Test Summary

Test Results

Expand All Collapse All
All times are UTC
2021-12-09 22:54:14 INFO
TEST-RUNNER
Test instance UisCUKUCH9FYlkZ created
baseUrl
https://www.certification.openid.net/test/a/geru
variant
{
  "client_auth_type": "private_key_jwt",
  "fapi_auth_request_method": "pushed",
  "fapi_profile": "openbanking_brazil",
  "fapi_jarm_type": "oidc",
  "fapi_response_mode": "plain_response"
}
alias
geru
description
Geru - Data Reception
planId
OVjcdzl04CIqt
config
{
  "alias": "geru",
  "description": "Geru - Data Reception",
  "server": {
    "jwks": {
      "keys": [
        {
          "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
          "kty": "RSA",
          "alg": "PS256",
          "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
          "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
          "e": "AQAB",
          "use": "sig",
          "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
          "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
          "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
          "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
          "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
          "x5c": [
            "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
          ]
        },
        {
          "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
          "kty": "RSA",
          "alg": "RSA-OAEP",
          "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
          "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
          "e": "AQAB",
          "use": "enc",
          "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
          "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
          "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
          "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
          "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
        }
      ]
    }
  },
  "client": {
    "client_id": "geru-bank",
    "redirect_uri": "https://scd-open-banking-frontend.dev.scd.open-co.tech",
    "jwks": {
      "keys": [
        {
          "kty": "RSA",
          "use": "sig",
          "alg": "PS256",
          "n": "vOX4NX97_AqAYJZXxyfMWtlGPfWF_4PbQspCtM-mJSSJUgFCVETgm8777NYem--3ELXNXI38oTCJzotf8AgtEf9elUU1OBVBKNVUAY2F4LrtaBEAWRLqBqr3wbE1bW0_WlOE2ak7I2IwPMJj2R-Shdu5fBLz-vwtA8cKnvsp5S1cCGtSGPoBiCyl_X0G-54UzWy81M9oVBWmnANqXWPuaaIpJwX_MEDbAf-ycTnK9YdV-RLe7CET_8cRAQvJGoYg5oH_FlfAw6fGK97wydFnf3AsAzefMru-PTbDCfTQkzE3SVPphNkvKAqle7ZR8-H5Ne58TrGWfBGnuh7clNT0ow",
          "e": "AQAB",
          "kid": "b9dde4fc8a6deec5044a994da119b73d007db30d0978f78bfb1676db4150b323"
        },
        {
          "kty": "RSA",
          "use": "enc",
          "alg": "RSA-OAEP",
          "n": "vE25NVuoSYVc5w89PVmN6m9Z8cmxcQIiK-cogtj52iqMkHswgXLCjj1Ce6AnpxPO93A-1O73SistW_6xzR4sAMn5wzBnd7ieARj1Pmj4MTa03lfoZ8M989MBCLeU1Z22OjLUaM_fVWG2MeVY2E6BO5uI_ByqFxPGpwkIWpYD3hP-qnC7KiWKnxD-L-FVVXvWQ2xc2b2u4jf7dRug3s3Bk2StkJvDdU852SxXiPPbxYdVlLsMxyN44-IcwFiDylSZ_TEkoVhEeyEQPl0JZ_uhjUCRV2gaFWynI9yDah0wGS7W8MQCBoWTGR0byAg_O4wotJw4rkLdY-JFS_JhtUBv2w",
          "e": "AQAB",
          "kid": "a269918160d0253d6f454f130ff4e03f75874d3ee53f9a49ddc854219cebad38"
        }
      ]
    },
    "certificate": "-----BEGIN CERTIFICATE-----\nMIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4\nMDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS\nRVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj\nY2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz\nODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB\nAxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00\nZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH\nMpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza\n6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf\nZ0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk\nj7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK\ntC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY\nUV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW\nBBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7\nsM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw\nLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC\nMECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls\nLm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud\nDwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU\nMIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD\nZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj\nZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z\nIHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr\nIFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp\ndHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy\ndGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE\nBggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy\nYXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514\nEpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4\nvv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF\nNzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi\n99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M\nRyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa\nHI5ipvGg/0g\u003d\n-----END CERTIFICATE-----"
  },
  "client2": {
    "client_id": "geru-bank-two",
    "redirect_uri": "https://scd-open-banking-frontend.dev.scd.open-co.tech",
    "id_token_encrypted_response_alg": "RSA-OAEP",
    "id_token_encrypted_response_enc": "A256GCM",
    "certificate": "-----BEGIN CERTIFICATE-----\nMIIG9DCCBdygAwIBAgIUY2PZxSF4TSc5rzzBRjnDjwDNVBUwDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDgwMFoXDTIyMTEwNzE4\nMDgwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS\nRVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj\nY2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz\nODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB\nAxMCQlIxNDAyBgoJkiaJk/IsZAEBEyRjM2ZkNzk5ZS00MDI4LTQxZjgtOTk1NC0z\nYzhhMzQyMzJjMjUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHNeCm\nS535la4jF2UuZGDv/WnfXP3ar8R73wHbUov59Gq2IYlnno3vqqNkQgmpPlTsP3Pr\nkNnehWZGmAk/S3beZZge9Q9/VHwgTbMYDxjXh2X447sIlcFgp7b0wEAJpcPzGzI6\nvMttZDS169VVPKNzAsF89qxtQjQhRRvsW9lD9yhPOLSAmPvKUkSf32lg5LLPs0HW\n5S40voyXSceGCI/P2HI6ruT4BWaqOY3z98C1DxWxtjjRMEy5qE7rhLcfSxhTfEdi\nUPJ4FU04n362NgOtQvosHeB8Cc+eQwg8rYqUY52HeuHuSnjkcJTYYIKSqebe2Pr3\ngZ/XbaLmhJd43lsjAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW\nBBR4qGDmpafIhhqC+zzAydgS0xaIzDAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7\nsM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw\nLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC\nMECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls\nLm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud\nDwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU\nMIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD\nZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj\nZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z\nIHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr\nIFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp\ndHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy\ndGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE\nBggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy\nYXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBANx0iEPMKOpj\n7SngTy/DDI9s8rgX3W8GjN3ZZaDFgMfCYbLq3buLDoqFrX4BIewVocnRZAnl001O\n37uzLc4Q0lhr2YNjwZDB6Oq+s/waNJ8LKjGQMKlNXLgx9sCag8PRk+36SKWZ/R1G\nqq4bLQUWYWdwcyvN3WCVHtUakBciVcoSVLClf5ZoEGlVQqNKXIUgvivzdgVKXDXK\naEQ14uOinFOuPDdqLAXzD2IDALN74xnrGnT9Q6aL5xWxo/KRxwGgDc++SU20uW3r\nAgH/qbMDpfcEXJlAeqbe6QImKpMF8jBCIiYGWnlzDCi0plhl7pvE5+P7FywjRnYy\nEz2A6GQHxs4\u003d\n-----END CERTIFICATE-----",
    "jwks": {
      "keys": [
        {
          "kty": "RSA",
          "use": "sig",
          "alg": "PS256",
          "n": "uIl9xTeOhvb9r7wf8B0tRSIWTNgIISepevXXaV78ozO_AJCsMpUQSqt6cET9_3EAb9JPtSDJUtOX0UaI6b4VMAeeq78v_vVlRTX61sxhuNIb5wXIct_jxUs7nIPJfvmJ3PEdhKC4QTOmavoSN84rRS_yYiLeXTnhvuv0JJ75Ik6NgJNDyGjzxTYaXBXXQKq-ZvM38718S_zu7kcoFZJwKRaCoadoZ3V83-MizdKlRnoRzC7q8bfSc9WYt3KPl4ZSVMxi_151h9_T7M5TEvUcKhjRh3SCGGJZoSqvxgGoknXQ_58Njbm-EjSVSDWQMIvifvLAwNj5z_gwU2vsYe770w",
          "e": "AQAB",
          "kid": "c3e45db3743a0d5065b2ad404932ab9bb4a592a00966dfd3dc8f1c74309a9e71"
        },
        {
          "kty": "RSA",
          "use": "enc",
          "alg": "RSA-OAEP",
          "n": "tYG8Tx175zj9e0uCyFZ9tkPnd-wLwxVHJ2v6mTDFGkci9hx9as9DXFKUaGJ_OfPQDx-5csyKN_eCyJCcrxOoZPv1YDtCvgL1ZXUC7nfb9sNl7d2OmRapottNVfLJYAguFWF2vP6ZD0uOwaUxs6FHGl0smljSd3EUgGgdUnxWxiFfYumnc89gvz20imG8qDFg0-h8X2VMTqR2CPbjFa_YZiHO2i5tUuAw7QohqFBSs9xoicImI19OsxXZO2qocVdtGBuvTEx-7z4g0WfM6A3fJ5IHWeIL3pVPRVOW1YqlQIWqcRU9TDYuWxCbB_PYiTYC_95yTDTrHcV-rePpETA1Pw",
          "e": "AQAB",
          "kid": "7c7247aebd7543255e1ad5168cfc34843ce6a4f3e9b8644c87e13fb834c76606"
        }
      ]
    }
  },
  "directory": {
    "keystore": "https://keystore.sandbox.directory.openbankingbrasil.org.br/"
  }
}
testName
fapi1-advanced-final-client-refresh-token-test
2021-12-09 22:54:14 SUCCESS
FAPIBrazilGenerateServerConfiguration
Created server configuration
server
{
  "issuer": "https://www.certification.openid.net/test/a/geru/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/geru/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/geru/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/geru/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/geru/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/geru/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true
}
issuer
https://www.certification.openid.net/test/a/geru/
discoveryUrl
https://www.certification.openid.net/test/a/geru/.well-known/openid-configuration
2021-12-09 22:54:14 SUCCESS
LoadServerJWKs
Parsed public and private JWK sets
server_jwks
{
  "keys": [
    {
      "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
      "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
      "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
      "kty": "RSA",
      "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
      "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
      "alg": "PS256"
    },
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
server_encryption_keys
{
  "keys": [
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
server_public_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "alg": "PS256",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "alg": "RSA-OAEP",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
2021-12-09 22:54:14 SUCCESS
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2021-12-09 22:54:14
SetServerSigningAlgToPS256
Successfully set signing algorithm to PS256
2021-12-09 22:54:14
FAPIBrazilSetGrantTypesSupportedInServerConfiguration
Successfully set grant_types_supported
server
{
  "issuer": "https://www.certification.openid.net/test/a/geru/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/geru/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/geru/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/geru/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/geru/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/geru/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ]
}
2021-12-09 22:54:14
AddClaimsParameterSupportedTrueToServerConfiguration
Successfully added claims_parameter_supported to server configuration
server
{
  "issuer": "https://www.certification.openid.net/test/a/geru/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/geru/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/geru/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/geru/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/geru/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/geru/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true
}
2021-12-09 22:54:14
FAPIBrazilAddBrazilSpecificSettingsToServerConfiguration
Added open banking Brazil specific server settings
server
{
  "issuer": "https://www.certification.openid.net/test/a/geru/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/geru/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/geru/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/geru/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/geru/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/geru/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ]
}
2021-12-09 22:54:14
SetTokenEndpointAuthMethodsSupportedToPrivateKeyJWTOnly
Changed token_endpoint_auth_methods_supported to private_key_jwt only in server configuration
server_configuration
{
  "issuer": "https://www.certification.openid.net/test/a/geru/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/geru/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/geru/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/geru/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/geru/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/geru/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ]
}
2021-12-09 22:54:14
AddPushedAuthorizationRequestEndpointToServerConfig
Added pushed_authorization_request_endpoint to server configuration
endpoint
https://www.certification.openid.net/test/a/geru/par
2021-12-09 22:54:14
AddRequirePushedAuthorizationRequestsToServerConfig
Added require_pushed_authorization_requests to server configuration
value
true
2021-12-09 22:54:14 SUCCESS
AddResponseTypeCodeIdTokenToServerConfiguration
Added code id_token as response type supported
response_types_supported
[
  "code id_token"
]
2021-12-09 22:54:14 SUCCESS
FAPIBrazilAddTokenEndpointAuthSigningAlgValuesSupportedToServer
Set token_endpoint_auth_signing_alg_values_supported
values
[
  "PS256"
]
2021-12-09 22:54:14 SUCCESS
CheckServerConfiguration
Found required server configuration keys
required
[
  "authorization_endpoint",
  "token_endpoint",
  "issuer"
]
2021-12-09 22:54:14 SUCCESS
FAPIEnsureMinimumServerKeyLength
Validated minimum key lengths for server_jwks
server_jwks
{
  "keys": [
    {
      "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
      "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
      "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
      "kty": "RSA",
      "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
      "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
      "alg": "PS256"
    },
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
2021-12-09 22:54:14 SUCCESS
LoadUserInfo
Added user information
user_info
{
  "sub": "user-subject-1234531",
  "name": "Demo T. User",
  "email": "user@example.com",
  "email_verified": false
}
Verify configuration of first client
2021-12-09 22:54:14 SUCCESS
GetStaticClientConfiguration
Found a static client object
client_id
geru-bank
redirect_uri
https://scd-open-banking-frontend.dev.scd.open-co.tech
jwks
{
  "keys": [
    {
      "kty": "RSA",
      "use": "sig",
      "alg": "PS256",
      "n": "vOX4NX97_AqAYJZXxyfMWtlGPfWF_4PbQspCtM-mJSSJUgFCVETgm8777NYem--3ELXNXI38oTCJzotf8AgtEf9elUU1OBVBKNVUAY2F4LrtaBEAWRLqBqr3wbE1bW0_WlOE2ak7I2IwPMJj2R-Shdu5fBLz-vwtA8cKnvsp5S1cCGtSGPoBiCyl_X0G-54UzWy81M9oVBWmnANqXWPuaaIpJwX_MEDbAf-ycTnK9YdV-RLe7CET_8cRAQvJGoYg5oH_FlfAw6fGK97wydFnf3AsAzefMru-PTbDCfTQkzE3SVPphNkvKAqle7ZR8-H5Ne58TrGWfBGnuh7clNT0ow",
      "e": "AQAB",
      "kid": "b9dde4fc8a6deec5044a994da119b73d007db30d0978f78bfb1676db4150b323"
    },
    {
      "kty": "RSA",
      "use": "enc",
      "alg": "RSA-OAEP",
      "n": "vE25NVuoSYVc5w89PVmN6m9Z8cmxcQIiK-cogtj52iqMkHswgXLCjj1Ce6AnpxPO93A-1O73SistW_6xzR4sAMn5wzBnd7ieARj1Pmj4MTa03lfoZ8M989MBCLeU1Z22OjLUaM_fVWG2MeVY2E6BO5uI_ByqFxPGpwkIWpYD3hP-qnC7KiWKnxD-L-FVVXvWQ2xc2b2u4jf7dRug3s3Bk2StkJvDdU852SxXiPPbxYdVlLsMxyN44-IcwFiDylSZ_TEkoVhEeyEQPl0JZ_uhjUCRV2gaFWynI9yDah0wGS7W8MQCBoWTGR0byAg_O4wotJw4rkLdY-JFS_JhtUBv2w",
      "e": "AQAB",
      "kid": "a269918160d0253d6f454f130ff4e03f75874d3ee53f9a49ddc854219cebad38"
    }
  ]
}
certificate
-----BEGIN CERTIFICATE-----
MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4
MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS
RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj
Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz
ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB
AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00
ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH
MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza
6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf
Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk
j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK
tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY
UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW
BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7
sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw
LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC
MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls
Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud
DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU
MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD
ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj
ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z
IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr
IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp
dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy
dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE
BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy
YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514
EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4
vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF
NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi
99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M
RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa
HI5ipvGg/0g=
-----END CERTIFICATE-----
2021-12-09 22:54:14 SUCCESS
ValidateClientJWKsPublicPart
Valid client JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2021-12-09 22:54:14 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "use": "sig",
      "alg": "PS256",
      "n": "vOX4NX97_AqAYJZXxyfMWtlGPfWF_4PbQspCtM-mJSSJUgFCVETgm8777NYem--3ELXNXI38oTCJzotf8AgtEf9elUU1OBVBKNVUAY2F4LrtaBEAWRLqBqr3wbE1bW0_WlOE2ak7I2IwPMJj2R-Shdu5fBLz-vwtA8cKnvsp5S1cCGtSGPoBiCyl_X0G-54UzWy81M9oVBWmnANqXWPuaaIpJwX_MEDbAf-ycTnK9YdV-RLe7CET_8cRAQvJGoYg5oH_FlfAw6fGK97wydFnf3AsAzefMru-PTbDCfTQkzE3SVPphNkvKAqle7ZR8-H5Ne58TrGWfBGnuh7clNT0ow",
      "e": "AQAB",
      "kid": "b9dde4fc8a6deec5044a994da119b73d007db30d0978f78bfb1676db4150b323"
    },
    {
      "kty": "RSA",
      "use": "enc",
      "alg": "RSA-OAEP",
      "n": "vE25NVuoSYVc5w89PVmN6m9Z8cmxcQIiK-cogtj52iqMkHswgXLCjj1Ce6AnpxPO93A-1O73SistW_6xzR4sAMn5wzBnd7ieARj1Pmj4MTa03lfoZ8M989MBCLeU1Z22OjLUaM_fVWG2MeVY2E6BO5uI_ByqFxPGpwkIWpYD3hP-qnC7KiWKnxD-L-FVVXvWQ2xc2b2u4jf7dRug3s3Bk2StkJvDdU852SxXiPPbxYdVlLsMxyN44-IcwFiDylSZ_TEkoVhEeyEQPl0JZ_uhjUCRV2gaFWynI9yDah0wGS7W8MQCBoWTGR0byAg_O4wotJw4rkLdY-JFS_JhtUBv2w",
      "e": "AQAB",
      "kid": "a269918160d0253d6f454f130ff4e03f75874d3ee53f9a49ddc854219cebad38"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "b9dde4fc8a6deec5044a994da119b73d007db30d0978f78bfb1676db4150b323",
      "alg": "PS256",
      "n": "vOX4NX97_AqAYJZXxyfMWtlGPfWF_4PbQspCtM-mJSSJUgFCVETgm8777NYem--3ELXNXI38oTCJzotf8AgtEf9elUU1OBVBKNVUAY2F4LrtaBEAWRLqBqr3wbE1bW0_WlOE2ak7I2IwPMJj2R-Shdu5fBLz-vwtA8cKnvsp5S1cCGtSGPoBiCyl_X0G-54UzWy81M9oVBWmnANqXWPuaaIpJwX_MEDbAf-ycTnK9YdV-RLe7CET_8cRAQvJGoYg5oH_FlfAw6fGK97wydFnf3AsAzefMru-PTbDCfTQkzE3SVPphNkvKAqle7ZR8-H5Ne58TrGWfBGnuh7clNT0ow"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "a269918160d0253d6f454f130ff4e03f75874d3ee53f9a49ddc854219cebad38",
      "alg": "RSA-OAEP",
      "n": "vE25NVuoSYVc5w89PVmN6m9Z8cmxcQIiK-cogtj52iqMkHswgXLCjj1Ce6AnpxPO93A-1O73SistW_6xzR4sAMn5wzBnd7ieARj1Pmj4MTa03lfoZ8M989MBCLeU1Z22OjLUaM_fVWG2MeVY2E6BO5uI_ByqFxPGpwkIWpYD3hP-qnC7KiWKnxD-L-FVVXvWQ2xc2b2u4jf7dRug3s3Bk2StkJvDdU852SxXiPPbxYdVlLsMxyN44-IcwFiDylSZ_TEkoVhEeyEQPl0JZ_uhjUCRV2gaFWynI9yDah0wGS7W8MQCBoWTGR0byAg_O4wotJw4rkLdY-JFS_JhtUBv2w"
    }
  ]
}
2021-12-09 22:54:14 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2021-12-09 22:54:14 SUCCESS
EnsureClientJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2021-12-09 22:54:14 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "use": "sig",
      "alg": "PS256",
      "n": "vOX4NX97_AqAYJZXxyfMWtlGPfWF_4PbQspCtM-mJSSJUgFCVETgm8777NYem--3ELXNXI38oTCJzotf8AgtEf9elUU1OBVBKNVUAY2F4LrtaBEAWRLqBqr3wbE1bW0_WlOE2ak7I2IwPMJj2R-Shdu5fBLz-vwtA8cKnvsp5S1cCGtSGPoBiCyl_X0G-54UzWy81M9oVBWmnANqXWPuaaIpJwX_MEDbAf-ycTnK9YdV-RLe7CET_8cRAQvJGoYg5oH_FlfAw6fGK97wydFnf3AsAzefMru-PTbDCfTQkzE3SVPphNkvKAqle7ZR8-H5Ne58TrGWfBGnuh7clNT0ow",
      "e": "AQAB",
      "kid": "b9dde4fc8a6deec5044a994da119b73d007db30d0978f78bfb1676db4150b323"
    },
    {
      "kty": "RSA",
      "use": "enc",
      "alg": "RSA-OAEP",
      "n": "vE25NVuoSYVc5w89PVmN6m9Z8cmxcQIiK-cogtj52iqMkHswgXLCjj1Ce6AnpxPO93A-1O73SistW_6xzR4sAMn5wzBnd7ieARj1Pmj4MTa03lfoZ8M989MBCLeU1Z22OjLUaM_fVWG2MeVY2E6BO5uI_ByqFxPGpwkIWpYD3hP-qnC7KiWKnxD-L-FVVXvWQ2xc2b2u4jf7dRug3s3Bk2StkJvDdU852SxXiPPbxYdVlLsMxyN44-IcwFiDylSZ_TEkoVhEeyEQPl0JZ_uhjUCRV2gaFWynI9yDah0wGS7W8MQCBoWTGR0byAg_O4wotJw4rkLdY-JFS_JhtUBv2w",
      "e": "AQAB",
      "kid": "a269918160d0253d6f454f130ff4e03f75874d3ee53f9a49ddc854219cebad38"
    }
  ]
}
Verify configuration of second client
2021-12-09 22:54:14 SUCCESS
GetStaticClient2Configuration
Found a static second client object
client_id
geru-bank-two
redirect_uri
https://scd-open-banking-frontend.dev.scd.open-co.tech
id_token_encrypted_response_alg
RSA-OAEP
id_token_encrypted_response_enc
A256GCM
certificate
-----BEGIN CERTIFICATE-----
MIIG9DCCBdygAwIBAgIUY2PZxSF4TSc5rzzBRjnDjwDNVBUwDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDgwMFoXDTIyMTEwNzE4
MDgwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS
RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj
Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz
ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB
AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyRjM2ZkNzk5ZS00MDI4LTQxZjgtOTk1NC0z
YzhhMzQyMzJjMjUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHNeCm
S535la4jF2UuZGDv/WnfXP3ar8R73wHbUov59Gq2IYlnno3vqqNkQgmpPlTsP3Pr
kNnehWZGmAk/S3beZZge9Q9/VHwgTbMYDxjXh2X447sIlcFgp7b0wEAJpcPzGzI6
vMttZDS169VVPKNzAsF89qxtQjQhRRvsW9lD9yhPOLSAmPvKUkSf32lg5LLPs0HW
5S40voyXSceGCI/P2HI6ruT4BWaqOY3z98C1DxWxtjjRMEy5qE7rhLcfSxhTfEdi
UPJ4FU04n362NgOtQvosHeB8Cc+eQwg8rYqUY52HeuHuSnjkcJTYYIKSqebe2Pr3
gZ/XbaLmhJd43lsjAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW
BBR4qGDmpafIhhqC+zzAydgS0xaIzDAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7
sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw
LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC
MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls
Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud
DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU
MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD
ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj
ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z
IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr
IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp
dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy
dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE
BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy
YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBANx0iEPMKOpj
7SngTy/DDI9s8rgX3W8GjN3ZZaDFgMfCYbLq3buLDoqFrX4BIewVocnRZAnl001O
37uzLc4Q0lhr2YNjwZDB6Oq+s/waNJ8LKjGQMKlNXLgx9sCag8PRk+36SKWZ/R1G
qq4bLQUWYWdwcyvN3WCVHtUakBciVcoSVLClf5ZoEGlVQqNKXIUgvivzdgVKXDXK
aEQ14uOinFOuPDdqLAXzD2IDALN74xnrGnT9Q6aL5xWxo/KRxwGgDc++SU20uW3r
AgH/qbMDpfcEXJlAeqbe6QImKpMF8jBCIiYGWnlzDCi0plhl7pvE5+P7FywjRnYy
Ez2A6GQHxs4=
-----END CERTIFICATE-----
jwks
{
  "keys": [
    {
      "kty": "RSA",
      "use": "sig",
      "alg": "PS256",
      "n": "uIl9xTeOhvb9r7wf8B0tRSIWTNgIISepevXXaV78ozO_AJCsMpUQSqt6cET9_3EAb9JPtSDJUtOX0UaI6b4VMAeeq78v_vVlRTX61sxhuNIb5wXIct_jxUs7nIPJfvmJ3PEdhKC4QTOmavoSN84rRS_yYiLeXTnhvuv0JJ75Ik6NgJNDyGjzxTYaXBXXQKq-ZvM38718S_zu7kcoFZJwKRaCoadoZ3V83-MizdKlRnoRzC7q8bfSc9WYt3KPl4ZSVMxi_151h9_T7M5TEvUcKhjRh3SCGGJZoSqvxgGoknXQ_58Njbm-EjSVSDWQMIvifvLAwNj5z_gwU2vsYe770w",
      "e": "AQAB",
      "kid": "c3e45db3743a0d5065b2ad404932ab9bb4a592a00966dfd3dc8f1c74309a9e71"
    },
    {
      "kty": "RSA",
      "use": "enc",
      "alg": "RSA-OAEP",
      "n": "tYG8Tx175zj9e0uCyFZ9tkPnd-wLwxVHJ2v6mTDFGkci9hx9as9DXFKUaGJ_OfPQDx-5csyKN_eCyJCcrxOoZPv1YDtCvgL1ZXUC7nfb9sNl7d2OmRapottNVfLJYAguFWF2vP6ZD0uOwaUxs6FHGl0smljSd3EUgGgdUnxWxiFfYumnc89gvz20imG8qDFg0-h8X2VMTqR2CPbjFa_YZiHO2i5tUuAw7QohqFBSs9xoicImI19OsxXZO2qocVdtGBuvTEx-7z4g0WfM6A3fJ5IHWeIL3pVPRVOW1YqlQIWqcRU9TDYuWxCbB_PYiTYC_95yTDTrHcV-rePpETA1Pw",
      "e": "AQAB",
      "kid": "7c7247aebd7543255e1ad5168cfc34843ce6a4f3e9b8644c87e13fb834c76606"
    }
  ]
}
2021-12-09 22:54:14 SUCCESS
ValidateClientJWKsPublicPart
Valid client JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2021-12-09 22:54:14 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "use": "sig",
      "alg": "PS256",
      "n": "uIl9xTeOhvb9r7wf8B0tRSIWTNgIISepevXXaV78ozO_AJCsMpUQSqt6cET9_3EAb9JPtSDJUtOX0UaI6b4VMAeeq78v_vVlRTX61sxhuNIb5wXIct_jxUs7nIPJfvmJ3PEdhKC4QTOmavoSN84rRS_yYiLeXTnhvuv0JJ75Ik6NgJNDyGjzxTYaXBXXQKq-ZvM38718S_zu7kcoFZJwKRaCoadoZ3V83-MizdKlRnoRzC7q8bfSc9WYt3KPl4ZSVMxi_151h9_T7M5TEvUcKhjRh3SCGGJZoSqvxgGoknXQ_58Njbm-EjSVSDWQMIvifvLAwNj5z_gwU2vsYe770w",
      "e": "AQAB",
      "kid": "c3e45db3743a0d5065b2ad404932ab9bb4a592a00966dfd3dc8f1c74309a9e71"
    },
    {
      "kty": "RSA",
      "use": "enc",
      "alg": "RSA-OAEP",
      "n": "tYG8Tx175zj9e0uCyFZ9tkPnd-wLwxVHJ2v6mTDFGkci9hx9as9DXFKUaGJ_OfPQDx-5csyKN_eCyJCcrxOoZPv1YDtCvgL1ZXUC7nfb9sNl7d2OmRapottNVfLJYAguFWF2vP6ZD0uOwaUxs6FHGl0smljSd3EUgGgdUnxWxiFfYumnc89gvz20imG8qDFg0-h8X2VMTqR2CPbjFa_YZiHO2i5tUuAw7QohqFBSs9xoicImI19OsxXZO2qocVdtGBuvTEx-7z4g0WfM6A3fJ5IHWeIL3pVPRVOW1YqlQIWqcRU9TDYuWxCbB_PYiTYC_95yTDTrHcV-rePpETA1Pw",
      "e": "AQAB",
      "kid": "7c7247aebd7543255e1ad5168cfc34843ce6a4f3e9b8644c87e13fb834c76606"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "c3e45db3743a0d5065b2ad404932ab9bb4a592a00966dfd3dc8f1c74309a9e71",
      "alg": "PS256",
      "n": "uIl9xTeOhvb9r7wf8B0tRSIWTNgIISepevXXaV78ozO_AJCsMpUQSqt6cET9_3EAb9JPtSDJUtOX0UaI6b4VMAeeq78v_vVlRTX61sxhuNIb5wXIct_jxUs7nIPJfvmJ3PEdhKC4QTOmavoSN84rRS_yYiLeXTnhvuv0JJ75Ik6NgJNDyGjzxTYaXBXXQKq-ZvM38718S_zu7kcoFZJwKRaCoadoZ3V83-MizdKlRnoRzC7q8bfSc9WYt3KPl4ZSVMxi_151h9_T7M5TEvUcKhjRh3SCGGJZoSqvxgGoknXQ_58Njbm-EjSVSDWQMIvifvLAwNj5z_gwU2vsYe770w"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "7c7247aebd7543255e1ad5168cfc34843ce6a4f3e9b8644c87e13fb834c76606",
      "alg": "RSA-OAEP",
      "n": "tYG8Tx175zj9e0uCyFZ9tkPnd-wLwxVHJ2v6mTDFGkci9hx9as9DXFKUaGJ_OfPQDx-5csyKN_eCyJCcrxOoZPv1YDtCvgL1ZXUC7nfb9sNl7d2OmRapottNVfLJYAguFWF2vP6ZD0uOwaUxs6FHGl0smljSd3EUgGgdUnxWxiFfYumnc89gvz20imG8qDFg0-h8X2VMTqR2CPbjFa_YZiHO2i5tUuAw7QohqFBSs9xoicImI19OsxXZO2qocVdtGBuvTEx-7z4g0WfM6A3fJ5IHWeIL3pVPRVOW1YqlQIWqcRU9TDYuWxCbB_PYiTYC_95yTDTrHcV-rePpETA1Pw"
    }
  ]
}
2021-12-09 22:54:14 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2021-12-09 22:54:14 SUCCESS
EnsureClientJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2021-12-09 22:54:14 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "use": "sig",
      "alg": "PS256",
      "n": "uIl9xTeOhvb9r7wf8B0tRSIWTNgIISepevXXaV78ozO_AJCsMpUQSqt6cET9_3EAb9JPtSDJUtOX0UaI6b4VMAeeq78v_vVlRTX61sxhuNIb5wXIct_jxUs7nIPJfvmJ3PEdhKC4QTOmavoSN84rRS_yYiLeXTnhvuv0JJ75Ik6NgJNDyGjzxTYaXBXXQKq-ZvM38718S_zu7kcoFZJwKRaCoadoZ3V83-MizdKlRnoRzC7q8bfSc9WYt3KPl4ZSVMxi_151h9_T7M5TEvUcKhjRh3SCGGJZoSqvxgGoknXQ_58Njbm-EjSVSDWQMIvifvLAwNj5z_gwU2vsYe770w",
      "e": "AQAB",
      "kid": "c3e45db3743a0d5065b2ad404932ab9bb4a592a00966dfd3dc8f1c74309a9e71"
    },
    {
      "kty": "RSA",
      "use": "enc",
      "alg": "RSA-OAEP",
      "n": "tYG8Tx175zj9e0uCyFZ9tkPnd-wLwxVHJ2v6mTDFGkci9hx9as9DXFKUaGJ_OfPQDx-5csyKN_eCyJCcrxOoZPv1YDtCvgL1ZXUC7nfb9sNl7d2OmRapottNVfLJYAguFWF2vP6ZD0uOwaUxs6FHGl0smljSd3EUgGgdUnxWxiFfYumnc89gvz20imG8qDFg0-h8X2VMTqR2CPbjFa_YZiHO2i5tUuAw7QohqFBSs9xoicImI19OsxXZO2qocVdtGBuvTEx-7z4g0WfM6A3fJ5IHWeIL3pVPRVOW1YqlQIWqcRU9TDYuWxCbB_PYiTYC_95yTDTrHcV-rePpETA1Pw",
      "e": "AQAB",
      "kid": "7c7247aebd7543255e1ad5168cfc34843ce6a4f3e9b8644c87e13fb834c76606"
    }
  ]
}
2021-12-09 22:54:14
fapi1-advanced-final-client-refresh-token-test
Setup Done
2021-12-09 22:54:16 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance UisCUKUCH9FYlkZ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.7.4 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/geru/.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-09 22:54:16 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-09 22:54:16 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance UisCUKUCH9FYlkZ
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/geru/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/geru/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/geru/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/geru/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/geru/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/geru/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/userinfo",
    "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/par"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ],
  "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test/a/geru/par",
  "require_pushed_authorization_requests": true,
  "response_types_supported": [
    "code id_token"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256"
  ]
}
outgoing_path
.well-known/openid-configuration
2021-12-09 22:54:16 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance UisCUKUCH9FYlkZ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.7.4 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded",
  "accept-encoding": "gzip, deflate, br",
  "content-length": "1050",
  "connection": "close"
}
incoming_path
/test-mtls/a/geru/token
incoming_body_form_params
{
  "grant_type": "client_credentials",
  "scope": "consents",
  "client_id": "geru-bank",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImI5ZGRlNGZjOGE2ZGVlYzUwNDRhOTk0ZGExMTliNzNkMDA3ZGIzMGQwOTc4Zjc4YmZiMTY3NmRiNDE1MGIzMjMifQ.eyJpYXQiOjE2MzkwOTA0NTYsImV4cCI6MTYzOTA5MDUxNiwianRpIjoiWTd2WnFNc0dKckw2akptX1I5cS1kcnc3T3U5Wks5Y3RyTndzenVmR1BOVSIsImlzcyI6ImdlcnUtYmFuayIsInN1YiI6ImdlcnUtYmFuayIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL2dlcnUvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9nZXJ1L3Rva2VuIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL2dlcnUvdG9rZW4iXX0.PAIHWkYZajoCnpo7lawPOwLgTxhGFExXy0kaxU3EDuA1XTNksudLUaRaWTNhZx8ofDdEStPN_rn3AWtdm06sxWg-EcUSvj_xt874NfLdZQxMn_vhmgIKg7uYeW6hp8MCzv3uuBy1ovmQmgP3VMAUdTOmjZQ5CMa1MFjTo7CSfciaAWeMhlUchTJDbvVJLJ0W4U254Ypwd_vViKskr1NN57uNsHTT1XJ4jn03jc2YjSxbCY87W395qhc9YJyEY4Uh2BZWSGF8Z3wzp6PU3R0LCN9mUJAwZUO5lGXjJpOwdlC5fY8Vud-0iL6_HB5y7mSURl0OIwXvj8ylaxFqOejDjg",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4 MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00 ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza 6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7 sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514 EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4 vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi 99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa HI5ipvGg/0g= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
grant_type=client_credentials&scope=consents&client_id=geru-bank&client_assertion=eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImI5ZGRlNGZjOGE2ZGVlYzUwNDRhOTk0ZGExMTliNzNkMDA3ZGIzMGQwOTc4Zjc4YmZiMTY3NmRiNDE1MGIzMjMifQ.eyJpYXQiOjE2MzkwOTA0NTYsImV4cCI6MTYzOTA5MDUxNiwianRpIjoiWTd2WnFNc0dKckw2akptX1I5cS1kcnc3T3U5Wks5Y3RyTndzenVmR1BOVSIsImlzcyI6ImdlcnUtYmFuayIsInN1YiI6ImdlcnUtYmFuayIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL2dlcnUvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9nZXJ1L3Rva2VuIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL2dlcnUvdG9rZW4iXX0.PAIHWkYZajoCnpo7lawPOwLgTxhGFExXy0kaxU3EDuA1XTNksudLUaRaWTNhZx8ofDdEStPN_rn3AWtdm06sxWg-EcUSvj_xt874NfLdZQxMn_vhmgIKg7uYeW6hp8MCzv3uuBy1ovmQmgP3VMAUdTOmjZQ5CMa1MFjTo7CSfciaAWeMhlUchTJDbvVJLJ0W4U254Ypwd_vViKskr1NN57uNsHTT1XJ4jn03jc2YjSxbCY87W395qhc9YJyEY4Uh2BZWSGF8Z3wzp6PU3R0LCN9mUJAwZUO5lGXjJpOwdlC5fY8Vud-0iL6_HB5y7mSURl0OIwXvj8ylaxFqOejDjg&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2021-12-09 22:54:16 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2021-12-09 22:54:16 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4 MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00 ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza 6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7 sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514 EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4 vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi 99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa HI5ipvGg/0g\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4\nMDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS\nRVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj\nY2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz\nODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB\nAxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00\nZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH\nMpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza\n6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf\nZ0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk\nj7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK\ntC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY\nUV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW\nBBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7\nsM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw\nLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC\nMECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls\nLm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud\nDwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU\nMIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD\nZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj\nZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z\nIHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr\nIFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp\ndHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy\ndGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE\nBggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy\nYXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514\nEpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4\nvv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF\nNzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi\n99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M\nRyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa\nHI5ipvGg/0g\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003d73885603-f3ff-41bf-b2b2-4f7ca9fe6076,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3337373633383437303030313338,CN\u003dgeru.com.br,OU\u003d0ca05092-025f-47c4-b878-4a03c150cccf,O\u003dGERU SOCIEDADE DE CREDITO DIRETO,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "geru.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2021-12-09 22:54:16 SUCCESS
CheckForClientCertificate
Found client certificate
2021-12-09 22:54:16 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4
MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS
RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj
Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz
ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB
AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00
ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH
MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza
6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf
Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk
j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK
tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY
UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW
BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7
sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw
LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC
MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls
Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud
DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU
MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD
ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj
ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z
IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr
IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp
dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy
dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE
BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy
YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514
EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4
vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF
NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi
99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M
RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa
HI5ipvGg/0g=
-----END CERTIFICATE-----
2021-12-09 22:54:16 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImI5ZGRlNGZjOGE2ZGVlYzUwNDRhOTk0ZGExMTliNzNkMDA3ZGIzMGQwOTc4Zjc4YmZiMTY3NmRiNDE1MGIzMjMifQ.eyJpYXQiOjE2MzkwOTA0NTYsImV4cCI6MTYzOTA5MDUxNiwianRpIjoiWTd2WnFNc0dKckw2akptX1I5cS1kcnc3T3U5Wks5Y3RyTndzenVmR1BOVSIsImlzcyI6ImdlcnUtYmFuayIsInN1YiI6ImdlcnUtYmFuayIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL2dlcnUvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9nZXJ1L3Rva2VuIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL2dlcnUvdG9rZW4iXX0.PAIHWkYZajoCnpo7lawPOwLgTxhGFExXy0kaxU3EDuA1XTNksudLUaRaWTNhZx8ofDdEStPN_rn3AWtdm06sxWg-EcUSvj_xt874NfLdZQxMn_vhmgIKg7uYeW6hp8MCzv3uuBy1ovmQmgP3VMAUdTOmjZQ5CMa1MFjTo7CSfciaAWeMhlUchTJDbvVJLJ0W4U254Ypwd_vViKskr1NN57uNsHTT1XJ4jn03jc2YjSxbCY87W395qhc9YJyEY4Uh2BZWSGF8Z3wzp6PU3R0LCN9mUJAwZUO5lGXjJpOwdlC5fY8Vud-0iL6_HB5y7mSURl0OIwXvj8ylaxFqOejDjg",
  "header": {
    "kid": "b9dde4fc8a6deec5044a994da119b73d007db30d0978f78bfb1676db4150b323",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "geru-bank",
    "aud": [
      "https://www.certification.openid.net/test/a/geru/",
      "https://www.certification.openid.net/test/a/geru/token",
      "https://www.certification.openid.net/test-mtls/a/geru/token"
    ],
    "iss": "geru-bank",
    "exp": 1639090516,
    "iat": 1639090456,
    "jti": "Y7vZqMsGJrL6jJm_R9q-drw7Ou9ZK9ctrNwszufGPNU"
  }
}
2021-12-09 22:54:16
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2021-12-09 22:54:16 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImI5ZGRlNGZjOGE2ZGVlYzUwNDRhOTk0ZGExMTliNzNkMDA3ZGIzMGQwOTc4Zjc4YmZiMTY3NmRiNDE1MGIzMjMifQ.eyJpYXQiOjE2MzkwOTA0NTYsImV4cCI6MTYzOTA5MDUxNiwianRpIjoiWTd2WnFNc0dKckw2akptX1I5cS1kcnc3T3U5Wks5Y3RyTndzenVmR1BOVSIsImlzcyI6ImdlcnUtYmFuayIsInN1YiI6ImdlcnUtYmFuayIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL2dlcnUvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9nZXJ1L3Rva2VuIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL2dlcnUvdG9rZW4iXX0.PAIHWkYZajoCnpo7lawPOwLgTxhGFExXy0kaxU3EDuA1XTNksudLUaRaWTNhZx8ofDdEStPN_rn3AWtdm06sxWg-EcUSvj_xt874NfLdZQxMn_vhmgIKg7uYeW6hp8MCzv3uuBy1ovmQmgP3VMAUdTOmjZQ5CMa1MFjTo7CSfciaAWeMhlUchTJDbvVJLJ0W4U254Ypwd_vViKskr1NN57uNsHTT1XJ4jn03jc2YjSxbCY87W395qhc9YJyEY4Uh2BZWSGF8Z3wzp6PU3R0LCN9mUJAwZUO5lGXjJpOwdlC5fY8Vud-0iL6_HB5y7mSURl0OIwXvj8ylaxFqOejDjg
2021-12-09 22:54:16 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-12-09 22:54:16 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2021-12-09 22:54:16 SUCCESS
FAPIBrazilExtractRequestedScopeFromClientCredentialsGrant
Found 'consents' scope in request
actual
[
  "consents"
]
expected
consents
2021-12-09 22:54:16 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
DJcBMO5Yvqz1s7M45l4rmcNY1i82rlhz7nyaQpf9wYvEO4KEl6
2021-12-09 22:54:16 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
DJcBMO5Yvqz1s7M45l4rmcNY1i82rlhz7nyaQpf9wYvEO4KEl6
token_type
Bearer
2021-12-09 22:54:16
CopyAccessTokenToClientCredentialsField
Condition ran but did not log anything
2021-12-09 22:54:16 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance UisCUKUCH9FYlkZ
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "DJcBMO5Yvqz1s7M45l4rmcNY1i82rlhz7nyaQpf9wYvEO4KEl6",
  "token_type": "Bearer"
}
outgoing_path
token
2021-12-09 22:54:16 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance UisCUKUCH9FYlkZ
incoming_headers
{
  "host": "www.certification.openid.net",
  "accept": "application/json, text/plain, */*",
  "content-type": "application/json",
  "authorization": "Bearer DJcBMO5Yvqz1s7M45l4rmcNY1i82rlhz7nyaQpf9wYvEO4KEl6",
  "user-agent": "axios/0.21.1",
  "content-length": "1174",
  "connection": "close"
}
incoming_path
/test-mtls/a/geru/consents/v1/consents
incoming_body_form_params
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4 MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00 ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza 6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7 sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514 EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4 vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi 99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa HI5ipvGg/0g= -----END CERTIFICATE-----
incoming_body_json
{
  "data": {
    "loggedUser": {
      "document": {
        "identification": "57784518064",
        "rel": "CPF"
      }
    },
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_OVERDRAFT_LIMITS_READ",
      "ACCOUNTS_BALANCES_READ",
      "ACCOUNTS_TRANSACTIONS_READ",
      "CREDIT_CARDS_ACCOUNTS_BILLS_READ",
      "CREDIT_CARDS_ACCOUNTS_BILLS_TRANSACTIONS_READ",
      "CREDIT_CARDS_ACCOUNTS_LIMITS_READ",
      "CREDIT_CARDS_ACCOUNTS_READ",
      "CREDIT_CARDS_ACCOUNTS_TRANSACTIONS_READ",
      "CUSTOMERS_PERSONAL_ADITTIONALINFO_READ",
      "CUSTOMERS_PERSONAL_IDENTIFICATIONS_READ",
      "LOANS_READ",
      "LOANS_WARRANTIES_READ",
      "LOANS_SCHEDULED_INSTALMENTS_READ",
      "LOANS_PAYMENTS_READ",
      "FINANCINGS_READ",
      "FINANCINGS_WARRANTIES_READ",
      "FINANCINGS_SCHEDULED_INSTALMENTS_READ",
      "FINANCINGS_PAYMENTS_READ",
      "UNARRANGED_ACCOUNTS_OVERDRAFT_READ",
      "UNARRANGED_ACCOUNTS_OVERDRAFT_WARRANTIES_READ",
      "UNARRANGED_ACCOUNTS_OVERDRAFT_SCHEDULED_INSTALMENTS_READ",
      "UNARRANGED_ACCOUNTS_OVERDRAFT_PAYMENTS_READ",
      "INVOICE_FINANCINGS_READ",
      "INVOICE_FINANCINGS_WARRANTIES_READ",
      "INVOICE_FINANCINGS_SCHEDULED_INSTALMENTS_READ",
      "INVOICE_FINANCINGS_PAYMENTS_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2021-12-31T00:00:00Z",
    "transactionFromDateTime": "2021-08-10T00:00:00Z",
    "transactionToDateTime": "2021-12-31T23:59:59Z"
  }
}
incoming_query_string_params
{}
incoming_body
{"data":{"loggedUser":{"document":{"identification":"57784518064","rel":"CPF"}},"permissions":["ACCOUNTS_READ","ACCOUNTS_OVERDRAFT_LIMITS_READ","ACCOUNTS_BALANCES_READ","ACCOUNTS_TRANSACTIONS_READ","CREDIT_CARDS_ACCOUNTS_BILLS_READ","CREDIT_CARDS_ACCOUNTS_BILLS_TRANSACTIONS_READ","CREDIT_CARDS_ACCOUNTS_LIMITS_READ","CREDIT_CARDS_ACCOUNTS_READ","CREDIT_CARDS_ACCOUNTS_TRANSACTIONS_READ","CUSTOMERS_PERSONAL_ADITTIONALINFO_READ","CUSTOMERS_PERSONAL_IDENTIFICATIONS_READ","LOANS_READ","LOANS_WARRANTIES_READ","LOANS_SCHEDULED_INSTALMENTS_READ","LOANS_PAYMENTS_READ","FINANCINGS_READ","FINANCINGS_WARRANTIES_READ","FINANCINGS_SCHEDULED_INSTALMENTS_READ","FINANCINGS_PAYMENTS_READ","UNARRANGED_ACCOUNTS_OVERDRAFT_READ","UNARRANGED_ACCOUNTS_OVERDRAFT_WARRANTIES_READ","UNARRANGED_ACCOUNTS_OVERDRAFT_SCHEDULED_INSTALMENTS_READ","UNARRANGED_ACCOUNTS_OVERDRAFT_PAYMENTS_READ","INVOICE_FINANCINGS_READ","INVOICE_FINANCINGS_WARRANTIES_READ","INVOICE_FINANCINGS_SCHEDULED_INSTALMENTS_READ","INVOICE_FINANCINGS_PAYMENTS_READ","RESOURCES_READ"],"expirationDateTime":"2021-12-31T00:00:00Z","transactionFromDateTime":"2021-08-10T00:00:00Z","transactionToDateTime":"2021-12-31T23:59:59Z"}}
2021-12-09 22:54:16 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
New consent endpoint
2021-12-09 22:54:16 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4 MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00 ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza 6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7 sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514 EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4 vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi 99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa HI5ipvGg/0g\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4\nMDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS\nRVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj\nY2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz\nODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB\nAxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00\nZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH\nMpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza\n6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf\nZ0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk\nj7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK\ntC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY\nUV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW\nBBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7\nsM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw\nLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC\nMECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls\nLm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud\nDwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU\nMIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD\nZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj\nZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z\nIHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr\nIFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp\ndHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy\ndGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE\nBggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy\nYXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514\nEpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4\nvv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF\nNzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi\n99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M\nRyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa\nHI5ipvGg/0g\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003d73885603-f3ff-41bf-b2b2-4f7ca9fe6076,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3337373633383437303030313338,CN\u003dgeru.com.br,OU\u003d0ca05092-025f-47c4-b878-4a03c150cccf,O\u003dGERU SOCIEDADE DE CREDITO DIRETO,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "geru.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2021-12-09 22:54:16 SUCCESS
CheckForClientCertificate
Found client certificate
2021-12-09 22:54:16 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4
MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS
RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj
Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz
ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB
AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00
ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH
MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza
6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf
Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk
j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK
tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY
UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW
BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7
sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw
LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC
MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls
Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud
DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU
MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD
ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj
ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z
IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr
IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp
dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy
dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE
BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy
YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514
EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4
vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF
NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi
99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M
RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa
HI5ipvGg/0g=
-----END CERTIFICATE-----
2021-12-09 22:54:16 SUCCESS
EnsureIncomingRequestMethodIsPost
Client correctly used http POST method
2021-12-09 22:54:16 SUCCESS
EnsureBearerAccessTokenNotInParams
Client correctly did not send access token in query parameters or form body
2021-12-09 22:54:16 SUCCESS
ExtractBearerAccessTokenFromHeader
Found access token on incoming request
access_token
DJcBMO5Yvqz1s7M45l4rmcNY1i82rlhz7nyaQpf9wYvEO4KEl6
2021-12-09 22:54:16 SUCCESS
RequireBearerClientCredentialsAccessToken
Found access token in request
actual
DJcBMO5Yvqz1s7M45l4rmcNY1i82rlhz7nyaQpf9wYvEO4KEl6
2021-12-09 22:54:16 INFO
ExtractFapiDateHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-auth-date
path
headers.x-fapi-auth-date
mapped
object
incoming_request
2021-12-09 22:54:16 INFO
ExtractFapiIpAddressHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-customer-ip-address
path
headers.x-fapi-customer-ip-address
mapped
object
incoming_request
2021-12-09 22:54:16 INFO
ExtractFapiInteractionIdHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-interaction-id
path
headers.x-fapi-interaction-id
mapped
object
incoming_request
2021-12-09 22:54:16 SUCCESS
FAPIBrazilEnsureClientCredentialsScopeContainedConsents
The token request which was used to obtain the access token contained 'consents' scope
actual
[
  "consents"
]
2021-12-09 22:54:16
FAPIBrazilExtractConsentRequest
Condition ran but did not log anything
2021-12-09 22:54:16 SUCCESS
CreateFapiInteractionIdIfNeeded
Created new FAPI interaction ID
fapi_interaction_id
e7ee8555-792e-4972-bc5e-7a820d7200db
2021-12-09 22:54:16 SUCCESS
FAPIBrazilGenerateNewConsentResponse
Created consent response
headers
{
  "x-fapi-interaction-id": "e7ee8555-792e-4972-bc5e-7a820d7200db"
}
consentId
urn:conformance.oidf:dEw82wAIdm
consent_response
{
  "data": {
    "consentId": "urn:conformance.oidf:dEw82wAIdm",
    "creationDateTime": "2021-12-09T22:54:16Z",
    "status": "AWAITING_AUTHORISATION",
    "statusUpdateDateTime": "2021-12-09T22:54:16Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2021-12-10T00:54:16Z",
    "transactionFromDateTime": "2021-12-09T22:49:16Z",
    "transactionToDateTime": "2021-12-10T00:54:16Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/geruconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2021-12-09T22:54:16Z"
  }
}
2021-12-09 22:54:16
ClearAccessTokenFromRequest
Condition ran but did not log anything
2021-12-09 22:54:16 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance UisCUKUCH9FYlkZ
outgoing_status_code
201
outgoing_headers
{
  "x-fapi-interaction-id": [
    "e7ee8555-792e-4972-bc5e-7a820d7200db"
  ]
}
outgoing_body
{
  "data": {
    "consentId": "urn:conformance.oidf:dEw82wAIdm",
    "creationDateTime": "2021-12-09T22:54:16Z",
    "status": "AWAITING_AUTHORISATION",
    "statusUpdateDateTime": "2021-12-09T22:54:16Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2021-12-10T00:54:16Z",
    "transactionFromDateTime": "2021-12-09T22:49:16Z",
    "transactionToDateTime": "2021-12-10T00:54:16Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/geruconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2021-12-09T22:54:16Z"
  }
}
outgoing_path
consents/v1/consents
2021-12-09 22:54:16 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance UisCUKUCH9FYlkZ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.7.4 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/geru/jwks
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-09 22:54:16 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-09 22:54:16 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance UisCUKUCH9FYlkZ
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "alg": "PS256",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "alg": "RSA-OAEP",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
outgoing_path
jwks
2021-12-09 22:54:16 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance UisCUKUCH9FYlkZ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.7.4 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded",
  "accept-encoding": "gzip, deflate, br",
  "content-length": "3463",
  "connection": "close"
}
incoming_path
/test-mtls/a/geru/par
incoming_body_form_params
{
  "request": "eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZHQ00iLCJjdHkiOiJvYXV0aC1hdXRoei1yZXErand0Iiwia2lkIjoiMGZlNTAyZGQtMTRmMC00ZjQ1LTgwZjktZmViOWEyMTZmOTk2In0.qrO96hYl_j7Dap6CpNb_0UmyyMXVuCibtfvariVK9m_AuPMV6tp0Xv12ABaIvF_D0ZcSJjo7hufn5D9l5MgR0Etg3glcF43nDZKAHcu4SZ5ME01LYayY0cgiUWJFRPPPvHyA3ekIvosiq5vNJgEWpVeBf-dR10jKgkV_E3y2aBlDi9sJojYyJ-kLJ_mNyjCxFRSYmvaX1MMPdfSeZxmHkX14uYjtTkwoOMbEtYn-1x07AGOs2qkEzXKu-CWodtM2cmnuFb5ARJzT4Te9VUarBK0IeNavlS1fAES7BRQrKrKx5K3mcEFNebGBIsY6Ea5hUOQ-CBM6Ovt6W1G7Nzt5_w.yafj7hI_N1MgHofR.QD1wYOF3O0Mo2pGPNApGdLzktw5ZnbX3NjHBHgWepHEqMVzetXPiTrqOTjJa60qNHzQfb-KJHP7in7UykjMYR-9TbO79RksaaaKgS5RfZWG7I17dZAzDUHCm2mkGzgJqTNG1c-yiVlSZJfkKRGGbqkfRkn41uD9hDdX3NOqyhY529Lnwc4bXhQZBc_t5FGGC7yjmkr5JIZIVk9hbwIaWbSmzOs_-r90OEyKjf7qld0ASDf3c1GhCTNtSApcTpi2v34PFcdadvI86Tj0NAOoBKvpnKCHl8zxKILWiRG5CI2_gFlybqGDggAdNXpRJ_-a-4gCuk6L4T3euXcs1XjbCiZoa6YxU-8R9pawXUI4UVe1nz0v1Vp1fIVbs_JkBmoZ3sGknSLkTzjeKPTWE6HrNbXRub5JKKnwjYwjfwZ-73BnqnpxFJAj1s53VwBfXEigy1TD1O4geHC2btSRH40AozWmveE-bfyYF2BXmnfquJrLCzLp1O7O9QWmUNOKb6_gZJvzweK7Esb9ilgIfVOCrDgut5x4As0Ktc6soIRM4gEhQtBhO5YcLy80F8npq7DMnqI9TnwdNx3DNK_tE3ufLZOgS2IxGFs1mPTVBt3bPTkg0Iy6s8z5PjCSJlxAPo7XzA8tClc3nqrmT-3-kmniAb899tofF58QZa3IhAuJJAwwWQfOyDWd9FZV4tK8rHb2kuIGzjwmRYIwbvhrPGnKy0iaCpBgSsbftumn7y9wJt3SM9tWxWPi_v_gUGn7PQpfFW5oPdAZepqoioANdqtDuGcSkTKDauNhY0EwaZveuOjl1zvuLfN_PuLzJl8zQkNHwEyPhoVmJugueGrHa5Bn5SwonMD8Ch86-cME5dCxWyNFBxM0B7z_LzHE2E4-5qWi1mNbeI-kaijknQGp34pNh5F8SrEGQ9OdHWWFT-_DkjCy_Eyh4-SEj2FgV4YziluuC2jY5Lp-ll1LsxsISj4LxIaGMEOqiwPnK9y3Vrijam3GFUUc4_0rzIylDpsCTqz1JUfkOdzwITNAf9Co-swKAWrqi1i25bWz-HWIi5h5SCpvTj2sTnW7ULJ_iQxuYh4m4ZY00jb4MSLViX4LwM6b3B61KRqvZ5IWEObOynFSpXcZoHO_79SQQK_l_Pz2ZcYIS8t9mrFcITH71j0aqSrtFSzSxreT2kI4vHaJn90EHaLKMSXUe0bnbM2D0XnKpdCABE6UuX4MHHR1IQ1WAerkQ7AvW-Dpu6sJnE0rKAUWeb1Kj98N_BgO4pbVaXwApaUpa0qZTf1smQh-I19L8UHgaD78l81N_6QrpMMChjSC0GkzLsDopmVnyE0y3leCse02CYW7pnXLXoWlAlBjqwZdY4joefDrjCHO3RvuMlXI87qZ2ZRrAbJV9_GCzG3ffeBSchvwKmvJZ1DPUj9z7j5mUVHE7_kN6dbs_fxSwDLPx2krEsKEU7CXJKrThGcJhOVKk6Il8hw6FFnwU6dFlAod-cKWEvkbbKKhPtlCfxfV-xFT4E_wDr7NE0vROIp6q3-Td5ukXaaAz2_J-R91c6ctl1mOvERGin4-dsOh2nEtM7glfi3hnKf8khmfYxR2SWEe8Jw434ebeI5mhLeVomoCw_vY7F88-Yh5iRCygXqWmB3QNPoKcatovWzBtOQU6R-VCIbnInKaHkfZC2HLdFhEfNJ_jfm1tT95RMpXNewcUjv_VZgiE4yqknZ1oxH_8ebjacR_nwcGxnzWIEryNitvoAfk72Zyn7wWhqhdGgil5Mh1ouJMENFq_MjuDFLI1zo0J2X2IKxL06b4F9QmnO-oRDlugCZyg0zAtFWUroPNY4yivYv6d97iq_ZQ8QwSNCDLfohCxJ50j_hCy1SDBDWow3faK6o4f9q31jP5DTdhqJwhqFBr4NmiwQzFkp08bV1tRyg.FXvsMt1qF4SB84V36AUKPA",
  "client_id": "geru-bank",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImI5ZGRlNGZjOGE2ZGVlYzUwNDRhOTk0ZGExMTliNzNkMDA3ZGIzMGQwOTc4Zjc4YmZiMTY3NmRiNDE1MGIzMjMifQ.eyJpYXQiOjE2MzkwOTA0NTYsImV4cCI6MTYzOTA5MDUxNiwianRpIjoiWmE0andFbUVmOWIxaVFFX2VUZnN4bjd3dHBrUGhOdWJkRTVIOUV0dXctNCIsImlzcyI6ImdlcnUtYmFuayIsInN1YiI6ImdlcnUtYmFuayIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL2dlcnUvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9nZXJ1L3Rva2VuIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL2dlcnUvdG9rZW4iXX0.pV2Njv72zqLJM1ab0qkOTS51C1Iy-8fkAfMASVN9ieStzkgJoEGGWVH8NGTz-asYIOj21Apbxpcb8S7RKX2B6ObuyYIpyOLJpr82DO5Ieigvv0Iz2-1Rc8GHvTjVKc78kmTWHZIDkCuPiHtQgP81qsW12sF1jPNBd2W-ZkxukMU61Pn7v1Fv123mGNb93S--VYTnXksYXRog5pCt_kV0pTckyxgqek0FyYPOdUG0PpJu6mmIptgR32-SzsiA2akRiDidOY3cQCrWib7O94jsa1miO5bCuTjJ0Y-_-rGvyhZNQTbox55d90fSIXNZxG7KlHrvDqdWi19lQra86BObZg",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4 MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00 ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza 6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7 sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514 EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4 vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi 99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa HI5ipvGg/0g= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
request=eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZHQ00iLCJjdHkiOiJvYXV0aC1hdXRoei1yZXErand0Iiwia2lkIjoiMGZlNTAyZGQtMTRmMC00ZjQ1LTgwZjktZmViOWEyMTZmOTk2In0.qrO96hYl_j7Dap6CpNb_0UmyyMXVuCibtfvariVK9m_AuPMV6tp0Xv12ABaIvF_D0ZcSJjo7hufn5D9l5MgR0Etg3glcF43nDZKAHcu4SZ5ME01LYayY0cgiUWJFRPPPvHyA3ekIvosiq5vNJgEWpVeBf-dR10jKgkV_E3y2aBlDi9sJojYyJ-kLJ_mNyjCxFRSYmvaX1MMPdfSeZxmHkX14uYjtTkwoOMbEtYn-1x07AGOs2qkEzXKu-CWodtM2cmnuFb5ARJzT4Te9VUarBK0IeNavlS1fAES7BRQrKrKx5K3mcEFNebGBIsY6Ea5hUOQ-CBM6Ovt6W1G7Nzt5_w.yafj7hI_N1MgHofR.QD1wYOF3O0Mo2pGPNApGdLzktw5ZnbX3NjHBHgWepHEqMVzetXPiTrqOTjJa60qNHzQfb-KJHP7in7UykjMYR-9TbO79RksaaaKgS5RfZWG7I17dZAzDUHCm2mkGzgJqTNG1c-yiVlSZJfkKRGGbqkfRkn41uD9hDdX3NOqyhY529Lnwc4bXhQZBc_t5FGGC7yjmkr5JIZIVk9hbwIaWbSmzOs_-r90OEyKjf7qld0ASDf3c1GhCTNtSApcTpi2v34PFcdadvI86Tj0NAOoBKvpnKCHl8zxKILWiRG5CI2_gFlybqGDggAdNXpRJ_-a-4gCuk6L4T3euXcs1XjbCiZoa6YxU-8R9pawXUI4UVe1nz0v1Vp1fIVbs_JkBmoZ3sGknSLkTzjeKPTWE6HrNbXRub5JKKnwjYwjfwZ-73BnqnpxFJAj1s53VwBfXEigy1TD1O4geHC2btSRH40AozWmveE-bfyYF2BXmnfquJrLCzLp1O7O9QWmUNOKb6_gZJvzweK7Esb9ilgIfVOCrDgut5x4As0Ktc6soIRM4gEhQtBhO5YcLy80F8npq7DMnqI9TnwdNx3DNK_tE3ufLZOgS2IxGFs1mPTVBt3bPTkg0Iy6s8z5PjCSJlxAPo7XzA8tClc3nqrmT-3-kmniAb899tofF58QZa3IhAuJJAwwWQfOyDWd9FZV4tK8rHb2kuIGzjwmRYIwbvhrPGnKy0iaCpBgSsbftumn7y9wJt3SM9tWxWPi_v_gUGn7PQpfFW5oPdAZepqoioANdqtDuGcSkTKDauNhY0EwaZveuOjl1zvuLfN_PuLzJl8zQkNHwEyPhoVmJugueGrHa5Bn5SwonMD8Ch86-cME5dCxWyNFBxM0B7z_LzHE2E4-5qWi1mNbeI-kaijknQGp34pNh5F8SrEGQ9OdHWWFT-_DkjCy_Eyh4-SEj2FgV4YziluuC2jY5Lp-ll1LsxsISj4LxIaGMEOqiwPnK9y3Vrijam3GFUUc4_0rzIylDpsCTqz1JUfkOdzwITNAf9Co-swKAWrqi1i25bWz-HWIi5h5SCpvTj2sTnW7ULJ_iQxuYh4m4ZY00jb4MSLViX4LwM6b3B61KRqvZ5IWEObOynFSpXcZoHO_79SQQK_l_Pz2ZcYIS8t9mrFcITH71j0aqSrtFSzSxreT2kI4vHaJn90EHaLKMSXUe0bnbM2D0XnKpdCABE6UuX4MHHR1IQ1WAerkQ7AvW-Dpu6sJnE0rKAUWeb1Kj98N_BgO4pbVaXwApaUpa0qZTf1smQh-I19L8UHgaD78l81N_6QrpMMChjSC0GkzLsDopmVnyE0y3leCse02CYW7pnXLXoWlAlBjqwZdY4joefDrjCHO3RvuMlXI87qZ2ZRrAbJV9_GCzG3ffeBSchvwKmvJZ1DPUj9z7j5mUVHE7_kN6dbs_fxSwDLPx2krEsKEU7CXJKrThGcJhOVKk6Il8hw6FFnwU6dFlAod-cKWEvkbbKKhPtlCfxfV-xFT4E_wDr7NE0vROIp6q3-Td5ukXaaAz2_J-R91c6ctl1mOvERGin4-dsOh2nEtM7glfi3hnKf8khmfYxR2SWEe8Jw434ebeI5mhLeVomoCw_vY7F88-Yh5iRCygXqWmB3QNPoKcatovWzBtOQU6R-VCIbnInKaHkfZC2HLdFhEfNJ_jfm1tT95RMpXNewcUjv_VZgiE4yqknZ1oxH_8ebjacR_nwcGxnzWIEryNitvoAfk72Zyn7wWhqhdGgil5Mh1ouJMENFq_MjuDFLI1zo0J2X2IKxL06b4F9QmnO-oRDlugCZyg0zAtFWUroPNY4yivYv6d97iq_ZQ8QwSNCDLfohCxJ50j_hCy1SDBDWow3faK6o4f9q31jP5DTdhqJwhqFBr4NmiwQzFkp08bV1tRyg.FXvsMt1qF4SB84V36AUKPA&client_id=geru-bank&client_assertion=eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImI5ZGRlNGZjOGE2ZGVlYzUwNDRhOTk0ZGExMTliNzNkMDA3ZGIzMGQwOTc4Zjc4YmZiMTY3NmRiNDE1MGIzMjMifQ.eyJpYXQiOjE2MzkwOTA0NTYsImV4cCI6MTYzOTA5MDUxNiwianRpIjoiWmE0andFbUVmOWIxaVFFX2VUZnN4bjd3dHBrUGhOdWJkRTVIOUV0dXctNCIsImlzcyI6ImdlcnUtYmFuayIsInN1YiI6ImdlcnUtYmFuayIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL2dlcnUvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9nZXJ1L3Rva2VuIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL2dlcnUvdG9rZW4iXX0.pV2Njv72zqLJM1ab0qkOTS51C1Iy-8fkAfMASVN9ieStzkgJoEGGWVH8NGTz-asYIOj21Apbxpcb8S7RKX2B6ObuyYIpyOLJpr82DO5Ieigvv0Iz2-1Rc8GHvTjVKc78kmTWHZIDkCuPiHtQgP81qsW12sF1jPNBd2W-ZkxukMU61Pn7v1Fv123mGNb93S--VYTnXksYXRog5pCt_kV0pTckyxgqek0FyYPOdUG0PpJu6mmIptgR32-SzsiA2akRiDidOY3cQCrWib7O94jsa1miO5bCuTjJ0Y-_-rGvyhZNQTbox55d90fSIXNZxG7KlHrvDqdWi19lQra86BObZg&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2021-12-09 22:54:16 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
PAR endpoint
2021-12-09 22:54:16 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4 MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00 ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza 6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7 sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514 EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4 vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi 99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa HI5ipvGg/0g\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4\nMDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS\nRVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj\nY2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz\nODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB\nAxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00\nZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH\nMpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza\n6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf\nZ0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk\nj7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK\ntC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY\nUV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW\nBBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7\nsM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw\nLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC\nMECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls\nLm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud\nDwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU\nMIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD\nZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj\nZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z\nIHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr\nIFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp\ndHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy\ndGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE\nBggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy\nYXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514\nEpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4\nvv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF\nNzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi\n99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M\nRyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa\nHI5ipvGg/0g\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003d73885603-f3ff-41bf-b2b2-4f7ca9fe6076,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3337373633383437303030313338,CN\u003dgeru.com.br,OU\u003d0ca05092-025f-47c4-b878-4a03c150cccf,O\u003dGERU SOCIEDADE DE CREDITO DIRETO,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "geru.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2021-12-09 22:54:16 SUCCESS
CheckForClientCertificate
Found client certificate
2021-12-09 22:54:16 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4
MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS
RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj
Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz
ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB
AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00
ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH
MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza
6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf
Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk
j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK
tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY
UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW
BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7
sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw
LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC
MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls
Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud
DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU
MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD
ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj
ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z
IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr
IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp
dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy
dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE
BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy
YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514
EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4
vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF
NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi
99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M
RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa
HI5ipvGg/0g=
-----END CERTIFICATE-----
2021-12-09 22:54:16 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImI5ZGRlNGZjOGE2ZGVlYzUwNDRhOTk0ZGExMTliNzNkMDA3ZGIzMGQwOTc4Zjc4YmZiMTY3NmRiNDE1MGIzMjMifQ.eyJpYXQiOjE2MzkwOTA0NTYsImV4cCI6MTYzOTA5MDUxNiwianRpIjoiWmE0andFbUVmOWIxaVFFX2VUZnN4bjd3dHBrUGhOdWJkRTVIOUV0dXctNCIsImlzcyI6ImdlcnUtYmFuayIsInN1YiI6ImdlcnUtYmFuayIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL2dlcnUvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9nZXJ1L3Rva2VuIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL2dlcnUvdG9rZW4iXX0.pV2Njv72zqLJM1ab0qkOTS51C1Iy-8fkAfMASVN9ieStzkgJoEGGWVH8NGTz-asYIOj21Apbxpcb8S7RKX2B6ObuyYIpyOLJpr82DO5Ieigvv0Iz2-1Rc8GHvTjVKc78kmTWHZIDkCuPiHtQgP81qsW12sF1jPNBd2W-ZkxukMU61Pn7v1Fv123mGNb93S--VYTnXksYXRog5pCt_kV0pTckyxgqek0FyYPOdUG0PpJu6mmIptgR32-SzsiA2akRiDidOY3cQCrWib7O94jsa1miO5bCuTjJ0Y-_-rGvyhZNQTbox55d90fSIXNZxG7KlHrvDqdWi19lQra86BObZg",
  "header": {
    "kid": "b9dde4fc8a6deec5044a994da119b73d007db30d0978f78bfb1676db4150b323",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "geru-bank",
    "aud": [
      "https://www.certification.openid.net/test/a/geru/",
      "https://www.certification.openid.net/test/a/geru/token",
      "https://www.certification.openid.net/test-mtls/a/geru/token"
    ],
    "iss": "geru-bank",
    "exp": 1639090516,
    "iat": 1639090456,
    "jti": "Za4jwEmEf9b1iQE_eTfsxn7wtpkPhNubdE5H9Etuw-4"
  }
}
2021-12-09 22:54:16
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2021-12-09 22:54:16 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImI5ZGRlNGZjOGE2ZGVlYzUwNDRhOTk0ZGExMTliNzNkMDA3ZGIzMGQwOTc4Zjc4YmZiMTY3NmRiNDE1MGIzMjMifQ.eyJpYXQiOjE2MzkwOTA0NTYsImV4cCI6MTYzOTA5MDUxNiwianRpIjoiWmE0andFbUVmOWIxaVFFX2VUZnN4bjd3dHBrUGhOdWJkRTVIOUV0dXctNCIsImlzcyI6ImdlcnUtYmFuayIsInN1YiI6ImdlcnUtYmFuayIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL2dlcnUvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9nZXJ1L3Rva2VuIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL2dlcnUvdG9rZW4iXX0.pV2Njv72zqLJM1ab0qkOTS51C1Iy-8fkAfMASVN9ieStzkgJoEGGWVH8NGTz-asYIOj21Apbxpcb8S7RKX2B6ObuyYIpyOLJpr82DO5Ieigvv0Iz2-1Rc8GHvTjVKc78kmTWHZIDkCuPiHtQgP81qsW12sF1jPNBd2W-ZkxukMU61Pn7v1Fv123mGNb93S--VYTnXksYXRog5pCt_kV0pTckyxgqek0FyYPOdUG0PpJu6mmIptgR32-SzsiA2akRiDidOY3cQCrWib7O94jsa1miO5bCuTjJ0Y-_-rGvyhZNQTbox55d90fSIXNZxG7KlHrvDqdWi19lQra86BObZg
2021-12-09 22:54:16 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-12-09 22:54:16 SUCCESS
ValidateClientAssertionClaimsForPAREndpoint
Client Assertion passed all validation checks
2021-12-09 22:54:16 SUCCESS
ExtractRequestObjectFromPAREndpointRequest
Parsed request object
request_object
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6Im9hdXRoLWF1dGh6LXJlcStqd3QiLCJraWQiOiJiOWRkZTRmYzhhNmRlZWM1MDQ0YTk5NGRhMTE5YjczZDAwN2RiMzBkMDk3OGY3OGJmYjE2NzZkYjQxNTBiMzIzIn0.eyJub25jZSI6Ijc4dDNia3BnN0RHTjEtaDY0MGs4TFJ3ODlTT01BYVYyYk9pS184MmRyTVEiLCJzdGF0ZSI6IkxsTzIxMHlGMEVEUlFXY1VGemI4RVpvdDlhb09KdzhTY2lXRlgxakNzdW8iLCJzY29wZSI6Im9wZW5pZCBjb25zZW50OnVybjpjb25mb3JtYW5jZS5vaWRmOmRFdzgyd0FJZG0gYWNjb3VudHMgcmVzb3VyY2VzIiwicmVzcG9uc2VfdHlwZSI6ImNvZGUgaWRfdG9rZW4iLCJyZWRpcmVjdF91cmkiOiJodHRwczovL3NjZC1vcGVuLWJhbmtpbmctZnJvbnRlbmQuZGV2LnNjZC5vcGVuLWNvLnRlY2giLCJjbGFpbXMiOnsiaWRfdG9rZW4iOnsiYWNyIjp7InZhbHVlcyI6WyJ1cm46YnJhc2lsOm9wZW5iYW5raW5nOmxvYTIiLCJ1cm46YnJhc2lsOm9wZW5iYW5raW5nOmxvYTMiXSwiZXNzZW50aWFsIjp0cnVlfX19LCJjb2RlX2NoYWxsZW5nZSI6InZmUlJmMS1UYnl1VzBfMmEtR2I1dnJKaWlOSThpUGtvWEVUWHZWVTI3bjgiLCJjb2RlX2NoYWxsZW5nZV9tZXRob2QiOiJTMjU2IiwiaXNzIjoiZ2VydS1iYW5rIiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9nZXJ1LyIsImNsaWVudF9pZCI6ImdlcnUtYmFuayIsImp0aSI6IkRvRHFaZ2ppcTZaTk83ellXS2ZYWVVLLUN1bEhXVDRnRl9YeXJIRU5ZTlkiLCJpYXQiOjE2MzkwOTA0NTYsImV4cCI6MTYzOTA5MDc1NiwibmJmIjoxNjM5MDkwNDU2fQ.hjpLaJfkid-hf0PIhpionIp8ZimOxtgzHpOTgSCVUcUR9w0Zx1e8FMMgM2IdRKKFoqXuXMp9uaYPGfPppvjNJex1gUlbEFYsO1eaI7Gkn4lLpelZvreamNwfjZiMuytXSyOlrDtANvoDaOK6vmTs5RU3t-yDzpY35O-P8O-YJlhlenztcLJOYjIivi_YeoGk_-Rm-1sDjVbVFUYBWwH6HlwUm28xT3snyrsJcGVKx4o8x0TMuFG5btcmiMe0xnZilx1Si8bZ1-qyJLaoU_JzmwGVc_6r0xM_YRipyYLqbsZxYivRI1eQFpFN7e0vLmbaweXxzwNOlaI2q-kehrt-Eg",
  "header": {
    "kid": "b9dde4fc8a6deec5044a994da119b73d007db30d0978f78bfb1676db4150b323",
    "typ": "oauth-authz-req+jwt",
    "alg": "PS256"
  },
  "claims": {
    "iss": "geru-bank",
    "response_type": "code id_token",
    "code_challenge_method": "S256",
    "nonce": "78t3bkpg7DGN1-h640k8LRw89SOMAaV2bOiK_82drMQ",
    "client_id": "geru-bank",
    "aud": "https://www.certification.openid.net/test/a/geru/",
    "nbf": 1639090456,
    "scope": "openid consent:urn:conformance.oidf:dEw82wAIdm accounts resources",
    "claims": {
      "id_token": {
        "acr": {
          "values": [
            "urn:brasil:openbanking:loa2",
            "urn:brasil:openbanking:loa3"
          ],
          "essential": true
        }
      }
    },
    "state": "LlO210yF0EDRQWcUFzb8EZot9aoOJw8SciWFX1jCsuo",
    "redirect_uri": "https://scd-open-banking-frontend.dev.scd.open-co.tech",
    "exp": 1639090756,
    "iat": 1639090456,
    "code_challenge": "vfRRf1-TbyuW0_2a-Gb5vrJiiNI8iPkoXETXvVU27n8",
    "jti": "DoDqZgjiq6ZNO7zYWKfXYUK-CulHWT4gF_XyrHENYNY"
  },
  "jwe_header": {
    "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
    "cty": "oauth-authz-req+jwt",
    "enc": "A256GCM",
    "alg": "RSA-OAEP"
  }
}
2021-12-09 22:54:16 SUCCESS
EnsurePAREndpointRequestDoesNotContainRequestUriParameter
PAR endpoint request does not contain a request_uri parameter
2021-12-09 22:54:16 SUCCESS
ValidateEncryptedRequestObjectHasKid
kid was found in the encrypted request object header
kid
0fe502dd-14f0-4f45-80f9-feb9a216f996
2021-12-09 22:54:16 SUCCESS
FAPIValidateRequestObjectSigningAlg
Request object was signed with a permitted algorithm
alg
PS256
2021-12-09 22:54:16 SUCCESS
FAPIBrazilValidateRequestObjectIdTokenACRClaims
Acr value in request object is as expected
received
[
  "urn:brasil:openbanking:loa2",
  "urn:brasil:openbanking:loa3"
]
2021-12-09 22:54:16 SUCCESS
FAPIValidateRequestObjectExp
Request object contains a valid exp claim, expiry time
exp
"Dec 9, 2021, 10:59:16 PM"
2021-12-09 22:54:16 SUCCESS
FAPI1AdvancedValidateRequestObjectNBFClaim
nbf claim is valid
nbf
"Dec 9, 2021, 10:54:16 PM"
now
"Dec 9, 2021, 10:54:16 PM"
2021-12-09 22:54:16
ValidateRequestObjectClaims
Request object does not contain a max_age claim
2021-12-09 22:54:16 SUCCESS
ValidateRequestObjectClaims
Request object claims passed all validation checks
2021-12-09 22:54:16 SUCCESS
EnsureNumericRequestObjectClaimsAreNotNull
None of the claims expected to have numeric values, have null values
numeric_claims
[
  "max_age"
]
2021-12-09 22:54:16 SUCCESS
EnsureRequestObjectDoesNotContainRequestOrRequestUri
Request object does not contain request or request_uri
2021-12-09 22:54:16 SUCCESS
EnsureRequestObjectDoesNotContainSubWithClientId
Request object does not contain Client Id in sub
2021-12-09 22:54:16 SUCCESS
ValidateRequestObjectSignature
Request object signature validated using a key in the client's JWKS and using the client's registered request_object_signing_alg
request_object
eyJhbGciOiJQUzI1NiIsInR5cCI6Im9hdXRoLWF1dGh6LXJlcStqd3QiLCJraWQiOiJiOWRkZTRmYzhhNmRlZWM1MDQ0YTk5NGRhMTE5YjczZDAwN2RiMzBkMDk3OGY3OGJmYjE2NzZkYjQxNTBiMzIzIn0.eyJub25jZSI6Ijc4dDNia3BnN0RHTjEtaDY0MGs4TFJ3ODlTT01BYVYyYk9pS184MmRyTVEiLCJzdGF0ZSI6IkxsTzIxMHlGMEVEUlFXY1VGemI4RVpvdDlhb09KdzhTY2lXRlgxakNzdW8iLCJzY29wZSI6Im9wZW5pZCBjb25zZW50OnVybjpjb25mb3JtYW5jZS5vaWRmOmRFdzgyd0FJZG0gYWNjb3VudHMgcmVzb3VyY2VzIiwicmVzcG9uc2VfdHlwZSI6ImNvZGUgaWRfdG9rZW4iLCJyZWRpcmVjdF91cmkiOiJodHRwczovL3NjZC1vcGVuLWJhbmtpbmctZnJvbnRlbmQuZGV2LnNjZC5vcGVuLWNvLnRlY2giLCJjbGFpbXMiOnsiaWRfdG9rZW4iOnsiYWNyIjp7InZhbHVlcyI6WyJ1cm46YnJhc2lsOm9wZW5iYW5raW5nOmxvYTIiLCJ1cm46YnJhc2lsOm9wZW5iYW5raW5nOmxvYTMiXSwiZXNzZW50aWFsIjp0cnVlfX19LCJjb2RlX2NoYWxsZW5nZSI6InZmUlJmMS1UYnl1VzBfMmEtR2I1dnJKaWlOSThpUGtvWEVUWHZWVTI3bjgiLCJjb2RlX2NoYWxsZW5nZV9tZXRob2QiOiJTMjU2IiwiaXNzIjoiZ2VydS1iYW5rIiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9nZXJ1LyIsImNsaWVudF9pZCI6ImdlcnUtYmFuayIsImp0aSI6IkRvRHFaZ2ppcTZaTk83ellXS2ZYWVVLLUN1bEhXVDRnRl9YeXJIRU5ZTlkiLCJpYXQiOjE2MzkwOTA0NTYsImV4cCI6MTYzOTA5MDc1NiwibmJmIjoxNjM5MDkwNDU2fQ.hjpLaJfkid-hf0PIhpionIp8ZimOxtgzHpOTgSCVUcUR9w0Zx1e8FMMgM2IdRKKFoqXuXMp9uaYPGfPppvjNJex1gUlbEFYsO1eaI7Gkn4lLpelZvreamNwfjZiMuytXSyOlrDtANvoDaOK6vmTs5RU3t-yDzpY35O-P8O-YJlhlenztcLJOYjIivi_YeoGk_-Rm-1sDjVbVFUYBWwH6HlwUm28xT3snyrsJcGVKx4o8x0TMuFG5btcmiMe0xnZilx1Si8bZ1-qyJLaoU_JzmwGVc_6r0xM_YRipyYLqbsZxYivRI1eQFpFN7e0vLmbaweXxzwNOlaI2q-kehrt-Eg
request_object_signing_alg
PS256
jwk
Sun RSA public key, 2048 bits
  params: null
  modulus: 23846203553327299365485107100321162062448244492919797859629076287606513086740596402294906878752765419601271099327917193127743990852690041322094040768383624198441789676616318840569608585300544508421247227694480125120011781104845171406661909259669843088703052128954082054458558581984082288825913040315191061271341269671844781543618915159191802461219585744523115979009976811561492232351444788743896594549287340146305490872256509509758988721256204420339679579868976863245716219653823319013979181514515286901014485674968733408565577242188259099799342877974860953629031553001593460063839039078239812104831432758847492912291
  public exponent: 65537
2021-12-09 22:54:16 SUCCESS
EnsureMatchingRedirectUriInRequestObject
Redirect URI matched
actual
https://scd-open-banking-frontend.dev.scd.open-co.tech
2021-12-09 22:54:16 SUCCESS
EnsureRequestObjectContainsCodeChallengeWhenUsingPAR
Found required PKCE parameters in request
code_challenge_method
S256
code_challenge
vfRRf1-TbyuW0_2a-Gb5vrJiiNI8iPkoXETXvVU27n8
2021-12-09 22:54:16 SUCCESS
CreatePAREndpointResponse
Created PAR endpoint response
request_uri
urn:ietf:params:oauth:request_uri:de54e4f6-f6be-49db-9772-6bb3d192fcf0
expires_in
600
2021-12-09 22:54:16 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance UisCUKUCH9FYlkZ
outgoing_status_code
201
outgoing_headers
{}
outgoing_body
{
  "request_uri": "urn:ietf:params:oauth:request_uri:de54e4f6-f6be-49db-9772-6bb3d192fcf0",
  "expires_in": 600
}
outgoing_path
par
2021-12-09 22:54:17 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance UisCUKUCH9FYlkZ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "PostmanRuntime/7.28.4",
  "accept": "*/*",
  "cache-control": "no-cache",
  "postman-token": "8560b30f-e0a3-493b-8e0f-e074ef78287c",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/geru/authorize
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{
  "client_id": "geru-bank",
  "scope": "openid consent:urn:conformance.oidf:dEw82wAIdm accounts resources",
  "response_type": "code id_token",
  "redirect_uri": "https://scd-open-banking-frontend.dev.scd.open-co.tech",
  "request_uri": "urn:ietf:params:oauth:request_uri:de54e4f6-f6be-49db-9772-6bb3d192fcf0"
}
incoming_body
2021-12-09 22:54:17 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Authorization endpoint
2021-12-09 22:54:17 SUCCESS
EnsureAuthorizationRequestDoesNotContainRequestWhenUsingPAR
Request does not contain a request parameter
2021-12-09 22:54:17 SUCCESS
ValidateEncryptedRequestObjectHasKid
kid was found in the encrypted request object header
kid
0fe502dd-14f0-4f45-80f9-feb9a216f996
2021-12-09 22:54:17 SUCCESS
CreateEffectiveAuthorizationRequestParameters
Merged http request parameters with request object claims
effective_authorization_endpoint_request
{
  "client_id": "geru-bank",
  "scope": "openid consent:urn:conformance.oidf:dEw82wAIdm accounts resources",
  "response_type": "code id_token",
  "redirect_uri": "https://scd-open-banking-frontend.dev.scd.open-co.tech",
  "iss": "geru-bank",
  "code_challenge_method": "S256",
  "nonce": "78t3bkpg7DGN1-h640k8LRw89SOMAaV2bOiK_82drMQ",
  "aud": "https://www.certification.openid.net/test/a/geru/",
  "nbf": 1639090456,
  "claims": {
    "id_token": {
      "acr": {
        "values": [
          "urn:brasil:openbanking:loa2",
          "urn:brasil:openbanking:loa3"
        ],
        "essential": true
      }
    }
  },
  "state": "LlO210yF0EDRQWcUFzb8EZot9aoOJw8SciWFX1jCsuo",
  "exp": 1639090756,
  "iat": 1639090456,
  "code_challenge": "vfRRf1-TbyuW0_2a-Gb5vrJiiNI8iPkoXETXvVU27n8",
  "jti": "DoDqZgjiq6ZNO7zYWKfXYUK-CulHWT4gF_XyrHENYNY"
}
2021-12-09 22:54:17 SUCCESS
EnsureClientIdInAuthorizationRequestParametersMatchRequestObject
client_id http request parameter value matches client_id in request object
2021-12-09 22:54:17 SUCCESS
ExtractRequestedScopes
Requested scopes
scope
openid consent:urn:conformance.oidf:dEw82wAIdm accounts resources
2021-12-09 22:54:17 SUCCESS
FAPIBrazilValidateConsentScope
Found consent scope in request
actual
[
  "openid",
  "consent:urn:conformance.oidf:dEw82wAIdm",
  "accounts",
  "resources"
]
expected
consent:urn:conformance.oidf:dEw82wAIdm
2021-12-09 22:54:17 SUCCESS
EnsureScopeContainsAccounts
Found accounts scope in request
actual
[
  "openid",
  "consent:urn:conformance.oidf:dEw82wAIdm",
  "accounts",
  "resources"
]
2021-12-09 22:54:17 SUCCESS
EnsureResponseTypeIsCodeIdToken
Response type is expected value
expected
code id_token
2021-12-09 22:54:17 SUCCESS
EnsureOpenIDInScopeRequest
Found 'openid' scope in request
actual
[
  "openid",
  "consent:urn:conformance.oidf:dEw82wAIdm",
  "accounts",
  "resources"
]
expected
openid
2021-12-09 22:54:17 SUCCESS
EnsureMatchingClientId
Client ID matched
client_id
geru-bank
2021-12-09 22:54:17 SUCCESS
CreateAuthorizationCode
Created authorization code
authorization_code
k8W9UWTjpXhYWzJXK5XRyu85KofJhIUK
2021-12-09 22:54:17 SUCCESS
ExtractNonceFromAuthorizationRequest
Extracted nonce
nonce
78t3bkpg7DGN1-h640k8LRw89SOMAaV2bOiK_82drMQ
2021-12-09 22:54:17 SUCCESS
CalculateCHash
Successful c_hash encoding
c_hash
S293hGjrCqwkZhMYV2anCg
2021-12-09 22:54:17 SUCCESS
CalculateSHash
Successful s_hash encoding
s_hash
UD1061qG5kh0N34oE83CGQ
2021-12-09 22:54:17 SUCCESS
GenerateIdTokenClaims
Created ID Token Claims
iss
https://www.certification.openid.net/test/a/geru/
sub
user-subject-1234531
aud
geru-bank
nonce
78t3bkpg7DGN1-h640k8LRw89SOMAaV2bOiK_82drMQ
iat
1639090457
exp
1639090757
2021-12-09 22:54:17 SUCCESS
FAPIBrazilAddCPFAndCPNJToIdTokenClaims
Added claims to id_token claims
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/geru/",
  "sub": "user-subject-1234531",
  "aud": "geru-bank",
  "nonce": "78t3bkpg7DGN1-h640k8LRw89SOMAaV2bOiK_82drMQ",
  "iat": 1639090457,
  "exp": 1639090757
}
2021-12-09 22:54:17 SUCCESS
AddCHashToIdTokenClaims
Added c_hash to ID token claims
c_hash
S293hGjrCqwkZhMYV2anCg
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/geru/",
  "sub": "user-subject-1234531",
  "aud": "geru-bank",
  "nonce": "78t3bkpg7DGN1-h640k8LRw89SOMAaV2bOiK_82drMQ",
  "iat": 1639090457,
  "exp": 1639090757,
  "c_hash": "S293hGjrCqwkZhMYV2anCg"
}
2021-12-09 22:54:17 SUCCESS
AddSHashToIdTokenClaims
Added s_hash to ID token claims
s_hash
UD1061qG5kh0N34oE83CGQ
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/geru/",
  "sub": "user-subject-1234531",
  "aud": "geru-bank",
  "nonce": "78t3bkpg7DGN1-h640k8LRw89SOMAaV2bOiK_82drMQ",
  "iat": 1639090457,
  "exp": 1639090757,
  "c_hash": "S293hGjrCqwkZhMYV2anCg",
  "s_hash": "UD1061qG5kh0N34oE83CGQ"
}
2021-12-09 22:54:17 INFO
AddAtHashToIdTokenClaims
Skipped evaluation due to missing required string: at_hash
expected
at_hash
2021-12-09 22:54:17 SUCCESS
FAPIBrazilAddACRClaimToIdTokenClaims
Added acr value to id_token_claims
acr_value
urn:brasil:openbanking:loa2
claims
{
  "iss": "https://www.certification.openid.net/test/a/geru/",
  "sub": "user-subject-1234531",
  "aud": "geru-bank",
  "nonce": "78t3bkpg7DGN1-h640k8LRw89SOMAaV2bOiK_82drMQ",
  "iat": 1639090457,
  "exp": 1639090757,
  "c_hash": "S293hGjrCqwkZhMYV2anCg",
  "s_hash": "UD1061qG5kh0N34oE83CGQ",
  "acr": "urn:brasil:openbanking:loa2"
}
2021-12-09 22:54:17 SUCCESS
SignIdToken
Signed the ID token
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6ImdlcnUtYmFuayIsImNfaGFzaCI6IlMyOTNoR2pyQ3F3a1poTVlWMmFuQ2ciLCJhY3IiOiJ1cm46YnJhc2lsOm9wZW5iYW5raW5nOmxvYTIiLCJzX2hhc2giOiJVRDEwNjFxRzVraDBOMzRvRTgzQ0dRIiwiaXNzIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL2dlcnVcLyIsImV4cCI6MTYzOTA5MDc1Nywibm9uY2UiOiI3OHQzYmtwZzdER04xLWg2NDBrOExSdzg5U09NQWFWMmJPaUtfODJkck1RIiwiaWF0IjoxNjM5MDkwNDU3fQ.pJPTGbbCeCvwc8zfHJVWzsY1w9mHmVqJmxWWrINnCK4qvvPTNUhP50JBCMgLDFj4_iwwgUjr-_Xg6ThXrEro0jo0lC7ECm5NZPddcpxfWwje83w2Ppjr4Jmyny1spLmwjXsvjy8MoFK5YcRPDJd8_F0w9E4xo7O3K6GBGe_E3RAoj0X1eHCPFw3JwXEXuAIWTQV8jbbGlx8yqN13eaDlyVPkFmI-rwbPe-MaSW2d3HHJEx7oTit64mtwE3hvjSDsuc_EJPI-cnWrQ2nF5ggPRd9Q7hKtXjfR938HR8OuOJed08da_vE_uttHJWQw0eO5Ve3q14VqTAw6_o-ziladdA
2021-12-09 22:54:17 SUCCESS
FAPIBrazilChangeConsentStatusToAuthorized
Changed consent status to AUTHORISED
consent
{
  "data": {
    "consentId": "urn:conformance.oidf:dEw82wAIdm",
    "creationDateTime": "2021-12-09T22:54:16Z",
    "status": "AUTHORISED",
    "statusUpdateDateTime": "2021-12-09T22:54:17Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2021-12-10T00:54:16Z",
    "transactionFromDateTime": "2021-12-09T22:49:16Z",
    "transactionToDateTime": "2021-12-10T00:54:16Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/geruconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2021-12-09T22:54:16Z"
  }
}
2021-12-09 22:54:17 SUCCESS
CreateAuthorizationEndpointResponseParams
Added authorization_endpoint_response_params to environment
params
{
  "redirect_uri": "https://scd-open-banking-frontend.dev.scd.open-co.tech",
  "state": "LlO210yF0EDRQWcUFzb8EZot9aoOJw8SciWFX1jCsuo"
}
2021-12-09 22:54:17 SUCCESS
AddCodeToAuthorizationEndpointResponseParams
Added code to authorization endpoint response params
authorization_endpoint_response_params
{
  "redirect_uri": "https://scd-open-banking-frontend.dev.scd.open-co.tech",
  "state": "LlO210yF0EDRQWcUFzb8EZot9aoOJw8SciWFX1jCsuo",
  "code": "k8W9UWTjpXhYWzJXK5XRyu85KofJhIUK"
}
2021-12-09 22:54:17 SUCCESS
AddIdTokenToAuthorizationEndpointResponseParams
Added id_token to authorization endpoint response params
authorization_endpoint_response_params
{
  "redirect_uri": "https://scd-open-banking-frontend.dev.scd.open-co.tech",
  "state": "LlO210yF0EDRQWcUFzb8EZot9aoOJw8SciWFX1jCsuo",
  "code": "k8W9UWTjpXhYWzJXK5XRyu85KofJhIUK",
  "id_token": "eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6ImdlcnUtYmFuayIsImNfaGFzaCI6IlMyOTNoR2pyQ3F3a1poTVlWMmFuQ2ciLCJhY3IiOiJ1cm46YnJhc2lsOm9wZW5iYW5raW5nOmxvYTIiLCJzX2hhc2giOiJVRDEwNjFxRzVraDBOMzRvRTgzQ0dRIiwiaXNzIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL2dlcnVcLyIsImV4cCI6MTYzOTA5MDc1Nywibm9uY2UiOiI3OHQzYmtwZzdER04xLWg2NDBrOExSdzg5U09NQWFWMmJPaUtfODJkck1RIiwiaWF0IjoxNjM5MDkwNDU3fQ.pJPTGbbCeCvwc8zfHJVWzsY1w9mHmVqJmxWWrINnCK4qvvPTNUhP50JBCMgLDFj4_iwwgUjr-_Xg6ThXrEro0jo0lC7ECm5NZPddcpxfWwje83w2Ppjr4Jmyny1spLmwjXsvjy8MoFK5YcRPDJd8_F0w9E4xo7O3K6GBGe_E3RAoj0X1eHCPFw3JwXEXuAIWTQV8jbbGlx8yqN13eaDlyVPkFmI-rwbPe-MaSW2d3HHJEx7oTit64mtwE3hvjSDsuc_EJPI-cnWrQ2nF5ggPRd9Q7hKtXjfR938HR8OuOJed08da_vE_uttHJWQw0eO5Ve3q14VqTAw6_o-ziladdA"
}
2021-12-09 22:54:17
SendAuthorizationResponseWithResponseModeFragment
Redirecting back to client
uri
https://scd-open-banking-frontend.dev.scd.open-co.tech#state=LlO210yF0EDRQWcUFzb8EZot9aoOJw8SciWFX1jCsuo&code=k8W9UWTjpXhYWzJXK5XRyu85KofJhIUK&id_token=eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6ImdlcnUtYmFuayIsImNfaGFzaCI6IlMyOTNoR2pyQ3F3a1poTVlWMmFuQ2ciLCJhY3IiOiJ1cm46YnJhc2lsOm9wZW5iYW5raW5nOmxvYTIiLCJzX2hhc2giOiJVRDEwNjFxRzVraDBOMzRvRTgzQ0dRIiwiaXNzIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL2dlcnVcLyIsImV4cCI6MTYzOTA5MDc1Nywibm9uY2UiOiI3OHQzYmtwZzdER04xLWg2NDBrOExSdzg5U09NQWFWMmJPaUtfODJkck1RIiwiaWF0IjoxNjM5MDkwNDU3fQ.pJPTGbbCeCvwc8zfHJVWzsY1w9mHmVqJmxWWrINnCK4qvvPTNUhP50JBCMgLDFj4_iwwgUjr-_Xg6ThXrEro0jo0lC7ECm5NZPddcpxfWwje83w2Ppjr4Jmyny1spLmwjXsvjy8MoFK5YcRPDJd8_F0w9E4xo7O3K6GBGe_E3RAoj0X1eHCPFw3JwXEXuAIWTQV8jbbGlx8yqN13eaDlyVPkFmI-rwbPe-MaSW2d3HHJEx7oTit64mtwE3hvjSDsuc_EJPI-cnWrQ2nF5ggPRd9Q7hKtXjfR938HR8OuOJed08da_vE_uttHJWQw0eO5Ve3q14VqTAw6_o-ziladdA
2021-12-09 22:54:17 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance UisCUKUCH9FYlkZ
outgoing
org.springframework.web.servlet.view.RedirectView: [RedirectView]; URL [https://scd-open-banking-frontend.dev.scd.open-co.tech#state=LlO210yF0EDRQWcUFzb8EZot9aoOJw8SciWFX1jCsuo&code=k8W9UWTjpXhYWzJXK5XRyu85KofJhIUK&id_token=eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6ImdlcnUtYmFuayIsImNfaGFzaCI6IlMyOTNoR2pyQ3F3a1poTVlWMmFuQ2ciLCJhY3IiOiJ1cm46YnJhc2lsOm9wZW5iYW5raW5nOmxvYTIiLCJzX2hhc2giOiJVRDEwNjFxRzVraDBOMzRvRTgzQ0dRIiwiaXNzIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL2dlcnVcLyIsImV4cCI6MTYzOTA5MDc1Nywibm9uY2UiOiI3OHQzYmtwZzdER04xLWg2NDBrOExSdzg5U09NQWFWMmJPaUtfODJkck1RIiwiaWF0IjoxNjM5MDkwNDU3fQ.pJPTGbbCeCvwc8zfHJVWzsY1w9mHmVqJmxWWrINnCK4qvvPTNUhP50JBCMgLDFj4_iwwgUjr-_Xg6ThXrEro0jo0lC7ECm5NZPddcpxfWwje83w2Ppjr4Jmyny1spLmwjXsvjy8MoFK5YcRPDJd8_F0w9E4xo7O3K6GBGe_E3RAoj0X1eHCPFw3JwXEXuAIWTQV8jbbGlx8yqN13eaDlyVPkFmI-rwbPe-MaSW2d3HHJEx7oTit64mtwE3hvjSDsuc_EJPI-cnWrQ2nF5ggPRd9Q7hKtXjfR938HR8OuOJed08da_vE_uttHJWQw0eO5Ve3q14VqTAw6_o-ziladdA]
outgoing_path
authorize
2021-12-09 22:54:17 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance UisCUKUCH9FYlkZ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.7.4 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/geru/.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-09 22:54:17 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-09 22:54:17 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance UisCUKUCH9FYlkZ
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/geru/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/geru/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/geru/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/geru/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/geru/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/geru/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/userinfo",
    "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/par"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ],
  "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test/a/geru/par",
  "require_pushed_authorization_requests": true,
  "response_types_supported": [
    "code id_token"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256"
  ]
}
outgoing_path
.well-known/openid-configuration
2021-12-09 22:54:17 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance UisCUKUCH9FYlkZ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.7.4 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/geru/jwks
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-09 22:54:17 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-09 22:54:17 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance UisCUKUCH9FYlkZ
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "alg": "PS256",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "alg": "RSA-OAEP",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
outgoing_path
jwks
2021-12-09 22:54:17 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance UisCUKUCH9FYlkZ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.7.4 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded",
  "accept-encoding": "gzip, deflate, br",
  "content-length": "1205",
  "connection": "close"
}
incoming_path
/test-mtls/a/geru/token
incoming_body_form_params
{
  "grant_type": "authorization_code",
  "code": "k8W9UWTjpXhYWzJXK5XRyu85KofJhIUK",
  "redirect_uri": "https://scd-open-banking-frontend.dev.scd.open-co.tech",
  "code_verifier": "lEsNj-wk_8J6B3RRe83EolortaNDzkewTdHoPSTMl-M",
  "client_id": "geru-bank",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImI5ZGRlNGZjOGE2ZGVlYzUwNDRhOTk0ZGExMTliNzNkMDA3ZGIzMGQwOTc4Zjc4YmZiMTY3NmRiNDE1MGIzMjMifQ.eyJpYXQiOjE2MzkwOTA0NTcsImV4cCI6MTYzOTA5MDUxNywianRpIjoiLTVDbnJhLV8zTzBXSjdqS2t4a2F0RmptY3NxN2VKWUpWaDVYX3JWT1lBWSIsImlzcyI6ImdlcnUtYmFuayIsInN1YiI6ImdlcnUtYmFuayIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL2dlcnUvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9nZXJ1L3Rva2VuIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL2dlcnUvdG9rZW4iXX0.CjsZNRrmkOdBiXAsuEEWE8NQ4h1uEWum3HeEORYuiEJZqREVfltWQx_-KV_IPgCw1QbDADfY7gk4AgWnxWMOaWNwlm5sn18v8ESOSqrzFWP6Fe_9452THUvHJMKAx9AE-CK5VH5OtCAtKbfb8WWZ7mTu3YegH0-nGcGDY4PCVxf5BVkgipD5v4ANTEWQECWbFwZu8Q_1myICpjpj0tfJ-qV1oImhXryV3yxOvPgknFr4YHJ3a8Z-CJQkZxMphzLzJDYU08pIB8f_DwkYhH7ioemhsLBiaaRFD3R8JO2x41J85ncPBJLb5fvFSAndfiuIVoNsJHz3NO85M6B6eYAczg",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4 MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00 ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza 6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7 sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514 EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4 vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi 99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa HI5ipvGg/0g= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
grant_type=authorization_code&code=k8W9UWTjpXhYWzJXK5XRyu85KofJhIUK&redirect_uri=https%3A%2F%2Fscd-open-banking-frontend.dev.scd.open-co.tech&code_verifier=lEsNj-wk_8J6B3RRe83EolortaNDzkewTdHoPSTMl-M&client_id=geru-bank&client_assertion=eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImI5ZGRlNGZjOGE2ZGVlYzUwNDRhOTk0ZGExMTliNzNkMDA3ZGIzMGQwOTc4Zjc4YmZiMTY3NmRiNDE1MGIzMjMifQ.eyJpYXQiOjE2MzkwOTA0NTcsImV4cCI6MTYzOTA5MDUxNywianRpIjoiLTVDbnJhLV8zTzBXSjdqS2t4a2F0RmptY3NxN2VKWUpWaDVYX3JWT1lBWSIsImlzcyI6ImdlcnUtYmFuayIsInN1YiI6ImdlcnUtYmFuayIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL2dlcnUvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9nZXJ1L3Rva2VuIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL2dlcnUvdG9rZW4iXX0.CjsZNRrmkOdBiXAsuEEWE8NQ4h1uEWum3HeEORYuiEJZqREVfltWQx_-KV_IPgCw1QbDADfY7gk4AgWnxWMOaWNwlm5sn18v8ESOSqrzFWP6Fe_9452THUvHJMKAx9AE-CK5VH5OtCAtKbfb8WWZ7mTu3YegH0-nGcGDY4PCVxf5BVkgipD5v4ANTEWQECWbFwZu8Q_1myICpjpj0tfJ-qV1oImhXryV3yxOvPgknFr4YHJ3a8Z-CJQkZxMphzLzJDYU08pIB8f_DwkYhH7ioemhsLBiaaRFD3R8JO2x41J85ncPBJLb5fvFSAndfiuIVoNsJHz3NO85M6B6eYAczg&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2021-12-09 22:54:17 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2021-12-09 22:54:17 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4 MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00 ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza 6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7 sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514 EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4 vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi 99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa HI5ipvGg/0g\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4\nMDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS\nRVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj\nY2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz\nODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB\nAxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00\nZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH\nMpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza\n6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf\nZ0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk\nj7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK\ntC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY\nUV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW\nBBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7\nsM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw\nLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC\nMECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls\nLm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud\nDwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU\nMIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD\nZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj\nZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z\nIHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr\nIFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp\ndHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy\ndGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE\nBggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy\nYXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514\nEpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4\nvv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF\nNzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi\n99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M\nRyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa\nHI5ipvGg/0g\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003d73885603-f3ff-41bf-b2b2-4f7ca9fe6076,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3337373633383437303030313338,CN\u003dgeru.com.br,OU\u003d0ca05092-025f-47c4-b878-4a03c150cccf,O\u003dGERU SOCIEDADE DE CREDITO DIRETO,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "geru.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2021-12-09 22:54:17 SUCCESS
CheckForClientCertificate
Found client certificate
2021-12-09 22:54:17 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4
MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS
RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj
Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz
ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB
AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00
ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH
MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza
6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf
Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk
j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK
tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY
UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW
BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7
sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw
LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC
MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls
Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud
DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU
MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD
ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj
ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z
IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr
IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp
dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy
dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE
BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy
YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514
EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4
vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF
NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi
99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M
RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa
HI5ipvGg/0g=
-----END CERTIFICATE-----
2021-12-09 22:54:17 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImI5ZGRlNGZjOGE2ZGVlYzUwNDRhOTk0ZGExMTliNzNkMDA3ZGIzMGQwOTc4Zjc4YmZiMTY3NmRiNDE1MGIzMjMifQ.eyJpYXQiOjE2MzkwOTA0NTcsImV4cCI6MTYzOTA5MDUxNywianRpIjoiLTVDbnJhLV8zTzBXSjdqS2t4a2F0RmptY3NxN2VKWUpWaDVYX3JWT1lBWSIsImlzcyI6ImdlcnUtYmFuayIsInN1YiI6ImdlcnUtYmFuayIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL2dlcnUvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9nZXJ1L3Rva2VuIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL2dlcnUvdG9rZW4iXX0.CjsZNRrmkOdBiXAsuEEWE8NQ4h1uEWum3HeEORYuiEJZqREVfltWQx_-KV_IPgCw1QbDADfY7gk4AgWnxWMOaWNwlm5sn18v8ESOSqrzFWP6Fe_9452THUvHJMKAx9AE-CK5VH5OtCAtKbfb8WWZ7mTu3YegH0-nGcGDY4PCVxf5BVkgipD5v4ANTEWQECWbFwZu8Q_1myICpjpj0tfJ-qV1oImhXryV3yxOvPgknFr4YHJ3a8Z-CJQkZxMphzLzJDYU08pIB8f_DwkYhH7ioemhsLBiaaRFD3R8JO2x41J85ncPBJLb5fvFSAndfiuIVoNsJHz3NO85M6B6eYAczg",
  "header": {
    "kid": "b9dde4fc8a6deec5044a994da119b73d007db30d0978f78bfb1676db4150b323",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "geru-bank",
    "aud": [
      "https://www.certification.openid.net/test/a/geru/",
      "https://www.certification.openid.net/test/a/geru/token",
      "https://www.certification.openid.net/test-mtls/a/geru/token"
    ],
    "iss": "geru-bank",
    "exp": 1639090517,
    "iat": 1639090457,
    "jti": "-5Cnra-_3O0WJ7jKkxkatFjmcsq7eJYJVh5X_rVOYAY"
  }
}
2021-12-09 22:54:17
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2021-12-09 22:54:17 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImI5ZGRlNGZjOGE2ZGVlYzUwNDRhOTk0ZGExMTliNzNkMDA3ZGIzMGQwOTc4Zjc4YmZiMTY3NmRiNDE1MGIzMjMifQ.eyJpYXQiOjE2MzkwOTA0NTcsImV4cCI6MTYzOTA5MDUxNywianRpIjoiLTVDbnJhLV8zTzBXSjdqS2t4a2F0RmptY3NxN2VKWUpWaDVYX3JWT1lBWSIsImlzcyI6ImdlcnUtYmFuayIsInN1YiI6ImdlcnUtYmFuayIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL2dlcnUvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9nZXJ1L3Rva2VuIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL2dlcnUvdG9rZW4iXX0.CjsZNRrmkOdBiXAsuEEWE8NQ4h1uEWum3HeEORYuiEJZqREVfltWQx_-KV_IPgCw1QbDADfY7gk4AgWnxWMOaWNwlm5sn18v8ESOSqrzFWP6Fe_9452THUvHJMKAx9AE-CK5VH5OtCAtKbfb8WWZ7mTu3YegH0-nGcGDY4PCVxf5BVkgipD5v4ANTEWQECWbFwZu8Q_1myICpjpj0tfJ-qV1oImhXryV3yxOvPgknFr4YHJ3a8Z-CJQkZxMphzLzJDYU08pIB8f_DwkYhH7ioemhsLBiaaRFD3R8JO2x41J85ncPBJLb5fvFSAndfiuIVoNsJHz3NO85M6B6eYAczg
2021-12-09 22:54:17 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-12-09 22:54:17 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2021-12-09 22:54:17 SUCCESS
ValidateAuthorizationCode
Found authorization code
authorization_code
k8W9UWTjpXhYWzJXK5XRyu85KofJhIUK
2021-12-09 22:54:17 SUCCESS
ValidateRedirectUri
Found redirect uri
redirect_uri
https://scd-open-banking-frontend.dev.scd.open-co.tech
2021-12-09 22:54:17 SUCCESS
ValidateCodeVerifierWithS256
Validated code_verifier successfully
code_challenge_method
S256
code_verifier
lEsNj-wk_8J6B3RRe83EolortaNDzkewTdHoPSTMl-M
code_challenge
vfRRf1-TbyuW0_2a-Gb5vrJiiNI8iPkoXETXvVU27n8
2021-12-09 22:54:17 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
cvNoljWysyffDCi2Nk2wXzYZw6b5LhYkjgwAMTLllc3s4QEPsQ
2021-12-09 22:54:17 SUCCESS
CalculateAtHash
Successful at_hash encoding
at_hash
6Q7RCxqdej7RI1qRRlY2oA
2021-12-09 22:54:17
CreateRefreshToken
Created refresh token
refresh_token
JNzVzWhEukqxfVRohkvgcUhOIizDMoIjCUGFCYvifnBYaMbucb0441563489/**<-
2021-12-09 22:54:17 SUCCESS
GenerateIdTokenClaims
Created ID Token Claims
iss
https://www.certification.openid.net/test/a/geru/
sub
user-subject-1234531
aud
geru-bank
nonce
78t3bkpg7DGN1-h640k8LRw89SOMAaV2bOiK_82drMQ
iat
1639090457
exp
1639090757
2021-12-09 22:54:17 SUCCESS
FAPIBrazilAddCPFAndCPNJToIdTokenClaims
Added claims to id_token claims
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/geru/",
  "sub": "user-subject-1234531",
  "aud": "geru-bank",
  "nonce": "78t3bkpg7DGN1-h640k8LRw89SOMAaV2bOiK_82drMQ",
  "iat": 1639090457,
  "exp": 1639090757
}
2021-12-09 22:54:17 SUCCESS
AddAtHashToIdTokenClaims
Added at_hash to ID token claims
at_hash
6Q7RCxqdej7RI1qRRlY2oA
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/geru/",
  "sub": "user-subject-1234531",
  "aud": "geru-bank",
  "nonce": "78t3bkpg7DGN1-h640k8LRw89SOMAaV2bOiK_82drMQ",
  "iat": 1639090457,
  "exp": 1639090757,
  "at_hash": "6Q7RCxqdej7RI1qRRlY2oA"
}
2021-12-09 22:54:17 SUCCESS
FAPIBrazilAddACRClaimToIdTokenClaims
Added acr value to id_token_claims
acr_value
urn:brasil:openbanking:loa2
claims
{
  "iss": "https://www.certification.openid.net/test/a/geru/",
  "sub": "user-subject-1234531",
  "aud": "geru-bank",
  "nonce": "78t3bkpg7DGN1-h640k8LRw89SOMAaV2bOiK_82drMQ",
  "iat": 1639090457,
  "exp": 1639090757,
  "at_hash": "6Q7RCxqdej7RI1qRRlY2oA",
  "acr": "urn:brasil:openbanking:loa2"
}
2021-12-09 22:54:18 SUCCESS
SignIdToken
Signed the ID token
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdF9oYXNoIjoiNlE3UkN4cWRlajdSSTFxUlJsWTJvQSIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoiZ2VydS1iYW5rIiwiYWNyIjoidXJuOmJyYXNpbDpvcGVuYmFua2luZzpsb2EyIiwiaXNzIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL2dlcnVcLyIsImV4cCI6MTYzOTA5MDc1Nywibm9uY2UiOiI3OHQzYmtwZzdER04xLWg2NDBrOExSdzg5U09NQWFWMmJPaUtfODJkck1RIiwiaWF0IjoxNjM5MDkwNDU3fQ.OM6s2FfGtU85GrbwrxoOr46tR6uaQworaShq6_JfGctep6TmUTMGD9DJ-QGjJ3kYWqPMJ0MGChf8xuUTRXCO8cVBGzpoEkkla8vgK_3yEPir2Yn26LzukiBO7MqZaoDOzvk1RIk9IbTTFnSHu03MMiBaVGtypHMAG4RmQzaFT0y__WJ6HLgaKN1qmvjJph4Nu1WgYxWFD9SuFFqgOlPifK4RHsTYEPxOOBYsQGjB9m8J5OToX83u_pbaHhMbp2HJE9gbahRpV7sjp12i2aV9jIEaGJ9nbKKcXxmNaGBrVUhwOi2BEcr9oRh-aEZTXSkacu-gJqyfM0EgvHozQYewbA
2021-12-09 22:54:18 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
cvNoljWysyffDCi2Nk2wXzYZw6b5LhYkjgwAMTLllc3s4QEPsQ
token_type
Bearer
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdF9oYXNoIjoiNlE3UkN4cWRlajdSSTFxUlJsWTJvQSIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoiZ2VydS1iYW5rIiwiYWNyIjoidXJuOmJyYXNpbDpvcGVuYmFua2luZzpsb2EyIiwiaXNzIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL2dlcnVcLyIsImV4cCI6MTYzOTA5MDc1Nywibm9uY2UiOiI3OHQzYmtwZzdER04xLWg2NDBrOExSdzg5U09NQWFWMmJPaUtfODJkck1RIiwiaWF0IjoxNjM5MDkwNDU3fQ.OM6s2FfGtU85GrbwrxoOr46tR6uaQworaShq6_JfGctep6TmUTMGD9DJ-QGjJ3kYWqPMJ0MGChf8xuUTRXCO8cVBGzpoEkkla8vgK_3yEPir2Yn26LzukiBO7MqZaoDOzvk1RIk9IbTTFnSHu03MMiBaVGtypHMAG4RmQzaFT0y__WJ6HLgaKN1qmvjJph4Nu1WgYxWFD9SuFFqgOlPifK4RHsTYEPxOOBYsQGjB9m8J5OToX83u_pbaHhMbp2HJE9gbahRpV7sjp12i2aV9jIEaGJ9nbKKcXxmNaGBrVUhwOi2BEcr9oRh-aEZTXSkacu-gJqyfM0EgvHozQYewbA
refresh_token
JNzVzWhEukqxfVRohkvgcUhOIizDMoIjCUGFCYvifnBYaMbucb0441563489/**<-
scope
openid consent:urn:conformance.oidf:dEw82wAIdm accounts resources
2021-12-09 22:54:18
RemoveIssuedAccessTokenFromEnvironment
Removed access_token and token_type from environment
2021-12-09 22:54:18 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance UisCUKUCH9FYlkZ
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "cvNoljWysyffDCi2Nk2wXzYZw6b5LhYkjgwAMTLllc3s4QEPsQ",
  "token_type": "Bearer",
  "id_token": "eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdF9oYXNoIjoiNlE3UkN4cWRlajdSSTFxUlJsWTJvQSIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoiZ2VydS1iYW5rIiwiYWNyIjoidXJuOmJyYXNpbDpvcGVuYmFua2luZzpsb2EyIiwiaXNzIjoiaHR0cHM6XC9cL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXRcL3Rlc3RcL2FcL2dlcnVcLyIsImV4cCI6MTYzOTA5MDc1Nywibm9uY2UiOiI3OHQzYmtwZzdER04xLWg2NDBrOExSdzg5U09NQWFWMmJPaUtfODJkck1RIiwiaWF0IjoxNjM5MDkwNDU3fQ.OM6s2FfGtU85GrbwrxoOr46tR6uaQworaShq6_JfGctep6TmUTMGD9DJ-QGjJ3kYWqPMJ0MGChf8xuUTRXCO8cVBGzpoEkkla8vgK_3yEPir2Yn26LzukiBO7MqZaoDOzvk1RIk9IbTTFnSHu03MMiBaVGtypHMAG4RmQzaFT0y__WJ6HLgaKN1qmvjJph4Nu1WgYxWFD9SuFFqgOlPifK4RHsTYEPxOOBYsQGjB9m8J5OToX83u_pbaHhMbp2HJE9gbahRpV7sjp12i2aV9jIEaGJ9nbKKcXxmNaGBrVUhwOi2BEcr9oRh-aEZTXSkacu-gJqyfM0EgvHozQYewbA",
  "refresh_token": "JNzVzWhEukqxfVRohkvgcUhOIizDMoIjCUGFCYvifnBYaMbucb0441563489/**\u003c-",
  "scope": "openid consent:urn:conformance.oidf:dEw82wAIdm accounts resources"
}
outgoing_path
token
2021-12-09 22:54:18 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance UisCUKUCH9FYlkZ
incoming_headers
{
  "host": "www.certification.openid.net",
  "authorization": "Bearer cvNoljWysyffDCi2Nk2wXzYZw6b5LhYkjgwAMTLllc3s4QEPsQ",
  "user-agent": "PostmanRuntime/7.28.4",
  "accept": "*/*",
  "cache-control": "no-cache",
  "postman-token": "c9ff8a0e-745a-4a89-b4b6-46712c180e1f",
  "accept-encoding": "gzip, deflate, br",
  "cookie": "JSESSIONID\u003d12B30FBE0152E5EA2C1837DF82D02952",
  "connection": "close"
}
incoming_path
/test-mtls/a/geru/accounts/v1/accounts
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4 MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00 ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza 6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7 sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514 EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4 vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi 99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa HI5ipvGg/0g= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-09 22:54:18 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Accounts endpoint (always rejected)
2021-12-09 22:54:18 SUCCESS
LogAccessTokenAlwaysRejectedToForceARefreshGrant
This call will be always rejected. The client must obtain a new access token twice using the refresh_token
2021-12-09 22:54:18 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance UisCUKUCH9FYlkZ
outgoing_status_code
401
outgoing_headers
{
  "WWW-Authenticate": [
    "Bearer realm\u003d\"conformancesuite\", error\u003d\"invalid_token\", error_description\u003d\"Invalid access token. This test requires you to obtain a new access token twice using the refresh_token\""
  ]
}
outgoing_body
outgoing_path
accounts/v1/accounts
2021-12-09 22:54:18 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance UisCUKUCH9FYlkZ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.7.4 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/geru/.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-09 22:54:18 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-09 22:54:18 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance UisCUKUCH9FYlkZ
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/geru/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/geru/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/geru/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/geru/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/geru/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/geru/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/userinfo",
    "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/par"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ],
  "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test/a/geru/par",
  "require_pushed_authorization_requests": true,
  "response_types_supported": [
    "code id_token"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256"
  ]
}
outgoing_path
.well-known/openid-configuration
2021-12-09 22:54:19 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance UisCUKUCH9FYlkZ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.7.4 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded",
  "accept-encoding": "gzip, deflate, br",
  "content-length": "1114",
  "connection": "close"
}
incoming_path
/test-mtls/a/geru/token
incoming_body_form_params
{
  "grant_type": "refresh_token",
  "refresh_token": "JNzVzWhEukqxfVRohkvgcUhOIizDMoIjCUGFCYvifnBYaMbucb0441563489/**\u003c-",
  "client_id": "geru-bank",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImI5ZGRlNGZjOGE2ZGVlYzUwNDRhOTk0ZGExMTliNzNkMDA3ZGIzMGQwOTc4Zjc4YmZiMTY3NmRiNDE1MGIzMjMifQ.eyJpYXQiOjE2MzkwOTA0NTgsImV4cCI6MTYzOTA5MDUxOCwianRpIjoiRndjT1hreFpIRmZESS1qRWQwSGRPV1VncUhmMDcyWGRFcm1DdHVDU3oyQSIsImlzcyI6ImdlcnUtYmFuayIsInN1YiI6ImdlcnUtYmFuayIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL2dlcnUvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9nZXJ1L3Rva2VuIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL2dlcnUvdG9rZW4iXX0.N7cVarfzwtl5g3LCyqjo43SpyUTCvFN2NM7qkFRcPuHUtcNU5BXuUOKdjwlStCkdMB-Is1CWKGbCengs1vb7QDvikJQnUhLm-MkI8Czs_Vp42_6VTOF7Ic7vZ9Er0txp9qGcvcFAqzweYnJKmy5Z9kyRC-pyhop-fKTfCZSb73Q0m-Wd3MmBOV5l4SqH7kq1KiWJzr88jZEarlMu4sGT0E30-_YXf5afVCNRjs2tU2OWBGbKnRcMfsGwiZ8ArYluBespnUzAYX7p5Ta7l9aMWTsxN0zLeUeOaUJMCdNMLugZvT9b03YT1cL6XqYp6wtpjBbp0ZpLEkAto4E8GCZ_Mg",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4 MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00 ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza 6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7 sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514 EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4 vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi 99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa HI5ipvGg/0g= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
grant_type=refresh_token&refresh_token=JNzVzWhEukqxfVRohkvgcUhOIizDMoIjCUGFCYvifnBYaMbucb0441563489%2F**%3C-&client_id=geru-bank&client_assertion=eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImI5ZGRlNGZjOGE2ZGVlYzUwNDRhOTk0ZGExMTliNzNkMDA3ZGIzMGQwOTc4Zjc4YmZiMTY3NmRiNDE1MGIzMjMifQ.eyJpYXQiOjE2MzkwOTA0NTgsImV4cCI6MTYzOTA5MDUxOCwianRpIjoiRndjT1hreFpIRmZESS1qRWQwSGRPV1VncUhmMDcyWGRFcm1DdHVDU3oyQSIsImlzcyI6ImdlcnUtYmFuayIsInN1YiI6ImdlcnUtYmFuayIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL2dlcnUvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9nZXJ1L3Rva2VuIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL2dlcnUvdG9rZW4iXX0.N7cVarfzwtl5g3LCyqjo43SpyUTCvFN2NM7qkFRcPuHUtcNU5BXuUOKdjwlStCkdMB-Is1CWKGbCengs1vb7QDvikJQnUhLm-MkI8Czs_Vp42_6VTOF7Ic7vZ9Er0txp9qGcvcFAqzweYnJKmy5Z9kyRC-pyhop-fKTfCZSb73Q0m-Wd3MmBOV5l4SqH7kq1KiWJzr88jZEarlMu4sGT0E30-_YXf5afVCNRjs2tU2OWBGbKnRcMfsGwiZ8ArYluBespnUzAYX7p5Ta7l9aMWTsxN0zLeUeOaUJMCdNMLugZvT9b03YT1cL6XqYp6wtpjBbp0ZpLEkAto4E8GCZ_Mg&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2021-12-09 22:54:19 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2021-12-09 22:54:19 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4 MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00 ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza 6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7 sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514 EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4 vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi 99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa HI5ipvGg/0g\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4\nMDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS\nRVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj\nY2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz\nODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB\nAxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00\nZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH\nMpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza\n6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf\nZ0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk\nj7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK\ntC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY\nUV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW\nBBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7\nsM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw\nLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC\nMECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls\nLm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud\nDwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU\nMIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD\nZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj\nZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z\nIHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr\nIFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp\ndHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy\ndGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE\nBggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy\nYXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514\nEpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4\nvv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF\nNzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi\n99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M\nRyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa\nHI5ipvGg/0g\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003d73885603-f3ff-41bf-b2b2-4f7ca9fe6076,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3337373633383437303030313338,CN\u003dgeru.com.br,OU\u003d0ca05092-025f-47c4-b878-4a03c150cccf,O\u003dGERU SOCIEDADE DE CREDITO DIRETO,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "geru.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2021-12-09 22:54:19 SUCCESS
CheckForClientCertificate
Found client certificate
2021-12-09 22:54:19 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4
MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS
RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj
Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz
ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB
AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00
ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH
MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza
6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf
Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk
j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK
tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY
UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW
BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7
sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw
LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC
MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls
Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud
DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU
MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD
ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj
ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z
IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr
IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp
dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy
dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE
BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy
YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514
EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4
vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF
NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi
99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M
RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa
HI5ipvGg/0g=
-----END CERTIFICATE-----
2021-12-09 22:54:19 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImI5ZGRlNGZjOGE2ZGVlYzUwNDRhOTk0ZGExMTliNzNkMDA3ZGIzMGQwOTc4Zjc4YmZiMTY3NmRiNDE1MGIzMjMifQ.eyJpYXQiOjE2MzkwOTA0NTgsImV4cCI6MTYzOTA5MDUxOCwianRpIjoiRndjT1hreFpIRmZESS1qRWQwSGRPV1VncUhmMDcyWGRFcm1DdHVDU3oyQSIsImlzcyI6ImdlcnUtYmFuayIsInN1YiI6ImdlcnUtYmFuayIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL2dlcnUvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9nZXJ1L3Rva2VuIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL2dlcnUvdG9rZW4iXX0.N7cVarfzwtl5g3LCyqjo43SpyUTCvFN2NM7qkFRcPuHUtcNU5BXuUOKdjwlStCkdMB-Is1CWKGbCengs1vb7QDvikJQnUhLm-MkI8Czs_Vp42_6VTOF7Ic7vZ9Er0txp9qGcvcFAqzweYnJKmy5Z9kyRC-pyhop-fKTfCZSb73Q0m-Wd3MmBOV5l4SqH7kq1KiWJzr88jZEarlMu4sGT0E30-_YXf5afVCNRjs2tU2OWBGbKnRcMfsGwiZ8ArYluBespnUzAYX7p5Ta7l9aMWTsxN0zLeUeOaUJMCdNMLugZvT9b03YT1cL6XqYp6wtpjBbp0ZpLEkAto4E8GCZ_Mg",
  "header": {
    "kid": "b9dde4fc8a6deec5044a994da119b73d007db30d0978f78bfb1676db4150b323",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "geru-bank",
    "aud": [
      "https://www.certification.openid.net/test/a/geru/",
      "https://www.certification.openid.net/test/a/geru/token",
      "https://www.certification.openid.net/test-mtls/a/geru/token"
    ],
    "iss": "geru-bank",
    "exp": 1639090518,
    "iat": 1639090458,
    "jti": "FwcOXkxZHFfDI-jEd0HdOWUgqHf072XdErmCtuCSz2A"
  }
}
2021-12-09 22:54:19
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2021-12-09 22:54:19 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImI5ZGRlNGZjOGE2ZGVlYzUwNDRhOTk0ZGExMTliNzNkMDA3ZGIzMGQwOTc4Zjc4YmZiMTY3NmRiNDE1MGIzMjMifQ.eyJpYXQiOjE2MzkwOTA0NTgsImV4cCI6MTYzOTA5MDUxOCwianRpIjoiRndjT1hreFpIRmZESS1qRWQwSGRPV1VncUhmMDcyWGRFcm1DdHVDU3oyQSIsImlzcyI6ImdlcnUtYmFuayIsInN1YiI6ImdlcnUtYmFuayIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL2dlcnUvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9nZXJ1L3Rva2VuIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL2dlcnUvdG9rZW4iXX0.N7cVarfzwtl5g3LCyqjo43SpyUTCvFN2NM7qkFRcPuHUtcNU5BXuUOKdjwlStCkdMB-Is1CWKGbCengs1vb7QDvikJQnUhLm-MkI8Czs_Vp42_6VTOF7Ic7vZ9Er0txp9qGcvcFAqzweYnJKmy5Z9kyRC-pyhop-fKTfCZSb73Q0m-Wd3MmBOV5l4SqH7kq1KiWJzr88jZEarlMu4sGT0E30-_YXf5afVCNRjs2tU2OWBGbKnRcMfsGwiZ8ArYluBespnUzAYX7p5Ta7l9aMWTsxN0zLeUeOaUJMCdNMLugZvT9b03YT1cL6XqYp6wtpjBbp0ZpLEkAto4E8GCZ_Mg
2021-12-09 22:54:19 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-12-09 22:54:19 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2021-12-09 22:54:19 SUCCESS
ValidateRefreshToken
refresh_token parameter matches the expected value.
refresh_token
JNzVzWhEukqxfVRohkvgcUhOIizDMoIjCUGFCYvifnBYaMbucb0441563489/**<-
2021-12-09 22:54:19 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
rXMzWZXfqzqDVARkjpIECZjO5jKHOTRuHCDzc3kZ8iekzdMRuw
2021-12-09 22:54:19 SUCCESS
CalculateAtHash
Successful at_hash encoding
at_hash
Ioc33WNi8AYl3trO1b6Cdg
2021-12-09 22:54:19
CreateRefreshToken
Created refresh token
refresh_token
eOzhzsOFqXGlXcHxXAihUkUoqbvaAIeUeDvpUJiIqKgXzBuNjL7106423664^;$>@
2021-12-09 22:54:19 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
rXMzWZXfqzqDVARkjpIECZjO5jKHOTRuHCDzc3kZ8iekzdMRuw
token_type
Bearer
refresh_token
eOzhzsOFqXGlXcHxXAihUkUoqbvaAIeUeDvpUJiIqKgXzBuNjL7106423664^;$>@
scope
openid consent:urn:conformance.oidf:dEw82wAIdm accounts resources
2021-12-09 22:54:19 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance UisCUKUCH9FYlkZ
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "rXMzWZXfqzqDVARkjpIECZjO5jKHOTRuHCDzc3kZ8iekzdMRuw",
  "token_type": "Bearer",
  "refresh_token": "eOzhzsOFqXGlXcHxXAihUkUoqbvaAIeUeDvpUJiIqKgXzBuNjL7106423664^;$\u003e@",
  "scope": "openid consent:urn:conformance.oidf:dEw82wAIdm accounts resources"
}
outgoing_path
token
2021-12-09 22:54:19 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance UisCUKUCH9FYlkZ
incoming_headers
{
  "host": "www.certification.openid.net",
  "authorization": "Bearer rXMzWZXfqzqDVARkjpIECZjO5jKHOTRuHCDzc3kZ8iekzdMRuw",
  "user-agent": "PostmanRuntime/7.28.4",
  "accept": "*/*",
  "cache-control": "no-cache",
  "postman-token": "d83ccf21-fa7f-41a6-ba57-5ffbf4a6d003",
  "accept-encoding": "gzip, deflate, br",
  "cookie": "JSESSIONID\u003d12B30FBE0152E5EA2C1837DF82D02952",
  "connection": "close"
}
incoming_path
/test-mtls/a/geru/accounts/v1/accounts
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4 MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00 ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza 6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7 sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514 EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4 vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi 99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa HI5ipvGg/0g= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-09 22:54:19 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Accounts endpoint (always rejected)
2021-12-09 22:54:19 SUCCESS
LogAccessTokenAlwaysRejectedToForceARefreshGrant
This call will be always rejected. The client must obtain a new access token twice using the refresh_token
2021-12-09 22:54:19 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance UisCUKUCH9FYlkZ
outgoing_status_code
401
outgoing_headers
{
  "WWW-Authenticate": [
    "Bearer realm\u003d\"conformancesuite\", error\u003d\"invalid_token\", error_description\u003d\"Invalid access token. This test requires you to obtain a new access token twice using the refresh_token\""
  ]
}
outgoing_body
outgoing_path
accounts/v1/accounts
2021-12-09 22:54:19 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance UisCUKUCH9FYlkZ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.7.4 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/geru/.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-09 22:54:19 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2021-12-09 22:54:19 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance UisCUKUCH9FYlkZ
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/geru/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/geru/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/geru/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/geru/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/geru/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/geru/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/userinfo",
    "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test-mtls/a/geru/par"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ],
  "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test/a/geru/par",
  "require_pushed_authorization_requests": true,
  "response_types_supported": [
    "code id_token"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256"
  ]
}
outgoing_path
.well-known/openid-configuration
2021-12-09 22:54:19 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance UisCUKUCH9FYlkZ
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.7.4 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded",
  "accept-encoding": "gzip, deflate, br",
  "content-length": "1120",
  "connection": "close"
}
incoming_path
/test-mtls/a/geru/token
incoming_body_form_params
{
  "grant_type": "refresh_token",
  "refresh_token": "eOzhzsOFqXGlXcHxXAihUkUoqbvaAIeUeDvpUJiIqKgXzBuNjL7106423664^;$\u003e@",
  "client_id": "geru-bank",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImI5ZGRlNGZjOGE2ZGVlYzUwNDRhOTk0ZGExMTliNzNkMDA3ZGIzMGQwOTc4Zjc4YmZiMTY3NmRiNDE1MGIzMjMifQ.eyJpYXQiOjE2MzkwOTA0NTksImV4cCI6MTYzOTA5MDUxOSwianRpIjoiTHMyTnUyYnB6Q2huWTZ3cTFSeGNXS0IzUFVRdlBCWmNvTUllN0N6bUloQSIsImlzcyI6ImdlcnUtYmFuayIsInN1YiI6ImdlcnUtYmFuayIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL2dlcnUvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9nZXJ1L3Rva2VuIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL2dlcnUvdG9rZW4iXX0.fdaI9ArDDXB0JDxYMn0HgsKf2FiL6FZvxajymAWQYZ6Lrg5eAUjkSZ1QliJIQKrg9FEFc6jCrbj51elQ4xYZb8aDoUdA0hxTVo4ixZ68r-KWw5aDZiOfyS1rVaTmuu8fOM8jvS7SucUgCpQbHfmTVq7RqFZy23_WIY9yoi2Yi5DXK677rdwk_u8VY6ow3NTP_VeSDOhHCcgqI2TPPc7nZqeuDQ97QL_c21QHRO4gBPgIzLpAWhf_ndw6fgj04_hF0Y7sRhgHm6xIJddrUN1aDZA0Y6Odf-18i35W3GwOqljWJuyz8rDRuqG3-dftNE6-inOyw8pZGl1aiYJbsySFMQ",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4 MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00 ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza 6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7 sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514 EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4 vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi 99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa HI5ipvGg/0g= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
grant_type=refresh_token&refresh_token=eOzhzsOFqXGlXcHxXAihUkUoqbvaAIeUeDvpUJiIqKgXzBuNjL7106423664%5E%3B%24%3E%40&client_id=geru-bank&client_assertion=eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImI5ZGRlNGZjOGE2ZGVlYzUwNDRhOTk0ZGExMTliNzNkMDA3ZGIzMGQwOTc4Zjc4YmZiMTY3NmRiNDE1MGIzMjMifQ.eyJpYXQiOjE2MzkwOTA0NTksImV4cCI6MTYzOTA5MDUxOSwianRpIjoiTHMyTnUyYnB6Q2huWTZ3cTFSeGNXS0IzUFVRdlBCWmNvTUllN0N6bUloQSIsImlzcyI6ImdlcnUtYmFuayIsInN1YiI6ImdlcnUtYmFuayIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL2dlcnUvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9nZXJ1L3Rva2VuIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL2dlcnUvdG9rZW4iXX0.fdaI9ArDDXB0JDxYMn0HgsKf2FiL6FZvxajymAWQYZ6Lrg5eAUjkSZ1QliJIQKrg9FEFc6jCrbj51elQ4xYZb8aDoUdA0hxTVo4ixZ68r-KWw5aDZiOfyS1rVaTmuu8fOM8jvS7SucUgCpQbHfmTVq7RqFZy23_WIY9yoi2Yi5DXK677rdwk_u8VY6ow3NTP_VeSDOhHCcgqI2TPPc7nZqeuDQ97QL_c21QHRO4gBPgIzLpAWhf_ndw6fgj04_hF0Y7sRhgHm6xIJddrUN1aDZA0Y6Odf-18i35W3GwOqljWJuyz8rDRuqG3-dftNE6-inOyw8pZGl1aiYJbsySFMQ&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2021-12-09 22:54:19 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2021-12-09 22:54:19 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4 MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00 ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza 6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7 sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514 EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4 vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi 99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa HI5ipvGg/0g\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4\nMDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS\nRVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj\nY2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz\nODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB\nAxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00\nZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH\nMpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza\n6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf\nZ0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk\nj7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK\ntC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY\nUV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW\nBBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7\nsM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw\nLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC\nMECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls\nLm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud\nDwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU\nMIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD\nZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj\nZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z\nIHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr\nIFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp\ndHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy\ndGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE\nBggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy\nYXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514\nEpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4\nvv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF\nNzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi\n99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M\nRyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa\nHI5ipvGg/0g\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003d73885603-f3ff-41bf-b2b2-4f7ca9fe6076,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3337373633383437303030313338,CN\u003dgeru.com.br,OU\u003d0ca05092-025f-47c4-b878-4a03c150cccf,O\u003dGERU SOCIEDADE DE CREDITO DIRETO,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "geru.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2021-12-09 22:54:19 SUCCESS
CheckForClientCertificate
Found client certificate
2021-12-09 22:54:19 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4
MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS
RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj
Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz
ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB
AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00
ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH
MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza
6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf
Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk
j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK
tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY
UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW
BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7
sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw
LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC
MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls
Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud
DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU
MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD
ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj
ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z
IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr
IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp
dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy
dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE
BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy
YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514
EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4
vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF
NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi
99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M
RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa
HI5ipvGg/0g=
-----END CERTIFICATE-----
2021-12-09 22:54:19 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImI5ZGRlNGZjOGE2ZGVlYzUwNDRhOTk0ZGExMTliNzNkMDA3ZGIzMGQwOTc4Zjc4YmZiMTY3NmRiNDE1MGIzMjMifQ.eyJpYXQiOjE2MzkwOTA0NTksImV4cCI6MTYzOTA5MDUxOSwianRpIjoiTHMyTnUyYnB6Q2huWTZ3cTFSeGNXS0IzUFVRdlBCWmNvTUllN0N6bUloQSIsImlzcyI6ImdlcnUtYmFuayIsInN1YiI6ImdlcnUtYmFuayIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL2dlcnUvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9nZXJ1L3Rva2VuIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL2dlcnUvdG9rZW4iXX0.fdaI9ArDDXB0JDxYMn0HgsKf2FiL6FZvxajymAWQYZ6Lrg5eAUjkSZ1QliJIQKrg9FEFc6jCrbj51elQ4xYZb8aDoUdA0hxTVo4ixZ68r-KWw5aDZiOfyS1rVaTmuu8fOM8jvS7SucUgCpQbHfmTVq7RqFZy23_WIY9yoi2Yi5DXK677rdwk_u8VY6ow3NTP_VeSDOhHCcgqI2TPPc7nZqeuDQ97QL_c21QHRO4gBPgIzLpAWhf_ndw6fgj04_hF0Y7sRhgHm6xIJddrUN1aDZA0Y6Odf-18i35W3GwOqljWJuyz8rDRuqG3-dftNE6-inOyw8pZGl1aiYJbsySFMQ",
  "header": {
    "kid": "b9dde4fc8a6deec5044a994da119b73d007db30d0978f78bfb1676db4150b323",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "geru-bank",
    "aud": [
      "https://www.certification.openid.net/test/a/geru/",
      "https://www.certification.openid.net/test/a/geru/token",
      "https://www.certification.openid.net/test-mtls/a/geru/token"
    ],
    "iss": "geru-bank",
    "exp": 1639090519,
    "iat": 1639090459,
    "jti": "Ls2Nu2bpzChnY6wq1RxcWKB3PUQvPBZcoMIe7CzmIhA"
  }
}
2021-12-09 22:54:19
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2021-12-09 22:54:19 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImI5ZGRlNGZjOGE2ZGVlYzUwNDRhOTk0ZGExMTliNzNkMDA3ZGIzMGQwOTc4Zjc4YmZiMTY3NmRiNDE1MGIzMjMifQ.eyJpYXQiOjE2MzkwOTA0NTksImV4cCI6MTYzOTA5MDUxOSwianRpIjoiTHMyTnUyYnB6Q2huWTZ3cTFSeGNXS0IzUFVRdlBCWmNvTUllN0N6bUloQSIsImlzcyI6ImdlcnUtYmFuayIsInN1YiI6ImdlcnUtYmFuayIsImF1ZCI6WyJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL2dlcnUvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9nZXJ1L3Rva2VuIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL2dlcnUvdG9rZW4iXX0.fdaI9ArDDXB0JDxYMn0HgsKf2FiL6FZvxajymAWQYZ6Lrg5eAUjkSZ1QliJIQKrg9FEFc6jCrbj51elQ4xYZb8aDoUdA0hxTVo4ixZ68r-KWw5aDZiOfyS1rVaTmuu8fOM8jvS7SucUgCpQbHfmTVq7RqFZy23_WIY9yoi2Yi5DXK677rdwk_u8VY6ow3NTP_VeSDOhHCcgqI2TPPc7nZqeuDQ97QL_c21QHRO4gBPgIzLpAWhf_ndw6fgj04_hF0Y7sRhgHm6xIJddrUN1aDZA0Y6Odf-18i35W3GwOqljWJuyz8rDRuqG3-dftNE6-inOyw8pZGl1aiYJbsySFMQ
2021-12-09 22:54:19 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2021-12-09 22:54:19 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2021-12-09 22:54:19 SUCCESS
ValidateRefreshToken
refresh_token parameter matches the expected value.
refresh_token
eOzhzsOFqXGlXcHxXAihUkUoqbvaAIeUeDvpUJiIqKgXzBuNjL7106423664^;$>@
2021-12-09 22:54:19 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
p8xeuAdfW0JEiwHLQlaJKZffGEg6xOPyV1Lz0Fc9LhFNQk9xBi
2021-12-09 22:54:19 SUCCESS
CalculateAtHash
Successful at_hash encoding
at_hash
vRmV9F9qaQ6Oq97rH8YVoQ
2021-12-09 22:54:19
CreateRefreshToken
Created refresh token
refresh_token
fJNWURjfMQCpDtFudXsWMRIttuMHeKeaRmJmPuZQYljxytKrit3848646598",=-&
2021-12-09 22:54:19 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
p8xeuAdfW0JEiwHLQlaJKZffGEg6xOPyV1Lz0Fc9LhFNQk9xBi
token_type
Bearer
refresh_token
fJNWURjfMQCpDtFudXsWMRIttuMHeKeaRmJmPuZQYljxytKrit3848646598",=-&
scope
openid consent:urn:conformance.oidf:dEw82wAIdm accounts resources
2021-12-09 22:54:19 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance UisCUKUCH9FYlkZ
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "p8xeuAdfW0JEiwHLQlaJKZffGEg6xOPyV1Lz0Fc9LhFNQk9xBi",
  "token_type": "Bearer",
  "refresh_token": "fJNWURjfMQCpDtFudXsWMRIttuMHeKeaRmJmPuZQYljxytKrit3848646598\",\u003d-\u0026",
  "scope": "openid consent:urn:conformance.oidf:dEw82wAIdm accounts resources"
}
outgoing_path
token
2021-12-09 22:54:20 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance UisCUKUCH9FYlkZ
incoming_headers
{
  "host": "www.certification.openid.net",
  "authorization": "Bearer p8xeuAdfW0JEiwHLQlaJKZffGEg6xOPyV1Lz0Fc9LhFNQk9xBi",
  "user-agent": "PostmanRuntime/7.28.4",
  "accept": "*/*",
  "cache-control": "no-cache",
  "postman-token": "36fb37d3-804d-427b-8c1e-66595f09dc23",
  "accept-encoding": "gzip, deflate, br",
  "cookie": "JSESSIONID\u003d12B30FBE0152E5EA2C1837DF82D02952",
  "connection": "close"
}
incoming_path
/test-mtls/a/geru/accounts/v1/accounts
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4 MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00 ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza 6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7 sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514 EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4 vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi 99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa HI5ipvGg/0g= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
2021-12-09 22:54:20 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Accounts endpoint
2021-12-09 22:54:20 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4 MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00 ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza 6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7 sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514 EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4 vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi 99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa HI5ipvGg/0g\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4\nMDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS\nRVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj\nY2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz\nODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB\nAxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00\nZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH\nMpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza\n6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf\nZ0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk\nj7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK\ntC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY\nUV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW\nBBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7\nsM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw\nLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC\nMECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls\nLm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud\nDwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU\nMIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD\nZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj\nZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z\nIHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr\nIFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp\ndHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy\ndGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE\nBggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy\nYXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514\nEpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4\nvv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF\nNzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi\n99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M\nRyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa\nHI5ipvGg/0g\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003d73885603-f3ff-41bf-b2b2-4f7ca9fe6076,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3337373633383437303030313338,CN\u003dgeru.com.br,OU\u003d0ca05092-025f-47c4-b878-4a03c150cccf,O\u003dGERU SOCIEDADE DE CREDITO DIRETO,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "geru.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2021-12-09 22:54:20 SUCCESS
CheckForClientCertificate
Found client certificate
2021-12-09 22:54:20 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG9DCCBdygAwIBAgIUHP7pETZ8wo3KhRaFkfUQK7ckwZYwDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAwODE4MDYwMFoXDTIyMTEwNzE4
MDYwMFowggEiMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xKTAnBgNVBAoTIEdFUlUgU09DSUVEQURFIERFIENSRURJVE8gRElS
RVRPMS0wKwYDVQQLEyQwY2EwNTA5Mi0wMjVmLTQ3YzQtYjg3OC00YTAzYzE1MGNj
Y2YxFDASBgNVBAMTC2dlcnUuY29tLmJyMRcwFQYDVQQFEw4zNzc2Mzg0NzAwMDEz
ODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIB
AxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ3Mzg4NTYwMy1mM2ZmLTQxYmYtYjJiMi00
ZjdjYTlmZTYwNzYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrJOCH
MpEDtdG4A9N7+xuah2UfuNAnWrc2ZKzYltRthR/7agiWIw8yqe/Pdh/oegvWHlza
6uQYeTvIL6YER/3O+D9g4VgWiKqh8tH/U0FC+9ZgRKmjFcJGmwaQa8EuyY7Dlxzf
Z0BpfteDV22XXRlovO41zXAGGWm4zQ+FlLmJgdJz+lGpCAR1tPsYjvlLFrZiM5jk
j7ho3ZuWoP3DcA74aGD86QFmyF+iWXiaPUJLpjfEWhpjfu6wLiNpLBbf2Le/7HCK
tC6IwASHTbhbbhiCImbnRmu9reUBENPHm/6RFtzviEa6KSHDMQVDhafgXTIUPfOY
UV3JZhA/yzGBWLltAgMBAAGjggLPMIICyzAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW
BBQQ6aNldx5PKww0znqaQFe3t8D2DzAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7
sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3Nw
LnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBC
MECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2ls
Lm9yZy5ici9pc3N1ZXIuY3JsMBYGA1UdEQQPMA2CC2dlcnUuY29tLmJyMA4GA1Ud
DwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGU
MIIBkAYKKwYBBAGDui9kATCCAYAwggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBD
ZXJ0aWZpY2F0ZSBpcyBzb2xlbHkgZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2Vydmlj
ZXMgTGltaXRlZCBhbmQgb3RoZXIgcGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25z
IHVzaW5nIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3Jr
IFNlcnZpY2VzLiBJdHMgcmVjZWlwdCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3Rp
dHV0ZXMgYWNjZXB0YW5jZSBvZiB0aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2Vy
dGljaWNhdGUgUG9saWN5IGFuZCByZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBE
BggrBgEFBQcCARY4aHR0cDovL2Nwcy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2Jy
YXNpbC5vcmcuYnIvcG9saWNpZXMwDQYJKoZIhvcNAQELBQADggEBAElSrcNfZ514
EpOjwyueAMOcYvkjb1VUBQmSWMcZuKS/QoKbYuFn7qx9vn+id6O+a48h1k1MfFD4
vv8og6aKaEHHQn5tD6KBQoYlimvuVQkjupXPFFhlH8lMpPmWZ17LAnwjwdwDKdVF
NzVLHylg3s9T0DXh1uR1namY2uLD0jwHBnm2tqucjLZ/00pha2L4IT1fjw3OqIXi
99SSrtqExpWEZpXJSxBpfygWXl1IKvlveLTG3EzNpjGcKoudXFwqQvFQtiP9sQ3M
RyIF8QwW83IqpOIdXRw7nVgizujc0aTBUqlL7xGsjiR6JsiR+/3FNuJxpKVQ4pHa
HI5ipvGg/0g=
-----END CERTIFICATE-----
2021-12-09 22:54:20 SUCCESS
EnsureBearerAccessTokenNotInParams
Client correctly did not send access token in query parameters or form body
2021-12-09 22:54:20 SUCCESS
ExtractBearerAccessTokenFromHeader
Found access token on incoming request
access_token
p8xeuAdfW0JEiwHLQlaJKZffGEg6xOPyV1Lz0Fc9LhFNQk9xBi
2021-12-09 22:54:20 SUCCESS
RequireBearerAccessToken
Found access token in request
actual
p8xeuAdfW0JEiwHLQlaJKZffGEg6xOPyV1Lz0Fc9LhFNQk9xBi
2021-12-09 22:54:20 INFO
ExtractFapiDateHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-auth-date
path
headers.x-fapi-auth-date
mapped
object
incoming_request
2021-12-09 22:54:20 INFO
ExtractFapiIpAddressHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-customer-ip-address
path
headers.x-fapi-customer-ip-address
mapped
object
incoming_request
2021-12-09 22:54:20 INFO
ExtractFapiInteractionIdHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-interaction-id
path
headers.x-fapi-interaction-id
mapped
object
incoming_request
2021-12-09 22:54:20 SUCCESS
FAPIBrazilEnsureAuthorizationRequestScopesContainAccounts
'accounts' was included in authorization request scopes
actual
openid consent:urn:conformance.oidf:dEw82wAIdm accounts resources
expected
accounts
2021-12-09 22:54:20 INFO
CreateFapiInteractionIdIfNeeded
Found existing FAPI interaction ID
fapi_interaction_id
e7ee8555-792e-4972-bc5e-7a820d7200db
2021-12-09 22:54:20 SUCCESS
CreateFAPIAccountEndpointResponse
Created account response object
accounts_endpoint_response
{
  "conformance-test-finished": "true"
}
accounts_endpoint_response_headers
{
  "x-fapi-interaction-id": "e7ee8555-792e-4972-bc5e-7a820d7200db",
  "content-type": "application/json; charset\u003dUTF-8"
}
2021-12-09 22:54:20 SUCCESS
CreateBrazilAccountsEndpointResponse
Created Brazil accounts response (Please note that this is a hardcoded response copied from API documentation)
accounts_endpoint_response
{
  "data": [
    {
      "brandName": "Organização A",
      "companyCnpj": "21128159000166",
      "type": "CONTA_DEPOSITO_A_VISTA",
      "compeCode": "001",
      "branchCode": "6272",
      "number": "94088392",
      "checkDigit": "4",
      "accountId": "92792126019929279212650822221989319252576"
    }
  ],
  "links": {
    "self": "https://api.banco.com.br/open-banking/api/v1/resource",
    "first": "https://api.banco.com.br/open-banking/api/v1/resource",
    "prev": "https://api.banco.com.br/open-banking/api/v1/resource",
    "next": "https://api.banco.com.br/open-banking/api/v1/resource",
    "last": "https://api.banco.com.br/open-banking/api/v1/resource"
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2021-12-09T22:54:20Z"
  }
}
accounts_endpoint_response_headers
{
  "x-fapi-interaction-id": "e7ee8555-792e-4972-bc5e-7a820d7200db",
  "content-type": "application/json"
}
2021-12-09 22:54:20
ClearAccessTokenFromRequest
Condition ran but did not log anything
2021-12-09 22:54:20 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance UisCUKUCH9FYlkZ
outgoing_status_code
200
outgoing_headers
{
  "x-fapi-interaction-id": [
    "e7ee8555-792e-4972-bc5e-7a820d7200db"
  ],
  "content-type": [
    "application/json"
  ]
}
outgoing_body
{
  "data": [
    {
      "brandName": "Organização A",
      "companyCnpj": "21128159000166",
      "type": "CONTA_DEPOSITO_A_VISTA",
      "compeCode": "001",
      "branchCode": "6272",
      "number": "94088392",
      "checkDigit": "4",
      "accountId": "92792126019929279212650822221989319252576"
    }
  ],
  "links": {
    "self": "https://api.banco.com.br/open-banking/api/v1/resource",
    "first": "https://api.banco.com.br/open-banking/api/v1/resource",
    "prev": "https://api.banco.com.br/open-banking/api/v1/resource",
    "next": "https://api.banco.com.br/open-banking/api/v1/resource",
    "last": "https://api.banco.com.br/open-banking/api/v1/resource"
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2021-12-09T22:54:20Z"
  }
}
outgoing_path
accounts/v1/accounts
2021-12-09 22:54:20 FINISHED
fapi1-advanced-final-client-refresh-token-test
Test has run to completion
testmodule_result
PASSED
2021-12-09 22:54:23
TEST-RUNNER
Alias has now been claimed by another test
alias
geru
new_test_id
yoIkaDGG13VfSoL
Test Results