Test Summary

Test Results

Expand All Collapse All
All times are UTC
2022-01-13 00:34:19 INFO
TEST-RUNNER
Test instance NNF1dOmOl5OGYx5 created
baseUrl
https://www.certification.openid.net/test/a/SafraRPTest
variant
{
  "client_auth_type": "private_key_jwt",
  "fapi_auth_request_method": "by_value",
  "fapi_jarm_type": "oidc",
  "fapi_profile": "openbanking_brazil",
  "fapi_response_mode": "plain_response"
}
alias
SafraRPTest
description
Safra Relying Party Test
planId
aHKQkRwE1nAwr
config
{
  "alias": "SafraRPTest",
  "description": "Safra Relying Party Test",
  "server": {
    "jwks": {
      "keys": [
        {
          "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
          "kty": "RSA",
          "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
          "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
          "e": "AQAB",
          "alg": "PS256",
          "use": "sig",
          "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
          "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
          "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
          "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
          "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
          "x5c": [
            "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
          ]
        },
        {
          "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
          "kty": "RSA",
          "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
          "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
          "e": "AQAB",
          "use": "enc",
          "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
          "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
          "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
          "alg": "RSA-OAEP",
          "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
          "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
        }
      ]
    }
  },
  "client": {
    "client_id": "client_XUwBuUHRMTVHAleZEJxH18815",
    "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
    "certificate": "-----BEGIN CERTIFICATE-----\nMIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3\nMDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx\nMzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm\ncmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp\ndmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ\nk/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi\nMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG\nVfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b\nnE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4\nC4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF\nSaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0\nPR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB\nAAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce\nRCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF\nBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w\nZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v\nY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu\nY3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P\nAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw\nggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl\ncnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl\ncyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg\ndXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg\nU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0\ndXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0\naWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG\nCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh\nc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn\nLPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO\nhUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+\nVibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1\nzHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO\nVZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af\n1zroWKsv2A\u003d\u003d\n-----END CERTIFICATE-----",
    "jwks": {
      "keys": [
        {
          "kty": "RSA",
          "e": "AQAB",
          "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
          "alg": "PS256",
          "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ"
        }
      ]
    }
  },
  "client2": {
    "client_id": "client_XUwBuUHRMTVHAleZEJxH18815",
    "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
    "id_token_encrypted_response_alg": "RSA-OAEP",
    "certificate": "-----BEGIN CERTIFICATE-----\nMIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3\nMDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx\nMzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm\ncmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp\ndmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ\nk/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi\nMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG\nVfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b\nnE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4\nC4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF\nSaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0\nPR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB\nAAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce\nRCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF\nBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w\nZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v\nY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu\nY3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P\nAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw\nggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl\ncnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl\ncyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg\ndXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg\nU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0\ndXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0\naWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG\nCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh\nc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn\nLPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO\nhUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+\nVibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1\nzHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO\nVZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af\n1zroWKsv2A\u003d\u003d\n-----END CERTIFICATE-----",
    "jwks": {
      "keys": [
        {
          "kty": "RSA",
          "e": "AQAB",
          "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
          "alg": "PS256",
          "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ",
          "use": "sig"
        },
        {
          "kty": "RSA",
          "e": "AQAB",
          "kid": "o_xvg824afVVwHrd1A7-zOGeH2yA0Y5aXdpOUOzj0dM",
          "n": "2ACeyabQj1JtNk8eKPs0dtPohlXzAjEzmn00NvZIDmAJP8qXgwjXmbeJJIpf2czYx8AOjWd4FjFdPPAubnCeAJkvG5xOF328KMXmpQFgmtKRaFhHgUCvmW_0uHYCvi-sR5ClYhJUnULmLCrt8q2hbODLuAuLpI4QsWtwJb3EsOjwjGCeSylm31UKL7aMuaPrzrtSijSkk2mBEpkA6yDeFXg8hUmmLbTdIHfhzYnEZ6KW8n1nJp3UcFXcMlIE09meffwqXHSrovJIk9qysUTv5hdatD0dZZDxPRQQ0qPN3wK8d8l4FMjJqHY6ifuV_qZu8WUSfe0VcCKDIez0X-C1xw",
          "use": "enc",
          "alg": "PS256"
        }
      ]
    },
    "id_token_encrypted_response_enc": "A256GCM"
  },
  "directory": {
    "keystore": "https://keystore.sandbox.directory.openbankingbrasil.org.br/"
  }
}
testName
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
2022-01-13 00:34:19 SUCCESS
FAPIBrazilGenerateServerConfiguration
Created server configuration
server
{
  "issuer": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/SafraRPTest/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true
}
issuer
https://www.certification.openid.net/test/a/SafraRPTest/
discoveryUrl
https://www.certification.openid.net/test/a/SafraRPTest/.well-known/openid-configuration
2022-01-13 00:34:19 SUCCESS
LoadServerJWKs
Parsed public and private JWK sets
server_jwks
{
  "keys": [
    {
      "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
      "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
      "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
      "kty": "RSA",
      "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
      "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
      "alg": "PS256"
    },
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
server_encryption_keys
{
  "keys": [
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
server_public_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "alg": "PS256",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "alg": "RSA-OAEP",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
2022-01-13 00:34:19 SUCCESS
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2022-01-13 00:34:19
SetServerSigningAlgToPS256
Successfully set signing algorithm to PS256
2022-01-13 00:34:19
FAPIBrazilSetGrantTypesSupportedInServerConfiguration
Successfully set grant_types_supported
server
{
  "issuer": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/SafraRPTest/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ]
}
2022-01-13 00:34:19
AddClaimsParameterSupportedTrueToServerConfiguration
Successfully added claims_parameter_supported to server configuration
server
{
  "issuer": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/SafraRPTest/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true
}
2022-01-13 00:34:19
FAPIBrazilAddBrazilSpecificSettingsToServerConfiguration
Added open banking Brazil specific server settings
server
{
  "issuer": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/SafraRPTest/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ]
}
2022-01-13 00:34:19
SetTokenEndpointAuthMethodsSupportedToPrivateKeyJWTOnly
Changed token_endpoint_auth_methods_supported to private_key_jwt only in server configuration
server_configuration
{
  "issuer": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/SafraRPTest/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ]
}
2022-01-13 00:34:19 SUCCESS
AddResponseTypeCodeIdTokenToServerConfiguration
Added code id_token as response type supported
response_types_supported
[
  "code id_token"
]
2022-01-13 00:34:19 SUCCESS
FAPIBrazilAddTokenEndpointAuthSigningAlgValuesSupportedToServer
Set token_endpoint_auth_signing_alg_values_supported
values
[
  "PS256"
]
2022-01-13 00:34:19 SUCCESS
CheckServerConfiguration
Found required server configuration keys
required
[
  "authorization_endpoint",
  "token_endpoint",
  "issuer"
]
2022-01-13 00:34:19 SUCCESS
FAPIEnsureMinimumServerKeyLength
Validated minimum key lengths for server_jwks
server_jwks
{
  "keys": [
    {
      "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
      "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
      "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
      "kty": "RSA",
      "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
      "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
      "alg": "PS256"
    },
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
2022-01-13 00:34:19 SUCCESS
LoadUserInfo
Added user information
user_info
{
  "sub": "user-subject-1234531",
  "name": "Demo T. User",
  "email": "user@example.com",
  "email_verified": false
}
Verify configuration of first client
2022-01-13 00:34:19 SUCCESS
GetStaticClientConfiguration
Found a static client object
client_id
client_XUwBuUHRMTVHAleZEJxH18815
redirect_uri
https://portalspa-hml.safra.com.br/callback
certificate
-----BEGIN CERTIFICATE-----
MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3
MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx
MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm
cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp
dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ
k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG
VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b
nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4
C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF
SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0
PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB
AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce
RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF
BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w
ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v
Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu
Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P
AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw
ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl
cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl
cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg
dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg
U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0
dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0
aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG
CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh
c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn
LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO
hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+
Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1
zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO
VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af
1zroWKsv2A==
-----END CERTIFICATE-----
jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ"
    }
  ]
}
2022-01-13 00:34:19 SUCCESS
ValidateClientJWKsPublicPart
Valid client JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2022-01-13 00:34:19 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ"
    }
  ]
}
2022-01-13 00:34:19 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2022-01-13 00:34:19 SUCCESS
EnsureClientJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2022-01-13 00:34:19 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ"
    }
  ]
}
Verify configuration of second client
2022-01-13 00:34:19 SUCCESS
GetStaticClient2Configuration
Found a static second client object
client_id
client_XUwBuUHRMTVHAleZEJxH18815
redirect_uri
https://portalspa-hml.safra.com.br/callback
id_token_encrypted_response_alg
RSA-OAEP
certificate
-----BEGIN CERTIFICATE-----
MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3
MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx
MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm
cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp
dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ
k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG
VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b
nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4
C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF
SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0
PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB
AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce
RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF
BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w
ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v
Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu
Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P
AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw
ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl
cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl
cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg
dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg
U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0
dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0
aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG
CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh
c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn
LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO
hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+
Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1
zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO
VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af
1zroWKsv2A==
-----END CERTIFICATE-----
jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ",
      "use": "sig"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "o_xvg824afVVwHrd1A7-zOGeH2yA0Y5aXdpOUOzj0dM",
      "n": "2ACeyabQj1JtNk8eKPs0dtPohlXzAjEzmn00NvZIDmAJP8qXgwjXmbeJJIpf2czYx8AOjWd4FjFdPPAubnCeAJkvG5xOF328KMXmpQFgmtKRaFhHgUCvmW_0uHYCvi-sR5ClYhJUnULmLCrt8q2hbODLuAuLpI4QsWtwJb3EsOjwjGCeSylm31UKL7aMuaPrzrtSijSkk2mBEpkA6yDeFXg8hUmmLbTdIHfhzYnEZ6KW8n1nJp3UcFXcMlIE09meffwqXHSrovJIk9qysUTv5hdatD0dZZDxPRQQ0qPN3wK8d8l4FMjJqHY6ifuV_qZu8WUSfe0VcCKDIez0X-C1xw",
      "use": "enc",
      "alg": "PS256"
    }
  ]
}
id_token_encrypted_response_enc
A256GCM
2022-01-13 00:34:19 SUCCESS
ValidateClientJWKsPublicPart
Valid client JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2022-01-13 00:34:19 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ",
      "use": "sig"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "o_xvg824afVVwHrd1A7-zOGeH2yA0Y5aXdpOUOzj0dM",
      "n": "2ACeyabQj1JtNk8eKPs0dtPohlXzAjEzmn00NvZIDmAJP8qXgwjXmbeJJIpf2czYx8AOjWd4FjFdPPAubnCeAJkvG5xOF328KMXmpQFgmtKRaFhHgUCvmW_0uHYCvi-sR5ClYhJUnULmLCrt8q2hbODLuAuLpI4QsWtwJb3EsOjwjGCeSylm31UKL7aMuaPrzrtSijSkk2mBEpkA6yDeFXg8hUmmLbTdIHfhzYnEZ6KW8n1nJp3UcFXcMlIE09meffwqXHSrovJIk9qysUTv5hdatD0dZZDxPRQQ0qPN3wK8d8l4FMjJqHY6ifuV_qZu8WUSfe0VcCKDIez0X-C1xw",
      "use": "enc",
      "alg": "PS256"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "o_xvg824afVVwHrd1A7-zOGeH2yA0Y5aXdpOUOzj0dM",
      "alg": "PS256",
      "n": "2ACeyabQj1JtNk8eKPs0dtPohlXzAjEzmn00NvZIDmAJP8qXgwjXmbeJJIpf2czYx8AOjWd4FjFdPPAubnCeAJkvG5xOF328KMXmpQFgmtKRaFhHgUCvmW_0uHYCvi-sR5ClYhJUnULmLCrt8q2hbODLuAuLpI4QsWtwJb3EsOjwjGCeSylm31UKL7aMuaPrzrtSijSkk2mBEpkA6yDeFXg8hUmmLbTdIHfhzYnEZ6KW8n1nJp3UcFXcMlIE09meffwqXHSrovJIk9qysUTv5hdatD0dZZDxPRQQ0qPN3wK8d8l4FMjJqHY6ifuV_qZu8WUSfe0VcCKDIez0X-C1xw"
    }
  ]
}
2022-01-13 00:34:19 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2022-01-13 00:34:19 SUCCESS
EnsureClientJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2022-01-13 00:34:19 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ",
      "use": "sig"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "o_xvg824afVVwHrd1A7-zOGeH2yA0Y5aXdpOUOzj0dM",
      "n": "2ACeyabQj1JtNk8eKPs0dtPohlXzAjEzmn00NvZIDmAJP8qXgwjXmbeJJIpf2czYx8AOjWd4FjFdPPAubnCeAJkvG5xOF328KMXmpQFgmtKRaFhHgUCvmW_0uHYCvi-sR5ClYhJUnULmLCrt8q2hbODLuAuLpI4QsWtwJb3EsOjwjGCeSylm31UKL7aMuaPrzrtSijSkk2mBEpkA6yDeFXg8hUmmLbTdIHfhzYnEZ6KW8n1nJp3UcFXcMlIE09meffwqXHSrovJIk9qysUTv5hdatD0dZZDxPRQQ0qPN3wK8d8l4FMjJqHY6ifuV_qZu8WUSfe0VcCKDIez0X-C1xw",
      "use": "enc",
      "alg": "PS256"
    }
  ]
}
2022-01-13 00:34:19
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Setup Done
2022-01-13 00:34:26 INCOMING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Incoming HTTP request to test instance NNF1dOmOl5OGYx5
incoming_headers
{
  "host": "www.certification.openid.net",
  "x-dynatrace": "FW4;-987853115;1;-1606248171;699;0;-1738730375;437;5bf3;2h01;3ha0429915;4h02bb;6hde011dd8a2db3d1831474968c0782bd2;7hd1e5be0263448e1a",
  "traceparent": "00-de011dd8a2db3d1831474968c0782bd2-d1e5be0263448e1a-01",
  "tracestate": "985d1479-c51e8ec5@dt\u003dfw4;1;a0429915;2bb;0;0;0;1b5;cfbf;2h01;3ha0429915;4h02bb;7hd1e5be0263448e1a",
  "request-id": "|9807a83f-4189dfe58fc996ae.1.",
  "content-type": "application/x-www-form-urlencoded",
  "content-length": "1024",
  "connection": "close"
}
incoming_path
/test-mtls/a/SafraRPTest/token
incoming_body_form_params
{
  "scope": "consents",
  "grant_type": "client_credentials",
  "client_id": "client_XUwBuUHRMTVHAleZEJxH18815",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjRiMTQ2N2YxMTRjOTQ1YjBhZGI5NzgzOTI4OWNkYjQ2IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDM0MzY1LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzNDA2NSwibmJmIjoxNjQyMDM0MDY1fQ.JOVTMWnGi8MIGnLsIiMjACzU00qZmtmaCsUjun6aFtjwrj7R3shhUZ5NQFmpulESSOffX6NTxsnkDbuGC7UwnmcB73GcvtYTw8zgYQU-gocYY6MHhSBxXWqLkURKw9OSJ15rj89QPsPX6yZNL2yy36iFynYZ_S5i6O86UG5HVSLlYgYo2UfPGaKGDsP0y1eBp0nUd_LrSP7Xx4gO1eeTde-KNzbWMQGYIsvzw5IfDtsXjYMXQk347R9KUA3bEKkxv7VgWaQ7MH-lmzZFl8Ll5qD_sfrWViDDDQg6OWZZXGu-_ljjuf6HunHrMSuqT6z38iKNoMpTBYvIBkj7QnX76w",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES256-GCM-SHA384
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A== -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
scope=consents&grant_type=client_credentials&client_id=client_XUwBuUHRMTVHAleZEJxH18815&client_assertion=eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjRiMTQ2N2YxMTRjOTQ1YjBhZGI5NzgzOTI4OWNkYjQ2IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDM0MzY1LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzNDA2NSwibmJmIjoxNjQyMDM0MDY1fQ.JOVTMWnGi8MIGnLsIiMjACzU00qZmtmaCsUjun6aFtjwrj7R3shhUZ5NQFmpulESSOffX6NTxsnkDbuGC7UwnmcB73GcvtYTw8zgYQU-gocYY6MHhSBxXWqLkURKw9OSJ15rj89QPsPX6yZNL2yy36iFynYZ_S5i6O86UG5HVSLlYgYo2UfPGaKGDsP0y1eBp0nUd_LrSP7Xx4gO1eeTde-KNzbWMQGYIsvzw5IfDtsXjYMXQk347R9KUA3bEKkxv7VgWaQ7MH-lmzZFl8Ll5qD_sfrWViDDDQg6OWZZXGu-_ljjuf6HunHrMSuqT6z38iKNoMpTBYvIBkj7QnX76w&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2022-01-13 00:34:26 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES256-GCM-SHA384
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2022-01-13 00:34:26 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A\u003d\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3\nMDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx\nMzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm\ncmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp\ndmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ\nk/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi\nMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG\nVfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b\nnE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4\nC4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF\nSaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0\nPR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB\nAAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce\nRCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF\nBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w\nZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v\nY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu\nY3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P\nAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw\nggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl\ncnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl\ncyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg\ndXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg\nU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0\ndXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0\naWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG\nCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh\nc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn\nLPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO\nhUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+\nVibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1\nzHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO\nVZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af\n1zroWKsv2A\u003d\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003d44b261bc-4f6f-44ce-b3d7-3f98a2b225f4,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3538313630373839303030313238,CN\u003d*.safra.com.br,OU\u003d709138dd-6e9d-5f96-bfff-69a5b2cb3ec0,O\u003dBCO SAFRA S.A.,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "api-mtls-hml.safra.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2022-01-13 00:34:26 SUCCESS
CheckForClientCertificate
Found client certificate
2022-01-13 00:34:26 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3
MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx
MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm
cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp
dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ
k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG
VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b
nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4
C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF
SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0
PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB
AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce
RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF
BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w
ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v
Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu
Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P
AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw
ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl
cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl
cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg
dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg
U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0
dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0
aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG
CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh
c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn
LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO
hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+
Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1
zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO
VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af
1zroWKsv2A==
-----END CERTIFICATE-----
2022-01-13 00:34:26 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjRiMTQ2N2YxMTRjOTQ1YjBhZGI5NzgzOTI4OWNkYjQ2IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDM0MzY1LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzNDA2NSwibmJmIjoxNjQyMDM0MDY1fQ.JOVTMWnGi8MIGnLsIiMjACzU00qZmtmaCsUjun6aFtjwrj7R3shhUZ5NQFmpulESSOffX6NTxsnkDbuGC7UwnmcB73GcvtYTw8zgYQU-gocYY6MHhSBxXWqLkURKw9OSJ15rj89QPsPX6yZNL2yy36iFynYZ_S5i6O86UG5HVSLlYgYo2UfPGaKGDsP0y1eBp0nUd_LrSP7Xx4gO1eeTde-KNzbWMQGYIsvzw5IfDtsXjYMXQk347R9KUA3bEKkxv7VgWaQ7MH-lmzZFl8Ll5qD_sfrWViDDDQg6OWZZXGu-_ljjuf6HunHrMSuqT6z38iKNoMpTBYvIBkj7QnX76w",
  "header": {
    "x5t": "imeJtvhk1_UOZIIOKtvS3EW0nDo",
    "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "client_XUwBuUHRMTVHAleZEJxH18815",
    "aud": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "nbf": 1642034065,
    "iss": "client_XUwBuUHRMTVHAleZEJxH18815",
    "exp": 1642034365,
    "iat": 1642034065,
    "jti": "4b1467f114c945b0adb97839289cdb46"
  }
}
2022-01-13 00:34:26
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2022-01-13 00:34:26 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjRiMTQ2N2YxMTRjOTQ1YjBhZGI5NzgzOTI4OWNkYjQ2IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDM0MzY1LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzNDA2NSwibmJmIjoxNjQyMDM0MDY1fQ.JOVTMWnGi8MIGnLsIiMjACzU00qZmtmaCsUjun6aFtjwrj7R3shhUZ5NQFmpulESSOffX6NTxsnkDbuGC7UwnmcB73GcvtYTw8zgYQU-gocYY6MHhSBxXWqLkURKw9OSJ15rj89QPsPX6yZNL2yy36iFynYZ_S5i6O86UG5HVSLlYgYo2UfPGaKGDsP0y1eBp0nUd_LrSP7Xx4gO1eeTde-KNzbWMQGYIsvzw5IfDtsXjYMXQk347R9KUA3bEKkxv7VgWaQ7MH-lmzZFl8Ll5qD_sfrWViDDDQg6OWZZXGu-_ljjuf6HunHrMSuqT6z38iKNoMpTBYvIBkj7QnX76w
2022-01-13 00:34:26 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2022-01-13 00:34:26 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2022-01-13 00:34:26 SUCCESS
FAPIBrazilExtractRequestedScopeFromClientCredentialsGrant
Found 'consents' scope in request
actual
[
  "consents"
]
expected
consents
2022-01-13 00:34:26 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
0j1Q4D7EKpHd9yWdstwliv3BvJnIHfiZi2whv69LaWdxYQPglY
2022-01-13 00:34:26 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
0j1Q4D7EKpHd9yWdstwliv3BvJnIHfiZi2whv69LaWdxYQPglY
token_type
Bearer
2022-01-13 00:34:26
CopyAccessTokenToClientCredentialsField
Condition ran but did not log anything
2022-01-13 00:34:26 OUTGOING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Response to HTTP request to test instance NNF1dOmOl5OGYx5
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "0j1Q4D7EKpHd9yWdstwliv3BvJnIHfiZi2whv69LaWdxYQPglY",
  "token_type": "Bearer"
}
outgoing_path
token
2022-01-13 00:34:28 INCOMING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Incoming HTTP request to test instance NNF1dOmOl5OGYx5
incoming_headers
{
  "host": "www.certification.openid.net",
  "x-dynatrace": "FW4;-987853115;1;-1606248171;699;1;-1738730375;437;b4c8;2h01;3ha0429915;4h02bb;6hde011dd8a2db3d1831474968c0782bd2;7h6f9d1f515f6fa405",
  "traceparent": "00-de011dd8a2db3d1831474968c0782bd2-6f9d1f515f6fa405-01",
  "tracestate": "985d1479-c51e8ec5@dt\u003dfw4;1;a0429915;2bb;1;0;0;1b5;0719;2h01;3ha0429915;4h02bb;7h6f9d1f515f6fa405",
  "authorization": "Bearer 0j1Q4D7EKpHd9yWdstwliv3BvJnIHfiZi2whv69LaWdxYQPglY",
  "request-id": "|9807a83f-4189dfe58fc996ae.2.",
  "content-type": "application/json; charset\u003dutf-8",
  "content-length": "1078",
  "connection": "close"
}
incoming_path
/test-mtls/a/SafraRPTest/consents/v1/consents
incoming_body_form_params
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES256-GCM-SHA384
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A== -----END CERTIFICATE-----
incoming_body_json
{
  "data": {
    "loggedUser": {
      "document": {
        "identification": "16881808852",
        "rel": "CPF"
      }
    },
    "permissions": [
      "CUSTOMERS_PERSONAL_IDENTIFICATIONS_READ",
      "CUSTOMERS_PERSONAL_ADITTIONALINFO_READ",
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "ACCOUNTS_OVERDRAFT_LIMITS_READ",
      "ACCOUNTS_TRANSACTIONS_READ",
      "CREDIT_CARDS_ACCOUNTS_READ",
      "CREDIT_CARDS_ACCOUNTS_LIMITS_READ",
      "CREDIT_CARDS_ACCOUNTS_TRANSACTIONS_READ",
      "CREDIT_CARDS_ACCOUNTS_BILLS_READ",
      "CREDIT_CARDS_ACCOUNTS_BILLS_TRANSACTIONS_READ",
      "RESOURCES_READ",
      "INVOICE_FINANCINGS_READ",
      "INVOICE_FINANCINGS_SCHEDULED_INSTALMENTS_READ",
      "INVOICE_FINANCINGS_PAYMENTS_READ",
      "INVOICE_FINANCINGS_WARRANTIES_READ",
      "FINANCINGS_READ",
      "FINANCINGS_SCHEDULED_INSTALMENTS_READ",
      "FINANCINGS_PAYMENTS_READ",
      "FINANCINGS_WARRANTIES_READ",
      "LOANS_READ",
      "LOANS_SCHEDULED_INSTALMENTS_READ",
      "LOANS_PAYMENTS_READ",
      "LOANS_WARRANTIES_READ",
      "UNARRANGED_ACCOUNTS_OVERDRAFT_READ",
      "UNARRANGED_ACCOUNTS_OVERDRAFT_SCHEDULED_INSTALMENTS_READ",
      "UNARRANGED_ACCOUNTS_OVERDRAFT_PAYMENTS_READ",
      "UNARRANGED_ACCOUNTS_OVERDRAFT_WARRANTIES_READ"
    ],
    "expirationDateTime": "2023-01-13T00:34:26Z"
  }
}
incoming_query_string_params
{}
incoming_body
{"data":{"loggedUser":{"document":{"identification":"16881808852","rel":"CPF"}},"permissions":["CUSTOMERS_PERSONAL_IDENTIFICATIONS_READ","CUSTOMERS_PERSONAL_ADITTIONALINFO_READ","ACCOUNTS_READ","ACCOUNTS_BALANCES_READ","ACCOUNTS_OVERDRAFT_LIMITS_READ","ACCOUNTS_TRANSACTIONS_READ","CREDIT_CARDS_ACCOUNTS_READ","CREDIT_CARDS_ACCOUNTS_LIMITS_READ","CREDIT_CARDS_ACCOUNTS_TRANSACTIONS_READ","CREDIT_CARDS_ACCOUNTS_BILLS_READ","CREDIT_CARDS_ACCOUNTS_BILLS_TRANSACTIONS_READ","RESOURCES_READ","INVOICE_FINANCINGS_READ","INVOICE_FINANCINGS_SCHEDULED_INSTALMENTS_READ","INVOICE_FINANCINGS_PAYMENTS_READ","INVOICE_FINANCINGS_WARRANTIES_READ","FINANCINGS_READ","FINANCINGS_SCHEDULED_INSTALMENTS_READ","FINANCINGS_PAYMENTS_READ","FINANCINGS_WARRANTIES_READ","LOANS_READ","LOANS_SCHEDULED_INSTALMENTS_READ","LOANS_PAYMENTS_READ","LOANS_WARRANTIES_READ","UNARRANGED_ACCOUNTS_OVERDRAFT_READ","UNARRANGED_ACCOUNTS_OVERDRAFT_SCHEDULED_INSTALMENTS_READ","UNARRANGED_ACCOUNTS_OVERDRAFT_PAYMENTS_READ","UNARRANGED_ACCOUNTS_OVERDRAFT_WARRANTIES_READ"],"expirationDateTime":"2023-01-13T00:34:26Z"}}
2022-01-13 00:34:28 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES256-GCM-SHA384
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
New consent endpoint
2022-01-13 00:34:28 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A\u003d\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3\nMDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx\nMzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm\ncmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp\ndmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ\nk/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi\nMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG\nVfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b\nnE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4\nC4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF\nSaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0\nPR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB\nAAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce\nRCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF\nBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w\nZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v\nY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu\nY3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P\nAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw\nggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl\ncnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl\ncyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg\ndXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg\nU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0\ndXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0\naWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG\nCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh\nc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn\nLPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO\nhUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+\nVibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1\nzHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO\nVZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af\n1zroWKsv2A\u003d\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003d44b261bc-4f6f-44ce-b3d7-3f98a2b225f4,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3538313630373839303030313238,CN\u003d*.safra.com.br,OU\u003d709138dd-6e9d-5f96-bfff-69a5b2cb3ec0,O\u003dBCO SAFRA S.A.,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "api-mtls-hml.safra.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2022-01-13 00:34:28 SUCCESS
CheckForClientCertificate
Found client certificate
2022-01-13 00:34:28 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3
MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx
MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm
cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp
dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ
k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG
VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b
nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4
C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF
SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0
PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB
AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce
RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF
BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w
ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v
Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu
Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P
AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw
ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl
cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl
cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg
dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg
U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0
dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0
aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG
CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh
c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn
LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO
hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+
Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1
zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO
VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af
1zroWKsv2A==
-----END CERTIFICATE-----
2022-01-13 00:34:28 SUCCESS
EnsureIncomingRequestMethodIsPost
Client correctly used http POST method
2022-01-13 00:34:28 SUCCESS
EnsureBearerAccessTokenNotInParams
Client correctly did not send access token in query parameters or form body
2022-01-13 00:34:28 SUCCESS
ExtractBearerAccessTokenFromHeader
Found access token on incoming request
access_token
0j1Q4D7EKpHd9yWdstwliv3BvJnIHfiZi2whv69LaWdxYQPglY
2022-01-13 00:34:28 SUCCESS
RequireBearerClientCredentialsAccessToken
Found access token in request
actual
0j1Q4D7EKpHd9yWdstwliv3BvJnIHfiZi2whv69LaWdxYQPglY
2022-01-13 00:34:28 INFO
ExtractFapiDateHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-auth-date
path
headers.x-fapi-auth-date
mapped
object
incoming_request
2022-01-13 00:34:28 INFO
ExtractFapiIpAddressHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-customer-ip-address
path
headers.x-fapi-customer-ip-address
mapped
object
incoming_request
2022-01-13 00:34:28 INFO
ExtractFapiInteractionIdHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-interaction-id
path
headers.x-fapi-interaction-id
mapped
object
incoming_request
2022-01-13 00:34:28 SUCCESS
FAPIBrazilEnsureClientCredentialsScopeContainedConsents
The token request which was used to obtain the access token contained 'consents' scope
actual
[
  "consents"
]
2022-01-13 00:34:28
FAPIBrazilExtractConsentRequest
Condition ran but did not log anything
2022-01-13 00:34:28 SUCCESS
CreateFapiInteractionIdIfNeeded
Created new FAPI interaction ID
fapi_interaction_id
c23424e3-d89d-4559-9b11-12bfbf810c63
2022-01-13 00:34:28 SUCCESS
FAPIBrazilGenerateNewConsentResponse
Created consent response
headers
{
  "x-fapi-interaction-id": "c23424e3-d89d-4559-9b11-12bfbf810c63"
}
consentId
urn:conformance.oidf:0ELQGXOprz
consent_response
{
  "data": {
    "consentId": "urn:conformance.oidf:0ELQGXOprz",
    "creationDateTime": "2022-01-13T00:34:28Z",
    "status": "AWAITING_AUTHORISATION",
    "statusUpdateDateTime": "2022-01-13T00:34:28Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2022-01-13T02:34:28Z",
    "transactionFromDateTime": "2022-01-13T00:29:28Z",
    "transactionToDateTime": "2022-01-13T02:34:28Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/SafraRPTestconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2022-01-13T00:34:28Z"
  }
}
2022-01-13 00:34:28
ClearAccessTokenFromRequest
Condition ran but did not log anything
2022-01-13 00:34:28 OUTGOING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Response to HTTP request to test instance NNF1dOmOl5OGYx5
outgoing_status_code
201
outgoing_headers
{
  "x-fapi-interaction-id": [
    "c23424e3-d89d-4559-9b11-12bfbf810c63"
  ]
}
outgoing_body
{
  "data": {
    "consentId": "urn:conformance.oidf:0ELQGXOprz",
    "creationDateTime": "2022-01-13T00:34:28Z",
    "status": "AWAITING_AUTHORISATION",
    "statusUpdateDateTime": "2022-01-13T00:34:28Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2022-01-13T02:34:28Z",
    "transactionFromDateTime": "2022-01-13T00:29:28Z",
    "transactionToDateTime": "2022-01-13T02:34:28Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/SafraRPTestconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2022-01-13T00:34:28Z"
  }
}
outgoing_path
consents/v1/consents
2022-01-13 00:34:31 INCOMING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Incoming HTTP request to test instance NNF1dOmOl5OGYx5
incoming_headers
{
  "host": "www.certification.openid.net",
  "sec-ch-ua": "\" Not;A Brand\";v\u003d\"99\", \"Google Chrome\";v\u003d\"97\", \"Chromium\";v\u003d\"97\"",
  "sec-ch-ua-mobile": "?0",
  "sec-ch-ua-platform": "\"Windows\"",
  "upgrade-insecure-requests": "1",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/97.0.4692.71 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "none",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "pt-BR,pt;q\u003d0.9,en-US;q\u003d0.8,en;q\u003d0.7",
  "cookie": "__utmc\u003d201319536; __utma\u003d201319536.1341971708.1631915075.1641907690.1641941726.54; __utmz\u003d201319536.1641941726.54.15.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; JSESSIONID\u003d736655D537D3CECB0C8167ACF304265D",
  "connection": "close"
}
incoming_path
/test/a/SafraRPTest/authorize
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{
  "request": "eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZHQ00iLCJraWQiOiIwZmU1MDJkZC0xNGYwLTRmNDUtODBmOS1mZWI5YTIxNmY5OTYifQ.O5yUxlu-OkoCQg-oCpumMGkMS0MvRTZwe5odb0T3EJPcYAfHmgCyiiP_yuJaBQH1Tyf1bi5fFFCZi2YWVMQlR3A577jvZGbMEHw9BtHsZhp5EgU8XlrFNdMF-Py_mUst_aVIBM28mDcJ1cTxXzIcAd_LYexpb-qIsDDadFU3H4VFygT5wo5RLJGb_8UrjqhO4Ga3WwkxHUIu3l_qxJmkG-VKbn3uYVl1kVb-ezKTwkBiQAwRf6lPh3RMJzcK9ukIlYrk1TJWa2ZUseKqinC-SwnqiuNrPBhqytqdXaE2V1HWgNz4Ow48oEoGk1djv8VXCaCD9yL5VUHvcSfR3SiN-w.2MXORc-R3H9JZpWi.nk7gLscTiguzD55GEsY43KqdpPBOYYbaXd9Txr-YfiFu-Cke2VNQ-vIgBkKEdenwW5oYzEddjiAvPuLgPguakkKXtVELvtfMwcjbqNtVrsyQPo8kSDyRgXQCuxBK8gqBrleNkV_4oUa5nNRMSk1ydAcnNcLWsmYnlnKib2tBm1Lgavsyiz-1JIJlYGXmJMcqIHm-29OnlwJRRCYRU2UeBzodS9mpLr3aZegX_6a-Q7hhaF8IQT5eT47W5VCU4_32Dkr07X5kAUOqj3VTne2CriEMPje6OVTIa9nNb5iYlMDdEH3TQelxDk_eLDrBpsEsFammq-1KwvuxKdjHunHzEIocHA2hzPMq1d9RINTSpZgaLKh8JWV1qBndB3EB7VQw6T97lnofIYFZCRE1jled4iAJPMUHClM0Q_tjzdUBbHsiMV61czKmo748IobsVTthZLRF3G2KjxvtUd0WWNYRsRS7ppIAHeNQf-id1WdFsJvXcZ7mJ7muM5XzA-BfCTR8YY3VQGxO1GepOWuMCOPnWPEt3GWeGbBCblJ-TmOw35D9RgZghB-NJsh6f2IAaup-TQLO8KC8G-QBNsqEADWQr2wM7iPvrqMmJCZQSCW4efetjBv363pWvCQotnzcP1_urdIDVG-_KaJOxmIrfkoebEHNHJcvuXbJS7AdOsC1PzXqJab7eYHVzzeKAJ7L8IuZNMLwfAn8RX8gi_W4kztj9Zz_KF5v9xvtkgRcY5ON5SvWT3376-kDHX0GsPcbfrZapTtAg9HM-O_PIeFEHOkVuVO9wbwL8K_rRMg8KCKmfEo3VwEYfP6kecJGy8l-mTD52pZH15V01_j2oRlxz3QcVJ6-as_PKY3t-3MoFcW1FsYf_0Ma9vyQpL7435qDysG2gDwfLy1uTbImeXP1pT5j3-PZUaz16sIoPx_Eis6ZmRa0s_lUOCa1D97nH7ZyX9jWf3CkGCrbboDIPtNZy92oNLD7JLyWeatvhVtJ1m1U4MdQI88RNSFDBqjN2kzGzaWJt9Yj1jxazqgsymg2R3994GTxNyZv_Ir6wNFWtk69fJ-9EquC5mV4sJ9BxRsjzwIjuftSkxODZc1r4pI774fK1L-R1nYaxl2Y4zHXazVvxfOYtmzXqUkmc65euYUZ504Jl9WA7tWhXllmE-HAUudfIbxh2z8z1CHMV0J1-LjPZkTOojMGW9OfAzMSC4nNpnMsPWllCjpay3cSN57QaS9k9BBvyMue9UCkqHuTlJd2AzSgFDUkz3JLOqVGNVFvs_9zr_UhR6_ioRugqURP4eIIcB1HJ3W3H0WUJ6BFw7kvKSMA_C71yrrAW1Hxbe0SijMIBz_q5AdlPCJi5CAchYN5D3C3Z7Ftp_ewsD0gFO5O2xJV5UozX0CvsPPKZP6nV7iFy6oIyQCjTe327QTaQT4lZ-lmKgyyHTFnlGAfGyatdSwvithWlpfSc0bPoP07PKR23Nrh6LlnJruZ-MSoEEWxw2hPPuQudqsTpEwJ9fI7KBMj0g2o3txU-d_ZXYOIEzwdOEqdsnyzVSe_wXSlPX3hBg.0070-Qe-Bnc-howy6fUdNA",
  "client_id": "client_XUwBuUHRMTVHAleZEJxH18815",
  "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
  "scope": "openid consents customers accounts credit-cards-accounts resources invoice-financings financings loans unarranged-accounts-overdraft consent:urn:conformance.oidf:0ELQGXOprz",
  "response_type": "code id_token"
}
incoming_body
2022-01-13 00:34:31 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Authorization endpoint
2022-01-13 00:34:31 SUCCESS
ExtractRequestObject
Parsed request object
request_object
{
  "value": "eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgifQ.eyJhdWQiOiJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1NhZnJhUlBUZXN0LyIsIm5iZiI6MTY0MjAzNDA2OCwic2NvcGUiOiJvcGVuaWQgY29uc2VudHMgY3VzdG9tZXJzIGFjY291bnRzIGNyZWRpdC1jYXJkcy1hY2NvdW50cyByZXNvdXJjZXMgaW52b2ljZS1maW5hbmNpbmdzIGZpbmFuY2luZ3MgbG9hbnMgdW5hcnJhbmdlZC1hY2NvdW50cy1vdmVyZHJhZnQgY29uc2VudDp1cm46Y29uZm9ybWFuY2Uub2lkZjowRUxRR1hPcHJ6IiwiaXNzIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUiLCJyZXNwb25zZV90eXBlIjoiY29kZSBpZF90b2tlbiIsInJlZGlyZWN0X3VyaSI6Imh0dHBzOi8vcG9ydGFsc3BhLWhtbC5zYWZyYS5jb20uYnIvY2FsbGJhY2siLCJzdGF0ZSI6IjVlMjc0ZjllZTkwYTQ5ODA4NzBjYmUyN2JmMDM3Yzg5IiwiZXhwIjoxNjQyMDM0MzY4LCJub25jZSI6IjA1MDBlMzIyMDJiNDQ2MjI5YzVjM2JiYTBmMjM2NTA3IiwiY2xpZW50X2lkIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUifQ.xGm_NOuUxLMiZYZHJnHIQfImapr05mDy_cauFtFB4dWNHt3XRQJwuEtkklKqG2wXHikjTu-HRWX39_HbLm5G1CfxcHG8m9oY9SJzYXG7gdbduV1FOj6n1Ru8XHq_ticW-szE3_jKxp4EZ6BKFm_aMxMPWZ3TBqB7AQcFte4oXwEVpUuANIX0F00LF-cPkf5VdlI3SszC-NS2GEKEBUpXtgco033QtleVpxg02xQA-JV5wlY7ppLXxJfWbVQHCa6pVa9F4gkbJjt44o5FtJM7IBJ4zA1fDfs8KB8N6iljTxP59PCxKPhp3HuSY-L8LFMTkl9qT-qv9Y4zVOgUiEGU4g",
  "header": {
    "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
    "alg": "PS256"
  },
  "claims": {
    "aud": "https://www.certification.openid.net/test/a/SafraRPTest/",
    "nbf": 1642034068,
    "scope": "openid consents customers accounts credit-cards-accounts resources invoice-financings financings loans unarranged-accounts-overdraft consent:urn:conformance.oidf:0ELQGXOprz",
    "iss": "client_XUwBuUHRMTVHAleZEJxH18815",
    "response_type": "code id_token",
    "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
    "state": "5e274f9ee90a4980870cbe27bf037c89",
    "exp": 1642034368,
    "nonce": "0500e32202b446229c5c3bba0f236507",
    "client_id": "client_XUwBuUHRMTVHAleZEJxH18815"
  },
  "jwe_header": {
    "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
    "enc": "A256GCM",
    "alg": "RSA-OAEP"
  }
}
2022-01-13 00:34:31 SUCCESS
EnsureRequestObjectWasEncrypted
Request object was encrypted
jwe_header
{
  "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
  "enc": "A256GCM",
  "alg": "RSA-OAEP"
}
2022-01-13 00:34:31 SUCCESS
FAPIBrazilEnsureRequestObjectEncryptedUsingRSAOAEPA256GCM
Request object was encrypted using RSA-OAEP and A256GCM
jwe_header
{
  "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
  "enc": "A256GCM",
  "alg": "RSA-OAEP"
}
2022-01-13 00:34:31 SUCCESS
ValidateEncryptedRequestObjectHasKid
kid was found in the encrypted request object header
kid
0fe502dd-14f0-4f45-80f9-feb9a216f996
2022-01-13 00:34:31 SUCCESS
CreateEffectiveAuthorizationRequestParameters
Merged http request parameters with request object claims
effective_authorization_endpoint_request
{
  "request": "eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZHQ00iLCJraWQiOiIwZmU1MDJkZC0xNGYwLTRmNDUtODBmOS1mZWI5YTIxNmY5OTYifQ.O5yUxlu-OkoCQg-oCpumMGkMS0MvRTZwe5odb0T3EJPcYAfHmgCyiiP_yuJaBQH1Tyf1bi5fFFCZi2YWVMQlR3A577jvZGbMEHw9BtHsZhp5EgU8XlrFNdMF-Py_mUst_aVIBM28mDcJ1cTxXzIcAd_LYexpb-qIsDDadFU3H4VFygT5wo5RLJGb_8UrjqhO4Ga3WwkxHUIu3l_qxJmkG-VKbn3uYVl1kVb-ezKTwkBiQAwRf6lPh3RMJzcK9ukIlYrk1TJWa2ZUseKqinC-SwnqiuNrPBhqytqdXaE2V1HWgNz4Ow48oEoGk1djv8VXCaCD9yL5VUHvcSfR3SiN-w.2MXORc-R3H9JZpWi.nk7gLscTiguzD55GEsY43KqdpPBOYYbaXd9Txr-YfiFu-Cke2VNQ-vIgBkKEdenwW5oYzEddjiAvPuLgPguakkKXtVELvtfMwcjbqNtVrsyQPo8kSDyRgXQCuxBK8gqBrleNkV_4oUa5nNRMSk1ydAcnNcLWsmYnlnKib2tBm1Lgavsyiz-1JIJlYGXmJMcqIHm-29OnlwJRRCYRU2UeBzodS9mpLr3aZegX_6a-Q7hhaF8IQT5eT47W5VCU4_32Dkr07X5kAUOqj3VTne2CriEMPje6OVTIa9nNb5iYlMDdEH3TQelxDk_eLDrBpsEsFammq-1KwvuxKdjHunHzEIocHA2hzPMq1d9RINTSpZgaLKh8JWV1qBndB3EB7VQw6T97lnofIYFZCRE1jled4iAJPMUHClM0Q_tjzdUBbHsiMV61czKmo748IobsVTthZLRF3G2KjxvtUd0WWNYRsRS7ppIAHeNQf-id1WdFsJvXcZ7mJ7muM5XzA-BfCTR8YY3VQGxO1GepOWuMCOPnWPEt3GWeGbBCblJ-TmOw35D9RgZghB-NJsh6f2IAaup-TQLO8KC8G-QBNsqEADWQr2wM7iPvrqMmJCZQSCW4efetjBv363pWvCQotnzcP1_urdIDVG-_KaJOxmIrfkoebEHNHJcvuXbJS7AdOsC1PzXqJab7eYHVzzeKAJ7L8IuZNMLwfAn8RX8gi_W4kztj9Zz_KF5v9xvtkgRcY5ON5SvWT3376-kDHX0GsPcbfrZapTtAg9HM-O_PIeFEHOkVuVO9wbwL8K_rRMg8KCKmfEo3VwEYfP6kecJGy8l-mTD52pZH15V01_j2oRlxz3QcVJ6-as_PKY3t-3MoFcW1FsYf_0Ma9vyQpL7435qDysG2gDwfLy1uTbImeXP1pT5j3-PZUaz16sIoPx_Eis6ZmRa0s_lUOCa1D97nH7ZyX9jWf3CkGCrbboDIPtNZy92oNLD7JLyWeatvhVtJ1m1U4MdQI88RNSFDBqjN2kzGzaWJt9Yj1jxazqgsymg2R3994GTxNyZv_Ir6wNFWtk69fJ-9EquC5mV4sJ9BxRsjzwIjuftSkxODZc1r4pI774fK1L-R1nYaxl2Y4zHXazVvxfOYtmzXqUkmc65euYUZ504Jl9WA7tWhXllmE-HAUudfIbxh2z8z1CHMV0J1-LjPZkTOojMGW9OfAzMSC4nNpnMsPWllCjpay3cSN57QaS9k9BBvyMue9UCkqHuTlJd2AzSgFDUkz3JLOqVGNVFvs_9zr_UhR6_ioRugqURP4eIIcB1HJ3W3H0WUJ6BFw7kvKSMA_C71yrrAW1Hxbe0SijMIBz_q5AdlPCJi5CAchYN5D3C3Z7Ftp_ewsD0gFO5O2xJV5UozX0CvsPPKZP6nV7iFy6oIyQCjTe327QTaQT4lZ-lmKgyyHTFnlGAfGyatdSwvithWlpfSc0bPoP07PKR23Nrh6LlnJruZ-MSoEEWxw2hPPuQudqsTpEwJ9fI7KBMj0g2o3txU-d_ZXYOIEzwdOEqdsnyzVSe_wXSlPX3hBg.0070-Qe-Bnc-howy6fUdNA",
  "client_id": "client_XUwBuUHRMTVHAleZEJxH18815",
  "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
  "scope": "openid consents customers accounts credit-cards-accounts resources invoice-financings financings loans unarranged-accounts-overdraft consent:urn:conformance.oidf:0ELQGXOprz",
  "response_type": "code id_token",
  "aud": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "nbf": 1642034068,
  "iss": "client_XUwBuUHRMTVHAleZEJxH18815",
  "state": "5e274f9ee90a4980870cbe27bf037c89",
  "exp": 1642034368,
  "nonce": "0500e32202b446229c5c3bba0f236507"
}
2022-01-13 00:34:31 SUCCESS
FAPIValidateRequestObjectSigningAlg
Request object was signed with a permitted algorithm
alg
PS256
2022-01-13 00:34:31
FAPIBrazilValidateRequestObjectIdTokenACRClaims
acr claim is not requested
2022-01-13 00:34:31 SUCCESS
FAPIValidateRequestObjectExp
Request object contains a valid exp claim, expiry time
exp
"Jan 13, 2022, 12:39:28 AM"
2022-01-13 00:34:31 SUCCESS
FAPI1AdvancedValidateRequestObjectNBFClaim
nbf claim is valid
nbf
"Jan 13, 2022, 12:34:28 AM"
now
"Jan 13, 2022, 12:34:31 AM"
2022-01-13 00:34:31 INFO
ValidateRequestObjectClaims
Missing issuance time
2022-01-13 00:34:31
ValidateRequestObjectClaims
Request object does not contain a max_age claim
2022-01-13 00:34:31 SUCCESS
ValidateRequestObjectClaims
Request object claims passed all validation checks
2022-01-13 00:34:31 SUCCESS
EnsureNumericRequestObjectClaimsAreNotNull
None of the claims expected to have numeric values, have null values
numeric_claims
[
  "max_age"
]
2022-01-13 00:34:31 SUCCESS
EnsureRequestObjectDoesNotContainRequestOrRequestUri
Request object does not contain request or request_uri
2022-01-13 00:34:31 SUCCESS
EnsureRequestObjectDoesNotContainSubWithClientId
Request object does not contain Client Id in sub
2022-01-13 00:34:31 SUCCESS
ValidateRequestObjectSignature
Request object signature validated using a key in the client's JWKS and using the client's registered request_object_signing_alg
request_object
eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgifQ.eyJhdWQiOiJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1NhZnJhUlBUZXN0LyIsIm5iZiI6MTY0MjAzNDA2OCwic2NvcGUiOiJvcGVuaWQgY29uc2VudHMgY3VzdG9tZXJzIGFjY291bnRzIGNyZWRpdC1jYXJkcy1hY2NvdW50cyByZXNvdXJjZXMgaW52b2ljZS1maW5hbmNpbmdzIGZpbmFuY2luZ3MgbG9hbnMgdW5hcnJhbmdlZC1hY2NvdW50cy1vdmVyZHJhZnQgY29uc2VudDp1cm46Y29uZm9ybWFuY2Uub2lkZjowRUxRR1hPcHJ6IiwiaXNzIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUiLCJyZXNwb25zZV90eXBlIjoiY29kZSBpZF90b2tlbiIsInJlZGlyZWN0X3VyaSI6Imh0dHBzOi8vcG9ydGFsc3BhLWhtbC5zYWZyYS5jb20uYnIvY2FsbGJhY2siLCJzdGF0ZSI6IjVlMjc0ZjllZTkwYTQ5ODA4NzBjYmUyN2JmMDM3Yzg5IiwiZXhwIjoxNjQyMDM0MzY4LCJub25jZSI6IjA1MDBlMzIyMDJiNDQ2MjI5YzVjM2JiYTBmMjM2NTA3IiwiY2xpZW50X2lkIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUifQ.xGm_NOuUxLMiZYZHJnHIQfImapr05mDy_cauFtFB4dWNHt3XRQJwuEtkklKqG2wXHikjTu-HRWX39_HbLm5G1CfxcHG8m9oY9SJzYXG7gdbduV1FOj6n1Ru8XHq_ticW-szE3_jKxp4EZ6BKFm_aMxMPWZ3TBqB7AQcFte4oXwEVpUuANIX0F00LF-cPkf5VdlI3SszC-NS2GEKEBUpXtgco033QtleVpxg02xQA-JV5wlY7ppLXxJfWbVQHCa6pVa9F4gkbJjt44o5FtJM7IBJ4zA1fDfs8KB8N6iljTxP59PCxKPhp3HuSY-L8LFMTkl9qT-qv9Y4zVOgUiEGU4g
request_object_signing_alg
PS256
jwk
Sun RSA public key, 2048 bits
  params: null
  modulus: 27317005133317805192806760528852339923492353512235657242373770667550482636383058152241763242899243590510886742369909995744634317769376156025319367773285730731881660146466929919531999356316138694239765585923733085598540913159621964662231658995625650459587810069348726397568662051897147600110311023758046324349410668829004864378877917443777578185960111723181521868093201680907747046475384551022492435381540942020065252906547519942072030894200912668741513959140858170657378829949009347461870925320758566164123500357237516086049488677768389753461936607006172049603857829706031784001244671456119721973322682338748251959301
  public exponent: 65537
2022-01-13 00:34:31 SUCCESS
EnsureMatchingRedirectUriInRequestObject
Redirect URI matched
actual
https://portalspa-hml.safra.com.br/callback
2022-01-13 00:34:31 SUCCESS
EnsureRequiredAuthorizationRequestParametersMatchRequestObject
Required http request parameters match request object claims
response_type
code id_token
client_id
client_XUwBuUHRMTVHAleZEJxH18815
2022-01-13 00:34:31 SUCCESS
EnsureOptionalAuthorizationRequestParametersMatchRequestObject
All http request parameters and request object claims match
2022-01-13 00:34:31 SUCCESS
EnsureAuthorizationHttpRequestContainsOpenIDScope
Found 'openid' in scope http request parameter
actual
[
  "openid",
  "consents",
  "customers",
  "accounts",
  "credit-cards-accounts",
  "resources",
  "invoice-financings",
  "financings",
  "loans",
  "unarranged-accounts-overdraft",
  "consent:urn:conformance.oidf:0ELQGXOprz"
]
expected
openid
2022-01-13 00:34:31 SUCCESS
ExtractRequestedScopes
Requested scopes
scope
openid consents customers accounts credit-cards-accounts resources invoice-financings financings loans unarranged-accounts-overdraft consent:urn:conformance.oidf:0ELQGXOprz
2022-01-13 00:34:31 SUCCESS
FAPIBrazilValidateConsentScope
Found consent scope in request
actual
[
  "openid",
  "consents",
  "customers",
  "accounts",
  "credit-cards-accounts",
  "resources",
  "invoice-financings",
  "financings",
  "loans",
  "unarranged-accounts-overdraft",
  "consent:urn:conformance.oidf:0ELQGXOprz"
]
expected
consent:urn:conformance.oidf:0ELQGXOprz
2022-01-13 00:34:31 SUCCESS
EnsureScopeContainsAccounts
Found accounts scope in request
actual
[
  "openid",
  "consents",
  "customers",
  "accounts",
  "credit-cards-accounts",
  "resources",
  "invoice-financings",
  "financings",
  "loans",
  "unarranged-accounts-overdraft",
  "consent:urn:conformance.oidf:0ELQGXOprz"
]
2022-01-13 00:34:31 SUCCESS
EnsureResponseTypeIsCodeIdToken
Response type is expected value
expected
code id_token
2022-01-13 00:34:31 SUCCESS
EnsureOpenIDInScopeRequest
Found 'openid' scope in request
actual
[
  "openid",
  "consents",
  "customers",
  "accounts",
  "credit-cards-accounts",
  "resources",
  "invoice-financings",
  "financings",
  "loans",
  "unarranged-accounts-overdraft",
  "consent:urn:conformance.oidf:0ELQGXOprz"
]
expected
openid
2022-01-13 00:34:31 SUCCESS
EnsureMatchingClientId
Client ID matched
client_id
client_XUwBuUHRMTVHAleZEJxH18815
2022-01-13 00:34:31 SUCCESS
CreateAuthorizationCode
Created authorization code
authorization_code
Kb08MqrnBLe8AujId6iLJJcZSm4pL21e
2022-01-13 00:34:31 SUCCESS
ExtractNonceFromAuthorizationRequest
Extracted nonce
nonce
0500e32202b446229c5c3bba0f236507
2022-01-13 00:34:31 SUCCESS
CalculateCHash
Successful c_hash encoding
c_hash
UthMEewrj-6J0MWRGbQjWQ
2022-01-13 00:34:31 SUCCESS
CalculateSHash
Successful s_hash encoding
s_hash
G0m6TNAdoMM3SiJEasLrGw
2022-01-13 00:34:31 SUCCESS
GenerateIdTokenClaims
Created ID Token Claims
iss
https://www.certification.openid.net/test/a/SafraRPTest/
sub
user-subject-1234531
aud
client_XUwBuUHRMTVHAleZEJxH18815
nonce
0500e32202b446229c5c3bba0f236507
iat
1642034071
exp
1642034371
2022-01-13 00:34:31
FAPIBrazilAddCPFAndCPNJToIdTokenClaims
Request object does not contain a claims element.id_token
2022-01-13 00:34:31 SUCCESS
AddCHashToIdTokenClaims
Added c_hash to ID token claims
c_hash
UthMEewrj-6J0MWRGbQjWQ
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "sub": "user-subject-1234531",
  "aud": "client_XUwBuUHRMTVHAleZEJxH18815",
  "nonce": "0500e32202b446229c5c3bba0f236507",
  "iat": 1642034071,
  "exp": 1642034371,
  "c_hash": "UthMEewrj-6J0MWRGbQjWQ"
}
2022-01-13 00:34:31 SUCCESS
AddSHashToIdTokenClaims
Added s_hash to ID token claims
s_hash
G0m6TNAdoMM3SiJEasLrGw
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "sub": "user-subject-1234531",
  "aud": "client_XUwBuUHRMTVHAleZEJxH18815",
  "nonce": "0500e32202b446229c5c3bba0f236507",
  "iat": 1642034071,
  "exp": 1642034371,
  "c_hash": "UthMEewrj-6J0MWRGbQjWQ",
  "s_hash": "G0m6TNAdoMM3SiJEasLrGw"
}
2022-01-13 00:34:31 INFO
AddAtHashToIdTokenClaims
Skipped evaluation due to missing required string: at_hash
expected
at_hash
2022-01-13 00:34:31 INFO
FAPIBrazilAddACRClaimToIdTokenClaims
Skipped evaluation due to missing required string: requested_id_token_acr_values
expected
requested_id_token_acr_values
2022-01-13 00:34:31 SUCCESS
SignIdToken
Signed the ID token
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6ImNsaWVudF9YVXdCdVVIUk1UVkhBbGVaRUp4SDE4ODE1IiwiY19oYXNoIjoiVXRoTUVld3JqLTZKME1XUkdiUWpXUSIsInNfaGFzaCI6IkcwbTZUTkFkb01NM1NpSkVhc0xyR3ciLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvU2FmcmFSUFRlc3RcLyIsImV4cCI6MTY0MjAzNDM3MSwibm9uY2UiOiIwNTAwZTMyMjAyYjQ0NjIyOWM1YzNiYmEwZjIzNjUwNyIsImlhdCI6MTY0MjAzNDA3MX0.KNVpHfVE6KyB-1BdrHzgAttPJGc2mWbPTehfVE_qdn92cH3J9sadXa_ZvW_S25DVtW4-0Tv7aTxzt6rveGSyvot4Eoh_b35o2xG98x74wBEpLv7jbpPZD8r8_chc7320rgxSyVDX4Luv4gkRsSErlcTJ-59agqy2GSH2mHfkiNP8YytpxoNZXKZi73bvm059Hw5fF4c_mp8P2gFOcQQqE9D2KmMVzH8uMXYSOVLw6tdCsRXo-GXhrBb3Z147nWVOqe-0Fp-Kz49m6lpPetorTmkAz7KBTOQFnrkE13Z3xKRProX-VttKONuKHOxrL04SlPfzsG8bQb4O8RQleNeMbQ
2022-01-13 00:34:31 SUCCESS
FAPIBrazilChangeConsentStatusToAuthorized
Changed consent status to AUTHORISED
consent
{
  "data": {
    "consentId": "urn:conformance.oidf:0ELQGXOprz",
    "creationDateTime": "2022-01-13T00:34:28Z",
    "status": "AUTHORISED",
    "statusUpdateDateTime": "2022-01-13T00:34:31Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2022-01-13T02:34:28Z",
    "transactionFromDateTime": "2022-01-13T00:29:28Z",
    "transactionToDateTime": "2022-01-13T02:34:28Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/SafraRPTestconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2022-01-13T00:34:28Z"
  }
}
2022-01-13 00:34:31 SUCCESS
CreateAuthorizationEndpointResponseParams
Added authorization_endpoint_response_params to environment
params
{
  "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
  "state": "5e274f9ee90a4980870cbe27bf037c89"
}
2022-01-13 00:34:31 SUCCESS
AddCodeToAuthorizationEndpointResponseParams
Added code to authorization endpoint response params
authorization_endpoint_response_params
{
  "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
  "state": "5e274f9ee90a4980870cbe27bf037c89",
  "code": "Kb08MqrnBLe8AujId6iLJJcZSm4pL21e"
}
2022-01-13 00:34:31 SUCCESS
AddIdTokenToAuthorizationEndpointResponseParams
Added id_token to authorization endpoint response params
authorization_endpoint_response_params
{
  "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
  "state": "5e274f9ee90a4980870cbe27bf037c89",
  "code": "Kb08MqrnBLe8AujId6iLJJcZSm4pL21e",
  "id_token": "eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6ImNsaWVudF9YVXdCdVVIUk1UVkhBbGVaRUp4SDE4ODE1IiwiY19oYXNoIjoiVXRoTUVld3JqLTZKME1XUkdiUWpXUSIsInNfaGFzaCI6IkcwbTZUTkFkb01NM1NpSkVhc0xyR3ciLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvU2FmcmFSUFRlc3RcLyIsImV4cCI6MTY0MjAzNDM3MSwibm9uY2UiOiIwNTAwZTMyMjAyYjQ0NjIyOWM1YzNiYmEwZjIzNjUwNyIsImlhdCI6MTY0MjAzNDA3MX0.KNVpHfVE6KyB-1BdrHzgAttPJGc2mWbPTehfVE_qdn92cH3J9sadXa_ZvW_S25DVtW4-0Tv7aTxzt6rveGSyvot4Eoh_b35o2xG98x74wBEpLv7jbpPZD8r8_chc7320rgxSyVDX4Luv4gkRsSErlcTJ-59agqy2GSH2mHfkiNP8YytpxoNZXKZi73bvm059Hw5fF4c_mp8P2gFOcQQqE9D2KmMVzH8uMXYSOVLw6tdCsRXo-GXhrBb3Z147nWVOqe-0Fp-Kz49m6lpPetorTmkAz7KBTOQFnrkE13Z3xKRProX-VttKONuKHOxrL04SlPfzsG8bQb4O8RQleNeMbQ"
}
2022-01-13 00:34:31
SendAuthorizationResponseWithResponseModeFragment
Redirecting back to client
uri
https://portalspa-hml.safra.com.br/callback#state=5e274f9ee90a4980870cbe27bf037c89&code=Kb08MqrnBLe8AujId6iLJJcZSm4pL21e&id_token=eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6ImNsaWVudF9YVXdCdVVIUk1UVkhBbGVaRUp4SDE4ODE1IiwiY19oYXNoIjoiVXRoTUVld3JqLTZKME1XUkdiUWpXUSIsInNfaGFzaCI6IkcwbTZUTkFkb01NM1NpSkVhc0xyR3ciLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvU2FmcmFSUFRlc3RcLyIsImV4cCI6MTY0MjAzNDM3MSwibm9uY2UiOiIwNTAwZTMyMjAyYjQ0NjIyOWM1YzNiYmEwZjIzNjUwNyIsImlhdCI6MTY0MjAzNDA3MX0.KNVpHfVE6KyB-1BdrHzgAttPJGc2mWbPTehfVE_qdn92cH3J9sadXa_ZvW_S25DVtW4-0Tv7aTxzt6rveGSyvot4Eoh_b35o2xG98x74wBEpLv7jbpPZD8r8_chc7320rgxSyVDX4Luv4gkRsSErlcTJ-59agqy2GSH2mHfkiNP8YytpxoNZXKZi73bvm059Hw5fF4c_mp8P2gFOcQQqE9D2KmMVzH8uMXYSOVLw6tdCsRXo-GXhrBb3Z147nWVOqe-0Fp-Kz49m6lpPetorTmkAz7KBTOQFnrkE13Z3xKRProX-VttKONuKHOxrL04SlPfzsG8bQb4O8RQleNeMbQ
2022-01-13 00:34:31 OUTGOING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Response to HTTP request to test instance NNF1dOmOl5OGYx5
outgoing
org.springframework.web.servlet.view.RedirectView: [RedirectView]; URL [https://portalspa-hml.safra.com.br/callback#state=5e274f9ee90a4980870cbe27bf037c89&code=Kb08MqrnBLe8AujId6iLJJcZSm4pL21e&id_token=eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6ImNsaWVudF9YVXdCdVVIUk1UVkhBbGVaRUp4SDE4ODE1IiwiY19oYXNoIjoiVXRoTUVld3JqLTZKME1XUkdiUWpXUSIsInNfaGFzaCI6IkcwbTZUTkFkb01NM1NpSkVhc0xyR3ciLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvU2FmcmFSUFRlc3RcLyIsImV4cCI6MTY0MjAzNDM3MSwibm9uY2UiOiIwNTAwZTMyMjAyYjQ0NjIyOWM1YzNiYmEwZjIzNjUwNyIsImlhdCI6MTY0MjAzNDA3MX0.KNVpHfVE6KyB-1BdrHzgAttPJGc2mWbPTehfVE_qdn92cH3J9sadXa_ZvW_S25DVtW4-0Tv7aTxzt6rveGSyvot4Eoh_b35o2xG98x74wBEpLv7jbpPZD8r8_chc7320rgxSyVDX4Luv4gkRsSErlcTJ-59agqy2GSH2mHfkiNP8YytpxoNZXKZi73bvm059Hw5fF4c_mp8P2gFOcQQqE9D2KmMVzH8uMXYSOVLw6tdCsRXo-GXhrBb3Z147nWVOqe-0Fp-Kz49m6lpPetorTmkAz7KBTOQFnrkE13Z3xKRProX-VttKONuKHOxrL04SlPfzsG8bQb4O8RQleNeMbQ]
outgoing_path
authorize
2022-01-13 00:34:33 INCOMING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Incoming HTTP request to test instance NNF1dOmOl5OGYx5
incoming_headers
{
  "host": "www.certification.openid.net",
  "x-dynatrace": "FW4;-987853115;1;-1606248171;700;0;-1738730375;826;fce8;2h01;3ha0429915;4h02bc;6h63a807cde1e23b353a26babb061414b4;7h9210d7e67d7210ce",
  "traceparent": "00-63a807cde1e23b353a26babb061414b4-9210d7e67d7210ce-01",
  "tracestate": "985d1479-c51e8ec5@dt\u003dfw4;1;a0429915;2bc;0;0;0;33a;04cb;2h01;3ha0429915;4h02bc;7h9210d7e67d7210ce",
  "content-type": "application/x-www-form-urlencoded",
  "x-cert": "MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPDo28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkxMzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2FmcmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iGVfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8bnE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyFSaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMBAAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkceRCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIuY3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0PAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wnLPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLOhUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqOVZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af1zroWKsv2A\u003d\u003d",
  "content-length": "1112",
  "connection": "close"
}
incoming_path
/test-mtls/a/SafraRPTest/token
incoming_body_form_params
{
  "grant_type": "authorization_code",
  "code": "Kb08MqrnBLe8AujId6iLJJcZSm4pL21e",
  "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
  "client_id": "client_XUwBuUHRMTVHAleZEJxH18815",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjYxZWJmYmFkZjcxNzRiYzI4NTBlMjBhYmMyZDM0YzA3IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDM0MzcyLCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzNDA3MiwibmJmIjoxNjQyMDM0MDcyfQ.ofbc0vSMS7FBGbP_-4R09jkDsmBDe9pH1Qpk0gShOoLk8FI4EBngbBvmeOyAo9L3GCVYuDdX1G5CzaRz0VGl0SfIVJmExPYF5HwvhW1Z_MsD6bw65YinLpDK_Fw7U_dlexW0YSvjKp444q6EjTaID2NhmNhNS3TTZ7nc7w3PpN4HkmTVhIKG2D2gyVeKqsQAO9oAdatgnx7udKdPETBMUxMlQzHMfocSo5Xc26FyycEW3lkz07bGHIneSQyPGtdvqgWuP87Ger-RLzLiwvUaUGG4inKuLovMrvoEd81opxejhpbz8Dhxc8f6Rx_iUQj7Vl8BbHjTYPzSYNkM0iPdaw",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES256-GCM-SHA384
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A== -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
grant_type=authorization_code&code=Kb08MqrnBLe8AujId6iLJJcZSm4pL21e&redirect_uri=https%3A%2F%2Fportalspa-hml.safra.com.br%2Fcallback&client_id=client_XUwBuUHRMTVHAleZEJxH18815&client_assertion=eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjYxZWJmYmFkZjcxNzRiYzI4NTBlMjBhYmMyZDM0YzA3IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDM0MzcyLCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzNDA3MiwibmJmIjoxNjQyMDM0MDcyfQ.ofbc0vSMS7FBGbP_-4R09jkDsmBDe9pH1Qpk0gShOoLk8FI4EBngbBvmeOyAo9L3GCVYuDdX1G5CzaRz0VGl0SfIVJmExPYF5HwvhW1Z_MsD6bw65YinLpDK_Fw7U_dlexW0YSvjKp444q6EjTaID2NhmNhNS3TTZ7nc7w3PpN4HkmTVhIKG2D2gyVeKqsQAO9oAdatgnx7udKdPETBMUxMlQzHMfocSo5Xc26FyycEW3lkz07bGHIneSQyPGtdvqgWuP87Ger-RLzLiwvUaUGG4inKuLovMrvoEd81opxejhpbz8Dhxc8f6Rx_iUQj7Vl8BbHjTYPzSYNkM0iPdaw&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2022-01-13 00:34:33 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES256-GCM-SHA384
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2022-01-13 00:34:33 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A\u003d\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3\nMDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx\nMzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm\ncmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp\ndmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ\nk/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi\nMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG\nVfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b\nnE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4\nC4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF\nSaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0\nPR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB\nAAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce\nRCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF\nBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w\nZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v\nY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu\nY3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P\nAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw\nggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl\ncnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl\ncyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg\ndXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg\nU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0\ndXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0\naWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG\nCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh\nc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn\nLPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO\nhUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+\nVibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1\nzHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO\nVZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af\n1zroWKsv2A\u003d\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003d44b261bc-4f6f-44ce-b3d7-3f98a2b225f4,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3538313630373839303030313238,CN\u003d*.safra.com.br,OU\u003d709138dd-6e9d-5f96-bfff-69a5b2cb3ec0,O\u003dBCO SAFRA S.A.,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "api-mtls-hml.safra.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2022-01-13 00:34:33 SUCCESS
CheckForClientCertificate
Found client certificate
2022-01-13 00:34:33 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3
MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx
MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm
cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp
dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ
k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG
VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b
nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4
C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF
SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0
PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB
AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce
RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF
BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w
ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v
Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu
Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P
AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw
ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl
cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl
cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg
dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg
U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0
dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0
aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG
CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh
c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn
LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO
hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+
Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1
zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO
VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af
1zroWKsv2A==
-----END CERTIFICATE-----
2022-01-13 00:34:33 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjYxZWJmYmFkZjcxNzRiYzI4NTBlMjBhYmMyZDM0YzA3IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDM0MzcyLCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzNDA3MiwibmJmIjoxNjQyMDM0MDcyfQ.ofbc0vSMS7FBGbP_-4R09jkDsmBDe9pH1Qpk0gShOoLk8FI4EBngbBvmeOyAo9L3GCVYuDdX1G5CzaRz0VGl0SfIVJmExPYF5HwvhW1Z_MsD6bw65YinLpDK_Fw7U_dlexW0YSvjKp444q6EjTaID2NhmNhNS3TTZ7nc7w3PpN4HkmTVhIKG2D2gyVeKqsQAO9oAdatgnx7udKdPETBMUxMlQzHMfocSo5Xc26FyycEW3lkz07bGHIneSQyPGtdvqgWuP87Ger-RLzLiwvUaUGG4inKuLovMrvoEd81opxejhpbz8Dhxc8f6Rx_iUQj7Vl8BbHjTYPzSYNkM0iPdaw",
  "header": {
    "x5t": "imeJtvhk1_UOZIIOKtvS3EW0nDo",
    "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "client_XUwBuUHRMTVHAleZEJxH18815",
    "aud": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "nbf": 1642034072,
    "iss": "client_XUwBuUHRMTVHAleZEJxH18815",
    "exp": 1642034372,
    "iat": 1642034072,
    "jti": "61ebfbadf7174bc2850e20abc2d34c07"
  }
}
2022-01-13 00:34:33
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2022-01-13 00:34:33 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjYxZWJmYmFkZjcxNzRiYzI4NTBlMjBhYmMyZDM0YzA3IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDM0MzcyLCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjAzNDA3MiwibmJmIjoxNjQyMDM0MDcyfQ.ofbc0vSMS7FBGbP_-4R09jkDsmBDe9pH1Qpk0gShOoLk8FI4EBngbBvmeOyAo9L3GCVYuDdX1G5CzaRz0VGl0SfIVJmExPYF5HwvhW1Z_MsD6bw65YinLpDK_Fw7U_dlexW0YSvjKp444q6EjTaID2NhmNhNS3TTZ7nc7w3PpN4HkmTVhIKG2D2gyVeKqsQAO9oAdatgnx7udKdPETBMUxMlQzHMfocSo5Xc26FyycEW3lkz07bGHIneSQyPGtdvqgWuP87Ger-RLzLiwvUaUGG4inKuLovMrvoEd81opxejhpbz8Dhxc8f6Rx_iUQj7Vl8BbHjTYPzSYNkM0iPdaw
2022-01-13 00:34:33 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2022-01-13 00:34:33 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2022-01-13 00:34:33 SUCCESS
ValidateAuthorizationCode
Found authorization code
authorization_code
Kb08MqrnBLe8AujId6iLJJcZSm4pL21e
2022-01-13 00:34:33 SUCCESS
ValidateRedirectUri
Found redirect uri
redirect_uri
https://portalspa-hml.safra.com.br/callback
2022-01-13 00:34:33 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
jwULkUgrtKNFVXvWMr7XXETOGTKKGRqYqsOHvaSh89C21wIAZY
2022-01-13 00:34:33 SUCCESS
CalculateAtHash
Successful at_hash encoding
at_hash
U2iXU56yPahdk0brOXdPxQ
2022-01-13 00:34:33
CreateRefreshToken
Created refresh token
refresh_token
jQTLzkydQZdchmGbHVdpIOttRUcRaQupTdvRyEsKHUrSJkmksv6583693618/,#^ 
2022-01-13 00:34:33 SUCCESS
GenerateIdTokenClaims
Created ID Token Claims
iss
https://www.certification.openid.net/test/a/SafraRPTest/
sub
user-subject-1234531
aud
client_XUwBuUHRMTVHAleZEJxH18815
nonce
0500e32202b446229c5c3bba0f236507
iat
1642034073
exp
1642034373
2022-01-13 00:34:33
FAPIBrazilAddCPFAndCPNJToIdTokenClaims
Request object does not contain a claims element.id_token
2022-01-13 00:34:33 SUCCESS
AddAtHashToIdTokenClaims
Added at_hash to ID token claims
at_hash
U2iXU56yPahdk0brOXdPxQ
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "sub": "user-subject-1234531",
  "aud": "client_XUwBuUHRMTVHAleZEJxH18815",
  "nonce": "0500e32202b446229c5c3bba0f236507",
  "iat": 1642034073,
  "exp": 1642034373,
  "at_hash": "U2iXU56yPahdk0brOXdPxQ"
}
2022-01-13 00:34:33 INFO
FAPIBrazilAddACRClaimToIdTokenClaims
Skipped evaluation due to missing required string: requested_id_token_acr_values
expected
requested_id_token_acr_values
2022-01-13 00:34:33 SUCCESS
SignIdToken
Signed the ID token
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdF9oYXNoIjoiVTJpWFU1NnlQYWhkazBick9YZFB4USIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUiLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvU2FmcmFSUFRlc3RcLyIsImV4cCI6MTY0MjAzNDM3Mywibm9uY2UiOiIwNTAwZTMyMjAyYjQ0NjIyOWM1YzNiYmEwZjIzNjUwNyIsImlhdCI6MTY0MjAzNDA3M30.qam3qZhhVtUcLZ2w0_x932_nVnCUS0fbchprQ-arvfv7NdLl-xZahBV8vaTco8Oi7BoAHwQCOaR8HfQ7NUH8UhhosNgRhbQtGjIqo_KbFPmti6UykLctcDNatOjfXwv5OmtlMzwn8YxxXJtafY5L02mBJad-2LO_AhmPdMNVefQNFMCjIJdOGbXzUwcDnDdNUQCIkVh1zfKGa_5AT6FNy3NZ16LVepZKAwUIPGrD9VrxMnQmNPtXuUwg9ynvmMUO_g90mM_O8xlbHdMypfq1SNsEn60htYm0ITcePPcG2tJP_Ap_FBpPCB2sWJM83bC2trsyeSLr14hc-RSpprrrzQ
2022-01-13 00:34:33 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
jwULkUgrtKNFVXvWMr7XXETOGTKKGRqYqsOHvaSh89C21wIAZY
token_type
Bearer
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdF9oYXNoIjoiVTJpWFU1NnlQYWhkazBick9YZFB4USIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUiLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvU2FmcmFSUFRlc3RcLyIsImV4cCI6MTY0MjAzNDM3Mywibm9uY2UiOiIwNTAwZTMyMjAyYjQ0NjIyOWM1YzNiYmEwZjIzNjUwNyIsImlhdCI6MTY0MjAzNDA3M30.qam3qZhhVtUcLZ2w0_x932_nVnCUS0fbchprQ-arvfv7NdLl-xZahBV8vaTco8Oi7BoAHwQCOaR8HfQ7NUH8UhhosNgRhbQtGjIqo_KbFPmti6UykLctcDNatOjfXwv5OmtlMzwn8YxxXJtafY5L02mBJad-2LO_AhmPdMNVefQNFMCjIJdOGbXzUwcDnDdNUQCIkVh1zfKGa_5AT6FNy3NZ16LVepZKAwUIPGrD9VrxMnQmNPtXuUwg9ynvmMUO_g90mM_O8xlbHdMypfq1SNsEn60htYm0ITcePPcG2tJP_Ap_FBpPCB2sWJM83bC2trsyeSLr14hc-RSpprrrzQ
refresh_token
jQTLzkydQZdchmGbHVdpIOttRUcRaQupTdvRyEsKHUrSJkmksv6583693618/,#^ 
scope
openid consents customers accounts credit-cards-accounts resources invoice-financings financings loans unarranged-accounts-overdraft consent:urn:conformance.oidf:0ELQGXOprz 75e64237-ab29-40e9-8ded-95ec866d306d
2022-01-13 00:34:33 OUTGOING
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Response to HTTP request to test instance NNF1dOmOl5OGYx5
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "jwULkUgrtKNFVXvWMr7XXETOGTKKGRqYqsOHvaSh89C21wIAZY",
  "token_type": "Bearer",
  "id_token": "eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdF9oYXNoIjoiVTJpWFU1NnlQYWhkazBick9YZFB4USIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUiLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvU2FmcmFSUFRlc3RcLyIsImV4cCI6MTY0MjAzNDM3Mywibm9uY2UiOiIwNTAwZTMyMjAyYjQ0NjIyOWM1YzNiYmEwZjIzNjUwNyIsImlhdCI6MTY0MjAzNDA3M30.qam3qZhhVtUcLZ2w0_x932_nVnCUS0fbchprQ-arvfv7NdLl-xZahBV8vaTco8Oi7BoAHwQCOaR8HfQ7NUH8UhhosNgRhbQtGjIqo_KbFPmti6UykLctcDNatOjfXwv5OmtlMzwn8YxxXJtafY5L02mBJad-2LO_AhmPdMNVefQNFMCjIJdOGbXzUwcDnDdNUQCIkVh1zfKGa_5AT6FNy3NZ16LVepZKAwUIPGrD9VrxMnQmNPtXuUwg9ynvmMUO_g90mM_O8xlbHdMypfq1SNsEn60htYm0ITcePPcG2tJP_Ap_FBpPCB2sWJM83bC2trsyeSLr14hc-RSpprrrzQ",
  "refresh_token": "jQTLzkydQZdchmGbHVdpIOttRUcRaQupTdvRyEsKHUrSJkmksv6583693618/,#^ ",
  "scope": "openid consents customers accounts credit-cards-accounts resources invoice-financings financings loans unarranged-accounts-overdraft consent:urn:conformance.oidf:0ELQGXOprz 75e64237-ab29-40e9-8ded-95ec866d306d"
}
outgoing_path
token
2022-01-13 00:34:38 FINISHED
fapi1-advanced-final-client-test-invalid-scope-in-token-endpoint-response
Test has run to completion
testmodule_result
PASSED
2022-01-13 00:37:06
TEST-RUNNER
Alias has now been claimed by another test
alias
SafraRPTest
new_test_id
JO5wslH9BWsbPGo
Test Results