Test Summary

Test Results

Expand All Collapse All
All times are UTC
2021-12-16 19:12:26 INFO
TEST-RUNNER
Test instance OTNPIugcMuRJx9S created
baseUrl
https://www.certification.openid.net/test/a/RP-Security-Test-PAN
variant
{
  "client_auth_type": "private_key_jwt",
  "fapi_auth_request_method": "by_value",
  "fapi_profile": "openbanking_brazil",
  "fapi_jarm_type": "oidc",
  "fapi_response_mode": "plain_response"
}
alias
RP-Security-Test-PAN
description
Teste de Segurança de RP do Ambiente de Homologação do PAN para o Open Banking
planId
TQoMgbFqkMMZ0
config
{
  "alias": "RP-Security-Test-PAN",
  "description": "Teste de Segurança de RP do Ambiente de Homologação do PAN para o Open Banking",
  "server": {
    "jwks": {
      "keys": [
        {
          "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
          "kty": "RSA",
          "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
          "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
          "e": "AQAB",
          "alg": "PS256",
          "use": "sig",
          "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
          "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
          "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
          "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
          "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
          "x5c": [
            "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
          ]
        },
        {
          "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
          "kty": "RSA",
          "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
          "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
          "e": "AQAB",
          "use": "enc",
          "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
          "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
          "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
          "alg": "RSA-OAEP",
          "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
          "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
        }
      ]
    }
  },
  "client": {
    "client_id": "SBSfBTOJMVQBBL848VGXI",
    "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
    "certificate": "-----BEGIN CERTIFICATE-----\nMIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz\nMjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct\nNjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j\nb20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk\nYWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ\ncml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ\nKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4\n9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r\niu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6\ni56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV\nCLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3\n5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC\nAtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO\nEUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA\noD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v\ncmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB\nBQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC\nD2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k\nATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz\nb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg\nb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g\nU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg\ncmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j\nZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5\nIGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0\ncDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s\naWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL\n8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs\nZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0\nQZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY\nYFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG\nOZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d\n-----END CERTIFICATE-----",
    "jwks": {
      "keys": [
        {
          "alg": "PS256",
          "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
          "kty": "RSA",
          "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
          "e": "AQAB"
        }
      ]
    }
  },
  "client2": {
    "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
    "id_token_encrypted_response_alg": "RSA-OAEP",
    "id_token_encrypted_response_enc": "A256GCM",
    "client_id": "Lk4dFn0ve0wnQiN37NSDR",
    "jwks": {
      "keys": [
        {
          "alg": "PS256",
          "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
          "kty": "RSA",
          "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
          "e": "AQAB"
        },
        {
          "kty": "RSA",
          "use": "enc",
          "alg": "PS256",
          "n": "xY64ckpxUTXk7Q9e_ulwxLogYEzJ7tZswwGt7EesKk8E_Sq9o4ybEq-tWL2l_h_Q38Y8MkyxPsiKQqzwXdb5npvtZ5fv-QF3u2eqryqWm3ialiWZtIG48ia__ApswN1JZUX_3YdrzwdxJjc-SeSR0eTXB21WvJ5DxhfX8aiU8p93oHP_K7nqjUAr241XNYK119KvDI0pVbaJuwXqWJvLXWnLLfWyZXCsuoMc0yU9yEeos2CkJlEyslNF37q2M_rv-52yrevzhJ_OJjxc2As-U2EpoKAOfhqa-sVSEGEaa-YApVNV-KmEE3nw-6T7sqBBvp7sbtXuKq8RoFaQkA2kzQ",
          "e": "AQAB",
          "kid": "5997c113bd799f7e61039be31353e4e5917c28a3536ee7d0f44d5bfbf301cc55"
        }
      ]
    },
    "certificate": "-----BEGIN CERTIFICATE-----\nMIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz\nMjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct\nNjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j\nb20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk\nYWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ\ncml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ\nKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4\n9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r\niu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6\ni56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV\nCLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3\n5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC\nAtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO\nEUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA\noD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v\ncmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB\nBQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC\nD2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k\nATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz\nb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg\nb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g\nU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg\ncmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j\nZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5\nIGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0\ncDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s\naWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL\n8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs\nZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0\nQZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY\nYFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG\nOZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d\n-----END CERTIFICATE-----"
  },
  "directory": {
    "keystore": "https://keystore.sandbox.directory.openbankingbrasil.org.br/"
  }
}
testName
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
2021-12-16 19:12:26 SUCCESS
FAPIBrazilGenerateServerConfiguration
Created server configuration
server
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true
}
issuer
https://www.certification.openid.net/test/a/RP-Security-Test-PAN/
discoveryUrl
https://www.certification.openid.net/test/a/RP-Security-Test-PAN/.well-known/openid-configuration
2021-12-16 19:12:26 SUCCESS
LoadServerJWKs
Parsed public and private JWK sets
server_jwks
{
  "keys": [
    {
      "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
      "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
      "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
      "kty": "RSA",
      "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
      "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
      "alg": "PS256"
    },
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
server_encryption_keys
{
  "keys": [
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
server_public_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "alg": "PS256",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "alg": "RSA-OAEP",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
2021-12-16 19:12:26 SUCCESS
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2021-12-16 19:12:26
SetServerSigningAlgToPS256
Successfully set signing algorithm to PS256
2021-12-16 19:12:26
FAPIBrazilSetGrantTypesSupportedInServerConfiguration
Successfully set grant_types_supported
server
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ]
}
2021-12-16 19:12:26
AddClaimsParameterSupportedTrueToServerConfiguration
Successfully added claims_parameter_supported to server configuration
server
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true
}
2021-12-16 19:12:26
FAPIBrazilAddBrazilSpecificSettingsToServerConfiguration
Added open banking Brazil specific server settings
server
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ]
}
2021-12-16 19:12:26
SetTokenEndpointAuthMethodsSupportedToPrivateKeyJWTOnly
Changed token_endpoint_auth_methods_supported to private_key_jwt only in server configuration
server_configuration
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ]
}
2021-12-16 19:12:26 SUCCESS
AddResponseTypeCodeIdTokenToServerConfiguration
Added code id_token as response type supported
response_types_supported
[
  "code id_token"
]
2021-12-16 19:12:26 SUCCESS
FAPIBrazilAddTokenEndpointAuthSigningAlgValuesSupportedToServer
Set token_endpoint_auth_signing_alg_values_supported
values
[
  "PS256"
]
2021-12-16 19:12:26 SUCCESS
CheckServerConfiguration
Found required server configuration keys
required
[
  "authorization_endpoint",
  "token_endpoint",
  "issuer"
]
2021-12-16 19:12:26 SUCCESS
FAPIEnsureMinimumServerKeyLength
Validated minimum key lengths for server_jwks
server_jwks
{
  "keys": [
    {
      "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
      "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
      "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
      "kty": "RSA",
      "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
      "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
      "alg": "PS256"
    },
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
2021-12-16 19:12:26 SUCCESS
LoadUserInfo
Added user information
user_info
{
  "sub": "user-subject-1234531",
  "name": "Demo T. User",
  "email": "user@example.com",
  "email_verified": false
}
Verify configuration of first client
2021-12-16 19:12:26 SUCCESS
GetStaticClientConfiguration
Found a static client object
client_id
SBSfBTOJMVQBBL848VGXI
redirect_uri
https://api-openbanking-hml.bancopan.com.br/tpp/callback
certificate
-----BEGIN CERTIFICATE-----
MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz
MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct
NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j
b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk
YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ
cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4
9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r
iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6
i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV
CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3
5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC
AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO
EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA
oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v
cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB
BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC
D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k
ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz
b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg
b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g
U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg
cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j
ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5
IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0
cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s
aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL
8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs
ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0
QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY
YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG
OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks=
-----END CERTIFICATE-----
jwks
{
  "keys": [
    {
      "alg": "PS256",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "kty": "RSA",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
      "e": "AQAB"
    }
  ]
}
2021-12-16 19:12:26 SUCCESS
ValidateClientJWKsPublicPart
Valid client JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2021-12-16 19:12:26 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "alg": "PS256",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "kty": "RSA",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
      "e": "AQAB"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "alg": "PS256",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew"
    }
  ]
}
2021-12-16 19:12:26 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2021-12-16 19:12:26 SUCCESS
EnsureClientJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2021-12-16 19:12:26 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "alg": "PS256",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "kty": "RSA",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
      "e": "AQAB"
    }
  ]
}
Verify configuration of second client
2021-12-16 19:12:26 SUCCESS
GetStaticClient2Configuration
Found a static second client object
redirect_uri
https://api-openbanking-hml.bancopan.com.br/tpp/callback
id_token_encrypted_response_alg
RSA-OAEP
id_token_encrypted_response_enc
A256GCM
client_id
Lk4dFn0ve0wnQiN37NSDR
jwks
{
  "keys": [
    {
      "alg": "PS256",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "kty": "RSA",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
      "e": "AQAB"
    },
    {
      "kty": "RSA",
      "use": "enc",
      "alg": "PS256",
      "n": "xY64ckpxUTXk7Q9e_ulwxLogYEzJ7tZswwGt7EesKk8E_Sq9o4ybEq-tWL2l_h_Q38Y8MkyxPsiKQqzwXdb5npvtZ5fv-QF3u2eqryqWm3ialiWZtIG48ia__ApswN1JZUX_3YdrzwdxJjc-SeSR0eTXB21WvJ5DxhfX8aiU8p93oHP_K7nqjUAr241XNYK119KvDI0pVbaJuwXqWJvLXWnLLfWyZXCsuoMc0yU9yEeos2CkJlEyslNF37q2M_rv-52yrevzhJ_OJjxc2As-U2EpoKAOfhqa-sVSEGEaa-YApVNV-KmEE3nw-6T7sqBBvp7sbtXuKq8RoFaQkA2kzQ",
      "e": "AQAB",
      "kid": "5997c113bd799f7e61039be31353e4e5917c28a3536ee7d0f44d5bfbf301cc55"
    }
  ]
}
certificate
-----BEGIN CERTIFICATE-----
MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz
MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct
NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j
b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk
YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ
cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4
9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r
iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6
i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV
CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3
5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC
AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO
EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA
oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v
cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB
BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC
D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k
ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz
b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg
b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g
U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg
cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j
ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5
IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0
cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s
aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL
8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs
ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0
QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY
YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG
OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks=
-----END CERTIFICATE-----
2021-12-16 19:12:26 SUCCESS
ValidateClientJWKsPublicPart
Valid client JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2021-12-16 19:12:26 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "alg": "PS256",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "kty": "RSA",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
      "e": "AQAB"
    },
    {
      "kty": "RSA",
      "use": "enc",
      "alg": "PS256",
      "n": "xY64ckpxUTXk7Q9e_ulwxLogYEzJ7tZswwGt7EesKk8E_Sq9o4ybEq-tWL2l_h_Q38Y8MkyxPsiKQqzwXdb5npvtZ5fv-QF3u2eqryqWm3ialiWZtIG48ia__ApswN1JZUX_3YdrzwdxJjc-SeSR0eTXB21WvJ5DxhfX8aiU8p93oHP_K7nqjUAr241XNYK119KvDI0pVbaJuwXqWJvLXWnLLfWyZXCsuoMc0yU9yEeos2CkJlEyslNF37q2M_rv-52yrevzhJ_OJjxc2As-U2EpoKAOfhqa-sVSEGEaa-YApVNV-KmEE3nw-6T7sqBBvp7sbtXuKq8RoFaQkA2kzQ",
      "e": "AQAB",
      "kid": "5997c113bd799f7e61039be31353e4e5917c28a3536ee7d0f44d5bfbf301cc55"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "alg": "PS256",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "5997c113bd799f7e61039be31353e4e5917c28a3536ee7d0f44d5bfbf301cc55",
      "alg": "PS256",
      "n": "xY64ckpxUTXk7Q9e_ulwxLogYEzJ7tZswwGt7EesKk8E_Sq9o4ybEq-tWL2l_h_Q38Y8MkyxPsiKQqzwXdb5npvtZ5fv-QF3u2eqryqWm3ialiWZtIG48ia__ApswN1JZUX_3YdrzwdxJjc-SeSR0eTXB21WvJ5DxhfX8aiU8p93oHP_K7nqjUAr241XNYK119KvDI0pVbaJuwXqWJvLXWnLLfWyZXCsuoMc0yU9yEeos2CkJlEyslNF37q2M_rv-52yrevzhJ_OJjxc2As-U2EpoKAOfhqa-sVSEGEaa-YApVNV-KmEE3nw-6T7sqBBvp7sbtXuKq8RoFaQkA2kzQ"
    }
  ]
}
2021-12-16 19:12:26 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2021-12-16 19:12:26 SUCCESS
EnsureClientJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2021-12-16 19:12:26 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "alg": "PS256",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "kty": "RSA",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
      "e": "AQAB"
    },
    {
      "kty": "RSA",
      "use": "enc",
      "alg": "PS256",
      "n": "xY64ckpxUTXk7Q9e_ulwxLogYEzJ7tZswwGt7EesKk8E_Sq9o4ybEq-tWL2l_h_Q38Y8MkyxPsiKQqzwXdb5npvtZ5fv-QF3u2eqryqWm3ialiWZtIG48ia__ApswN1JZUX_3YdrzwdxJjc-SeSR0eTXB21WvJ5DxhfX8aiU8p93oHP_K7nqjUAr241XNYK119KvDI0pVbaJuwXqWJvLXWnLLfWyZXCsuoMc0yU9yEeos2CkJlEyslNF37q2M_rv-52yrevzhJ_OJjxc2As-U2EpoKAOfhqa-sVSEGEaa-YApVNV-KmEE3nw-6T7sqBBvp7sbtXuKq8RoFaQkA2kzQ",
      "e": "AQAB",
      "kid": "5997c113bd799f7e61039be31353e4e5917c28a3536ee7d0f44d5bfbf301cc55"
    }
  ]
}
2021-12-16 19:12:26
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Setup Done
2021-12-16 19:12:32 INCOMING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Incoming HTTP request to test instance OTNPIugcMuRJx9S
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/RP-Security-Test-PAN/.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-16 19:12:32 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-16 19:12:32 OUTGOING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Response to HTTP request to test instance OTNPIugcMuRJx9S
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ],
  "response_types_supported": [
    "code id_token"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256"
  ]
}
outgoing_path
.well-known/openid-configuration
2021-12-16 19:12:32 INCOMING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Incoming HTTP request to test instance OTNPIugcMuRJx9S
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded",
  "accept-encoding": "gzip, deflate, br",
  "content-length": "1210",
  "connection": "close"
}
incoming_path
/test-mtls/a/RP-Security-Test-PAN/token
incoming_body_form_params
{
  "scope": "consents",
  "grant_type": "client_credentials",
  "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
  "client_id": "SBSfBTOJMVQBBL848VGXI",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODE5NTIsImV4cCI6MTYzOTY4MjAxMiwianRpIjoia0l5ZlR2ek9PY2FmaGhnT3laMVZQcV9fS2wwQUdZdXV6aWtXcHZxaXJfUSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.eDv93qIWfLVtvqsTxXBn8ijMzdu977lJqPLOSok2-Wxvb0sItkZvyGNVMSdprrWKRK5tIkPHGmjN9L3BKdV_VLQXgqOb662GDst3AoTFEvTrEcMRQB0pfguooGWETEol7HbM80JKCsg8mEYFGed75fugBaLvEIT_wE_60GCnDXNj9CL96ycDZTlmLRPXp2n4RI1qHD5T1bkoqij3vlJGb_Nzdrl2f3ZY3hA3Q9rGv-GVYZxNXndAa3oM7w-99bORmTrx7ha9gtpNwGPJ0_kCtC94Kmy2kcHPhQPvTM3WuNUaTe-qtAJdeW0j2vWIqEggHMB-eAyuOnTXMhKwxwceZA",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
scope=consents&grant_type=client_credentials&redirect_uri=https%3A%2F%2Fapi-openbanking-hml.bancopan.com.br%2Ftpp%2Fcallback&client_id=SBSfBTOJMVQBBL848VGXI&client_assertion=eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODE5NTIsImV4cCI6MTYzOTY4MjAxMiwianRpIjoia0l5ZlR2ek9PY2FmaGhnT3laMVZQcV9fS2wwQUdZdXV6aWtXcHZxaXJfUSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.eDv93qIWfLVtvqsTxXBn8ijMzdu977lJqPLOSok2-Wxvb0sItkZvyGNVMSdprrWKRK5tIkPHGmjN9L3BKdV_VLQXgqOb662GDst3AoTFEvTrEcMRQB0pfguooGWETEol7HbM80JKCsg8mEYFGed75fugBaLvEIT_wE_60GCnDXNj9CL96ycDZTlmLRPXp2n4RI1qHD5T1bkoqij3vlJGb_Nzdrl2f3ZY3hA3Q9rGv-GVYZxNXndAa3oM7w-99bORmTrx7ha9gtpNwGPJ0_kCtC94Kmy2kcHPhQPvTM3WuNUaTe-qtAJdeW0j2vWIqEggHMB-eAyuOnTXMhKwxwceZA&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2021-12-16 19:12:32 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2021-12-16 19:12:32 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz\nMjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct\nNjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j\nb20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk\nYWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ\ncml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ\nKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4\n9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r\niu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6\ni56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV\nCLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3\n5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC\nAtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO\nEUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA\noD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v\ncmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB\nBQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC\nD2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k\nATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz\nb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg\nb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g\nU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg\ncmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j\nZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5\nIGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0\ncDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s\naWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL\n8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs\nZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0\nQZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY\nYFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG\nOZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,UID\u003dac60fe65-58ca-44c3-9352-6f556c5cb98e,2.5.4.5\u003d#130e3539323835343131303030313133,CN\u003dbancopan.com.br,OU\u003db6a214c7-6332-5a41-8464-a281fb9a4ca0,O\u003dBANCO PAN,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "bancopan.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2021-12-16 19:12:32 SUCCESS
CheckForClientCertificate
Found client certificate
2021-12-16 19:12:32 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz
MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct
NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j
b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk
YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ
cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4
9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r
iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6
i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV
CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3
5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC
AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO
EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA
oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v
cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB
BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC
D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k
ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz
b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg
b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g
U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg
cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j
ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5
IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0
cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s
aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL
8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs
ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0
QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY
YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG
OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks=
-----END CERTIFICATE-----
2021-12-16 19:12:32 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODE5NTIsImV4cCI6MTYzOTY4MjAxMiwianRpIjoia0l5ZlR2ek9PY2FmaGhnT3laMVZQcV9fS2wwQUdZdXV6aWtXcHZxaXJfUSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.eDv93qIWfLVtvqsTxXBn8ijMzdu977lJqPLOSok2-Wxvb0sItkZvyGNVMSdprrWKRK5tIkPHGmjN9L3BKdV_VLQXgqOb662GDst3AoTFEvTrEcMRQB0pfguooGWETEol7HbM80JKCsg8mEYFGed75fugBaLvEIT_wE_60GCnDXNj9CL96ycDZTlmLRPXp2n4RI1qHD5T1bkoqij3vlJGb_Nzdrl2f3ZY3hA3Q9rGv-GVYZxNXndAa3oM7w-99bORmTrx7ha9gtpNwGPJ0_kCtC94Kmy2kcHPhQPvTM3WuNUaTe-qtAJdeW0j2vWIqEggHMB-eAyuOnTXMhKwxwceZA",
  "header": {
    "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "SBSfBTOJMVQBBL848VGXI",
    "aud": [
      "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
      "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
      "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token"
    ],
    "iss": "SBSfBTOJMVQBBL848VGXI",
    "exp": 1639682012,
    "iat": 1639681952,
    "jti": "kIyfTvzOOcafhhgOyZ1VPq__Kl0AGYuuzikWpvqir_Q"
  }
}
2021-12-16 19:12:32
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2021-12-16 19:12:32 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODE5NTIsImV4cCI6MTYzOTY4MjAxMiwianRpIjoia0l5ZlR2ek9PY2FmaGhnT3laMVZQcV9fS2wwQUdZdXV6aWtXcHZxaXJfUSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.eDv93qIWfLVtvqsTxXBn8ijMzdu977lJqPLOSok2-Wxvb0sItkZvyGNVMSdprrWKRK5tIkPHGmjN9L3BKdV_VLQXgqOb662GDst3AoTFEvTrEcMRQB0pfguooGWETEol7HbM80JKCsg8mEYFGed75fugBaLvEIT_wE_60GCnDXNj9CL96ycDZTlmLRPXp2n4RI1qHD5T1bkoqij3vlJGb_Nzdrl2f3ZY3hA3Q9rGv-GVYZxNXndAa3oM7w-99bORmTrx7ha9gtpNwGPJ0_kCtC94Kmy2kcHPhQPvTM3WuNUaTe-qtAJdeW0j2vWIqEggHMB-eAyuOnTXMhKwxwceZA
2021-12-16 19:12:32 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-12-16 19:12:32 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2021-12-16 19:12:32 SUCCESS
FAPIBrazilExtractRequestedScopeFromClientCredentialsGrant
Found 'consents' scope in request
actual
[
  "consents"
]
expected
consents
2021-12-16 19:12:32 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
mSbukxMRhB2LcLYqPupAtcIRiDkwdzZnEfQXsSrUzcKYiGtPjS
2021-12-16 19:12:32 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
mSbukxMRhB2LcLYqPupAtcIRiDkwdzZnEfQXsSrUzcKYiGtPjS
token_type
Bearer
2021-12-16 19:12:32
CopyAccessTokenToClientCredentialsField
Condition ran but did not log anything
2021-12-16 19:12:32 OUTGOING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Response to HTTP request to test instance OTNPIugcMuRJx9S
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "mSbukxMRhB2LcLYqPupAtcIRiDkwdzZnEfQXsSrUzcKYiGtPjS",
  "token_type": "Bearer"
}
outgoing_path
token
2021-12-16 19:12:32 INCOMING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Incoming HTTP request to test instance OTNPIugcMuRJx9S
incoming_headers
{
  "host": "www.certification.openid.net",
  "accept": "application/json, text/plain, */*",
  "content-type": "application/json",
  "authorization": "Bearer mSbukxMRhB2LcLYqPupAtcIRiDkwdzZnEfQXsSrUzcKYiGtPjS",
  "user-agent": "axios/0.21.4",
  "content-length": "261",
  "connection": "close"
}
incoming_path
/test-mtls/a/RP-Security-Test-PAN/consents/v1/consents
incoming_body_form_params
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks= -----END CERTIFICATE-----
incoming_body_json
{
  "data": {
    "loggedUser": {
      "document": {
        "identification": "44257214899",
        "rel": "CPF"
      }
    },
    "permissions": [
      "RESOURCES_READ",
      "ACCOUNTS_READ",
      "ACCOUNTS_TRANSACTIONS_READ",
      "ACCOUNTS_OVERDRAFT_LIMITS_READ",
      "ACCOUNTS_BALANCES_READ"
    ],
    "expirationDateTime": "2022-08-21T08:30:00Z"
  }
}
incoming_query_string_params
{}
incoming_body
{"data":{"loggedUser":{"document":{"identification":"44257214899","rel":"CPF"}},"permissions":["RESOURCES_READ","ACCOUNTS_READ","ACCOUNTS_TRANSACTIONS_READ","ACCOUNTS_OVERDRAFT_LIMITS_READ","ACCOUNTS_BALANCES_READ"],"expirationDateTime":"2022-08-21T08:30:00Z"}}
2021-12-16 19:12:32 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
New consent endpoint
2021-12-16 19:12:32 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz\nMjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct\nNjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j\nb20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk\nYWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ\ncml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ\nKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4\n9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r\niu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6\ni56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV\nCLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3\n5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC\nAtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO\nEUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA\noD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v\ncmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB\nBQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC\nD2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k\nATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz\nb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg\nb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g\nU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg\ncmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j\nZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5\nIGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0\ncDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s\naWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL\n8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs\nZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0\nQZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY\nYFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG\nOZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,UID\u003dac60fe65-58ca-44c3-9352-6f556c5cb98e,2.5.4.5\u003d#130e3539323835343131303030313133,CN\u003dbancopan.com.br,OU\u003db6a214c7-6332-5a41-8464-a281fb9a4ca0,O\u003dBANCO PAN,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "bancopan.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2021-12-16 19:12:32 SUCCESS
CheckForClientCertificate
Found client certificate
2021-12-16 19:12:32 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz
MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct
NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j
b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk
YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ
cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4
9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r
iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6
i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV
CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3
5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC
AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO
EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA
oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v
cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB
BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC
D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k
ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz
b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg
b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g
U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg
cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j
ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5
IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0
cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s
aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL
8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs
ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0
QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY
YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG
OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks=
-----END CERTIFICATE-----
2021-12-16 19:12:32 SUCCESS
EnsureIncomingRequestMethodIsPost
Client correctly used http POST method
2021-12-16 19:12:32 SUCCESS
EnsureBearerAccessTokenNotInParams
Client correctly did not send access token in query parameters or form body
2021-12-16 19:12:32 SUCCESS
ExtractBearerAccessTokenFromHeader
Found access token on incoming request
access_token
mSbukxMRhB2LcLYqPupAtcIRiDkwdzZnEfQXsSrUzcKYiGtPjS
2021-12-16 19:12:32 SUCCESS
RequireBearerClientCredentialsAccessToken
Found access token in request
actual
mSbukxMRhB2LcLYqPupAtcIRiDkwdzZnEfQXsSrUzcKYiGtPjS
2021-12-16 19:12:32 INFO
ExtractFapiDateHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-auth-date
path
headers.x-fapi-auth-date
mapped
object
incoming_request
2021-12-16 19:12:32 INFO
ExtractFapiIpAddressHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-customer-ip-address
path
headers.x-fapi-customer-ip-address
mapped
object
incoming_request
2021-12-16 19:12:32 INFO
ExtractFapiInteractionIdHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-interaction-id
path
headers.x-fapi-interaction-id
mapped
object
incoming_request
2021-12-16 19:12:32 SUCCESS
FAPIBrazilEnsureClientCredentialsScopeContainedConsents
The token request which was used to obtain the access token contained 'consents' scope
actual
[
  "consents"
]
2021-12-16 19:12:32
FAPIBrazilExtractConsentRequest
Condition ran but did not log anything
2021-12-16 19:12:32 SUCCESS
CreateFapiInteractionIdIfNeeded
Created new FAPI interaction ID
fapi_interaction_id
8c460149-b7fb-48a1-8d9e-f7caa464e398
2021-12-16 19:12:32 SUCCESS
FAPIBrazilGenerateNewConsentResponse
Created consent response
headers
{
  "x-fapi-interaction-id": "8c460149-b7fb-48a1-8d9e-f7caa464e398"
}
consentId
urn:conformance.oidf:2vwcM0K6Mk
consent_response
{
  "data": {
    "consentId": "urn:conformance.oidf:2vwcM0K6Mk",
    "creationDateTime": "2021-12-16T19:12:32Z",
    "status": "AWAITING_AUTHORISATION",
    "statusUpdateDateTime": "2021-12-16T19:12:32Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2021-12-16T21:12:32Z",
    "transactionFromDateTime": "2021-12-16T19:07:32Z",
    "transactionToDateTime": "2021-12-16T21:12:32Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/RP-Security-Test-PANconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2021-12-16T19:12:32Z"
  }
}
2021-12-16 19:12:32
ClearAccessTokenFromRequest
Condition ran but did not log anything
2021-12-16 19:12:32 OUTGOING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Response to HTTP request to test instance OTNPIugcMuRJx9S
outgoing_status_code
201
outgoing_headers
{
  "x-fapi-interaction-id": [
    "8c460149-b7fb-48a1-8d9e-f7caa464e398"
  ]
}
outgoing_body
{
  "data": {
    "consentId": "urn:conformance.oidf:2vwcM0K6Mk",
    "creationDateTime": "2021-12-16T19:12:32Z",
    "status": "AWAITING_AUTHORISATION",
    "statusUpdateDateTime": "2021-12-16T19:12:32Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2021-12-16T21:12:32Z",
    "transactionFromDateTime": "2021-12-16T19:07:32Z",
    "transactionToDateTime": "2021-12-16T21:12:32Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/RP-Security-Test-PANconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2021-12-16T19:12:32Z"
  }
}
outgoing_path
consents/v1/consents
2021-12-16 19:12:33 INCOMING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Incoming HTTP request to test instance OTNPIugcMuRJx9S
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/RP-Security-Test-PAN/.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-16 19:12:33 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-16 19:12:33 OUTGOING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Response to HTTP request to test instance OTNPIugcMuRJx9S
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ],
  "response_types_supported": [
    "code id_token"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256"
  ]
}
outgoing_path
.well-known/openid-configuration
2021-12-16 19:12:33 INCOMING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Incoming HTTP request to test instance OTNPIugcMuRJx9S
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/RP-Security-Test-PAN/jwks
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-16 19:12:33 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-16 19:12:33 OUTGOING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Response to HTTP request to test instance OTNPIugcMuRJx9S
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "alg": "PS256",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "alg": "RSA-OAEP",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
outgoing_path
jwks
2021-12-16 19:12:34 INCOMING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Incoming HTTP request to test instance OTNPIugcMuRJx9S
incoming_headers
{
  "host": "www.certification.openid.net",
  "accept": "application/json, text/plain, */*",
  "content-type": "application/json",
  "x-idempotency-key": "65ce33ad-50c1-430f-a097-6767be0f9cc6",
  "test-name": "22-fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response.by_value",
  "authorization": "Bearer eyJraWQiOiJkZWZhdWx0IiwiYWxnIjoiUlMyNTYifQ.eyJzdWIiOiI3NGViNGMyMi1mYTZlLTQzNTgtYWI0Yy0yMmZhNmUxMzU4MzMiLCJhdWQiOiI3NGViNGMyMi1mYTZlLTQzNTgtYWI0Yy0yMmZhNmUxMzU4MzMiLCJkb21haW4iOiIwZmI2NjgxOC0yZTE3LTRhNzQtYjY2OC0xODJlMTcyYTc0ZjgiLCJzY29wZSI6ImNvbnNlbnRfYWRtaW4gcHJveHlfcmVhZCB0ZW5hbnRfYWRtaW4gY2F0ZWdvcnlfYWRtaW4gb3JnYW5pemF0aW9uX2FkbWluIiwiaXNzIjoiaHR0cDpcL1wvdHBwLWlhbS1vcGVuYmFua2luZy1obWwuYmFuY29wYW4uY29tLmJyXC9hbVwvdHBwXC9vaWRjIiwiZXhwIjoxNjM5Njg5MTUwLCJpYXQiOjE2Mzk2ODE5NTAsImp0aSI6IlprYmFhb2NVaDRGWi00NktGZEY5OTNJQ3FPQ2FzaHBOZHRsRC1ydmoxR2sifQ.CI14nzlMtWghZyscDLzkH5ae4LRazxRUhoNLftS-FOUZSDE4lKDHCRx50haSIS4GxG95IDkDngkQxNPvpLbE-E9gCz_Vsest_R5N5lIKpGkB7PbzUPDVhQJhJTGxuB5z9LDto3G52RWOvTCI_gVJYXW9HDMl7TtcEZ_tANRJ0CeIHtKadbD3tJ_E72FK4clgh7ToF5EU3DB5QNZDPIk4FYbxYJgrEHpQGoR5Nk-rgvEmniXQ7J5fZzHWBA0E328kk5MQQW_r-JbCtBZgnSjX75Go1jWY3UoPHF78CMVVhw29Y0uqwDcuVUDtj3zlDuc9ew1_2HUsOpBVFKm0urY09g",
  "user-agent": "axios/0.24.0",
  "connection": "close"
}
incoming_path
/test/a/RP-Security-Test-PAN/authorize
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
DHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{
  "client_id": "SBSfBTOJMVQBBL848VGXI",
  "scope": "openid consent:urn:conformance.oidf:2vwcM0K6Mk accounts resources",
  "response_type": "code id_token",
  "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
  "request": "eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZHQ00iLCJjdHkiOiJvYXV0aC1hdXRoei1yZXErand0Iiwia2lkIjoiMGZlNTAyZGQtMTRmMC00ZjQ1LTgwZjktZmViOWEyMTZmOTk2In0.Y2sIOjW3qJQLz_IEY7pg07P_Gk48XjxJX6aIwq3LBIrNpZZmCvsMyTEDkzd4gaUU4Y7MOUl7oB6eLCRycGlLStUPyvarF9G7ZbBH2J71tbSpufMuyNz398VypBSW9G5m6TrqzUxThVq0pn8nn8pLNMZi8AU9i0rtUVssLGhc85gexTOJOEjW7wFFsw5-k3I2hCobK6NJ5d2q3W3eOCmEE93uX29J_hLVT19_w7MkOqUdk34j0DooVx_jTZsTKPqvv279v75QO12dEDiWLifWxUocRX8MqqZ3pIj7PUc-qd5Rsvsn7W-7GTAcpZg0_f9JktVWLm9epLJRaf6S4RkX5Q.ZMQL5HsfjrsMO8Kx.9mhfRt3JKU6HxAqqHmyyqqmFpQ6FEksWoian5krRY9_WqxY3rreU-JUjd6iJRTtiHz3_C6JN04vvDeSS6EroEBZRxDKJC1lmCZSHanfRBFDCCeAF2KofIMxxpOGWkAVTlWPYg_c-fgTPx0DRVxRyMhURR9obrPpdQLv9zEf1kHC_ePT8UVaIlahx38rJ8tnyEwqEAOAZmLrkipMtS9_rBH4U40H5ha89RvYnS2sxOEGmN5Np_1r93FCtXEA-MASBoYYoA18eJWkqmUxRGIlMNjRN9hVPjY5Gula7TQC8GOPy3P3YctcSmU4JdIiMsKhh9xHNSedikmmJ1f0GZPE1sUjoUJrAdpQep-PJpcL41EY7E2ePLtUIOfnRE8DxqIhXSsYyQ8PZqrPPFQEz9vyvG3ntyur3kbLhTYZgyGyhW3DkbjR2RP8PQgI2pmoUf4_jjJz7OKTJ-so032LL6t5X8iY33FyDXgFqsfi0s59GXz8ZMp_08zxYzYf66zwb3jMK3czNaJ-Ve-oaLO5GWVt8ugqsmH_t47yN_AsV5Z2U7HursxWh-kJ1S0BGECpPffWS7-y27yQbFX7ho_n0f28AT8mz6XUqppOfPSs4JOUos26C5wGub2BwMNYuBQj2ppSLcBQcFxWQe_WnPd0tM22f6zpsmgVpkBCtENLjWvKZU1AV82rGTDydj7Eb3phK_rlJg5TvdNfQPOvnAhDcbGccGXyU7lD261uTfGqU3ES8rGBhx_XLAM6ILAunqrSkyVS2g6m0unhJeF77kBJaiKOAMzkpjUY_cq7bAjy7ZOjjbScVMijLbe2KgW5MFjV5sjB_CMPSUN_yheignW7T8Y1sL9P8OcW9qtNsfVUQimUGtZbZp0byNJSwWdNvj7cCjjNT1ctf07zfBH4qe0Og6cm6pxDi2v4TNHOW9gQveNdTt4iDVN7bR7DSXS_reXeMyts5oUgC0xctfWwkhQ3b0tW9KUWE7IMDsfAhN4QgNKSe51q1gB--jTen1H33x2YGqQvApNGZM7h6HS94CNhiTtZGOmI148IPvgXXh-A74FfQSV2K-LhxeVb2fZEO9B5HNGqNKhm9NZFfSlH_fRUwvz05DS5OQwWBsRmvFlMfwcvOfcxUppAvdo_uxshBGV9xX_lMOw-P_ghG67i4IIJaPX4AQTyDjdLxUhAujsW4apSO-XPx_9hFlDFN2A6djaPS6Ae1ZqwI_DfoKdbBUquZIkKeB2h8hCH1MMiEaL58GKFnNMv-NPUX52JEW0lD6bmkyt4_HZRROV6lXbAiudOL6F37F-AkJhGu0bJbiAic_tU3vnJG4ZhpLhHMOru3vkEJgGeJ0S1j8OaoxrJkUNWM3F62DHBlK_iHSeDgPhO2qOtNxLwUof-gn7k5wwb9oTz3jI3rnt_Mx0AToCBDDtYU9mfBNYf11s9E5pBzaeQ5_2OOSmKer07Ym_FP7b-mqleUybKmLMY8kPW3ivR9wqa1k8kgpU9cFQJ41d-M0mCQwp3PyowUcnv6rdIKz3rdL9WUyB_kNpHQjpORkvd4UnoElLSg1WAzuI3bq37R9YnyaWZXLoQvsk83Jz9dQEeEtJwGSUFWKq7TmGMQU4s2Bj_daWjZ8kASXhjbf10TnBkOTXo3CvU89K9HJLy4q9fIfrjzNsJf6JNWl7DGIGK2kEfSy3OibUPTxltI0cbxSVTdV7e1ncJzCjEUXQXKz4YhfVVOw0FgmW0jI9QA_dftQuEvWpCOst5WKUhx0hQBD3TQECPgDfKMhZEAtoDG-vi9uC1YZoLubFeTGXL3Tx86_S1edYXp4eCRo_OShwk-1AEhO9KtuF03gsnU7vSzHDZuIZoJCmj0YXliTQHYWZFT.qkiI1PSRHRDj5k3v92SkYg"
}
incoming_body
2021-12-16 19:12:34 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
DHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Authorization endpoint
2021-12-16 19:12:34 SUCCESS
ExtractRequestObject
Parsed request object
request_object
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6Im9hdXRoLWF1dGh6LXJlcStqd3QiLCJraWQiOiI1Z1lISUhidHcwVUI0QndqdHFVbmh0Rk42V3RoRVcybWRYN2RmVUJRSElJIn0.eyJzY29wZSI6Im9wZW5pZCBjb25zZW50OnVybjpjb25mb3JtYW5jZS5vaWRmOjJ2d2NNMEs2TWsgYWNjb3VudHMgcmVzb3VyY2VzIiwicmVzcG9uc2VfdHlwZSI6ImNvZGUgaWRfdG9rZW4iLCJyZWRpcmVjdF91cmkiOiJodHRwczovL2FwaS1vcGVuYmFua2luZy1obWwuYmFuY29wYW4uY29tLmJyL3RwcC9jYWxsYmFjayIsImNvZGVfY2hhbGxlbmdlIjoiODNuS0RSVHZ4WkRGZm43T2RySS15clk5ZXE4WTRqRWliR1BLZDZHNDgxSSIsImNvZGVfY2hhbGxlbmdlX21ldGhvZCI6IlMyNTYiLCJyZXNwb25zZV9tb2RlIjoiZnJhZ21lbnQiLCJzdGF0ZSI6IjI1NmI0MmE5NGI0MmU3YzlmYWRiMDUxMjk3OGI3MTQyOTY2YTE5MDVmNTBmZWM2Nzg3NzQxNzkwZWNhMTIyYWMiLCJub25jZSI6IjFhOTAyMmIzZGQ2YTU2NDc3Mzc4NWI3ZWZhODE5NzVlNDljZmQ2NDJlNzU2YzZlYmNiMzQxYjcxMGNmOTBlZjUiLCJpc3MiOiJTQlNmQlRPSk1WUUJCTDg0OFZHWEkiLCJhdWQiOiJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImNsaWVudF9pZCI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImp0aSI6IjVQZzNORTljNU5rNkhQUjA5OEV4dzF2Z0NxMTFKcDhGT1VnZnkwWGNFeEEiLCJpYXQiOjE2Mzk2ODE5NTMsImV4cCI6MTYzOTY4MjI1MywibmJmIjoxNjM5NjgxOTUzfQ.bEhbHMKJSYv_oByprXN6bSKOYVgeJKW-EFPhikFAegV1eG8VIAvfdR93mU-bMMzhrYgYyUrhIRTU3YKpovYTh6w33enwlJA93pBJqhIuLEHBeJ53jTqlU8y-Hb9ZKE3Vv5r3QIxYZ3I1J666XEbAd-ObtiBSPeGJuMQAB0zB0bXk0gGoEVQfqemrkHUFrMSb_9_AydHQ-IDeLn_pLdSeAJnhPjdjQYB5Q8FcxUc1bSDeQ1cJnNY4me3A7-BiD23wg9rJrtxs_j-gEsoRIIp0sfdfNvSQKVhSskYQR8pilFDM7L04a9rFOZlA9lzvZ6rBzsrjhGRYXagWF59omdwvHA",
  "header": {
    "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
    "typ": "oauth-authz-req+jwt",
    "alg": "PS256"
  },
  "claims": {
    "iss": "SBSfBTOJMVQBBL848VGXI",
    "response_type": "code id_token",
    "code_challenge_method": "S256",
    "nonce": "1a9022b3dd6a564773785b7efa81975e49cfd642e756c6ebcb341b710cf90ef5",
    "client_id": "SBSfBTOJMVQBBL848VGXI",
    "response_mode": "fragment",
    "aud": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
    "nbf": 1639681953,
    "scope": "openid consent:urn:conformance.oidf:2vwcM0K6Mk accounts resources",
    "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
    "state": "256b42a94b42e7c9fadb0512978b7142966a1905f50fec6787741790eca122ac",
    "exp": 1639682253,
    "iat": 1639681953,
    "code_challenge": "83nKDRTvxZDFfn7OdrI-yrY9eq8Y4jEibGPKd6G481I",
    "jti": "5Pg3NE9c5Nk6HPR098Exw1vgCq11Jp8FOUgfy0XcExA"
  },
  "jwe_header": {
    "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
    "cty": "oauth-authz-req+jwt",
    "enc": "A256GCM",
    "alg": "RSA-OAEP"
  }
}
2021-12-16 19:12:34 SUCCESS
EnsureRequestObjectWasEncrypted
Request object was encrypted
jwe_header
{
  "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
  "cty": "oauth-authz-req+jwt",
  "enc": "A256GCM",
  "alg": "RSA-OAEP"
}
2021-12-16 19:12:34 SUCCESS
FAPIBrazilEnsureRequestObjectEncryptedUsingRSAOAEPA256GCM
Request object was encrypted using RSA-OAEP and A256GCM
jwe_header
{
  "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
  "cty": "oauth-authz-req+jwt",
  "enc": "A256GCM",
  "alg": "RSA-OAEP"
}
2021-12-16 19:12:34 SUCCESS
ValidateEncryptedRequestObjectHasKid
kid was found in the encrypted request object header
kid
0fe502dd-14f0-4f45-80f9-feb9a216f996
2021-12-16 19:12:34 SUCCESS
CreateEffectiveAuthorizationRequestParameters
Merged http request parameters with request object claims
effective_authorization_endpoint_request
{
  "client_id": "SBSfBTOJMVQBBL848VGXI",
  "scope": "openid consent:urn:conformance.oidf:2vwcM0K6Mk accounts resources",
  "response_type": "code id_token",
  "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
  "request": "eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZHQ00iLCJjdHkiOiJvYXV0aC1hdXRoei1yZXErand0Iiwia2lkIjoiMGZlNTAyZGQtMTRmMC00ZjQ1LTgwZjktZmViOWEyMTZmOTk2In0.Y2sIOjW3qJQLz_IEY7pg07P_Gk48XjxJX6aIwq3LBIrNpZZmCvsMyTEDkzd4gaUU4Y7MOUl7oB6eLCRycGlLStUPyvarF9G7ZbBH2J71tbSpufMuyNz398VypBSW9G5m6TrqzUxThVq0pn8nn8pLNMZi8AU9i0rtUVssLGhc85gexTOJOEjW7wFFsw5-k3I2hCobK6NJ5d2q3W3eOCmEE93uX29J_hLVT19_w7MkOqUdk34j0DooVx_jTZsTKPqvv279v75QO12dEDiWLifWxUocRX8MqqZ3pIj7PUc-qd5Rsvsn7W-7GTAcpZg0_f9JktVWLm9epLJRaf6S4RkX5Q.ZMQL5HsfjrsMO8Kx.9mhfRt3JKU6HxAqqHmyyqqmFpQ6FEksWoian5krRY9_WqxY3rreU-JUjd6iJRTtiHz3_C6JN04vvDeSS6EroEBZRxDKJC1lmCZSHanfRBFDCCeAF2KofIMxxpOGWkAVTlWPYg_c-fgTPx0DRVxRyMhURR9obrPpdQLv9zEf1kHC_ePT8UVaIlahx38rJ8tnyEwqEAOAZmLrkipMtS9_rBH4U40H5ha89RvYnS2sxOEGmN5Np_1r93FCtXEA-MASBoYYoA18eJWkqmUxRGIlMNjRN9hVPjY5Gula7TQC8GOPy3P3YctcSmU4JdIiMsKhh9xHNSedikmmJ1f0GZPE1sUjoUJrAdpQep-PJpcL41EY7E2ePLtUIOfnRE8DxqIhXSsYyQ8PZqrPPFQEz9vyvG3ntyur3kbLhTYZgyGyhW3DkbjR2RP8PQgI2pmoUf4_jjJz7OKTJ-so032LL6t5X8iY33FyDXgFqsfi0s59GXz8ZMp_08zxYzYf66zwb3jMK3czNaJ-Ve-oaLO5GWVt8ugqsmH_t47yN_AsV5Z2U7HursxWh-kJ1S0BGECpPffWS7-y27yQbFX7ho_n0f28AT8mz6XUqppOfPSs4JOUos26C5wGub2BwMNYuBQj2ppSLcBQcFxWQe_WnPd0tM22f6zpsmgVpkBCtENLjWvKZU1AV82rGTDydj7Eb3phK_rlJg5TvdNfQPOvnAhDcbGccGXyU7lD261uTfGqU3ES8rGBhx_XLAM6ILAunqrSkyVS2g6m0unhJeF77kBJaiKOAMzkpjUY_cq7bAjy7ZOjjbScVMijLbe2KgW5MFjV5sjB_CMPSUN_yheignW7T8Y1sL9P8OcW9qtNsfVUQimUGtZbZp0byNJSwWdNvj7cCjjNT1ctf07zfBH4qe0Og6cm6pxDi2v4TNHOW9gQveNdTt4iDVN7bR7DSXS_reXeMyts5oUgC0xctfWwkhQ3b0tW9KUWE7IMDsfAhN4QgNKSe51q1gB--jTen1H33x2YGqQvApNGZM7h6HS94CNhiTtZGOmI148IPvgXXh-A74FfQSV2K-LhxeVb2fZEO9B5HNGqNKhm9NZFfSlH_fRUwvz05DS5OQwWBsRmvFlMfwcvOfcxUppAvdo_uxshBGV9xX_lMOw-P_ghG67i4IIJaPX4AQTyDjdLxUhAujsW4apSO-XPx_9hFlDFN2A6djaPS6Ae1ZqwI_DfoKdbBUquZIkKeB2h8hCH1MMiEaL58GKFnNMv-NPUX52JEW0lD6bmkyt4_HZRROV6lXbAiudOL6F37F-AkJhGu0bJbiAic_tU3vnJG4ZhpLhHMOru3vkEJgGeJ0S1j8OaoxrJkUNWM3F62DHBlK_iHSeDgPhO2qOtNxLwUof-gn7k5wwb9oTz3jI3rnt_Mx0AToCBDDtYU9mfBNYf11s9E5pBzaeQ5_2OOSmKer07Ym_FP7b-mqleUybKmLMY8kPW3ivR9wqa1k8kgpU9cFQJ41d-M0mCQwp3PyowUcnv6rdIKz3rdL9WUyB_kNpHQjpORkvd4UnoElLSg1WAzuI3bq37R9YnyaWZXLoQvsk83Jz9dQEeEtJwGSUFWKq7TmGMQU4s2Bj_daWjZ8kASXhjbf10TnBkOTXo3CvU89K9HJLy4q9fIfrjzNsJf6JNWl7DGIGK2kEfSy3OibUPTxltI0cbxSVTdV7e1ncJzCjEUXQXKz4YhfVVOw0FgmW0jI9QA_dftQuEvWpCOst5WKUhx0hQBD3TQECPgDfKMhZEAtoDG-vi9uC1YZoLubFeTGXL3Tx86_S1edYXp4eCRo_OShwk-1AEhO9KtuF03gsnU7vSzHDZuIZoJCmj0YXliTQHYWZFT.qkiI1PSRHRDj5k3v92SkYg",
  "iss": "SBSfBTOJMVQBBL848VGXI",
  "code_challenge_method": "S256",
  "nonce": "1a9022b3dd6a564773785b7efa81975e49cfd642e756c6ebcb341b710cf90ef5",
  "response_mode": "fragment",
  "aud": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "nbf": 1639681953,
  "state": "256b42a94b42e7c9fadb0512978b7142966a1905f50fec6787741790eca122ac",
  "exp": 1639682253,
  "iat": 1639681953,
  "code_challenge": "83nKDRTvxZDFfn7OdrI-yrY9eq8Y4jEibGPKd6G481I",
  "jti": "5Pg3NE9c5Nk6HPR098Exw1vgCq11Jp8FOUgfy0XcExA"
}
2021-12-16 19:12:34 SUCCESS
FAPIValidateRequestObjectSigningAlg
Request object was signed with a permitted algorithm
alg
PS256
2021-12-16 19:12:34
FAPIBrazilValidateRequestObjectIdTokenACRClaims
acr claim is not requested
2021-12-16 19:12:34 SUCCESS
FAPIValidateRequestObjectExp
Request object contains a valid exp claim, expiry time
exp
"Dec 16, 2021, 7:17:33 PM"
2021-12-16 19:12:34 SUCCESS
FAPI1AdvancedValidateRequestObjectNBFClaim
nbf claim is valid
nbf
"Dec 16, 2021, 7:12:33 PM"
now
"Dec 16, 2021, 7:12:34 PM"
2021-12-16 19:12:34
ValidateRequestObjectClaims
Request object does not contain a max_age claim
2021-12-16 19:12:34 SUCCESS
ValidateRequestObjectClaims
Request object claims passed all validation checks
2021-12-16 19:12:34 SUCCESS
EnsureNumericRequestObjectClaimsAreNotNull
None of the claims expected to have numeric values, have null values
numeric_claims
[
  "max_age"
]
2021-12-16 19:12:34 SUCCESS
EnsureRequestObjectDoesNotContainRequestOrRequestUri
Request object does not contain request or request_uri
2021-12-16 19:12:34 SUCCESS
EnsureRequestObjectDoesNotContainSubWithClientId
Request object does not contain Client Id in sub
2021-12-16 19:12:34 SUCCESS
ValidateRequestObjectSignature
Request object signature validated using a key in the client's JWKS and using the client's registered request_object_signing_alg
request_object
eyJhbGciOiJQUzI1NiIsInR5cCI6Im9hdXRoLWF1dGh6LXJlcStqd3QiLCJraWQiOiI1Z1lISUhidHcwVUI0QndqdHFVbmh0Rk42V3RoRVcybWRYN2RmVUJRSElJIn0.eyJzY29wZSI6Im9wZW5pZCBjb25zZW50OnVybjpjb25mb3JtYW5jZS5vaWRmOjJ2d2NNMEs2TWsgYWNjb3VudHMgcmVzb3VyY2VzIiwicmVzcG9uc2VfdHlwZSI6ImNvZGUgaWRfdG9rZW4iLCJyZWRpcmVjdF91cmkiOiJodHRwczovL2FwaS1vcGVuYmFua2luZy1obWwuYmFuY29wYW4uY29tLmJyL3RwcC9jYWxsYmFjayIsImNvZGVfY2hhbGxlbmdlIjoiODNuS0RSVHZ4WkRGZm43T2RySS15clk5ZXE4WTRqRWliR1BLZDZHNDgxSSIsImNvZGVfY2hhbGxlbmdlX21ldGhvZCI6IlMyNTYiLCJyZXNwb25zZV9tb2RlIjoiZnJhZ21lbnQiLCJzdGF0ZSI6IjI1NmI0MmE5NGI0MmU3YzlmYWRiMDUxMjk3OGI3MTQyOTY2YTE5MDVmNTBmZWM2Nzg3NzQxNzkwZWNhMTIyYWMiLCJub25jZSI6IjFhOTAyMmIzZGQ2YTU2NDc3Mzc4NWI3ZWZhODE5NzVlNDljZmQ2NDJlNzU2YzZlYmNiMzQxYjcxMGNmOTBlZjUiLCJpc3MiOiJTQlNmQlRPSk1WUUJCTDg0OFZHWEkiLCJhdWQiOiJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImNsaWVudF9pZCI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImp0aSI6IjVQZzNORTljNU5rNkhQUjA5OEV4dzF2Z0NxMTFKcDhGT1VnZnkwWGNFeEEiLCJpYXQiOjE2Mzk2ODE5NTMsImV4cCI6MTYzOTY4MjI1MywibmJmIjoxNjM5NjgxOTUzfQ.bEhbHMKJSYv_oByprXN6bSKOYVgeJKW-EFPhikFAegV1eG8VIAvfdR93mU-bMMzhrYgYyUrhIRTU3YKpovYTh6w33enwlJA93pBJqhIuLEHBeJ53jTqlU8y-Hb9ZKE3Vv5r3QIxYZ3I1J666XEbAd-ObtiBSPeGJuMQAB0zB0bXk0gGoEVQfqemrkHUFrMSb_9_AydHQ-IDeLn_pLdSeAJnhPjdjQYB5Q8FcxUc1bSDeQ1cJnNY4me3A7-BiD23wg9rJrtxs_j-gEsoRIIp0sfdfNvSQKVhSskYQR8pilFDM7L04a9rFOZlA9lzvZ6rBzsrjhGRYXagWF59omdwvHA
request_object_signing_alg
PS256
jwk
Sun RSA public key, 2048 bits
  params: null
  modulus: 22677997123100865027038163618440931425768853246042685053952059568088768370775879662687649598715143390108338286915488499774626148365554590008656132577357893743438278711902761437715966243285423555795769385881803147871566517201086180684345745904063840678522561040685569999111501676387252045965556897951681323146595605739539663340316188618451821106202340139520257397286742681119465613725230213120667075481235349311488074650446518605298417452683228189337358541483332915940982625541029074799406321696170037150264352053879457399805139882493978179691887049996822814968964846225178258105165825398408907737359544759640349473403
  public exponent: 65537
2021-12-16 19:12:34 SUCCESS
EnsureMatchingRedirectUriInRequestObject
Redirect URI matched
actual
https://api-openbanking-hml.bancopan.com.br/tpp/callback
2021-12-16 19:12:34 SUCCESS
EnsureRequiredAuthorizationRequestParametersMatchRequestObject
Required http request parameters match request object claims
response_type
code id_token
client_id
SBSfBTOJMVQBBL848VGXI
2021-12-16 19:12:34 SUCCESS
EnsureOptionalAuthorizationRequestParametersMatchRequestObject
All http request parameters and request object claims match
2021-12-16 19:12:34 SUCCESS
EnsureAuthorizationHttpRequestContainsOpenIDScope
Found 'openid' in scope http request parameter
actual
[
  "openid",
  "consent:urn:conformance.oidf:2vwcM0K6Mk",
  "accounts",
  "resources"
]
expected
openid
2021-12-16 19:12:34 SUCCESS
ExtractRequestedScopes
Requested scopes
scope
openid consent:urn:conformance.oidf:2vwcM0K6Mk accounts resources
2021-12-16 19:12:34 SUCCESS
FAPIBrazilValidateConsentScope
Found consent scope in request
actual
[
  "openid",
  "consent:urn:conformance.oidf:2vwcM0K6Mk",
  "accounts",
  "resources"
]
expected
consent:urn:conformance.oidf:2vwcM0K6Mk
2021-12-16 19:12:34 SUCCESS
EnsureScopeContainsAccounts
Found accounts scope in request
actual
[
  "openid",
  "consent:urn:conformance.oidf:2vwcM0K6Mk",
  "accounts",
  "resources"
]
2021-12-16 19:12:34 SUCCESS
EnsureResponseTypeIsCodeIdToken
Response type is expected value
expected
code id_token
2021-12-16 19:12:34 SUCCESS
EnsureOpenIDInScopeRequest
Found 'openid' scope in request
actual
[
  "openid",
  "consent:urn:conformance.oidf:2vwcM0K6Mk",
  "accounts",
  "resources"
]
expected
openid
2021-12-16 19:12:34 SUCCESS
EnsureMatchingClientId
Client ID matched
client_id
SBSfBTOJMVQBBL848VGXI
2021-12-16 19:12:34 SUCCESS
CreateAuthorizationCode
Created authorization code
authorization_code
9F8fzBAirfbuk5O630sd9KcLUqd6Sysj
2021-12-16 19:12:34 SUCCESS
ExtractNonceFromAuthorizationRequest
Extracted nonce
nonce
1a9022b3dd6a564773785b7efa81975e49cfd642e756c6ebcb341b710cf90ef5
2021-12-16 19:12:34 SUCCESS
CalculateCHash
Successful c_hash encoding
c_hash
62aRNo0ZpbLmgep2MT-u-g
2021-12-16 19:12:34 SUCCESS
CalculateSHash
Successful s_hash encoding
s_hash
rrsn-_c__J069d1B8Ub62A
2021-12-16 19:12:34 SUCCESS
GenerateIdTokenClaims
Created ID Token Claims
iss
https://www.certification.openid.net/test/a/RP-Security-Test-PAN/
sub
user-subject-1234531
aud
SBSfBTOJMVQBBL848VGXI
nonce
1a9022b3dd6a564773785b7efa81975e49cfd642e756c6ebcb341b710cf90ef5
iat
1639681954
exp
1639682254
2021-12-16 19:12:34
FAPIBrazilAddCPFAndCPNJToIdTokenClaims
Request object does not contain a claims element.id_token
2021-12-16 19:12:34 SUCCESS
AddCHashToIdTokenClaims
Added c_hash to ID token claims
c_hash
62aRNo0ZpbLmgep2MT-u-g
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "sub": "user-subject-1234531",
  "aud": "SBSfBTOJMVQBBL848VGXI",
  "nonce": "1a9022b3dd6a564773785b7efa81975e49cfd642e756c6ebcb341b710cf90ef5",
  "iat": 1639681954,
  "exp": 1639682254,
  "c_hash": "62aRNo0ZpbLmgep2MT-u-g"
}
2021-12-16 19:12:34 SUCCESS
AddSHashToIdTokenClaims
Added s_hash to ID token claims
s_hash
rrsn-_c__J069d1B8Ub62A
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "sub": "user-subject-1234531",
  "aud": "SBSfBTOJMVQBBL848VGXI",
  "nonce": "1a9022b3dd6a564773785b7efa81975e49cfd642e756c6ebcb341b710cf90ef5",
  "iat": 1639681954,
  "exp": 1639682254,
  "c_hash": "62aRNo0ZpbLmgep2MT-u-g",
  "s_hash": "rrsn-_c__J069d1B8Ub62A"
}
2021-12-16 19:12:34 INFO
AddAtHashToIdTokenClaims
Skipped evaluation due to missing required string: at_hash
expected
at_hash
2021-12-16 19:12:34 INFO
FAPIBrazilAddACRClaimToIdTokenClaims
Skipped evaluation due to missing required string: requested_id_token_acr_values
expected
requested_id_token_acr_values
2021-12-16 19:12:34 SUCCESS
SignIdToken
Signed the ID token
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImNfaGFzaCI6IjYyYVJObzBacGJMbWdlcDJNVC11LWciLCJzX2hhc2giOiJycnNuLV9jX19KMDY5ZDFCOFViNjJBIiwiaXNzIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL1JQLVNlY3VyaXR5LVRlc3QtUEFOXC8iLCJleHAiOjE2Mzk2ODIyNTQsIm5vbmNlIjoiMWE5MDIyYjNkZDZhNTY0NzczNzg1YjdlZmE4MTk3NWU0OWNmZDY0MmU3NTZjNmViY2IzNDFiNzEwY2Y5MGVmNSIsImlhdCI6MTYzOTY4MTk1NH0.JQ8sZPdfxLgvHjvx78MSnHz0Zc5rpQu6l5XRL5MXrcLrR1aK3VTtHD3i--HbRXNsTt2cBQetMOefl2ul4M85GP_xQ3W_c_bXTBpdQwlti-tVLkl2NWtHGNo8-MNjah7NBrGoA38YDIh3PG3F7yhfdBL6kti9tpQQ6ER2X-bYAhaqth971WSyD7OsrvJ0Ag27xmyFfIVGiAszYhH_fA6A1CB7rxqd0KTt2FGvhQYPW0Wmqpy4_dLc8zyiSBY7oJ65dhznDSFV0PCfm4CdJ_tVYYBb0y50YxLFq7NcuKxJ0sEahWNoRcDC_HgMEyhOca5UxRkbSZgQGGC6FuCjnNNlzQ
2021-12-16 19:12:34 SUCCESS
FAPIBrazilChangeConsentStatusToAuthorized
Changed consent status to AUTHORISED
consent
{
  "data": {
    "consentId": "urn:conformance.oidf:2vwcM0K6Mk",
    "creationDateTime": "2021-12-16T19:12:32Z",
    "status": "AUTHORISED",
    "statusUpdateDateTime": "2021-12-16T19:12:34Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2021-12-16T21:12:32Z",
    "transactionFromDateTime": "2021-12-16T19:07:32Z",
    "transactionToDateTime": "2021-12-16T21:12:32Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/RP-Security-Test-PANconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2021-12-16T19:12:32Z"
  }
}
2021-12-16 19:12:34 SUCCESS
CreateAuthorizationEndpointResponseParams
Added authorization_endpoint_response_params to environment
params
{
  "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
  "state": "256b42a94b42e7c9fadb0512978b7142966a1905f50fec6787741790eca122ac"
}
2021-12-16 19:12:34 SUCCESS
AddCodeToAuthorizationEndpointResponseParams
Added code to authorization endpoint response params
authorization_endpoint_response_params
{
  "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
  "state": "256b42a94b42e7c9fadb0512978b7142966a1905f50fec6787741790eca122ac",
  "code": "9F8fzBAirfbuk5O630sd9KcLUqd6Sysj"
}
2021-12-16 19:12:34 SUCCESS
AddIdTokenToAuthorizationEndpointResponseParams
Added id_token to authorization endpoint response params
authorization_endpoint_response_params
{
  "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
  "state": "256b42a94b42e7c9fadb0512978b7142966a1905f50fec6787741790eca122ac",
  "code": "9F8fzBAirfbuk5O630sd9KcLUqd6Sysj",
  "id_token": "eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImNfaGFzaCI6IjYyYVJObzBacGJMbWdlcDJNVC11LWciLCJzX2hhc2giOiJycnNuLV9jX19KMDY5ZDFCOFViNjJBIiwiaXNzIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL1JQLVNlY3VyaXR5LVRlc3QtUEFOXC8iLCJleHAiOjE2Mzk2ODIyNTQsIm5vbmNlIjoiMWE5MDIyYjNkZDZhNTY0NzczNzg1YjdlZmE4MTk3NWU0OWNmZDY0MmU3NTZjNmViY2IzNDFiNzEwY2Y5MGVmNSIsImlhdCI6MTYzOTY4MTk1NH0.JQ8sZPdfxLgvHjvx78MSnHz0Zc5rpQu6l5XRL5MXrcLrR1aK3VTtHD3i--HbRXNsTt2cBQetMOefl2ul4M85GP_xQ3W_c_bXTBpdQwlti-tVLkl2NWtHGNo8-MNjah7NBrGoA38YDIh3PG3F7yhfdBL6kti9tpQQ6ER2X-bYAhaqth971WSyD7OsrvJ0Ag27xmyFfIVGiAszYhH_fA6A1CB7rxqd0KTt2FGvhQYPW0Wmqpy4_dLc8zyiSBY7oJ65dhznDSFV0PCfm4CdJ_tVYYBb0y50YxLFq7NcuKxJ0sEahWNoRcDC_HgMEyhOca5UxRkbSZgQGGC6FuCjnNNlzQ"
}
2021-12-16 19:12:34
SendAuthorizationResponseWithResponseModeFragment
Redirecting back to client
uri
https://api-openbanking-hml.bancopan.com.br/tpp/callback#state=256b42a94b42e7c9fadb0512978b7142966a1905f50fec6787741790eca122ac&code=9F8fzBAirfbuk5O630sd9KcLUqd6Sysj&id_token=eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImNfaGFzaCI6IjYyYVJObzBacGJMbWdlcDJNVC11LWciLCJzX2hhc2giOiJycnNuLV9jX19KMDY5ZDFCOFViNjJBIiwiaXNzIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL1JQLVNlY3VyaXR5LVRlc3QtUEFOXC8iLCJleHAiOjE2Mzk2ODIyNTQsIm5vbmNlIjoiMWE5MDIyYjNkZDZhNTY0NzczNzg1YjdlZmE4MTk3NWU0OWNmZDY0MmU3NTZjNmViY2IzNDFiNzEwY2Y5MGVmNSIsImlhdCI6MTYzOTY4MTk1NH0.JQ8sZPdfxLgvHjvx78MSnHz0Zc5rpQu6l5XRL5MXrcLrR1aK3VTtHD3i--HbRXNsTt2cBQetMOefl2ul4M85GP_xQ3W_c_bXTBpdQwlti-tVLkl2NWtHGNo8-MNjah7NBrGoA38YDIh3PG3F7yhfdBL6kti9tpQQ6ER2X-bYAhaqth971WSyD7OsrvJ0Ag27xmyFfIVGiAszYhH_fA6A1CB7rxqd0KTt2FGvhQYPW0Wmqpy4_dLc8zyiSBY7oJ65dhznDSFV0PCfm4CdJ_tVYYBb0y50YxLFq7NcuKxJ0sEahWNoRcDC_HgMEyhOca5UxRkbSZgQGGC6FuCjnNNlzQ
2021-12-16 19:12:34 OUTGOING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Response to HTTP request to test instance OTNPIugcMuRJx9S
outgoing
org.springframework.web.servlet.view.RedirectView: [RedirectView]; URL [https://api-openbanking-hml.bancopan.com.br/tpp/callback#state=256b42a94b42e7c9fadb0512978b7142966a1905f50fec6787741790eca122ac&code=9F8fzBAirfbuk5O630sd9KcLUqd6Sysj&id_token=eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImNfaGFzaCI6IjYyYVJObzBacGJMbWdlcDJNVC11LWciLCJzX2hhc2giOiJycnNuLV9jX19KMDY5ZDFCOFViNjJBIiwiaXNzIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL1JQLVNlY3VyaXR5LVRlc3QtUEFOXC8iLCJleHAiOjE2Mzk2ODIyNTQsIm5vbmNlIjoiMWE5MDIyYjNkZDZhNTY0NzczNzg1YjdlZmE4MTk3NWU0OWNmZDY0MmU3NTZjNmViY2IzNDFiNzEwY2Y5MGVmNSIsImlhdCI6MTYzOTY4MTk1NH0.JQ8sZPdfxLgvHjvx78MSnHz0Zc5rpQu6l5XRL5MXrcLrR1aK3VTtHD3i--HbRXNsTt2cBQetMOefl2ul4M85GP_xQ3W_c_bXTBpdQwlti-tVLkl2NWtHGNo8-MNjah7NBrGoA38YDIh3PG3F7yhfdBL6kti9tpQQ6ER2X-bYAhaqth971WSyD7OsrvJ0Ag27xmyFfIVGiAszYhH_fA6A1CB7rxqd0KTt2FGvhQYPW0Wmqpy4_dLc8zyiSBY7oJ65dhznDSFV0PCfm4CdJ_tVYYBb0y50YxLFq7NcuKxJ0sEahWNoRcDC_HgMEyhOca5UxRkbSZgQGGC6FuCjnNNlzQ]
outgoing_path
authorize
2021-12-16 19:12:35 INCOMING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Incoming HTTP request to test instance OTNPIugcMuRJx9S
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/RP-Security-Test-PAN/.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-16 19:12:35 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-16 19:12:35 OUTGOING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Response to HTTP request to test instance OTNPIugcMuRJx9S
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ],
  "response_types_supported": [
    "code id_token"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256"
  ]
}
outgoing_path
.well-known/openid-configuration
2021-12-16 19:12:35 INCOMING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Incoming HTTP request to test instance OTNPIugcMuRJx9S
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/RP-Security-Test-PAN/jwks
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-16 19:12:35 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-16 19:12:35 OUTGOING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Response to HTTP request to test instance OTNPIugcMuRJx9S
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "alg": "PS256",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "alg": "RSA-OAEP",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
outgoing_path
jwks
2021-12-16 19:12:35 INCOMING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Incoming HTTP request to test instance OTNPIugcMuRJx9S
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded",
  "accept-encoding": "gzip, deflate, br",
  "content-length": "1291",
  "connection": "close"
}
incoming_path
/test-mtls/a/RP-Security-Test-PAN/token
incoming_body_form_params
{
  "grant_type": "authorization_code",
  "code": "9F8fzBAirfbuk5O630sd9KcLUqd6Sysj",
  "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
  "code_verifier": "5v6ZuTiYimM7BffapFfpajCHBy6vc7iIWCLTG0Q3SsE",
  "client_id": "SBSfBTOJMVQBBL848VGXI",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODE5NTUsImV4cCI6MTYzOTY4MjAxNSwianRpIjoiSURUTTBsc1RuUGZXSl9xN2IwZ1UyY1pFWWtiSFFqNzhKUGF0SDdicVd4TSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.pcRGiAJbQ475TgDpGtweRM6VHwQBiKaXieC4rxRA_aEZsJu_JW-puu9C5ye4l34i6ijsHXFnSfY-SHZw8DFqf9L7h4jSGZcg0wf3IDjMCtDNURtyvd0CrBoHNEYVgVqSHL34-s5H62c8bWcYQvXzT0G6av6nOS87AotiDJ6QtHln5maUxlR7H2pFMGKXTjDqgMhDm8zmfVpmO-fqIGKzSlwuqMWbdZKgUz4_sidxYpH3osoM-6Uqab8KIULRwW4qizZWeHB8L46p0O7rlK_p9OHD7zMSjDvXQKM8uJ55pLIBhQjCI0xpFO8_zSpAuVTlEumirJEiR2Wjv4xxrDxJiA",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
grant_type=authorization_code&code=9F8fzBAirfbuk5O630sd9KcLUqd6Sysj&redirect_uri=https%3A%2F%2Fapi-openbanking-hml.bancopan.com.br%2Ftpp%2Fcallback&code_verifier=5v6ZuTiYimM7BffapFfpajCHBy6vc7iIWCLTG0Q3SsE&client_id=SBSfBTOJMVQBBL848VGXI&client_assertion=eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODE5NTUsImV4cCI6MTYzOTY4MjAxNSwianRpIjoiSURUTTBsc1RuUGZXSl9xN2IwZ1UyY1pFWWtiSFFqNzhKUGF0SDdicVd4TSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.pcRGiAJbQ475TgDpGtweRM6VHwQBiKaXieC4rxRA_aEZsJu_JW-puu9C5ye4l34i6ijsHXFnSfY-SHZw8DFqf9L7h4jSGZcg0wf3IDjMCtDNURtyvd0CrBoHNEYVgVqSHL34-s5H62c8bWcYQvXzT0G6av6nOS87AotiDJ6QtHln5maUxlR7H2pFMGKXTjDqgMhDm8zmfVpmO-fqIGKzSlwuqMWbdZKgUz4_sidxYpH3osoM-6Uqab8KIULRwW4qizZWeHB8L46p0O7rlK_p9OHD7zMSjDvXQKM8uJ55pLIBhQjCI0xpFO8_zSpAuVTlEumirJEiR2Wjv4xxrDxJiA&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2021-12-16 19:12:35 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2021-12-16 19:12:35 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz\nMjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct\nNjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j\nb20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk\nYWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ\ncml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ\nKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4\n9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r\niu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6\ni56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV\nCLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3\n5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC\nAtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO\nEUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA\noD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v\ncmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB\nBQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC\nD2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k\nATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz\nb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg\nb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g\nU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg\ncmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j\nZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5\nIGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0\ncDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s\naWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL\n8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs\nZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0\nQZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY\nYFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG\nOZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,UID\u003dac60fe65-58ca-44c3-9352-6f556c5cb98e,2.5.4.5\u003d#130e3539323835343131303030313133,CN\u003dbancopan.com.br,OU\u003db6a214c7-6332-5a41-8464-a281fb9a4ca0,O\u003dBANCO PAN,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "bancopan.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2021-12-16 19:12:35 SUCCESS
CheckForClientCertificate
Found client certificate
2021-12-16 19:12:35 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz
MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct
NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j
b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk
YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ
cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4
9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r
iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6
i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV
CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3
5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC
AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO
EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA
oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v
cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB
BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC
D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k
ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz
b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg
b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g
U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg
cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j
ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5
IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0
cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s
aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL
8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs
ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0
QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY
YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG
OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks=
-----END CERTIFICATE-----
2021-12-16 19:12:35 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODE5NTUsImV4cCI6MTYzOTY4MjAxNSwianRpIjoiSURUTTBsc1RuUGZXSl9xN2IwZ1UyY1pFWWtiSFFqNzhKUGF0SDdicVd4TSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.pcRGiAJbQ475TgDpGtweRM6VHwQBiKaXieC4rxRA_aEZsJu_JW-puu9C5ye4l34i6ijsHXFnSfY-SHZw8DFqf9L7h4jSGZcg0wf3IDjMCtDNURtyvd0CrBoHNEYVgVqSHL34-s5H62c8bWcYQvXzT0G6av6nOS87AotiDJ6QtHln5maUxlR7H2pFMGKXTjDqgMhDm8zmfVpmO-fqIGKzSlwuqMWbdZKgUz4_sidxYpH3osoM-6Uqab8KIULRwW4qizZWeHB8L46p0O7rlK_p9OHD7zMSjDvXQKM8uJ55pLIBhQjCI0xpFO8_zSpAuVTlEumirJEiR2Wjv4xxrDxJiA",
  "header": {
    "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "SBSfBTOJMVQBBL848VGXI",
    "aud": [
      "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
      "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
      "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token"
    ],
    "iss": "SBSfBTOJMVQBBL848VGXI",
    "exp": 1639682015,
    "iat": 1639681955,
    "jti": "IDTM0lsTnPfWJ_q7b0gU2cZEYkbHQj78JPatH7bqWxM"
  }
}
2021-12-16 19:12:35
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2021-12-16 19:12:35 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODE5NTUsImV4cCI6MTYzOTY4MjAxNSwianRpIjoiSURUTTBsc1RuUGZXSl9xN2IwZ1UyY1pFWWtiSFFqNzhKUGF0SDdicVd4TSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.pcRGiAJbQ475TgDpGtweRM6VHwQBiKaXieC4rxRA_aEZsJu_JW-puu9C5ye4l34i6ijsHXFnSfY-SHZw8DFqf9L7h4jSGZcg0wf3IDjMCtDNURtyvd0CrBoHNEYVgVqSHL34-s5H62c8bWcYQvXzT0G6av6nOS87AotiDJ6QtHln5maUxlR7H2pFMGKXTjDqgMhDm8zmfVpmO-fqIGKzSlwuqMWbdZKgUz4_sidxYpH3osoM-6Uqab8KIULRwW4qizZWeHB8L46p0O7rlK_p9OHD7zMSjDvXQKM8uJ55pLIBhQjCI0xpFO8_zSpAuVTlEumirJEiR2Wjv4xxrDxJiA
2021-12-16 19:12:35 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-12-16 19:12:35 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2021-12-16 19:12:35 SUCCESS
ValidateAuthorizationCode
Found authorization code
authorization_code
9F8fzBAirfbuk5O630sd9KcLUqd6Sysj
2021-12-16 19:12:35 SUCCESS
ValidateRedirectUri
Found redirect uri
redirect_uri
https://api-openbanking-hml.bancopan.com.br/tpp/callback
2021-12-16 19:12:35 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
QgByFqK1vnKGMaqUINVsHzQLGh62jdo70dWenT3DXsZYlnxjh9
2021-12-16 19:12:35 SUCCESS
CalculateAtHash
Successful at_hash encoding
at_hash
8JCTrqOmTomXfS7bxKz4jg
2021-12-16 19:12:35
CreateRefreshToken
Created refresh token
refresh_token
YdaoirJbIDNqfGTqxWwshDEkBAdSrxpBDwVOpyVcUFpyHODyCz7409828590;([|^
2021-12-16 19:12:35 SUCCESS
GenerateIdTokenClaims
Created ID Token Claims
iss
https://www.certification.openid.net/test/a/RP-Security-Test-PAN/
sub
user-subject-1234531
aud
SBSfBTOJMVQBBL848VGXI
nonce
1a9022b3dd6a564773785b7efa81975e49cfd642e756c6ebcb341b710cf90ef5
iat
1639681955
exp
1639682255
2021-12-16 19:12:35
FAPIBrazilAddCPFAndCPNJToIdTokenClaims
Request object does not contain a claims element.id_token
2021-12-16 19:12:35 SUCCESS
AddAtHashToIdTokenClaims
Added at_hash to ID token claims
at_hash
8JCTrqOmTomXfS7bxKz4jg
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "sub": "user-subject-1234531",
  "aud": "SBSfBTOJMVQBBL848VGXI",
  "nonce": "1a9022b3dd6a564773785b7efa81975e49cfd642e756c6ebcb341b710cf90ef5",
  "iat": 1639681955,
  "exp": 1639682255,
  "at_hash": "8JCTrqOmTomXfS7bxKz4jg"
}
2021-12-16 19:12:35 INFO
FAPIBrazilAddACRClaimToIdTokenClaims
Skipped evaluation due to missing required string: requested_id_token_acr_values
expected
requested_id_token_acr_values
2021-12-16 19:12:35 SUCCESS
SignIdToken
Signed the ID token
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdF9oYXNoIjoiOEpDVHJxT21Ub21YZlM3YnhLejRqZyIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoiU0JTZkJUT0pNVlFCQkw4NDhWR1hJIiwiaXNzIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL1JQLVNlY3VyaXR5LVRlc3QtUEFOXC8iLCJleHAiOjE2Mzk2ODIyNTUsIm5vbmNlIjoiMWE5MDIyYjNkZDZhNTY0NzczNzg1YjdlZmE4MTk3NWU0OWNmZDY0MmU3NTZjNmViY2IzNDFiNzEwY2Y5MGVmNSIsImlhdCI6MTYzOTY4MTk1NX0.gMKF_xWBHvJUULsladvgP3_VzDLKwlNQscQVA1pGxuZr9nYJW9iU5nCAEdjHsBBTw2GYQULbWMB0YpVpOZr-PiCsJ_2XYPz51MIkQXuYnHq_-69yA7P3EqcVrHClRFwMLhRhEbMajIq3OSAribjsNI7Nrba0ig9LhSS4to30KB6HzkaA7NRFU8Tjb5MZoF6rppxKeyDx0MruD18D87KYop_ALaaBASQoLbZQsgawM8iWmEf_EAUazcnC0cVgozgU1yz_oZC6Q7FuYlrOX40Y_-CXvbW0nuLodHNSvGQKcsiE7QUACeGSWwlmcAD1O9hyRyg_ER8BY3eQyjvTKTsNcA
2021-12-16 19:12:35 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
QgByFqK1vnKGMaqUINVsHzQLGh62jdo70dWenT3DXsZYlnxjh9
token_type
Bearer
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdF9oYXNoIjoiOEpDVHJxT21Ub21YZlM3YnhLejRqZyIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoiU0JTZkJUT0pNVlFCQkw4NDhWR1hJIiwiaXNzIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL1JQLVNlY3VyaXR5LVRlc3QtUEFOXC8iLCJleHAiOjE2Mzk2ODIyNTUsIm5vbmNlIjoiMWE5MDIyYjNkZDZhNTY0NzczNzg1YjdlZmE4MTk3NWU0OWNmZDY0MmU3NTZjNmViY2IzNDFiNzEwY2Y5MGVmNSIsImlhdCI6MTYzOTY4MTk1NX0.gMKF_xWBHvJUULsladvgP3_VzDLKwlNQscQVA1pGxuZr9nYJW9iU5nCAEdjHsBBTw2GYQULbWMB0YpVpOZr-PiCsJ_2XYPz51MIkQXuYnHq_-69yA7P3EqcVrHClRFwMLhRhEbMajIq3OSAribjsNI7Nrba0ig9LhSS4to30KB6HzkaA7NRFU8Tjb5MZoF6rppxKeyDx0MruD18D87KYop_ALaaBASQoLbZQsgawM8iWmEf_EAUazcnC0cVgozgU1yz_oZC6Q7FuYlrOX40Y_-CXvbW0nuLodHNSvGQKcsiE7QUACeGSWwlmcAD1O9hyRyg_ER8BY3eQyjvTKTsNcA
refresh_token
YdaoirJbIDNqfGTqxWwshDEkBAdSrxpBDwVOpyVcUFpyHODyCz7409828590;([|^
scope
openid consent:urn:conformance.oidf:2vwcM0K6Mk accounts resources a796103b-6eeb-4b48-8265-23bfdedcc12d
2021-12-16 19:12:35 OUTGOING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Response to HTTP request to test instance OTNPIugcMuRJx9S
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "QgByFqK1vnKGMaqUINVsHzQLGh62jdo70dWenT3DXsZYlnxjh9",
  "token_type": "Bearer",
  "id_token": "eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdF9oYXNoIjoiOEpDVHJxT21Ub21YZlM3YnhLejRqZyIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoiU0JTZkJUT0pNVlFCQkw4NDhWR1hJIiwiaXNzIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL1JQLVNlY3VyaXR5LVRlc3QtUEFOXC8iLCJleHAiOjE2Mzk2ODIyNTUsIm5vbmNlIjoiMWE5MDIyYjNkZDZhNTY0NzczNzg1YjdlZmE4MTk3NWU0OWNmZDY0MmU3NTZjNmViY2IzNDFiNzEwY2Y5MGVmNSIsImlhdCI6MTYzOTY4MTk1NX0.gMKF_xWBHvJUULsladvgP3_VzDLKwlNQscQVA1pGxuZr9nYJW9iU5nCAEdjHsBBTw2GYQULbWMB0YpVpOZr-PiCsJ_2XYPz51MIkQXuYnHq_-69yA7P3EqcVrHClRFwMLhRhEbMajIq3OSAribjsNI7Nrba0ig9LhSS4to30KB6HzkaA7NRFU8Tjb5MZoF6rppxKeyDx0MruD18D87KYop_ALaaBASQoLbZQsgawM8iWmEf_EAUazcnC0cVgozgU1yz_oZC6Q7FuYlrOX40Y_-CXvbW0nuLodHNSvGQKcsiE7QUACeGSWwlmcAD1O9hyRyg_ER8BY3eQyjvTKTsNcA",
  "refresh_token": "YdaoirJbIDNqfGTqxWwshDEkBAdSrxpBDwVOpyVcUFpyHODyCz7409828590;([|^",
  "scope": "openid consent:urn:conformance.oidf:2vwcM0K6Mk accounts resources a796103b-6eeb-4b48-8265-23bfdedcc12d"
}
outgoing_path
token
2021-12-16 19:12:40 FINISHED
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Test has run to completion
testmodule_result
PASSED
2021-12-16 19:12:45
TEST-RUNNER
Alias has now been claimed by another test
alias
RP-Security-Test-PAN
new_test_id
8m2OsACRBpoDgWM
Test Results