Test Summary

Test Results

Expand All Collapse All
All times are UTC
2021-12-16 19:19:16 INFO
TEST-RUNNER
Test instance Om6erTyR3wCwg7c created
baseUrl
https://www.certification.openid.net/test/a/RP-Security-Test-PAN
variant
{
  "client_auth_type": "private_key_jwt",
  "fapi_auth_request_method": "pushed",
  "fapi_profile": "openbanking_brazil",
  "fapi_jarm_type": "oidc",
  "fapi_response_mode": "plain_response"
}
alias
RP-Security-Test-PAN
description
Teste de Segurança de RP do Ambiente de Homologação do PAN para o Open Banking
planId
TQoMgbFqkMMZ0
config
{
  "alias": "RP-Security-Test-PAN",
  "description": "Teste de Segurança de RP do Ambiente de Homologação do PAN para o Open Banking",
  "server": {
    "jwks": {
      "keys": [
        {
          "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
          "kty": "RSA",
          "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
          "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
          "e": "AQAB",
          "alg": "PS256",
          "use": "sig",
          "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
          "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
          "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
          "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
          "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
          "x5c": [
            "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
          ]
        },
        {
          "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
          "kty": "RSA",
          "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
          "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
          "e": "AQAB",
          "use": "enc",
          "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
          "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
          "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
          "alg": "RSA-OAEP",
          "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
          "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
        }
      ]
    }
  },
  "client": {
    "client_id": "SBSfBTOJMVQBBL848VGXI",
    "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
    "certificate": "-----BEGIN CERTIFICATE-----\nMIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz\nMjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct\nNjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j\nb20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk\nYWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ\ncml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ\nKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4\n9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r\niu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6\ni56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV\nCLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3\n5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC\nAtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO\nEUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA\noD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v\ncmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB\nBQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC\nD2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k\nATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz\nb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg\nb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g\nU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg\ncmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j\nZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5\nIGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0\ncDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s\naWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL\n8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs\nZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0\nQZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY\nYFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG\nOZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d\n-----END CERTIFICATE-----",
    "jwks": {
      "keys": [
        {
          "alg": "PS256",
          "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
          "kty": "RSA",
          "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
          "e": "AQAB"
        }
      ]
    }
  },
  "client2": {
    "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
    "id_token_encrypted_response_alg": "RSA-OAEP",
    "id_token_encrypted_response_enc": "A256GCM",
    "client_id": "Lk4dFn0ve0wnQiN37NSDR",
    "jwks": {
      "keys": [
        {
          "alg": "PS256",
          "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
          "kty": "RSA",
          "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
          "e": "AQAB"
        },
        {
          "kty": "RSA",
          "use": "enc",
          "alg": "PS256",
          "n": "xY64ckpxUTXk7Q9e_ulwxLogYEzJ7tZswwGt7EesKk8E_Sq9o4ybEq-tWL2l_h_Q38Y8MkyxPsiKQqzwXdb5npvtZ5fv-QF3u2eqryqWm3ialiWZtIG48ia__ApswN1JZUX_3YdrzwdxJjc-SeSR0eTXB21WvJ5DxhfX8aiU8p93oHP_K7nqjUAr241XNYK119KvDI0pVbaJuwXqWJvLXWnLLfWyZXCsuoMc0yU9yEeos2CkJlEyslNF37q2M_rv-52yrevzhJ_OJjxc2As-U2EpoKAOfhqa-sVSEGEaa-YApVNV-KmEE3nw-6T7sqBBvp7sbtXuKq8RoFaQkA2kzQ",
          "e": "AQAB",
          "kid": "5997c113bd799f7e61039be31353e4e5917c28a3536ee7d0f44d5bfbf301cc55"
        }
      ]
    },
    "certificate": "-----BEGIN CERTIFICATE-----\nMIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz\nMjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct\nNjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j\nb20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk\nYWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ\ncml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ\nKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4\n9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r\niu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6\ni56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV\nCLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3\n5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC\nAtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO\nEUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA\noD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v\ncmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB\nBQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC\nD2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k\nATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz\nb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg\nb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g\nU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg\ncmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j\nZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5\nIGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0\ncDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s\naWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL\n8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs\nZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0\nQZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY\nYFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG\nOZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d\n-----END CERTIFICATE-----"
  },
  "directory": {
    "keystore": "https://keystore.sandbox.directory.openbankingbrasil.org.br/"
  }
}
testName
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
2021-12-16 19:19:16 SUCCESS
FAPIBrazilGenerateServerConfiguration
Created server configuration
server
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true
}
issuer
https://www.certification.openid.net/test/a/RP-Security-Test-PAN/
discoveryUrl
https://www.certification.openid.net/test/a/RP-Security-Test-PAN/.well-known/openid-configuration
2021-12-16 19:19:16 SUCCESS
LoadServerJWKs
Parsed public and private JWK sets
server_jwks
{
  "keys": [
    {
      "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
      "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
      "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
      "kty": "RSA",
      "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
      "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
      "alg": "PS256"
    },
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
server_encryption_keys
{
  "keys": [
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
server_public_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "alg": "PS256",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "alg": "RSA-OAEP",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
2021-12-16 19:19:16 SUCCESS
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2021-12-16 19:19:16
SetServerSigningAlgToPS256
Successfully set signing algorithm to PS256
2021-12-16 19:19:16
FAPIBrazilSetGrantTypesSupportedInServerConfiguration
Successfully set grant_types_supported
server
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ]
}
2021-12-16 19:19:16
AddClaimsParameterSupportedTrueToServerConfiguration
Successfully added claims_parameter_supported to server configuration
server
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true
}
2021-12-16 19:19:16
FAPIBrazilAddBrazilSpecificSettingsToServerConfiguration
Added open banking Brazil specific server settings
server
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ]
}
2021-12-16 19:19:16
SetTokenEndpointAuthMethodsSupportedToPrivateKeyJWTOnly
Changed token_endpoint_auth_methods_supported to private_key_jwt only in server configuration
server_configuration
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ]
}
2021-12-16 19:19:16
AddPushedAuthorizationRequestEndpointToServerConfig
Added pushed_authorization_request_endpoint to server configuration
endpoint
https://www.certification.openid.net/test/a/RP-Security-Test-PAN/par
2021-12-16 19:19:16
AddRequirePushedAuthorizationRequestsToServerConfig
Added require_pushed_authorization_requests to server configuration
value
true
2021-12-16 19:19:16 SUCCESS
AddResponseTypeCodeIdTokenToServerConfiguration
Added code id_token as response type supported
response_types_supported
[
  "code id_token"
]
2021-12-16 19:19:16 SUCCESS
FAPIBrazilAddTokenEndpointAuthSigningAlgValuesSupportedToServer
Set token_endpoint_auth_signing_alg_values_supported
values
[
  "PS256"
]
2021-12-16 19:19:16 SUCCESS
CheckServerConfiguration
Found required server configuration keys
required
[
  "authorization_endpoint",
  "token_endpoint",
  "issuer"
]
2021-12-16 19:19:16 SUCCESS
FAPIEnsureMinimumServerKeyLength
Validated minimum key lengths for server_jwks
server_jwks
{
  "keys": [
    {
      "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
      "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
      "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
      "kty": "RSA",
      "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
      "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
      "alg": "PS256"
    },
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
2021-12-16 19:19:16 SUCCESS
LoadUserInfo
Added user information
user_info
{
  "sub": "user-subject-1234531",
  "name": "Demo T. User",
  "email": "user@example.com",
  "email_verified": false
}
Verify configuration of first client
2021-12-16 19:19:16 SUCCESS
GetStaticClientConfiguration
Found a static client object
client_id
SBSfBTOJMVQBBL848VGXI
redirect_uri
https://api-openbanking-hml.bancopan.com.br/tpp/callback
certificate
-----BEGIN CERTIFICATE-----
MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz
MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct
NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j
b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk
YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ
cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4
9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r
iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6
i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV
CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3
5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC
AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO
EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA
oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v
cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB
BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC
D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k
ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz
b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg
b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g
U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg
cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j
ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5
IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0
cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s
aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL
8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs
ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0
QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY
YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG
OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks=
-----END CERTIFICATE-----
jwks
{
  "keys": [
    {
      "alg": "PS256",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "kty": "RSA",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
      "e": "AQAB"
    }
  ]
}
2021-12-16 19:19:16 SUCCESS
ValidateClientJWKsPublicPart
Valid client JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2021-12-16 19:19:16 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "alg": "PS256",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "kty": "RSA",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
      "e": "AQAB"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "alg": "PS256",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew"
    }
  ]
}
2021-12-16 19:19:16 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2021-12-16 19:19:16 SUCCESS
EnsureClientJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2021-12-16 19:19:16 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "alg": "PS256",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "kty": "RSA",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
      "e": "AQAB"
    }
  ]
}
Verify configuration of second client
2021-12-16 19:19:16 SUCCESS
GetStaticClient2Configuration
Found a static second client object
redirect_uri
https://api-openbanking-hml.bancopan.com.br/tpp/callback
id_token_encrypted_response_alg
RSA-OAEP
id_token_encrypted_response_enc
A256GCM
client_id
Lk4dFn0ve0wnQiN37NSDR
jwks
{
  "keys": [
    {
      "alg": "PS256",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "kty": "RSA",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
      "e": "AQAB"
    },
    {
      "kty": "RSA",
      "use": "enc",
      "alg": "PS256",
      "n": "xY64ckpxUTXk7Q9e_ulwxLogYEzJ7tZswwGt7EesKk8E_Sq9o4ybEq-tWL2l_h_Q38Y8MkyxPsiKQqzwXdb5npvtZ5fv-QF3u2eqryqWm3ialiWZtIG48ia__ApswN1JZUX_3YdrzwdxJjc-SeSR0eTXB21WvJ5DxhfX8aiU8p93oHP_K7nqjUAr241XNYK119KvDI0pVbaJuwXqWJvLXWnLLfWyZXCsuoMc0yU9yEeos2CkJlEyslNF37q2M_rv-52yrevzhJ_OJjxc2As-U2EpoKAOfhqa-sVSEGEaa-YApVNV-KmEE3nw-6T7sqBBvp7sbtXuKq8RoFaQkA2kzQ",
      "e": "AQAB",
      "kid": "5997c113bd799f7e61039be31353e4e5917c28a3536ee7d0f44d5bfbf301cc55"
    }
  ]
}
certificate
-----BEGIN CERTIFICATE-----
MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz
MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct
NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j
b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk
YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ
cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4
9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r
iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6
i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV
CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3
5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC
AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO
EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA
oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v
cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB
BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC
D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k
ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz
b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg
b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g
U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg
cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j
ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5
IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0
cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s
aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL
8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs
ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0
QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY
YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG
OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks=
-----END CERTIFICATE-----
2021-12-16 19:19:16 SUCCESS
ValidateClientJWKsPublicPart
Valid client JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2021-12-16 19:19:16 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "alg": "PS256",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "kty": "RSA",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
      "e": "AQAB"
    },
    {
      "kty": "RSA",
      "use": "enc",
      "alg": "PS256",
      "n": "xY64ckpxUTXk7Q9e_ulwxLogYEzJ7tZswwGt7EesKk8E_Sq9o4ybEq-tWL2l_h_Q38Y8MkyxPsiKQqzwXdb5npvtZ5fv-QF3u2eqryqWm3ialiWZtIG48ia__ApswN1JZUX_3YdrzwdxJjc-SeSR0eTXB21WvJ5DxhfX8aiU8p93oHP_K7nqjUAr241XNYK119KvDI0pVbaJuwXqWJvLXWnLLfWyZXCsuoMc0yU9yEeos2CkJlEyslNF37q2M_rv-52yrevzhJ_OJjxc2As-U2EpoKAOfhqa-sVSEGEaa-YApVNV-KmEE3nw-6T7sqBBvp7sbtXuKq8RoFaQkA2kzQ",
      "e": "AQAB",
      "kid": "5997c113bd799f7e61039be31353e4e5917c28a3536ee7d0f44d5bfbf301cc55"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "alg": "PS256",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "5997c113bd799f7e61039be31353e4e5917c28a3536ee7d0f44d5bfbf301cc55",
      "alg": "PS256",
      "n": "xY64ckpxUTXk7Q9e_ulwxLogYEzJ7tZswwGt7EesKk8E_Sq9o4ybEq-tWL2l_h_Q38Y8MkyxPsiKQqzwXdb5npvtZ5fv-QF3u2eqryqWm3ialiWZtIG48ia__ApswN1JZUX_3YdrzwdxJjc-SeSR0eTXB21WvJ5DxhfX8aiU8p93oHP_K7nqjUAr241XNYK119KvDI0pVbaJuwXqWJvLXWnLLfWyZXCsuoMc0yU9yEeos2CkJlEyslNF37q2M_rv-52yrevzhJ_OJjxc2As-U2EpoKAOfhqa-sVSEGEaa-YApVNV-KmEE3nw-6T7sqBBvp7sbtXuKq8RoFaQkA2kzQ"
    }
  ]
}
2021-12-16 19:19:16 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2021-12-16 19:19:16 SUCCESS
EnsureClientJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2021-12-16 19:19:16 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "alg": "PS256",
      "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
      "kty": "RSA",
      "n": "s6TziphxtrX8j3vjj4KG-sIowBuRnLa8qqs48z0uZ6Agzk9mJH0D8noFgQ_n1tgdo9et8B3fUxhE1l3gQtMOS2mtH9rE6HuJXJjjIPLpOxNsxa7UPQSEZlfP_o6uJOkidGxpDF66x7Xb5n5KBZEV_wbPTeLcB9XNkfoGvCw1o-Ni5tEg7o2oN9thmSYznSrbRUeM15dmBxz6ZYhtKdGM3z_aK6nva4lkGUrps1RZlcWShocDVaz8DXLBt2M5d-YbCLfsF4sDy5BqPk-WccQJr2do7sGA1n38tUQbY5TKw5i6bgHxlxupWvrFEc4s0yHXiSgvzLDMOiM3-5jMBdv6ew",
      "e": "AQAB"
    },
    {
      "kty": "RSA",
      "use": "enc",
      "alg": "PS256",
      "n": "xY64ckpxUTXk7Q9e_ulwxLogYEzJ7tZswwGt7EesKk8E_Sq9o4ybEq-tWL2l_h_Q38Y8MkyxPsiKQqzwXdb5npvtZ5fv-QF3u2eqryqWm3ialiWZtIG48ia__ApswN1JZUX_3YdrzwdxJjc-SeSR0eTXB21WvJ5DxhfX8aiU8p93oHP_K7nqjUAr241XNYK119KvDI0pVbaJuwXqWJvLXWnLLfWyZXCsuoMc0yU9yEeos2CkJlEyslNF37q2M_rv-52yrevzhJ_OJjxc2As-U2EpoKAOfhqa-sVSEGEaa-YApVNV-KmEE3nw-6T7sqBBvp7sbtXuKq8RoFaQkA2kzQ",
      "e": "AQAB",
      "kid": "5997c113bd799f7e61039be31353e4e5917c28a3536ee7d0f44d5bfbf301cc55"
    }
  ]
}
2021-12-16 19:19:16
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Setup Done
2021-12-16 19:19:23 INCOMING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Incoming HTTP request to test instance Om6erTyR3wCwg7c
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/RP-Security-Test-PAN/.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-16 19:19:23 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-16 19:19:23 OUTGOING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Response to HTTP request to test instance Om6erTyR3wCwg7c
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo",
    "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/par"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ],
  "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/par",
  "require_pushed_authorization_requests": true,
  "response_types_supported": [
    "code id_token"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256"
  ]
}
outgoing_path
.well-known/openid-configuration
2021-12-16 19:19:23 INCOMING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Incoming HTTP request to test instance Om6erTyR3wCwg7c
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded",
  "accept-encoding": "gzip, deflate, br",
  "content-length": "1210",
  "connection": "close"
}
incoming_path
/test-mtls/a/RP-Security-Test-PAN/token
incoming_body_form_params
{
  "scope": "consents",
  "grant_type": "client_credentials",
  "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
  "client_id": "SBSfBTOJMVQBBL848VGXI",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNjMsImV4cCI6MTYzOTY4MjQyMywianRpIjoiTWNYaVo1QnJ0eVMtRHhDbUc4VmhVT2IxWHJkSXFuX25YUS1TS2NVZTFMTSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.MyavzkWeNZecRRegwI8niIj8x05DNvMh04s_EmcHJ4EFicAFQdkjSHOeovW6aopmMAL-fp_pylPT8-qS8Z1IGRitduADgnsRA5X0g7wbW_TTJZk-r36OrejOJEaTuU1vUhCTIlQuLWRy1gGFjqPGb3fCf6g_DrMIzPgy8cusWDQQdDlm7D7heR-K2vkYwLgcju0UcTsqT5s_8fxhsfzymmAS9xEVpmjY5sjDPcBWhnDbPrOGTXALEx-9K0r5dfU6UJ2dcW9DMF-6J2R7xdykgeG-DnKpTeayrqwqcM0Dk4ws9jyeznxXJ8HS-Z52rIenT3Dvf7tUY0PB788ayX0NGQ",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
scope=consents&grant_type=client_credentials&redirect_uri=https%3A%2F%2Fapi-openbanking-hml.bancopan.com.br%2Ftpp%2Fcallback&client_id=SBSfBTOJMVQBBL848VGXI&client_assertion=eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNjMsImV4cCI6MTYzOTY4MjQyMywianRpIjoiTWNYaVo1QnJ0eVMtRHhDbUc4VmhVT2IxWHJkSXFuX25YUS1TS2NVZTFMTSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.MyavzkWeNZecRRegwI8niIj8x05DNvMh04s_EmcHJ4EFicAFQdkjSHOeovW6aopmMAL-fp_pylPT8-qS8Z1IGRitduADgnsRA5X0g7wbW_TTJZk-r36OrejOJEaTuU1vUhCTIlQuLWRy1gGFjqPGb3fCf6g_DrMIzPgy8cusWDQQdDlm7D7heR-K2vkYwLgcju0UcTsqT5s_8fxhsfzymmAS9xEVpmjY5sjDPcBWhnDbPrOGTXALEx-9K0r5dfU6UJ2dcW9DMF-6J2R7xdykgeG-DnKpTeayrqwqcM0Dk4ws9jyeznxXJ8HS-Z52rIenT3Dvf7tUY0PB788ayX0NGQ&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2021-12-16 19:19:23 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2021-12-16 19:19:23 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz\nMjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct\nNjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j\nb20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk\nYWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ\ncml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ\nKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4\n9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r\niu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6\ni56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV\nCLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3\n5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC\nAtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO\nEUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA\noD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v\ncmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB\nBQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC\nD2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k\nATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz\nb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg\nb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g\nU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg\ncmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j\nZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5\nIGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0\ncDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s\naWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL\n8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs\nZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0\nQZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY\nYFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG\nOZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,UID\u003dac60fe65-58ca-44c3-9352-6f556c5cb98e,2.5.4.5\u003d#130e3539323835343131303030313133,CN\u003dbancopan.com.br,OU\u003db6a214c7-6332-5a41-8464-a281fb9a4ca0,O\u003dBANCO PAN,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "bancopan.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2021-12-16 19:19:23 SUCCESS
CheckForClientCertificate
Found client certificate
2021-12-16 19:19:23 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz
MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct
NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j
b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk
YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ
cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4
9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r
iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6
i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV
CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3
5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC
AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO
EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA
oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v
cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB
BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC
D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k
ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz
b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg
b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g
U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg
cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j
ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5
IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0
cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s
aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL
8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs
ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0
QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY
YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG
OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks=
-----END CERTIFICATE-----
2021-12-16 19:19:23 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNjMsImV4cCI6MTYzOTY4MjQyMywianRpIjoiTWNYaVo1QnJ0eVMtRHhDbUc4VmhVT2IxWHJkSXFuX25YUS1TS2NVZTFMTSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.MyavzkWeNZecRRegwI8niIj8x05DNvMh04s_EmcHJ4EFicAFQdkjSHOeovW6aopmMAL-fp_pylPT8-qS8Z1IGRitduADgnsRA5X0g7wbW_TTJZk-r36OrejOJEaTuU1vUhCTIlQuLWRy1gGFjqPGb3fCf6g_DrMIzPgy8cusWDQQdDlm7D7heR-K2vkYwLgcju0UcTsqT5s_8fxhsfzymmAS9xEVpmjY5sjDPcBWhnDbPrOGTXALEx-9K0r5dfU6UJ2dcW9DMF-6J2R7xdykgeG-DnKpTeayrqwqcM0Dk4ws9jyeznxXJ8HS-Z52rIenT3Dvf7tUY0PB788ayX0NGQ",
  "header": {
    "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "SBSfBTOJMVQBBL848VGXI",
    "aud": [
      "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
      "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
      "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token"
    ],
    "iss": "SBSfBTOJMVQBBL848VGXI",
    "exp": 1639682423,
    "iat": 1639682363,
    "jti": "McXiZ5BrtyS-DxCmG8VhUOb1XrdIqn_nXQ-SKcUe1LM"
  }
}
2021-12-16 19:19:23
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2021-12-16 19:19:23 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNjMsImV4cCI6MTYzOTY4MjQyMywianRpIjoiTWNYaVo1QnJ0eVMtRHhDbUc4VmhVT2IxWHJkSXFuX25YUS1TS2NVZTFMTSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.MyavzkWeNZecRRegwI8niIj8x05DNvMh04s_EmcHJ4EFicAFQdkjSHOeovW6aopmMAL-fp_pylPT8-qS8Z1IGRitduADgnsRA5X0g7wbW_TTJZk-r36OrejOJEaTuU1vUhCTIlQuLWRy1gGFjqPGb3fCf6g_DrMIzPgy8cusWDQQdDlm7D7heR-K2vkYwLgcju0UcTsqT5s_8fxhsfzymmAS9xEVpmjY5sjDPcBWhnDbPrOGTXALEx-9K0r5dfU6UJ2dcW9DMF-6J2R7xdykgeG-DnKpTeayrqwqcM0Dk4ws9jyeznxXJ8HS-Z52rIenT3Dvf7tUY0PB788ayX0NGQ
2021-12-16 19:19:23 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-12-16 19:19:23 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2021-12-16 19:19:23 SUCCESS
FAPIBrazilExtractRequestedScopeFromClientCredentialsGrant
Found 'consents' scope in request
actual
[
  "consents"
]
expected
consents
2021-12-16 19:19:23 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
VoWBo1zIgHZu0Bs4kHCpGQeUvjjLEHuVrQtMhLBYInTMsmrdDU
2021-12-16 19:19:23 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
VoWBo1zIgHZu0Bs4kHCpGQeUvjjLEHuVrQtMhLBYInTMsmrdDU
token_type
Bearer
2021-12-16 19:19:23
CopyAccessTokenToClientCredentialsField
Condition ran but did not log anything
2021-12-16 19:19:23 OUTGOING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Response to HTTP request to test instance Om6erTyR3wCwg7c
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "VoWBo1zIgHZu0Bs4kHCpGQeUvjjLEHuVrQtMhLBYInTMsmrdDU",
  "token_type": "Bearer"
}
outgoing_path
token
2021-12-16 19:19:23 INCOMING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Incoming HTTP request to test instance Om6erTyR3wCwg7c
incoming_headers
{
  "host": "www.certification.openid.net",
  "accept": "application/json, text/plain, */*",
  "content-type": "application/json",
  "authorization": "Bearer VoWBo1zIgHZu0Bs4kHCpGQeUvjjLEHuVrQtMhLBYInTMsmrdDU",
  "user-agent": "axios/0.21.4",
  "content-length": "261",
  "connection": "close"
}
incoming_path
/test-mtls/a/RP-Security-Test-PAN/consents/v1/consents
incoming_body_form_params
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks= -----END CERTIFICATE-----
incoming_body_json
{
  "data": {
    "loggedUser": {
      "document": {
        "identification": "44257214899",
        "rel": "CPF"
      }
    },
    "permissions": [
      "RESOURCES_READ",
      "ACCOUNTS_READ",
      "ACCOUNTS_TRANSACTIONS_READ",
      "ACCOUNTS_OVERDRAFT_LIMITS_READ",
      "ACCOUNTS_BALANCES_READ"
    ],
    "expirationDateTime": "2022-08-21T08:30:00Z"
  }
}
incoming_query_string_params
{}
incoming_body
{"data":{"loggedUser":{"document":{"identification":"44257214899","rel":"CPF"}},"permissions":["RESOURCES_READ","ACCOUNTS_READ","ACCOUNTS_TRANSACTIONS_READ","ACCOUNTS_OVERDRAFT_LIMITS_READ","ACCOUNTS_BALANCES_READ"],"expirationDateTime":"2022-08-21T08:30:00Z"}}
2021-12-16 19:19:23 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
New consent endpoint
2021-12-16 19:19:23 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz\nMjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct\nNjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j\nb20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk\nYWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ\ncml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ\nKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4\n9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r\niu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6\ni56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV\nCLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3\n5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC\nAtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO\nEUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA\noD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v\ncmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB\nBQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC\nD2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k\nATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz\nb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg\nb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g\nU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg\ncmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j\nZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5\nIGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0\ncDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s\naWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL\n8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs\nZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0\nQZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY\nYFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG\nOZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,UID\u003dac60fe65-58ca-44c3-9352-6f556c5cb98e,2.5.4.5\u003d#130e3539323835343131303030313133,CN\u003dbancopan.com.br,OU\u003db6a214c7-6332-5a41-8464-a281fb9a4ca0,O\u003dBANCO PAN,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "bancopan.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2021-12-16 19:19:23 SUCCESS
CheckForClientCertificate
Found client certificate
2021-12-16 19:19:23 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz
MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct
NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j
b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk
YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ
cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4
9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r
iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6
i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV
CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3
5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC
AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO
EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA
oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v
cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB
BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC
D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k
ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz
b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg
b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g
U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg
cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j
ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5
IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0
cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s
aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL
8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs
ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0
QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY
YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG
OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks=
-----END CERTIFICATE-----
2021-12-16 19:19:23 SUCCESS
EnsureIncomingRequestMethodIsPost
Client correctly used http POST method
2021-12-16 19:19:23 SUCCESS
EnsureBearerAccessTokenNotInParams
Client correctly did not send access token in query parameters or form body
2021-12-16 19:19:23 SUCCESS
ExtractBearerAccessTokenFromHeader
Found access token on incoming request
access_token
VoWBo1zIgHZu0Bs4kHCpGQeUvjjLEHuVrQtMhLBYInTMsmrdDU
2021-12-16 19:19:23 SUCCESS
RequireBearerClientCredentialsAccessToken
Found access token in request
actual
VoWBo1zIgHZu0Bs4kHCpGQeUvjjLEHuVrQtMhLBYInTMsmrdDU
2021-12-16 19:19:23 INFO
ExtractFapiDateHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-auth-date
path
headers.x-fapi-auth-date
mapped
object
incoming_request
2021-12-16 19:19:23 INFO
ExtractFapiIpAddressHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-customer-ip-address
path
headers.x-fapi-customer-ip-address
mapped
object
incoming_request
2021-12-16 19:19:23 INFO
ExtractFapiInteractionIdHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-interaction-id
path
headers.x-fapi-interaction-id
mapped
object
incoming_request
2021-12-16 19:19:23 SUCCESS
FAPIBrazilEnsureClientCredentialsScopeContainedConsents
The token request which was used to obtain the access token contained 'consents' scope
actual
[
  "consents"
]
2021-12-16 19:19:23
FAPIBrazilExtractConsentRequest
Condition ran but did not log anything
2021-12-16 19:19:23 SUCCESS
CreateFapiInteractionIdIfNeeded
Created new FAPI interaction ID
fapi_interaction_id
b5885f9f-d58d-45a1-bb84-18145e4247e3
2021-12-16 19:19:23 SUCCESS
FAPIBrazilGenerateNewConsentResponse
Created consent response
headers
{
  "x-fapi-interaction-id": "b5885f9f-d58d-45a1-bb84-18145e4247e3"
}
consentId
urn:conformance.oidf:auzxSxBMwq
consent_response
{
  "data": {
    "consentId": "urn:conformance.oidf:auzxSxBMwq",
    "creationDateTime": "2021-12-16T19:19:23Z",
    "status": "AWAITING_AUTHORISATION",
    "statusUpdateDateTime": "2021-12-16T19:19:23Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2021-12-16T21:19:23Z",
    "transactionFromDateTime": "2021-12-16T19:14:23Z",
    "transactionToDateTime": "2021-12-16T21:19:23Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/RP-Security-Test-PANconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2021-12-16T19:19:23Z"
  }
}
2021-12-16 19:19:23
ClearAccessTokenFromRequest
Condition ran but did not log anything
2021-12-16 19:19:23 OUTGOING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Response to HTTP request to test instance Om6erTyR3wCwg7c
outgoing_status_code
201
outgoing_headers
{
  "x-fapi-interaction-id": [
    "b5885f9f-d58d-45a1-bb84-18145e4247e3"
  ]
}
outgoing_body
{
  "data": {
    "consentId": "urn:conformance.oidf:auzxSxBMwq",
    "creationDateTime": "2021-12-16T19:19:23Z",
    "status": "AWAITING_AUTHORISATION",
    "statusUpdateDateTime": "2021-12-16T19:19:23Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2021-12-16T21:19:23Z",
    "transactionFromDateTime": "2021-12-16T19:14:23Z",
    "transactionToDateTime": "2021-12-16T21:19:23Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/RP-Security-Test-PANconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2021-12-16T19:19:23Z"
  }
}
outgoing_path
consents/v1/consents
2021-12-16 19:19:24 INCOMING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Incoming HTTP request to test instance Om6erTyR3wCwg7c
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/RP-Security-Test-PAN/.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-16 19:19:24 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-16 19:19:24 OUTGOING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Response to HTTP request to test instance Om6erTyR3wCwg7c
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo",
    "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/par"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ],
  "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/par",
  "require_pushed_authorization_requests": true,
  "response_types_supported": [
    "code id_token"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256"
  ]
}
outgoing_path
.well-known/openid-configuration
2021-12-16 19:19:24 INCOMING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Incoming HTTP request to test instance Om6erTyR3wCwg7c
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/RP-Security-Test-PAN/jwks
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-16 19:19:24 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-16 19:19:24 OUTGOING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Response to HTTP request to test instance Om6erTyR3wCwg7c
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "alg": "PS256",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "alg": "RSA-OAEP",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
outgoing_path
jwks
2021-12-16 19:19:24 INCOMING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Incoming HTTP request to test instance Om6erTyR3wCwg7c
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded",
  "accept-encoding": "gzip, deflate, br",
  "content-length": "3489",
  "connection": "close"
}
incoming_path
/test-mtls/a/RP-Security-Test-PAN/par
incoming_body_form_params
{
  "request": "eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZHQ00iLCJjdHkiOiJvYXV0aC1hdXRoei1yZXErand0Iiwia2lkIjoiMGZlNTAyZGQtMTRmMC00ZjQ1LTgwZjktZmViOWEyMTZmOTk2In0.MHKSi2Gsoxuy49IObEEJYJLD50YP9CGITaCXEO3paUo1W4JLl0vEylOZ30bn7Qh6ghr6VHyP65jPt1LDTLlOeXTGZmyH_eFVc2thyWUKSr3VouXjvp_Ywd0SObP2JSWzpUiSGOweE3I1LwPodvCiAlkGB3Uj-bRvZ0ymJYbFTTdRY7BJoZkG3kTmjIyzBnuwkocpTxU5RvQn6vclfRaHL0JUlBVw-dqP8d2anzO6z2F7HF26V7ukow5viqF0Gvnv5M_vvpRodUsOvA96qntxbqfteW8tz9aaL4-1U4ygltA9BiHFuo8f1XNOsYCRhfJ5A0oB8cHPwcG4x7ik5KW5wQ.BckgeCt21O1bWMqZ.1xgufuCMjRGNrKex8OHG2-76QgtCiY9JvpBt-s0-nMJEwdkR5eP226pOD9f3LZh-1nNXrMu82iMhmXobzEGpuGG33R6xcbOcztL0bXPWnmlMb4XZPmCtYHTAfN-LLH69w0BQ0rzCxqmbfLh6E-c03ujgCqVtIn2ab-z5iA_dZCPyk2Ikn9-6W1tbsoR2HHkb8moVWxa4RS1LDNKn2DVcYQXmye0-VZ0kMm4P1R0_zRmzmrKeXNwbjkfrKk5U8xezyMD5dJVT-QSEmFwSiUZd4gQTvL2zjB4ZWWBX_MsjXtzTbC33FEJVYAJP4tgjaib1OUAj002CLnWBHGOxoKjGaZV_5ZaFFCAMnhWiaVFdIwzVKSkN0bHsKej6VGqOc_UuOauiPlOHjp2kbNc9cCSmn3H5wzjRS161l6YBzRQTVy4GpNQfN_avcAg1bnJwdu9Rvlasp4YVRNuJsgollVqZn8E_f20RLJrxcbb8IDz2j21VpBDXfxSBmO679gS2HuQsPhWjlQ-IsD77kPjrZlvKjW9impLnY8M_bSfZS56EhV3fkGTUvfQwsf4Yz66BneI2xHh6yzb3_jSPEUNAOgDTGQBTW0WJFtigFGxhUvdR1aY78xiBFYzFSakyNgwno6vK0QzrG8hpsdHtORejTQmQYeOFlmpei29D-t97m36EcnZaI6UGsj0rfD287LMF7Y8wGd7Yb2CzF1j4fsLZGSY8qp8yXFjtSGybCoV5vOErYrPCQ_8xmO_PyM2-QJcJe7QCif_2qnWqL6WkpgbwjbNbqU-b6cORbInlh10x-2d1nAvnQOKK1OOgpZI_Gq5ydC8jU_eBN6UEA4uu0nFyfy3eeIsg4v2Wfspt2ikstKEPCNz-9ZZZXCTIsZeq46MF0aAr9X0hA6mNrnxMk9WiUh20HbDX7MXYtsS-XXZX2d4SIk8bqAxKYDhv94C7qMVvEYNQtb-X_ArXW-yc6plV35eeo8ZmBzMHCFEXpa0H3PUTBW673t0sVSWC4ky-erpZ97nOnywFVLF7JrX07lHvunC_apYJodlDZjV4m0E8x_9D92r1C4twL9u43zpnA-9YrX9P2JdQ7NRhCFrTA2jZ-o-hnYU-8Utgj4Z9kjnhuxZ_R0FGhNO2HU8TH4oRMtHXi7tspZFCsbCu3brQT8BRBmpHWVGYBHPNCyYpP9kEcM2Q_Bl5pxeWHdMIiu-RzGZJ2trt5cdhqJqHKA-qNyvOGjQFboYroiMIu4x57khSPAjkfC4wwCVulIlESPPVLmG9ODndg6jOdt322AtB0N777KAr2JafLnwxhorLGZFVRiPlHxT1Nr6d1RRhfuHLtw9oi9xcga0a4_yFl9Hjkok0mkNOVzrB7jVWfea658z1CdwERw61S9yDIy4OjTUcRO0yTsXoJnpn4LXUPuxEI6ys6wBYCIFQOawKd3g02Exn3ROfsos3zJqyRdRK46uGi1xDctKGPGDXv4-84vUM-Yjapb_pUfVfcT5d9Joue66lETh4jRncZsi3QksIGHuREDxYg27RyA5QAcst6UAzWKFIh4WaaTGJoP5Dh0JQpoU9yl90IaMNu4wcrQXYrTtgcomR9mG7-lUq856xqhn_RkPFPQbhISVGPlNt79n1YoSRdGZQlKZNHLoT3DRVr8CkXWIzTrqeqeUQYoNAfxg_nTpcbrjQkylLXFv2mmgIS-QAbv0WJdj49FXkTtoxpjSf5qE_9olIAul02kBNugI6qSbAxKEEru4xHwccm90PUUCov5JsR62eikinYow5wH9zMpM40YYFgS9NoFFPyKYjt-_iEOC_5xtRY3BXRzS7lbtIVLEdpynQlsDgrAfG9afuwkLCUEfmebrFIop756_I.80LGCOorWPIYPZC_OnQ8Lg",
  "client_id": "SBSfBTOJMVQBBL848VGXI",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNjQsImV4cCI6MTYzOTY4MjQyNCwianRpIjoielN0a0JkRlI2VWgwbDg0MmQzX01YUzdtelFTN2xTc3M4d2ZDVktXZjZFUSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.RzdsD6deJ20o4Yei17hjOWQSQT7cvoRuivUJOXQNXHP-S3EZ41J-gYjj6K4B73CzHQF2uNjLQ30RZZSK7j-e_yKhSlA5bL-fh0YIF52tt4pOxk0N8I3F-Q4fcSJ5X_zvDtybM5xHWJnV9A5PT5VtsS_tw3yezLM5nmskKIOcsdv4LSAU0IKBpXO79rpYOfzb67wMwLz_9TgcLuCzdxh90IS4It7BLNEQhKlKqfbZLISGkr1onao2r4xhn1vOiulicN2xWeCdlZVtwR-iAND6Yz189LysEOab7AReHWzN7FpDMzU2e7nl3g972lT49urQ4PeUDVkMOPICP0jfP9Hr4A",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
request=eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZHQ00iLCJjdHkiOiJvYXV0aC1hdXRoei1yZXErand0Iiwia2lkIjoiMGZlNTAyZGQtMTRmMC00ZjQ1LTgwZjktZmViOWEyMTZmOTk2In0.MHKSi2Gsoxuy49IObEEJYJLD50YP9CGITaCXEO3paUo1W4JLl0vEylOZ30bn7Qh6ghr6VHyP65jPt1LDTLlOeXTGZmyH_eFVc2thyWUKSr3VouXjvp_Ywd0SObP2JSWzpUiSGOweE3I1LwPodvCiAlkGB3Uj-bRvZ0ymJYbFTTdRY7BJoZkG3kTmjIyzBnuwkocpTxU5RvQn6vclfRaHL0JUlBVw-dqP8d2anzO6z2F7HF26V7ukow5viqF0Gvnv5M_vvpRodUsOvA96qntxbqfteW8tz9aaL4-1U4ygltA9BiHFuo8f1XNOsYCRhfJ5A0oB8cHPwcG4x7ik5KW5wQ.BckgeCt21O1bWMqZ.1xgufuCMjRGNrKex8OHG2-76QgtCiY9JvpBt-s0-nMJEwdkR5eP226pOD9f3LZh-1nNXrMu82iMhmXobzEGpuGG33R6xcbOcztL0bXPWnmlMb4XZPmCtYHTAfN-LLH69w0BQ0rzCxqmbfLh6E-c03ujgCqVtIn2ab-z5iA_dZCPyk2Ikn9-6W1tbsoR2HHkb8moVWxa4RS1LDNKn2DVcYQXmye0-VZ0kMm4P1R0_zRmzmrKeXNwbjkfrKk5U8xezyMD5dJVT-QSEmFwSiUZd4gQTvL2zjB4ZWWBX_MsjXtzTbC33FEJVYAJP4tgjaib1OUAj002CLnWBHGOxoKjGaZV_5ZaFFCAMnhWiaVFdIwzVKSkN0bHsKej6VGqOc_UuOauiPlOHjp2kbNc9cCSmn3H5wzjRS161l6YBzRQTVy4GpNQfN_avcAg1bnJwdu9Rvlasp4YVRNuJsgollVqZn8E_f20RLJrxcbb8IDz2j21VpBDXfxSBmO679gS2HuQsPhWjlQ-IsD77kPjrZlvKjW9impLnY8M_bSfZS56EhV3fkGTUvfQwsf4Yz66BneI2xHh6yzb3_jSPEUNAOgDTGQBTW0WJFtigFGxhUvdR1aY78xiBFYzFSakyNgwno6vK0QzrG8hpsdHtORejTQmQYeOFlmpei29D-t97m36EcnZaI6UGsj0rfD287LMF7Y8wGd7Yb2CzF1j4fsLZGSY8qp8yXFjtSGybCoV5vOErYrPCQ_8xmO_PyM2-QJcJe7QCif_2qnWqL6WkpgbwjbNbqU-b6cORbInlh10x-2d1nAvnQOKK1OOgpZI_Gq5ydC8jU_eBN6UEA4uu0nFyfy3eeIsg4v2Wfspt2ikstKEPCNz-9ZZZXCTIsZeq46MF0aAr9X0hA6mNrnxMk9WiUh20HbDX7MXYtsS-XXZX2d4SIk8bqAxKYDhv94C7qMVvEYNQtb-X_ArXW-yc6plV35eeo8ZmBzMHCFEXpa0H3PUTBW673t0sVSWC4ky-erpZ97nOnywFVLF7JrX07lHvunC_apYJodlDZjV4m0E8x_9D92r1C4twL9u43zpnA-9YrX9P2JdQ7NRhCFrTA2jZ-o-hnYU-8Utgj4Z9kjnhuxZ_R0FGhNO2HU8TH4oRMtHXi7tspZFCsbCu3brQT8BRBmpHWVGYBHPNCyYpP9kEcM2Q_Bl5pxeWHdMIiu-RzGZJ2trt5cdhqJqHKA-qNyvOGjQFboYroiMIu4x57khSPAjkfC4wwCVulIlESPPVLmG9ODndg6jOdt322AtB0N777KAr2JafLnwxhorLGZFVRiPlHxT1Nr6d1RRhfuHLtw9oi9xcga0a4_yFl9Hjkok0mkNOVzrB7jVWfea658z1CdwERw61S9yDIy4OjTUcRO0yTsXoJnpn4LXUPuxEI6ys6wBYCIFQOawKd3g02Exn3ROfsos3zJqyRdRK46uGi1xDctKGPGDXv4-84vUM-Yjapb_pUfVfcT5d9Joue66lETh4jRncZsi3QksIGHuREDxYg27RyA5QAcst6UAzWKFIh4WaaTGJoP5Dh0JQpoU9yl90IaMNu4wcrQXYrTtgcomR9mG7-lUq856xqhn_RkPFPQbhISVGPlNt79n1YoSRdGZQlKZNHLoT3DRVr8CkXWIzTrqeqeUQYoNAfxg_nTpcbrjQkylLXFv2mmgIS-QAbv0WJdj49FXkTtoxpjSf5qE_9olIAul02kBNugI6qSbAxKEEru4xHwccm90PUUCov5JsR62eikinYow5wH9zMpM40YYFgS9NoFFPyKYjt-_iEOC_5xtRY3BXRzS7lbtIVLEdpynQlsDgrAfG9afuwkLCUEfmebrFIop756_I.80LGCOorWPIYPZC_OnQ8Lg&client_id=SBSfBTOJMVQBBL848VGXI&client_assertion=eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNjQsImV4cCI6MTYzOTY4MjQyNCwianRpIjoielN0a0JkRlI2VWgwbDg0MmQzX01YUzdtelFTN2xTc3M4d2ZDVktXZjZFUSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.RzdsD6deJ20o4Yei17hjOWQSQT7cvoRuivUJOXQNXHP-S3EZ41J-gYjj6K4B73CzHQF2uNjLQ30RZZSK7j-e_yKhSlA5bL-fh0YIF52tt4pOxk0N8I3F-Q4fcSJ5X_zvDtybM5xHWJnV9A5PT5VtsS_tw3yezLM5nmskKIOcsdv4LSAU0IKBpXO79rpYOfzb67wMwLz_9TgcLuCzdxh90IS4It7BLNEQhKlKqfbZLISGkr1onao2r4xhn1vOiulicN2xWeCdlZVtwR-iAND6Yz189LysEOab7AReHWzN7FpDMzU2e7nl3g972lT49urQ4PeUDVkMOPICP0jfP9Hr4A&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2021-12-16 19:19:24 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
PAR endpoint
2021-12-16 19:19:24 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz\nMjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct\nNjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j\nb20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk\nYWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ\ncml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ\nKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4\n9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r\niu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6\ni56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV\nCLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3\n5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC\nAtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO\nEUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA\noD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v\ncmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB\nBQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC\nD2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k\nATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz\nb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg\nb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g\nU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg\ncmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j\nZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5\nIGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0\ncDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s\naWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL\n8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs\nZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0\nQZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY\nYFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG\nOZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,UID\u003dac60fe65-58ca-44c3-9352-6f556c5cb98e,2.5.4.5\u003d#130e3539323835343131303030313133,CN\u003dbancopan.com.br,OU\u003db6a214c7-6332-5a41-8464-a281fb9a4ca0,O\u003dBANCO PAN,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "bancopan.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2021-12-16 19:19:24 SUCCESS
CheckForClientCertificate
Found client certificate
2021-12-16 19:19:24 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz
MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct
NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j
b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk
YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ
cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4
9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r
iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6
i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV
CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3
5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC
AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO
EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA
oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v
cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB
BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC
D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k
ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz
b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg
b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g
U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg
cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j
ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5
IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0
cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s
aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL
8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs
ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0
QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY
YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG
OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks=
-----END CERTIFICATE-----
2021-12-16 19:19:24 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNjQsImV4cCI6MTYzOTY4MjQyNCwianRpIjoielN0a0JkRlI2VWgwbDg0MmQzX01YUzdtelFTN2xTc3M4d2ZDVktXZjZFUSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.RzdsD6deJ20o4Yei17hjOWQSQT7cvoRuivUJOXQNXHP-S3EZ41J-gYjj6K4B73CzHQF2uNjLQ30RZZSK7j-e_yKhSlA5bL-fh0YIF52tt4pOxk0N8I3F-Q4fcSJ5X_zvDtybM5xHWJnV9A5PT5VtsS_tw3yezLM5nmskKIOcsdv4LSAU0IKBpXO79rpYOfzb67wMwLz_9TgcLuCzdxh90IS4It7BLNEQhKlKqfbZLISGkr1onao2r4xhn1vOiulicN2xWeCdlZVtwR-iAND6Yz189LysEOab7AReHWzN7FpDMzU2e7nl3g972lT49urQ4PeUDVkMOPICP0jfP9Hr4A",
  "header": {
    "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "SBSfBTOJMVQBBL848VGXI",
    "aud": [
      "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
      "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
      "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token"
    ],
    "iss": "SBSfBTOJMVQBBL848VGXI",
    "exp": 1639682424,
    "iat": 1639682364,
    "jti": "zStkBdFR6Uh0l842d3_MXS7mzQS7lSss8wfCVKWf6EQ"
  }
}
2021-12-16 19:19:24
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2021-12-16 19:19:24 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNjQsImV4cCI6MTYzOTY4MjQyNCwianRpIjoielN0a0JkRlI2VWgwbDg0MmQzX01YUzdtelFTN2xTc3M4d2ZDVktXZjZFUSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.RzdsD6deJ20o4Yei17hjOWQSQT7cvoRuivUJOXQNXHP-S3EZ41J-gYjj6K4B73CzHQF2uNjLQ30RZZSK7j-e_yKhSlA5bL-fh0YIF52tt4pOxk0N8I3F-Q4fcSJ5X_zvDtybM5xHWJnV9A5PT5VtsS_tw3yezLM5nmskKIOcsdv4LSAU0IKBpXO79rpYOfzb67wMwLz_9TgcLuCzdxh90IS4It7BLNEQhKlKqfbZLISGkr1onao2r4xhn1vOiulicN2xWeCdlZVtwR-iAND6Yz189LysEOab7AReHWzN7FpDMzU2e7nl3g972lT49urQ4PeUDVkMOPICP0jfP9Hr4A
2021-12-16 19:19:24 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-12-16 19:19:24 SUCCESS
ValidateClientAssertionClaimsForPAREndpoint
Client Assertion passed all validation checks
2021-12-16 19:19:24 SUCCESS
ExtractRequestObjectFromPAREndpointRequest
Parsed request object
request_object
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6Im9hdXRoLWF1dGh6LXJlcStqd3QiLCJraWQiOiI1Z1lISUhidHcwVUI0QndqdHFVbmh0Rk42V3RoRVcybWRYN2RmVUJRSElJIn0.eyJzY29wZSI6Im9wZW5pZCBjb25zZW50OnVybjpjb25mb3JtYW5jZS5vaWRmOmF1enhTeEJNd3EgYWNjb3VudHMgcmVzb3VyY2VzIiwicmVzcG9uc2VfdHlwZSI6ImNvZGUgaWRfdG9rZW4iLCJyZWRpcmVjdF91cmkiOiJodHRwczovL2FwaS1vcGVuYmFua2luZy1obWwuYmFuY29wYW4uY29tLmJyL3RwcC9jYWxsYmFjayIsImNvZGVfY2hhbGxlbmdlIjoibjBYLXdySloxa1dMWWZXMVRZMlpMNUhuZkM4bEpRVnNBUlE5OFhQTnlWTSIsImNvZGVfY2hhbGxlbmdlX21ldGhvZCI6IlMyNTYiLCJyZXNwb25zZV9tb2RlIjoiZnJhZ21lbnQiLCJzdGF0ZSI6IjU4N2M3MjMwOGM1OGZjMDdiYjY2YmU5MTMxNmM2MTllMTljMjRjMjAwNmRjMDlhODVkMzFlNjI0ZGI1NDA2ZjAiLCJub25jZSI6IjU1YjE1YWUzZDdkY2QxMzE5ZTA2Y2EwMjkxYTI0MTE5ODBhMTdlODNmNzc4MDA4ZmRkYmMzOWM4ODBkOWE2M2EiLCJpc3MiOiJTQlNmQlRPSk1WUUJCTDg0OFZHWEkiLCJhdWQiOiJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImNsaWVudF9pZCI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImp0aSI6InpYLWQzVzQ4ZE8yMjctRi04YmdzMHNZTlhURkFmQWVFUHB2UEtzVXFRUm8iLCJpYXQiOjE2Mzk2ODIzNjQsImV4cCI6MTYzOTY4MjY2NCwibmJmIjoxNjM5NjgyMzY0fQ.mcu6N6YiVhXJrvA5sB7ryOCQasLZd939vzRA8gGhS-Hi5mX0oLN79gpx_G_NR2AaoP6yNTvMTObbfCbkHChzTq4uzF7QgPlaFkI-Y8cAtpFIHeWKX2lFD7QoSeDUzkfrPxKtlq3LO3k0j98aPz9YWI1gexrDg9X0dnFZIWZL1tFnSZtz7-ylh53jgtjfTsccbeRx-bwXQP9v7q21dpAR9o_Bry-0NbT4YQ_pGVxOn9ocTlhqI44KU2__y4b7VfYmyKF1A5BQpPVqLfk-6a2YUsXAurvLQ4kMQbHwNmDH9rmpOCKt4SLfmfP0QoaCXmcdEK4cHnEsGn7lA8mitsx43Q",
  "header": {
    "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
    "typ": "oauth-authz-req+jwt",
    "alg": "PS256"
  },
  "claims": {
    "iss": "SBSfBTOJMVQBBL848VGXI",
    "response_type": "code id_token",
    "code_challenge_method": "S256",
    "nonce": "55b15ae3d7dcd1319e06ca0291a2411980a17e83f778008fddbc39c880d9a63a",
    "client_id": "SBSfBTOJMVQBBL848VGXI",
    "response_mode": "fragment",
    "aud": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
    "nbf": 1639682364,
    "scope": "openid consent:urn:conformance.oidf:auzxSxBMwq accounts resources",
    "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
    "state": "587c72308c58fc07bb66be91316c619e19c24c2006dc09a85d31e624db5406f0",
    "exp": 1639682664,
    "iat": 1639682364,
    "code_challenge": "n0X-wrJZ1kWLYfW1TY2ZL5HnfC8lJQVsARQ98XPNyVM",
    "jti": "zX-d3W48dO227-F-8bgs0sYNXTFAfAeEPpvPKsUqQRo"
  },
  "jwe_header": {
    "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
    "cty": "oauth-authz-req+jwt",
    "enc": "A256GCM",
    "alg": "RSA-OAEP"
  }
}
2021-12-16 19:19:24 SUCCESS
EnsurePAREndpointRequestDoesNotContainRequestUriParameter
PAR endpoint request does not contain a request_uri parameter
2021-12-16 19:19:24 SUCCESS
ValidateEncryptedRequestObjectHasKid
kid was found in the encrypted request object header
kid
0fe502dd-14f0-4f45-80f9-feb9a216f996
2021-12-16 19:19:24 SUCCESS
FAPIValidateRequestObjectSigningAlg
Request object was signed with a permitted algorithm
alg
PS256
2021-12-16 19:19:24
FAPIBrazilValidateRequestObjectIdTokenACRClaims
acr claim is not requested
2021-12-16 19:19:24 SUCCESS
FAPIValidateRequestObjectExp
Request object contains a valid exp claim, expiry time
exp
"Dec 16, 2021, 7:24:24 PM"
2021-12-16 19:19:24 SUCCESS
FAPI1AdvancedValidateRequestObjectNBFClaim
nbf claim is valid
nbf
"Dec 16, 2021, 7:19:24 PM"
now
"Dec 16, 2021, 7:19:24 PM"
2021-12-16 19:19:24
ValidateRequestObjectClaims
Request object does not contain a max_age claim
2021-12-16 19:19:24 SUCCESS
ValidateRequestObjectClaims
Request object claims passed all validation checks
2021-12-16 19:19:24 SUCCESS
EnsureNumericRequestObjectClaimsAreNotNull
None of the claims expected to have numeric values, have null values
numeric_claims
[
  "max_age"
]
2021-12-16 19:19:24 SUCCESS
EnsureRequestObjectDoesNotContainRequestOrRequestUri
Request object does not contain request or request_uri
2021-12-16 19:19:24 SUCCESS
EnsureRequestObjectDoesNotContainSubWithClientId
Request object does not contain Client Id in sub
2021-12-16 19:19:24 SUCCESS
ValidateRequestObjectSignature
Request object signature validated using a key in the client's JWKS and using the client's registered request_object_signing_alg
request_object
eyJhbGciOiJQUzI1NiIsInR5cCI6Im9hdXRoLWF1dGh6LXJlcStqd3QiLCJraWQiOiI1Z1lISUhidHcwVUI0QndqdHFVbmh0Rk42V3RoRVcybWRYN2RmVUJRSElJIn0.eyJzY29wZSI6Im9wZW5pZCBjb25zZW50OnVybjpjb25mb3JtYW5jZS5vaWRmOmF1enhTeEJNd3EgYWNjb3VudHMgcmVzb3VyY2VzIiwicmVzcG9uc2VfdHlwZSI6ImNvZGUgaWRfdG9rZW4iLCJyZWRpcmVjdF91cmkiOiJodHRwczovL2FwaS1vcGVuYmFua2luZy1obWwuYmFuY29wYW4uY29tLmJyL3RwcC9jYWxsYmFjayIsImNvZGVfY2hhbGxlbmdlIjoibjBYLXdySloxa1dMWWZXMVRZMlpMNUhuZkM4bEpRVnNBUlE5OFhQTnlWTSIsImNvZGVfY2hhbGxlbmdlX21ldGhvZCI6IlMyNTYiLCJyZXNwb25zZV9tb2RlIjoiZnJhZ21lbnQiLCJzdGF0ZSI6IjU4N2M3MjMwOGM1OGZjMDdiYjY2YmU5MTMxNmM2MTllMTljMjRjMjAwNmRjMDlhODVkMzFlNjI0ZGI1NDA2ZjAiLCJub25jZSI6IjU1YjE1YWUzZDdkY2QxMzE5ZTA2Y2EwMjkxYTI0MTE5ODBhMTdlODNmNzc4MDA4ZmRkYmMzOWM4ODBkOWE2M2EiLCJpc3MiOiJTQlNmQlRPSk1WUUJCTDg0OFZHWEkiLCJhdWQiOiJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImNsaWVudF9pZCI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImp0aSI6InpYLWQzVzQ4ZE8yMjctRi04YmdzMHNZTlhURkFmQWVFUHB2UEtzVXFRUm8iLCJpYXQiOjE2Mzk2ODIzNjQsImV4cCI6MTYzOTY4MjY2NCwibmJmIjoxNjM5NjgyMzY0fQ.mcu6N6YiVhXJrvA5sB7ryOCQasLZd939vzRA8gGhS-Hi5mX0oLN79gpx_G_NR2AaoP6yNTvMTObbfCbkHChzTq4uzF7QgPlaFkI-Y8cAtpFIHeWKX2lFD7QoSeDUzkfrPxKtlq3LO3k0j98aPz9YWI1gexrDg9X0dnFZIWZL1tFnSZtz7-ylh53jgtjfTsccbeRx-bwXQP9v7q21dpAR9o_Bry-0NbT4YQ_pGVxOn9ocTlhqI44KU2__y4b7VfYmyKF1A5BQpPVqLfk-6a2YUsXAurvLQ4kMQbHwNmDH9rmpOCKt4SLfmfP0QoaCXmcdEK4cHnEsGn7lA8mitsx43Q
request_object_signing_alg
PS256
jwk
Sun RSA public key, 2048 bits
  params: null
  modulus: 22677997123100865027038163618440931425768853246042685053952059568088768370775879662687649598715143390108338286915488499774626148365554590008656132577357893743438278711902761437715966243285423555795769385881803147871566517201086180684345745904063840678522561040685569999111501676387252045965556897951681323146595605739539663340316188618451821106202340139520257397286742681119465613725230213120667075481235349311488074650446518605298417452683228189337358541483332915940982625541029074799406321696170037150264352053879457399805139882493978179691887049996822814968964846225178258105165825398408907737359544759640349473403
  public exponent: 65537
2021-12-16 19:19:24 SUCCESS
EnsureMatchingRedirectUriInRequestObject
Redirect URI matched
actual
https://api-openbanking-hml.bancopan.com.br/tpp/callback
2021-12-16 19:19:24 SUCCESS
EnsureRequestObjectContainsCodeChallengeWhenUsingPAR
Found required PKCE parameters in request
code_challenge_method
S256
code_challenge
n0X-wrJZ1kWLYfW1TY2ZL5HnfC8lJQVsARQ98XPNyVM
2021-12-16 19:19:24 SUCCESS
CreatePAREndpointResponse
Created PAR endpoint response
request_uri
urn:ietf:params:oauth:request_uri:8f26e6c8-2421-4203-a1ad-0b95d8613e8d
expires_in
600
2021-12-16 19:19:24 OUTGOING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Response to HTTP request to test instance Om6erTyR3wCwg7c
outgoing_status_code
201
outgoing_headers
{}
outgoing_body
{
  "request_uri": "urn:ietf:params:oauth:request_uri:8f26e6c8-2421-4203-a1ad-0b95d8613e8d",
  "expires_in": 600
}
outgoing_path
par
2021-12-16 19:19:25 INCOMING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Incoming HTTP request to test instance Om6erTyR3wCwg7c
incoming_headers
{
  "host": "www.certification.openid.net",
  "accept": "application/json, text/plain, */*",
  "content-type": "application/json",
  "x-idempotency-key": "68d8153c-c246-465b-af1d-296c046cc851",
  "test-name": "45-fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response.pushed",
  "authorization": "Bearer eyJraWQiOiJkZWZhdWx0IiwiYWxnIjoiUlMyNTYifQ.eyJzdWIiOiI3NGViNGMyMi1mYTZlLTQzNTgtYWI0Yy0yMmZhNmUxMzU4MzMiLCJhdWQiOiI3NGViNGMyMi1mYTZlLTQzNTgtYWI0Yy0yMmZhNmUxMzU4MzMiLCJkb21haW4iOiIwZmI2NjgxOC0yZTE3LTRhNzQtYjY2OC0xODJlMTcyYTc0ZjgiLCJzY29wZSI6ImNvbnNlbnRfYWRtaW4gcHJveHlfcmVhZCB0ZW5hbnRfYWRtaW4gY2F0ZWdvcnlfYWRtaW4gb3JnYW5pemF0aW9uX2FkbWluIiwiaXNzIjoiaHR0cDpcL1wvdHBwLWlhbS1vcGVuYmFua2luZy1obWwuYmFuY29wYW4uY29tLmJyXC9hbVwvdHBwXC9vaWRjIiwiZXhwIjoxNjM5Njg5NTYxLCJpYXQiOjE2Mzk2ODIzNjEsImp0aSI6ImRRQ0NUM3c0UHpucUJUYjZ0ZVkxam14ZFd2aGYyMnMxeXdtU1FRLVY0d28ifQ.WjJ_U6zvF-z3LRju00ijyaKxdvyXuOaeS1WzNCL1gJDibqjPBPqapVRSTLFile09NgeNlhxpW2a5fdH_fBjDQy_7-KQLOdCZ6xtGYwTy6ZQRI0mZkH0Wtjdpd7oOx8vY2hMQhlGDUxTC2uIe3cctyXzEt7o34lucp3MJ51HwTK78TytuuAxbA1u4Nw9yHhnE29XrGvvCdhIjwEO9sP4O-l0rzRY2H9N25kJ4-CCBNQkPNcr4kviO-LuvgN4_3nbIdHp71g_Kdt9471G6afoiX2QcL793EHtBKcB8sn4UMLS_A5aVdVC5wQcmc6M36WibcvNOTlNBFUSNYW_aSylGTw",
  "user-agent": "axios/0.24.0",
  "connection": "close"
}
incoming_path
/test/a/RP-Security-Test-PAN/authorize
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
DHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{
  "client_id": "SBSfBTOJMVQBBL848VGXI",
  "scope": "openid consent:urn:conformance.oidf:auzxSxBMwq accounts resources",
  "response_type": "code",
  "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
  "request_uri": "urn:ietf:params:oauth:request_uri:8f26e6c8-2421-4203-a1ad-0b95d8613e8d"
}
incoming_body
2021-12-16 19:19:25 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
DHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Authorization endpoint
2021-12-16 19:19:25 SUCCESS
EnsureAuthorizationRequestDoesNotContainRequestWhenUsingPAR
Request does not contain a request parameter
2021-12-16 19:19:25 SUCCESS
ValidateEncryptedRequestObjectHasKid
kid was found in the encrypted request object header
kid
0fe502dd-14f0-4f45-80f9-feb9a216f996
2021-12-16 19:19:25 SUCCESS
CreateEffectiveAuthorizationRequestParameters
Merged http request parameters with request object claims
effective_authorization_endpoint_request
{
  "client_id": "SBSfBTOJMVQBBL848VGXI",
  "scope": "openid consent:urn:conformance.oidf:auzxSxBMwq accounts resources",
  "response_type": "code id_token",
  "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
  "iss": "SBSfBTOJMVQBBL848VGXI",
  "code_challenge_method": "S256",
  "nonce": "55b15ae3d7dcd1319e06ca0291a2411980a17e83f778008fddbc39c880d9a63a",
  "response_mode": "fragment",
  "aud": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "nbf": 1639682364,
  "state": "587c72308c58fc07bb66be91316c619e19c24c2006dc09a85d31e624db5406f0",
  "exp": 1639682664,
  "iat": 1639682364,
  "code_challenge": "n0X-wrJZ1kWLYfW1TY2ZL5HnfC8lJQVsARQ98XPNyVM",
  "jti": "zX-d3W48dO227-F-8bgs0sYNXTFAfAeEPpvPKsUqQRo"
}
2021-12-16 19:19:25 SUCCESS
EnsureClientIdInAuthorizationRequestParametersMatchRequestObject
client_id http request parameter value matches client_id in request object
2021-12-16 19:19:25 SUCCESS
ExtractRequestedScopes
Requested scopes
scope
openid consent:urn:conformance.oidf:auzxSxBMwq accounts resources
2021-12-16 19:19:25 SUCCESS
FAPIBrazilValidateConsentScope
Found consent scope in request
actual
[
  "openid",
  "consent:urn:conformance.oidf:auzxSxBMwq",
  "accounts",
  "resources"
]
expected
consent:urn:conformance.oidf:auzxSxBMwq
2021-12-16 19:19:25 SUCCESS
EnsureScopeContainsAccounts
Found accounts scope in request
actual
[
  "openid",
  "consent:urn:conformance.oidf:auzxSxBMwq",
  "accounts",
  "resources"
]
2021-12-16 19:19:25 SUCCESS
EnsureResponseTypeIsCodeIdToken
Response type is expected value
expected
code id_token
2021-12-16 19:19:25 SUCCESS
EnsureOpenIDInScopeRequest
Found 'openid' scope in request
actual
[
  "openid",
  "consent:urn:conformance.oidf:auzxSxBMwq",
  "accounts",
  "resources"
]
expected
openid
2021-12-16 19:19:25 SUCCESS
EnsureMatchingClientId
Client ID matched
client_id
SBSfBTOJMVQBBL848VGXI
2021-12-16 19:19:25 SUCCESS
CreateAuthorizationCode
Created authorization code
authorization_code
zvJ5jUrkTzz5vmY8FgYdlZ8OfAycTSKa
2021-12-16 19:19:25 SUCCESS
ExtractNonceFromAuthorizationRequest
Extracted nonce
nonce
55b15ae3d7dcd1319e06ca0291a2411980a17e83f778008fddbc39c880d9a63a
2021-12-16 19:19:25 SUCCESS
CalculateCHash
Successful c_hash encoding
c_hash
5eVp-wSS2u2xmHqf6d08Uw
2021-12-16 19:19:25 SUCCESS
CalculateSHash
Successful s_hash encoding
s_hash
2qlNXFi5yo7JX-uDC4vZ9Q
2021-12-16 19:19:25 SUCCESS
GenerateIdTokenClaims
Created ID Token Claims
iss
https://www.certification.openid.net/test/a/RP-Security-Test-PAN/
sub
user-subject-1234531
aud
SBSfBTOJMVQBBL848VGXI
nonce
55b15ae3d7dcd1319e06ca0291a2411980a17e83f778008fddbc39c880d9a63a
iat
1639682365
exp
1639682665
2021-12-16 19:19:25
FAPIBrazilAddCPFAndCPNJToIdTokenClaims
Request object does not contain a claims element.id_token
2021-12-16 19:19:25 SUCCESS
AddCHashToIdTokenClaims
Added c_hash to ID token claims
c_hash
5eVp-wSS2u2xmHqf6d08Uw
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "sub": "user-subject-1234531",
  "aud": "SBSfBTOJMVQBBL848VGXI",
  "nonce": "55b15ae3d7dcd1319e06ca0291a2411980a17e83f778008fddbc39c880d9a63a",
  "iat": 1639682365,
  "exp": 1639682665,
  "c_hash": "5eVp-wSS2u2xmHqf6d08Uw"
}
2021-12-16 19:19:25 SUCCESS
AddSHashToIdTokenClaims
Added s_hash to ID token claims
s_hash
2qlNXFi5yo7JX-uDC4vZ9Q
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "sub": "user-subject-1234531",
  "aud": "SBSfBTOJMVQBBL848VGXI",
  "nonce": "55b15ae3d7dcd1319e06ca0291a2411980a17e83f778008fddbc39c880d9a63a",
  "iat": 1639682365,
  "exp": 1639682665,
  "c_hash": "5eVp-wSS2u2xmHqf6d08Uw",
  "s_hash": "2qlNXFi5yo7JX-uDC4vZ9Q"
}
2021-12-16 19:19:25 INFO
AddAtHashToIdTokenClaims
Skipped evaluation due to missing required string: at_hash
expected
at_hash
2021-12-16 19:19:25 INFO
FAPIBrazilAddACRClaimToIdTokenClaims
Skipped evaluation due to missing required string: requested_id_token_acr_values
expected
requested_id_token_acr_values
2021-12-16 19:19:25 SUCCESS
SignIdToken
Signed the ID token
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImNfaGFzaCI6IjVlVnAtd1NTMnUyeG1IcWY2ZDA4VXciLCJzX2hhc2giOiIycWxOWEZpNXlvN0pYLXVEQzR2WjlRIiwiaXNzIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL1JQLVNlY3VyaXR5LVRlc3QtUEFOXC8iLCJleHAiOjE2Mzk2ODI2NjUsIm5vbmNlIjoiNTViMTVhZTNkN2RjZDEzMTllMDZjYTAyOTFhMjQxMTk4MGExN2U4M2Y3NzgwMDhmZGRiYzM5Yzg4MGQ5YTYzYSIsImlhdCI6MTYzOTY4MjM2NX0.nFxugaMA74iM8JeraKTs0UaCbFYiXFLUjoMsy3Q7B0PNjoigMlGC-FWqr2CMTBT3DfQTJUQgaVCxGyQKx3zRL0a5CsZKFqMbaKy9PxUWDYA9wtUVB_C9_f37YTHtwlJfH0673M4ApARQanV1TUXwqz1XWHCPZMvp5yNftIlL14-8xr1e4fXn0C5NDMVw5XSsnDXtX80pgoajXSd0HRGofIJOQoPcBUpV2WHA4oJ7XUcdM0a4ck5EewtqU2ryl_ssTSCjV2LMPxSsgMsSCoyizKpEW27tHWwbPvZDpbZKBqudMyzBOIFkU9ilTVTTbAxpxR6Avgx3R_Lgl8SWvBSo7Q
2021-12-16 19:19:25 SUCCESS
FAPIBrazilChangeConsentStatusToAuthorized
Changed consent status to AUTHORISED
consent
{
  "data": {
    "consentId": "urn:conformance.oidf:auzxSxBMwq",
    "creationDateTime": "2021-12-16T19:19:23Z",
    "status": "AUTHORISED",
    "statusUpdateDateTime": "2021-12-16T19:19:25Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2021-12-16T21:19:23Z",
    "transactionFromDateTime": "2021-12-16T19:14:23Z",
    "transactionToDateTime": "2021-12-16T21:19:23Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/RP-Security-Test-PANconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2021-12-16T19:19:23Z"
  }
}
2021-12-16 19:19:25 SUCCESS
CreateAuthorizationEndpointResponseParams
Added authorization_endpoint_response_params to environment
params
{
  "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
  "state": "587c72308c58fc07bb66be91316c619e19c24c2006dc09a85d31e624db5406f0"
}
2021-12-16 19:19:25 SUCCESS
AddCodeToAuthorizationEndpointResponseParams
Added code to authorization endpoint response params
authorization_endpoint_response_params
{
  "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
  "state": "587c72308c58fc07bb66be91316c619e19c24c2006dc09a85d31e624db5406f0",
  "code": "zvJ5jUrkTzz5vmY8FgYdlZ8OfAycTSKa"
}
2021-12-16 19:19:25 SUCCESS
AddIdTokenToAuthorizationEndpointResponseParams
Added id_token to authorization endpoint response params
authorization_endpoint_response_params
{
  "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
  "state": "587c72308c58fc07bb66be91316c619e19c24c2006dc09a85d31e624db5406f0",
  "code": "zvJ5jUrkTzz5vmY8FgYdlZ8OfAycTSKa",
  "id_token": "eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImNfaGFzaCI6IjVlVnAtd1NTMnUyeG1IcWY2ZDA4VXciLCJzX2hhc2giOiIycWxOWEZpNXlvN0pYLXVEQzR2WjlRIiwiaXNzIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL1JQLVNlY3VyaXR5LVRlc3QtUEFOXC8iLCJleHAiOjE2Mzk2ODI2NjUsIm5vbmNlIjoiNTViMTVhZTNkN2RjZDEzMTllMDZjYTAyOTFhMjQxMTk4MGExN2U4M2Y3NzgwMDhmZGRiYzM5Yzg4MGQ5YTYzYSIsImlhdCI6MTYzOTY4MjM2NX0.nFxugaMA74iM8JeraKTs0UaCbFYiXFLUjoMsy3Q7B0PNjoigMlGC-FWqr2CMTBT3DfQTJUQgaVCxGyQKx3zRL0a5CsZKFqMbaKy9PxUWDYA9wtUVB_C9_f37YTHtwlJfH0673M4ApARQanV1TUXwqz1XWHCPZMvp5yNftIlL14-8xr1e4fXn0C5NDMVw5XSsnDXtX80pgoajXSd0HRGofIJOQoPcBUpV2WHA4oJ7XUcdM0a4ck5EewtqU2ryl_ssTSCjV2LMPxSsgMsSCoyizKpEW27tHWwbPvZDpbZKBqudMyzBOIFkU9ilTVTTbAxpxR6Avgx3R_Lgl8SWvBSo7Q"
}
2021-12-16 19:19:25
SendAuthorizationResponseWithResponseModeFragment
Redirecting back to client
uri
https://api-openbanking-hml.bancopan.com.br/tpp/callback#state=587c72308c58fc07bb66be91316c619e19c24c2006dc09a85d31e624db5406f0&code=zvJ5jUrkTzz5vmY8FgYdlZ8OfAycTSKa&id_token=eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImNfaGFzaCI6IjVlVnAtd1NTMnUyeG1IcWY2ZDA4VXciLCJzX2hhc2giOiIycWxOWEZpNXlvN0pYLXVEQzR2WjlRIiwiaXNzIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL1JQLVNlY3VyaXR5LVRlc3QtUEFOXC8iLCJleHAiOjE2Mzk2ODI2NjUsIm5vbmNlIjoiNTViMTVhZTNkN2RjZDEzMTllMDZjYTAyOTFhMjQxMTk4MGExN2U4M2Y3NzgwMDhmZGRiYzM5Yzg4MGQ5YTYzYSIsImlhdCI6MTYzOTY4MjM2NX0.nFxugaMA74iM8JeraKTs0UaCbFYiXFLUjoMsy3Q7B0PNjoigMlGC-FWqr2CMTBT3DfQTJUQgaVCxGyQKx3zRL0a5CsZKFqMbaKy9PxUWDYA9wtUVB_C9_f37YTHtwlJfH0673M4ApARQanV1TUXwqz1XWHCPZMvp5yNftIlL14-8xr1e4fXn0C5NDMVw5XSsnDXtX80pgoajXSd0HRGofIJOQoPcBUpV2WHA4oJ7XUcdM0a4ck5EewtqU2ryl_ssTSCjV2LMPxSsgMsSCoyizKpEW27tHWwbPvZDpbZKBqudMyzBOIFkU9ilTVTTbAxpxR6Avgx3R_Lgl8SWvBSo7Q
2021-12-16 19:19:25 OUTGOING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Response to HTTP request to test instance Om6erTyR3wCwg7c
outgoing
org.springframework.web.servlet.view.RedirectView: [RedirectView]; URL [https://api-openbanking-hml.bancopan.com.br/tpp/callback#state=587c72308c58fc07bb66be91316c619e19c24c2006dc09a85d31e624db5406f0&code=zvJ5jUrkTzz5vmY8FgYdlZ8OfAycTSKa&id_token=eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImNfaGFzaCI6IjVlVnAtd1NTMnUyeG1IcWY2ZDA4VXciLCJzX2hhc2giOiIycWxOWEZpNXlvN0pYLXVEQzR2WjlRIiwiaXNzIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL1JQLVNlY3VyaXR5LVRlc3QtUEFOXC8iLCJleHAiOjE2Mzk2ODI2NjUsIm5vbmNlIjoiNTViMTVhZTNkN2RjZDEzMTllMDZjYTAyOTFhMjQxMTk4MGExN2U4M2Y3NzgwMDhmZGRiYzM5Yzg4MGQ5YTYzYSIsImlhdCI6MTYzOTY4MjM2NX0.nFxugaMA74iM8JeraKTs0UaCbFYiXFLUjoMsy3Q7B0PNjoigMlGC-FWqr2CMTBT3DfQTJUQgaVCxGyQKx3zRL0a5CsZKFqMbaKy9PxUWDYA9wtUVB_C9_f37YTHtwlJfH0673M4ApARQanV1TUXwqz1XWHCPZMvp5yNftIlL14-8xr1e4fXn0C5NDMVw5XSsnDXtX80pgoajXSd0HRGofIJOQoPcBUpV2WHA4oJ7XUcdM0a4ck5EewtqU2ryl_ssTSCjV2LMPxSsgMsSCoyizKpEW27tHWwbPvZDpbZKBqudMyzBOIFkU9ilTVTTbAxpxR6Avgx3R_Lgl8SWvBSo7Q]
outgoing_path
authorize
2021-12-16 19:19:26 INCOMING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Incoming HTTP request to test instance Om6erTyR3wCwg7c
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/RP-Security-Test-PAN/.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-16 19:19:26 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-16 19:19:26 OUTGOING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Response to HTTP request to test instance Om6erTyR3wCwg7c
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo",
    "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/par"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ],
  "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/par",
  "require_pushed_authorization_requests": true,
  "response_types_supported": [
    "code id_token"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256"
  ]
}
outgoing_path
.well-known/openid-configuration
2021-12-16 19:19:26 INCOMING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Incoming HTTP request to test instance Om6erTyR3wCwg7c
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/RP-Security-Test-PAN/jwks
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-16 19:19:26 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-16 19:19:26 OUTGOING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Response to HTTP request to test instance Om6erTyR3wCwg7c
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "alg": "PS256",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "alg": "RSA-OAEP",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
outgoing_path
jwks
2021-12-16 19:19:27 INCOMING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Incoming HTTP request to test instance Om6erTyR3wCwg7c
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded",
  "accept-encoding": "gzip, deflate, br",
  "content-length": "1291",
  "connection": "close"
}
incoming_path
/test-mtls/a/RP-Security-Test-PAN/token
incoming_body_form_params
{
  "grant_type": "authorization_code",
  "code": "zvJ5jUrkTzz5vmY8FgYdlZ8OfAycTSKa",
  "redirect_uri": "https://api-openbanking-hml.bancopan.com.br/tpp/callback",
  "code_verifier": "KTuT15LfVjItGStp09eku6Cf36adn6xxAMLqpzPwDxM",
  "client_id": "SBSfBTOJMVQBBL848VGXI",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNjYsImV4cCI6MTYzOTY4MjQyNiwianRpIjoiTkpzREJVdVNpUlliRGFRT3RLYURzXzlhT2JZdGhneXJ1WmNMdTRxNlBaMCIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.jF2SqaZnVY6J9rTQiHMNEVbsBjUMF2fKuOmxYr7oWV1_HFQr8uLjGC_Z3eB3srXas2GpTB7G6edXagchor92exutbwjzJqSewOE6q-O51Yf41kNaZVPmoRkQsd3ZvtuCdoMQLufMtWq50rOKl6cMynYpRq9DvLwrOP3yEFQkXRtaFYcoXu4WSH3jaVjW-MAk6pbyAtwoufal89y9nECs_l1Q7BLfna3fUyZLBCCA-yIh9aBjcZK8fDBzI2st9Kd0J-E5MJpA-AzVwz5XTncEmnRI85otVIF7_cR0_6GgoqKLDj2cEBfPl5NsbvV3e0fr9ELufPIGz4ecHXVbMurB4Q",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
grant_type=authorization_code&code=zvJ5jUrkTzz5vmY8FgYdlZ8OfAycTSKa&redirect_uri=https%3A%2F%2Fapi-openbanking-hml.bancopan.com.br%2Ftpp%2Fcallback&code_verifier=KTuT15LfVjItGStp09eku6Cf36adn6xxAMLqpzPwDxM&client_id=SBSfBTOJMVQBBL848VGXI&client_assertion=eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNjYsImV4cCI6MTYzOTY4MjQyNiwianRpIjoiTkpzREJVdVNpUlliRGFRT3RLYURzXzlhT2JZdGhneXJ1WmNMdTRxNlBaMCIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.jF2SqaZnVY6J9rTQiHMNEVbsBjUMF2fKuOmxYr7oWV1_HFQr8uLjGC_Z3eB3srXas2GpTB7G6edXagchor92exutbwjzJqSewOE6q-O51Yf41kNaZVPmoRkQsd3ZvtuCdoMQLufMtWq50rOKl6cMynYpRq9DvLwrOP3yEFQkXRtaFYcoXu4WSH3jaVjW-MAk6pbyAtwoufal89y9nECs_l1Q7BLfna3fUyZLBCCA-yIh9aBjcZK8fDBzI2st9Kd0J-E5MJpA-AzVwz5XTncEmnRI85otVIF7_cR0_6GgoqKLDj2cEBfPl5NsbvV3e0fr9ELufPIGz4ecHXVbMurB4Q&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2021-12-16 19:19:27 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2021-12-16 19:19:27 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz\nMjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct\nNjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j\nb20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk\nYWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ\ncml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ\nKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4\n9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r\niu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6\ni56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV\nCLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3\n5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC\nAtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO\nEUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA\noD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v\ncmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB\nBQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC\nD2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k\nATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz\nb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg\nb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g\nU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg\ncmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j\nZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5\nIGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0\ncDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s\naWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL\n8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs\nZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0\nQZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY\nYFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG\nOZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,UID\u003dac60fe65-58ca-44c3-9352-6f556c5cb98e,2.5.4.5\u003d#130e3539323835343131303030313133,CN\u003dbancopan.com.br,OU\u003db6a214c7-6332-5a41-8464-a281fb9a4ca0,O\u003dBANCO PAN,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "bancopan.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2021-12-16 19:19:27 SUCCESS
CheckForClientCertificate
Found client certificate
2021-12-16 19:19:27 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz
MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct
NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j
b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk
YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ
cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4
9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r
iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6
i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV
CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3
5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC
AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO
EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA
oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v
cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB
BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC
D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k
ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz
b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg
b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g
U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg
cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j
ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5
IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0
cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s
aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL
8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs
ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0
QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY
YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG
OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks=
-----END CERTIFICATE-----
2021-12-16 19:19:27 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNjYsImV4cCI6MTYzOTY4MjQyNiwianRpIjoiTkpzREJVdVNpUlliRGFRT3RLYURzXzlhT2JZdGhneXJ1WmNMdTRxNlBaMCIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.jF2SqaZnVY6J9rTQiHMNEVbsBjUMF2fKuOmxYr7oWV1_HFQr8uLjGC_Z3eB3srXas2GpTB7G6edXagchor92exutbwjzJqSewOE6q-O51Yf41kNaZVPmoRkQsd3ZvtuCdoMQLufMtWq50rOKl6cMynYpRq9DvLwrOP3yEFQkXRtaFYcoXu4WSH3jaVjW-MAk6pbyAtwoufal89y9nECs_l1Q7BLfna3fUyZLBCCA-yIh9aBjcZK8fDBzI2st9Kd0J-E5MJpA-AzVwz5XTncEmnRI85otVIF7_cR0_6GgoqKLDj2cEBfPl5NsbvV3e0fr9ELufPIGz4ecHXVbMurB4Q",
  "header": {
    "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "SBSfBTOJMVQBBL848VGXI",
    "aud": [
      "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
      "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
      "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token"
    ],
    "iss": "SBSfBTOJMVQBBL848VGXI",
    "exp": 1639682426,
    "iat": 1639682366,
    "jti": "NJsDBUuSiRYbDaQOtKaDs_9aObYthgyruZcLu4q6PZ0"
  }
}
2021-12-16 19:19:27
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2021-12-16 19:19:27 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNjYsImV4cCI6MTYzOTY4MjQyNiwianRpIjoiTkpzREJVdVNpUlliRGFRT3RLYURzXzlhT2JZdGhneXJ1WmNMdTRxNlBaMCIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.jF2SqaZnVY6J9rTQiHMNEVbsBjUMF2fKuOmxYr7oWV1_HFQr8uLjGC_Z3eB3srXas2GpTB7G6edXagchor92exutbwjzJqSewOE6q-O51Yf41kNaZVPmoRkQsd3ZvtuCdoMQLufMtWq50rOKl6cMynYpRq9DvLwrOP3yEFQkXRtaFYcoXu4WSH3jaVjW-MAk6pbyAtwoufal89y9nECs_l1Q7BLfna3fUyZLBCCA-yIh9aBjcZK8fDBzI2st9Kd0J-E5MJpA-AzVwz5XTncEmnRI85otVIF7_cR0_6GgoqKLDj2cEBfPl5NsbvV3e0fr9ELufPIGz4ecHXVbMurB4Q
2021-12-16 19:19:27 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-12-16 19:19:27 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2021-12-16 19:19:27 SUCCESS
ValidateAuthorizationCode
Found authorization code
authorization_code
zvJ5jUrkTzz5vmY8FgYdlZ8OfAycTSKa
2021-12-16 19:19:27 SUCCESS
ValidateRedirectUri
Found redirect uri
redirect_uri
https://api-openbanking-hml.bancopan.com.br/tpp/callback
2021-12-16 19:19:27 SUCCESS
ValidateCodeVerifierWithS256
Validated code_verifier successfully
code_challenge_method
S256
code_verifier
KTuT15LfVjItGStp09eku6Cf36adn6xxAMLqpzPwDxM
code_challenge
n0X-wrJZ1kWLYfW1TY2ZL5HnfC8lJQVsARQ98XPNyVM
2021-12-16 19:19:27 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
1OfFeUvgngY7o4hr83iozw5bz1zuOqzRJKrAmydxshrB7r9GFT
2021-12-16 19:19:27 SUCCESS
CalculateAtHash
Successful at_hash encoding
at_hash
eUtSUHaY9MMxY7JdPbxP6A
2021-12-16 19:19:27
CreateRefreshToken
Created refresh token
refresh_token
jVlmsQknvhhkRIfuKowitOaWwzmoXYdPxvkqNrSPoOJmZWJEQq0911903688;&:!/
2021-12-16 19:19:27 SUCCESS
GenerateIdTokenClaims
Created ID Token Claims
iss
https://www.certification.openid.net/test/a/RP-Security-Test-PAN/
sub
user-subject-1234531
aud
SBSfBTOJMVQBBL848VGXI
nonce
55b15ae3d7dcd1319e06ca0291a2411980a17e83f778008fddbc39c880d9a63a
iat
1639682367
exp
1639682667
2021-12-16 19:19:27
FAPIBrazilAddCPFAndCPNJToIdTokenClaims
Request object does not contain a claims element.id_token
2021-12-16 19:19:27 SUCCESS
AddAtHashToIdTokenClaims
Added at_hash to ID token claims
at_hash
eUtSUHaY9MMxY7JdPbxP6A
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "sub": "user-subject-1234531",
  "aud": "SBSfBTOJMVQBBL848VGXI",
  "nonce": "55b15ae3d7dcd1319e06ca0291a2411980a17e83f778008fddbc39c880d9a63a",
  "iat": 1639682367,
  "exp": 1639682667,
  "at_hash": "eUtSUHaY9MMxY7JdPbxP6A"
}
2021-12-16 19:19:27 INFO
FAPIBrazilAddACRClaimToIdTokenClaims
Skipped evaluation due to missing required string: requested_id_token_acr_values
expected
requested_id_token_acr_values
2021-12-16 19:19:27 SUCCESS
SignIdToken
Signed the ID token
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdF9oYXNoIjoiZVV0U1VIYVk5TU14WTdKZFBieFA2QSIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoiU0JTZkJUT0pNVlFCQkw4NDhWR1hJIiwiaXNzIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL1JQLVNlY3VyaXR5LVRlc3QtUEFOXC8iLCJleHAiOjE2Mzk2ODI2NjcsIm5vbmNlIjoiNTViMTVhZTNkN2RjZDEzMTllMDZjYTAyOTFhMjQxMTk4MGExN2U4M2Y3NzgwMDhmZGRiYzM5Yzg4MGQ5YTYzYSIsImlhdCI6MTYzOTY4MjM2N30.w2WSzfAnGa9Bqc1MhzRzSCtC2HeKTq0XMtCjeLe8CzQtn2ldb-JV4ZdPseSeR4pXTMKMFn27Z53ycSzPOISRoWvM54YescbJWEOcO8LQ0UKg67U2lw--tstwY5s3ye1vvSCWdDT8eXTN9MQV1OHafSlvVjIFfWAXSm5Ao7VJtu6B63FF7POb4LxtFJDtdxqntFvNn8IWIesp2wgLUEI4oGdaFWOxCDIZFvbDtMA1Xhzxvp5asYlT0oY3FAjwyEtemvSmjxmcKWVp1MI-QCDLfmr9NhtVoUmI0w-0xg1L6IYu7zSTAtItoRIKTB6zSi76ge6pwdLoiwUnYsE6cugFKg
2021-12-16 19:19:27 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
1OfFeUvgngY7o4hr83iozw5bz1zuOqzRJKrAmydxshrB7r9GFT
token_type
Bearer
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdF9oYXNoIjoiZVV0U1VIYVk5TU14WTdKZFBieFA2QSIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoiU0JTZkJUT0pNVlFCQkw4NDhWR1hJIiwiaXNzIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL1JQLVNlY3VyaXR5LVRlc3QtUEFOXC8iLCJleHAiOjE2Mzk2ODI2NjcsIm5vbmNlIjoiNTViMTVhZTNkN2RjZDEzMTllMDZjYTAyOTFhMjQxMTk4MGExN2U4M2Y3NzgwMDhmZGRiYzM5Yzg4MGQ5YTYzYSIsImlhdCI6MTYzOTY4MjM2N30.w2WSzfAnGa9Bqc1MhzRzSCtC2HeKTq0XMtCjeLe8CzQtn2ldb-JV4ZdPseSeR4pXTMKMFn27Z53ycSzPOISRoWvM54YescbJWEOcO8LQ0UKg67U2lw--tstwY5s3ye1vvSCWdDT8eXTN9MQV1OHafSlvVjIFfWAXSm5Ao7VJtu6B63FF7POb4LxtFJDtdxqntFvNn8IWIesp2wgLUEI4oGdaFWOxCDIZFvbDtMA1Xhzxvp5asYlT0oY3FAjwyEtemvSmjxmcKWVp1MI-QCDLfmr9NhtVoUmI0w-0xg1L6IYu7zSTAtItoRIKTB6zSi76ge6pwdLoiwUnYsE6cugFKg
refresh_token
jVlmsQknvhhkRIfuKowitOaWwzmoXYdPxvkqNrSPoOJmZWJEQq0911903688;&:!/
2021-12-16 19:19:27 OUTGOING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Response to HTTP request to test instance Om6erTyR3wCwg7c
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "1OfFeUvgngY7o4hr83iozw5bz1zuOqzRJKrAmydxshrB7r9GFT",
  "token_type": "Bearer",
  "id_token": "eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdF9oYXNoIjoiZVV0U1VIYVk5TU14WTdKZFBieFA2QSIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoiU0JTZkJUT0pNVlFCQkw4NDhWR1hJIiwiaXNzIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL1JQLVNlY3VyaXR5LVRlc3QtUEFOXC8iLCJleHAiOjE2Mzk2ODI2NjcsIm5vbmNlIjoiNTViMTVhZTNkN2RjZDEzMTllMDZjYTAyOTFhMjQxMTk4MGExN2U4M2Y3NzgwMDhmZGRiYzM5Yzg4MGQ5YTYzYSIsImlhdCI6MTYzOTY4MjM2N30.w2WSzfAnGa9Bqc1MhzRzSCtC2HeKTq0XMtCjeLe8CzQtn2ldb-JV4ZdPseSeR4pXTMKMFn27Z53ycSzPOISRoWvM54YescbJWEOcO8LQ0UKg67U2lw--tstwY5s3ye1vvSCWdDT8eXTN9MQV1OHafSlvVjIFfWAXSm5Ao7VJtu6B63FF7POb4LxtFJDtdxqntFvNn8IWIesp2wgLUEI4oGdaFWOxCDIZFvbDtMA1Xhzxvp5asYlT0oY3FAjwyEtemvSmjxmcKWVp1MI-QCDLfmr9NhtVoUmI0w-0xg1L6IYu7zSTAtItoRIKTB6zSi76ge6pwdLoiwUnYsE6cugFKg",
  "refresh_token": "jVlmsQknvhhkRIfuKowitOaWwzmoXYdPxvkqNrSPoOJmZWJEQq0911903688;\u0026:!/"
}
outgoing_path
token
2021-12-16 19:19:29 INCOMING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Incoming HTTP request to test instance Om6erTyR3wCwg7c
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/RP-Security-Test-PAN/.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-16 19:19:29 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-16 19:19:29 OUTGOING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Response to HTTP request to test instance Om6erTyR3wCwg7c
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo",
    "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/par"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ],
  "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/par",
  "require_pushed_authorization_requests": true,
  "response_types_supported": [
    "code id_token"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256"
  ]
}
outgoing_path
.well-known/openid-configuration
2021-12-16 19:19:29 INCOMING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Incoming HTTP request to test instance Om6erTyR3wCwg7c
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/RP-Security-Test-PAN/.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-16 19:19:29 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-16 19:19:29 OUTGOING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Response to HTTP request to test instance Om6erTyR3wCwg7c
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/userinfo",
    "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/par"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ],
  "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/par",
  "require_pushed_authorization_requests": true,
  "response_types_supported": [
    "code id_token"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256"
  ]
}
outgoing_path
.well-known/openid-configuration
2021-12-16 19:19:29 INCOMING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Incoming HTTP request to test instance Om6erTyR3wCwg7c
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.9.1 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded",
  "accept-encoding": "gzip, deflate, br",
  "content-length": "1200",
  "connection": "close"
}
incoming_path
/test-mtls/a/RP-Security-Test-PAN/token
incoming_body_form_params
{
  "grant_type": "refresh_token",
  "refresh_token": "jVlmsQknvhhkRIfuKowitOaWwzmoXYdPxvkqNrSPoOJmZWJEQq0911903688;\u0026:!/",
  "client_id": "SBSfBTOJMVQBBL848VGXI",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNjksImV4cCI6MTYzOTY4MjQyOSwianRpIjoiQ3RwRHR3eXZUVy1KbWxXSGFnVEF3ZmZhTklRR1BEQXkwRUlCeFRJeU1lVSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.W6inv7XXDaPWJkdwlYjA_2-SmCo9Vj3lTo_J4gvXvBzFmzdDOQbEv6J8IuWjMUnGLetpr0FrV9WdkpHUEzYDICkUx4bX605jKfZcLFbSvOrUt_ddNethkyOdhoX6OD01hlsGb8l9zNToZZnbukHpdu8KgrwsepC8NRap6tTUtvF_ndR0GE1q-F2zx7KZwxFsNaFf5eZq__VF0IyYOZvJi5gFeUkuLL9ZpVmbBwC4b7GLVs2bXDI6ors3D_DRr_RNMxBaQZFCTJ4iXSDV3BAE0hDKS3j8n-5MuFjBP4tYYTd_t0U9JA74DENHaYqvID2mm2ofT6gaDm92jcq9Df-TWQ",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
grant_type=refresh_token&refresh_token=jVlmsQknvhhkRIfuKowitOaWwzmoXYdPxvkqNrSPoOJmZWJEQq0911903688%3B%26%3A%21%2F&client_id=SBSfBTOJMVQBBL848VGXI&client_assertion=eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNjksImV4cCI6MTYzOTY4MjQyOSwianRpIjoiQ3RwRHR3eXZUVy1KbWxXSGFnVEF3ZmZhTklRR1BEQXkwRUlCeFRJeU1lVSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.W6inv7XXDaPWJkdwlYjA_2-SmCo9Vj3lTo_J4gvXvBzFmzdDOQbEv6J8IuWjMUnGLetpr0FrV9WdkpHUEzYDICkUx4bX605jKfZcLFbSvOrUt_ddNethkyOdhoX6OD01hlsGb8l9zNToZZnbukHpdu8KgrwsepC8NRap6tTUtvF_ndR0GE1q-F2zx7KZwxFsNaFf5eZq__VF0IyYOZvJi5gFeUkuLL9ZpVmbBwC4b7GLVs2bXDI6ors3D_DRr_RNMxBaQZFCTJ4iXSDV3BAE0hDKS3j8n-5MuFjBP4tYYTd_t0U9JA74DENHaYqvID2mm2ofT6gaDm92jcq9Df-TWQ&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2021-12-16 19:19:29 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2021-12-16 19:19:29 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz\nMjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct\nNjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j\nb20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk\nYWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ\ncml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ\nKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4\n9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r\niu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6\ni56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV\nCLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3\n5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC\nAtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO\nEUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA\noD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v\ncmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB\nBQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC\nD2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k\nATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz\nb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg\nb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g\nU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg\ncmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j\nZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5\nIGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0\ncDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s\naWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL\n8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs\nZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0\nQZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY\nYFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG\nOZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,UID\u003dac60fe65-58ca-44c3-9352-6f556c5cb98e,2.5.4.5\u003d#130e3539323835343131303030313133,CN\u003dbancopan.com.br,OU\u003db6a214c7-6332-5a41-8464-a281fb9a4ca0,O\u003dBANCO PAN,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "bancopan.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2021-12-16 19:19:29 SUCCESS
CheckForClientCertificate
Found client certificate
2021-12-16 19:19:29 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz
MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct
NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j
b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk
YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ
cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4
9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r
iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6
i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV
CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3
5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC
AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO
EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA
oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v
cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB
BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC
D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k
ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz
b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg
b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g
U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg
cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j
ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5
IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0
cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s
aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL
8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs
ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0
QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY
YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG
OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks=
-----END CERTIFICATE-----
2021-12-16 19:19:29 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNjksImV4cCI6MTYzOTY4MjQyOSwianRpIjoiQ3RwRHR3eXZUVy1KbWxXSGFnVEF3ZmZhTklRR1BEQXkwRUlCeFRJeU1lVSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.W6inv7XXDaPWJkdwlYjA_2-SmCo9Vj3lTo_J4gvXvBzFmzdDOQbEv6J8IuWjMUnGLetpr0FrV9WdkpHUEzYDICkUx4bX605jKfZcLFbSvOrUt_ddNethkyOdhoX6OD01hlsGb8l9zNToZZnbukHpdu8KgrwsepC8NRap6tTUtvF_ndR0GE1q-F2zx7KZwxFsNaFf5eZq__VF0IyYOZvJi5gFeUkuLL9ZpVmbBwC4b7GLVs2bXDI6ors3D_DRr_RNMxBaQZFCTJ4iXSDV3BAE0hDKS3j8n-5MuFjBP4tYYTd_t0U9JA74DENHaYqvID2mm2ofT6gaDm92jcq9Df-TWQ",
  "header": {
    "kid": "5gYHIHbtw0UB4BwjtqUnhtFN6WthEW2mdX7dfUBQHII",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "SBSfBTOJMVQBBL848VGXI",
    "aud": [
      "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/",
      "https://www.certification.openid.net/test/a/RP-Security-Test-PAN/token",
      "https://www.certification.openid.net/test-mtls/a/RP-Security-Test-PAN/token"
    ],
    "iss": "SBSfBTOJMVQBBL848VGXI",
    "exp": 1639682429,
    "iat": 1639682369,
    "jti": "CtpDtwyvTW-JmlWHagTAwffaNIQGPDAy0EIBxTIyMeU"
  }
}
2021-12-16 19:19:29
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2021-12-16 19:19:29 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjVnWUhJSGJ0dzBVQjRCd2p0cVVuaHRGTjZXdGhFVzJtZFg3ZGZVQlFISUkifQ.eyJpYXQiOjE2Mzk2ODIzNjksImV4cCI6MTYzOTY4MjQyOSwianRpIjoiQ3RwRHR3eXZUVy1KbWxXSGFnVEF3ZmZhTklRR1BEQXkwRUlCeFRJeU1lVSIsImlzcyI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsInN1YiI6IlNCU2ZCVE9KTVZRQkJMODQ4VkdYSSIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1JQLVNlY3VyaXR5LVRlc3QtUEFOLyIsImh0dHBzOi8vd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldC90ZXN0L2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvUlAtU2VjdXJpdHktVGVzdC1QQU4vdG9rZW4iXX0.W6inv7XXDaPWJkdwlYjA_2-SmCo9Vj3lTo_J4gvXvBzFmzdDOQbEv6J8IuWjMUnGLetpr0FrV9WdkpHUEzYDICkUx4bX605jKfZcLFbSvOrUt_ddNethkyOdhoX6OD01hlsGb8l9zNToZZnbukHpdu8KgrwsepC8NRap6tTUtvF_ndR0GE1q-F2zx7KZwxFsNaFf5eZq__VF0IyYOZvJi5gFeUkuLL9ZpVmbBwC4b7GLVs2bXDI6ors3D_DRr_RNMxBaQZFCTJ4iXSDV3BAE0hDKS3j8n-5MuFjBP4tYYTd_t0U9JA74DENHaYqvID2mm2ofT6gaDm92jcq9Df-TWQ
2021-12-16 19:19:29 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-12-16 19:19:29 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2021-12-16 19:19:29 SUCCESS
ValidateRefreshToken
refresh_token parameter matches the expected value.
refresh_token
jVlmsQknvhhkRIfuKowitOaWwzmoXYdPxvkqNrSPoOJmZWJEQq0911903688;&:!/
2021-12-16 19:19:29 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
7EkXc46FHHJuZjFRxKWGlrL89hZQVTapD82aswfAcxbIZan2tc
2021-12-16 19:19:29 SUCCESS
CalculateAtHash
Successful at_hash encoding
at_hash
SjrB0bumw-Dm-4dUDz1zBw
2021-12-16 19:19:29
CreateRefreshToken
Created refresh token
refresh_token
kJIpOOjJlzYdvCwMYwmNVVDUDZDoJgKzzxvrcFNkkPBvWcDtJS3784295471;!,$~
2021-12-16 19:19:29 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
7EkXc46FHHJuZjFRxKWGlrL89hZQVTapD82aswfAcxbIZan2tc
token_type
Bearer
refresh_token
kJIpOOjJlzYdvCwMYwmNVVDUDZDoJgKzzxvrcFNkkPBvWcDtJS3784295471;!,$~
scope
openid consent:urn:conformance.oidf:auzxSxBMwq accounts resources
2021-12-16 19:19:29 OUTGOING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Response to HTTP request to test instance Om6erTyR3wCwg7c
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "7EkXc46FHHJuZjFRxKWGlrL89hZQVTapD82aswfAcxbIZan2tc",
  "token_type": "Bearer",
  "refresh_token": "kJIpOOjJlzYdvCwMYwmNVVDUDZDoJgKzzxvrcFNkkPBvWcDtJS3784295471;!,$~",
  "scope": "openid consent:urn:conformance.oidf:auzxSxBMwq accounts resources"
}
outgoing_path
token
2021-12-16 19:19:29 INCOMING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Incoming HTTP request to test instance Om6erTyR3wCwg7c
incoming_headers
{
  "host": "www.certification.openid.net",
  "accept": "application/json, text/plain, */*",
  "authorization": "Bearer 7EkXc46FHHJuZjFRxKWGlrL89hZQVTapD82aswfAcxbIZan2tc",
  "user-agent": "axios/0.21.4",
  "connection": "close"
}
incoming_path
/test-mtls/a/RP-Security-Test-PAN/accounts/v1/accounts
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-16 19:19:29 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Accounts endpoint
2021-12-16 19:19:29 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4 9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6 i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3 5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5 IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0 cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL 8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0 QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz\nMjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct\nNjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j\nb20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk\nYWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ\ncml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ\nKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4\n9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r\niu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6\ni56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV\nCLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3\n5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC\nAtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO\nEUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA\noD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v\ncmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB\nBQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC\nD2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k\nATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz\nb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg\nb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g\nU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg\ncmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j\nZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5\nIGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0\ncDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s\naWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL\n8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs\nZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0\nQZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY\nYFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG\nOZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,UID\u003dac60fe65-58ca-44c3-9352-6f556c5cb98e,2.5.4.5\u003d#130e3539323835343131303030313133,CN\u003dbancopan.com.br,OU\u003db6a214c7-6332-5a41-8464-a281fb9a4ca0,O\u003dBANCO PAN,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "bancopan.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2021-12-16 19:19:29 SUCCESS
CheckForClientCertificate
Found client certificate
2021-12-16 19:19:29 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG5TCCBc2gAwIBAgIUPz5BkF1/67noL2gNUfej8F/Srk8wDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDYyNTEzMjEwMFoXDTIyMDcyNTEz
MjEwMFowggEPMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xEjAQBgNVBAoTCUJBTkNPIFBBTjEtMCsGA1UECxMkYjZhMjE0Yzct
NjMzMi01YTQxLTg0NjQtYTI4MWZiOWE0Y2EwMRgwFgYDVQQDEw9iYW5jb3Bhbi5j
b20uYnIxFzAVBgNVBAUTDjU5Mjg1NDExMDAwMTEzMTQwMgYKCZImiZPyLGQBARMk
YWM2MGZlNjUtNThjYS00NGMzLTkzNTItNmY1NTZjNWNiOThlMR0wGwYDVQQPExRQ
cml2YXRlIE9yZ2FuaXphdGlvbjETMBEGCysGAQQBgjc8AgEDEwJCUjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9iTsg4Msxj3uccgD/6XTlbFz27VtV4
9PJqZf23TvhEbz6o80y2VMZ+5Q57lh9RbN2uAmGLO/jpfbzrCsWS7Zh53dvesi0r
iu6TwOHdJ1n2kLgSOtH3lZFYKHesnWNi+DndNMRDWeZeWJMSXoMNK8zQP7NMUhO6
i56vB8Dv6OLAyZ0HgC/xpfUj9GCyDDFa2HvqEJsf5YwAEnXBWqvDTVLIkt8on+WV
CLrlgYJsNunCZrpAJ9/ws7V4WZCEoJBjl7eFe8LuqRQ5G3L/5Lsd2jBtgS4u2xG3
5iTWbWWQ+FnBN9enlw0lw7djwQohndIxSVhMy/YL+b6rO5vJFWD7s3sCAwEAAaOC
AtMwggLPMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DO
EUPfTL4wTAYIKwYBBQUHAQEEQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBA
oD6gPIY6aHR0cDovL2NybC5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5v
cmcuYnIvaXNzdWVyLmNybDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYB
BQUHAwIwHQYDVR0OBBYEFKoNhBSY0ndO3mFsjapYiGGn82PGMBoGA1UdEQQTMBGC
D2JhbmNvcGFuLmNvbS5icjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9k
ATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBz
b2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQg
b3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0g
U2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMg
cmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5j
ZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5
IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0
cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9s
aWNpZXMwDQYJKoZIhvcNAQELBQADggEBAISLc+dYvh4KZpPGgr5BT59CVtAETbyL
8ztUdhATHzRouH1HhG5UhXPzsgpsceF9DL/OuKVuAHMGvlPVBUdfMNo/dztdNfZs
ZG7XT/OLzF5KPfjbNcP0z3NgmGzLE61QafJ7a88eBkUJR6VqI/FAQEJ339NYh5i0
QZRll4z7H2c9NO+oS7rEd3EC9ixUY+hMnibtX/F9XXPc4rNlmhTL1Jx3R3EjTRrY
YFTmIjrI8KTz2+UX1tV6/6WgkDxujsbpQmOTtoC6Sy7HQoeN9pGJ/20/AOFDTMsG
OZOp5hfqEfELz3nzHp7ZETCx0Jg4YgaeQmQh7/5Y1UlRd1IRGbDDdks=
-----END CERTIFICATE-----
2021-12-16 19:19:29 SUCCESS
EnsureBearerAccessTokenNotInParams
Client correctly did not send access token in query parameters or form body
2021-12-16 19:19:29 SUCCESS
ExtractBearerAccessTokenFromHeader
Found access token on incoming request
access_token
7EkXc46FHHJuZjFRxKWGlrL89hZQVTapD82aswfAcxbIZan2tc
2021-12-16 19:19:29 SUCCESS
RequireBearerAccessToken
Found access token in request
actual
7EkXc46FHHJuZjFRxKWGlrL89hZQVTapD82aswfAcxbIZan2tc
2021-12-16 19:19:29 INFO
ExtractFapiDateHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-auth-date
path
headers.x-fapi-auth-date
mapped
object
incoming_request
2021-12-16 19:19:29 INFO
ExtractFapiIpAddressHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-customer-ip-address
path
headers.x-fapi-customer-ip-address
mapped
object
incoming_request
2021-12-16 19:19:29 INFO
ExtractFapiInteractionIdHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-interaction-id
path
headers.x-fapi-interaction-id
mapped
object
incoming_request
2021-12-16 19:19:29 SUCCESS
FAPIBrazilEnsureAuthorizationRequestScopesContainAccounts
'accounts' was included in authorization request scopes
actual
openid consent:urn:conformance.oidf:auzxSxBMwq accounts resources
expected
accounts
2021-12-16 19:19:29 INFO
CreateFapiInteractionIdIfNeeded
Found existing FAPI interaction ID
fapi_interaction_id
b5885f9f-d58d-45a1-bb84-18145e4247e3
2021-12-16 19:19:29 SUCCESS
CreateFAPIAccountEndpointResponse
Created account response object
accounts_endpoint_response
{
  "conformance-test-finished": "true"
}
accounts_endpoint_response_headers
{
  "x-fapi-interaction-id": "b5885f9f-d58d-45a1-bb84-18145e4247e3",
  "content-type": "application/json; charset\u003dUTF-8"
}
2021-12-16 19:19:29 SUCCESS
CreateBrazilAccountsEndpointResponse
Created Brazil accounts response (Please note that this is a hardcoded response copied from API documentation)
accounts_endpoint_response
{
  "data": [
    {
      "brandName": "Organização A",
      "companyCnpj": "21128159000166",
      "type": "CONTA_DEPOSITO_A_VISTA",
      "compeCode": "001",
      "branchCode": "6272",
      "number": "94088392",
      "checkDigit": "4",
      "accountId": "92792126019929279212650822221989319252576"
    }
  ],
  "links": {
    "self": "https://api.banco.com.br/open-banking/api/v1/resource",
    "first": "https://api.banco.com.br/open-banking/api/v1/resource",
    "prev": "https://api.banco.com.br/open-banking/api/v1/resource",
    "next": "https://api.banco.com.br/open-banking/api/v1/resource",
    "last": "https://api.banco.com.br/open-banking/api/v1/resource"
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2021-12-16T19:19:29Z"
  }
}
accounts_endpoint_response_headers
{
  "x-fapi-interaction-id": "b5885f9f-d58d-45a1-bb84-18145e4247e3",
  "content-type": "application/json"
}
2021-12-16 19:19:29
ClearAccessTokenFromRequest
Condition ran but did not log anything
2021-12-16 19:19:29 OUTGOING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Response to HTTP request to test instance Om6erTyR3wCwg7c
outgoing_status_code
200
outgoing_headers
{
  "x-fapi-interaction-id": [
    "b5885f9f-d58d-45a1-bb84-18145e4247e3"
  ],
  "content-type": [
    "application/json"
  ]
}
outgoing_body
{
  "data": [
    {
      "brandName": "Organização A",
      "companyCnpj": "21128159000166",
      "type": "CONTA_DEPOSITO_A_VISTA",
      "compeCode": "001",
      "branchCode": "6272",
      "number": "94088392",
      "checkDigit": "4",
      "accountId": "92792126019929279212650822221989319252576"
    }
  ],
  "links": {
    "self": "https://api.banco.com.br/open-banking/api/v1/resource",
    "first": "https://api.banco.com.br/open-banking/api/v1/resource",
    "prev": "https://api.banco.com.br/open-banking/api/v1/resource",
    "next": "https://api.banco.com.br/open-banking/api/v1/resource",
    "last": "https://api.banco.com.br/open-banking/api/v1/resource"
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2021-12-16T19:19:29Z"
  }
}
outgoing_path
accounts/v1/accounts
2021-12-16 19:19:29 FINISHED
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Test has run to completion
testmodule_result
PASSED
2021-12-16 19:19:33
TEST-RUNNER
Alias has now been claimed by another test
alias
RP-Security-Test-PAN
new_test_id
AWdh0lCj4qBQ1FP
Test Results