Test Summary

Test Results

Expand All Collapse All
All times are UTC
2022-01-13 02:08:17 INFO
TEST-RUNNER
Test instance WxAbxHSlSbGFkXI created
baseUrl
https://www.certification.openid.net/test/a/SafraRPTest
variant
{
  "client_auth_type": "private_key_jwt",
  "fapi_auth_request_method": "by_value",
  "fapi_profile": "openbanking_brazil",
  "fapi_jarm_type": "oidc",
  "fapi_response_mode": "plain_response"
}
alias
SafraRPTest
description
Safra Relying Party Test
planId
aHKQkRwE1nAwr
config
{
  "alias": "SafraRPTest",
  "description": "Safra Relying Party Test",
  "server": {
    "jwks": {
      "keys": [
        {
          "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
          "kty": "RSA",
          "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
          "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
          "e": "AQAB",
          "alg": "PS256",
          "use": "sig",
          "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
          "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
          "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
          "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
          "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
          "x5c": [
            "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
          ]
        },
        {
          "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
          "kty": "RSA",
          "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
          "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
          "e": "AQAB",
          "use": "enc",
          "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
          "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
          "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
          "alg": "RSA-OAEP",
          "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
          "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
        }
      ]
    }
  },
  "client": {
    "client_id": "client_XUwBuUHRMTVHAleZEJxH18815",
    "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
    "certificate": "-----BEGIN CERTIFICATE-----\nMIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3\nMDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx\nMzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm\ncmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp\ndmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ\nk/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi\nMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG\nVfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b\nnE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4\nC4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF\nSaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0\nPR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB\nAAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce\nRCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF\nBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w\nZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v\nY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu\nY3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P\nAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw\nggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl\ncnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl\ncyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg\ndXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg\nU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0\ndXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0\naWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG\nCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh\nc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn\nLPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO\nhUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+\nVibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1\nzHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO\nVZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af\n1zroWKsv2A\u003d\u003d\n-----END CERTIFICATE-----",
    "jwks": {
      "keys": [
        {
          "kty": "RSA",
          "e": "AQAB",
          "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
          "alg": "PS256",
          "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ"
        }
      ]
    }
  },
  "client2": {
    "client_id": "client_XUwBuUHRMTVHAleZEJxH18815",
    "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
    "id_token_encrypted_response_alg": "RSA-OAEP",
    "certificate": "-----BEGIN CERTIFICATE-----\nMIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3\nMDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx\nMzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm\ncmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp\ndmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ\nk/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi\nMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG\nVfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b\nnE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4\nC4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF\nSaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0\nPR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB\nAAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce\nRCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF\nBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w\nZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v\nY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu\nY3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P\nAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw\nggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl\ncnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl\ncyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg\ndXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg\nU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0\ndXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0\naWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG\nCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh\nc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn\nLPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO\nhUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+\nVibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1\nzHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO\nVZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af\n1zroWKsv2A\u003d\u003d\n-----END CERTIFICATE-----",
    "jwks": {
      "keys": [
        {
          "kty": "RSA",
          "e": "AQAB",
          "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
          "alg": "PS256",
          "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ",
          "use": "sig"
        },
        {
          "kty": "RSA",
          "e": "AQAB",
          "kid": "o_xvg824afVVwHrd1A7-zOGeH2yA0Y5aXdpOUOzj0dM",
          "n": "2ACeyabQj1JtNk8eKPs0dtPohlXzAjEzmn00NvZIDmAJP8qXgwjXmbeJJIpf2czYx8AOjWd4FjFdPPAubnCeAJkvG5xOF328KMXmpQFgmtKRaFhHgUCvmW_0uHYCvi-sR5ClYhJUnULmLCrt8q2hbODLuAuLpI4QsWtwJb3EsOjwjGCeSylm31UKL7aMuaPrzrtSijSkk2mBEpkA6yDeFXg8hUmmLbTdIHfhzYnEZ6KW8n1nJp3UcFXcMlIE09meffwqXHSrovJIk9qysUTv5hdatD0dZZDxPRQQ0qPN3wK8d8l4FMjJqHY6ifuV_qZu8WUSfe0VcCKDIez0X-C1xw",
          "use": "enc",
          "alg": "PS256"
        }
      ]
    },
    "id_token_encrypted_response_enc": "A256GCM"
  },
  "directory": {
    "keystore": "https://keystore.sandbox.directory.openbankingbrasil.org.br/"
  }
}
testName
fapi1-advanced-final-client-refresh-token-test
2022-01-13 02:08:17 SUCCESS
FAPIBrazilGenerateServerConfiguration
Created server configuration
server
{
  "issuer": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/SafraRPTest/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true
}
issuer
https://www.certification.openid.net/test/a/SafraRPTest/
discoveryUrl
https://www.certification.openid.net/test/a/SafraRPTest/.well-known/openid-configuration
2022-01-13 02:08:17 SUCCESS
LoadServerJWKs
Parsed public and private JWK sets
server_jwks
{
  "keys": [
    {
      "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
      "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
      "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
      "kty": "RSA",
      "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
      "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
      "alg": "PS256"
    },
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
server_encryption_keys
{
  "keys": [
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
server_public_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "alg": "PS256",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "alg": "RSA-OAEP",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
2022-01-13 02:08:17 SUCCESS
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2022-01-13 02:08:17
SetServerSigningAlgToPS256
Successfully set signing algorithm to PS256
2022-01-13 02:08:17
FAPIBrazilSetGrantTypesSupportedInServerConfiguration
Successfully set grant_types_supported
server
{
  "issuer": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/SafraRPTest/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ]
}
2022-01-13 02:08:17
AddClaimsParameterSupportedTrueToServerConfiguration
Successfully added claims_parameter_supported to server configuration
server
{
  "issuer": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/SafraRPTest/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true
}
2022-01-13 02:08:17
FAPIBrazilAddBrazilSpecificSettingsToServerConfiguration
Added open banking Brazil specific server settings
server
{
  "issuer": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/SafraRPTest/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ]
}
2022-01-13 02:08:17
SetTokenEndpointAuthMethodsSupportedToPrivateKeyJWTOnly
Changed token_endpoint_auth_methods_supported to private_key_jwt only in server configuration
server_configuration
{
  "issuer": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/SafraRPTest/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ]
}
2022-01-13 02:08:17 SUCCESS
AddResponseTypeCodeIdTokenToServerConfiguration
Added code id_token as response type supported
response_types_supported
[
  "code id_token"
]
2022-01-13 02:08:17 SUCCESS
FAPIBrazilAddTokenEndpointAuthSigningAlgValuesSupportedToServer
Set token_endpoint_auth_signing_alg_values_supported
values
[
  "PS256"
]
2022-01-13 02:08:17 SUCCESS
CheckServerConfiguration
Found required server configuration keys
required
[
  "authorization_endpoint",
  "token_endpoint",
  "issuer"
]
2022-01-13 02:08:17 SUCCESS
FAPIEnsureMinimumServerKeyLength
Validated minimum key lengths for server_jwks
server_jwks
{
  "keys": [
    {
      "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
      "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
      "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
      "kty": "RSA",
      "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
      "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
      "alg": "PS256"
    },
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
2022-01-13 02:08:17 SUCCESS
LoadUserInfo
Added user information
user_info
{
  "sub": "user-subject-1234531",
  "name": "Demo T. User",
  "email": "user@example.com",
  "email_verified": false
}
Verify configuration of first client
2022-01-13 02:08:17 SUCCESS
GetStaticClientConfiguration
Found a static client object
client_id
client_XUwBuUHRMTVHAleZEJxH18815
redirect_uri
https://portalspa-hml.safra.com.br/callback
certificate
-----BEGIN CERTIFICATE-----
MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3
MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx
MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm
cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp
dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ
k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG
VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b
nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4
C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF
SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0
PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB
AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce
RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF
BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w
ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v
Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu
Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P
AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw
ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl
cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl
cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg
dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg
U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0
dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0
aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG
CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh
c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn
LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO
hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+
Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1
zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO
VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af
1zroWKsv2A==
-----END CERTIFICATE-----
jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ"
    }
  ]
}
2022-01-13 02:08:17 SUCCESS
ValidateClientJWKsPublicPart
Valid client JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2022-01-13 02:08:17 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ"
    }
  ]
}
2022-01-13 02:08:17 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2022-01-13 02:08:17 SUCCESS
EnsureClientJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2022-01-13 02:08:17 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ"
    }
  ]
}
Verify configuration of second client
2022-01-13 02:08:17 SUCCESS
GetStaticClient2Configuration
Found a static second client object
client_id
client_XUwBuUHRMTVHAleZEJxH18815
redirect_uri
https://portalspa-hml.safra.com.br/callback
id_token_encrypted_response_alg
RSA-OAEP
certificate
-----BEGIN CERTIFICATE-----
MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3
MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx
MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm
cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp
dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ
k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG
VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b
nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4
C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF
SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0
PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB
AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce
RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF
BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w
ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v
Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu
Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P
AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw
ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl
cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl
cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg
dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg
U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0
dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0
aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG
CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh
c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn
LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO
hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+
Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1
zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO
VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af
1zroWKsv2A==
-----END CERTIFICATE-----
jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ",
      "use": "sig"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "o_xvg824afVVwHrd1A7-zOGeH2yA0Y5aXdpOUOzj0dM",
      "n": "2ACeyabQj1JtNk8eKPs0dtPohlXzAjEzmn00NvZIDmAJP8qXgwjXmbeJJIpf2czYx8AOjWd4FjFdPPAubnCeAJkvG5xOF328KMXmpQFgmtKRaFhHgUCvmW_0uHYCvi-sR5ClYhJUnULmLCrt8q2hbODLuAuLpI4QsWtwJb3EsOjwjGCeSylm31UKL7aMuaPrzrtSijSkk2mBEpkA6yDeFXg8hUmmLbTdIHfhzYnEZ6KW8n1nJp3UcFXcMlIE09meffwqXHSrovJIk9qysUTv5hdatD0dZZDxPRQQ0qPN3wK8d8l4FMjJqHY6ifuV_qZu8WUSfe0VcCKDIez0X-C1xw",
      "use": "enc",
      "alg": "PS256"
    }
  ]
}
id_token_encrypted_response_enc
A256GCM
2022-01-13 02:08:17 SUCCESS
ValidateClientJWKsPublicPart
Valid client JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2022-01-13 02:08:17 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ",
      "use": "sig"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "o_xvg824afVVwHrd1A7-zOGeH2yA0Y5aXdpOUOzj0dM",
      "n": "2ACeyabQj1JtNk8eKPs0dtPohlXzAjEzmn00NvZIDmAJP8qXgwjXmbeJJIpf2czYx8AOjWd4FjFdPPAubnCeAJkvG5xOF328KMXmpQFgmtKRaFhHgUCvmW_0uHYCvi-sR5ClYhJUnULmLCrt8q2hbODLuAuLpI4QsWtwJb3EsOjwjGCeSylm31UKL7aMuaPrzrtSijSkk2mBEpkA6yDeFXg8hUmmLbTdIHfhzYnEZ6KW8n1nJp3UcFXcMlIE09meffwqXHSrovJIk9qysUTv5hdatD0dZZDxPRQQ0qPN3wK8d8l4FMjJqHY6ifuV_qZu8WUSfe0VcCKDIez0X-C1xw",
      "use": "enc",
      "alg": "PS256"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "o_xvg824afVVwHrd1A7-zOGeH2yA0Y5aXdpOUOzj0dM",
      "alg": "PS256",
      "n": "2ACeyabQj1JtNk8eKPs0dtPohlXzAjEzmn00NvZIDmAJP8qXgwjXmbeJJIpf2czYx8AOjWd4FjFdPPAubnCeAJkvG5xOF328KMXmpQFgmtKRaFhHgUCvmW_0uHYCvi-sR5ClYhJUnULmLCrt8q2hbODLuAuLpI4QsWtwJb3EsOjwjGCeSylm31UKL7aMuaPrzrtSijSkk2mBEpkA6yDeFXg8hUmmLbTdIHfhzYnEZ6KW8n1nJp3UcFXcMlIE09meffwqXHSrovJIk9qysUTv5hdatD0dZZDxPRQQ0qPN3wK8d8l4FMjJqHY6ifuV_qZu8WUSfe0VcCKDIez0X-C1xw"
    }
  ]
}
2022-01-13 02:08:17 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2022-01-13 02:08:17 SUCCESS
EnsureClientJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2022-01-13 02:08:17 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ",
      "use": "sig"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "o_xvg824afVVwHrd1A7-zOGeH2yA0Y5aXdpOUOzj0dM",
      "n": "2ACeyabQj1JtNk8eKPs0dtPohlXzAjEzmn00NvZIDmAJP8qXgwjXmbeJJIpf2czYx8AOjWd4FjFdPPAubnCeAJkvG5xOF328KMXmpQFgmtKRaFhHgUCvmW_0uHYCvi-sR5ClYhJUnULmLCrt8q2hbODLuAuLpI4QsWtwJb3EsOjwjGCeSylm31UKL7aMuaPrzrtSijSkk2mBEpkA6yDeFXg8hUmmLbTdIHfhzYnEZ6KW8n1nJp3UcFXcMlIE09meffwqXHSrovJIk9qysUTv5hdatD0dZZDxPRQQ0qPN3wK8d8l4FMjJqHY6ifuV_qZu8WUSfe0VcCKDIez0X-C1xw",
      "use": "enc",
      "alg": "PS256"
    }
  ]
}
2022-01-13 02:08:17
fapi1-advanced-final-client-refresh-token-test
Setup Done
2022-01-13 02:08:27 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance WxAbxHSlSbGFkXI
incoming_headers
{
  "host": "www.certification.openid.net",
  "x-dynatrace": "FW4;-987853115;3;1343653795;24;0;-1738730375;863;d9ec;2h01;3h501687a3;4h18;6hbf68e943df5b81c78b90cd72b77b2586;7he4bf9b120215aaff",
  "traceparent": "00-bf68e943df5b81c78b90cd72b77b2586-e4bf9b120215aaff-01",
  "tracestate": "985d1479-c51e8ec5@dt\u003dfw4;3;501687a3;18;0;0;0;35f;2ac7;2h01;3h501687a3;4h18;7he4bf9b120215aaff",
  "request-id": "|28c0d00d-4449a4c379b97d24.1.",
  "connection": "close"
}
incoming_path
/test/a/SafraRPTest/.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES256-GCM-SHA384
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2022-01-13 02:08:27 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES256-GCM-SHA384
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2022-01-13 02:08:27 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance WxAbxHSlSbGFkXI
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/SafraRPTest/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ],
  "response_types_supported": [
    "code id_token"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256"
  ]
}
outgoing_path
.well-known/openid-configuration
2022-01-13 02:08:29 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance WxAbxHSlSbGFkXI
incoming_headers
{
  "host": "www.certification.openid.net",
  "x-dynatrace": "FW4;-987853115;3;1343653795;24;1;-1738730375;863;ed25;2h01;3h501687a3;4h18;6hbf68e943df5b81c78b90cd72b77b2586;7h3632ee288e257d88",
  "traceparent": "00-bf68e943df5b81c78b90cd72b77b2586-3632ee288e257d88-01",
  "tracestate": "985d1479-c51e8ec5@dt\u003dfw4;3;501687a3;18;1;0;0;35f;02a9;2h01;3h501687a3;4h18;7h3632ee288e257d88",
  "request-id": "|28c0d00d-4449a4c379b97d24.2.",
  "content-type": "application/x-www-form-urlencoded",
  "content-length": "1024",
  "connection": "close"
}
incoming_path
/test-mtls/a/SafraRPTest/token
incoming_body_form_params
{
  "scope": "consents",
  "grant_type": "client_credentials",
  "client_id": "client_XUwBuUHRMTVHAleZEJxH18815",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjcwZGI5MDc2NWE1YTQ3NTk4YTJjNWRmNzkxZDQ0OWJiIiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDQwMDA4LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzOTcwOCwibmJmIjoxNjQyMDM5NzA4fQ.kJBK8oB27UG6Oh45o5xF8RN8ZQiOBpd9Y9JfDEn5zeBVMq7U5jUguucdM-eytxnWReuVUvoGYx8e86AmfTSg6VUM3MRSbzsoZf6lPAdOyIfEdfFesJJ_xCzmZNADc3m2QVizExCOrKv3uePCbNCYv3BGon2lQZ6Nltq7LGOvBARBvJOg8n0fYXtSOW3TxkcnCEG4Y_Fnume2LrGDhL6-G7GZj-Qd3PMINbYxZGv-S8eEps1XdyjO6mxhEiqUAtyNuNwP-cw46NWU6ZkVSK0uDhimXvGPwuFulgY4pZrccUZVcgA1vnHUCuYy-jB6ual6UXEjs-M0RcpdrNNWXYdemg",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES256-GCM-SHA384
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A== -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
scope=consents&grant_type=client_credentials&client_id=client_XUwBuUHRMTVHAleZEJxH18815&client_assertion=eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjcwZGI5MDc2NWE1YTQ3NTk4YTJjNWRmNzkxZDQ0OWJiIiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDQwMDA4LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzOTcwOCwibmJmIjoxNjQyMDM5NzA4fQ.kJBK8oB27UG6Oh45o5xF8RN8ZQiOBpd9Y9JfDEn5zeBVMq7U5jUguucdM-eytxnWReuVUvoGYx8e86AmfTSg6VUM3MRSbzsoZf6lPAdOyIfEdfFesJJ_xCzmZNADc3m2QVizExCOrKv3uePCbNCYv3BGon2lQZ6Nltq7LGOvBARBvJOg8n0fYXtSOW3TxkcnCEG4Y_Fnume2LrGDhL6-G7GZj-Qd3PMINbYxZGv-S8eEps1XdyjO6mxhEiqUAtyNuNwP-cw46NWU6ZkVSK0uDhimXvGPwuFulgY4pZrccUZVcgA1vnHUCuYy-jB6ual6UXEjs-M0RcpdrNNWXYdemg&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2022-01-13 02:08:29 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES256-GCM-SHA384
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2022-01-13 02:08:29 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A\u003d\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3\nMDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx\nMzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm\ncmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp\ndmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ\nk/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi\nMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG\nVfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b\nnE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4\nC4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF\nSaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0\nPR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB\nAAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce\nRCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF\nBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w\nZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v\nY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu\nY3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P\nAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw\nggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl\ncnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl\ncyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg\ndXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg\nU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0\ndXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0\naWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG\nCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh\nc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn\nLPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO\nhUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+\nVibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1\nzHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO\nVZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af\n1zroWKsv2A\u003d\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003d44b261bc-4f6f-44ce-b3d7-3f98a2b225f4,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3538313630373839303030313238,CN\u003d*.safra.com.br,OU\u003d709138dd-6e9d-5f96-bfff-69a5b2cb3ec0,O\u003dBCO SAFRA S.A.,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "api-mtls-hml.safra.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2022-01-13 02:08:29 SUCCESS
CheckForClientCertificate
Found client certificate
2022-01-13 02:08:29 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3
MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx
MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm
cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp
dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ
k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG
VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b
nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4
C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF
SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0
PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB
AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce
RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF
BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w
ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v
Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu
Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P
AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw
ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl
cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl
cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg
dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg
U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0
dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0
aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG
CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh
c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn
LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO
hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+
Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1
zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO
VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af
1zroWKsv2A==
-----END CERTIFICATE-----
2022-01-13 02:08:29 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjcwZGI5MDc2NWE1YTQ3NTk4YTJjNWRmNzkxZDQ0OWJiIiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDQwMDA4LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzOTcwOCwibmJmIjoxNjQyMDM5NzA4fQ.kJBK8oB27UG6Oh45o5xF8RN8ZQiOBpd9Y9JfDEn5zeBVMq7U5jUguucdM-eytxnWReuVUvoGYx8e86AmfTSg6VUM3MRSbzsoZf6lPAdOyIfEdfFesJJ_xCzmZNADc3m2QVizExCOrKv3uePCbNCYv3BGon2lQZ6Nltq7LGOvBARBvJOg8n0fYXtSOW3TxkcnCEG4Y_Fnume2LrGDhL6-G7GZj-Qd3PMINbYxZGv-S8eEps1XdyjO6mxhEiqUAtyNuNwP-cw46NWU6ZkVSK0uDhimXvGPwuFulgY4pZrccUZVcgA1vnHUCuYy-jB6ual6UXEjs-M0RcpdrNNWXYdemg",
  "header": {
    "x5t": "imeJtvhk1_UOZIIOKtvS3EW0nDo",
    "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "client_XUwBuUHRMTVHAleZEJxH18815",
    "aud": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "nbf": 1642039708,
    "iss": "client_XUwBuUHRMTVHAleZEJxH18815",
    "exp": 1642040008,
    "iat": 1642039708,
    "jti": "70db90765a5a47598a2c5df791d449bb"
  }
}
2022-01-13 02:08:29
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2022-01-13 02:08:29 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjcwZGI5MDc2NWE1YTQ3NTk4YTJjNWRmNzkxZDQ0OWJiIiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDQwMDA4LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzOTcwOCwibmJmIjoxNjQyMDM5NzA4fQ.kJBK8oB27UG6Oh45o5xF8RN8ZQiOBpd9Y9JfDEn5zeBVMq7U5jUguucdM-eytxnWReuVUvoGYx8e86AmfTSg6VUM3MRSbzsoZf6lPAdOyIfEdfFesJJ_xCzmZNADc3m2QVizExCOrKv3uePCbNCYv3BGon2lQZ6Nltq7LGOvBARBvJOg8n0fYXtSOW3TxkcnCEG4Y_Fnume2LrGDhL6-G7GZj-Qd3PMINbYxZGv-S8eEps1XdyjO6mxhEiqUAtyNuNwP-cw46NWU6ZkVSK0uDhimXvGPwuFulgY4pZrccUZVcgA1vnHUCuYy-jB6ual6UXEjs-M0RcpdrNNWXYdemg
2022-01-13 02:08:29 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2022-01-13 02:08:29 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2022-01-13 02:08:29 SUCCESS
FAPIBrazilExtractRequestedScopeFromClientCredentialsGrant
Found 'consents' scope in request
actual
[
  "consents"
]
expected
consents
2022-01-13 02:08:29 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
0YNOnMKK4rjI2tpccG2qm5qd4GzBHtumgPvV6j9avB3pDwDZuK
2022-01-13 02:08:29 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
0YNOnMKK4rjI2tpccG2qm5qd4GzBHtumgPvV6j9avB3pDwDZuK
token_type
Bearer
2022-01-13 02:08:29
CopyAccessTokenToClientCredentialsField
Condition ran but did not log anything
2022-01-13 02:08:29 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance WxAbxHSlSbGFkXI
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "0YNOnMKK4rjI2tpccG2qm5qd4GzBHtumgPvV6j9avB3pDwDZuK",
  "token_type": "Bearer"
}
outgoing_path
token
2022-01-13 02:08:30 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance WxAbxHSlSbGFkXI
incoming_headers
{
  "host": "www.certification.openid.net",
  "x-dynatrace": "FW4;-987853115;3;1343653795;24;2;-1738730375;863;284e;2h01;3h501687a3;4h18;6hbf68e943df5b81c78b90cd72b77b2586;7h5d8f3663f9e7c21a",
  "traceparent": "00-bf68e943df5b81c78b90cd72b77b2586-5d8f3663f9e7c21a-01",
  "tracestate": "985d1479-c51e8ec5@dt\u003dfw4;3;501687a3;18;2;0;0;35f;0eef;2h01;3h501687a3;4h18;7h5d8f3663f9e7c21a",
  "authorization": "Bearer 0YNOnMKK4rjI2tpccG2qm5qd4GzBHtumgPvV6j9avB3pDwDZuK",
  "request-id": "|28c0d00d-4449a4c379b97d24.3.",
  "content-type": "application/json; charset\u003dutf-8",
  "content-length": "1078",
  "connection": "close"
}
incoming_path
/test-mtls/a/SafraRPTest/consents/v1/consents
incoming_body_form_params
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES256-GCM-SHA384
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A== -----END CERTIFICATE-----
incoming_body_json
{
  "data": {
    "loggedUser": {
      "document": {
        "identification": "16881808852",
        "rel": "CPF"
      }
    },
    "permissions": [
      "CUSTOMERS_PERSONAL_IDENTIFICATIONS_READ",
      "CUSTOMERS_PERSONAL_ADITTIONALINFO_READ",
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "ACCOUNTS_OVERDRAFT_LIMITS_READ",
      "ACCOUNTS_TRANSACTIONS_READ",
      "CREDIT_CARDS_ACCOUNTS_READ",
      "CREDIT_CARDS_ACCOUNTS_LIMITS_READ",
      "CREDIT_CARDS_ACCOUNTS_TRANSACTIONS_READ",
      "CREDIT_CARDS_ACCOUNTS_BILLS_READ",
      "CREDIT_CARDS_ACCOUNTS_BILLS_TRANSACTIONS_READ",
      "RESOURCES_READ",
      "INVOICE_FINANCINGS_READ",
      "INVOICE_FINANCINGS_SCHEDULED_INSTALMENTS_READ",
      "INVOICE_FINANCINGS_PAYMENTS_READ",
      "INVOICE_FINANCINGS_WARRANTIES_READ",
      "FINANCINGS_READ",
      "FINANCINGS_SCHEDULED_INSTALMENTS_READ",
      "FINANCINGS_PAYMENTS_READ",
      "FINANCINGS_WARRANTIES_READ",
      "LOANS_READ",
      "LOANS_SCHEDULED_INSTALMENTS_READ",
      "LOANS_PAYMENTS_READ",
      "LOANS_WARRANTIES_READ",
      "UNARRANGED_ACCOUNTS_OVERDRAFT_READ",
      "UNARRANGED_ACCOUNTS_OVERDRAFT_SCHEDULED_INSTALMENTS_READ",
      "UNARRANGED_ACCOUNTS_OVERDRAFT_PAYMENTS_READ",
      "UNARRANGED_ACCOUNTS_OVERDRAFT_WARRANTIES_READ"
    ],
    "expirationDateTime": "2023-01-13T02:08:29Z"
  }
}
incoming_query_string_params
{}
incoming_body
{"data":{"loggedUser":{"document":{"identification":"16881808852","rel":"CPF"}},"permissions":["CUSTOMERS_PERSONAL_IDENTIFICATIONS_READ","CUSTOMERS_PERSONAL_ADITTIONALINFO_READ","ACCOUNTS_READ","ACCOUNTS_BALANCES_READ","ACCOUNTS_OVERDRAFT_LIMITS_READ","ACCOUNTS_TRANSACTIONS_READ","CREDIT_CARDS_ACCOUNTS_READ","CREDIT_CARDS_ACCOUNTS_LIMITS_READ","CREDIT_CARDS_ACCOUNTS_TRANSACTIONS_READ","CREDIT_CARDS_ACCOUNTS_BILLS_READ","CREDIT_CARDS_ACCOUNTS_BILLS_TRANSACTIONS_READ","RESOURCES_READ","INVOICE_FINANCINGS_READ","INVOICE_FINANCINGS_SCHEDULED_INSTALMENTS_READ","INVOICE_FINANCINGS_PAYMENTS_READ","INVOICE_FINANCINGS_WARRANTIES_READ","FINANCINGS_READ","FINANCINGS_SCHEDULED_INSTALMENTS_READ","FINANCINGS_PAYMENTS_READ","FINANCINGS_WARRANTIES_READ","LOANS_READ","LOANS_SCHEDULED_INSTALMENTS_READ","LOANS_PAYMENTS_READ","LOANS_WARRANTIES_READ","UNARRANGED_ACCOUNTS_OVERDRAFT_READ","UNARRANGED_ACCOUNTS_OVERDRAFT_SCHEDULED_INSTALMENTS_READ","UNARRANGED_ACCOUNTS_OVERDRAFT_PAYMENTS_READ","UNARRANGED_ACCOUNTS_OVERDRAFT_WARRANTIES_READ"],"expirationDateTime":"2023-01-13T02:08:29Z"}}
2022-01-13 02:08:30 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES256-GCM-SHA384
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
New consent endpoint
2022-01-13 02:08:30 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A\u003d\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3\nMDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx\nMzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm\ncmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp\ndmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ\nk/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi\nMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG\nVfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b\nnE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4\nC4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF\nSaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0\nPR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB\nAAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce\nRCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF\nBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w\nZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v\nY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu\nY3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P\nAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw\nggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl\ncnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl\ncyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg\ndXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg\nU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0\ndXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0\naWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG\nCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh\nc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn\nLPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO\nhUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+\nVibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1\nzHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO\nVZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af\n1zroWKsv2A\u003d\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003d44b261bc-4f6f-44ce-b3d7-3f98a2b225f4,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3538313630373839303030313238,CN\u003d*.safra.com.br,OU\u003d709138dd-6e9d-5f96-bfff-69a5b2cb3ec0,O\u003dBCO SAFRA S.A.,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "api-mtls-hml.safra.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2022-01-13 02:08:30 SUCCESS
CheckForClientCertificate
Found client certificate
2022-01-13 02:08:30 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3
MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx
MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm
cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp
dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ
k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG
VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b
nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4
C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF
SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0
PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB
AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce
RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF
BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w
ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v
Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu
Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P
AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw
ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl
cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl
cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg
dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg
U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0
dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0
aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG
CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh
c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn
LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO
hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+
Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1
zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO
VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af
1zroWKsv2A==
-----END CERTIFICATE-----
2022-01-13 02:08:30 SUCCESS
EnsureIncomingRequestMethodIsPost
Client correctly used http POST method
2022-01-13 02:08:30 SUCCESS
EnsureBearerAccessTokenNotInParams
Client correctly did not send access token in query parameters or form body
2022-01-13 02:08:30 SUCCESS
ExtractBearerAccessTokenFromHeader
Found access token on incoming request
access_token
0YNOnMKK4rjI2tpccG2qm5qd4GzBHtumgPvV6j9avB3pDwDZuK
2022-01-13 02:08:30 SUCCESS
RequireBearerClientCredentialsAccessToken
Found access token in request
actual
0YNOnMKK4rjI2tpccG2qm5qd4GzBHtumgPvV6j9avB3pDwDZuK
2022-01-13 02:08:30 INFO
ExtractFapiDateHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-auth-date
path
headers.x-fapi-auth-date
mapped
object
incoming_request
2022-01-13 02:08:30 INFO
ExtractFapiIpAddressHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-customer-ip-address
path
headers.x-fapi-customer-ip-address
mapped
object
incoming_request
2022-01-13 02:08:30 INFO
ExtractFapiInteractionIdHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-interaction-id
path
headers.x-fapi-interaction-id
mapped
object
incoming_request
2022-01-13 02:08:30 SUCCESS
FAPIBrazilEnsureClientCredentialsScopeContainedConsents
The token request which was used to obtain the access token contained 'consents' scope
actual
[
  "consents"
]
2022-01-13 02:08:30
FAPIBrazilExtractConsentRequest
Condition ran but did not log anything
2022-01-13 02:08:30 SUCCESS
CreateFapiInteractionIdIfNeeded
Created new FAPI interaction ID
fapi_interaction_id
3d8a394d-0c50-4b90-91db-e5c6804f10b3
2022-01-13 02:08:30 SUCCESS
FAPIBrazilGenerateNewConsentResponse
Created consent response
headers
{
  "x-fapi-interaction-id": "3d8a394d-0c50-4b90-91db-e5c6804f10b3"
}
consentId
urn:conformance.oidf:hM5fQwgUCy
consent_response
{
  "data": {
    "consentId": "urn:conformance.oidf:hM5fQwgUCy",
    "creationDateTime": "2022-01-13T02:08:30Z",
    "status": "AWAITING_AUTHORISATION",
    "statusUpdateDateTime": "2022-01-13T02:08:30Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2022-01-13T04:08:30Z",
    "transactionFromDateTime": "2022-01-13T02:03:30Z",
    "transactionToDateTime": "2022-01-13T04:08:30Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/SafraRPTestconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2022-01-13T02:08:30Z"
  }
}
2022-01-13 02:08:30
ClearAccessTokenFromRequest
Condition ran but did not log anything
2022-01-13 02:08:30 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance WxAbxHSlSbGFkXI
outgoing_status_code
201
outgoing_headers
{
  "x-fapi-interaction-id": [
    "3d8a394d-0c50-4b90-91db-e5c6804f10b3"
  ]
}
outgoing_body
{
  "data": {
    "consentId": "urn:conformance.oidf:hM5fQwgUCy",
    "creationDateTime": "2022-01-13T02:08:30Z",
    "status": "AWAITING_AUTHORISATION",
    "statusUpdateDateTime": "2022-01-13T02:08:30Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2022-01-13T04:08:30Z",
    "transactionFromDateTime": "2022-01-13T02:03:30Z",
    "transactionToDateTime": "2022-01-13T04:08:30Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/SafraRPTestconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2022-01-13T02:08:30Z"
  }
}
outgoing_path
consents/v1/consents
2022-01-13 02:08:31 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance WxAbxHSlSbGFkXI
incoming_headers
{
  "host": "www.certification.openid.net",
  "x-dynatrace": "FW4;-987853115;3;1343653795;24;3;-1738730375;863;11ef;2h01;3h501687a3;4h18;6hbf68e943df5b81c78b90cd72b77b2586;7h70bc9d8f607f0bbf",
  "traceparent": "00-bf68e943df5b81c78b90cd72b77b2586-70bc9d8f607f0bbf-01",
  "tracestate": "985d1479-c51e8ec5@dt\u003dfw4;3;501687a3;18;3;0;0;35f;bf2c;2h01;3h501687a3;4h18;7h70bc9d8f607f0bbf",
  "request-id": "|28c0d00d-4449a4c379b97d24.4.",
  "connection": "close"
}
incoming_path
/test/a/SafraRPTest/jwks
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES256-GCM-SHA384
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2022-01-13 02:08:31 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES256-GCM-SHA384
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2022-01-13 02:08:31 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance WxAbxHSlSbGFkXI
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "alg": "PS256",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "alg": "RSA-OAEP",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
outgoing_path
jwks
2022-01-13 02:08:35 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance WxAbxHSlSbGFkXI
incoming_headers
{
  "host": "www.certification.openid.net",
  "sec-ch-ua": "\" Not;A Brand\";v\u003d\"99\", \"Google Chrome\";v\u003d\"97\", \"Chromium\";v\u003d\"97\"",
  "sec-ch-ua-mobile": "?0",
  "sec-ch-ua-platform": "\"Windows\"",
  "upgrade-insecure-requests": "1",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/97.0.4692.71 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "none",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "pt-BR,pt;q\u003d0.9,en-US;q\u003d0.8,en;q\u003d0.7",
  "cookie": "__utmc\u003d201319536; __utma\u003d201319536.1341971708.1631915075.1641907690.1641941726.54; __utmz\u003d201319536.1641941726.54.15.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; JSESSIONID\u003d736655D537D3CECB0C8167ACF304265D",
  "connection": "close"
}
incoming_path
/test/a/SafraRPTest/authorize
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{
  "request": "eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZHQ00iLCJraWQiOiIwZmU1MDJkZC0xNGYwLTRmNDUtODBmOS1mZWI5YTIxNmY5OTYifQ.jwjX2MSrD7qAFmYBXh-w9csu-8gM2QHBNJp0hJL0GI9a-IXf_9Hj_O_xdSLZKZ63O-ga2c4bftroiam4HoZpNvmJEa3uZOr0qMgniyFqQeyPV2n7mdRAXe35brfFWVvlBHv6DPb5-Z_2wvA_YPIQNPodZRij323G8TnZ5GnDwaMxazSkcoaFXFe-K9lNG9pkm5p7mO2wSbt8lba7HeFVWwbDTaSKoNdW05ahzUi8i_tgbO6RFks16JQayol35jkOkHJrpEwMyznT1345m-vozINTfVP1jKkK_KKeCnFt6djsbEnRnAsgRuWgUevV_dI_QRSbVM3pKsYJRymnYG6ssg.z87q1DJJOENkaup0.pH1PxC0Utd8vn0R30mrD02RDuRy931cAHCmZGZtzyxCOiSCQ-RpT1JjSvi00eB-1qMPF3kJ2XrW9YB7mEWZEq0oNNz-5DlzsOvxxxqBpygQ3kp-x0LZ_D0vaQ5CuDTThWYIPTe9ZkZq8OAVr1rZWsaVPEGY26ifvDTMlcp0vxNZdRQyU09li6jL_rvPuY6VaOVudQx3PzNLBM6taQXhP2Fv88iw4eFrC3f4WtH8_o5amMnK1tJyKGJAkeZ5oCArh7wp6FnS2EhOIUj6fvNanK1bM_pYFYrA5wdH7b4x_pRGRcE321zlNZfNHoEw-qhIu4MBk5eCOORYPq1NkSkgslEuNVAXdFoxOGOyjC4VUl-sEjTUVhSXjfFEdXqIGbDNJ2zaxhVxL7yUJPigjLjmleZfreSNSu9i6EZMA2SGBTpLnxgfc2Xm_fFNyKyGOIjpxZWHOXgOYCAj7wB9o7_a_TxB4FD4xCobgFA3rm-FKLOwGnhj3HysgXy5q99QNWkpidhTbydCS7lO-546GwngfUWVL5EEq6UWcWJpTQzeCrjGVfHNb4ahQQzM4JRfYMcPwdW1iNNEFUIzGCKZF4JXLk-FBXgLOJe8QGE9Pwz8Y14izhDZ4taoQ9JGuhDi5zGl0scTuvo0QrWLbxm09hPWTXk-UswIWpGREctj1hu9AOe9wym46AvCk1CmsAeHmxj8Ib2vkuW5ataab66YiXwi1ffy3LLz5jEppmp2hAHuO83HiQRCinMO9hpF7G38KU4fczDjsp15Iy_dNbiQDOckwZtX0C-h_y1qFNiNIQSFp2q2sJEPMgG0rM3_0-gRkulUKXocNskY2aKDgaME2WN0dnykulGPd3tzfXm3O0nh415xMprewQdIy-Y-PkhXFTbzbLwwD8l56W3mj_uKwoB3nDcbxCvV7nmazMAJEEVL-l-shiBU0TW_X0eXHWc_TndjjsctgWyfUyAZ1OFmzBx2-gNqHqx0m-r58IoI1E3phVd_UX18lAoe7UIdRXCy9y-qMDfdH0vjYVGQrFUcjrHrSnJN11-Jyd5iI81Bk8thTDhKB4sM3mvmySeb_dNv_UF43nyNrktfgmn9AOeM1HjnsvNDun72DvkMD1kf6InZBW1D7h1Bqxzn5lSli5_MFWK7be0BnAhE2dvJ9GwxcEg5WboFGhzxlXIu1T6wKV1V8XCJZCWdYhehFYyUJ062-pariC2VTR0A8EchKYfEIkbwHSUA4NIb0epV9cxO2fvlOloXGXO9qorfPZeeappMMrFbJBnJyYdhQfoHfnvTEhRS1IoxfpiHLaCX1btGLSt4Upz_qYnUp3nG2gHuVaXGl_rBYYCAn1qU7rW4SaNrTsJTdSWZL133nwfeFXptdSj7rjtgb3uLMjiB7hQqN7k_LpJmaYHMHVDBocFakmbIiPtT3-ZeIFwZSLdbFMjqO4LREwDEjcnrL3_-JJTdzCDLClM0OMNgriH6G1sfvAAf4xjBZ5nsU6gycBmdznFAE1ELXpvQCbJFYhC8Q-i40SRrPSmMXhvbwsl7Wnzi7D6Xb02tQvA.I9tjYWYT83zxcIvQMCC9mQ",
  "client_id": "client_XUwBuUHRMTVHAleZEJxH18815",
  "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
  "scope": "openid consents customers accounts credit-cards-accounts resources invoice-financings financings loans unarranged-accounts-overdraft consent:urn:conformance.oidf:hM5fQwgUCy",
  "response_type": "code id_token"
}
incoming_body
2022-01-13 02:08:35 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Authorization endpoint
2022-01-13 02:08:35 SUCCESS
ExtractRequestObject
Parsed request object
request_object
{
  "value": "eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgifQ.eyJhdWQiOiJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1NhZnJhUlBUZXN0LyIsIm5iZiI6MTY0MjAzOTcxMSwic2NvcGUiOiJvcGVuaWQgY29uc2VudHMgY3VzdG9tZXJzIGFjY291bnRzIGNyZWRpdC1jYXJkcy1hY2NvdW50cyByZXNvdXJjZXMgaW52b2ljZS1maW5hbmNpbmdzIGZpbmFuY2luZ3MgbG9hbnMgdW5hcnJhbmdlZC1hY2NvdW50cy1vdmVyZHJhZnQgY29uc2VudDp1cm46Y29uZm9ybWFuY2Uub2lkZjpoTTVmUXdnVUN5IiwiaXNzIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUiLCJyZXNwb25zZV90eXBlIjoiY29kZSBpZF90b2tlbiIsInJlZGlyZWN0X3VyaSI6Imh0dHBzOi8vcG9ydGFsc3BhLWhtbC5zYWZyYS5jb20uYnIvY2FsbGJhY2siLCJzdGF0ZSI6IjUyODZmZmEzYjJmYTRlYmFhMjNlMThjMTU5MjdlMjZmIiwiZXhwIjoxNjQyMDQwMDExLCJub25jZSI6ImI5ZGFkNzBjNjI0ODQyZjA4YzMwODZlNjljNzkyYzVmIiwiY2xpZW50X2lkIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUifQ.taacsBmsk11Gpl9sltUqs2VfdXssO-myb0mK-5B6FJLm7FHOBhpMoeMP8z_-w1bRz2dz7UskwlkfLzR7IuBrZUv61FDyuGMlUdco4_v65feIz8WU9Vmf6fNPdEUoa8pLaXyijXMfaFfzgC9jMeeQbR_64ydVkRMCMFvg1xZKFYCDjpvwE3Bs_-FmAlZuZgtl-Y1vxTgXp9SbrIriPJpazOkfeJ_pi_KJYWYoLBpAZ9IynsE3ybzJpAuZaCs33ExZhIHg6Ru7NII4zOfgCwNiANrd5VDnLKDu3ofOFP1kFKvZGgO0q8Io74bS_rscco_-mmjsoF67oygsBou-_PU-Bg",
  "header": {
    "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
    "alg": "PS256"
  },
  "claims": {
    "aud": "https://www.certification.openid.net/test/a/SafraRPTest/",
    "nbf": 1642039711,
    "scope": "openid consents customers accounts credit-cards-accounts resources invoice-financings financings loans unarranged-accounts-overdraft consent:urn:conformance.oidf:hM5fQwgUCy",
    "iss": "client_XUwBuUHRMTVHAleZEJxH18815",
    "response_type": "code id_token",
    "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
    "state": "5286ffa3b2fa4ebaa23e18c15927e26f",
    "exp": 1642040011,
    "nonce": "b9dad70c624842f08c3086e69c792c5f",
    "client_id": "client_XUwBuUHRMTVHAleZEJxH18815"
  },
  "jwe_header": {
    "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
    "enc": "A256GCM",
    "alg": "RSA-OAEP"
  }
}
2022-01-13 02:08:35 SUCCESS
EnsureRequestObjectWasEncrypted
Request object was encrypted
jwe_header
{
  "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
  "enc": "A256GCM",
  "alg": "RSA-OAEP"
}
2022-01-13 02:08:35 SUCCESS
FAPIBrazilEnsureRequestObjectEncryptedUsingRSAOAEPA256GCM
Request object was encrypted using RSA-OAEP and A256GCM
jwe_header
{
  "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
  "enc": "A256GCM",
  "alg": "RSA-OAEP"
}
2022-01-13 02:08:35 SUCCESS
ValidateEncryptedRequestObjectHasKid
kid was found in the encrypted request object header
kid
0fe502dd-14f0-4f45-80f9-feb9a216f996
2022-01-13 02:08:35 SUCCESS
CreateEffectiveAuthorizationRequestParameters
Merged http request parameters with request object claims
effective_authorization_endpoint_request
{
  "request": "eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZHQ00iLCJraWQiOiIwZmU1MDJkZC0xNGYwLTRmNDUtODBmOS1mZWI5YTIxNmY5OTYifQ.jwjX2MSrD7qAFmYBXh-w9csu-8gM2QHBNJp0hJL0GI9a-IXf_9Hj_O_xdSLZKZ63O-ga2c4bftroiam4HoZpNvmJEa3uZOr0qMgniyFqQeyPV2n7mdRAXe35brfFWVvlBHv6DPb5-Z_2wvA_YPIQNPodZRij323G8TnZ5GnDwaMxazSkcoaFXFe-K9lNG9pkm5p7mO2wSbt8lba7HeFVWwbDTaSKoNdW05ahzUi8i_tgbO6RFks16JQayol35jkOkHJrpEwMyznT1345m-vozINTfVP1jKkK_KKeCnFt6djsbEnRnAsgRuWgUevV_dI_QRSbVM3pKsYJRymnYG6ssg.z87q1DJJOENkaup0.pH1PxC0Utd8vn0R30mrD02RDuRy931cAHCmZGZtzyxCOiSCQ-RpT1JjSvi00eB-1qMPF3kJ2XrW9YB7mEWZEq0oNNz-5DlzsOvxxxqBpygQ3kp-x0LZ_D0vaQ5CuDTThWYIPTe9ZkZq8OAVr1rZWsaVPEGY26ifvDTMlcp0vxNZdRQyU09li6jL_rvPuY6VaOVudQx3PzNLBM6taQXhP2Fv88iw4eFrC3f4WtH8_o5amMnK1tJyKGJAkeZ5oCArh7wp6FnS2EhOIUj6fvNanK1bM_pYFYrA5wdH7b4x_pRGRcE321zlNZfNHoEw-qhIu4MBk5eCOORYPq1NkSkgslEuNVAXdFoxOGOyjC4VUl-sEjTUVhSXjfFEdXqIGbDNJ2zaxhVxL7yUJPigjLjmleZfreSNSu9i6EZMA2SGBTpLnxgfc2Xm_fFNyKyGOIjpxZWHOXgOYCAj7wB9o7_a_TxB4FD4xCobgFA3rm-FKLOwGnhj3HysgXy5q99QNWkpidhTbydCS7lO-546GwngfUWVL5EEq6UWcWJpTQzeCrjGVfHNb4ahQQzM4JRfYMcPwdW1iNNEFUIzGCKZF4JXLk-FBXgLOJe8QGE9Pwz8Y14izhDZ4taoQ9JGuhDi5zGl0scTuvo0QrWLbxm09hPWTXk-UswIWpGREctj1hu9AOe9wym46AvCk1CmsAeHmxj8Ib2vkuW5ataab66YiXwi1ffy3LLz5jEppmp2hAHuO83HiQRCinMO9hpF7G38KU4fczDjsp15Iy_dNbiQDOckwZtX0C-h_y1qFNiNIQSFp2q2sJEPMgG0rM3_0-gRkulUKXocNskY2aKDgaME2WN0dnykulGPd3tzfXm3O0nh415xMprewQdIy-Y-PkhXFTbzbLwwD8l56W3mj_uKwoB3nDcbxCvV7nmazMAJEEVL-l-shiBU0TW_X0eXHWc_TndjjsctgWyfUyAZ1OFmzBx2-gNqHqx0m-r58IoI1E3phVd_UX18lAoe7UIdRXCy9y-qMDfdH0vjYVGQrFUcjrHrSnJN11-Jyd5iI81Bk8thTDhKB4sM3mvmySeb_dNv_UF43nyNrktfgmn9AOeM1HjnsvNDun72DvkMD1kf6InZBW1D7h1Bqxzn5lSli5_MFWK7be0BnAhE2dvJ9GwxcEg5WboFGhzxlXIu1T6wKV1V8XCJZCWdYhehFYyUJ062-pariC2VTR0A8EchKYfEIkbwHSUA4NIb0epV9cxO2fvlOloXGXO9qorfPZeeappMMrFbJBnJyYdhQfoHfnvTEhRS1IoxfpiHLaCX1btGLSt4Upz_qYnUp3nG2gHuVaXGl_rBYYCAn1qU7rW4SaNrTsJTdSWZL133nwfeFXptdSj7rjtgb3uLMjiB7hQqN7k_LpJmaYHMHVDBocFakmbIiPtT3-ZeIFwZSLdbFMjqO4LREwDEjcnrL3_-JJTdzCDLClM0OMNgriH6G1sfvAAf4xjBZ5nsU6gycBmdznFAE1ELXpvQCbJFYhC8Q-i40SRrPSmMXhvbwsl7Wnzi7D6Xb02tQvA.I9tjYWYT83zxcIvQMCC9mQ",
  "client_id": "client_XUwBuUHRMTVHAleZEJxH18815",
  "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
  "scope": "openid consents customers accounts credit-cards-accounts resources invoice-financings financings loans unarranged-accounts-overdraft consent:urn:conformance.oidf:hM5fQwgUCy",
  "response_type": "code id_token",
  "aud": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "nbf": 1642039711,
  "iss": "client_XUwBuUHRMTVHAleZEJxH18815",
  "state": "5286ffa3b2fa4ebaa23e18c15927e26f",
  "exp": 1642040011,
  "nonce": "b9dad70c624842f08c3086e69c792c5f"
}
2022-01-13 02:08:35 SUCCESS
FAPIValidateRequestObjectSigningAlg
Request object was signed with a permitted algorithm
alg
PS256
2022-01-13 02:08:35
FAPIBrazilValidateRequestObjectIdTokenACRClaims
acr claim is not requested
2022-01-13 02:08:35 SUCCESS
FAPIValidateRequestObjectExp
Request object contains a valid exp claim, expiry time
exp
"Jan 13, 2022, 2:13:31 AM"
2022-01-13 02:08:35 SUCCESS
FAPI1AdvancedValidateRequestObjectNBFClaim
nbf claim is valid
nbf
"Jan 13, 2022, 2:08:31 AM"
now
"Jan 13, 2022, 2:08:35 AM"
2022-01-13 02:08:35 INFO
ValidateRequestObjectClaims
Missing issuance time
2022-01-13 02:08:35
ValidateRequestObjectClaims
Request object does not contain a max_age claim
2022-01-13 02:08:35 SUCCESS
ValidateRequestObjectClaims
Request object claims passed all validation checks
2022-01-13 02:08:35 SUCCESS
EnsureNumericRequestObjectClaimsAreNotNull
None of the claims expected to have numeric values, have null values
numeric_claims
[
  "max_age"
]
2022-01-13 02:08:35 SUCCESS
EnsureRequestObjectDoesNotContainRequestOrRequestUri
Request object does not contain request or request_uri
2022-01-13 02:08:35 SUCCESS
EnsureRequestObjectDoesNotContainSubWithClientId
Request object does not contain Client Id in sub
2022-01-13 02:08:35 SUCCESS
ValidateRequestObjectSignature
Request object signature validated using a key in the client's JWKS and using the client's registered request_object_signing_alg
request_object
eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgifQ.eyJhdWQiOiJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1NhZnJhUlBUZXN0LyIsIm5iZiI6MTY0MjAzOTcxMSwic2NvcGUiOiJvcGVuaWQgY29uc2VudHMgY3VzdG9tZXJzIGFjY291bnRzIGNyZWRpdC1jYXJkcy1hY2NvdW50cyByZXNvdXJjZXMgaW52b2ljZS1maW5hbmNpbmdzIGZpbmFuY2luZ3MgbG9hbnMgdW5hcnJhbmdlZC1hY2NvdW50cy1vdmVyZHJhZnQgY29uc2VudDp1cm46Y29uZm9ybWFuY2Uub2lkZjpoTTVmUXdnVUN5IiwiaXNzIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUiLCJyZXNwb25zZV90eXBlIjoiY29kZSBpZF90b2tlbiIsInJlZGlyZWN0X3VyaSI6Imh0dHBzOi8vcG9ydGFsc3BhLWhtbC5zYWZyYS5jb20uYnIvY2FsbGJhY2siLCJzdGF0ZSI6IjUyODZmZmEzYjJmYTRlYmFhMjNlMThjMTU5MjdlMjZmIiwiZXhwIjoxNjQyMDQwMDExLCJub25jZSI6ImI5ZGFkNzBjNjI0ODQyZjA4YzMwODZlNjljNzkyYzVmIiwiY2xpZW50X2lkIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUifQ.taacsBmsk11Gpl9sltUqs2VfdXssO-myb0mK-5B6FJLm7FHOBhpMoeMP8z_-w1bRz2dz7UskwlkfLzR7IuBrZUv61FDyuGMlUdco4_v65feIz8WU9Vmf6fNPdEUoa8pLaXyijXMfaFfzgC9jMeeQbR_64ydVkRMCMFvg1xZKFYCDjpvwE3Bs_-FmAlZuZgtl-Y1vxTgXp9SbrIriPJpazOkfeJ_pi_KJYWYoLBpAZ9IynsE3ybzJpAuZaCs33ExZhIHg6Ru7NII4zOfgCwNiANrd5VDnLKDu3ofOFP1kFKvZGgO0q8Io74bS_rscco_-mmjsoF67oygsBou-_PU-Bg
request_object_signing_alg
PS256
jwk
Sun RSA public key, 2048 bits
  params: null
  modulus: 27317005133317805192806760528852339923492353512235657242373770667550482636383058152241763242899243590510886742369909995744634317769376156025319367773285730731881660146466929919531999356316138694239765585923733085598540913159621964662231658995625650459587810069348726397568662051897147600110311023758046324349410668829004864378877917443777578185960111723181521868093201680907747046475384551022492435381540942020065252906547519942072030894200912668741513959140858170657378829949009347461870925320758566164123500357237516086049488677768389753461936607006172049603857829706031784001244671456119721973322682338748251959301
  public exponent: 65537
2022-01-13 02:08:35 SUCCESS
EnsureMatchingRedirectUriInRequestObject
Redirect URI matched
actual
https://portalspa-hml.safra.com.br/callback
2022-01-13 02:08:35 SUCCESS
EnsureRequiredAuthorizationRequestParametersMatchRequestObject
Required http request parameters match request object claims
response_type
code id_token
client_id
client_XUwBuUHRMTVHAleZEJxH18815
2022-01-13 02:08:35 SUCCESS
EnsureOptionalAuthorizationRequestParametersMatchRequestObject
All http request parameters and request object claims match
2022-01-13 02:08:35 SUCCESS
EnsureAuthorizationHttpRequestContainsOpenIDScope
Found 'openid' in scope http request parameter
actual
[
  "openid",
  "consents",
  "customers",
  "accounts",
  "credit-cards-accounts",
  "resources",
  "invoice-financings",
  "financings",
  "loans",
  "unarranged-accounts-overdraft",
  "consent:urn:conformance.oidf:hM5fQwgUCy"
]
expected
openid
2022-01-13 02:08:35 SUCCESS
ExtractRequestedScopes
Requested scopes
scope
openid consents customers accounts credit-cards-accounts resources invoice-financings financings loans unarranged-accounts-overdraft consent:urn:conformance.oidf:hM5fQwgUCy
2022-01-13 02:08:35 SUCCESS
FAPIBrazilValidateConsentScope
Found consent scope in request
actual
[
  "openid",
  "consents",
  "customers",
  "accounts",
  "credit-cards-accounts",
  "resources",
  "invoice-financings",
  "financings",
  "loans",
  "unarranged-accounts-overdraft",
  "consent:urn:conformance.oidf:hM5fQwgUCy"
]
expected
consent:urn:conformance.oidf:hM5fQwgUCy
2022-01-13 02:08:35 SUCCESS
EnsureScopeContainsAccounts
Found accounts scope in request
actual
[
  "openid",
  "consents",
  "customers",
  "accounts",
  "credit-cards-accounts",
  "resources",
  "invoice-financings",
  "financings",
  "loans",
  "unarranged-accounts-overdraft",
  "consent:urn:conformance.oidf:hM5fQwgUCy"
]
2022-01-13 02:08:35 SUCCESS
EnsureResponseTypeIsCodeIdToken
Response type is expected value
expected
code id_token
2022-01-13 02:08:35 SUCCESS
EnsureOpenIDInScopeRequest
Found 'openid' scope in request
actual
[
  "openid",
  "consents",
  "customers",
  "accounts",
  "credit-cards-accounts",
  "resources",
  "invoice-financings",
  "financings",
  "loans",
  "unarranged-accounts-overdraft",
  "consent:urn:conformance.oidf:hM5fQwgUCy"
]
expected
openid
2022-01-13 02:08:35 SUCCESS
EnsureMatchingClientId
Client ID matched
client_id
client_XUwBuUHRMTVHAleZEJxH18815
2022-01-13 02:08:35 SUCCESS
CreateAuthorizationCode
Created authorization code
authorization_code
QvyJpwKWXD1chpunjjAaEuOzKCv9b32q
2022-01-13 02:08:35 SUCCESS
ExtractNonceFromAuthorizationRequest
Extracted nonce
nonce
b9dad70c624842f08c3086e69c792c5f
2022-01-13 02:08:35 SUCCESS
CalculateCHash
Successful c_hash encoding
c_hash
KtSRkXtUZ5js9maYK_niqg
2022-01-13 02:08:35 SUCCESS
CalculateSHash
Successful s_hash encoding
s_hash
8dYnQJ9uqXybOCvqA0JiaA
2022-01-13 02:08:35 SUCCESS
GenerateIdTokenClaims
Created ID Token Claims
iss
https://www.certification.openid.net/test/a/SafraRPTest/
sub
user-subject-1234531
aud
client_XUwBuUHRMTVHAleZEJxH18815
nonce
b9dad70c624842f08c3086e69c792c5f
iat
1642039715
exp
1642040015
2022-01-13 02:08:35
FAPIBrazilAddCPFAndCPNJToIdTokenClaims
Request object does not contain a claims element.id_token
2022-01-13 02:08:35 SUCCESS
AddCHashToIdTokenClaims
Added c_hash to ID token claims
c_hash
KtSRkXtUZ5js9maYK_niqg
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "sub": "user-subject-1234531",
  "aud": "client_XUwBuUHRMTVHAleZEJxH18815",
  "nonce": "b9dad70c624842f08c3086e69c792c5f",
  "iat": 1642039715,
  "exp": 1642040015,
  "c_hash": "KtSRkXtUZ5js9maYK_niqg"
}
2022-01-13 02:08:35 SUCCESS
AddSHashToIdTokenClaims
Added s_hash to ID token claims
s_hash
8dYnQJ9uqXybOCvqA0JiaA
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "sub": "user-subject-1234531",
  "aud": "client_XUwBuUHRMTVHAleZEJxH18815",
  "nonce": "b9dad70c624842f08c3086e69c792c5f",
  "iat": 1642039715,
  "exp": 1642040015,
  "c_hash": "KtSRkXtUZ5js9maYK_niqg",
  "s_hash": "8dYnQJ9uqXybOCvqA0JiaA"
}
2022-01-13 02:08:35 INFO
AddAtHashToIdTokenClaims
Skipped evaluation due to missing required string: at_hash
expected
at_hash
2022-01-13 02:08:35 INFO
FAPIBrazilAddACRClaimToIdTokenClaims
Skipped evaluation due to missing required string: requested_id_token_acr_values
expected
requested_id_token_acr_values
2022-01-13 02:08:35 SUCCESS
SignIdToken
Signed the ID token
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6ImNsaWVudF9YVXdCdVVIUk1UVkhBbGVaRUp4SDE4ODE1IiwiY19oYXNoIjoiS3RTUmtYdFVaNWpzOW1hWUtfbmlxZyIsInNfaGFzaCI6IjhkWW5RSjl1cVh5Yk9DdnFBMEppYUEiLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvU2FmcmFSUFRlc3RcLyIsImV4cCI6MTY0MjA0MDAxNSwibm9uY2UiOiJiOWRhZDcwYzYyNDg0MmYwOGMzMDg2ZTY5Yzc5MmM1ZiIsImlhdCI6MTY0MjAzOTcxNX0.PVvM-_GRd_RENdEqgmjYLILE6RqHcLWVSkN-kcOOb5V6-OTbu2XwRnBEDKl1j8ylBMq3Hi2FM1aj6ywwNiQH2dl0BzyRgDA9phezqXg_AHWJ1fLBwKT6VvKcc9EzVLUaJGf-6m4yuEGWawP2Bhgy-LthQdKUHimF-nVa04Bf7uhkHRzTI8n72T2hku3TiPagD8vXRijfoc_uY_n-PmqpA9lSsneKFfQHT_cKBF7CkdEB2dueqhTtCj4A5ydDWkgtYx8nPuKrs_Z84gMv0WsWPDy3DFHyl5V9R5hVY3-l9qJhDgUnN6aObLSChUsdZDwTa63Aj6dToZHCNodHB1uKvA
2022-01-13 02:08:35 SUCCESS
FAPIBrazilChangeConsentStatusToAuthorized
Changed consent status to AUTHORISED
consent
{
  "data": {
    "consentId": "urn:conformance.oidf:hM5fQwgUCy",
    "creationDateTime": "2022-01-13T02:08:30Z",
    "status": "AUTHORISED",
    "statusUpdateDateTime": "2022-01-13T02:08:35Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2022-01-13T04:08:30Z",
    "transactionFromDateTime": "2022-01-13T02:03:30Z",
    "transactionToDateTime": "2022-01-13T04:08:30Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/SafraRPTestconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2022-01-13T02:08:30Z"
  }
}
2022-01-13 02:08:35 SUCCESS
CreateAuthorizationEndpointResponseParams
Added authorization_endpoint_response_params to environment
params
{
  "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
  "state": "5286ffa3b2fa4ebaa23e18c15927e26f"
}
2022-01-13 02:08:35 SUCCESS
AddCodeToAuthorizationEndpointResponseParams
Added code to authorization endpoint response params
authorization_endpoint_response_params
{
  "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
  "state": "5286ffa3b2fa4ebaa23e18c15927e26f",
  "code": "QvyJpwKWXD1chpunjjAaEuOzKCv9b32q"
}
2022-01-13 02:08:35 SUCCESS
AddIdTokenToAuthorizationEndpointResponseParams
Added id_token to authorization endpoint response params
authorization_endpoint_response_params
{
  "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
  "state": "5286ffa3b2fa4ebaa23e18c15927e26f",
  "code": "QvyJpwKWXD1chpunjjAaEuOzKCv9b32q",
  "id_token": "eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6ImNsaWVudF9YVXdCdVVIUk1UVkhBbGVaRUp4SDE4ODE1IiwiY19oYXNoIjoiS3RTUmtYdFVaNWpzOW1hWUtfbmlxZyIsInNfaGFzaCI6IjhkWW5RSjl1cVh5Yk9DdnFBMEppYUEiLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvU2FmcmFSUFRlc3RcLyIsImV4cCI6MTY0MjA0MDAxNSwibm9uY2UiOiJiOWRhZDcwYzYyNDg0MmYwOGMzMDg2ZTY5Yzc5MmM1ZiIsImlhdCI6MTY0MjAzOTcxNX0.PVvM-_GRd_RENdEqgmjYLILE6RqHcLWVSkN-kcOOb5V6-OTbu2XwRnBEDKl1j8ylBMq3Hi2FM1aj6ywwNiQH2dl0BzyRgDA9phezqXg_AHWJ1fLBwKT6VvKcc9EzVLUaJGf-6m4yuEGWawP2Bhgy-LthQdKUHimF-nVa04Bf7uhkHRzTI8n72T2hku3TiPagD8vXRijfoc_uY_n-PmqpA9lSsneKFfQHT_cKBF7CkdEB2dueqhTtCj4A5ydDWkgtYx8nPuKrs_Z84gMv0WsWPDy3DFHyl5V9R5hVY3-l9qJhDgUnN6aObLSChUsdZDwTa63Aj6dToZHCNodHB1uKvA"
}
2022-01-13 02:08:35
SendAuthorizationResponseWithResponseModeFragment
Redirecting back to client
uri
https://portalspa-hml.safra.com.br/callback#state=5286ffa3b2fa4ebaa23e18c15927e26f&code=QvyJpwKWXD1chpunjjAaEuOzKCv9b32q&id_token=eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6ImNsaWVudF9YVXdCdVVIUk1UVkhBbGVaRUp4SDE4ODE1IiwiY19oYXNoIjoiS3RTUmtYdFVaNWpzOW1hWUtfbmlxZyIsInNfaGFzaCI6IjhkWW5RSjl1cVh5Yk9DdnFBMEppYUEiLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvU2FmcmFSUFRlc3RcLyIsImV4cCI6MTY0MjA0MDAxNSwibm9uY2UiOiJiOWRhZDcwYzYyNDg0MmYwOGMzMDg2ZTY5Yzc5MmM1ZiIsImlhdCI6MTY0MjAzOTcxNX0.PVvM-_GRd_RENdEqgmjYLILE6RqHcLWVSkN-kcOOb5V6-OTbu2XwRnBEDKl1j8ylBMq3Hi2FM1aj6ywwNiQH2dl0BzyRgDA9phezqXg_AHWJ1fLBwKT6VvKcc9EzVLUaJGf-6m4yuEGWawP2Bhgy-LthQdKUHimF-nVa04Bf7uhkHRzTI8n72T2hku3TiPagD8vXRijfoc_uY_n-PmqpA9lSsneKFfQHT_cKBF7CkdEB2dueqhTtCj4A5ydDWkgtYx8nPuKrs_Z84gMv0WsWPDy3DFHyl5V9R5hVY3-l9qJhDgUnN6aObLSChUsdZDwTa63Aj6dToZHCNodHB1uKvA
2022-01-13 02:08:35 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance WxAbxHSlSbGFkXI
outgoing
org.springframework.web.servlet.view.RedirectView: [RedirectView]; URL [https://portalspa-hml.safra.com.br/callback#state=5286ffa3b2fa4ebaa23e18c15927e26f&code=QvyJpwKWXD1chpunjjAaEuOzKCv9b32q&id_token=eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6ImNsaWVudF9YVXdCdVVIUk1UVkhBbGVaRUp4SDE4ODE1IiwiY19oYXNoIjoiS3RTUmtYdFVaNWpzOW1hWUtfbmlxZyIsInNfaGFzaCI6IjhkWW5RSjl1cVh5Yk9DdnFBMEppYUEiLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvU2FmcmFSUFRlc3RcLyIsImV4cCI6MTY0MjA0MDAxNSwibm9uY2UiOiJiOWRhZDcwYzYyNDg0MmYwOGMzMDg2ZTY5Yzc5MmM1ZiIsImlhdCI6MTY0MjAzOTcxNX0.PVvM-_GRd_RENdEqgmjYLILE6RqHcLWVSkN-kcOOb5V6-OTbu2XwRnBEDKl1j8ylBMq3Hi2FM1aj6ywwNiQH2dl0BzyRgDA9phezqXg_AHWJ1fLBwKT6VvKcc9EzVLUaJGf-6m4yuEGWawP2Bhgy-LthQdKUHimF-nVa04Bf7uhkHRzTI8n72T2hku3TiPagD8vXRijfoc_uY_n-PmqpA9lSsneKFfQHT_cKBF7CkdEB2dueqhTtCj4A5ydDWkgtYx8nPuKrs_Z84gMv0WsWPDy3DFHyl5V9R5hVY3-l9qJhDgUnN6aObLSChUsdZDwTa63Aj6dToZHCNodHB1uKvA]
outgoing_path
authorize
2022-01-13 02:08:37 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance WxAbxHSlSbGFkXI
incoming_headers
{
  "host": "www.certification.openid.net",
  "x-dynatrace": "FW4;-987853115;4;1343653795;25;0;-1738730375;491;62a0;2h01;3h501687a3;4h19;6hcdfac3a964232a9d52db101a5a5ae517;7hfd981c391783129e",
  "traceparent": "00-cdfac3a964232a9d52db101a5a5ae517-fd981c391783129e-01",
  "tracestate": "985d1479-c51e8ec5@dt\u003dfw4;4;501687a3;19;0;0;0;1eb;a09a;2h01;3h501687a3;4h19;7hfd981c391783129e",
  "content-type": "application/x-www-form-urlencoded",
  "x-cert": "MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPDo28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkxMzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2FmcmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iGVfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8bnE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyFSaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMBAAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkceRCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIuY3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0PAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wnLPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLOhUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqOVZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af1zroWKsv2A\u003d\u003d",
  "content-length": "1112",
  "connection": "close"
}
incoming_path
/test-mtls/a/SafraRPTest/token
incoming_body_form_params
{
  "grant_type": "authorization_code",
  "code": "QvyJpwKWXD1chpunjjAaEuOzKCv9b32q",
  "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
  "client_id": "client_XUwBuUHRMTVHAleZEJxH18815",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6ImFmZTlhNzlkYjgzMzQyYWE4NDFhNzhlZjhlMGM2OWExIiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDQwMDE2LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzOTcxNiwibmJmIjoxNjQyMDM5NzE2fQ.dtF0OrzvnPOoO1ws2ABK_eqsSZfrxrfz1RL7zCatN9BckDZzeUyO9zScyjGjOCm56QJ0yOjyJICnENUd9w6fkfOjPn40L8kQc36XteUy4FPj0yVeJbm8JqReGAqKbGT73PvJbGru4EGzHgWaSzMSZE5No8wfqkf-fEDimLpdNN3pHdL9NQGg1pD_ZBUdZ2jS9V28OTjPv3_B6dca3CfptOE4393pzaeaPwgQMckgaBrTgUTgRR_AkmyrGbs3WIXNi7JFBe099mryg4-aAY5LrW5orgK3gx8mHywzZ2c7vqwWGfK9___x75WFEOSuE3Qmv3ab4xpSs3Uju4UDVTyy_Q",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES256-GCM-SHA384
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A== -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
grant_type=authorization_code&code=QvyJpwKWXD1chpunjjAaEuOzKCv9b32q&redirect_uri=https%3A%2F%2Fportalspa-hml.safra.com.br%2Fcallback&client_id=client_XUwBuUHRMTVHAleZEJxH18815&client_assertion=eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6ImFmZTlhNzlkYjgzMzQyYWE4NDFhNzhlZjhlMGM2OWExIiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDQwMDE2LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzOTcxNiwibmJmIjoxNjQyMDM5NzE2fQ.dtF0OrzvnPOoO1ws2ABK_eqsSZfrxrfz1RL7zCatN9BckDZzeUyO9zScyjGjOCm56QJ0yOjyJICnENUd9w6fkfOjPn40L8kQc36XteUy4FPj0yVeJbm8JqReGAqKbGT73PvJbGru4EGzHgWaSzMSZE5No8wfqkf-fEDimLpdNN3pHdL9NQGg1pD_ZBUdZ2jS9V28OTjPv3_B6dca3CfptOE4393pzaeaPwgQMckgaBrTgUTgRR_AkmyrGbs3WIXNi7JFBe099mryg4-aAY5LrW5orgK3gx8mHywzZ2c7vqwWGfK9___x75WFEOSuE3Qmv3ab4xpSs3Uju4UDVTyy_Q&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2022-01-13 02:08:37 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES256-GCM-SHA384
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2022-01-13 02:08:37 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A\u003d\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3\nMDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx\nMzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm\ncmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp\ndmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ\nk/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi\nMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG\nVfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b\nnE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4\nC4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF\nSaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0\nPR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB\nAAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce\nRCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF\nBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w\nZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v\nY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu\nY3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P\nAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw\nggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl\ncnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl\ncyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg\ndXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg\nU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0\ndXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0\naWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG\nCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh\nc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn\nLPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO\nhUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+\nVibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1\nzHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO\nVZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af\n1zroWKsv2A\u003d\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003d44b261bc-4f6f-44ce-b3d7-3f98a2b225f4,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3538313630373839303030313238,CN\u003d*.safra.com.br,OU\u003d709138dd-6e9d-5f96-bfff-69a5b2cb3ec0,O\u003dBCO SAFRA S.A.,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "api-mtls-hml.safra.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2022-01-13 02:08:37 SUCCESS
CheckForClientCertificate
Found client certificate
2022-01-13 02:08:37 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3
MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx
MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm
cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp
dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ
k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG
VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b
nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4
C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF
SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0
PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB
AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce
RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF
BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w
ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v
Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu
Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P
AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw
ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl
cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl
cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg
dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg
U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0
dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0
aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG
CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh
c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn
LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO
hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+
Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1
zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO
VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af
1zroWKsv2A==
-----END CERTIFICATE-----
2022-01-13 02:08:37 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6ImFmZTlhNzlkYjgzMzQyYWE4NDFhNzhlZjhlMGM2OWExIiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDQwMDE2LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzOTcxNiwibmJmIjoxNjQyMDM5NzE2fQ.dtF0OrzvnPOoO1ws2ABK_eqsSZfrxrfz1RL7zCatN9BckDZzeUyO9zScyjGjOCm56QJ0yOjyJICnENUd9w6fkfOjPn40L8kQc36XteUy4FPj0yVeJbm8JqReGAqKbGT73PvJbGru4EGzHgWaSzMSZE5No8wfqkf-fEDimLpdNN3pHdL9NQGg1pD_ZBUdZ2jS9V28OTjPv3_B6dca3CfptOE4393pzaeaPwgQMckgaBrTgUTgRR_AkmyrGbs3WIXNi7JFBe099mryg4-aAY5LrW5orgK3gx8mHywzZ2c7vqwWGfK9___x75WFEOSuE3Qmv3ab4xpSs3Uju4UDVTyy_Q",
  "header": {
    "x5t": "imeJtvhk1_UOZIIOKtvS3EW0nDo",
    "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "client_XUwBuUHRMTVHAleZEJxH18815",
    "aud": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "nbf": 1642039716,
    "iss": "client_XUwBuUHRMTVHAleZEJxH18815",
    "exp": 1642040016,
    "iat": 1642039716,
    "jti": "afe9a79db83342aa841a78ef8e0c69a1"
  }
}
2022-01-13 02:08:37
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2022-01-13 02:08:37 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6ImFmZTlhNzlkYjgzMzQyYWE4NDFhNzhlZjhlMGM2OWExIiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDQwMDE2LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzOTcxNiwibmJmIjoxNjQyMDM5NzE2fQ.dtF0OrzvnPOoO1ws2ABK_eqsSZfrxrfz1RL7zCatN9BckDZzeUyO9zScyjGjOCm56QJ0yOjyJICnENUd9w6fkfOjPn40L8kQc36XteUy4FPj0yVeJbm8JqReGAqKbGT73PvJbGru4EGzHgWaSzMSZE5No8wfqkf-fEDimLpdNN3pHdL9NQGg1pD_ZBUdZ2jS9V28OTjPv3_B6dca3CfptOE4393pzaeaPwgQMckgaBrTgUTgRR_AkmyrGbs3WIXNi7JFBe099mryg4-aAY5LrW5orgK3gx8mHywzZ2c7vqwWGfK9___x75WFEOSuE3Qmv3ab4xpSs3Uju4UDVTyy_Q
2022-01-13 02:08:37 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2022-01-13 02:08:37 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2022-01-13 02:08:37 SUCCESS
ValidateAuthorizationCode
Found authorization code
authorization_code
QvyJpwKWXD1chpunjjAaEuOzKCv9b32q
2022-01-13 02:08:37 SUCCESS
ValidateRedirectUri
Found redirect uri
redirect_uri
https://portalspa-hml.safra.com.br/callback
2022-01-13 02:08:37 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
pdHf8nf1eAftZDpy0SAd19rargpVOkMEi1B3Izl3LXkZHcE1Ox
2022-01-13 02:08:37 SUCCESS
CalculateAtHash
Successful at_hash encoding
at_hash
6OZblpf6v08TVW-XE1Y7uA
2022-01-13 02:08:37
CreateRefreshToken
Created refresh token
refresh_token
YwVyeyfJfhxkrhgzwWRvJirGYMwSsRgsZRGfgnvIUCuOAfoSAs8740618391[]='@
2022-01-13 02:08:37 SUCCESS
GenerateIdTokenClaims
Created ID Token Claims
iss
https://www.certification.openid.net/test/a/SafraRPTest/
sub
user-subject-1234531
aud
client_XUwBuUHRMTVHAleZEJxH18815
nonce
b9dad70c624842f08c3086e69c792c5f
iat
1642039717
exp
1642040017
2022-01-13 02:08:37
FAPIBrazilAddCPFAndCPNJToIdTokenClaims
Request object does not contain a claims element.id_token
2022-01-13 02:08:37 SUCCESS
AddAtHashToIdTokenClaims
Added at_hash to ID token claims
at_hash
6OZblpf6v08TVW-XE1Y7uA
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "sub": "user-subject-1234531",
  "aud": "client_XUwBuUHRMTVHAleZEJxH18815",
  "nonce": "b9dad70c624842f08c3086e69c792c5f",
  "iat": 1642039717,
  "exp": 1642040017,
  "at_hash": "6OZblpf6v08TVW-XE1Y7uA"
}
2022-01-13 02:08:37 INFO
FAPIBrazilAddACRClaimToIdTokenClaims
Skipped evaluation due to missing required string: requested_id_token_acr_values
expected
requested_id_token_acr_values
2022-01-13 02:08:37 SUCCESS
SignIdToken
Signed the ID token
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdF9oYXNoIjoiNk9aYmxwZjZ2MDhUVlctWEUxWTd1QSIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUiLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvU2FmcmFSUFRlc3RcLyIsImV4cCI6MTY0MjA0MDAxNywibm9uY2UiOiJiOWRhZDcwYzYyNDg0MmYwOGMzMDg2ZTY5Yzc5MmM1ZiIsImlhdCI6MTY0MjAzOTcxN30.0ikGlwv_7ZYqQtyYueMUKtlizbJhJ3VDF5BJfwEjheTQPZRQ7d1dmnAmjT-rgFM1coolUyxInADag49EPTMRLnxr-D5HecIe1uHxGN9qyRaJmesgWsqrbXO5jw0CiWonickYYAjVkWc3ZAAKBg7X6qAgzvXGAQ3ZO4YEfYroONKFO60lz39ncAjkifHvfaF45U4PZ4RC9Or--8srPTyVKfO-Hld0-VAVtqZ3rZc_fV36ThEC4-HroqEbCMyDRv2YoldQ0HwBWEKcQePEmDn3RDBEAjqkhph5Ip0MdS7-F3DiPX9__zcgNC_jYfbeZnk1nFeNZGUBmOdK7HJYE2J1Bw
2022-01-13 02:08:37 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
pdHf8nf1eAftZDpy0SAd19rargpVOkMEi1B3Izl3LXkZHcE1Ox
token_type
Bearer
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdF9oYXNoIjoiNk9aYmxwZjZ2MDhUVlctWEUxWTd1QSIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUiLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvU2FmcmFSUFRlc3RcLyIsImV4cCI6MTY0MjA0MDAxNywibm9uY2UiOiJiOWRhZDcwYzYyNDg0MmYwOGMzMDg2ZTY5Yzc5MmM1ZiIsImlhdCI6MTY0MjAzOTcxN30.0ikGlwv_7ZYqQtyYueMUKtlizbJhJ3VDF5BJfwEjheTQPZRQ7d1dmnAmjT-rgFM1coolUyxInADag49EPTMRLnxr-D5HecIe1uHxGN9qyRaJmesgWsqrbXO5jw0CiWonickYYAjVkWc3ZAAKBg7X6qAgzvXGAQ3ZO4YEfYroONKFO60lz39ncAjkifHvfaF45U4PZ4RC9Or--8srPTyVKfO-Hld0-VAVtqZ3rZc_fV36ThEC4-HroqEbCMyDRv2YoldQ0HwBWEKcQePEmDn3RDBEAjqkhph5Ip0MdS7-F3DiPX9__zcgNC_jYfbeZnk1nFeNZGUBmOdK7HJYE2J1Bw
refresh_token
YwVyeyfJfhxkrhgzwWRvJirGYMwSsRgsZRGfgnvIUCuOAfoSAs8740618391[]='@
scope
openid consents customers accounts credit-cards-accounts resources invoice-financings financings loans unarranged-accounts-overdraft consent:urn:conformance.oidf:hM5fQwgUCy
2022-01-13 02:08:37
RemoveIssuedAccessTokenFromEnvironment
Removed access_token and token_type from environment
2022-01-13 02:08:37 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance WxAbxHSlSbGFkXI
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "pdHf8nf1eAftZDpy0SAd19rargpVOkMEi1B3Izl3LXkZHcE1Ox",
  "token_type": "Bearer",
  "id_token": "eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdF9oYXNoIjoiNk9aYmxwZjZ2MDhUVlctWEUxWTd1QSIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUiLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvU2FmcmFSUFRlc3RcLyIsImV4cCI6MTY0MjA0MDAxNywibm9uY2UiOiJiOWRhZDcwYzYyNDg0MmYwOGMzMDg2ZTY5Yzc5MmM1ZiIsImlhdCI6MTY0MjAzOTcxN30.0ikGlwv_7ZYqQtyYueMUKtlizbJhJ3VDF5BJfwEjheTQPZRQ7d1dmnAmjT-rgFM1coolUyxInADag49EPTMRLnxr-D5HecIe1uHxGN9qyRaJmesgWsqrbXO5jw0CiWonickYYAjVkWc3ZAAKBg7X6qAgzvXGAQ3ZO4YEfYroONKFO60lz39ncAjkifHvfaF45U4PZ4RC9Or--8srPTyVKfO-Hld0-VAVtqZ3rZc_fV36ThEC4-HroqEbCMyDRv2YoldQ0HwBWEKcQePEmDn3RDBEAjqkhph5Ip0MdS7-F3DiPX9__zcgNC_jYfbeZnk1nFeNZGUBmOdK7HJYE2J1Bw",
  "refresh_token": "YwVyeyfJfhxkrhgzwWRvJirGYMwSsRgsZRGfgnvIUCuOAfoSAs8740618391[]\u003d\u0027@",
  "scope": "openid consents customers accounts credit-cards-accounts resources invoice-financings financings loans unarranged-accounts-overdraft consent:urn:conformance.oidf:hM5fQwgUCy"
}
outgoing_path
token
2022-01-13 02:08:37 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance WxAbxHSlSbGFkXI
incoming_headers
{
  "host": "www.certification.openid.net",
  "authorization": "Bearer pdHf8nf1eAftZDpy0SAd19rargpVOkMEi1B3Izl3LXkZHcE1Ox",
  "x-dynatrace": "FW4;-987853115;4;1343653795;25;1;-1738730375;491;91e8;2h01;3h501687a3;4h19;6hcdfac3a964232a9d52db101a5a5ae517;7h609ae789cc77a430",
  "traceparent": "00-cdfac3a964232a9d52db101a5a5ae517-609ae789cc77a430-01",
  "tracestate": "985d1479-c51e8ec5@dt\u003dfw4;4;501687a3;19;1;0;0;1eb;d4eb;2h01;3h501687a3;4h19;7h609ae789cc77a430",
  "cookie": "JSESSIONID\u003d9BD7F4A0F4AFC5BD174340F6CF6F2611",
  "connection": "close"
}
incoming_path
/test-mtls/a/SafraRPTest/accounts/v1/accounts
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES256-GCM-SHA384
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A== -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
2022-01-13 02:08:37 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES256-GCM-SHA384
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Accounts endpoint (always rejected)
2022-01-13 02:08:37 SUCCESS
LogAccessTokenAlwaysRejectedToForceARefreshGrant
This call will be always rejected. The client must obtain a new access token twice using the refresh_token
2022-01-13 02:08:37 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance WxAbxHSlSbGFkXI
outgoing_status_code
401
outgoing_headers
{
  "WWW-Authenticate": [
    "Bearer realm\u003d\"conformancesuite\", error\u003d\"invalid_token\", error_description\u003d\"Invalid access token. This test requires you to obtain a new access token twice using the refresh_token\""
  ]
}
outgoing_body
outgoing_path
accounts/v1/accounts
2022-01-13 02:08:37 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance WxAbxHSlSbGFkXI
incoming_headers
{
  "host": "www.certification.openid.net",
  "x-dynatrace": "FW4;-987853115;4;1343653795;25;2;-1738730375;491;c929;2h01;3h501687a3;4h19;6hcdfac3a964232a9d52db101a5a5ae517;7h3ad1dc2ddef927e5",
  "traceparent": "00-cdfac3a964232a9d52db101a5a5ae517-3ad1dc2ddef927e5-01",
  "tracestate": "985d1479-c51e8ec5@dt\u003dfw4;4;501687a3;19;2;0;0;1eb;63d6;2h01;3h501687a3;4h19;7h3ad1dc2ddef927e5",
  "cookie": "JSESSIONID\u003d9BD7F4A0F4AFC5BD174340F6CF6F2611",
  "content-type": "application/x-www-form-urlencoded",
  "content-length": "1094",
  "connection": "close"
}
incoming_path
/test-mtls/a/SafraRPTest/token
incoming_body_form_params
{
  "grant_type": "refresh_token",
  "refresh_token": "YwVyeyfJfhxkrhgzwWRvJirGYMwSsRgsZRGfgnvIUCuOAfoSAs8740618391[]\u003d\u0027@",
  "client_id": "client_XUwBuUHRMTVHAleZEJxH18815",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjExNzc0ZjZmMDYyNDQ5ZGE5M2Y0NTkwZjAxYTY1OGE4IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDQwMDE3LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzOTcxNywibmJmIjoxNjQyMDM5NzE3fQ.0LpK5k68j9Y5fOXgL80XfDOIWX9UftEC3GoHZOVYD-eHdBwnAKOjJuJNB3ryDm5v_mvqva_PxmZdbzkJeNpB9gsEv75NSIV-EOGK760i_mcoLcrYezAqT4TNdfsmb-SnWW-XhA1Ooi4fHSwTwyNJueGWKUW4oncfnO5AEwOa6QBt1Al26AunueCxm68rWt5h0E-T6ufGgqV4q4cL7LeW_UN8sjDdW1-kdTYjIFdDzhowccczGttUON5tfPpwcjvzCg70WzguJZDIwp3HdH_D1Al0R1FQaq_IH-ODNO8jvtxFKVOrakSoLppLbq43zBiMXulgXVbaEa0OphW27vzZDw",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES256-GCM-SHA384
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A== -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
grant_type=refresh_token&refresh_token=YwVyeyfJfhxkrhgzwWRvJirGYMwSsRgsZRGfgnvIUCuOAfoSAs8740618391%5B%5D%3D%27%40&client_id=client_XUwBuUHRMTVHAleZEJxH18815&client_assertion=eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjExNzc0ZjZmMDYyNDQ5ZGE5M2Y0NTkwZjAxYTY1OGE4IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDQwMDE3LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzOTcxNywibmJmIjoxNjQyMDM5NzE3fQ.0LpK5k68j9Y5fOXgL80XfDOIWX9UftEC3GoHZOVYD-eHdBwnAKOjJuJNB3ryDm5v_mvqva_PxmZdbzkJeNpB9gsEv75NSIV-EOGK760i_mcoLcrYezAqT4TNdfsmb-SnWW-XhA1Ooi4fHSwTwyNJueGWKUW4oncfnO5AEwOa6QBt1Al26AunueCxm68rWt5h0E-T6ufGgqV4q4cL7LeW_UN8sjDdW1-kdTYjIFdDzhowccczGttUON5tfPpwcjvzCg70WzguJZDIwp3HdH_D1Al0R1FQaq_IH-ODNO8jvtxFKVOrakSoLppLbq43zBiMXulgXVbaEa0OphW27vzZDw&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2022-01-13 02:08:37 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES256-GCM-SHA384
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2022-01-13 02:08:37 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A\u003d\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3\nMDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx\nMzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm\ncmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp\ndmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ\nk/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi\nMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG\nVfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b\nnE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4\nC4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF\nSaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0\nPR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB\nAAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce\nRCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF\nBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w\nZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v\nY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu\nY3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P\nAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw\nggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl\ncnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl\ncyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg\ndXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg\nU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0\ndXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0\naWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG\nCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh\nc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn\nLPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO\nhUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+\nVibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1\nzHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO\nVZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af\n1zroWKsv2A\u003d\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003d44b261bc-4f6f-44ce-b3d7-3f98a2b225f4,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3538313630373839303030313238,CN\u003d*.safra.com.br,OU\u003d709138dd-6e9d-5f96-bfff-69a5b2cb3ec0,O\u003dBCO SAFRA S.A.,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "api-mtls-hml.safra.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2022-01-13 02:08:37 SUCCESS
CheckForClientCertificate
Found client certificate
2022-01-13 02:08:37 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3
MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx
MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm
cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp
dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ
k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG
VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b
nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4
C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF
SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0
PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB
AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce
RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF
BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w
ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v
Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu
Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P
AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw
ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl
cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl
cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg
dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg
U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0
dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0
aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG
CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh
c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn
LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO
hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+
Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1
zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO
VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af
1zroWKsv2A==
-----END CERTIFICATE-----
2022-01-13 02:08:37 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjExNzc0ZjZmMDYyNDQ5ZGE5M2Y0NTkwZjAxYTY1OGE4IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDQwMDE3LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzOTcxNywibmJmIjoxNjQyMDM5NzE3fQ.0LpK5k68j9Y5fOXgL80XfDOIWX9UftEC3GoHZOVYD-eHdBwnAKOjJuJNB3ryDm5v_mvqva_PxmZdbzkJeNpB9gsEv75NSIV-EOGK760i_mcoLcrYezAqT4TNdfsmb-SnWW-XhA1Ooi4fHSwTwyNJueGWKUW4oncfnO5AEwOa6QBt1Al26AunueCxm68rWt5h0E-T6ufGgqV4q4cL7LeW_UN8sjDdW1-kdTYjIFdDzhowccczGttUON5tfPpwcjvzCg70WzguJZDIwp3HdH_D1Al0R1FQaq_IH-ODNO8jvtxFKVOrakSoLppLbq43zBiMXulgXVbaEa0OphW27vzZDw",
  "header": {
    "x5t": "imeJtvhk1_UOZIIOKtvS3EW0nDo",
    "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "client_XUwBuUHRMTVHAleZEJxH18815",
    "aud": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "nbf": 1642039717,
    "iss": "client_XUwBuUHRMTVHAleZEJxH18815",
    "exp": 1642040017,
    "iat": 1642039717,
    "jti": "11774f6f062449da93f4590f01a658a8"
  }
}
2022-01-13 02:08:37
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2022-01-13 02:08:37 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjExNzc0ZjZmMDYyNDQ5ZGE5M2Y0NTkwZjAxYTY1OGE4IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDQwMDE3LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzOTcxNywibmJmIjoxNjQyMDM5NzE3fQ.0LpK5k68j9Y5fOXgL80XfDOIWX9UftEC3GoHZOVYD-eHdBwnAKOjJuJNB3ryDm5v_mvqva_PxmZdbzkJeNpB9gsEv75NSIV-EOGK760i_mcoLcrYezAqT4TNdfsmb-SnWW-XhA1Ooi4fHSwTwyNJueGWKUW4oncfnO5AEwOa6QBt1Al26AunueCxm68rWt5h0E-T6ufGgqV4q4cL7LeW_UN8sjDdW1-kdTYjIFdDzhowccczGttUON5tfPpwcjvzCg70WzguJZDIwp3HdH_D1Al0R1FQaq_IH-ODNO8jvtxFKVOrakSoLppLbq43zBiMXulgXVbaEa0OphW27vzZDw
2022-01-13 02:08:37 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2022-01-13 02:08:37 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2022-01-13 02:08:37 SUCCESS
ValidateRefreshToken
refresh_token parameter matches the expected value.
refresh_token
YwVyeyfJfhxkrhgzwWRvJirGYMwSsRgsZRGfgnvIUCuOAfoSAs8740618391[]='@
2022-01-13 02:08:37 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
AMLjW88SyTB7uwKlhBdEBnOjbEG07faKlufO5jLPpyJQVNtc93
2022-01-13 02:08:37 SUCCESS
CalculateAtHash
Successful at_hash encoding
at_hash
A9-ojeKlrj7o3gIEdTSaYw
2022-01-13 02:08:37
CreateRefreshToken
Created refresh token
refresh_token
wqmcaopeEwHsKuQoXBgrkrjXyokcXqrnCyWcuZWKIHQIPULECT5808479191+)|; 
2022-01-13 02:08:37 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
AMLjW88SyTB7uwKlhBdEBnOjbEG07faKlufO5jLPpyJQVNtc93
token_type
Bearer
refresh_token
wqmcaopeEwHsKuQoXBgrkrjXyokcXqrnCyWcuZWKIHQIPULECT5808479191+)|; 
scope
openid consents customers accounts credit-cards-accounts resources invoice-financings financings loans unarranged-accounts-overdraft consent:urn:conformance.oidf:hM5fQwgUCy
2022-01-13 02:08:37 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance WxAbxHSlSbGFkXI
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "AMLjW88SyTB7uwKlhBdEBnOjbEG07faKlufO5jLPpyJQVNtc93",
  "token_type": "Bearer",
  "refresh_token": "wqmcaopeEwHsKuQoXBgrkrjXyokcXqrnCyWcuZWKIHQIPULECT5808479191+)|; ",
  "scope": "openid consents customers accounts credit-cards-accounts resources invoice-financings financings loans unarranged-accounts-overdraft consent:urn:conformance.oidf:hM5fQwgUCy"
}
outgoing_path
token
2022-01-13 02:08:38 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance WxAbxHSlSbGFkXI
incoming_headers
{
  "host": "www.certification.openid.net",
  "x-dynatrace": "FW4;-987853115;4;1343653795;25;3;-1738730375;491;46b8;2h01;3h501687a3;4h19;6hcdfac3a964232a9d52db101a5a5ae517;7hb2ca0a7b34982bc9",
  "traceparent": "00-cdfac3a964232a9d52db101a5a5ae517-b2ca0a7b34982bc9-01",
  "tracestate": "985d1479-c51e8ec5@dt\u003dfw4;4;501687a3;19;3;0;0;1eb;d894;2h01;3h501687a3;4h19;7hb2ca0a7b34982bc9",
  "cookie": "JSESSIONID\u003d9BD7F4A0F4AFC5BD174340F6CF6F2611",
  "content-type": "application/x-www-form-urlencoded",
  "content-length": "1092",
  "connection": "close"
}
incoming_path
/test-mtls/a/SafraRPTest/token
incoming_body_form_params
{
  "grant_type": "refresh_token",
  "refresh_token": "wqmcaopeEwHsKuQoXBgrkrjXyokcXqrnCyWcuZWKIHQIPULECT5808479191+)|; ",
  "client_id": "client_XUwBuUHRMTVHAleZEJxH18815",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjY0MWJlYjI0MDdkMDQwNmE5NmNiNzQ4OTNlZmZkN2I1IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDQwMDE4LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzOTcxOCwibmJmIjoxNjQyMDM5NzE4fQ.Kf7tAAWm1jcvGRsyz0A82g5bbQyw_7FEDw_-nYRL9_u4gzAH_H2e7qJ8cPd5Kzb6eKihAR874wTg1M283CSazY3YDlFkNXu246ESkdJsoiyd3SvHO9AWvRLauMtMSVJmumGnaik6EmO-AC7dOHhO_SAbb1WAyDH1kYHx1LcKqKJV7uP2s5tB6aRCvPZTBtAG1Qdo0WAq05E-qN2ZoA08FbCFR8aU3eORoQ1OwcKCvuq4vjdt7zpwknan3ksO3HQ-MwAiAlPf4w1efsjhgfcbCtc64rwoqa4z5tsZaj6elErErU-flJw9hTEq-RT1hPSWJJ4mf_nTF2OkyzhfiwVSkA",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES256-GCM-SHA384
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A== -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
grant_type=refresh_token&refresh_token=wqmcaopeEwHsKuQoXBgrkrjXyokcXqrnCyWcuZWKIHQIPULECT5808479191%2B%29%7C%3B+&client_id=client_XUwBuUHRMTVHAleZEJxH18815&client_assertion=eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjY0MWJlYjI0MDdkMDQwNmE5NmNiNzQ4OTNlZmZkN2I1IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDQwMDE4LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzOTcxOCwibmJmIjoxNjQyMDM5NzE4fQ.Kf7tAAWm1jcvGRsyz0A82g5bbQyw_7FEDw_-nYRL9_u4gzAH_H2e7qJ8cPd5Kzb6eKihAR874wTg1M283CSazY3YDlFkNXu246ESkdJsoiyd3SvHO9AWvRLauMtMSVJmumGnaik6EmO-AC7dOHhO_SAbb1WAyDH1kYHx1LcKqKJV7uP2s5tB6aRCvPZTBtAG1Qdo0WAq05E-qN2ZoA08FbCFR8aU3eORoQ1OwcKCvuq4vjdt7zpwknan3ksO3HQ-MwAiAlPf4w1efsjhgfcbCtc64rwoqa4z5tsZaj6elErErU-flJw9hTEq-RT1hPSWJJ4mf_nTF2OkyzhfiwVSkA&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2022-01-13 02:08:38 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES256-GCM-SHA384
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2022-01-13 02:08:38 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A\u003d\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3\nMDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx\nMzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm\ncmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp\ndmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ\nk/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi\nMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG\nVfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b\nnE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4\nC4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF\nSaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0\nPR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB\nAAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce\nRCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF\nBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w\nZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v\nY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu\nY3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P\nAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw\nggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl\ncnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl\ncyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg\ndXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg\nU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0\ndXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0\naWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG\nCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh\nc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn\nLPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO\nhUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+\nVibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1\nzHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO\nVZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af\n1zroWKsv2A\u003d\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003d44b261bc-4f6f-44ce-b3d7-3f98a2b225f4,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3538313630373839303030313238,CN\u003d*.safra.com.br,OU\u003d709138dd-6e9d-5f96-bfff-69a5b2cb3ec0,O\u003dBCO SAFRA S.A.,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "api-mtls-hml.safra.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2022-01-13 02:08:38 SUCCESS
CheckForClientCertificate
Found client certificate
2022-01-13 02:08:38 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3
MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx
MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm
cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp
dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ
k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG
VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b
nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4
C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF
SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0
PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB
AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce
RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF
BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w
ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v
Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu
Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P
AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw
ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl
cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl
cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg
dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg
U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0
dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0
aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG
CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh
c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn
LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO
hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+
Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1
zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO
VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af
1zroWKsv2A==
-----END CERTIFICATE-----
2022-01-13 02:08:38 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjY0MWJlYjI0MDdkMDQwNmE5NmNiNzQ4OTNlZmZkN2I1IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDQwMDE4LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzOTcxOCwibmJmIjoxNjQyMDM5NzE4fQ.Kf7tAAWm1jcvGRsyz0A82g5bbQyw_7FEDw_-nYRL9_u4gzAH_H2e7qJ8cPd5Kzb6eKihAR874wTg1M283CSazY3YDlFkNXu246ESkdJsoiyd3SvHO9AWvRLauMtMSVJmumGnaik6EmO-AC7dOHhO_SAbb1WAyDH1kYHx1LcKqKJV7uP2s5tB6aRCvPZTBtAG1Qdo0WAq05E-qN2ZoA08FbCFR8aU3eORoQ1OwcKCvuq4vjdt7zpwknan3ksO3HQ-MwAiAlPf4w1efsjhgfcbCtc64rwoqa4z5tsZaj6elErErU-flJw9hTEq-RT1hPSWJJ4mf_nTF2OkyzhfiwVSkA",
  "header": {
    "x5t": "imeJtvhk1_UOZIIOKtvS3EW0nDo",
    "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "client_XUwBuUHRMTVHAleZEJxH18815",
    "aud": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "nbf": 1642039718,
    "iss": "client_XUwBuUHRMTVHAleZEJxH18815",
    "exp": 1642040018,
    "iat": 1642039718,
    "jti": "641beb2407d0406a96cb74893effd7b5"
  }
}
2022-01-13 02:08:38
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2022-01-13 02:08:38 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjY0MWJlYjI0MDdkMDQwNmE5NmNiNzQ4OTNlZmZkN2I1IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDQwMDE4LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzOTcxOCwibmJmIjoxNjQyMDM5NzE4fQ.Kf7tAAWm1jcvGRsyz0A82g5bbQyw_7FEDw_-nYRL9_u4gzAH_H2e7qJ8cPd5Kzb6eKihAR874wTg1M283CSazY3YDlFkNXu246ESkdJsoiyd3SvHO9AWvRLauMtMSVJmumGnaik6EmO-AC7dOHhO_SAbb1WAyDH1kYHx1LcKqKJV7uP2s5tB6aRCvPZTBtAG1Qdo0WAq05E-qN2ZoA08FbCFR8aU3eORoQ1OwcKCvuq4vjdt7zpwknan3ksO3HQ-MwAiAlPf4w1efsjhgfcbCtc64rwoqa4z5tsZaj6elErErU-flJw9hTEq-RT1hPSWJJ4mf_nTF2OkyzhfiwVSkA
2022-01-13 02:08:38 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2022-01-13 02:08:38 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2022-01-13 02:08:38 SUCCESS
ValidateRefreshToken
refresh_token parameter matches the expected value.
refresh_token
wqmcaopeEwHsKuQoXBgrkrjXyokcXqrnCyWcuZWKIHQIPULECT5808479191+)|; 
2022-01-13 02:08:38 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
PU7cw8ehj6ijfiB0Bmp9xEpwSeCLj4nkxvoGMWWTpvsAz4mKXS
2022-01-13 02:08:38 SUCCESS
CalculateAtHash
Successful at_hash encoding
at_hash
nH3NplOj-tbNlm1KepBbww
2022-01-13 02:08:38
CreateRefreshToken
Created refresh token
refresh_token
OaszQoBiyophvtUwPHDLBTKRUiCKPtZIlrqwGcJoSsGRDNBrXt5579761411\#&_~
2022-01-13 02:08:38 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
PU7cw8ehj6ijfiB0Bmp9xEpwSeCLj4nkxvoGMWWTpvsAz4mKXS
token_type
Bearer
refresh_token
OaszQoBiyophvtUwPHDLBTKRUiCKPtZIlrqwGcJoSsGRDNBrXt5579761411\#&_~
scope
openid consents customers accounts credit-cards-accounts resources invoice-financings financings loans unarranged-accounts-overdraft consent:urn:conformance.oidf:hM5fQwgUCy
2022-01-13 02:08:38 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance WxAbxHSlSbGFkXI
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "PU7cw8ehj6ijfiB0Bmp9xEpwSeCLj4nkxvoGMWWTpvsAz4mKXS",
  "token_type": "Bearer",
  "refresh_token": "OaszQoBiyophvtUwPHDLBTKRUiCKPtZIlrqwGcJoSsGRDNBrXt5579761411\\#\u0026_~",
  "scope": "openid consents customers accounts credit-cards-accounts resources invoice-financings financings loans unarranged-accounts-overdraft consent:urn:conformance.oidf:hM5fQwgUCy"
}
outgoing_path
token
2022-01-13 02:08:38 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance WxAbxHSlSbGFkXI
incoming_headers
{
  "host": "www.certification.openid.net",
  "authorization": "Bearer PU7cw8ehj6ijfiB0Bmp9xEpwSeCLj4nkxvoGMWWTpvsAz4mKXS",
  "x-dynatrace": "FW4;-987853115;4;1343653795;25;4;-1738730375;491;e4d4;2h01;3h501687a3;4h19;6hcdfac3a964232a9d52db101a5a5ae517;7hcb7134215bbe7fb5",
  "traceparent": "00-cdfac3a964232a9d52db101a5a5ae517-cb7134215bbe7fb5-01",
  "tracestate": "985d1479-c51e8ec5@dt\u003dfw4;4;501687a3;19;4;0;0;1eb;9c80;2h01;3h501687a3;4h19;7hcb7134215bbe7fb5",
  "cookie": "JSESSIONID\u003d9BD7F4A0F4AFC5BD174340F6CF6F2611",
  "connection": "close"
}
incoming_path
/test-mtls/a/SafraRPTest/accounts/v1/accounts
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES256-GCM-SHA384
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A== -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
2022-01-13 02:08:38 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES256-GCM-SHA384
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Accounts endpoint
2022-01-13 02:08:38 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A\u003d\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3\nMDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx\nMzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm\ncmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp\ndmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ\nk/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi\nMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG\nVfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b\nnE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4\nC4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF\nSaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0\nPR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB\nAAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce\nRCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF\nBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w\nZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v\nY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu\nY3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P\nAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw\nggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl\ncnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl\ncyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg\ndXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg\nU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0\ndXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0\naWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG\nCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh\nc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn\nLPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO\nhUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+\nVibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1\nzHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO\nVZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af\n1zroWKsv2A\u003d\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003d44b261bc-4f6f-44ce-b3d7-3f98a2b225f4,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3538313630373839303030313238,CN\u003d*.safra.com.br,OU\u003d709138dd-6e9d-5f96-bfff-69a5b2cb3ec0,O\u003dBCO SAFRA S.A.,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "api-mtls-hml.safra.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2022-01-13 02:08:38 SUCCESS
CheckForClientCertificate
Found client certificate
2022-01-13 02:08:38 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3
MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx
MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm
cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp
dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ
k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG
VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b
nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4
C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF
SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0
PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB
AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce
RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF
BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w
ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v
Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu
Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P
AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw
ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl
cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl
cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg
dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg
U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0
dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0
aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG
CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh
c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn
LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO
hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+
Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1
zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO
VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af
1zroWKsv2A==
-----END CERTIFICATE-----
2022-01-13 02:08:38 SUCCESS
EnsureBearerAccessTokenNotInParams
Client correctly did not send access token in query parameters or form body
2022-01-13 02:08:38 SUCCESS
ExtractBearerAccessTokenFromHeader
Found access token on incoming request
access_token
PU7cw8ehj6ijfiB0Bmp9xEpwSeCLj4nkxvoGMWWTpvsAz4mKXS
2022-01-13 02:08:38 SUCCESS
RequireBearerAccessToken
Found access token in request
actual
PU7cw8ehj6ijfiB0Bmp9xEpwSeCLj4nkxvoGMWWTpvsAz4mKXS
2022-01-13 02:08:38 INFO
ExtractFapiDateHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-auth-date
path
headers.x-fapi-auth-date
mapped
object
incoming_request
2022-01-13 02:08:38 INFO
ExtractFapiIpAddressHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-customer-ip-address
path
headers.x-fapi-customer-ip-address
mapped
object
incoming_request
2022-01-13 02:08:38 INFO
ExtractFapiInteractionIdHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-interaction-id
path
headers.x-fapi-interaction-id
mapped
object
incoming_request
2022-01-13 02:08:38 SUCCESS
FAPIBrazilEnsureAuthorizationRequestScopesContainAccounts
'accounts' was included in authorization request scopes
actual
openid consents customers accounts credit-cards-accounts resources invoice-financings financings loans unarranged-accounts-overdraft consent:urn:conformance.oidf:hM5fQwgUCy
expected
accounts
2022-01-13 02:08:38 INFO
CreateFapiInteractionIdIfNeeded
Found existing FAPI interaction ID
fapi_interaction_id
3d8a394d-0c50-4b90-91db-e5c6804f10b3
2022-01-13 02:08:38 SUCCESS
CreateFAPIAccountEndpointResponse
Created account response object
accounts_endpoint_response
{
  "conformance-test-finished": "true"
}
accounts_endpoint_response_headers
{
  "x-fapi-interaction-id": "3d8a394d-0c50-4b90-91db-e5c6804f10b3",
  "content-type": "application/json; charset\u003dUTF-8"
}
2022-01-13 02:08:38 SUCCESS
CreateBrazilAccountsEndpointResponse
Created Brazil accounts response (Please note that this is a hardcoded response copied from API documentation)
accounts_endpoint_response
{
  "data": [
    {
      "brandName": "Organização A",
      "companyCnpj": "21128159000166",
      "type": "CONTA_DEPOSITO_A_VISTA",
      "compeCode": "001",
      "branchCode": "6272",
      "number": "94088392",
      "checkDigit": "4",
      "accountId": "92792126019929279212650822221989319252576"
    }
  ],
  "links": {
    "self": "https://api.banco.com.br/open-banking/api/v1/resource",
    "first": "https://api.banco.com.br/open-banking/api/v1/resource",
    "prev": "https://api.banco.com.br/open-banking/api/v1/resource",
    "next": "https://api.banco.com.br/open-banking/api/v1/resource",
    "last": "https://api.banco.com.br/open-banking/api/v1/resource"
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2022-01-13T02:08:38Z"
  }
}
accounts_endpoint_response_headers
{
  "x-fapi-interaction-id": "3d8a394d-0c50-4b90-91db-e5c6804f10b3",
  "content-type": "application/json"
}
2022-01-13 02:08:38
ClearAccessTokenFromRequest
Condition ran but did not log anything
2022-01-13 02:08:38 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance WxAbxHSlSbGFkXI
outgoing_status_code
200
outgoing_headers
{
  "x-fapi-interaction-id": [
    "3d8a394d-0c50-4b90-91db-e5c6804f10b3"
  ],
  "content-type": [
    "application/json"
  ]
}
outgoing_body
{
  "data": [
    {
      "brandName": "Organização A",
      "companyCnpj": "21128159000166",
      "type": "CONTA_DEPOSITO_A_VISTA",
      "compeCode": "001",
      "branchCode": "6272",
      "number": "94088392",
      "checkDigit": "4",
      "accountId": "92792126019929279212650822221989319252576"
    }
  ],
  "links": {
    "self": "https://api.banco.com.br/open-banking/api/v1/resource",
    "first": "https://api.banco.com.br/open-banking/api/v1/resource",
    "prev": "https://api.banco.com.br/open-banking/api/v1/resource",
    "next": "https://api.banco.com.br/open-banking/api/v1/resource",
    "last": "https://api.banco.com.br/open-banking/api/v1/resource"
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2022-01-13T02:08:38Z"
  }
}
outgoing_path
accounts/v1/accounts
2022-01-13 02:08:38 FINISHED
fapi1-advanced-final-client-refresh-token-test
Test has run to completion
testmodule_result
PASSED
2022-01-13 02:09:54
TEST-RUNNER
Alias has now been claimed by another test
alias
SafraRPTest
new_test_id
4AE9FvzkDvg6sMb
Test Results