
    "permissions": [
      "RESOURCES_READ",
      "ACCOUNTS_READ",
      "ACCOUNTS_TRANSACTIONS_READ",
      "ACCOUNTS_OVERDRAFT_LIMITS_READ",
      "ACCOUNTS_BALANCES_READ"
    ],
    "expirationDateTime": "2022-08-21T08:30:00Z"
  }
}
incoming_query_string_params
{}
incoming_body
{"data":{"loggedUser":{"document":{"identification":"44257214899","rel":"CPF"}},"permissions":["RESOURCES_READ","ACCOUNTS_READ","ACCOUNTS_TRANSACTIONS_READ","ACCOUNTS_OVERDRAFT_LIMITS_READ","ACCOUNTS_BALANCES_READ"],"expirationDateTime":"2022-08-21T08:30:00Z"}}
2021-12-16 19:19:06 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
New consent endpoint
2021-12-16 19:19:06 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz\nMjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct\nNjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j\nb20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk\nYWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ\ncml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ\nKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4\n9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r\niu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6\ni56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV\nCLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3\n5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC\nAtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO\nEUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA\noD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v\ncmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB\nBQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC\nD2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k\nATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz\nb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg\nb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g\nU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg\ncmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j\nZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5\nIGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0\ncDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s\naWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL\n8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs\nZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0\nQZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY\nYFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG\nOZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,UID\u003dac60fe65-58ca-44c3-9352-6f556c5cb98e,2.5.4.5\u003d#130e3539323835343131303030313133,CN\u003dbancopan.com.br,OU\u003db6a214c7-6332-5a41-8464-a281fb9a4ca0,O\u003dBANCO PAN,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "bancopan.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2021-12-16 19:19:06 SUCCESS
CheckForClientCertificate
Found client certificate
2021-12-16 19:19:06 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz
MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct
NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j
b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk
YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ
cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4
9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r
iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6
i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV
CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3
5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC
AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO
EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA
oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v
cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB
BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC
D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k
ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz
b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg
b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g
U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg
cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j
ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5
IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0
cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s
aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL
8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs
ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0
QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY
YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG
OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks=
-----END CERTIFICATE-----
2021-12-16 19:19:06 SUCCESS
EnsureIncomingRequestMethodIsPost
Client correctly used http POST method
2021-12-16 19:19:06 SUCCESS
EnsureBearerAccessTokenNotInParams
Client correctly did not send access token in query parameters or form body
2021-12-16 19:19:06 SUCCESS
ExtractBearerAccessTokenFromHeader
Found access token on incoming request
access_token
HYWmMc34LzSCu0reNR3nUCDNevhyBxAlPTj3ZwGLikRNNbNEk5
2021-12-16 19:19:06 SUCCESS
RequireBearerClientCredentialsAccessToken
Found access token in request
actual
HYWmMc34LzSCu0reNR3nUCDNevhyBxAlPTj3ZwGLikRNNbNEk5
2021-12-16 19:19:06 INFO
ExtractFapiDateHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-auth-date
path
headers.x-fapi-auth-date
mapped
object
incoming_request
2021-12-16 19:19:06 INFO
ExtractFapiIpAddressHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-customer-ip-address
path
headers.x-fapi-customer-ip-address
mapped
object
incoming_request
2021-12-16 19:19:06 INFO
ExtractFapiInteractionIdHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-interaction-id
path
headers.x-fapi-interaction-id
mapped
object
incoming_request
2021-12-16 19:19:06 SUCCESS
FAPIBrazilEnsureClientCredentialsScopeContainedConsents
The token request which was used to obtain the access token contained 'consents' scope
actual
[
  "consents"
]
2021-12-16 19:19:06
FAPIBrazilExtractConsentRequest
Condition ran but did not log anything
2021-12-16 19:19:06 SUCCESS
CreateFapiInteractionIdIfNeeded
Created new FAPI interaction ID
fapi_interaction_id
8830f113-bb0f-4e35-907d-9308105c3445
2021-12-16 19:19:06 SUCCESS
FAPIBrazilGenerateNewConsentResponse
Created consent response
headers
{
  "x-fapi-interaction-id": "8830f113-bb0f-4e35-907d-9308105c3445"
}
consentId
urn:conformance.oidf:oypnoNOgsO
consent_response
{
  "data": {
    "consentId": "urn:conformance.oidf:oypnoNOgsO",
    "creationDateTime": "2021-12-16T19:19:06Z",
    "status": "AWAITING_AUTHORISATION",
    "statusUpdateDateTime": "2021-12-16T19:19:06Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2021-12-16T21:19:06Z",
    "transactionFromDateTime": "2021-12-16T19:14:06Z",
    "transactionToDateTime": "2021-12-16T21:19:06Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/RP-Security-Test-PANconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2021-12-16T19:19:06Z"
  }
}
2021-12-16 19:19:06
ClearAccessTokenFromRequest
Condition ran but did not log anything
2021-12-16 19:19:06 OUTGOING
fapi1-advanced-final-client-test-valid-aud-as-array
Response to HTTP request to test instance wBVidr0t2MGeTMJ
outgoing_status_code
201
outgoing_headers
{
  "x-fapi-interaction-id": [
    "8830f113-bb0f-4e35-907d-9308105c3445"
  ]
}
outgoing_body
{
  "data": {
    "consentId": "urn:conformance.oidf:oypnoNOgsO",
    "creationDateTime": "2021-12-16T19:19:06Z",
    "status": "AWAITING_AUTHORISATION",
    "statusUpdateDateTime": "2021-12-16T19:19:06Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2021-12-16T21:19:06Z",
    "transactionFromDateTime": "2021-12-16T19:14:06Z",
    "transactionToDateTime": "2021-12-16T21:19:06Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/RP-Security-Test-PANconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2021-12-16T19:19:06Z"
  }
}
outgoing_path
consents/v1/consents
2021-12-16 19:19:07 INCOMING
fapi1-advanced-final-client-test-valid-aud-as-array
Incoming HTTP request to test instance wBVidr0t2MGeTMJ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/RP-Security-Test-PAN/.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-16 19:19:07 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-16 19:19:07 OUTGOING
fapi1-advanced-final-client-test-valid-aud-as-array
Response to HTTP request to test instance wBVidr0t2MGeTMJ
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo",
    "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/par"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ],
  "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/par",
  "require_pushed_authorization_requests": true,
  "response_types_supported": [
    "code id_token"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256"
  ]
}
outgoing_path
.well-known/openid-configuration
2021-12-16 19:19:07 INCOMING
fapi1-advanced-final-client-test-valid-aud-as-array
Incoming HTTP request to test instance wBVidr0t2MGeTMJ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/RP-Security-Test-PAN/jwks
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-16 19:19:07 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-16 19:19:07 OUTGOING
fapi1-advanced-final-client-test-valid-aud-as-array
Response to HTTP request to test instance wBVidr0t2MGeTMJ
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "alg": "PS256",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "alg": "RSA-OAEP",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
outgoing_path
jwks
2021-12-16 19:19:07 INCOMING
fapi1-advanced-final-client-test-valid-aud-as-array
Incoming HTTP request to test instance wBVidr0t2MGeTMJ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded",
  "accept-encoding": "gzip, deflate, br",
  "content-length": "3489",
  "connection": "close"
}
incoming_path
/test-mtls/a/RP-Security-Test-PAN/par
incoming_body_form_params
{
  "request": "eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZHQ00iLCJjdHkiOiJvYXV0aC1hdXRoei1yZXErand0Iiwia2lkIjoiMGZlNTAyZGQtMTRmMC00ZjQ1LTgwZjktZmViOWEyMTZmOTk2In0.mXRRqR6nCGrFM2QVi58M6ScZ95V4l-2XApBeN3bwrUxr-d-eAcGQudMR5smkE6lUAoRsfx0XIKOFm6RgaAkQrn8ZZm1bMEITaAdiVS2JfbbEpQ0zFFWxewwJvfBoKUacPcI-qYyd5iyLJYjpzm9pKgEn5ghAy8MVcWrO-4-iQhiBEw5pTpJUw-IlQu-kw8oQ-IjR1ieM8eUeZkIFztbq5Q3BWpESceJFF7oWanQ1fUjv5-ZBIqotZGrKmQ7kkYPk9O52_1BAp_0sfUQvHvucNLscYzbQgldZ_A5vnc1UKZVlrOeKlsvX9g_bm50RMwmyVPSBoYuoqu--Jvjhg1iWMg.oDtKswo6TFvq5PPj.dcxPQdFPtBlQEdf0AElvm4hf4JoNxwfNMRt6QUey41EdHnvwbmqGdtevzkyvOMY0yb55kWEyKv1nVBDGZ4BSDo9nbeGVvWLCo5W8CKIKqbnwFmj5PkIKH9IfiNshoL9V8KGLn-NaqZf-f2VMVJcRrzwnEho1I9L8abo6qUQBPgRcrQjdO6D0kEf7oma_IdWtB5_bOtg69lqfhr-qr77ZGookk2ZNohwsapR-y75QBzKvzF7XFbDNUX9JBti_yI4c0ShqbweP2XezJllJkshGnfLlZwlTyxrd1UQlf9x0Jcl6wxJnfiKQ6kSH1iCcJ7KqikvCuZNbxPVYxt2ei4PVVFU3GhVbQv1w4p8LGcFd8BTnyNnX-eBtEQWg8PY_jQWzHmLrPvPkd8Bsxe1WpgvcCU19X17KulgtKQDZOV_uSYV0qQ9RNwW1jbiKb23aWu_XHHmbOLvIDydpCZkhCcyzXLKQMKj5nyRkJGmL6nsNUXUi0LcXPr1sE03aJGClQdDqa4pmhUbDl1PYfWAzxOblFldhUbKe6vbmanOqnwFBMyNnI5Z_W_kjo5fVL9FcuR8mq54h_l7k7daxPjJbbtxpAe3DoEko4QXeYnVCpjkg7rqIjj2oat-mt-alZXD0QjvlezlIOw8hUDJ59RsNdQ3Z5f6K1w5gilY_2zGyEFc0lVxqs7zKz0IoaqXFNY2LPsjU0X3BgmiIKRYNGajkK41KZfaqsfV6bvLwRiWzHsmL5TYSb0pmL0VMKUb7OenI-UFV3UHTfNdnNIbsuJmRu9LvR0wXlfzmc5WGvFnC8A3DmQ661XwUzZaH1TUyLpqnJ0toKotQwM_3wnuwtEBKg65llewO4FzucenK0m4AlkUn5rZB75rbD-pC0lCNELxz9S3KEpU5r38WidAMUKerfV7Dtu7kKOzkw0RJKEwrrHpTblre0ab0SdzAFJkdiLVoRn2noGKe9FRG8rmOCQHv6QvOAvi0QS1lGN9wVgkcdTArpDw8J_QPSkn1qBGVo3Int1r-4vUpAmtkmn1KskcjuuHpKwNqXHbBjNsrM4_sXW1vSUJu2j4XEvAtSPoVp1AFhTku4K9m-bWm035QLbwNoxwy4Rhusj1YQmvEenJQ8YBYJX7Yi9gK8O0WR_gptDqnncsT0ho4cncz2QOCGc4KfNMX4yPu-B2CiMRjIB4hiRtGaTJ7vniyuH5zQjDK2VebOMd9G88K1s3FckdJxTNe7ZnjeFgh6Kdy-AHno8RxQaYOa3AbszmGH1kiWajt_69aMhzlO5GqVRXEZFYLtaswFFUSPiqdzEvS_e_pHnoUjHXAU7N6zW5odmU3pUcB9ZvL5j-QHQkAluGFmvBUlGAJd5vWJqIR8VNdQupc4DW5FGF3iXJup6OCGPQ49nD7dPfJt9JagQYJGIAnLVsR-eZ95jULruICyJjPUNLfsMgDwuDObwkfEM47HoqriPJyI_KpyCQHIt1FqCSaatOv66HrDVz84pHLWzWeYvBlDtF-T1f9RipyDZBRiQqScN5nCt60h8by8y6sISgWqUvcDAWf3tDR6SPIq2BW8SxVMLeXb5CGVsZHHwOqM0T1FgZqKyUv5b0V_ou61wcUz09fHOm89pWKXNwPfUz5_E34_DpCB_EWht542EVT_GB23JrmYHe5IFlzt_QriC7uWnfZr8kFL8gViejN5Zu8hCq8wq5CTdba2vSLvBH9MpICtMgjMW-71eFHkHrmyCRk2L9kp-vXSwyvxd1TBIQBqY7P8k7HfTK9CsoBJufFjHixQZ_3kT8F2IKEGeREMMzkOAUkPLW4cz0jme3j6eheFq3jQ89lPiELqvTy8K7eVsjEVWStkTl-KOqoeoYfWYlY-T9m.QcZt3JxL8EBAslgWJ7a_6w",
  "client_id": "SBSfBTOJMVQBBL848VGXI",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNDcsImV4cCI6MTYzOTY4MjQwNywianRpIjoiRTRxTExmT3JOMkUzNXlXMjdkdHBQUFVYMnNJakxFcW92cVBUMGJkR0VpOCIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.lisMc60Rd_gG-QnTlcvRtbdekWuWn_8aEB1IeUre9ezNclNWtGsNGkP5o8HA0pJF7VMAtcYbI0TnpM3d_Ja5xaag3lwsBsR9gd8JiGDX4oFOAOfqmxu0_Y8fmOUQkQGWAQDp8GVhcMkV5TE37ENxqGRf2d8jX3L38zJdWXVzANF5aLHoqeRlufYGVxaB2Q4wRMWD_cq-sFZDaxTzboBu_KvkaocCV3fGVZ2gAOWFKJBQxE7FgBJDIfnDtdEH35yZg6UNoy7GFakJt57bEF3PCfFYwr_xnMyXLsnWdwS7Ta9ucFqt3bkAqIctUQuyxw522sjrIjYqlTI61GR708PLMQ",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
request=eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZHQ00iLCJjdHkiOiJvYXV0aC1hdXRoei1yZXErand0Iiwia2lkIjoiMGZlNTAyZGQtMTRmMC00ZjQ1LTgwZjktZmViOWEyMTZmOTk2In0.mXRRqR6nCGrFM2QVi58M6ScZ95V4l-2XApBeN3bwrUxr-d-eAcGQudMR5smkE6lUAoRsfx0XIKOFm6RgaAkQrn8ZZm1bMEITaAdiVS2JfbbEpQ0zFFWxewwJvfBoKUacPcI-qYyd5iyLJYjpzm9pKgEn5ghAy8MVcWrO-4-iQhiBEw5pTpJUw-IlQu-kw8oQ-IjR1ieM8eUeZkIFztbq5Q3BWpESceJFF7oWanQ1fUjv5-ZBIqotZGrKmQ7kkYPk9O52_1BAp_0sfUQvHvucNLscYzbQgldZ_A5vnc1UKZVlrOeKlsvX9g_bm50RMwmyVPSBoYuoqu--Jvjhg1iWMg.oDtKswo6TFvq5PPj.dcxPQdFPtBlQEdf0AElvm4hf4JoNxwfNMRt6QUey41EdHnvwbmqGdtevzkyvOMY0yb55kWEyKv1nVBDGZ4BSDo9nbeGVvWLCo5W8CKIKqbnwFmj5PkIKH9IfiNshoL9V8KGLn-NaqZf-f2VMVJcRrzwnEho1I9L8abo6qUQBPgRcrQjdO6D0kEf7oma_IdWtB5_bOtg69lqfhr-qr77ZGookk2ZNohwsapR-y75QBzKvzF7XFbDNUX9JBti_yI4c0ShqbweP2XezJllJkshGnfLlZwlTyxrd1UQlf9x0Jcl6wxJnfiKQ6kSH1iCcJ7KqikvCuZNbxPVYxt2ei4PVVFU3GhVbQv1w4p8LGcFd8BTnyNnX-eBtEQWg8PY_jQWzHmLrPvPkd8Bsxe1WpgvcCU19X17KulgtKQDZOV_uSYV0qQ9RNwW1jbiKb23aWu_XHHmbOLvIDydpCZkhCcyzXLKQMKj5nyRkJGmL6nsNUXUi0LcXPr1sE03aJGClQdDqa4pmhUbDl1PYfWAzxOblFldhUbKe6vbmanOqnwFBMyNnI5Z_W_kjo5fVL9FcuR8mq54h_l7k7daxPjJbbtxpAe3DoEko4QXeYnVCpjkg7rqIjj2oat-mt-alZXD0QjvlezlIOw8hUDJ59RsNdQ3Z5f6K1w5gilY_2zGyEFc0lVxqs7zKz0IoaqXFNY2LPsjU0X3BgmiIKRYNGajkK41KZfaqsfV6bvLwRiWzHsmL5TYSb0pmL0VMKUb7OenI-UFV3UHTfNdnNIbsuJmRu9LvR0wXlfzmc5WGvFnC8A3DmQ661XwUzZaH1TUyLpqnJ0toKotQwM_3wnuwtEBKg65llewO4FzucenK0m4AlkUn5rZB75rbD-pC0lCNELxz9S3KEpU5r38WidAMUKerfV7Dtu7kKOzkw0RJKEwrrHpTblre0ab0SdzAFJkdiLVoRn2noGKe9FRG8rmOCQHv6QvOAvi0QS1lGN9wVgkcdTArpDw8J_QPSkn1qBGVo3Int1r-4vUpAmtkmn1KskcjuuHpKwNqXHbBjNsrM4_sXW1vSUJu2j4XEvAtSPoVp1AFhTku4K9m-bWm035QLbwNoxwy4Rhusj1YQmvEenJQ8YBYJX7Yi9gK8O0WR_gptDqnncsT0ho4cncz2QOCGc4KfNMX4yPu-B2CiMRjIB4hiRtGaTJ7vniyuH5zQjDK2VebOMd9G88K1s3FckdJxTNe7ZnjeFgh6Kdy-AHno8RxQaYOa3AbszmGH1kiWajt_69aMhzlO5GqVRXEZFYLtaswFFUSPiqdzEvS_e_pHnoUjHXAU7N6zW5odmU3pUcB9ZvL5j-QHQkAluGFmvBUlGAJd5vWJqIR8VNdQupc4DW5FGF3iXJup6OCGPQ49nD7dPfJt9JagQYJGIAnLVsR-eZ95jULruICyJjPUNLfsMgDwuDObwkfEM47HoqriPJyI_KpyCQHIt1FqCSaatOv66HrDVz84pHLWzWeYvBlDtF-T1f9RipyDZBRiQqScN5nCt60h8by8y6sISgWqUvcDAWf3tDR6SPIq2BW8SxVMLeXb5CGVsZHHwOqM0T1FgZqKyUv5b0V_ou61wcUz09fHOm89pWKXNwPfUz5_E34_DpCB_EWht542EVT_GB23JrmYHe5IFlzt_QriC7uWnfZr8kFL8gViejN5Zu8hCq8wq5CTdba2vSLvBH9MpICtMgjMW-71eFHkHrmyCRk2L9kp-vXSwyvxd1TBIQBqY7P8k7HfTK9CsoBJufFjHixQZ_3kT8F2IKEGeREMMzkOAUkPLW4cz0jme3j6eheFq3jQ89lPiELqvTy8K7eVsjEVWStkTl-KOqoeoYfWYlY-T9m.QcZt3JxL8EBAslgWJ7a_6w&client_id=SBSfBTOJMVQBBL848VGXI&client_assertion=eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNDcsImV4cCI6MTYzOTY4MjQwNywianRpIjoiRTRxTExmT3JOMkUzNXlXMjdkdHBQUFVYMnNJakxFcW92cVBUMGJkR0VpOCIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.lisMc60Rd_gG-QnTlcvRtbdekWuWn_8aEB1IeUre9ezNclNWtGsNGkP5o8HA0pJF7VMAtcYbI0TnpM3d_Ja5xaag3lwsBsR9gd8JiGDX4oFOAOfqmxu0_Y8fmOUQkQGWAQDp8GVhcMkV5TE37ENxqGRf2d8jX3L38zJdWXVzANF5aLHoqeRlufYGVxaB2Q4wRMWD_cq-sFZDaxTzboBu_KvkaocCV3fGVZ2gAOWFKJBQxE7FgBJDIfnDtdEH35yZg6UNoy7GFakJt57bEF3PCfFYwr_xnMyXLsnWdwS7Ta9ucFqt3bkAqIctUQuyxw522sjrIjYqlTI61GR708PLMQ&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2021-12-16 19:19:07 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
PAR endpoint
2021-12-16 19:19:07 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz\nMjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct\nNjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j\nb20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk\nYWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ\ncml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ\nKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4\n9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r\niu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6\ni56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV\nCLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3\n5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC\nAtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO\nEUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA\noD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v\ncmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB\nBQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC\nD2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k\nATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz\nb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg\nb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g\nU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg\ncmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j\nZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5\nIGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0\ncDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s\naWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL\n8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs\nZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0\nQZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY\nYFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG\nOZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,UID\u003dac60fe65-58ca-44c3-9352-6f556c5cb98e,2.5.4.5\u003d#130e3539323835343131303030313133,CN\u003dbancopan.com.br,OU\u003db6a214c7-6332-5a41-8464-a281fb9a4ca0,O\u003dBANCO PAN,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "bancopan.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2021-12-16 19:19:07 SUCCESS
CheckForClientCertificate
Found client certificate
2021-12-16 19:19:07 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz
MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct
NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j
b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk
YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ
cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4
9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r
iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6
i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV
CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3
5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC
AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO
EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA
oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v
cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB
BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC
D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k
ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz
b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg
b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g
U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg
cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j
ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5
IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0
cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s
aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL
8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs
ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0
QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY
YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG
OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks=
-----END CERTIFICATE-----
2021-12-16 19:19:07 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNDcsImV4cCI6MTYzOTY4MjQwNywianRpIjoiRTRxTExmT3JOMkUzNXlXMjdkdHBQUFVYMnNJakxFcW92cVBUMGJkR0VpOCIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.lisMc60Rd_gG-QnTlcvRtbdekWuWn_8aEB1IeUre9ezNclNWtGsNGkP5o8HA0pJF7VMAtcYbI0TnpM3d_Ja5xaag3lwsBsR9gd8JiGDX4oFOAOfqmxu0_Y8fmOUQkQGWAQDp8GVhcMkV5TE37ENxqGRf2d8jX3L38zJdWXVzANF5aLHoqeRlufYGVxaB2Q4wRMWD_cq-sFZDaxTzboBu_KvkaocCV3fGVZ2gAOWFKJBQxE7FgBJDIfnDtdEH35yZg6UNoy7GFakJt57bEF3PCfFYwr_xnMyXLsnWdwS7Ta9ucFqt3bkAqIctUQuyxw522sjrIjYqlTI61GR708PLMQ",
  "header": {
    "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "SBSfBTOJMVQBBL848VGXI",
    "aud": [
      "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
      "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
      "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token"
    ],
    "iss": "SBSfBTOJMVQBBL848VGXI",
    "exp": 1639682407,
    "iat": 1639682347,
    "jti": "E4qLLfOrN2E35yW27dtpPPUX2sIjLEqovqPT0bdGEi8"
  }
}
2021-12-16 19:19:07
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2021-12-16 19:19:07 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNDcsImV4cCI6MTYzOTY4MjQwNywianRpIjoiRTRxTExmT3JOMkUzNXlXMjdkdHBQUFVYMnNJakxFcW92cVBUMGJkR0VpOCIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.lisMc60Rd_gG-QnTlcvRtbdekWuWn_8aEB1IeUre9ezNclNWtGsNGkP5o8HA0pJF7VMAtcYbI0TnpM3d_Ja5xaag3lwsBsR9gd8JiGDX4oFOAOfqmxu0_Y8fmOUQkQGWAQDp8GVhcMkV5TE37ENxqGRf2d8jX3L38zJdWXVzANF5aLHoqeRlufYGVxaB2Q4wRMWD_cq-sFZDaxTzboBu_KvkaocCV3fGVZ2gAOWFKJBQxE7FgBJDIfnDtdEH35yZg6UNoy7GFakJt57bEF3PCfFYwr_xnMyXLsnWdwS7Ta9ucFqt3bkAqIctUQuyxw522sjrIjYqlTI61GR708PLMQ
2021-12-16 19:19:07 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-12-16 19:19:07 SUCCESS
ValidateClientAssertionClaimsForPAREndpoint
Client Assertion passed all validation checks
2021-12-16 19:19:07 SUCCESS
ExtractRequestObjectFromPAREndpointRequest
Parsed request object
request_object
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6Im9hdXRoLWF1dGh6LXJlcStqd3QiLCJraWQiOiI1Z1lISUhidHcwVUI0QndqdHFVbmh0Rk42V3RoRVcybWRYN2RmVUJRSElJIn0.eyJzY29wZSI6Im9wZW5pZCBjb25zZW50OnVybjpjb25mb3JtYW5jZS5vaWRmOm95cG5vTk9nc08gYWNjb3VudHMgcmVzb3VyY2VzIiwicmVzcG9uc2VfdHlwZSI6ImNvZGUgaWRfdG9rZW4iLCJyZWRpcmVjdF91cmkiOiJodHRwczovL2FwaS1vcGVuYmFua2luZy1obWwuYmFuY29wYW4uY29tLmJyL3RwcC9jYWxsYmFjayIsImNvZGVfY2hhbGxlbmdlIjoiVHAzVDRIb054TmxlWS1PVEthQXBBcUZJZjJvRTNIdTR1LXI3c1p5bmNocyIsImNvZGVfY2hhbGxlbmdlX21ldGhvZCI6IlMyNTYiLCJyZXNwb25zZV9tb2RlIjoiZnJhZ21lbnQiLCJzdGF0ZSI6IjUwM2EzODlmMTEyNTk2ZWNlNTY3ZmM0MjZlNDJmODJmNzQ3NjFkODEzODZmZDcxNzA3MzJmYzhhZjExOTc5NmEiLCJub25jZSI6IjFkODAzYzYwNTE4NWE1YWIyNjk5NWEyMzE1ODEzOTY0NDkwNTg0ZTYzMjMxZjkxZTA3YTQ3Yzk0Y2YyY2YzYmMiLCJpc3MiOiJTQlNmQlRPSk1WUUJCTDg0OFZHWEkiLCJhdWQiOiJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImNsaWVudF9pZCI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImp0aSI6IkdvcGZaWFZRb241b0JYWW9OMkdxTlRaekN1ZU1XaUlnanUxSGRQdXpOUzQiLCJpYXQiOjE2Mzk2ODIzNDcsImV4cCI6MTYzOTY4MjY0NywibmJmIjoxNjM5NjgyMzQ3fQ.Cy79H_VTGSw36x9fBJra9uw9jzpfNSQYdlev_eO1GlT9YAFDGpnpZEdDh014W9csysItlYPNrsyQ0f4ADauqfdu9a_cAwiXHMXHHTOCz99Rgj-wDFbx0qwkXaesFt7fUvRm8-9kwVgkzaqIiUpB54cEQH56QKu-FCkg6xhocBMds8PnQi7sJMbGbd8ghz-dKSHGdRlO-qZnVxQGvQps22NtgNr7GvSyLWXuBO85n-AuWVF-lo02J16zi7mJXxaeL0_y4U_QMqsjKH6bpifxDyZ1CYt2NHnc7gFiO5K8fvSgNLzLvuvqAYx3m65gyro8q-lPfScOvfh29ZL1qPGXNew",
  "header": {
    "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
    "typ": "oauth-authz-req+jwt",
    "alg": "PS256"
  },
  "claims": {
    "iss": "SBSfBTOJMVQBBL848VGXI",
    "response_type": "code id_token",
    "code_challenge_method": "S256",
    "nonce": "1d803c605185a5ab26995a2315813964490584e63231f91e07a47c94cf2cf3bc",
    "client_id": "SBSfBTOJMVQBBL848VGXI",
    "response_mode": "fragment",
    "aud": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
    "nbf": 1639682347,
    "scope": "openid consent:urn:conformance.oidf:oypnoNOgsO accounts resources",
    "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
    "state": "503a389f112596ece567fc426e42f82f74761d81386fd7170732fc8af119796a",
    "exp": 1639682647,
    "iat": 1639682347,
    "code_challenge": "Tp3T4HoNxNleY-OTKaApAqFIf2oE3Hu4u-r7sZynchs",
    "jti": "GopfZXVQon5oBXYoN2GqNTZzCueMWiIgju1HdPuzNS4"
  },
  "jwe_header": {
    "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
    "cty": "oauth-authz-req+jwt",
    "enc": "A256GCM",
    "alg": "RSA-OAEP"
  }
}
2021-12-16 19:19:07 SUCCESS
EnsurePAREndpointRequestDoesNotContainRequestUriParameter
PAR endpoint request does not contain a request_uri parameter
2021-12-16 19:19:07 SUCCESS
ValidateEncryptedRequestObjectHasKid
kid was found in the encrypted request object header
kid
0fe502dd-14f0-4f45-80f9-feb9a216f996
2021-12-16 19:19:07 SUCCESS
FAPIValidateRequestObjectSigningAlg
Request object was signed with a permitted algorithm
alg
PS256
2021-12-16 19:19:07
FAPIBrazilValidateRequestObjectIdTokenACRClaims
acr claim is not requested
2021-12-16 19:19:07 SUCCESS
FAPIValidateRequestObjectExp
Request object contains a valid exp claim, expiry time
exp
"Dec 16, 2021, 7:24:07 PM"
2021-12-16 19:19:07 SUCCESS
FAPI1AdvancedValidateRequestObjectNBFClaim
nbf claim is valid
nbf
"Dec 16, 2021, 7:19:07 PM"
now
"Dec 16, 2021, 7:19:07 PM"
2021-12-16 19:19:07
ValidateRequestObjectClaims
Request object does not contain a max_age claim
2021-12-16 19:19:07 SUCCESS
ValidateRequestObjectClaims
Request object claims passed all validation checks
2021-12-16 19:19:07 SUCCESS
EnsureNumericRequestObjectClaimsAreNotNull
None of the claims expected to have numeric values, have null values
numeric_claims
[
  "max_age"
]
2021-12-16 19:19:07 SUCCESS
EnsureRequestObjectDoesNotContainRequestOrRequestUri
Request object does not contain request or request_uri
2021-12-16 19:19:07 SUCCESS
EnsureRequestObjectDoesNotContainSubWithClientId
Request object does not contain Client Id in sub
2021-12-16 19:19:07 SUCCESS
ValidateRequestObjectSignature
Request object signature validated using a key in the client's JWKS and using the client's registered request_object_signing_alg
request_object
eyJhbGciOiJQUzI1NiIsInR5cCI6Im9hdXRoLWF1dGh6LXJlcStqd3QiLCJraWQiOiI1Z1lISUhidHcwVUI0QndqdHFVbmh0Rk42V3RoRVcybWRYN2RmVUJRSElJIn0.eyJzY29wZSI6Im9wZW5pZCBjb25zZW50OnVybjpjb25mb3JtYW5jZS5vaWRmOm95cG5vTk9nc08gYWNjb3VudHMgcmVzb3VyY2VzIiwicmVzcG9uc2VfdHlwZSI6ImNvZGUgaWRfdG9rZW4iLCJyZWRpcmVjdF91cmkiOiJodHRwczovL2FwaS1vcGVuYmFua2luZy1obWwuYmFuY29wYW4uY29tLmJyL3RwcC9jYWxsYmFjayIsImNvZGVfY2hhbGxlbmdlIjoiVHAzVDRIb054TmxlWS1PVEthQXBBcUZJZjJvRTNIdTR1LXI3c1p5bmNocyIsImNvZGVfY2hhbGxlbmdlX21ldGhvZCI6IlMyNTYiLCJyZXNwb25zZV9tb2RlIjoiZnJhZ21lbnQiLCJzdGF0ZSI6IjUwM2EzODlmMTEyNTk2ZWNlNTY3ZmM0MjZlNDJmODJmNzQ3NjFkODEzODZmZDcxNzA3MzJmYzhhZjExOTc5NmEiLCJub25jZSI6IjFkODAzYzYwNTE4NWE1YWIyNjk5NWEyMzE1ODEzOTY0NDkwNTg0ZTYzMjMxZjkxZTA3YTQ3Yzk0Y2YyY2YzYmMiLCJpc3MiOiJTQlNmQlRPSk1WUUJCTDg0OFZHWEkiLCJhdWQiOiJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImNsaWVudF9pZCI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImp0aSI6IkdvcGZaWFZRb241b0JYWW9OMkdxTlRaekN1ZU1XaUlnanUxSGRQdXpOUzQiLCJpYXQiOjE2Mzk2ODIzNDcsImV4cCI6MTYzOTY4MjY0NywibmJmIjoxNjM5NjgyMzQ3fQ.Cy79H_VTGSw36x9fBJra9uw9jzpfNSQYdlev_eO1GlT9YAFDGpnpZEdDh014W9csysItlYPNrsyQ0f4ADauqfdu9a_cAwiXHMXHHTOCz99Rgj-wDFbx0qwkXaesFt7fUvRm8-9kwVgkzaqIiUpB54cEQH56QKu-FCkg6xhocBMds8PnQi7sJMbGbd8ghz-dKSHGdRlO-qZnVxQGvQps22NtgNr7GvSyLWXuBO85n-AuWVF-lo02J16zi7mJXxaeL0_y4U_QMqsjKH6bpifxDyZ1CYt2NHnc7gFiO5K8fvSgNLzLvuvqAYx3m65gyro8q-lPfScOvfh29ZL1qPGXNew
request_object_signing_alg
PS256
jwk
Sun RSA public key, 2048 bits
  params: null
  modulus: 22677997123100865027038163618440931425768853246042685053952059568088768370775879662687649598715143390108338286915488499774626148365554590008656132577357893743438278711902761437715966243285423555795769385881803147871566517201086180684345745904063840678522561040685569999111501676387252045965556897951681323146595605739539663340316188618451821106202340139520257397286742681119465613725230213120667075481235349311488074650446518605298417452683228189337358541483332915940982625541029074799406321696170037150264352053879457399805139882493978179691887049996822814968964846225178258105165825398408907737359544759640349473403
  public exponent: 65537
2021-12-16 19:19:07 SUCCESS
EnsureMatchingRedirectUriInRequestObject
Redirect URI matched
actual
https://api-openbanking-hml.bancopan.com.br/tpp/callback
2021-12-16 19:19:07 SUCCESS
EnsureRequestObjectContainsCodeChallengeWhenUsingPAR
Found required PKCE parameters in request
code_challenge_method
S256
code_challenge
Tp3T4HoNxNleY-OTKaApAqFIf2oE3Hu4u-r7sZynchs
2021-12-16 19:19:07 SUCCESS
CreatePAREndpointResponse
Created PAR endpoint response
request_uri
urn:ietf:params:oauth:request_uri:0016edef-f553-4e4e-8552-9ece9861a926
expires_in
600
2021-12-16 19:19:07 OUTGOING
fapi1-advanced-final-client-test-valid-aud-as-array
Response to HTTP request to test instance wBVidr0t2MGeTMJ
outgoing_status_code
201
outgoing_headers
{}
outgoing_body
{
  "request_uri": "urn:ietf:params:oauth:request_uri:0016edef-f553-4e4e-8552-9ece9861a926",
  "expires_in": 600
}
outgoing_path
par
2021-12-16 19:19:08 INCOMING
fapi1-advanced-final-client-test-valid-aud-as-array
Incoming HTTP request to test instance wBVidr0t2MGeTMJ
incoming_headers
{
  "host": "www.certification.openid.net",
  "accept": "application/json, text/plain, */*",
  "content-type": "application/json",
  "x-idempotency-key": "a2e522ff-f4c6-4c7e-9fab-a492783902f1",
  "test-name": "44-fapi1-advanced-final-client-test-valid-aud-as-array.pushed",
  "authorization": "Bearer eyJraWQiOiJkZWZhdWx0IiwiYWxnIjoiUlMyNTYifQ.eyJzdWIiOiI3NGViNGMyMi1mYTZlLTQzNTgtYWI0Yy0yMmZhNmUxMzU4MzMiLCJhdWQiOiI3NGViNGMyMi1mYTZlLTQzNTgtYWI0Yy0yMmZhNmUxMzU4MzMiLCJkb21haW4iOiIwZmI2NjgxOC0yZTE3LTRhNzQtYjY2OC0xODJlMTcyYTc0ZjgiLCJzY29wZSI6ImNvbnNlbnRfYWRtaW4gcHJveHlfcmVhZCB0ZW5hbnRfYWRtaW4gY2F0ZWdvcnlfYWRtaW4gb3JnYW5pemF0aW9uX2FkbWluIiwiaXNzIjoiaHR0cDpcL1wvdHBwLWlhbS1vcGVuYmFua2luZy1obWwuYmFuY29wYW4uY29tLmJyXC9hbVwvdHBwXC9vaWRjIiwiZXhwIjoxNjM5Njg5NTQ0LCJpYXQiOjE2Mzk2ODIzNDQsImp0aSI6IlM3NDVSbDJSeFpFNUUtVURhZnF4QnNJWUR5bm9FREdjeW5hemVVOVM5ajQifQ.Zt1wNIkP9vzxhaazt4v4Wtq11JkUyV3u6OE_9z1M90u8-WUAGrAVrtPoSIX-Ffo4gpk2H1m5FXl8hGY-UGO-zpw1oZl_J2wnBm069DYQfgvHqfSVEYi8FRJlk1QFBR8566fNuY4BnX-clNfC9WRXbp-Av522P126hIQXvpRMCzEgXauOxDQGY47uqMyDpgINZFUUnKMJXAd_gGC3TKUh4601rJ5Qw20qRKI3EflJW8kZcERGv9OhtbjgBhsAzA89WCHggh5EXPALINqjwkHGQ7u-wpDLg9QNB2njiEhlJ3UYNIY5Uqge9KMGYTYKA40sw3HbuNqSff4ciSne_xnQoA",
  "user-agent": "axios/0.24.0",
  "connection": "close"
}
incoming_path
/test/a/RP-Security-Test-PAN/authorize
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
DHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{
  "client_id": "SBSfBTOJMVQBBL848VGXI",
  "scope": "openid consent:urn:conformance.oidf:oypnoNOgsO accounts resources",
  "response_type": "code",
  "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
  "request_uri": "urn:ietf:params:oauth:request_uri:0016edef-f553-4e4e-8552-9ece9861a926"
}
incoming_body
2021-12-16 19:19:08 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
DHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Authorization endpoint
2021-12-16 19:19:08 SUCCESS
EnsureAuthorizationRequestDoesNotContainRequestWhenUsingPAR
Request does not contain a request parameter
2021-12-16 19:19:08 SUCCESS
ValidateEncryptedRequestObjectHasKid
kid was found in the encrypted request object header
kid
0fe502dd-14f0-4f45-80f9-feb9a216f996
2021-12-16 19:19:08 SUCCESS
CreateEffectiveAuthorizationRequestParameters
Merged http request parameters with request object claims
effective_authorization_endpoint_request
{
  "client_id": "SBSfBTOJMVQBBL848VGXI",
  "scope": "openid consent:urn:conformance.oidf:oypnoNOgsO accounts resources",
  "response_type": "code id_token",
  "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
  "iss": "SBSfBTOJMVQBBL848VGXI",
  "code_challenge_method": "S256",
  "nonce": "1d803c605185a5ab26995a2315813964490584e63231f91e07a47c94cf2cf3bc",
  "response_mode": "fragment",
  "aud": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "nbf": 1639682347,
  "state": "503a389f112596ece567fc426e42f82f74761d81386fd7170732fc8af119796a",
  "exp": 1639682647,
  "iat": 1639682347,
  "code_challenge": "Tp3T4HoNxNleY-OTKaApAqFIf2oE3Hu4u-r7sZynchs",
  "jti": "GopfZXVQon5oBXYoN2GqNTZzCueMWiIgju1HdPuzNS4"
}
2021-12-16 19:19:08 SUCCESS
EnsureClientIdInAuthorizationRequestParametersMatchRequestObject
client_id http request parameter value matches client_id in request object
2021-12-16 19:19:08 SUCCESS
ExtractRequestedScopes
Requested scopes
scope
openid consent:urn:conformance.oidf:oypnoNOgsO accounts resources
2021-12-16 19:19:08 SUCCESS
FAPIBrazilValidateConsentScope
Found consent scope in request
actual
[
  "openid",
  "consent:urn:conformance.oidf:oypnoNOgsO",
  "accounts",
  "resources"
]
expected
consent:urn:conformance.oidf:oypnoNOgsO
2021-12-16 19:19:08 SUCCESS
EnsureScopeContainsAccounts
Found accounts scope in request
actual
[
  "openid",
  "consent:urn:conformance.oidf:oypnoNOgsO",
  "accounts",
  "resources"
]
2021-12-16 19:19:08 SUCCESS
EnsureResponseTypeIsCodeIdToken
Response type is expected value
expected
code id_token
2021-12-16 19:19:08 SUCCESS
EnsureOpenIDInScopeRequest
Found 'openid' scope in request
actual
[
  "openid",
  "consent:urn:conformance.oidf:oypnoNOgsO",
  "accounts",
  "resources"
]
expected
openid
2021-12-16 19:19:08 SUCCESS
EnsureMatchingClientId
Client ID matched
client_id
SBSfBTOJMVQBBL848VGXI
2021-12-16 19:19:08 SUCCESS
CreateAuthorizationCode
Created authorization code
authorization_code
yWoah4IgpQRospbeSPxF8fFrDQbXWAmB
2021-12-16 19:19:08 SUCCESS
ExtractNonceFromAuthorizationRequest
Extracted nonce
nonce
1d803c605185a5ab26995a2315813964490584e63231f91e07a47c94cf2cf3bc
2021-12-16 19:19:08 SUCCESS
CalculateCHash
Successful c_hash encoding
c_hash
VPXo7_xL4uCDkZoaipdnvw
2021-12-16 19:19:08 SUCCESS
CalculateSHash
Successful s_hash encoding
s_hash
GpF_lYEyHu7wAjE0NMTi2g
2021-12-16 19:19:08 SUCCESS
GenerateIdTokenClaims
Created ID Token Claims
iss
https://www.certification.openid.net/test/a/RP-Security-Test-PAN/
sub
user-subject-1234531
aud
SBSfBTOJMVQBBL848VGXI
nonce
1d803c605185a5ab26995a2315813964490584e63231f91e07a47c94cf2cf3bc
iat
1639682348
exp
1639682648
2021-12-16 19:19:08
FAPIBrazilAddCPFAndCPNJToIdTokenClaims
Request object does not contain a claims element.id_token
2021-12-16 19:19:08 SUCCESS
AddCHashToIdTokenClaims
Added c_hash to ID token claims
c_hash
VPXo7_xL4uCDkZoaipdnvw
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "sub": "user-subject-1234531",
  "aud": "SBSfBTOJMVQBBL848VGXI",
  "nonce": "1d803c605185a5ab26995a2315813964490584e63231f91e07a47c94cf2cf3bc",
  "iat": 1639682348,
  "exp": 1639682648,
  "c_hash": "VPXo7_xL4uCDkZoaipdnvw"
}
2021-12-16 19:19:08 SUCCESS
AddSHashToIdTokenClaims
Added s_hash to ID token claims
s_hash
GpF_lYEyHu7wAjE0NMTi2g
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "sub": "user-subject-1234531",
  "aud": "SBSfBTOJMVQBBL848VGXI",
  "nonce": "1d803c605185a5ab26995a2315813964490584e63231f91e07a47c94cf2cf3bc",
  "iat": 1639682348,
  "exp": 1639682648,
  "c_hash": "VPXo7_xL4uCDkZoaipdnvw",
  "s_hash": "GpF_lYEyHu7wAjE0NMTi2g"
}
2021-12-16 19:19:08 INFO
AddAtHashToIdTokenClaims
Skipped evaluation due to missing required string: at_hash
expected
at_hash
2021-12-16 19:19:08 SUCCESS
AddAudValueAsArrayToIdToken
Added the aud value as an array to ID token claims
aud
[
  "SBSfBTOJMVQBBL848VGXI"
]
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "sub": "user-subject-1234531",
  "aud": [
    "SBSfBTOJMVQBBL848VGXI"
  ],
  "nonce": "1d803c605185a5ab26995a2315813964490584e63231f91e07a47c94cf2cf3bc",
  "iat": 1639682348,
  "exp": 1639682648,
  "c_hash": "VPXo7_xL4uCDkZoaipdnvw",
  "s_hash": "GpF_lYEyHu7wAjE0NMTi2g"
}
2021-12-16 19:19:08 INFO
FAPIBrazilAddACRClaimToIdTokenClaims
Skipped evaluation due to missing required string: requested_id_token_acr_values
expected
requested_id_token_acr_values
2021-12-16 19:19:08 SUCCESS
SignIdToken
Signed the ID token
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImNfaGFzaCI6IlZQWG83X3hMNHVDRGtab2FpcGRudnciLCJzX2hhc2giOiJHcEZfbFlFeUh1N3dBakUwTk1UaTJnIiwiaXNzIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL1JQLVNlY3VyaXR5LVRlc3QtUEFOXC8iLCJleHAiOjE2Mzk2ODI2NDgsIm5vbmNlIjoiMWQ4MDNjNjA1MTg1YTVhYjI2OTk1YTIzMTU4MTM5NjQ0OTA1ODRlNjMyMzFmOTFlMDdhNDdjOTRjZjJjZjNiYyIsImlhdCI6MTYzOTY4MjM0OH0.yfl1PEdFMeTcE2_MxyEk-FxjFrWIzTOma6u6eg_0D23F_k6c_umUHkonLbKhGw-q4nxdlqEI0tcDv_RZmL-iZNdyxpLZhJdVcmKOpbzNWrKniPf4suQ1ipRkJYBAn3h7OyF0gpI13dxBjp9RK0DNx6c1_ppJh-sHKRWYqz7nX03lHbY2fRLQ-TFvY0O5ws_4o2jmUQx39dhibKUnAH_kxIuXN7xvjboUEcaBGvxLt0XVbKSyY092G36_2taApaTOiCoyz1Q4LQxM9IEdBEAGY4x0CYzsQaTix9TjtYGf3rgH3QaPVNtZT4COllM9D78XZKnW82BY3fJSZ6VqdQLqJg
2021-12-16 19:19:08 SUCCESS
SignIdTokenBypassingNimbusChecks
Signed the ID token
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJpc3MiOiJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjpbIlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSJdLCJub25jZSI6IjFkODAzYzYwNTE4NWE1YWIyNjk5NWEyMzE1ODEzOTY0NDkwNTg0ZTYzMjMxZjkxZTA3YTQ3Yzk0Y2YyY2YzYmMiLCJpYXQiOjE2Mzk2ODIzNDgsImV4cCI6MTYzOTY4MjY0OCwiY19oYXNoIjoiVlBYbzdfeEw0dUNEa1pvYWlwZG52dyIsInNfaGFzaCI6IkdwRl9sWUV5SHU3d0FqRTBOTVRpMmcifQ.ntoUFBq7VqbTMD78YecC5iVFpaofL-1Wbn9E98BqIWcULQ21sPgK0PGZbrlYoOln9QU0_VtGTHGq8OGxWd6kwi4W6R64PTJNz8kMBHL3Jg38h8aQk_vwdAuQns3kEObX7swVv2RIYaOKdHM6fYml8PlOrHurbMpLmPXF6A3NNN7DD2CMtQMmmUtuZgo6eNifKZ5SbubxSLdQie40BLTPKXlnjn_BPo3JKhwBII7NEzdHqpVlBQrP0PzXbga6ASoB1eiTiFW_ZlAS_Utk_FjX1f6rgEIXeG-3mEk4RkdRAuMUs2bNK-LncWBR5lFS52N9OYq7mkzmWc6Qkrv1xot8Ew
2021-12-16 19:19:08 SUCCESS
FAPIBrazilChangeConsentStatusToAuthorized
Changed consent status to AUTHORISED
consent
{
  "data": {
    "consentId": "urn:conformance.oidf:oypnoNOgsO",
    "creationDateTime": "2021-12-16T19:19:06Z",
    "status": "AUTHORISED",
    "statusUpdateDateTime": "2021-12-16T19:19:08Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2021-12-16T21:19:06Z",
    "transactionFromDateTime": "2021-12-16T19:14:06Z",
    "transactionToDateTime": "2021-12-16T21:19:06Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/RP-Security-Test-PANconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2021-12-16T19:19:06Z"
  }
}
2021-12-16 19:19:08 SUCCESS
CreateAuthorizationEndpointResponseParams
Added authorization_endpoint_response_params to environment
params
{
  "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
  "state": "503a389f112596ece567fc426e42f82f74761d81386fd7170732fc8af119796a"
}
2021-12-16 19:19:08 SUCCESS
AddCodeToAuthorizationEndpointResponseParams
Added code to authorization endpoint response params
authorization_endpoint_response_params
{
  "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
  "state": "503a389f112596ece567fc426e42f82f74761d81386fd7170732fc8af119796a",
  "code": "yWoah4IgpQRospbeSPxF8fFrDQbXWAmB"
}
2021-12-16 19:19:08 SUCCESS
AddIdTokenToAuthorizationEndpointResponseParams
Added id_token to authorization endpoint response params
authorization_endpoint_response_params
{
  "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
  "state": "503a389f112596ece567fc426e42f82f74761d81386fd7170732fc8af119796a",
  "code": "yWoah4IgpQRospbeSPxF8fFrDQbXWAmB",
  "id_token": "eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJpc3MiOiJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjpbIlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSJdLCJub25jZSI6IjFkODAzYzYwNTE4NWE1YWIyNjk5NWEyMzE1ODEzOTY0NDkwNTg0ZTYzMjMxZjkxZTA3YTQ3Yzk0Y2YyY2YzYmMiLCJpYXQiOjE2Mzk2ODIzNDgsImV4cCI6MTYzOTY4MjY0OCwiY19oYXNoIjoiVlBYbzdfeEw0dUNEa1pvYWlwZG52dyIsInNfaGFzaCI6IkdwRl9sWUV5SHU3d0FqRTBOTVRpMmcifQ.ntoUFBq7VqbTMD78YecC5iVFpaofL-1Wbn9E98BqIWcULQ21sPgK0PGZbrlYoOln9QU0_VtGTHGq8OGxWd6kwi4W6R64PTJNz8kMBHL3Jg38h8aQk_vwdAuQns3kEObX7swVv2RIYaOKdHM6fYml8PlOrHurbMpLmPXF6A3NNN7DD2CMtQMmmUtuZgo6eNifKZ5SbubxSLdQie40BLTPKXlnjn_BPo3JKhwBII7NEzdHqpVlBQrP0PzXbga6ASoB1eiTiFW_ZlAS_Utk_FjX1f6rgEIXeG-3mEk4RkdRAuMUs2bNK-LncWBR5lFS52N9OYq7mkzmWc6Qkrv1xot8Ew"
}
2021-12-16 19:19:08
SendAuthorizationResponseWithResponseModeFragment
Redirecting back to client
uri
https://api-openbanking-hml.bancopan.com.br/tpp/callback#state=503a389f112596ece567fc426e42f82f74761d81386fd7170732fc8af119796a&code=yWoah4IgpQRospbeSPxF8fFrDQbXWAmB&id_token=eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJpc3MiOiJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjpbIlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSJdLCJub25jZSI6IjFkODAzYzYwNTE4NWE1YWIyNjk5NWEyMzE1ODEzOTY0NDkwNTg0ZTYzMjMxZjkxZTA3YTQ3Yzk0Y2YyY2YzYmMiLCJpYXQiOjE2Mzk2ODIzNDgsImV4cCI6MTYzOTY4MjY0OCwiY19oYXNoIjoiVlBYbzdfeEw0dUNEa1pvYWlwZG52dyIsInNfaGFzaCI6IkdwRl9sWUV5SHU3d0FqRTBOTVRpMmcifQ.ntoUFBq7VqbTMD78YecC5iVFpaofL-1Wbn9E98BqIWcULQ21sPgK0PGZbrlYoOln9QU0_VtGTHGq8OGxWd6kwi4W6R64PTJNz8kMBHL3Jg38h8aQk_vwdAuQns3kEObX7swVv2RIYaOKdHM6fYml8PlOrHurbMpLmPXF6A3NNN7DD2CMtQMmmUtuZgo6eNifKZ5SbubxSLdQie40BLTPKXlnjn_BPo3JKhwBII7NEzdHqpVlBQrP0PzXbga6ASoB1eiTiFW_ZlAS_Utk_FjX1f6rgEIXeG-3mEk4RkdRAuMUs2bNK-LncWBR5lFS52N9OYq7mkzmWc6Qkrv1xot8Ew
2021-12-16 19:19:08 OUTGOING
fapi1-advanced-final-client-test-valid-aud-as-array
Response to HTTP request to test instance wBVidr0t2MGeTMJ
outgoing
org.springframework.web.servlet.view.RedirectView: [RedirectView]; URL [https://api-openbanking-hml.bancopan.com.br/tpp/callback#state=503a389f112596ece567fc426e42f82f74761d81386fd7170732fc8af119796a&code=yWoah4IgpQRospbeSPxF8fFrDQbXWAmB&id_token=eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJpc3MiOiJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjpbIlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSJdLCJub25jZSI6IjFkODAzYzYwNTE4NWE1YWIyNjk5NWEyMzE1ODEzOTY0NDkwNTg0ZTYzMjMxZjkxZTA3YTQ3Yzk0Y2YyY2YzYmMiLCJpYXQiOjE2Mzk2ODIzNDgsImV4cCI6MTYzOTY4MjY0OCwiY19oYXNoIjoiVlBYbzdfeEw0dUNEa1pvYWlwZG52dyIsInNfaGFzaCI6IkdwRl9sWUV5SHU3d0FqRTBOTVRpMmcifQ.ntoUFBq7VqbTMD78YecC5iVFpaofL-1Wbn9E98BqIWcULQ21sPgK0PGZbrlYoOln9QU0_VtGTHGq8OGxWd6kwi4W6R64PTJNz8kMBHL3Jg38h8aQk_vwdAuQns3kEObX7swVv2RIYaOKdHM6fYml8PlOrHurbMpLmPXF6A3NNN7DD2CMtQMmmUtuZgo6eNifKZ5SbubxSLdQie40BLTPKXlnjn_BPo3JKhwBII7NEzdHqpVlBQrP0PzXbga6ASoB1eiTiFW_ZlAS_Utk_FjX1f6rgEIXeG-3mEk4RkdRAuMUs2bNK-LncWBR5lFS52N9OYq7mkzmWc6Qkrv1xot8Ew]
outgoing_path
authorize
2021-12-16 19:19:09 INCOMING
fapi1-advanced-final-client-test-valid-aud-as-array
Incoming HTTP request to test instance wBVidr0t2MGeTMJ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/RP-Security-Test-PAN/.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-16 19:19:09 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-16 19:19:09 OUTGOING
fapi1-advanced-final-client-test-valid-aud-as-array
Response to HTTP request to test instance wBVidr0t2MGeTMJ
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo",
    "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/par"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ],
  "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/par",
  "require_pushed_authorization_requests": true,
  "response_types_supported": [
    "code id_token"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256"
  ]
}
outgoing_path
.well-known/openid-configuration
2021-12-16 19:19:09 INCOMING
fapi1-advanced-final-client-test-valid-aud-as-array
Incoming HTTP request to test instance wBVidr0t2MGeTMJ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/RP-Security-Test-PAN/jwks
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-16 19:19:09 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-16 19:19:09 OUTGOING
fapi1-advanced-final-client-test-valid-aud-as-array
Response to HTTP request to test instance wBVidr0t2MGeTMJ
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "alg": "PS256",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "alg": "RSA-OAEP",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
outgoing_path
jwks
2021-12-16 19:19:09 INCOMING
fapi1-advanced-final-client-test-valid-aud-as-array
Incoming HTTP request to test instance wBVidr0t2MGeTMJ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded",
  "accept-encoding": "gzip, deflate, br",
  "content-length": "1291",
  "connection": "close"
}
incoming_path
/test-mtls/a/RP-Security-Test-PAN/token
incoming_body_form_params
{
  "grant_type": "authorization_code",
  "code": "yWoah4IgpQRospbeSPxF8fFrDQbXWAmB",
  "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
  "code_verifier": "NnR9jRMQuvjdWoIsXyvYb4I48BtAMTCqObtcbt5c-Wg",
  "client_id": "SBSfBTOJMVQBBL848VGXI",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNDksImV4cCI6MTYzOTY4MjQwOSwianRpIjoiQjR5MFhuY2V2NUUyOTVWV0F3S19BU0pFMkFmVjlKSFBEYndSODJOUnhjOCIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.nGnC4NfgRc-fZ7fW5sGzoghsMKQZXkLMnNAlsuIWi7KoApNDauV-mMJiQ9Z_QsHx1EUvHcPOU3NgF53k_yQLteyKxxB3WrWmVwtDAH-x2j7YXM2mY7VBhomGjceiOusB6AGuY03NYRQbgCamRX6CjbiO7XD9bMsSAsufMH10gfBOSrfYK_jUDeh56r3_bz1lPzQNd9PF7CLKjAQrguwnfnldR3LCJTVsBg67VyMKOnnRNCos9LRrCt7nx-mWSNgKZKJQSp6s6Sv7BuoVFZ-FJiiC1LyObFup0lsnVFEhAyOYwen8vk5hOOqiFLldq7vwy5ZNCsV_uMWNyY1vIAuhPA",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
grant_type=authorization_code&code=yWoah4IgpQRospbeSPxF8fFrDQbXWAmB&redirect_uri=https%3A%2F%2Fapi-openbanking-hml.bancopan.com.br%2Ftpp%2Fcallback&code_verifier=NnR9jRMQuvjdWoIsXyvYb4I48BtAMTCqObtcbt5c-Wg&client_id=SBSfBTOJMVQBBL848VGXI&client_assertion=eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNDksImV4cCI6MTYzOTY4MjQwOSwianRpIjoiQjR5MFhuY2V2NUUyOTVWV0F3S19BU0pFMkFmVjlKSFBEYndSODJOUnhjOCIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.nGnC4NfgRc-fZ7fW5sGzoghsMKQZXkLMnNAlsuIWi7KoApNDauV-mMJiQ9Z_QsHx1EUvHcPOU3NgF53k_yQLteyKxxB3WrWmVwtDAH-x2j7YXM2mY7VBhomGjceiOusB6AGuY03NYRQbgCamRX6CjbiO7XD9bMsSAsufMH10gfBOSrfYK_jUDeh56r3_bz1lPzQNd9PF7CLKjAQrguwnfnldR3LCJTVsBg67VyMKOnnRNCos9LRrCt7nx-mWSNgKZKJQSp6s6Sv7BuoVFZ-FJiiC1LyObFup0lsnVFEhAyOYwen8vk5hOOqiFLldq7vwy5ZNCsV_uMWNyY1vIAuhPA&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2021-12-16 19:19:09 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2021-12-16 19:19:09 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz\nMjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct\nNjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j\nb20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk\nYWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ\ncml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ\nKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4\n9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r\niu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6\ni56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV\nCLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3\n5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC\nAtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO\nEUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA\noD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v\ncmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB\nBQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC\nD2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k\nATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz\nb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg\nb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g\nU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg\ncmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j\nZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5\nIGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0\ncDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s\naWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL\n8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs\nZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0\nQZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY\nYFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG\nOZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,UID\u003dac60fe65-58ca-44c3-9352-6f556c5cb98e,2.5.4.5\u003d#130e3539323835343131303030313133,CN\u003dbancopan.com.br,OU\u003db6a214c7-6332-5a41-8464-a281fb9a4ca0,O\u003dBANCO PAN,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "bancopan.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2021-12-16 19:19:09 SUCCESS
CheckForClientCertificate
Found client certificate
2021-12-16 19:19:09 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz
MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct
NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j
b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk
YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ
cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4
9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r
iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6
i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV
CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3
5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC
AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO
EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA
oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v
cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB
BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC
D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k
ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz
b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg
b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g
U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg
cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j
ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5
IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0
cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s
aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL
8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs
ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0
QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY
YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG
OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks=
-----END CERTIFICATE-----
2021-12-16 19:19:09 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNDksImV4cCI6MTYzOTY4MjQwOSwianRpIjoiQjR5MFhuY2V2NUUyOTVWV0F3S19BU0pFMkFmVjlKSFBEYndSODJOUnhjOCIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.nGnC4NfgRc-fZ7fW5sGzoghsMKQZXkLMnNAlsuIWi7KoApNDauV-mMJiQ9Z_QsHx1EUvHcPOU3NgF53k_yQLteyKxxB3WrWmVwtDAH-x2j7YXM2mY7VBhomGjceiOusB6AGuY03NYRQbgCamRX6CjbiO7XD9bMsSAsufMH10gfBOSrfYK_jUDeh56r3_bz1lPzQNd9PF7CLKjAQrguwnfnldR3LCJTVsBg67VyMKOnnRNCos9LRrCt7nx-mWSNgKZKJQSp6s6Sv7BuoVFZ-FJiiC1LyObFup0lsnVFEhAyOYwen8vk5hOOqiFLldq7vwy5ZNCsV_uMWNyY1vIAuhPA",
  "header": {
    "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "SBSfBTOJMVQBBL848VGXI",
    "aud": [
      "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
      "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
      "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token"
    ],
    "iss": "SBSfBTOJMVQBBL848VGXI",
    "exp": 1639682409,
    "iat": 1639682349,
    "jti": "B4y0Xncev5E295VWAwK_ASJE2AfV9JHPDbwR82NRxc8"
  }
}
2021-12-16 19:19:09
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2021-12-16 19:19:09 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNDksImV4cCI6MTYzOTY4MjQwOSwianRpIjoiQjR5MFhuY2V2NUUyOTVWV0F3S19BU0pFMkFmVjlKSFBEYndSODJOUnhjOCIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.nGnC4NfgRc-fZ7fW5sGzoghsMKQZXkLMnNAlsuIWi7KoApNDauV-mMJiQ9Z_QsHx1EUvHcPOU3NgF53k_yQLteyKxxB3WrWmVwtDAH-x2j7YXM2mY7VBhomGjceiOusB6AGuY03NYRQbgCamRX6CjbiO7XD9bMsSAsufMH10gfBOSrfYK_jUDeh56r3_bz1lPzQNd9PF7CLKjAQrguwnfnldR3LCJTVsBg67VyMKOnnRNCos9LRrCt7nx-mWSNgKZKJQSp6s6Sv7BuoVFZ-FJiiC1LyObFup0lsnVFEhAyOYwen8vk5hOOqiFLldq7vwy5ZNCsV_uMWNyY1vIAuhPA
2021-12-16 19:19:09 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-12-16 19:19:09 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2021-12-16 19:19:09 SUCCESS
ValidateAuthorizationCode
Found authorization code
authorization_code
yWoah4IgpQRospbeSPxF8fFrDQbXWAmB
2021-12-16 19:19:09 SUCCESS
ValidateRedirectUri
Found redirect uri
redirect_uri
https://api-openbanking-hml.bancopan.com.br/tpp/callback
2021-12-16 19:19:09 SUCCESS
ValidateCodeVerifierWithS256
Validated code_verifier successfully
code_challenge_method
S256
code_verifier
NnR9jRMQuvjdWoIsXyvYb4I48BtAMTCqObtcbt5c-Wg
code_challenge
Tp3T4HoNxNleY-OTKaApAqFIf2oE3Hu4u-r7sZynchs
2021-12-16 19:19:09 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
EjzhkcQhzVKxCONpOMmmR7KyA2gEfFnyNrZlOj1OpqsPaYL2xx
2021-12-16 19:19:09 SUCCESS
CalculateAtHash
Successful at_hash encoding
at_hash
XnKPcD5Zqnk11LYWxWE-mA
2021-12-16 19:19:09
CreateRefreshToken
Created refresh token
refresh_token
pnnPVQueJASeZtLWXIguCJLSBNEpjCQfesRNbKMuSLYFItvfQz3691338188%>? ?
2021-12-16 19:19:09 SUCCESS
GenerateIdTokenClaims
Created ID Token Claims
iss
https://www.certification.openid.net/test/a/RP-Security-Test-PAN/
sub
user-subject-1234531
aud
SBSfBTOJMVQBBL848VGXI
nonce
1d803c605185a5ab26995a2315813964490584e63231f91e07a47c94cf2cf3bc
iat
1639682349
exp
1639682649
2021-12-16 19:19:09
FAPIBrazilAddCPFAndCPNJToIdTokenClaims
Request object does not contain a claims element.id_token
2021-12-16 19:19:09 SUCCESS
AddAtHashToIdTokenClaims
Added at_hash to ID token claims
at_hash
XnKPcD5Zqnk11LYWxWE-mA
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "sub": "user-subject-1234531",
  "aud": "SBSfBTOJMVQBBL848VGXI",
  "nonce": "1d803c605185a5ab26995a2315813964490584e63231f91e07a47c94cf2cf3bc",
  "iat": 1639682349,
  "exp": 1639682649,
  "at_hash": "XnKPcD5Zqnk11LYWxWE-mA"
}
2021-12-16 19:19:09 SUCCESS
AddAudValueAsArrayToIdToken
Added the aud value as an array to ID token claims
aud
[
  "SBSfBTOJMVQBBL848VGXI"
]
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "sub": "user-subject-1234531",
  "aud": [
    "SBSfBTOJMVQBBL848VGXI"
  ],
  "nonce": "1d803c605185a5ab26995a2315813964490584e63231f91e07a47c94cf2cf3bc",
  "iat": 1639682349,
  "exp": 1639682649,
  "at_hash": "XnKPcD5Zqnk11LYWxWE-mA"
}
2021-12-16 19:19:09 INFO
FAPIBrazilAddACRClaimToIdTokenClaims
Skipped evaluation due to missing required string: requested_id_token_acr_values
expected
requested_id_token_acr_values
2021-12-16 19:19:09 SUCCESS
SignIdToken
Signed the ID token
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdF9oYXNoIjoiWG5LUGNENVpxbmsxMUxZV3hXRS1tQSIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoiU0JTZkJUT0pNVlFCQkw4NDhWR1hJIiwiaXNzIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL1JQLVNlY3VyaXR5LVRlc3QtUEFOXC8iLCJleHAiOjE2Mzk2ODI2NDksIm5vbmNlIjoiMWQ4MDNjNjA1MTg1YTVhYjI2OTk1YTIzMTU4MTM5NjQ0OTA1ODRlNjMyMzFmOTFlMDdhNDdjOTRjZjJjZjNiYyIsImlhdCI6MTYzOTY4MjM0OX0.juFwtjS0yIQmiVk-PYvKR1O2A-HaSlID6cPMEoUQx-kl3sWeeZzEKNGnnNUWaJLBWNJJDbq_8GfORIKeF655-krETNfxSkaITH0_oooKWUDOuIto9TlBMhhXBmapFKLHcNq5LYkiqxJMJGf5sLU4WT4MMZSj6A0-MPKHAF2hAWNtiG4ibdx5IRCYMhT8dfVTw01Yu-ZvVi93v-5joSQB-JezPSn3DQCjKVjUgcMm3D_ZLXy1k8QsXOYLsq8bqzVNmc5_wdQbGT8_CfmVjn9i4rFyEW0fHe_td-jp1JjeaTaEQBCNBoO_ma0d7GJybfWo53up01y2-lMSOgZu9f2zzA
2021-12-16 19:19:09 SUCCESS
SignIdTokenBypassingNimbusChecks
Signed the ID token
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJpc3MiOiJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjpbIlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSJdLCJub25jZSI6IjFkODAzYzYwNTE4NWE1YWIyNjk5NWEyMzE1ODEzOTY0NDkwNTg0ZTYzMjMxZjkxZTA3YTQ3Yzk0Y2YyY2YzYmMiLCJpYXQiOjE2Mzk2ODIzNDksImV4cCI6MTYzOTY4MjY0OSwiYXRfaGFzaCI6IlhuS1BjRDVacW5rMTFMWVd4V0UtbUEifQ.l3K7jqzJRXliG2WSOZcEm1Sr4K0nETCyqxPrOgBuEVfekGhfDBWm8n-1kgBiJ8V05o8ACJQ3bIkdlRPBIQ14SKhNuNNvVEVHkuKdmH9QXMcN_tvdzhBuN8cE98UDSHEJY4ejwG-P3wcRggzTiZZgYbNM5jKgE1qxY-HWvJx6-Qm3pPjtB3l9imGKYoZXs59TCERHIQIuSlGZJTrgl5uIidFFtUQb8DvaMSacPz7XMvpISxURo470OyOlBgaro5c-8vZ2OJWda2wgU-Lgp6lJpPEGs9FWsCYj6bg3S1DzkSmPbx1UQAZlu4AZl7MUOZLKrNU3I-6-vsjps48GxwckuA
2021-12-16 19:19:09 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
EjzhkcQhzVKxCONpOMmmR7KyA2gEfFnyNrZlOj1OpqsPaYL2xx
token_type
Bearer
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJpc3MiOiJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjpbIlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSJdLCJub25jZSI6IjFkODAzYzYwNTE4NWE1YWIyNjk5NWEyMzE1ODEzOTY0NDkwNTg0ZTYzMjMxZjkxZTA3YTQ3Yzk0Y2YyY2YzYmMiLCJpYXQiOjE2Mzk2ODIzNDksImV4cCI6MTYzOTY4MjY0OSwiYXRfaGFzaCI6IlhuS1BjRDVacW5rMTFMWVd4V0UtbUEifQ.l3K7jqzJRXliG2WSOZcEm1Sr4K0nETCyqxPrOgBuEVfekGhfDBWm8n-1kgBiJ8V05o8ACJQ3bIkdlRPBIQ14SKhNuNNvVEVHkuKdmH9QXMcN_tvdzhBuN8cE98UDSHEJY4ejwG-P3wcRggzTiZZgYbNM5jKgE1qxY-HWvJx6-Qm3pPjtB3l9imGKYoZXs59TCERHIQIuSlGZJTrgl5uIidFFtUQb8DvaMSacPz7XMvpISxURo470OyOlBgaro5c-8vZ2OJWda2wgU-Lgp6lJpPEGs9FWsCYj6bg3S1DzkSmPbx1UQAZlu4AZl7MUOZLKrNU3I-6-vsjps48GxwckuA
refresh_token
pnnPVQueJASeZtLWXIguCJLSBNEpjCQfesRNbKMuSLYFItvfQz3691338188%>? ?
scope
openid consent:urn:conformance.oidf:oypnoNOgsO accounts resources
2021-12-16 19:19:09 OUTGOING
fapi1-advanced-final-client-test-valid-aud-as-array
Response to HTTP request to test instance wBVidr0t2MGeTMJ
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "EjzhkcQhzVKxCONpOMmmR7KyA2gEfFnyNrZlOj1OpqsPaYL2xx",
  "token_type": "Bearer",
  "id_token": "eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJpc3MiOiJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjpbIlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSJdLCJub25jZSI6IjFkODAzYzYwNTE4NWE1YWIyNjk5NWEyMzE1ODEzOTY0NDkwNTg0ZTYzMjMxZjkxZTA3YTQ3Yzk0Y2YyY2YzYmMiLCJpYXQiOjE2Mzk2ODIzNDksImV4cCI6MTYzOTY4MjY0OSwiYXRfaGFzaCI6IlhuS1BjRDVacW5rMTFMWVd4V0UtbUEifQ.l3K7jqzJRXliG2WSOZcEm1Sr4K0nETCyqxPrOgBuEVfekGhfDBWm8n-1kgBiJ8V05o8ACJQ3bIkdlRPBIQ14SKhNuNNvVEVHkuKdmH9QXMcN_tvdzhBuN8cE98UDSHEJY4ejwG-P3wcRggzTiZZgYbNM5jKgE1qxY-HWvJx6-Qm3pPjtB3l9imGKYoZXs59TCERHIQIuSlGZJTrgl5uIidFFtUQb8DvaMSacPz7XMvpISxURo470OyOlBgaro5c-8vZ2OJWda2wgU-Lgp6lJpPEGs9FWsCYj6bg3S1DzkSmPbx1UQAZlu4AZl7MUOZLKrNU3I-6-vsjps48GxwckuA",
  "refresh_token": "pnnPVQueJASeZtLWXIguCJLSBNEpjCQfesRNbKMuSLYFItvfQz3691338188%\u003e? ?",
  "scope": "openid consent:urn:conformance.oidf:oypnoNOgsO accounts resources"
}
outgoing_path
token
2021-12-16 19:19:12 INCOMING
fapi1-advanced-final-client-test-valid-aud-as-array
Incoming HTTP request to test instance wBVidr0t2MGeTMJ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/RP-Security-Test-PAN/.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-16 19:19:12 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-16 19:19:12 OUTGOING
fapi1-advanced-final-client-test-valid-aud-as-array
Response to HTTP request to test instance wBVidr0t2MGeTMJ
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo",
    "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/par"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ],
  "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/par",
  "require_pushed_authorization_requests": true,
  "response_types_supported": [
    "code id_token"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256"
  ]
}
outgoing_path
.well-known/openid-configuration
2021-12-16 19:19:12 INCOMING
fapi1-advanced-final-client-test-valid-aud-as-array
Incoming HTTP request to test instance wBVidr0t2MGeTMJ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/RP-Security-Test-PAN/.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-16 19:19:12 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-16 19:19:12 OUTGOING
fapi1-advanced-final-client-test-valid-aud-as-array
Response to HTTP request to test instance wBVidr0t2MGeTMJ
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo",
    "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/par"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ],
  "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/par",
  "require_pushed_authorization_requests": true,
  "response_types_supported": [
    "code id_token"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256"
  ]
}
outgoing_path
.well-known/openid-configuration
2021-12-16 19:19:12 INCOMING
fapi1-advanced-final-client-test-valid-aud-as-array
Incoming HTTP request to test instance wBVidr0t2MGeTMJ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded",
  "accept-encoding": "gzip, deflate, br",
  "content-length": "1198",
  "connection": "close"
}
incoming_path
/test-mtls/a/RP-Security-Test-PAN/token
incoming_body_form_params
{
  "grant_type": "refresh_token",
  "refresh_token": "pnnPVQueJASeZtLWXIguCJLSBNEpjCQfesRNbKMuSLYFItvfQz3691338188%\u003e? ?",
  "client_id": "SBSfBTOJMVQBBL848VGXI",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNTIsImV4cCI6MTYzOTY4MjQxMiwianRpIjoiVnlUT0t5NTNDNTRfTzBFWGE5bUVRS19JRU5ZRnVjQ2lWd0hJVzRjMHlwcyIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.kc6HfsnzkUjLPwuTy1X93KZa8EKKDx-Zjhm4IWjMZYHysUTEpUC0Lw8Ojxt4LvE0ULy3InO_usx8VxzCYfKgWUoXQQ8KO2bHBrpc5DYwed5k2cCG81d51yK-AXSC4JRf1e5AqGWAnnDWr30xyZ_9T0YXD1c5yas3AKv4w35vA4DUbINGpGkTejteqQ_3lLhhIm-EAAEX0IiGtpnRkXH1MTFvYspLXU0d-g6SmpnqFjS7AHpyC5m_wDelbV1wFG_riA8axdXD9pSqg9V3_7vT3CAxzJuNHk152AgRdzjeCVVOvJLx10WvDfhlM9t12XZQNPVlTRn3x81yJI-nAa6KNg",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
grant_type=refresh_token&refresh_token=pnnPVQueJASeZtLWXIguCJLSBNEpjCQfesRNbKMuSLYFItvfQz3691338188%25%3E%3F+%3F&client_id=SBSfBTOJMVQBBL848VGXI&client_assertion=eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNTIsImV4cCI6MTYzOTY4MjQxMiwianRpIjoiVnlUT0t5NTNDNTRfTzBFWGE5bUVRS19JRU5ZRnVjQ2lWd0hJVzRjMHlwcyIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.kc6HfsnzkUjLPwuTy1X93KZa8EKKDx-Zjhm4IWjMZYHysUTEpUC0Lw8Ojxt4LvE0ULy3InO_usx8VxzCYfKgWUoXQQ8KO2bHBrpc5DYwed5k2cCG81d51yK-AXSC4JRf1e5AqGWAnnDWr30xyZ_9T0YXD1c5yas3AKv4w35vA4DUbINGpGkTejteqQ_3lLhhIm-EAAEX0IiGtpnRkXH1MTFvYspLXU0d-g6SmpnqFjS7AHpyC5m_wDelbV1wFG_riA8axdXD9pSqg9V3_7vT3CAxzJuNHk152AgRdzjeCVVOvJLx10WvDfhlM9t12XZQNPVlTRn3x81yJI-nAa6KNg&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2021-12-16 19:19:12 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2021-12-16 19:19:12 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz\nMjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct\nNjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j\nb20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk\nYWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ\ncml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ\nKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4\n9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r\niu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6\ni56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV\nCLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3\n5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC\nAtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO\nEUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA\noD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v\ncmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB\nBQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC\nD2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k\nATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz\nb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg\nb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g\nU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg\ncmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j\nZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5\nIGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0\ncDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s\naWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL\n8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs\nZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0\nQZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY\nYFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG\nOZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,UID\u003dac60fe65-58ca-44c3-9352-6f556c5cb98e,2.5.4.5\u003d#130e3539323835343131303030313133,CN\u003dbancopan.com.br,OU\u003db6a214c7-6332-5a41-8464-a281fb9a4ca0,O\u003dBANCO PAN,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "bancopan.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2021-12-16 19:19:12 SUCCESS
CheckForClientCertificate
Found client certificate
2021-12-16 19:19:12 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz
MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct
NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j
b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk
YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ
cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4
9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r
iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6
i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV
CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3
5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC
AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO
EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA
oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v
cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB
BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC
D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k
ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz
b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg
b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g
U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg
cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j
ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5
IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0
cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s
aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL
8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs
ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0
QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY
YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG
OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks=
-----END CERTIFICATE-----
2021-12-16 19:19:12 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNTIsImV4cCI6MTYzOTY4MjQxMiwianRpIjoiVnlUT0t5NTNDNTRfTzBFWGE5bUVRS19JRU5ZRnVjQ2lWd0hJVzRjMHlwcyIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.kc6HfsnzkUjLPwuTy1X93KZa8EKKDx-Zjhm4IWjMZYHysUTEpUC0Lw8Ojxt4LvE0ULy3InO_usx8VxzCYfKgWUoXQQ8KO2bHBrpc5DYwed5k2cCG81d51yK-AXSC4JRf1e5AqGWAnnDWr30xyZ_9T0YXD1c5yas3AKv4w35vA4DUbINGpGkTejteqQ_3lLhhIm-EAAEX0IiGtpnRkXH1MTFvYspLXU0d-g6SmpnqFjS7AHpyC5m_wDelbV1wFG_riA8axdXD9pSqg9V3_7vT3CAxzJuNHk152AgRdzjeCVVOvJLx10WvDfhlM9t12XZQNPVlTRn3x81yJI-nAa6KNg",
  "header": {
    "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "SBSfBTOJMVQBBL848VGXI",
    "aud": [
      "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
      "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
      "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token"
    ],
    "iss": "SBSfBTOJMVQBBL848VGXI",
    "exp": 1639682412,
    "iat": 1639682352,
    "jti": "VyTOKy53C54_O0EXa9mEQK_IENYFucCiVwHIW4c0yps"
  }
}
2021-12-16 19:19:12
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2021-12-16 19:19:12 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNTIsImV4cCI6MTYzOTY4MjQxMiwianRpIjoiVnlUT0t5NTNDNTRfTzBFWGE5bUVRS19JRU5ZRnVjQ2lWd0hJVzRjMHlwcyIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.kc6HfsnzkUjLPwuTy1X93KZa8EKKDx-Zjhm4IWjMZYHysUTEpUC0Lw8Ojxt4LvE0ULy3InO_usx8VxzCYfKgWUoXQQ8KO2bHBrpc5DYwed5k2cCG81d51yK-AXSC4JRf1e5AqGWAnnDWr30xyZ_9T0YXD1c5yas3AKv4w35vA4DUbINGpGkTejteqQ_3lLhhIm-EAAEX0IiGtpnRkXH1MTFvYspLXU0d-g6SmpnqFjS7AHpyC5m_wDelbV1wFG_riA8axdXD9pSqg9V3_7vT3CAxzJuNHk152AgRdzjeCVVOvJLx10WvDfhlM9t12XZQNPVlTRn3x81yJI-nAa6KNg
2021-12-16 19:19:12 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-12-16 19:19:12 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2021-12-16 19:19:12 SUCCESS
ValidateRefreshToken
refresh_token parameter matches the expected value.
refresh_token
pnnPVQueJASeZtLWXIguCJLSBNEpjCQfesRNbKMuSLYFItvfQz3691338188%>? ?
2021-12-16 19:19:12 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
Euco1IGHs2D6nnP2Qy8p3PkDF5tv6nmhpWevJ7snT5kC3YuS0B
2021-12-16 19:19:12 SUCCESS
CalculateAtHash
Successful at_hash encoding
at_hash
oGhIRp4nj-wrjncnBORXlQ
2021-12-16 19:19:12
CreateRefreshToken
Created refresh token
refresh_token
SqjBKglAdFsBvoHyOzuiStKXuXMfiJpilMsuKNvIHVDRbzsAuC6521137579(# |{
2021-12-16 19:19:12 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
Euco1IGHs2D6nnP2Qy8p3PkDF5tv6nmhpWevJ7snT5kC3YuS0B
token_type
Bearer
refresh_token
SqjBKglAdFsBvoHyOzuiStKXuXMfiJpilMsuKNvIHVDRbzsAuC6521137579(# |{
scope
openid consent:urn:conformance.oidf:oypnoNOgsO accounts resources
2021-12-16 19:19:12 OUTGOING
fapi1-advanced-final-client-test-valid-aud-as-array
Response to HTTP request to test instance wBVidr0t2MGeTMJ
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "Euco1IGHs2D6nnP2Qy8p3PkDF5tv6nmhpWevJ7snT5kC3YuS0B",
  "token_type": "Bearer",
  "refresh_token": "SqjBKglAdFsBvoHyOzuiStKXuXMfiJpilMsuKNvIHVDRbzsAuC6521137579(# |{",
  "scope": "openid consent:urn:conformance.oidf:oypnoNOgsO accounts resources"
}
outgoing_path
token
2021-12-16 19:19:12 INCOMING
fapi1-advanced-final-client-test-valid-aud-as-array
Incoming HTTP request to test instance wBVidr0t2MGeTMJ
incoming_headers
{
  "host": "www.certification.openid.net",
  "accept": "application/json, text/plain, */*",
  "authorization": "Bearer Euco1IGHs2D6nnP2Qy8p3PkDF5tv6nmhpWevJ7snT5kC3YuS0B",
  "user-agent": "axios/0.21.4",
  "connection": "close"
}
incoming_path
/test-mtls/a/RP-Security-Test-PAN/accounts/v1/accounts
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-16 19:19:12 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Accounts endpoint
2021-12-16 19:19:12 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz\nMjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct\nNjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j\nb20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk\nYWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ\ncml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ\nKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4\n9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r\niu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6\ni56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV\nCLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3\n5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC\nAtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO\nEUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA\noD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v\ncmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB\nBQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC\nD2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k\nATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz\nb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg\nb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g\nU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg\ncmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j\nZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5\nIGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0\ncDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s\naWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL\n8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs\nZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0\nQZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY\nYFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG\nOZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,UID\u003dac60fe65-58ca-44c3-9352-6f556c5cb98e,2.5.4.5\u003d#130e3539323835343131303030313133,CN\u003dbancopan.com.br,OU\u003db6a214c7-6332-5a41-8464-a281fb9a4ca0,O\u003dBANCO PAN,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "bancopan.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2021-12-16 19:19:12 SUCCESS
CheckForClientCertificate
Found client certificate
2021-12-16 19:19:12 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz
MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct
NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j
b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk
YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ
cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4
9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r
iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6
i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV
CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3
5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC
AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO
EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA
oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v
cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB
BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC
D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k
ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz
b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg
b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g
U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg
cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j
ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5
IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0
cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s
aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL
8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs
ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0
QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY
YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG
OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks=
-----END CERTIFICATE-----
2021-12-16 19:19:12 SUCCESS
EnsureBearerAccessTokenNotInParams
Client correctly did not send access token in query parameters or form body
2021-12-16 19:19:12 SUCCESS
ExtractBearerAccessTokenFromHeader
Found access token on incoming request
access_token
Euco1IGHs2D6nnP2Qy8p3PkDF5tv6nmhpWevJ7snT5kC3YuS0B
2021-12-16 19:19:12 SUCCESS
RequireBearerAccessToken
Found access token in request
actual
Euco1IGHs2D6nnP2Qy8p3PkDF5tv6nmhpWevJ7snT5kC3YuS0B
2021-12-16 19:19:12 INFO
ExtractFapiDateHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-auth-date
path
headers.x-fapi-auth-date
mapped
object
incoming_request
2021-12-16 19:19:12 INFO
ExtractFapiIpAddressHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-customer-ip-address
path
headers.x-fapi-customer-ip-address
mapped
object
incoming_request
2021-12-16 19:19:12 INFO
ExtractFapiInteractionIdHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-interaction-id
path
headers.x-fapi-interaction-id
mapped
object
incoming_request
2021-12-16 19:19:12 SUCCESS
FAPIBrazilEnsureAuthorizationRequestScopesContainAccounts
'accounts' was included in authorization request scopes
actual
openid consent:urn:conformance.oidf:oypnoNOgsO accounts resources
expected
accounts
2021-12-16 19:19:12 INFO
CreateFapiInteractionIdIfNeeded
Found existing FAPI interaction ID
fapi_interaction_id
8830f113-bb0f-4e35-907d-9308105c3445
2021-12-16 19:19:12 SUCCESS
CreateFAPIAccountEndpointResponse
Created account response object
accounts_endpoint_response
{
  "conformance-test-finished": "true"
}
accounts_endpoint_response_headers
{
  "x-fapi-interaction-id": "8830f113-bb0f-4e35-907d-9308105c3445",
  "content-type": "application/json; charset\u003dUTF-8"
}
2021-12-16 19:19:12 SUCCESS
CreateBrazilAccountsEndpointResponse
Created Brazil accounts response (Please note that this is a hardcoded response copied from API documentation)
accounts_endpoint_response
{
  "data": [
    {
      "brandName": "Organização A",
      "companyCnpj": "21128159000166",
      "type": "CONTA_DEPOSITO_A_VISTA",
      "compeCode": "001",
      "branchCode": "6272",
      "number": "94088392",
      "checkDigit": "4",
      "accountId": "92792126019929279212650822221989319252576"
    }
  ],
  "links": {
    "self": "https://api.banco.com.br/open-banking/api/v1/resource",
    "first": "https://api.banco.com.br/open-banking/api/v1/resource",
    "prev": "https://api.banco.com.br/open-banking/api/v1/resource",
    "next": "https://api.banco.com.br/open-banking/api/v1/resource",
    "last": "https://api.banco.com.br/open-banking/api/v1/resource"
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2021-12-16T19:19:12Z"
  }
}
accounts_endpoint_response_headers
{
  "x-fapi-interaction-id": "8830f113-bb0f-4e35-907d-9308105c3445",
  "content-type": "application/json"
}
2021-12-16 19:19:12
ClearAccessTokenFromRequest
Condition ran but did not log anything
2021-12-16 19:19:12 OUTGOING
fapi1-advanced-final-client-test-valid-aud-as-array
Response to HTTP request to test instance wBVidr0t2MGeTMJ
outgoing_status_code
200
outgoing_headers
{
  "x-fapi-interaction-id": [
    "8830f113-bb0f-4e35-907d-9308105c3445"
  ],
  "content-type": [
    "application/json"
  ]
}
outgoing_body
{
  "data": [
    {
      "brandName": "Organização A",
      "companyCnpj": "21128159000166",
      "type": "CONTA_DEPOSITO_A_VISTA",
      "compeCode": "001",
      "branchCode": "6272",
      "number": "94088392",
      "checkDigit": "4",
      "accountId": "92792126019929279212650822221989319252576"
    }
  ],
  "links": {
    "self": "https://api.banco.com.br/open-banking/api/v1/resource",
    "first": "https://api.banco.com.br/open-banking/api/v1/resource",
    "prev": "https://api.banco.com.br/open-banking/api/v1/resource",
    "next": "https://api.banco.com.br/open-banking/api/v1/resource",
    "last": "https://api.banco.com.br/open-banking/api/v1/resource"
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2021-12-16T19:19:12Z"
  }
}
outgoing_path
accounts/v1/accounts
2021-12-16 19:19:12 FINISHED
fapi1-advanced-final-client-test-valid-aud-as-array
Test has run to completion
testmodule_result
PASSED
2021-12-16 19:19:16
TEST-RUNNER
Alias has now been claimed by another test
alias
RP-Security-Test-PAN
new_test_id
Om6erTyR3wCwg7c
Test Results