Test Name | fapi1-advanced-final-client-test-encrypted-idtoken-usingrsa15 |
---|---|
Variant | client_auth_type=mtls, fapi_jarm_type=oidc, fapi_auth_request_method=by_value, fapi_profile=openbanking_brazil, fapi_response_mode=plain_response |
Test ID | uyuZYUEbhAEuBBZ https://www.certification.openid.net/log-detail.html?public=true&log=uyuZYUEbhAEuBBZ |
Created | 2021-12-10T16:24:36.095805Z |
Description | Sicoob - Iniciação de pagamentos |
Test Version | 4.1.38 |
Test Owner | 112635894686881875468 https://accounts.google.com |
Plan ID | xfiZ3tTX31sxk https://www.certification.openid.net/plan-detail.html?public=true&plan=xfiZ3tTX31sxk |
Exported From | https://www.certification.openid.net |
Exported By | 112176339140883317708 https://accounts.google.com |
Suite Version | 4.1.38 |
Exported | 2021-12-10 20:23:53 (UTC) |
Status: FINISHED Result: PASSED |
SUCCESS 95 FAILURE 0 WARNING 0 REVIEW 0 INFO 5 |
2021-12-10 16:24:36 |
INFO
|
TEST-RUNNER
Test instance uyuZYUEbhAEuBBZ created
|
||||||||||||||
|
2021-12-10 16:24:36 |
SUCCESS
|
FAPIBrazilGenerateServerConfiguration
Created server configuration
|
||||||
|
2021-12-10 16:24:36 |
SUCCESS
|
LoadServerJWKs
Parsed public and private JWK sets
|
||||||
|
2021-12-10 16:24:36 | SUCCESS |
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
|
|
2021-12-10 16:24:36 |
|
SetServerSigningAlgToPS256
Successfully set signing algorithm to PS256
|
|
2021-12-10 16:24:36 |
|
FAPIBrazilSetGrantTypesSupportedInServerConfiguration
Successfully set grant_types_supported
|
||
|
2021-12-10 16:24:36 |
|
AddClaimsParameterSupportedTrueToServerConfiguration
Successfully added claims_parameter_supported to server configuration
|
||
|
2021-12-10 16:24:36 |
|
FAPIBrazilAddBrazilSpecificSettingsToServerConfiguration
Added open banking Brazil specific server settings
|
||
|
2021-12-10 16:24:36 |
SUCCESS
|
AddTLSClientAuthToServerConfiguration
Added tls_client_auth for token_endpoint_auth_methods_supported
|
|
2021-12-10 16:24:36 | SUCCESS |
AddResponseTypeCodeIdTokenToServerConfiguration
Added code id_token as response type supported
|
||
|
2021-12-10 16:24:36 |
SUCCESS
|
FAPIBrazilAddTokenEndpointAuthSigningAlgValuesSupportedToServer
Set token_endpoint_auth_signing_alg_values_supported
|
||
|
2021-12-10 16:24:36 |
SUCCESS
|
CheckServerConfiguration
Found required server configuration keys
|
||
|
2021-12-10 16:24:36 | SUCCESS |
FAPIEnsureMinimumServerKeyLength
Validated minimum key lengths for server_jwks
|
||
|
2021-12-10 16:24:36 |
SUCCESS
|
LoadUserInfo
Added user information
|
||
|
Verify configuration of first client |
2021-12-10 16:24:36 |
SUCCESS
|
GetStaticClientConfiguration
Found a static client object
|
||||||||
|
2021-12-10 16:24:36 | SUCCESS |
ValidateClientJWKsPublicPart
Valid client JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
|
|
2021-12-10 16:24:36 |
SUCCESS
|
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
|
||||
|
2021-12-10 16:24:36 | SUCCESS |
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
|
||
|
2021-12-10 16:24:36 |
SUCCESS
|
EnsureClientJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
|
|
2021-12-10 16:24:36 | SUCCESS |
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
|
||
|
Verify configuration of second client |
2021-12-10 16:24:36 |
SUCCESS
|
GetStaticClient2Configuration
Found a static second client object
|
||||||||||||
|
2021-12-10 16:24:36 | SUCCESS |
ValidateClientJWKsPublicPart
Valid client JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
|
|
2021-12-10 16:24:36 |
SUCCESS
|
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
|
||||
|
2021-12-10 16:24:36 | SUCCESS |
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
|
||
|
2021-12-10 16:24:36 |
SUCCESS
|
EnsureClientJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
|
|
2021-12-10 16:24:36 | SUCCESS |
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
|
||
|
2021-12-10 16:24:36 | SUCCESS |
FAPIEnsureClientJwksContainsAnEncryptionKey
Found an encryption key in client jwks
|
||||
|
2021-12-10 16:24:36 |
|
fapi1-advanced-final-client-test-encrypted-idtoken-usingrsa15
Setup Done
|
|
2021-12-10 16:24:37 |
INCOMING
|
fapi1-advanced-final-client-test-encrypted-idtoken-usingrsa15
Incoming HTTP request to test instance uyuZYUEbhAEuBBZ
|
||||||||||||||||||||
|
2021-12-10 16:24:37 | SUCCESS |
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
|
||||
|
2021-12-10 16:24:37 |
OUTGOING
|
fapi1-advanced-final-client-test-encrypted-idtoken-usingrsa15
Response to HTTP request to test instance uyuZYUEbhAEuBBZ
|
||||||||
|
2021-12-10 16:24:38 |
INCOMING
|
fapi1-advanced-final-client-test-encrypted-idtoken-usingrsa15
Incoming HTTP request to test instance uyuZYUEbhAEuBBZ
|
||||||||||||||||||||
|
2021-12-10 16:24:38 | SUCCESS |
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
|
||||
|
Token endpoint |
2021-12-10 16:24:38 |
SUCCESS
|
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
|
||
|
2021-12-10 16:24:38 | SUCCESS |
CheckForClientCertificate
Found client certificate
|
|
2021-12-10 16:24:38 |
SUCCESS
|
EnsureClientCertificateMatches
Presented certificate matches registered certificate
|
||
|
2021-12-10 16:24:38 |
SUCCESS
|
EnsureNoClientAssertionSentToTokenEndpoint
Client did not send a client_assertion to token endpoint
|
|
2021-12-10 16:24:38 |
SUCCESS
|
FAPIBrazilExtractRequestedScopeFromClientCredentialsGrant
Found 'payments' scope in request
|
||||
|
2021-12-10 16:24:38 |
SUCCESS
|
GenerateBearerAccessToken
Generated access token
|
||
|
2021-12-10 16:24:38 |
SUCCESS
|
CreateTokenEndpointResponse
Created token endpoint response
|
||||
|
2021-12-10 16:24:38 |
|
CopyAccessTokenToClientCredentialsField
Condition ran but did not log anything
|
|
2021-12-10 16:24:38 |
OUTGOING
|
fapi1-advanced-final-client-test-encrypted-idtoken-usingrsa15
Response to HTTP request to test instance uyuZYUEbhAEuBBZ
|
||||||||
|
2021-12-10 16:24:39 |
INCOMING
|
fapi1-advanced-final-client-test-encrypted-idtoken-usingrsa15
Incoming HTTP request to test instance uyuZYUEbhAEuBBZ
|
||||||||||||||||||||
|
2021-12-10 16:24:39 | SUCCESS |
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
|
||||
|
New consent endpoint |
2021-12-10 16:24:39 |
SUCCESS
|
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
|
||
|
2021-12-10 16:24:39 | SUCCESS |
CheckForClientCertificate
Found client certificate
|
|
2021-12-10 16:24:39 |
SUCCESS
|
EnsureClientCertificateMatches
Presented certificate matches registered certificate
|
||
|
2021-12-10 16:24:39 |
SUCCESS
|
EnsureIncomingRequestMethodIsPost
Client correctly used http POST method
|
|
2021-12-10 16:24:39 | SUCCESS |
EnsureBearerAccessTokenNotInParams
Client correctly did not send access token in query parameters or form body
|
|
2021-12-10 16:24:39 | SUCCESS |
ExtractBearerAccessTokenFromHeader
Found access token on incoming request
|
||
|
2021-12-10 16:24:39 |
SUCCESS
|
RequireBearerClientCredentialsAccessToken
Found access token in request
|
||
|
2021-12-10 16:24:39 | INFO |
ExtractFapiDateHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-auth-date
|
||||||
|
2021-12-10 16:24:39 | INFO |
ExtractFapiIpAddressHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-customer-ip-address
|
||||||
|
2021-12-10 16:24:39 | INFO |
ExtractFapiInteractionIdHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-interaction-id
|
||||||
|
2021-12-10 16:24:39 |
SUCCESS
|
FAPIBrazilExtractCertificateSubjectFromServerJwks
Extracted subject from the certificate included in server jwks
|
||||||
|
2021-12-10 16:24:39 |
SUCCESS
|
FAPIBrazilEnsureClientCredentialsScopeContainedPayments
The token request which was used to obtain the access token contained 'payments' scope
|
||
|
2021-12-10 16:24:39 | SUCCESS |
FAPIBrazilExtractPaymentsConsentRequest
Parsed payments consent request
|
||
|
2021-12-10 16:24:39 | SUCCESS |
EnsureIncomingRequestContentTypeIsApplicationJwt
Client correctly used application/jwt content type
|
|
2021-12-10 16:24:39 |
SUCCESS
|
ExtractXIdempotencyKeyHeader
Found an x-idempotency-key header
|
||
|
2021-12-10 16:24:39 | SUCCESS |
FAPIBrazilValidatePaymentConsentRequestAud
aud claim matches the endpoint url
|
||
|
2021-12-10 16:24:39 | SUCCESS |
FAPIBrazilExtractCertificateSubjectFromIncomingMTLSCertifiate
Extracted subject from the mtls client certificate
|
||||||
|
2021-12-10 16:24:39 | SUCCESS |
FAPIBrazilEnsureConsentRequestIssEqualsOrganizationId
iss claim in consent request matches organizationId in client certificate
|
||
|
2021-12-10 16:24:39 | SUCCESS |
FAPIBrazilEnsureConsentRequestJtiIsUUIDv4
jti claim in consent request is a UUIDv4
|
||
|
2021-12-10 16:24:39 | SUCCESS |
FAPIBrazilValidateConsentRequestIat
iat claim in consent request is valid
|
||
|
2021-12-10 16:24:39 |
|
FAPIBrazilFetchClientOrganizationJwksFromDirectory
Fetching client organization keys
|
||
|
2021-12-10 16:24:39 |
|
FAPIBrazilFetchClientOrganizationJwksFromDirectory
HTTP request
|
||||||||
|
2021-12-10 16:24:39 |
RESPONSE
|
FAPIBrazilFetchClientOrganizationJwksFromDirectory
HTTP response
|
||||||||
|
2021-12-10 16:24:39 |
|
FAPIBrazilFetchClientOrganizationJwksFromDirectory
Found JWK set string
|
||
|
2021-12-10 16:24:39 | SUCCESS |
FAPIBrazilFetchClientOrganizationJwksFromDirectory
Downloaded and added client organization JWK set to environment
|
||
|
2021-12-10 16:24:39 | SUCCESS |
FAPIBrazilValidateJwtSignatureUsingOrganizationJwks
jwt signature validated
|
||
|
2021-12-10 16:24:39 | SUCCESS |
CreateFapiInteractionIdIfNeeded
Created new FAPI interaction ID
|
||
|
2021-12-10 16:24:39 | SUCCESS |
FAPIBrazilGenerateNewPaymentsConsentResponse
Created consent response
|
||||||
|
2021-12-10 16:24:39 | SUCCESS |
FAPIBrazilSignPaymentConsentResponse
Signed the payment consent response
|
||
|
2021-12-10 16:24:39 |
|
ClearAccessTokenFromRequest
Condition ran but did not log anything
|
|
2021-12-10 16:24:39 |
OUTGOING
|
fapi1-advanced-final-client-test-encrypted-idtoken-usingrsa15
Response to HTTP request to test instance uyuZYUEbhAEuBBZ
|
||||||||
|
2021-12-10 16:24:39 |
INCOMING
|
fapi1-advanced-final-client-test-encrypted-idtoken-usingrsa15
Incoming HTTP request to test instance uyuZYUEbhAEuBBZ
|
||||||||||||||||||||
|
2021-12-10 16:24:39 | SUCCESS |
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
|
||||
|
2021-12-10 16:24:39 |
OUTGOING
|
fapi1-advanced-final-client-test-encrypted-idtoken-usingrsa15
Response to HTTP request to test instance uyuZYUEbhAEuBBZ
|
||||||||
|
2021-12-10 16:24:40 |
INCOMING
|
fapi1-advanced-final-client-test-encrypted-idtoken-usingrsa15
Incoming HTTP request to test instance uyuZYUEbhAEuBBZ
|
||||||||||||||||||||
|
2021-12-10 16:24:40 | SUCCESS |
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
|
||||
|
Authorization endpoint |
2021-12-10 16:24:40 | SUCCESS |
ExtractRequestObject
Parsed request object
|
||
|
2021-12-10 16:24:40 | SUCCESS |
EnsureRequestObjectWasEncrypted
Request object was encrypted
|
||
|
2021-12-10 16:24:40 | SUCCESS |
FAPIBrazilEnsureRequestObjectEncryptedUsingRSAOAEPA256GCM
Request object was encrypted using RSA-OAEP and A256GCM
|
||
|
2021-12-10 16:24:40 | SUCCESS |
ValidateEncryptedRequestObjectHasKid
kid was found in the encrypted request object header
|
||
|
2021-12-10 16:24:40 |
SUCCESS
|
CreateEffectiveAuthorizationRequestParameters
Merged http request parameters with request object claims
|
||
|
2021-12-10 16:24:40 | SUCCESS |
FAPIValidateRequestObjectSigningAlg
Request object was signed with a permitted algorithm
|
||
|
2021-12-10 16:24:40 | SUCCESS |
FAPIBrazilValidateRequestObjectIdTokenACRClaims
Acr value in request object is as expected
|
||
|
2021-12-10 16:24:40 | SUCCESS |
FAPIValidateRequestObjectExp
Request object contains a valid exp claim, expiry time
|
||
|
2021-12-10 16:24:40 | SUCCESS |
FAPI1AdvancedValidateRequestObjectNBFClaim
nbf claim is valid
|
||||
|
2021-12-10 16:24:40 |
|
ValidateRequestObjectClaims
Request object does not contain a max_age claim
|
|
2021-12-10 16:24:40 |
SUCCESS
|
ValidateRequestObjectClaims
Request object claims passed all validation checks
|
|
2021-12-10 16:24:40 | SUCCESS |
EnsureNumericRequestObjectClaimsAreNotNull
None of the claims expected to have numeric values, have null values
|
||
|
2021-12-10 16:24:40 | SUCCESS |
EnsureRequestObjectDoesNotContainRequestOrRequestUri
Request object does not contain request or request_uri
|
|
2021-12-10 16:24:40 | SUCCESS |
EnsureRequestObjectDoesNotContainSubWithClientId
Request object does not contain Client Id in sub
|
|
2021-12-10 16:24:40 | SUCCESS |
ValidateRequestObjectSignature
Request object signature validated using a key in the client's JWKS and using the client's registered request_object_signing_alg
|
||||||
|
2021-12-10 16:24:40 |
SUCCESS
|
EnsureMatchingRedirectUriInRequestObject
Redirect URI matched
|
||
|
2021-12-10 16:24:40 | SUCCESS |
EnsureRequiredAuthorizationRequestParametersMatchRequestObject
Required http request parameters match request object claims
|
||||
|
2021-12-10 16:24:40 | SUCCESS |
EnsureOptionalAuthorizationRequestParametersMatchRequestObject
All http request parameters and request object claims match
|
|
2021-12-10 16:24:40 | SUCCESS |
EnsureAuthorizationHttpRequestContainsOpenIDScope
Found 'openid' in scope http request parameter
|
||||
|
2021-12-10 16:24:40 |
SUCCESS
|
ExtractRequestedScopes
Requested scopes
|
||
|
2021-12-10 16:24:40 |
SUCCESS
|
FAPIBrazilValidateConsentScope
Found consent scope in request
|
||||
|
2021-12-10 16:24:40 |
SUCCESS
|
EnsureScopeContainsPayments
Found payments scope in request
|
||
|
2021-12-10 16:24:40 | SUCCESS |
EnsureResponseTypeIsCodeIdToken
Response type is expected value
|
||
|
2021-12-10 16:24:40 | SUCCESS |
EnsureOpenIDInScopeRequest
Found 'openid' scope in request
|
||||
|
2021-12-10 16:24:40 | SUCCESS |
EnsureMatchingClientId
Client ID matched
|
||
|
2021-12-10 16:24:40 |
SUCCESS
|
CreateAuthorizationCode
Created authorization code
|
||
|
2021-12-10 16:24:40 | SUCCESS |
ExtractNonceFromAuthorizationRequest
Extracted nonce
|
||
|
2021-12-10 16:24:40 | SUCCESS |
CalculateCHash
Successful c_hash encoding
|
||
|
2021-12-10 16:24:40 | SUCCESS |
CalculateSHash
Successful s_hash encoding
|
||
|
2021-12-10 16:24:40 |
SUCCESS
|
GenerateIdTokenClaims
Created ID Token Claims
|
||||||||||||
|
2021-12-10 16:24:40 | SUCCESS |
FAPIBrazilAddCPFAndCPNJToIdTokenClaims
Added claims to id_token claims
|
||
|
2021-12-10 16:24:40 | SUCCESS |
AddCHashToIdTokenClaims
Added c_hash to ID token claims
|
||||
|
2021-12-10 16:24:40 | SUCCESS |
AddSHashToIdTokenClaims
Added s_hash to ID token claims
|
||||
|
2021-12-10 16:24:40 | INFO |
AddAtHashToIdTokenClaims
Skipped evaluation due to missing required string: at_hash
|
||
|
2021-12-10 16:24:40 | SUCCESS |
FAPIBrazilAddACRClaimToIdTokenClaims
Added acr value to id_token_claims
|
||||
|
2021-12-10 16:24:40 |
SUCCESS
|
SignIdToken
Signed the ID token
|
||
|
2021-12-10 16:24:40 |
|
ChangeIdTokenEncryptedResponseAlgToRSA15
Changed id_token_encrypted_response_alg to RSA1_5
|
|
2021-12-10 16:24:40 |
|
EncryptIdToken
Encrypted the id token
|
||||||
|
2021-12-10 16:24:40 |
SUCCESS
|
FAPIBrazilChangeConsentStatusToAuthorized
Changed consent status to AUTHORISED
|
||
|
2021-12-10 16:24:40 |
SUCCESS
|
CreateAuthorizationEndpointResponseParams
Added authorization_endpoint_response_params to environment
|
||
|
2021-12-10 16:24:40 | SUCCESS |
AddCodeToAuthorizationEndpointResponseParams
Added code to authorization endpoint response params
|
||
|
2021-12-10 16:24:40 | SUCCESS |
AddIdTokenToAuthorizationEndpointResponseParams
Added id_token to authorization endpoint response params
|
||
|
2021-12-10 16:24:40 |
|
SendAuthorizationResponseWithResponseModeFragment
Redirecting back to client
|
||
|
2021-12-10 16:24:40 |
OUTGOING
|
fapi1-advanced-final-client-test-encrypted-idtoken-usingrsa15
Response to HTTP request to test instance uyuZYUEbhAEuBBZ
|
||||
|
2021-12-10 16:24:41 |
INCOMING
|
fapi1-advanced-final-client-test-encrypted-idtoken-usingrsa15
Incoming HTTP request to test instance uyuZYUEbhAEuBBZ
|
||||||||||||||||||||
|
2021-12-10 16:24:41 | SUCCESS |
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
|
||||
|
2021-12-10 16:24:41 |
OUTGOING
|
fapi1-advanced-final-client-test-encrypted-idtoken-usingrsa15
Response to HTTP request to test instance uyuZYUEbhAEuBBZ
|
||||||||
|
2021-12-10 16:24:45 |
FINISHED
|
fapi1-advanced-final-client-test-encrypted-idtoken-usingrsa15
Test has run to completion
|
||
|
2021-12-10 16:24:46 |
|
TEST-RUNNER
Alias has now been claimed by another test
|
||||
|