Test Summary

Test Results

Expand All Collapse All
All times are UTC
2022-01-13 13:21:11 INFO
TEST-RUNNER
Test instance 8Zu5JxPG9CfXNiv created
baseUrl
https://www.certification.openid.net/test/a/SafraRPTest
variant
{
  "client_auth_type": "private_key_jwt",
  "fapi_auth_request_method": "pushed",
  "fapi_jarm_type": "oidc",
  "fapi_profile": "openbanking_brazil",
  "fapi_response_mode": "plain_response"
}
alias
SafraRPTest
description
Safra Relying Party Test
planId
aHKQkRwE1nAwr
config
{
  "alias": "SafraRPTest",
  "description": "Safra Relying Party Test",
  "server": {
    "jwks": {
      "keys": [
        {
          "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
          "kty": "RSA",
          "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
          "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
          "e": "AQAB",
          "alg": "PS256",
          "use": "sig",
          "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
          "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
          "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
          "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
          "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
          "x5c": [
            "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
          ]
        },
        {
          "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
          "kty": "RSA",
          "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
          "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
          "e": "AQAB",
          "use": "enc",
          "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
          "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
          "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
          "alg": "RSA-OAEP",
          "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
          "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
        }
      ]
    }
  },
  "client": {
    "client_id": "client_XUwBuUHRMTVHAleZEJxH18815",
    "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
    "certificate": "-----BEGIN CERTIFICATE-----\nMIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3\nMDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx\nMzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm\ncmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp\ndmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ\nk/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi\nMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG\nVfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b\nnE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4\nC4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF\nSaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0\nPR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB\nAAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce\nRCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF\nBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w\nZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v\nY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu\nY3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P\nAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw\nggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl\ncnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl\ncyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg\ndXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg\nU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0\ndXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0\naWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG\nCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh\nc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn\nLPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO\nhUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+\nVibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1\nzHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO\nVZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af\n1zroWKsv2A\u003d\u003d\n-----END CERTIFICATE-----",
    "jwks": {
      "keys": [
        {
          "kty": "RSA",
          "e": "AQAB",
          "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
          "alg": "PS256",
          "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ"
        }
      ]
    }
  },
  "client2": {
    "client_id": "client_XUwBuUHRMTVHAleZEJxH18815",
    "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
    "id_token_encrypted_response_alg": "RSA-OAEP",
    "certificate": "-----BEGIN CERTIFICATE-----\nMIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3\nMDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx\nMzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm\ncmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp\ndmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ\nk/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi\nMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG\nVfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b\nnE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4\nC4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF\nSaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0\nPR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB\nAAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce\nRCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF\nBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w\nZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v\nY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu\nY3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P\nAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw\nggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl\ncnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl\ncyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg\ndXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg\nU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0\ndXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0\naWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG\nCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh\nc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn\nLPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO\nhUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+\nVibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1\nzHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO\nVZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af\n1zroWKsv2A\u003d\u003d\n-----END CERTIFICATE-----",
    "jwks": {
      "keys": [
        {
          "kty": "RSA",
          "e": "AQAB",
          "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
          "alg": "PS256",
          "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ",
          "use": "sig"
        },
        {
          "kty": "RSA",
          "e": "AQAB",
          "kid": "o_xvg824afVVwHrd1A7-zOGeH2yA0Y5aXdpOUOzj0dM",
          "n": "2ACeyabQj1JtNk8eKPs0dtPohlXzAjEzmn00NvZIDmAJP8qXgwjXmbeJJIpf2czYx8AOjWd4FjFdPPAubnCeAJkvG5xOF328KMXmpQFgmtKRaFhHgUCvmW_0uHYCvi-sR5ClYhJUnULmLCrt8q2hbODLuAuLpI4QsWtwJb3EsOjwjGCeSylm31UKL7aMuaPrzrtSijSkk2mBEpkA6yDeFXg8hUmmLbTdIHfhzYnEZ6KW8n1nJp3UcFXcMlIE09meffwqXHSrovJIk9qysUTv5hdatD0dZZDxPRQQ0qPN3wK8d8l4FMjJqHY6ifuV_qZu8WUSfe0VcCKDIez0X-C1xw",
          "use": "enc",
          "alg": "PS256"
        }
      ]
    },
    "id_token_encrypted_response_enc": "A256GCM"
  },
  "directory": {
    "keystore": "https://keystore.sandbox.directory.openbankingbrasil.org.br/"
  }
}
testName
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
2022-01-13 13:21:12 SUCCESS
FAPIBrazilGenerateServerConfiguration
Created server configuration
server
{
  "issuer": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/SafraRPTest/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true
}
issuer
https://www.certification.openid.net/test/a/SafraRPTest/
discoveryUrl
https://www.certification.openid.net/test/a/SafraRPTest/.well-known/openid-configuration
2022-01-13 13:21:12 SUCCESS
LoadServerJWKs
Parsed public and private JWK sets
server_jwks
{
  "keys": [
    {
      "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
      "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
      "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
      "kty": "RSA",
      "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
      "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
      "alg": "PS256"
    },
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
server_encryption_keys
{
  "keys": [
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
server_public_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "alg": "PS256",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "alg": "RSA-OAEP",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
2022-01-13 13:21:12 SUCCESS
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2022-01-13 13:21:12
SetServerSigningAlgToPS256
Successfully set signing algorithm to PS256
2022-01-13 13:21:12
FAPIBrazilSetGrantTypesSupportedInServerConfiguration
Successfully set grant_types_supported
server
{
  "issuer": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/SafraRPTest/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ]
}
2022-01-13 13:21:12
AddClaimsParameterSupportedTrueToServerConfiguration
Successfully added claims_parameter_supported to server configuration
server
{
  "issuer": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/SafraRPTest/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true
}
2022-01-13 13:21:12
FAPIBrazilAddBrazilSpecificSettingsToServerConfiguration
Added open banking Brazil specific server settings
server
{
  "issuer": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/SafraRPTest/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ]
}
2022-01-13 13:21:12
SetTokenEndpointAuthMethodsSupportedToPrivateKeyJWTOnly
Changed token_endpoint_auth_methods_supported to private_key_jwt only in server configuration
server_configuration
{
  "issuer": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/SafraRPTest/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ]
}
2022-01-13 13:21:12
AddPushedAuthorizationRequestEndpointToServerConfig
Added pushed_authorization_request_endpoint to server configuration
endpoint
https://www.certification.openid.net/test/a/SafraRPTest/par
2022-01-13 13:21:12
AddRequirePushedAuthorizationRequestsToServerConfig
Added require_pushed_authorization_requests to server configuration
value
true
2022-01-13 13:21:12 SUCCESS
AddResponseTypeCodeIdTokenToServerConfiguration
Added code id_token as response type supported
response_types_supported
[
  "code id_token"
]
2022-01-13 13:21:12 SUCCESS
FAPIBrazilAddTokenEndpointAuthSigningAlgValuesSupportedToServer
Set token_endpoint_auth_signing_alg_values_supported
values
[
  "PS256"
]
2022-01-13 13:21:12 SUCCESS
CheckServerConfiguration
Found required server configuration keys
required
[
  "authorization_endpoint",
  "token_endpoint",
  "issuer"
]
2022-01-13 13:21:12 SUCCESS
FAPIEnsureMinimumServerKeyLength
Validated minimum key lengths for server_jwks
server_jwks
{
  "keys": [
    {
      "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
      "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
      "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
      "kty": "RSA",
      "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
      "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
      "alg": "PS256"
    },
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
2022-01-13 13:21:12 SUCCESS
LoadUserInfo
Added user information
user_info
{
  "sub": "user-subject-1234531",
  "name": "Demo T. User",
  "email": "user@example.com",
  "email_verified": false
}
Verify configuration of first client
2022-01-13 13:21:12 SUCCESS
GetStaticClientConfiguration
Found a static client object
client_id
client_XUwBuUHRMTVHAleZEJxH18815
redirect_uri
https://portalspa-hml.safra.com.br/callback
certificate
-----BEGIN CERTIFICATE-----
MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3
MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx
MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm
cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp
dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ
k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG
VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b
nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4
C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF
SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0
PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB
AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce
RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF
BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w
ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v
Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu
Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P
AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw
ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl
cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl
cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg
dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg
U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0
dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0
aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG
CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh
c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn
LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO
hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+
Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1
zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO
VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af
1zroWKsv2A==
-----END CERTIFICATE-----
jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ"
    }
  ]
}
2022-01-13 13:21:12 SUCCESS
ValidateClientJWKsPublicPart
Valid client JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2022-01-13 13:21:12 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ"
    }
  ]
}
2022-01-13 13:21:12 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2022-01-13 13:21:12 SUCCESS
EnsureClientJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2022-01-13 13:21:12 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ"
    }
  ]
}
Verify configuration of second client
2022-01-13 13:21:12 SUCCESS
GetStaticClient2Configuration
Found a static second client object
client_id
client_XUwBuUHRMTVHAleZEJxH18815
redirect_uri
https://portalspa-hml.safra.com.br/callback
id_token_encrypted_response_alg
RSA-OAEP
certificate
-----BEGIN CERTIFICATE-----
MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3
MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx
MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm
cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp
dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ
k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG
VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b
nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4
C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF
SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0
PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB
AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce
RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF
BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w
ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v
Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu
Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P
AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw
ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl
cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl
cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg
dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg
U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0
dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0
aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG
CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh
c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn
LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO
hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+
Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1
zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO
VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af
1zroWKsv2A==
-----END CERTIFICATE-----
jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ",
      "use": "sig"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "o_xvg824afVVwHrd1A7-zOGeH2yA0Y5aXdpOUOzj0dM",
      "n": "2ACeyabQj1JtNk8eKPs0dtPohlXzAjEzmn00NvZIDmAJP8qXgwjXmbeJJIpf2czYx8AOjWd4FjFdPPAubnCeAJkvG5xOF328KMXmpQFgmtKRaFhHgUCvmW_0uHYCvi-sR5ClYhJUnULmLCrt8q2hbODLuAuLpI4QsWtwJb3EsOjwjGCeSylm31UKL7aMuaPrzrtSijSkk2mBEpkA6yDeFXg8hUmmLbTdIHfhzYnEZ6KW8n1nJp3UcFXcMlIE09meffwqXHSrovJIk9qysUTv5hdatD0dZZDxPRQQ0qPN3wK8d8l4FMjJqHY6ifuV_qZu8WUSfe0VcCKDIez0X-C1xw",
      "use": "enc",
      "alg": "PS256"
    }
  ]
}
id_token_encrypted_response_enc
A256GCM
2022-01-13 13:21:12 SUCCESS
ValidateClientJWKsPublicPart
Valid client JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2022-01-13 13:21:12 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ",
      "use": "sig"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "o_xvg824afVVwHrd1A7-zOGeH2yA0Y5aXdpOUOzj0dM",
      "n": "2ACeyabQj1JtNk8eKPs0dtPohlXzAjEzmn00NvZIDmAJP8qXgwjXmbeJJIpf2czYx8AOjWd4FjFdPPAubnCeAJkvG5xOF328KMXmpQFgmtKRaFhHgUCvmW_0uHYCvi-sR5ClYhJUnULmLCrt8q2hbODLuAuLpI4QsWtwJb3EsOjwjGCeSylm31UKL7aMuaPrzrtSijSkk2mBEpkA6yDeFXg8hUmmLbTdIHfhzYnEZ6KW8n1nJp3UcFXcMlIE09meffwqXHSrovJIk9qysUTv5hdatD0dZZDxPRQQ0qPN3wK8d8l4FMjJqHY6ifuV_qZu8WUSfe0VcCKDIez0X-C1xw",
      "use": "enc",
      "alg": "PS256"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "o_xvg824afVVwHrd1A7-zOGeH2yA0Y5aXdpOUOzj0dM",
      "alg": "PS256",
      "n": "2ACeyabQj1JtNk8eKPs0dtPohlXzAjEzmn00NvZIDmAJP8qXgwjXmbeJJIpf2czYx8AOjWd4FjFdPPAubnCeAJkvG5xOF328KMXmpQFgmtKRaFhHgUCvmW_0uHYCvi-sR5ClYhJUnULmLCrt8q2hbODLuAuLpI4QsWtwJb3EsOjwjGCeSylm31UKL7aMuaPrzrtSijSkk2mBEpkA6yDeFXg8hUmmLbTdIHfhzYnEZ6KW8n1nJp3UcFXcMlIE09meffwqXHSrovJIk9qysUTv5hdatD0dZZDxPRQQ0qPN3wK8d8l4FMjJqHY6ifuV_qZu8WUSfe0VcCKDIez0X-C1xw"
    }
  ]
}
2022-01-13 13:21:12 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2022-01-13 13:21:12 SUCCESS
EnsureClientJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2022-01-13 13:21:12 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
      "alg": "PS256",
      "n": "2GRx6YnzhHGM5YfXoUYVk4SZsAv4u9hi72amXqxtksdBGc7l1DdZv4U6UZ--QPs2_nMtARHo1x91bRWbI9weqHwfwILiChy4gq3zchfF_PUn7o2tDipWLBVZfqO08B4qhqb5u-7KJ9RgqBUuWr3UJblQkAnWJl9h5AhsdTHDmmndUDnvHoojiaRmxU5IhNZeUx-BO7JpUxz5ZmUrxA279CMgVPnyQF9nh0yz9zWBMOyjYuMVzFEK6_7CX5gXh_wkKpd3YDmREzOYoL4egcOAysHRwfnby2ANlB0tnxQ55lZd0ZLLhOHV57ydx0GWbtHGCuVBT93ncWUL1i5L7PLwBQ",
      "use": "sig"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "kid": "o_xvg824afVVwHrd1A7-zOGeH2yA0Y5aXdpOUOzj0dM",
      "n": "2ACeyabQj1JtNk8eKPs0dtPohlXzAjEzmn00NvZIDmAJP8qXgwjXmbeJJIpf2czYx8AOjWd4FjFdPPAubnCeAJkvG5xOF328KMXmpQFgmtKRaFhHgUCvmW_0uHYCvi-sR5ClYhJUnULmLCrt8q2hbODLuAuLpI4QsWtwJb3EsOjwjGCeSylm31UKL7aMuaPrzrtSijSkk2mBEpkA6yDeFXg8hUmmLbTdIHfhzYnEZ6KW8n1nJp3UcFXcMlIE09meffwqXHSrovJIk9qysUTv5hdatD0dZZDxPRQQ0qPN3wK8d8l4FMjJqHY6ifuV_qZu8WUSfe0VcCKDIez0X-C1xw",
      "use": "enc",
      "alg": "PS256"
    }
  ]
}
2022-01-13 13:21:12
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Setup Done
2022-01-13 13:21:19 INCOMING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Incoming HTTP request to test instance 8Zu5JxPG9CfXNiv
incoming_headers
{
  "host": "www.certification.openid.net",
  "x-dynatrace": "FW4;-987853115;2;1343653795;342;0;-1738730375;588;c43c;2h01;3h501687a3;4h0156;6h875f06497d20aa52b4b87e8c30fa14d0;7h00a9e04378a58ad1",
  "traceparent": "00-875f06497d20aa52b4b87e8c30fa14d0-00a9e04378a58ad1-01",
  "tracestate": "985d1479-c51e8ec5@dt\u003dfw4;2;501687a3;156;0;0;0;24c;cd99;2h01;3h501687a3;4h0156;7h00a9e04378a58ad1",
  "request-id": "|28c0d08d-4449a4c379b97d24.1.",
  "connection": "close"
}
incoming_path
/test/a/SafraRPTest/.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES256-GCM-SHA384
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2022-01-13 13:21:19 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES256-GCM-SHA384
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2022-01-13 13:21:19 OUTGOING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Response to HTTP request to test instance 8Zu5JxPG9CfXNiv
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/SafraRPTest/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/userinfo",
    "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/par"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ],
  "pushed_authorization_request_endpoint": "https://www.certification.openid.net/test/a/SafraRPTest/par",
  "require_pushed_authorization_requests": true,
  "response_types_supported": [
    "code id_token"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256"
  ]
}
outgoing_path
.well-known/openid-configuration
2022-01-13 13:21:20 INCOMING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Incoming HTTP request to test instance 8Zu5JxPG9CfXNiv
incoming_headers
{
  "host": "www.certification.openid.net",
  "x-dynatrace": "FW4;-987853115;2;1343653795;342;1;-1738730375;588;3b27;2h01;3h501687a3;4h0156;6h875f06497d20aa52b4b87e8c30fa14d0;7h8f027739d41ad351",
  "traceparent": "00-875f06497d20aa52b4b87e8c30fa14d0-8f027739d41ad351-01",
  "tracestate": "985d1479-c51e8ec5@dt\u003dfw4;2;501687a3;156;1;0;0;24c;8c4a;2h01;3h501687a3;4h0156;7h8f027739d41ad351",
  "request-id": "|28c0d08d-4449a4c379b97d24.2.",
  "content-type": "application/x-www-form-urlencoded",
  "content-length": "1024",
  "connection": "close"
}
incoming_path
/test-mtls/a/SafraRPTest/token
incoming_body_form_params
{
  "scope": "consents",
  "grant_type": "client_credentials",
  "client_id": "client_XUwBuUHRMTVHAleZEJxH18815",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6Ijk5OGU0NzBlZjJkMTQxNDJiMTQ5MTlmNTAyOTQzMDUzIiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDgwMzc5LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjA4MDA3OSwibmJmIjoxNjQyMDgwMDc5fQ.FwO_GjJ4W9Ai69U-BkOzM6CtiIbz6eWP1gLOKVMcoY64bIeQtSuvHSzFmkmWRuMoi4januP9eFzFDOlMbV4T-l8eKHWYG314CKvSpmZtubj3D9gCVYhGXbLxNdKTXCpxluQVrhU0VCnSVBej014t87hwOVSGqfsqC-1I67WtRhybYLXZbHvecoA_DUA8YhCX8NuUkl8EsTy0Pg7P4ftIM7NVdevVlLfSt3EONTmN2_LqPjuaTeFx__zq6kPO0WWKzm2XkvEKMmE0tdH5zP6zI_JnYUHcoMM3oc6Il3E-gOK_hpAHhNvFBiWKKEQxJSjc53dxIiB0hTBWzmu-3SSKBg",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES256-GCM-SHA384
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A== -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
scope=consents&grant_type=client_credentials&client_id=client_XUwBuUHRMTVHAleZEJxH18815&client_assertion=eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6Ijk5OGU0NzBlZjJkMTQxNDJiMTQ5MTlmNTAyOTQzMDUzIiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDgwMzc5LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjA4MDA3OSwibmJmIjoxNjQyMDgwMDc5fQ.FwO_GjJ4W9Ai69U-BkOzM6CtiIbz6eWP1gLOKVMcoY64bIeQtSuvHSzFmkmWRuMoi4januP9eFzFDOlMbV4T-l8eKHWYG314CKvSpmZtubj3D9gCVYhGXbLxNdKTXCpxluQVrhU0VCnSVBej014t87hwOVSGqfsqC-1I67WtRhybYLXZbHvecoA_DUA8YhCX8NuUkl8EsTy0Pg7P4ftIM7NVdevVlLfSt3EONTmN2_LqPjuaTeFx__zq6kPO0WWKzm2XkvEKMmE0tdH5zP6zI_JnYUHcoMM3oc6Il3E-gOK_hpAHhNvFBiWKKEQxJSjc53dxIiB0hTBWzmu-3SSKBg&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2022-01-13 13:21:20 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES256-GCM-SHA384
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2022-01-13 13:21:20 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A\u003d\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3\nMDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx\nMzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm\ncmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp\ndmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ\nk/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi\nMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG\nVfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b\nnE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4\nC4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF\nSaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0\nPR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB\nAAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce\nRCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF\nBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w\nZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v\nY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu\nY3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P\nAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw\nggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl\ncnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl\ncyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg\ndXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg\nU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0\ndXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0\naWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG\nCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh\nc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn\nLPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO\nhUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+\nVibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1\nzHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO\nVZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af\n1zroWKsv2A\u003d\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003d44b261bc-4f6f-44ce-b3d7-3f98a2b225f4,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3538313630373839303030313238,CN\u003d*.safra.com.br,OU\u003d709138dd-6e9d-5f96-bfff-69a5b2cb3ec0,O\u003dBCO SAFRA S.A.,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "api-mtls-hml.safra.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2022-01-13 13:21:20 SUCCESS
CheckForClientCertificate
Found client certificate
2022-01-13 13:21:20 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3
MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx
MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm
cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp
dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ
k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG
VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b
nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4
C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF
SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0
PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB
AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce
RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF
BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w
ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v
Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu
Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P
AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw
ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl
cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl
cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg
dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg
U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0
dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0
aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG
CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh
c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn
LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO
hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+
Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1
zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO
VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af
1zroWKsv2A==
-----END CERTIFICATE-----
2022-01-13 13:21:20 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6Ijk5OGU0NzBlZjJkMTQxNDJiMTQ5MTlmNTAyOTQzMDUzIiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDgwMzc5LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjA4MDA3OSwibmJmIjoxNjQyMDgwMDc5fQ.FwO_GjJ4W9Ai69U-BkOzM6CtiIbz6eWP1gLOKVMcoY64bIeQtSuvHSzFmkmWRuMoi4januP9eFzFDOlMbV4T-l8eKHWYG314CKvSpmZtubj3D9gCVYhGXbLxNdKTXCpxluQVrhU0VCnSVBej014t87hwOVSGqfsqC-1I67WtRhybYLXZbHvecoA_DUA8YhCX8NuUkl8EsTy0Pg7P4ftIM7NVdevVlLfSt3EONTmN2_LqPjuaTeFx__zq6kPO0WWKzm2XkvEKMmE0tdH5zP6zI_JnYUHcoMM3oc6Il3E-gOK_hpAHhNvFBiWKKEQxJSjc53dxIiB0hTBWzmu-3SSKBg",
  "header": {
    "x5t": "imeJtvhk1_UOZIIOKtvS3EW0nDo",
    "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "client_XUwBuUHRMTVHAleZEJxH18815",
    "aud": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "nbf": 1642080079,
    "iss": "client_XUwBuUHRMTVHAleZEJxH18815",
    "exp": 1642080379,
    "iat": 1642080079,
    "jti": "998e470ef2d14142b14919f502943053"
  }
}
2022-01-13 13:21:20
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2022-01-13 13:21:20 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6Ijk5OGU0NzBlZjJkMTQxNDJiMTQ5MTlmNTAyOTQzMDUzIiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDgwMzc5LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjA4MDA3OSwibmJmIjoxNjQyMDgwMDc5fQ.FwO_GjJ4W9Ai69U-BkOzM6CtiIbz6eWP1gLOKVMcoY64bIeQtSuvHSzFmkmWRuMoi4januP9eFzFDOlMbV4T-l8eKHWYG314CKvSpmZtubj3D9gCVYhGXbLxNdKTXCpxluQVrhU0VCnSVBej014t87hwOVSGqfsqC-1I67WtRhybYLXZbHvecoA_DUA8YhCX8NuUkl8EsTy0Pg7P4ftIM7NVdevVlLfSt3EONTmN2_LqPjuaTeFx__zq6kPO0WWKzm2XkvEKMmE0tdH5zP6zI_JnYUHcoMM3oc6Il3E-gOK_hpAHhNvFBiWKKEQxJSjc53dxIiB0hTBWzmu-3SSKBg
2022-01-13 13:21:20 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2022-01-13 13:21:20 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2022-01-13 13:21:20 SUCCESS
FAPIBrazilExtractRequestedScopeFromClientCredentialsGrant
Found 'consents' scope in request
actual
[
  "consents"
]
expected
consents
2022-01-13 13:21:20 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
Vkgl30D0qJHB8AVXkDsL8QiXamhGQ9RUZwE5fiRmT1jYDRHpIH
2022-01-13 13:21:20 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
Vkgl30D0qJHB8AVXkDsL8QiXamhGQ9RUZwE5fiRmT1jYDRHpIH
token_type
Bearer
2022-01-13 13:21:20
CopyAccessTokenToClientCredentialsField
Condition ran but did not log anything
2022-01-13 13:21:20 OUTGOING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Response to HTTP request to test instance 8Zu5JxPG9CfXNiv
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "Vkgl30D0qJHB8AVXkDsL8QiXamhGQ9RUZwE5fiRmT1jYDRHpIH",
  "token_type": "Bearer"
}
outgoing_path
token
2022-01-13 13:21:22 INCOMING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Incoming HTTP request to test instance 8Zu5JxPG9CfXNiv
incoming_headers
{
  "host": "www.certification.openid.net",
  "x-dynatrace": "FW4;-987853115;2;1343653795;342;2;-1738730375;588;c4ec;2h01;3h501687a3;4h0156;6h875f06497d20aa52b4b87e8c30fa14d0;7h316da3412b1ccc01",
  "traceparent": "00-875f06497d20aa52b4b87e8c30fa14d0-316da3412b1ccc01-01",
  "tracestate": "985d1479-c51e8ec5@dt\u003dfw4;2;501687a3;156;2;0;0;24c;57fd;2h01;3h501687a3;4h0156;7h316da3412b1ccc01",
  "authorization": "Bearer Vkgl30D0qJHB8AVXkDsL8QiXamhGQ9RUZwE5fiRmT1jYDRHpIH",
  "request-id": "|28c0d08d-4449a4c379b97d24.3.",
  "content-type": "application/json; charset\u003dutf-8",
  "content-length": "1078",
  "connection": "close"
}
incoming_path
/test-mtls/a/SafraRPTest/consents/v1/consents
incoming_body_form_params
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES256-GCM-SHA384
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A== -----END CERTIFICATE-----
incoming_body_json
{
  "data": {
    "loggedUser": {
      "document": {
        "identification": "16881808852",
        "rel": "CPF"
      }
    },
    "permissions": [
      "CUSTOMERS_PERSONAL_IDENTIFICATIONS_READ",
      "CUSTOMERS_PERSONAL_ADITTIONALINFO_READ",
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "ACCOUNTS_OVERDRAFT_LIMITS_READ",
      "ACCOUNTS_TRANSACTIONS_READ",
      "CREDIT_CARDS_ACCOUNTS_READ",
      "CREDIT_CARDS_ACCOUNTS_LIMITS_READ",
      "CREDIT_CARDS_ACCOUNTS_TRANSACTIONS_READ",
      "CREDIT_CARDS_ACCOUNTS_BILLS_READ",
      "CREDIT_CARDS_ACCOUNTS_BILLS_TRANSACTIONS_READ",
      "RESOURCES_READ",
      "INVOICE_FINANCINGS_READ",
      "INVOICE_FINANCINGS_SCHEDULED_INSTALMENTS_READ",
      "INVOICE_FINANCINGS_PAYMENTS_READ",
      "INVOICE_FINANCINGS_WARRANTIES_READ",
      "FINANCINGS_READ",
      "FINANCINGS_SCHEDULED_INSTALMENTS_READ",
      "FINANCINGS_PAYMENTS_READ",
      "FINANCINGS_WARRANTIES_READ",
      "LOANS_READ",
      "LOANS_SCHEDULED_INSTALMENTS_READ",
      "LOANS_PAYMENTS_READ",
      "LOANS_WARRANTIES_READ",
      "UNARRANGED_ACCOUNTS_OVERDRAFT_READ",
      "UNARRANGED_ACCOUNTS_OVERDRAFT_SCHEDULED_INSTALMENTS_READ",
      "UNARRANGED_ACCOUNTS_OVERDRAFT_PAYMENTS_READ",
      "UNARRANGED_ACCOUNTS_OVERDRAFT_WARRANTIES_READ"
    ],
    "expirationDateTime": "2023-01-13T13:21:20Z"
  }
}
incoming_query_string_params
{}
incoming_body
{"data":{"loggedUser":{"document":{"identification":"16881808852","rel":"CPF"}},"permissions":["CUSTOMERS_PERSONAL_IDENTIFICATIONS_READ","CUSTOMERS_PERSONAL_ADITTIONALINFO_READ","ACCOUNTS_READ","ACCOUNTS_BALANCES_READ","ACCOUNTS_OVERDRAFT_LIMITS_READ","ACCOUNTS_TRANSACTIONS_READ","CREDIT_CARDS_ACCOUNTS_READ","CREDIT_CARDS_ACCOUNTS_LIMITS_READ","CREDIT_CARDS_ACCOUNTS_TRANSACTIONS_READ","CREDIT_CARDS_ACCOUNTS_BILLS_READ","CREDIT_CARDS_ACCOUNTS_BILLS_TRANSACTIONS_READ","RESOURCES_READ","INVOICE_FINANCINGS_READ","INVOICE_FINANCINGS_SCHEDULED_INSTALMENTS_READ","INVOICE_FINANCINGS_PAYMENTS_READ","INVOICE_FINANCINGS_WARRANTIES_READ","FINANCINGS_READ","FINANCINGS_SCHEDULED_INSTALMENTS_READ","FINANCINGS_PAYMENTS_READ","FINANCINGS_WARRANTIES_READ","LOANS_READ","LOANS_SCHEDULED_INSTALMENTS_READ","LOANS_PAYMENTS_READ","LOANS_WARRANTIES_READ","UNARRANGED_ACCOUNTS_OVERDRAFT_READ","UNARRANGED_ACCOUNTS_OVERDRAFT_SCHEDULED_INSTALMENTS_READ","UNARRANGED_ACCOUNTS_OVERDRAFT_PAYMENTS_READ","UNARRANGED_ACCOUNTS_OVERDRAFT_WARRANTIES_READ"],"expirationDateTime":"2023-01-13T13:21:20Z"}}
2022-01-13 13:21:22 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES256-GCM-SHA384
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
New consent endpoint
2022-01-13 13:21:22 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A\u003d\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3\nMDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx\nMzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm\ncmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp\ndmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ\nk/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi\nMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG\nVfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b\nnE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4\nC4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF\nSaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0\nPR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB\nAAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce\nRCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF\nBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w\nZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v\nY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu\nY3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P\nAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw\nggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl\ncnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl\ncyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg\ndXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg\nU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0\ndXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0\naWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG\nCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh\nc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn\nLPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO\nhUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+\nVibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1\nzHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO\nVZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af\n1zroWKsv2A\u003d\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003d44b261bc-4f6f-44ce-b3d7-3f98a2b225f4,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3538313630373839303030313238,CN\u003d*.safra.com.br,OU\u003d709138dd-6e9d-5f96-bfff-69a5b2cb3ec0,O\u003dBCO SAFRA S.A.,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "api-mtls-hml.safra.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2022-01-13 13:21:22 SUCCESS
CheckForClientCertificate
Found client certificate
2022-01-13 13:21:22 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3
MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx
MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm
cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp
dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ
k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG
VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b
nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4
C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF
SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0
PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB
AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce
RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF
BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w
ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v
Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu
Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P
AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw
ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl
cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl
cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg
dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg
U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0
dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0
aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG
CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh
c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn
LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO
hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+
Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1
zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO
VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af
1zroWKsv2A==
-----END CERTIFICATE-----
2022-01-13 13:21:22 SUCCESS
EnsureIncomingRequestMethodIsPost
Client correctly used http POST method
2022-01-13 13:21:22 SUCCESS
EnsureBearerAccessTokenNotInParams
Client correctly did not send access token in query parameters or form body
2022-01-13 13:21:22 SUCCESS
ExtractBearerAccessTokenFromHeader
Found access token on incoming request
access_token
Vkgl30D0qJHB8AVXkDsL8QiXamhGQ9RUZwE5fiRmT1jYDRHpIH
2022-01-13 13:21:22 SUCCESS
RequireBearerClientCredentialsAccessToken
Found access token in request
actual
Vkgl30D0qJHB8AVXkDsL8QiXamhGQ9RUZwE5fiRmT1jYDRHpIH
2022-01-13 13:21:22 INFO
ExtractFapiDateHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-auth-date
path
headers.x-fapi-auth-date
mapped
object
incoming_request
2022-01-13 13:21:22 INFO
ExtractFapiIpAddressHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-customer-ip-address
path
headers.x-fapi-customer-ip-address
mapped
object
incoming_request
2022-01-13 13:21:22 INFO
ExtractFapiInteractionIdHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-interaction-id
path
headers.x-fapi-interaction-id
mapped
object
incoming_request
2022-01-13 13:21:22 SUCCESS
FAPIBrazilEnsureClientCredentialsScopeContainedConsents
The token request which was used to obtain the access token contained 'consents' scope
actual
[
  "consents"
]
2022-01-13 13:21:22
FAPIBrazilExtractConsentRequest
Condition ran but did not log anything
2022-01-13 13:21:22 SUCCESS
CreateFapiInteractionIdIfNeeded
Created new FAPI interaction ID
fapi_interaction_id
e9cfd530-8bea-4473-acb9-4d278ab2c11e
2022-01-13 13:21:22 SUCCESS
FAPIBrazilGenerateNewConsentResponse
Created consent response
headers
{
  "x-fapi-interaction-id": "e9cfd530-8bea-4473-acb9-4d278ab2c11e"
}
consentId
urn:conformance.oidf:bLRknramvy
consent_response
{
  "data": {
    "consentId": "urn:conformance.oidf:bLRknramvy",
    "creationDateTime": "2022-01-13T13:21:22Z",
    "status": "AWAITING_AUTHORISATION",
    "statusUpdateDateTime": "2022-01-13T13:21:22Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2022-01-13T15:21:22Z",
    "transactionFromDateTime": "2022-01-13T13:16:22Z",
    "transactionToDateTime": "2022-01-13T15:21:22Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/SafraRPTestconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2022-01-13T13:21:22Z"
  }
}
2022-01-13 13:21:22
ClearAccessTokenFromRequest
Condition ran but did not log anything
2022-01-13 13:21:22 OUTGOING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Response to HTTP request to test instance 8Zu5JxPG9CfXNiv
outgoing_status_code
201
outgoing_headers
{
  "x-fapi-interaction-id": [
    "e9cfd530-8bea-4473-acb9-4d278ab2c11e"
  ]
}
outgoing_body
{
  "data": {
    "consentId": "urn:conformance.oidf:bLRknramvy",
    "creationDateTime": "2022-01-13T13:21:22Z",
    "status": "AWAITING_AUTHORISATION",
    "statusUpdateDateTime": "2022-01-13T13:21:22Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2022-01-13T15:21:22Z",
    "transactionFromDateTime": "2022-01-13T13:16:22Z",
    "transactionToDateTime": "2022-01-13T15:21:22Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/SafraRPTestconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2022-01-13T13:21:22Z"
  }
}
outgoing_path
consents/v1/consents
2022-01-13 13:21:23 INCOMING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Incoming HTTP request to test instance 8Zu5JxPG9CfXNiv
incoming_headers
{
  "host": "www.certification.openid.net",
  "x-dynatrace": "FW4;-987853115;2;1343653795;342;3;-1738730375;588;55dc;2h01;3h501687a3;4h0156;6h875f06497d20aa52b4b87e8c30fa14d0;7hbac814caa3314bd3",
  "traceparent": "00-875f06497d20aa52b4b87e8c30fa14d0-bac814caa3314bd3-01",
  "tracestate": "985d1479-c51e8ec5@dt\u003dfw4;2;501687a3;156;3;0;0;24c;4c17;2h01;3h501687a3;4h0156;7hbac814caa3314bd3",
  "request-id": "|28c0d08d-4449a4c379b97d24.4.",
  "content-type": "application/x-www-form-urlencoded",
  "x-cert": "System.Security.Cryptography.RSAOpenSsl",
  "content-length": "2224",
  "connection": "close"
}
incoming_path
/test-mtls/a/SafraRPTest/par
incoming_body_form_params
{
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6ImFkYTJhZDc1OTQxMTQyNzA5NGZhY2NjNTgyYjQxMTA0IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9TYWZyYVJQVGVzdC8iLCJleHAiOjE2NDIwODAzODIsImlzcyI6ImNsaWVudF9YVXdCdVVIUk1UVkhBbGVaRUp4SDE4ODE1IiwiaWF0IjoxNjQyMDgwMDgyLCJuYmYiOjE2NDIwODAwODJ9.pMxja-EjlTPOVECItDdLjC45wS_vXIQ54WmaEr5GaO2DNlcAAbiVPJLZDLglNjDMKktKE2ybpFM7rGBdSVxjw77ydamJ2XJqZKdUykC2XHSyi0gD5gwX2_KwYKvF24koyXH6sqQer_tI2dUdkawbdmxfradeRmRHQqOf28qUekCtUE6qqXS0f8pFMsC1vdZGdT1Ivx5wx0mSZqCGRv3HIwxKdy7nDZ3iyCar5B_k92B93SDkXXAtV8cnMtgnyoC7_xXn7v2aBmus6cv-luI_XF3oEQwUzP7cev1DlWwiivium2uAywTXs5uPceEBNsj3c05BydLMFPo8bNz-4lwvXg",
  "request": "eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgifQ.eyJhdWQiOiJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1NhZnJhUlBUZXN0LyIsIm5iZiI6MTY0MjA4MDA4Miwic2NvcGUiOiJvcGVuaWQgY29uc2VudHMgY3VzdG9tZXJzIGFjY291bnRzIGNyZWRpdC1jYXJkcy1hY2NvdW50cyByZXNvdXJjZXMgaW52b2ljZS1maW5hbmNpbmdzIGZpbmFuY2luZ3MgbG9hbnMgdW5hcnJhbmdlZC1hY2NvdW50cy1vdmVyZHJhZnQgY29uc2VudDp1cm46Y29uZm9ybWFuY2Uub2lkZjpiTFJrbnJhbXZ5IiwiaXNzIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUiLCJyZXNwb25zZV90eXBlIjoiY29kZSBpZF90b2tlbiIsInJlZGlyZWN0X3VyaSI6Imh0dHBzOi8vcG9ydGFsc3BhLWhtbC5zYWZyYS5jb20uYnIvY2FsbGJhY2siLCJzdGF0ZSI6IjA0NzVlZDQ5N2RhNDQ4YTBhNzk1MmQzNDNmZDU4NWQ3IiwiZXhwIjoxNjQyMDgwMzgyLCJub25jZSI6ImI0ZjMzNzMyYTgyYzRlMDg4YTMzYjE0MmQ4MmU2OWIxIiwiY2xpZW50X2lkIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUiLCJjb2RlX2NoYWxsZW5nZV9tZXRob2QiOiJTMjU2IiwiY29kZV9jaGFsbGVuZ2UiOiJSZDgzYmJPOExkTlJTRlZGTTBwNlU0cTVWVVdnZnFwVEVtTFlBTDJnYk9RIn0.h6UVw2np0wiAKdQB_4GKDz-lKwSs8NdSbmEd15NweSTPDEH2eED9CJmyg-wij4uX3xIqGOqrP5WlCXevClBn1KdT2ty9WXj9vW1oudZ0nlvMXSSDTFsdVQSTx4e1zkQDevarwJIOf6EgZ_fENjo1DwgPSFCfSdy52hV85sa8ZFuszc65UYIwPWDEYQrPCtD-XiDmMRr3Jw6jCvcdhAg0X2D-IKdecEg-HyvuGeQUmRMyb5fIzxhOcg0-ljpfGHdGBolH_UhVKeVgZKgl27wbz5prDTcrv6N-NWJ8a6Az7wJTh6xHcLn1g_goFYgohtb-WgL8yQoNnQovHYfoQkuuAw"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES256-GCM-SHA384
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A== -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer&client_assertion=eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6ImFkYTJhZDc1OTQxMTQyNzA5NGZhY2NjNTgyYjQxMTA0IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9TYWZyYVJQVGVzdC8iLCJleHAiOjE2NDIwODAzODIsImlzcyI6ImNsaWVudF9YVXdCdVVIUk1UVkhBbGVaRUp4SDE4ODE1IiwiaWF0IjoxNjQyMDgwMDgyLCJuYmYiOjE2NDIwODAwODJ9.pMxja-EjlTPOVECItDdLjC45wS_vXIQ54WmaEr5GaO2DNlcAAbiVPJLZDLglNjDMKktKE2ybpFM7rGBdSVxjw77ydamJ2XJqZKdUykC2XHSyi0gD5gwX2_KwYKvF24koyXH6sqQer_tI2dUdkawbdmxfradeRmRHQqOf28qUekCtUE6qqXS0f8pFMsC1vdZGdT1Ivx5wx0mSZqCGRv3HIwxKdy7nDZ3iyCar5B_k92B93SDkXXAtV8cnMtgnyoC7_xXn7v2aBmus6cv-luI_XF3oEQwUzP7cev1DlWwiivium2uAywTXs5uPceEBNsj3c05BydLMFPo8bNz-4lwvXg&request=eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgifQ.eyJhdWQiOiJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1NhZnJhUlBUZXN0LyIsIm5iZiI6MTY0MjA4MDA4Miwic2NvcGUiOiJvcGVuaWQgY29uc2VudHMgY3VzdG9tZXJzIGFjY291bnRzIGNyZWRpdC1jYXJkcy1hY2NvdW50cyByZXNvdXJjZXMgaW52b2ljZS1maW5hbmNpbmdzIGZpbmFuY2luZ3MgbG9hbnMgdW5hcnJhbmdlZC1hY2NvdW50cy1vdmVyZHJhZnQgY29uc2VudDp1cm46Y29uZm9ybWFuY2Uub2lkZjpiTFJrbnJhbXZ5IiwiaXNzIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUiLCJyZXNwb25zZV90eXBlIjoiY29kZSBpZF90b2tlbiIsInJlZGlyZWN0X3VyaSI6Imh0dHBzOi8vcG9ydGFsc3BhLWhtbC5zYWZyYS5jb20uYnIvY2FsbGJhY2siLCJzdGF0ZSI6IjA0NzVlZDQ5N2RhNDQ4YTBhNzk1MmQzNDNmZDU4NWQ3IiwiZXhwIjoxNjQyMDgwMzgyLCJub25jZSI6ImI0ZjMzNzMyYTgyYzRlMDg4YTMzYjE0MmQ4MmU2OWIxIiwiY2xpZW50X2lkIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUiLCJjb2RlX2NoYWxsZW5nZV9tZXRob2QiOiJTMjU2IiwiY29kZV9jaGFsbGVuZ2UiOiJSZDgzYmJPOExkTlJTRlZGTTBwNlU0cTVWVVdnZnFwVEVtTFlBTDJnYk9RIn0.h6UVw2np0wiAKdQB_4GKDz-lKwSs8NdSbmEd15NweSTPDEH2eED9CJmyg-wij4uX3xIqGOqrP5WlCXevClBn1KdT2ty9WXj9vW1oudZ0nlvMXSSDTFsdVQSTx4e1zkQDevarwJIOf6EgZ_fENjo1DwgPSFCfSdy52hV85sa8ZFuszc65UYIwPWDEYQrPCtD-XiDmMRr3Jw6jCvcdhAg0X2D-IKdecEg-HyvuGeQUmRMyb5fIzxhOcg0-ljpfGHdGBolH_UhVKeVgZKgl27wbz5prDTcrv6N-NWJ8a6Az7wJTh6xHcLn1g_goFYgohtb-WgL8yQoNnQovHYfoQkuuAw
2022-01-13 13:21:23 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES256-GCM-SHA384
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
PAR endpoint
2022-01-13 13:21:23 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A\u003d\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3\nMDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx\nMzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm\ncmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp\ndmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ\nk/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi\nMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG\nVfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b\nnE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4\nC4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF\nSaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0\nPR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB\nAAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce\nRCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF\nBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w\nZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v\nY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu\nY3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P\nAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw\nggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl\ncnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl\ncyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg\ndXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg\nU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0\ndXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0\naWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG\nCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh\nc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn\nLPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO\nhUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+\nVibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1\nzHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO\nVZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af\n1zroWKsv2A\u003d\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003d44b261bc-4f6f-44ce-b3d7-3f98a2b225f4,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3538313630373839303030313238,CN\u003d*.safra.com.br,OU\u003d709138dd-6e9d-5f96-bfff-69a5b2cb3ec0,O\u003dBCO SAFRA S.A.,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "api-mtls-hml.safra.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2022-01-13 13:21:23 SUCCESS
CheckForClientCertificate
Found client certificate
2022-01-13 13:21:23 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3
MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx
MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm
cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp
dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ
k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG
VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b
nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4
C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF
SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0
PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB
AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce
RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF
BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w
ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v
Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu
Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P
AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw
ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl
cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl
cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg
dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg
U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0
dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0
aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG
CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh
c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn
LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO
hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+
Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1
zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO
VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af
1zroWKsv2A==
-----END CERTIFICATE-----
2022-01-13 13:21:23 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6ImFkYTJhZDc1OTQxMTQyNzA5NGZhY2NjNTgyYjQxMTA0IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9TYWZyYVJQVGVzdC8iLCJleHAiOjE2NDIwODAzODIsImlzcyI6ImNsaWVudF9YVXdCdVVIUk1UVkhBbGVaRUp4SDE4ODE1IiwiaWF0IjoxNjQyMDgwMDgyLCJuYmYiOjE2NDIwODAwODJ9.pMxja-EjlTPOVECItDdLjC45wS_vXIQ54WmaEr5GaO2DNlcAAbiVPJLZDLglNjDMKktKE2ybpFM7rGBdSVxjw77ydamJ2XJqZKdUykC2XHSyi0gD5gwX2_KwYKvF24koyXH6sqQer_tI2dUdkawbdmxfradeRmRHQqOf28qUekCtUE6qqXS0f8pFMsC1vdZGdT1Ivx5wx0mSZqCGRv3HIwxKdy7nDZ3iyCar5B_k92B93SDkXXAtV8cnMtgnyoC7_xXn7v2aBmus6cv-luI_XF3oEQwUzP7cev1DlWwiivium2uAywTXs5uPceEBNsj3c05BydLMFPo8bNz-4lwvXg",
  "header": {
    "x5t": "imeJtvhk1_UOZIIOKtvS3EW0nDo",
    "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "client_XUwBuUHRMTVHAleZEJxH18815",
    "aud": "https://www.certification.openid.net/test/a/SafraRPTest/",
    "nbf": 1642080082,
    "iss": "client_XUwBuUHRMTVHAleZEJxH18815",
    "exp": 1642080382,
    "iat": 1642080082,
    "jti": "ada2ad759411427094faccc582b41104"
  }
}
2022-01-13 13:21:23
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2022-01-13 13:21:23 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6ImFkYTJhZDc1OTQxMTQyNzA5NGZhY2NjNTgyYjQxMTA0IiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS9TYWZyYVJQVGVzdC8iLCJleHAiOjE2NDIwODAzODIsImlzcyI6ImNsaWVudF9YVXdCdVVIUk1UVkhBbGVaRUp4SDE4ODE1IiwiaWF0IjoxNjQyMDgwMDgyLCJuYmYiOjE2NDIwODAwODJ9.pMxja-EjlTPOVECItDdLjC45wS_vXIQ54WmaEr5GaO2DNlcAAbiVPJLZDLglNjDMKktKE2ybpFM7rGBdSVxjw77ydamJ2XJqZKdUykC2XHSyi0gD5gwX2_KwYKvF24koyXH6sqQer_tI2dUdkawbdmxfradeRmRHQqOf28qUekCtUE6qqXS0f8pFMsC1vdZGdT1Ivx5wx0mSZqCGRv3HIwxKdy7nDZ3iyCar5B_k92B93SDkXXAtV8cnMtgnyoC7_xXn7v2aBmus6cv-luI_XF3oEQwUzP7cev1DlWwiivium2uAywTXs5uPceEBNsj3c05BydLMFPo8bNz-4lwvXg
2022-01-13 13:21:23 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2022-01-13 13:21:23 SUCCESS
ValidateClientAssertionClaimsForPAREndpoint
Client Assertion passed all validation checks
2022-01-13 13:21:23 SUCCESS
ExtractRequestObjectFromPAREndpointRequest
Parsed request object
request_object
{
  "value": "eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgifQ.eyJhdWQiOiJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1NhZnJhUlBUZXN0LyIsIm5iZiI6MTY0MjA4MDA4Miwic2NvcGUiOiJvcGVuaWQgY29uc2VudHMgY3VzdG9tZXJzIGFjY291bnRzIGNyZWRpdC1jYXJkcy1hY2NvdW50cyByZXNvdXJjZXMgaW52b2ljZS1maW5hbmNpbmdzIGZpbmFuY2luZ3MgbG9hbnMgdW5hcnJhbmdlZC1hY2NvdW50cy1vdmVyZHJhZnQgY29uc2VudDp1cm46Y29uZm9ybWFuY2Uub2lkZjpiTFJrbnJhbXZ5IiwiaXNzIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUiLCJyZXNwb25zZV90eXBlIjoiY29kZSBpZF90b2tlbiIsInJlZGlyZWN0X3VyaSI6Imh0dHBzOi8vcG9ydGFsc3BhLWhtbC5zYWZyYS5jb20uYnIvY2FsbGJhY2siLCJzdGF0ZSI6IjA0NzVlZDQ5N2RhNDQ4YTBhNzk1MmQzNDNmZDU4NWQ3IiwiZXhwIjoxNjQyMDgwMzgyLCJub25jZSI6ImI0ZjMzNzMyYTgyYzRlMDg4YTMzYjE0MmQ4MmU2OWIxIiwiY2xpZW50X2lkIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUiLCJjb2RlX2NoYWxsZW5nZV9tZXRob2QiOiJTMjU2IiwiY29kZV9jaGFsbGVuZ2UiOiJSZDgzYmJPOExkTlJTRlZGTTBwNlU0cTVWVVdnZnFwVEVtTFlBTDJnYk9RIn0.h6UVw2np0wiAKdQB_4GKDz-lKwSs8NdSbmEd15NweSTPDEH2eED9CJmyg-wij4uX3xIqGOqrP5WlCXevClBn1KdT2ty9WXj9vW1oudZ0nlvMXSSDTFsdVQSTx4e1zkQDevarwJIOf6EgZ_fENjo1DwgPSFCfSdy52hV85sa8ZFuszc65UYIwPWDEYQrPCtD-XiDmMRr3Jw6jCvcdhAg0X2D-IKdecEg-HyvuGeQUmRMyb5fIzxhOcg0-ljpfGHdGBolH_UhVKeVgZKgl27wbz5prDTcrv6N-NWJ8a6Az7wJTh6xHcLn1g_goFYgohtb-WgL8yQoNnQovHYfoQkuuAw",
  "header": {
    "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
    "alg": "PS256"
  },
  "claims": {
    "aud": "https://www.certification.openid.net/test/a/SafraRPTest/",
    "nbf": 1642080082,
    "scope": "openid consents customers accounts credit-cards-accounts resources invoice-financings financings loans unarranged-accounts-overdraft consent:urn:conformance.oidf:bLRknramvy",
    "iss": "client_XUwBuUHRMTVHAleZEJxH18815",
    "response_type": "code id_token",
    "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
    "state": "0475ed497da448a0a7952d343fd585d7",
    "code_challenge_method": "S256",
    "exp": 1642080382,
    "nonce": "b4f33732a82c4e088a33b142d82e69b1",
    "client_id": "client_XUwBuUHRMTVHAleZEJxH18815",
    "code_challenge": "Rd83bbO8LdNRSFVFM0p6U4q5VUWgfqpTEmLYAL2gbOQ"
  }
}
2022-01-13 13:21:23 SUCCESS
EnsurePAREndpointRequestDoesNotContainRequestUriParameter
PAR endpoint request does not contain a request_uri parameter
2022-01-13 13:21:23 INFO
ValidateEncryptedRequestObjectHasKid
Skipped evaluation due to missing required element: authorization_request_object jwe_header
path
jwe_header
mapped
object
authorization_request_object
2022-01-13 13:21:23 SUCCESS
FAPIValidateRequestObjectSigningAlg
Request object was signed with a permitted algorithm
alg
PS256
2022-01-13 13:21:23
FAPIBrazilValidateRequestObjectIdTokenACRClaims
acr claim is not requested
2022-01-13 13:21:23 SUCCESS
FAPIValidateRequestObjectExp
Request object contains a valid exp claim, expiry time
exp
"Jan 13, 2022, 1:26:22 PM"
2022-01-13 13:21:23 SUCCESS
FAPI1AdvancedValidateRequestObjectNBFClaim
nbf claim is valid
nbf
"Jan 13, 2022, 1:21:22 PM"
now
"Jan 13, 2022, 1:21:23 PM"
2022-01-13 13:21:23 INFO
ValidateRequestObjectClaims
Missing issuance time
2022-01-13 13:21:23
ValidateRequestObjectClaims
Request object does not contain a max_age claim
2022-01-13 13:21:23 SUCCESS
ValidateRequestObjectClaims
Request object claims passed all validation checks
2022-01-13 13:21:23 SUCCESS
EnsureNumericRequestObjectClaimsAreNotNull
None of the claims expected to have numeric values, have null values
numeric_claims
[
  "max_age"
]
2022-01-13 13:21:23 SUCCESS
EnsureRequestObjectDoesNotContainRequestOrRequestUri
Request object does not contain request or request_uri
2022-01-13 13:21:23 SUCCESS
EnsureRequestObjectDoesNotContainSubWithClientId
Request object does not contain Client Id in sub
2022-01-13 13:21:23 SUCCESS
ValidateRequestObjectSignature
Request object signature validated using a key in the client's JWKS and using the client's registered request_object_signing_alg
request_object
eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgifQ.eyJhdWQiOiJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC9hL1NhZnJhUlBUZXN0LyIsIm5iZiI6MTY0MjA4MDA4Miwic2NvcGUiOiJvcGVuaWQgY29uc2VudHMgY3VzdG9tZXJzIGFjY291bnRzIGNyZWRpdC1jYXJkcy1hY2NvdW50cyByZXNvdXJjZXMgaW52b2ljZS1maW5hbmNpbmdzIGZpbmFuY2luZ3MgbG9hbnMgdW5hcnJhbmdlZC1hY2NvdW50cy1vdmVyZHJhZnQgY29uc2VudDp1cm46Y29uZm9ybWFuY2Uub2lkZjpiTFJrbnJhbXZ5IiwiaXNzIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUiLCJyZXNwb25zZV90eXBlIjoiY29kZSBpZF90b2tlbiIsInJlZGlyZWN0X3VyaSI6Imh0dHBzOi8vcG9ydGFsc3BhLWhtbC5zYWZyYS5jb20uYnIvY2FsbGJhY2siLCJzdGF0ZSI6IjA0NzVlZDQ5N2RhNDQ4YTBhNzk1MmQzNDNmZDU4NWQ3IiwiZXhwIjoxNjQyMDgwMzgyLCJub25jZSI6ImI0ZjMzNzMyYTgyYzRlMDg4YTMzYjE0MmQ4MmU2OWIxIiwiY2xpZW50X2lkIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUiLCJjb2RlX2NoYWxsZW5nZV9tZXRob2QiOiJTMjU2IiwiY29kZV9jaGFsbGVuZ2UiOiJSZDgzYmJPOExkTlJTRlZGTTBwNlU0cTVWVVdnZnFwVEVtTFlBTDJnYk9RIn0.h6UVw2np0wiAKdQB_4GKDz-lKwSs8NdSbmEd15NweSTPDEH2eED9CJmyg-wij4uX3xIqGOqrP5WlCXevClBn1KdT2ty9WXj9vW1oudZ0nlvMXSSDTFsdVQSTx4e1zkQDevarwJIOf6EgZ_fENjo1DwgPSFCfSdy52hV85sa8ZFuszc65UYIwPWDEYQrPCtD-XiDmMRr3Jw6jCvcdhAg0X2D-IKdecEg-HyvuGeQUmRMyb5fIzxhOcg0-ljpfGHdGBolH_UhVKeVgZKgl27wbz5prDTcrv6N-NWJ8a6Az7wJTh6xHcLn1g_goFYgohtb-WgL8yQoNnQovHYfoQkuuAw
request_object_signing_alg
PS256
jwk
Sun RSA public key, 2048 bits
  params: null
  modulus: 27317005133317805192806760528852339923492353512235657242373770667550482636383058152241763242899243590510886742369909995744634317769376156025319367773285730731881660146466929919531999356316138694239765585923733085598540913159621964662231658995625650459587810069348726397568662051897147600110311023758046324349410668829004864378877917443777578185960111723181521868093201680907747046475384551022492435381540942020065252906547519942072030894200912668741513959140858170657378829949009347461870925320758566164123500357237516086049488677768389753461936607006172049603857829706031784001244671456119721973322682338748251959301
  public exponent: 65537
2022-01-13 13:21:23 SUCCESS
EnsureMatchingRedirectUriInRequestObject
Redirect URI matched
actual
https://portalspa-hml.safra.com.br/callback
2022-01-13 13:21:23 SUCCESS
EnsureRequestObjectContainsCodeChallengeWhenUsingPAR
Found required PKCE parameters in request
code_challenge_method
S256
code_challenge
Rd83bbO8LdNRSFVFM0p6U4q5VUWgfqpTEmLYAL2gbOQ
2022-01-13 13:21:23 SUCCESS
CreatePAREndpointResponse
Created PAR endpoint response
request_uri
urn:ietf:params:oauth:request_uri:f9d332bf-fb6b-41b2-a3c2-4da19ad1c2be
expires_in
600
2022-01-13 13:21:23 OUTGOING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Response to HTTP request to test instance 8Zu5JxPG9CfXNiv
outgoing_status_code
201
outgoing_headers
{}
outgoing_body
{
  "request_uri": "urn:ietf:params:oauth:request_uri:f9d332bf-fb6b-41b2-a3c2-4da19ad1c2be",
  "expires_in": 600
}
outgoing_path
par
2022-01-13 13:21:28 INCOMING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Incoming HTTP request to test instance 8Zu5JxPG9CfXNiv
incoming_headers
{
  "host": "www.certification.openid.net",
  "sec-ch-ua": "\" Not;A Brand\";v\u003d\"99\", \"Google Chrome\";v\u003d\"97\", \"Chromium\";v\u003d\"97\"",
  "sec-ch-ua-mobile": "?0",
  "sec-ch-ua-platform": "\"Windows\"",
  "upgrade-insecure-requests": "1",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/97.0.4692.71 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "none",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "pt-BR,pt;q\u003d0.9,en-US;q\u003d0.8,en;q\u003d0.7",
  "cookie": "__utmc\u003d201319536; __utma\u003d201319536.1341971708.1631915075.1641907690.1641941726.54; __utmz\u003d201319536.1641941726.54.15.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; JSESSIONID\u003d40F71EE6E98199D2EFB00F5ABE31D541",
  "connection": "close"
}
incoming_path
/test/a/SafraRPTest/authorize
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{
  "request_uri": "urn:ietf:params:oauth:request_uri:f9d332bf-fb6b-41b2-a3c2-4da19ad1c2be",
  "client_id": "client_XUwBuUHRMTVHAleZEJxH18815",
  "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
  "scope": "openid consents customers accounts credit-cards-accounts resources invoice-financings financings loans unarranged-accounts-overdraft consent:urn:conformance.oidf:bLRknramvy",
  "response_type": "code id_token"
}
incoming_body
2022-01-13 13:21:28 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Authorization endpoint
2022-01-13 13:21:28 SUCCESS
EnsureAuthorizationRequestDoesNotContainRequestWhenUsingPAR
Request does not contain a request parameter
2022-01-13 13:21:28 INFO
ValidateEncryptedRequestObjectHasKid
Skipped evaluation due to missing required element: authorization_request_object jwe_header
path
jwe_header
mapped
object
authorization_request_object
2022-01-13 13:21:28 SUCCESS
CreateEffectiveAuthorizationRequestParameters
Merged http request parameters with request object claims
effective_authorization_endpoint_request
{
  "client_id": "client_XUwBuUHRMTVHAleZEJxH18815",
  "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
  "scope": "openid consents customers accounts credit-cards-accounts resources invoice-financings financings loans unarranged-accounts-overdraft consent:urn:conformance.oidf:bLRknramvy",
  "response_type": "code id_token",
  "aud": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "nbf": 1642080082,
  "iss": "client_XUwBuUHRMTVHAleZEJxH18815",
  "state": "0475ed497da448a0a7952d343fd585d7",
  "code_challenge_method": "S256",
  "exp": 1642080382,
  "nonce": "b4f33732a82c4e088a33b142d82e69b1",
  "code_challenge": "Rd83bbO8LdNRSFVFM0p6U4q5VUWgfqpTEmLYAL2gbOQ"
}
2022-01-13 13:21:28 SUCCESS
EnsureClientIdInAuthorizationRequestParametersMatchRequestObject
client_id http request parameter value matches client_id in request object
2022-01-13 13:21:28 SUCCESS
ExtractRequestedScopes
Requested scopes
scope
openid consents customers accounts credit-cards-accounts resources invoice-financings financings loans unarranged-accounts-overdraft consent:urn:conformance.oidf:bLRknramvy
2022-01-13 13:21:28 SUCCESS
FAPIBrazilValidateConsentScope
Found consent scope in request
actual
[
  "openid",
  "consents",
  "customers",
  "accounts",
  "credit-cards-accounts",
  "resources",
  "invoice-financings",
  "financings",
  "loans",
  "unarranged-accounts-overdraft",
  "consent:urn:conformance.oidf:bLRknramvy"
]
expected
consent:urn:conformance.oidf:bLRknramvy
2022-01-13 13:21:28 SUCCESS
EnsureScopeContainsAccounts
Found accounts scope in request
actual
[
  "openid",
  "consents",
  "customers",
  "accounts",
  "credit-cards-accounts",
  "resources",
  "invoice-financings",
  "financings",
  "loans",
  "unarranged-accounts-overdraft",
  "consent:urn:conformance.oidf:bLRknramvy"
]
2022-01-13 13:21:28 SUCCESS
EnsureResponseTypeIsCodeIdToken
Response type is expected value
expected
code id_token
2022-01-13 13:21:28 SUCCESS
EnsureOpenIDInScopeRequest
Found 'openid' scope in request
actual
[
  "openid",
  "consents",
  "customers",
  "accounts",
  "credit-cards-accounts",
  "resources",
  "invoice-financings",
  "financings",
  "loans",
  "unarranged-accounts-overdraft",
  "consent:urn:conformance.oidf:bLRknramvy"
]
expected
openid
2022-01-13 13:21:28 SUCCESS
EnsureMatchingClientId
Client ID matched
client_id
client_XUwBuUHRMTVHAleZEJxH18815
2022-01-13 13:21:28 SUCCESS
CreateAuthorizationCode
Created authorization code
authorization_code
xn3B3oRXSpxVBvTBHkSGArls9qBc6rWZ
2022-01-13 13:21:28 SUCCESS
ExtractNonceFromAuthorizationRequest
Extracted nonce
nonce
b4f33732a82c4e088a33b142d82e69b1
2022-01-13 13:21:28 SUCCESS
CalculateCHash
Successful c_hash encoding
c_hash
RZyPt5UUZzGm7AztEKF2tg
2022-01-13 13:21:28 SUCCESS
CalculateSHash
Successful s_hash encoding
s_hash
iiLJFV4tQl3vcckcNZkMSw
2022-01-13 13:21:28 SUCCESS
GenerateIdTokenClaims
Created ID Token Claims
iss
https://www.certification.openid.net/test/a/SafraRPTest/
sub
user-subject-1234531
aud
client_XUwBuUHRMTVHAleZEJxH18815
nonce
b4f33732a82c4e088a33b142d82e69b1
iat
1642080088
exp
1642080388
2022-01-13 13:21:28
FAPIBrazilAddCPFAndCPNJToIdTokenClaims
Request object does not contain a claims element.id_token
2022-01-13 13:21:28 SUCCESS
AddCHashToIdTokenClaims
Added c_hash to ID token claims
c_hash
RZyPt5UUZzGm7AztEKF2tg
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "sub": "user-subject-1234531",
  "aud": "client_XUwBuUHRMTVHAleZEJxH18815",
  "nonce": "b4f33732a82c4e088a33b142d82e69b1",
  "iat": 1642080088,
  "exp": 1642080388,
  "c_hash": "RZyPt5UUZzGm7AztEKF2tg"
}
2022-01-13 13:21:28 SUCCESS
AddSHashToIdTokenClaims
Added s_hash to ID token claims
s_hash
iiLJFV4tQl3vcckcNZkMSw
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "sub": "user-subject-1234531",
  "aud": "client_XUwBuUHRMTVHAleZEJxH18815",
  "nonce": "b4f33732a82c4e088a33b142d82e69b1",
  "iat": 1642080088,
  "exp": 1642080388,
  "c_hash": "RZyPt5UUZzGm7AztEKF2tg",
  "s_hash": "iiLJFV4tQl3vcckcNZkMSw"
}
2022-01-13 13:21:28 INFO
AddAtHashToIdTokenClaims
Skipped evaluation due to missing required string: at_hash
expected
at_hash
2022-01-13 13:21:28 INFO
FAPIBrazilAddACRClaimToIdTokenClaims
Skipped evaluation due to missing required string: requested_id_token_acr_values
expected
requested_id_token_acr_values
2022-01-13 13:21:28 SUCCESS
SignIdToken
Signed the ID token
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6ImNsaWVudF9YVXdCdVVIUk1UVkhBbGVaRUp4SDE4ODE1IiwiY19oYXNoIjoiUlp5UHQ1VVVaekdtN0F6dEVLRjJ0ZyIsInNfaGFzaCI6ImlpTEpGVjR0UWwzdmNja2NOWmtNU3ciLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvU2FmcmFSUFRlc3RcLyIsImV4cCI6MTY0MjA4MDM4OCwibm9uY2UiOiJiNGYzMzczMmE4MmM0ZTA4OGEzM2IxNDJkODJlNjliMSIsImlhdCI6MTY0MjA4MDA4OH0.OnatSKa8oVAwlATH3aahJNunVZq2Ydv1fH1o26e5Fmh0R27vX_JG0Kvrd7Kc9z7JduPT7KaEBTPaF3_Kq1GDt1nm-NPxgb9nCUS_9CMq-LVhYodeiQAhf7QPjw-xsn3jkALqOaIgUhiWdpNPhL4zNLo4Hi4z46I9SItcTK-0kdh0m6vcxJ9QpWt_RLXaPAF1Ca23uDJiiisngI_SGko_6fgPzlSzMg8dxMCj9L6t7RzoSv1nUdpYatUrBsjlh9sIC0CV6Bzy6o8iQD0WgcFxQqxoIvhxVNxxFFvSrlBNyW0i4YpBjpFGuaEQ4v4QMZASqS6BjTBRbxfQ5TRvXG2kfA
2022-01-13 13:21:28 SUCCESS
FAPIBrazilChangeConsentStatusToAuthorized
Changed consent status to AUTHORISED
consent
{
  "data": {
    "consentId": "urn:conformance.oidf:bLRknramvy",
    "creationDateTime": "2022-01-13T13:21:22Z",
    "status": "AUTHORISED",
    "statusUpdateDateTime": "2022-01-13T13:21:28Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2022-01-13T15:21:22Z",
    "transactionFromDateTime": "2022-01-13T13:16:22Z",
    "transactionToDateTime": "2022-01-13T15:21:22Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/SafraRPTestconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2022-01-13T13:21:22Z"
  }
}
2022-01-13 13:21:28 SUCCESS
CreateAuthorizationEndpointResponseParams
Added authorization_endpoint_response_params to environment
params
{
  "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
  "state": "0475ed497da448a0a7952d343fd585d7"
}
2022-01-13 13:21:28 SUCCESS
AddCodeToAuthorizationEndpointResponseParams
Added code to authorization endpoint response params
authorization_endpoint_response_params
{
  "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
  "state": "0475ed497da448a0a7952d343fd585d7",
  "code": "xn3B3oRXSpxVBvTBHkSGArls9qBc6rWZ"
}
2022-01-13 13:21:28 SUCCESS
AddIdTokenToAuthorizationEndpointResponseParams
Added id_token to authorization endpoint response params
authorization_endpoint_response_params
{
  "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
  "state": "0475ed497da448a0a7952d343fd585d7",
  "code": "xn3B3oRXSpxVBvTBHkSGArls9qBc6rWZ",
  "id_token": "eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6ImNsaWVudF9YVXdCdVVIUk1UVkhBbGVaRUp4SDE4ODE1IiwiY19oYXNoIjoiUlp5UHQ1VVVaekdtN0F6dEVLRjJ0ZyIsInNfaGFzaCI6ImlpTEpGVjR0UWwzdmNja2NOWmtNU3ciLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvU2FmcmFSUFRlc3RcLyIsImV4cCI6MTY0MjA4MDM4OCwibm9uY2UiOiJiNGYzMzczMmE4MmM0ZTA4OGEzM2IxNDJkODJlNjliMSIsImlhdCI6MTY0MjA4MDA4OH0.OnatSKa8oVAwlATH3aahJNunVZq2Ydv1fH1o26e5Fmh0R27vX_JG0Kvrd7Kc9z7JduPT7KaEBTPaF3_Kq1GDt1nm-NPxgb9nCUS_9CMq-LVhYodeiQAhf7QPjw-xsn3jkALqOaIgUhiWdpNPhL4zNLo4Hi4z46I9SItcTK-0kdh0m6vcxJ9QpWt_RLXaPAF1Ca23uDJiiisngI_SGko_6fgPzlSzMg8dxMCj9L6t7RzoSv1nUdpYatUrBsjlh9sIC0CV6Bzy6o8iQD0WgcFxQqxoIvhxVNxxFFvSrlBNyW0i4YpBjpFGuaEQ4v4QMZASqS6BjTBRbxfQ5TRvXG2kfA"
}
2022-01-13 13:21:28
SendAuthorizationResponseWithResponseModeFragment
Redirecting back to client
uri
https://portalspa-hml.safra.com.br/callback#state=0475ed497da448a0a7952d343fd585d7&code=xn3B3oRXSpxVBvTBHkSGArls9qBc6rWZ&id_token=eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6ImNsaWVudF9YVXdCdVVIUk1UVkhBbGVaRUp4SDE4ODE1IiwiY19oYXNoIjoiUlp5UHQ1VVVaekdtN0F6dEVLRjJ0ZyIsInNfaGFzaCI6ImlpTEpGVjR0UWwzdmNja2NOWmtNU3ciLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvU2FmcmFSUFRlc3RcLyIsImV4cCI6MTY0MjA4MDM4OCwibm9uY2UiOiJiNGYzMzczMmE4MmM0ZTA4OGEzM2IxNDJkODJlNjliMSIsImlhdCI6MTY0MjA4MDA4OH0.OnatSKa8oVAwlATH3aahJNunVZq2Ydv1fH1o26e5Fmh0R27vX_JG0Kvrd7Kc9z7JduPT7KaEBTPaF3_Kq1GDt1nm-NPxgb9nCUS_9CMq-LVhYodeiQAhf7QPjw-xsn3jkALqOaIgUhiWdpNPhL4zNLo4Hi4z46I9SItcTK-0kdh0m6vcxJ9QpWt_RLXaPAF1Ca23uDJiiisngI_SGko_6fgPzlSzMg8dxMCj9L6t7RzoSv1nUdpYatUrBsjlh9sIC0CV6Bzy6o8iQD0WgcFxQqxoIvhxVNxxFFvSrlBNyW0i4YpBjpFGuaEQ4v4QMZASqS6BjTBRbxfQ5TRvXG2kfA
2022-01-13 13:21:28 OUTGOING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Response to HTTP request to test instance 8Zu5JxPG9CfXNiv
outgoing
org.springframework.web.servlet.view.RedirectView: [RedirectView]; URL [https://portalspa-hml.safra.com.br/callback#state=0475ed497da448a0a7952d343fd585d7&code=xn3B3oRXSpxVBvTBHkSGArls9qBc6rWZ&id_token=eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJ1c2VyLXN1YmplY3QtMTIzNDUzMSIsImF1ZCI6ImNsaWVudF9YVXdCdVVIUk1UVkhBbGVaRUp4SDE4ODE1IiwiY19oYXNoIjoiUlp5UHQ1VVVaekdtN0F6dEVLRjJ0ZyIsInNfaGFzaCI6ImlpTEpGVjR0UWwzdmNja2NOWmtNU3ciLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvU2FmcmFSUFRlc3RcLyIsImV4cCI6MTY0MjA4MDM4OCwibm9uY2UiOiJiNGYzMzczMmE4MmM0ZTA4OGEzM2IxNDJkODJlNjliMSIsImlhdCI6MTY0MjA4MDA4OH0.OnatSKa8oVAwlATH3aahJNunVZq2Ydv1fH1o26e5Fmh0R27vX_JG0Kvrd7Kc9z7JduPT7KaEBTPaF3_Kq1GDt1nm-NPxgb9nCUS_9CMq-LVhYodeiQAhf7QPjw-xsn3jkALqOaIgUhiWdpNPhL4zNLo4Hi4z46I9SItcTK-0kdh0m6vcxJ9QpWt_RLXaPAF1Ca23uDJiiisngI_SGko_6fgPzlSzMg8dxMCj9L6t7RzoSv1nUdpYatUrBsjlh9sIC0CV6Bzy6o8iQD0WgcFxQqxoIvhxVNxxFFvSrlBNyW0i4YpBjpFGuaEQ4v4QMZASqS6BjTBRbxfQ5TRvXG2kfA]
outgoing_path
authorize
2022-01-13 13:21:29 INCOMING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Incoming HTTP request to test instance 8Zu5JxPG9CfXNiv
incoming_headers
{
  "host": "www.certification.openid.net",
  "x-dynatrace": "FW4;-987853115;5;1343653795;343;0;-1738730375;691;9b53;2h01;3h501687a3;4h0157;6ha02dad9a0281abdeb6f2fecafa3ce91a;7h526c51b276262a11",
  "traceparent": "00-a02dad9a0281abdeb6f2fecafa3ce91a-526c51b276262a11-01",
  "tracestate": "985d1479-c51e8ec5@dt\u003dfw4;5;501687a3;157;0;0;0;2b3;b6a5;2h01;3h501687a3;4h0157;7h526c51b276262a11",
  "connection": "close"
}
incoming_path
/test/a/SafraRPTest/jwks
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES256-GCM-SHA384
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2022-01-13 13:21:29 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES256-GCM-SHA384
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2022-01-13 13:21:29 OUTGOING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Response to HTTP request to test instance 8Zu5JxPG9CfXNiv
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "alg": "PS256",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "alg": "RSA-OAEP",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
outgoing_path
jwks
2022-01-13 13:21:31 INCOMING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Incoming HTTP request to test instance 8Zu5JxPG9CfXNiv
incoming_headers
{
  "host": "www.certification.openid.net",
  "x-dynatrace": "FW4;-987853115;5;1343653795;343;1;-1738730375;691;bdbd;2h01;3h501687a3;4h0157;6ha02dad9a0281abdeb6f2fecafa3ce91a;7h1c5b8d952698d4ca",
  "traceparent": "00-a02dad9a0281abdeb6f2fecafa3ce91a-1c5b8d952698d4ca-01",
  "tracestate": "985d1479-c51e8ec5@dt\u003dfw4;5;501687a3;157;1;0;0;2b3;4d85;2h01;3h501687a3;4h0157;7h1c5b8d952698d4ca",
  "content-type": "application/x-www-form-urlencoded",
  "x-cert": "MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPDo28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkxMzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2FmcmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJk/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iGVfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8bnE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyFSaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMBAAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkceRCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEFBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8vY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIuY3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0PAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wnLPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLOhUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqOVZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af1zroWKsv2A\u003d\u003d",
  "content-length": "1255",
  "connection": "close"
}
incoming_path
/test-mtls/a/SafraRPTest/token
incoming_body_form_params
{
  "grant_type": "authorization_code",
  "code": "xn3B3oRXSpxVBvTBHkSGArls9qBc6rWZ",
  "redirect_uri": "https://portalspa-hml.safra.com.br/callback",
  "client_id": "client_XUwBuUHRMTVHAleZEJxH18815",
  "code_verifier": "b4f33732a82c4e088a33b142d82e69b1b4f33732a82c4e088a33b142d82e69b10475ed497da448a0a7952d343fd585d70475ed497da448a0a7952d343fd585d7",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjRjZTlkYTgxMzFmMTRjZGI4NGNlNzkxNDMyZDYzZDdkIiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDgwMzg5LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjA4MDA4OSwibmJmIjoxNjQyMDgwMDg5fQ.IMdjWevTLHNcCFUlfWXOWo_rr183BndWDB5ZSOOuHR1LD3nn9yVUUkpaHoVR0zy9Ir2A-JSCOkZKtBZtKmjiwzZ5hRPgztn9j-rhIY7DhA57TAlBwq5-TEIkuaXHCaRFarhssDEi9bM-eeGQfq-vsMOO1UXZFNHSPFL7NsJXZ59go1GaSHuiGxD7uTXX_ZzBQLzkek0kBy6KJ5ZWW-sw1HWuF2TCJoK8Q5tsYJl-xScZ31UNxV3bIXXzepX3M8IqAtc1GaCyyGY9lfIpXqvIBHzscVWj6WEqW7zuTiHN7jgRlraC4Ub3OGbXrzt6HZ92swgV-pQ2t92lgAdy8GAbTQ",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES256-GCM-SHA384
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A== -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
grant_type=authorization_code&code=xn3B3oRXSpxVBvTBHkSGArls9qBc6rWZ&redirect_uri=https%3A%2F%2Fportalspa-hml.safra.com.br%2Fcallback&client_id=client_XUwBuUHRMTVHAleZEJxH18815&code_verifier=b4f33732a82c4e088a33b142d82e69b1b4f33732a82c4e088a33b142d82e69b10475ed497da448a0a7952d343fd585d70475ed497da448a0a7952d343fd585d7&client_assertion=eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjRjZTlkYTgxMzFmMTRjZGI4NGNlNzkxNDMyZDYzZDdkIiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDgwMzg5LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjA4MDA4OSwibmJmIjoxNjQyMDgwMDg5fQ.IMdjWevTLHNcCFUlfWXOWo_rr183BndWDB5ZSOOuHR1LD3nn9yVUUkpaHoVR0zy9Ir2A-JSCOkZKtBZtKmjiwzZ5hRPgztn9j-rhIY7DhA57TAlBwq5-TEIkuaXHCaRFarhssDEi9bM-eeGQfq-vsMOO1UXZFNHSPFL7NsJXZ59go1GaSHuiGxD7uTXX_ZzBQLzkek0kBy6KJ5ZWW-sw1HWuF2TCJoK8Q5tsYJl-xScZ31UNxV3bIXXzepX3M8IqAtc1GaCyyGY9lfIpXqvIBHzscVWj6WEqW7zuTiHN7jgRlraC4Ub3OGbXrzt6HZ92swgV-pQ2t92lgAdy8GAbTQ&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2022-01-13 13:21:31 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES256-GCM-SHA384
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2022-01-13 13:21:31 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A\u003d\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3\nMDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx\nMzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm\ncmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp\ndmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ\nk/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi\nMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG\nVfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b\nnE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4\nC4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF\nSaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0\nPR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB\nAAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce\nRCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF\nBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w\nZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v\nY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu\nY3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P\nAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw\nggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl\ncnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl\ncyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg\ndXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg\nU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0\ndXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0\naWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG\nCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh\nc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn\nLPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO\nhUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+\nVibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1\nzHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO\nVZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af\n1zroWKsv2A\u003d\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003d44b261bc-4f6f-44ce-b3d7-3f98a2b225f4,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3538313630373839303030313238,CN\u003d*.safra.com.br,OU\u003d709138dd-6e9d-5f96-bfff-69a5b2cb3ec0,O\u003dBCO SAFRA S.A.,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "api-mtls-hml.safra.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2022-01-13 13:21:31 SUCCESS
CheckForClientCertificate
Found client certificate
2022-01-13 13:21:31 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3
MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx
MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm
cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp
dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ
k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG
VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b
nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4
C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF
SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0
PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB
AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce
RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF
BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w
ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v
Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu
Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P
AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw
ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl
cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl
cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg
dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg
U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0
dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0
aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG
CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh
c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn
LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO
hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+
Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1
zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO
VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af
1zroWKsv2A==
-----END CERTIFICATE-----
2022-01-13 13:21:31 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjRjZTlkYTgxMzFmMTRjZGI4NGNlNzkxNDMyZDYzZDdkIiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDgwMzg5LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjA4MDA4OSwibmJmIjoxNjQyMDgwMDg5fQ.IMdjWevTLHNcCFUlfWXOWo_rr183BndWDB5ZSOOuHR1LD3nn9yVUUkpaHoVR0zy9Ir2A-JSCOkZKtBZtKmjiwzZ5hRPgztn9j-rhIY7DhA57TAlBwq5-TEIkuaXHCaRFarhssDEi9bM-eeGQfq-vsMOO1UXZFNHSPFL7NsJXZ59go1GaSHuiGxD7uTXX_ZzBQLzkek0kBy6KJ5ZWW-sw1HWuF2TCJoK8Q5tsYJl-xScZ31UNxV3bIXXzepX3M8IqAtc1GaCyyGY9lfIpXqvIBHzscVWj6WEqW7zuTiHN7jgRlraC4Ub3OGbXrzt6HZ92swgV-pQ2t92lgAdy8GAbTQ",
  "header": {
    "x5t": "imeJtvhk1_UOZIIOKtvS3EW0nDo",
    "kid": "F_zU9LD1--CL5SvOm7aeqKpn9nte7OFLhq92U-V3f68",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "client_XUwBuUHRMTVHAleZEJxH18815",
    "aud": "https://www.certification.openid.net/test-mtls/a/SafraRPTest/token",
    "nbf": 1642080089,
    "iss": "client_XUwBuUHRMTVHAleZEJxH18815",
    "exp": 1642080389,
    "iat": 1642080089,
    "jti": "4ce9da8131f14cdb84ce791432d63d7d"
  }
}
2022-01-13 13:21:31
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2022-01-13 13:21:31 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsImtpZCI6IkZfelU5TEQxLS1DTDVTdk9tN2FlcUtwbjludGU3T0ZMaHE5MlUtVjNmNjgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJpbWVKdHZoazFfVU9aSUlPS3R2UzNFVzBuRG8ifQ.eyJzdWIiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImp0aSI6IjRjZTlkYTgxMzFmMTRjZGI4NGNlNzkxNDMyZDYzZDdkIiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QtbXRscy9hL1NhZnJhUlBUZXN0L3Rva2VuIiwiZXhwIjoxNjQyMDgwMzg5LCJpc3MiOiJjbGllbnRfWFV3QnVVSFJNVFZIQWxlWkVKeEgxODgxNSIsImlhdCI6MTY0MjA4MDA4OSwibmJmIjoxNjQyMDgwMDg5fQ.IMdjWevTLHNcCFUlfWXOWo_rr183BndWDB5ZSOOuHR1LD3nn9yVUUkpaHoVR0zy9Ir2A-JSCOkZKtBZtKmjiwzZ5hRPgztn9j-rhIY7DhA57TAlBwq5-TEIkuaXHCaRFarhssDEi9bM-eeGQfq-vsMOO1UXZFNHSPFL7NsJXZ59go1GaSHuiGxD7uTXX_ZzBQLzkek0kBy6KJ5ZWW-sw1HWuF2TCJoK8Q5tsYJl-xScZ31UNxV3bIXXzepX3M8IqAtc1GaCyyGY9lfIpXqvIBHzscVWj6WEqW7zuTiHN7jgRlraC4Ub3OGbXrzt6HZ92swgV-pQ2t92lgAdy8GAbTQ
2022-01-13 13:21:31 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2022-01-13 13:21:31 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2022-01-13 13:21:31 SUCCESS
ValidateAuthorizationCode
Found authorization code
authorization_code
xn3B3oRXSpxVBvTBHkSGArls9qBc6rWZ
2022-01-13 13:21:31 SUCCESS
ValidateRedirectUri
Found redirect uri
redirect_uri
https://portalspa-hml.safra.com.br/callback
2022-01-13 13:21:31 SUCCESS
ValidateCodeVerifierWithS256
Validated code_verifier successfully
code_challenge_method
S256
code_verifier
b4f33732a82c4e088a33b142d82e69b1b4f33732a82c4e088a33b142d82e69b10475ed497da448a0a7952d343fd585d70475ed497da448a0a7952d343fd585d7
code_challenge
Rd83bbO8LdNRSFVFM0p6U4q5VUWgfqpTEmLYAL2gbOQ
2022-01-13 13:21:31 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
1rBkjWlZacq1xQuBUIZuPrE66H5tEpvRnIKThKQ66chkE8As0y
2022-01-13 13:21:31 SUCCESS
CalculateAtHash
Successful at_hash encoding
at_hash
1gX2FlVh06NNj6yU94Ta0w
2022-01-13 13:21:31
CreateRefreshToken
Created refresh token
refresh_token
kDjIRczWofRCUSyszgcbbyuWaJPKeClHmchrciKsdAzzJAzSbA2937991750{'%^:
2022-01-13 13:21:31 SUCCESS
GenerateIdTokenClaims
Created ID Token Claims
iss
https://www.certification.openid.net/test/a/SafraRPTest/
sub
user-subject-1234531
aud
client_XUwBuUHRMTVHAleZEJxH18815
nonce
b4f33732a82c4e088a33b142d82e69b1
iat
1642080091
exp
1642080391
2022-01-13 13:21:31
FAPIBrazilAddCPFAndCPNJToIdTokenClaims
Request object does not contain a claims element.id_token
2022-01-13 13:21:31 SUCCESS
AddAtHashToIdTokenClaims
Added at_hash to ID token claims
at_hash
1gX2FlVh06NNj6yU94Ta0w
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/SafraRPTest/",
  "sub": "user-subject-1234531",
  "aud": "client_XUwBuUHRMTVHAleZEJxH18815",
  "nonce": "b4f33732a82c4e088a33b142d82e69b1",
  "iat": 1642080091,
  "exp": 1642080391,
  "at_hash": "1gX2FlVh06NNj6yU94Ta0w"
}
2022-01-13 13:21:31 INFO
FAPIBrazilAddACRClaimToIdTokenClaims
Skipped evaluation due to missing required string: requested_id_token_acr_values
expected
requested_id_token_acr_values
2022-01-13 13:21:31 SUCCESS
SignIdToken
Signed the ID token
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdF9oYXNoIjoiMWdYMkZsVmgwNk5OajZ5VTk0VGEwdyIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUiLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvU2FmcmFSUFRlc3RcLyIsImV4cCI6MTY0MjA4MDM5MSwibm9uY2UiOiJiNGYzMzczMmE4MmM0ZTA4OGEzM2IxNDJkODJlNjliMSIsImlhdCI6MTY0MjA4MDA5MX0.R7zMA6j5t5mtU-HSWtFuuq3NTxa3JSe_3DHR8iiV6SUOBMosxMn_4SWSmJBGYPwP3Jl-vG1YKv26vSyeHJ4Hv3hi9ZElwtqaoobzqbiRVBkK2c6hCUFaRmtmVgcVY1tyTbPrg4k6yUqihxLUnlcmXqUO5FV6QYdG_T21b3Y7CoqnghkRhVL_y0I-AR6daZ30b3mCUB3ugKwBk_zf9m8u62M0CyuKZhllVtvw6D_iN0_u0z6lt8kdJyurmSoG4GDLZ9UVdSFDVM7FGma0oJQmKupIq15s_Gpj8D-yuFzOxERbdg3is8Yug_n3D2GG9jkCnFvNEVCfeNgXeIukiSBvHQ
2022-01-13 13:21:31 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
1rBkjWlZacq1xQuBUIZuPrE66H5tEpvRnIKThKQ66chkE8As0y
token_type
Bearer
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdF9oYXNoIjoiMWdYMkZsVmgwNk5OajZ5VTk0VGEwdyIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUiLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvU2FmcmFSUFRlc3RcLyIsImV4cCI6MTY0MjA4MDM5MSwibm9uY2UiOiJiNGYzMzczMmE4MmM0ZTA4OGEzM2IxNDJkODJlNjliMSIsImlhdCI6MTY0MjA4MDA5MX0.R7zMA6j5t5mtU-HSWtFuuq3NTxa3JSe_3DHR8iiV6SUOBMosxMn_4SWSmJBGYPwP3Jl-vG1YKv26vSyeHJ4Hv3hi9ZElwtqaoobzqbiRVBkK2c6hCUFaRmtmVgcVY1tyTbPrg4k6yUqihxLUnlcmXqUO5FV6QYdG_T21b3Y7CoqnghkRhVL_y0I-AR6daZ30b3mCUB3ugKwBk_zf9m8u62M0CyuKZhllVtvw6D_iN0_u0z6lt8kdJyurmSoG4GDLZ9UVdSFDVM7FGma0oJQmKupIq15s_Gpj8D-yuFzOxERbdg3is8Yug_n3D2GG9jkCnFvNEVCfeNgXeIukiSBvHQ
refresh_token
kDjIRczWofRCUSyszgcbbyuWaJPKeClHmchrciKsdAzzJAzSbA2937991750{'%^:
2022-01-13 13:21:31 OUTGOING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Response to HTTP request to test instance 8Zu5JxPG9CfXNiv
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "1rBkjWlZacq1xQuBUIZuPrE66H5tEpvRnIKThKQ66chkE8As0y",
  "token_type": "Bearer",
  "id_token": "eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdF9oYXNoIjoiMWdYMkZsVmgwNk5OajZ5VTk0VGEwdyIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoiY2xpZW50X1hVd0J1VUhSTVRWSEFsZVpFSnhIMTg4MTUiLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvU2FmcmFSUFRlc3RcLyIsImV4cCI6MTY0MjA4MDM5MSwibm9uY2UiOiJiNGYzMzczMmE4MmM0ZTA4OGEzM2IxNDJkODJlNjliMSIsImlhdCI6MTY0MjA4MDA5MX0.R7zMA6j5t5mtU-HSWtFuuq3NTxa3JSe_3DHR8iiV6SUOBMosxMn_4SWSmJBGYPwP3Jl-vG1YKv26vSyeHJ4Hv3hi9ZElwtqaoobzqbiRVBkK2c6hCUFaRmtmVgcVY1tyTbPrg4k6yUqihxLUnlcmXqUO5FV6QYdG_T21b3Y7CoqnghkRhVL_y0I-AR6daZ30b3mCUB3ugKwBk_zf9m8u62M0CyuKZhllVtvw6D_iN0_u0z6lt8kdJyurmSoG4GDLZ9UVdSFDVM7FGma0oJQmKupIq15s_Gpj8D-yuFzOxERbdg3is8Yug_n3D2GG9jkCnFvNEVCfeNgXeIukiSBvHQ",
  "refresh_token": "kDjIRczWofRCUSyszgcbbyuWaJPKeClHmchrciKsdAzzJAzSbA2937991750{\u0027%^:"
}
outgoing_path
token
2022-01-13 13:21:31 INCOMING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Incoming HTTP request to test instance 8Zu5JxPG9CfXNiv
incoming_headers
{
  "host": "www.certification.openid.net",
  "authorization": "Bearer 1rBkjWlZacq1xQuBUIZuPrE66H5tEpvRnIKThKQ66chkE8As0y",
  "x-dynatrace": "FW4;-987853115;5;1343653795;343;2;-1738730375;691;5418;2h01;3h501687a3;4h0157;6ha02dad9a0281abdeb6f2fecafa3ce91a;7h3047cca96271952a",
  "traceparent": "00-a02dad9a0281abdeb6f2fecafa3ce91a-3047cca96271952a-01",
  "tracestate": "985d1479-c51e8ec5@dt\u003dfw4;5;501687a3;157;2;0;0;2b3;3d58;2h01;3h501687a3;4h0157;7h3047cca96271952a",
  "cookie": "JSESSIONID\u003d64EB3BCD100479FEB53C21C80DBAB127",
  "connection": "close"
}
incoming_path
/test-mtls/a/SafraRPTest/accounts/v1/accounts
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES256-GCM-SHA384
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A== -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
2022-01-13 13:21:31 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES256-GCM-SHA384
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Accounts endpoint
2022-01-13 13:21:31 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3 MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4 C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0 PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0 dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0 aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+ Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1 zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af 1zroWKsv2A\u003d\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3\nMDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx\nMzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm\ncmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp\ndmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ\nk/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi\nMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG\nVfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b\nnE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4\nC4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF\nSaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0\nPR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB\nAAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce\nRCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF\nBQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w\nZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v\nY3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu\nY3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P\nAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw\nggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl\ncnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl\ncyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg\ndXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg\nU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0\ndXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0\naWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG\nCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh\nc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn\nLPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO\nhUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+\nVibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1\nzHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO\nVZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af\n1zroWKsv2A\u003d\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003d44b261bc-4f6f-44ce-b3d7-3f98a2b225f4,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3538313630373839303030313238,CN\u003d*.safra.com.br,OU\u003d709138dd-6e9d-5f96-bfff-69a5b2cb3ec0,O\u003dBCO SAFRA S.A.,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "api-mtls-hml.safra.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2022-01-13 13:21:31 SUCCESS
CheckForClientCertificate
Found client certificate
2022-01-13 13:21:31 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG8zCCBdugAwIBAgIUOr2rNJSEw8bj9fVI9mZtaMk/VfowDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTEwMzE3MDUwMFoXDTIyMTIwMzE3
MDUwMFowggETMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFzAVBgNVBAoTDkJDTyBTQUZSQSBTLkEuMS0wKwYDVQQLEyQ3MDkx
MzhkZC02ZTlkLTVmOTYtYmZmZi02OWE1YjJjYjNlYzAxFzAVBgNVBAMMDiouc2Fm
cmEuY29tLmJyMRcwFQYDVQQFEw41ODE2MDc4OTAwMDEyODEdMBsGA1UEDxMUUHJp
dmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCQlIxNDAyBgoJkiaJ
k/IsZAEBEyQ0NGIyNjFiYy00ZjZmLTQ0Y2UtYjNkNy0zZjk4YTJiMjI1ZjQwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDYAJ7JptCPUm02Tx4o+zR20+iG
VfMCMTOafTQ29kgOYAk/ypeDCNeZt4kkil/ZzNjHwA6NZ3gWMV088C5ucJ4AmS8b
nE4XfbwoxealAWCa0pFoWEeBQK+Zb/S4dgK+L6xHkKViElSdQuYsKu3yraFs4Mu4
C4ukjhCxa3AlvcSw6PCMYJ5LKWbfVQovtoy5o+vOu1KKNKSTaYESmQDrIN4VeDyF
SaYttN0gd+HNicRnopbyfWcmndRwVdwyUgTT2Z59/CpcdKui8kiT2rKxRO/mF1q0
PR1lkPE9FBDSo83fArx3yXgUyMmodjqJ+5X+pm7xZRJ97RVwIoMh7PRf4LXHAgMB
AAGjggLdMIIC2TAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ60p75BB0ZNm+cJkce
RCif8/14izAfBgNVHSMEGDAWgBSGf1itF/WCtk60BbP7sM4RQ99MvjBMBggrBgEF
BQcBAQRAMD4wPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnNhbmRib3gucGtpLm9w
ZW5iYW5raW5nYnJhc2lsLm9yZy5icjBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8v
Y3JsLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9pc3N1ZXIu
Y3JsMCQGA1UdEQQdMBuCGWFwaS1tdGxzLWhtbC5zYWZyYS5jb20uYnIwDgYDVR0P
AQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMIIBoQYDVR0gBIIBmDCCAZQw
ggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENl
cnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNl
cyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMg
dXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsg
U2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0
dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0
aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQG
CCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJh
c2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAriUFRNI349wn
LPiNnHZckwjUV76m8LltS/BrHQSURP4Bq3Eu2KEZGD/Xkz9VcmumHwOC+Mr/haLO
hUMbwmZMn9q3QFzyd/EnoSyXeedZpPLczSPZ3AXoNaC8xJn4ZE66NKDQ2/PEFD7+
Vibcq6uWx4H6k8QjSBgrPAh03hHzdBpVBTO6fRNZPUtHJUcPvOJC0rtK1n3tCNk1
zHeO19CLNT1aUo99rXw8BT3bG4jVi/NMIPZqywxxk3S4Fq+6otMbtVRaB+O+NEqO
VZR8xmuX+ALi7oVaD0tif+PzhyVKLZiRvnMtY2Y51ujIxyGyRZYPmiJkYQ/PT2Af
1zroWKsv2A==
-----END CERTIFICATE-----
2022-01-13 13:21:31 SUCCESS
EnsureBearerAccessTokenNotInParams
Client correctly did not send access token in query parameters or form body
2022-01-13 13:21:31 SUCCESS
ExtractBearerAccessTokenFromHeader
Found access token on incoming request
access_token
1rBkjWlZacq1xQuBUIZuPrE66H5tEpvRnIKThKQ66chkE8As0y
2022-01-13 13:21:31 SUCCESS
RequireBearerAccessToken
Found access token in request
actual
1rBkjWlZacq1xQuBUIZuPrE66H5tEpvRnIKThKQ66chkE8As0y
2022-01-13 13:21:31 INFO
ExtractFapiDateHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-auth-date
path
headers.x-fapi-auth-date
mapped
object
incoming_request
2022-01-13 13:21:31 INFO
ExtractFapiIpAddressHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-customer-ip-address
path
headers.x-fapi-customer-ip-address
mapped
object
incoming_request
2022-01-13 13:21:31 INFO
ExtractFapiInteractionIdHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-interaction-id
path
headers.x-fapi-interaction-id
mapped
object
incoming_request
2022-01-13 13:21:31 SUCCESS
FAPIBrazilEnsureAuthorizationRequestScopesContainAccounts
'accounts' was included in authorization request scopes
actual
openid consents customers accounts credit-cards-accounts resources invoice-financings financings loans unarranged-accounts-overdraft consent:urn:conformance.oidf:bLRknramvy
expected
accounts
2022-01-13 13:21:31 INFO
CreateFapiInteractionIdIfNeeded
Found existing FAPI interaction ID
fapi_interaction_id
e9cfd530-8bea-4473-acb9-4d278ab2c11e
2022-01-13 13:21:31 SUCCESS
CreateFAPIAccountEndpointResponse
Created account response object
accounts_endpoint_response
{
  "conformance-test-finished": "true"
}
accounts_endpoint_response_headers
{
  "x-fapi-interaction-id": "e9cfd530-8bea-4473-acb9-4d278ab2c11e",
  "content-type": "application/json; charset\u003dUTF-8"
}
2022-01-13 13:21:31 SUCCESS
CreateBrazilAccountsEndpointResponse
Created Brazil accounts response (Please note that this is a hardcoded response copied from API documentation)
accounts_endpoint_response
{
  "data": [
    {
      "brandName": "Organização A",
      "companyCnpj": "21128159000166",
      "type": "CONTA_DEPOSITO_A_VISTA",
      "compeCode": "001",
      "branchCode": "6272",
      "number": "94088392",
      "checkDigit": "4",
      "accountId": "92792126019929279212650822221989319252576"
    }
  ],
  "links": {
    "self": "https://api.banco.com.br/open-banking/api/v1/resource",
    "first": "https://api.banco.com.br/open-banking/api/v1/resource",
    "prev": "https://api.banco.com.br/open-banking/api/v1/resource",
    "next": "https://api.banco.com.br/open-banking/api/v1/resource",
    "last": "https://api.banco.com.br/open-banking/api/v1/resource"
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2022-01-13T13:21:31Z"
  }
}
accounts_endpoint_response_headers
{
  "x-fapi-interaction-id": "e9cfd530-8bea-4473-acb9-4d278ab2c11e",
  "content-type": "application/json"
}
2022-01-13 13:21:31
ClearAccessTokenFromRequest
Condition ran but did not log anything
2022-01-13 13:21:31 OUTGOING
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Response to HTTP request to test instance 8Zu5JxPG9CfXNiv
outgoing_status_code
200
outgoing_headers
{
  "x-fapi-interaction-id": [
    "e9cfd530-8bea-4473-acb9-4d278ab2c11e"
  ],
  "content-type": [
    "application/json"
  ]
}
outgoing_body
{
  "data": [
    {
      "brandName": "Organização A",
      "companyCnpj": "21128159000166",
      "type": "CONTA_DEPOSITO_A_VISTA",
      "compeCode": "001",
      "branchCode": "6272",
      "number": "94088392",
      "checkDigit": "4",
      "accountId": "92792126019929279212650822221989319252576"
    }
  ],
  "links": {
    "self": "https://api.banco.com.br/open-banking/api/v1/resource",
    "first": "https://api.banco.com.br/open-banking/api/v1/resource",
    "prev": "https://api.banco.com.br/open-banking/api/v1/resource",
    "next": "https://api.banco.com.br/open-banking/api/v1/resource",
    "last": "https://api.banco.com.br/open-banking/api/v1/resource"
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2022-01-13T13:21:31Z"
  }
}
outgoing_path
accounts/v1/accounts
2022-01-13 13:21:31 FINISHED
fapi1-advanced-final-client-test-no-scope-in-token-endpoint-response
Test has run to completion
testmodule_result
PASSED
2022-01-13 13:22:19
TEST-RUNNER
Alias has now been claimed by another test
alias
SafraRPTest
new_test_id
h5xhhLyjnekWbMX
Test Results