Test Summary

Test Results

Expand All Collapse All
All times are UTC
2022-01-26 12:00:56 INFO
TEST-RUNNER
Test instance GPpmgFZuyrqCeSS created
baseUrl
https://www.certification.openid.net/test/a/upp
variant
{
  "client_auth_type": "private_key_jwt",
  "fapi_auth_request_method": "by_value",
  "fapi_profile": "openbanking_brazil",
  "fapi_jarm_type": "oidc",
  "fapi_response_mode": "jarm"
}
alias
upp
description
UP.P - Recepção de dados
planId
tud1Xx6YKZHwy
config
{
  "alias": "upp",
  "description": "UP.P - Recepção de dados",
  "server": {
    "jwks": {
      "keys": [
        {
          "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
          "kty": "RSA",
          "alg": "PS256",
          "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
          "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
          "e": "AQAB",
          "use": "sig",
          "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
          "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
          "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
          "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
          "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
          "x5c": [
            "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
          ]
        },
        {
          "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
          "kty": "RSA",
          "alg": "RSA-OAEP",
          "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
          "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
          "e": "AQAB",
          "use": "enc",
          "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
          "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
          "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
          "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
          "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
        }
      ]
    }
  },
  "client": {
    "client_id": "upp-bank",
    "redirect_uri": "https://www.upp.com.br/callback",
    "jwks": {
      "keys": [
        {
          "kty": "RSA",
          "use": "sig",
          "alg": "PS256",
          "n": "z53jstIY3rvuuVH9i-f3yBpaCU16Tf5gptz_iY2t4nCzsd3oGXgP9nKNGvT8SZuU45nDWsqBAe6wCwkDP6O0nl24cLMQYwowryhUSBh7kdw7icjWbF_TYdG13LbwblKVkpO7kcDx-Ujrq4bLBtx-z-99EQRa4eXq2OmTGtgW18MqQ2V3rLWC8SpxF3DfGVXoL8L4z4YvkpPT0Wevdelflte8-9tIy3tZun95vXX7ZTc5YeHIuzCB_VohPI4LVLmUcXymWUUDceOggLzvCi9PGK2SET-Bu0Nk2cw0BMnZEaWM6bZ5XVryaDvQtyK89d98RRUQimvCA2ZFtr7MlO7aaQ",
          "e": "AQAB",
          "kid": "6f5b95d8afdfc69fe37e7bb8cb70342f13ad44fef1bb8424b958d9abc069a80d"
        },
        {
          "kty": "RSA",
          "use": "enc",
          "alg": "RSA-OAEP",
          "n": "rpy9RGoXXnwg72mtJtC25i8XnPlxZiUVR9Ss2r4wSBfxDGH2S2fu5qnB8W-R7zpKQfCEyNfWmnZpYIcIsY3HdRd_5POhGwaTRwXHpHKtpjZw-s6oImS66ENfbmafa8zNTYw39mue5H7xQIv1eByZMfzjdY13rwk121w8WbAQIAnP7TqYfj9in8l8wnR3NyHDfYmylo9NZdcim8ShXTBszCmSXK_8pRvT1wRES1R914Nhn1nx-2kSI11j5qUM1zESiRsqLlTU0us-5iK9UMlEl7XaPQ5-hscqag9Jp5vME67komisSAVjYgEeONsE-tTz68Hel29LFMRwmLDWntd6WQ",
          "e": "AQAB",
          "kid": "24c73a6a0cfd3277da5e3e83a44d4b2be60adc19d62aae14725e621453cb39e3"
        }
      ]
    },
    "certificate": "-----BEGIN CERTIFICATE-----\nMIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw\nMjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx\nMDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv\nbS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg\nT3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB\nARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq\nhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku\nl2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97\nULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK\nj9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv\nC7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G\n+cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC\nzjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP\nY3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE\nQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu\na2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV\nBgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK\nBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw\nggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg\nZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg\ncGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj\nZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw\ndCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0\naGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy\nZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw\ncy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw\nDQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj\nytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow\no5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese\n7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq\neE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit\npaZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4\u003d\n-----END CERTIFICATE-----"
  },
  "client2": {
    "client_id": "upp-bank-two",
    "redirect_uri": "https://www.upp.com.br/callback",
    "id_token_encrypted_response_alg": "RSA-OAEP",
    "id_token_encrypted_response_enc": "A256GCM",
    "certificate": "-----BEGIN CERTIFICATE-----\nMIIG3zCCBcegAwIBAgIUdF9ouib6iQhFg/iGea4kaMVLN98wDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMzEwMFoXDTIyMTEyNTAw\nMzEwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx\nMDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv\nbS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg\nT3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB\nARMkYjlhZDE4ZmEtZDRjNy00YWUyLWFkYmEtZjAxNmEyYzcyOWI0MIIBIjANBgkq\nhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3hkfaGrPN4PJ+A9TjBTT/FjS2loGKhY4\nAo1T+YTUWZckSDQZf5IMxjIZ5ZD1RmFEUmVW6X2xaU4MHgWfiapSvBf+K/FEVkvR\n9b6cCcgvANUUyKsA6gyNNQK5nvbhRf9bpY0hCeT2MysL4iXoC8mGvw9ai5/beUCi\n42u3GkOg7wsW3KbAEBOxySHFArlKUFnl4484pR1ZfgYQTdcV8YKVzTu0pAc9dN+m\nCYciZL81P6C0WWjCUc6B3qo3ARGXD2EzcVvZ/mmENjCzJUhOC54gCU3JiOAwxnMb\ntAf5YLOfq1fi/pa2qqHkaoT3r4nWuvuhlJzqeZ0mL0TAhJKEy3QVgQIDAQABo4IC\nzjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUc0f+UElsE0tnYmcFhKb90BPD\nsGkwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE\nQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu\na2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV\nBgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK\nBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw\nggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg\nZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg\ncGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj\nZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw\ndCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0\naGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy\nZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw\ncy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw\nDQYJKoZIhvcNAQELBQADggEBAJzH8RqR80cRXeyfHiRKJC/5Fm+U6jT5tR2qRYh9\nb79bMtJaZg3DkT4s04Hq4OXtARLbCq6zKNR7EgR5BjqD6yrFgEvGe0R0AWDbjPju\noAduXV620rTnr6KmCcEwyR3d1ZQff7Q/RhV2NKsh1qcCQJzdMPhazKhKkjbglfuc\nQVwu0ZAAf8ci2rZ3YsY6M4NuMq77wIHSfrPlmVq5oto+9j5BfOce7qa+ypcLsMJS\nUqo2cFCN3SAbyisJ9r4W0dXm0EIsJ3nJbkDq6v29jm7L9Lt/E8PvnDb95ZCiNrKB\n0KmKWino3dfNqtjaCv/5K4GQe/3OOktsjyT6OAjxE/nGF+8\u003d\n-----END CERTIFICATE-----",
    "jwks": {
      "keys": [
        {
          "kty": "RSA",
          "use": "sig",
          "alg": "PS256",
          "n": "7pqFiGchP3a61yP2IayP6hywX0-FKDz-JPCLz5eItq49_0YaIeVbhdHJe9B9cjuoyQ8uB8vNd6wii6dc4TMVbOWAo0nrZymAP5Cfp6zGOk1uSVyEOuDBUDRFlJEEJtNREknIX9lTou4-EtHu1o8gFFAJvKa22tMtUrC8A_jQNcdc6id-NNgZ3gL3pkUAobwax3ImOvhjT7TfZDLySANgww2OdOzkiVTq_abymxmSjxRXpGxJv_5Yc9Kltaj6a9_yqsbq8RvJImYGHv24p08hnkq5KvOXaqiFzBxJBrYf4_LyCEShFF9wrCoClUkhSRhMoNbZfln_oLAnFZ9JxQr-pQ",
          "e": "AQAB",
          "kid": "3e274b78e9b7779a570067ec0318234f28d5d921512e9f9500714a5915aa286e"
        },
        {
          "kty": "RSA",
          "use": "enc",
          "alg": "RSA-OAEP",
          "n": "rJ82cyRXhegVp9JJn9KX41J-U6j1keOY94B4geY81D0A5gQTovHUdkkk9lX9iQ-4Y12uDOTEhOBkNJTQZp_YoT1P8GfTgCBNiAM1HWN8RYIu8rJBaqfwncbuk0K7U6wAuYLGswnMDt2LoRIE4agtSMBH_8SstCbRhjmz29Nm349LZCN_KWWyKpOrl60_pLUVcUyKtzIxUdbpSR_xYZtLoGLud0TBucMeVgJTBuj4ZNRf49NfXscfY_yI1VK273oyIeyAZYIINxVqCY20CbUGup5T7gTvyMosoe1vXgEkYEBpmfSbEZ5ksaCYQ_i_vn9lJsqW5onvErzQTe1RvF9tWQ",
          "e": "AQAB",
          "kid": "8d22d327b8d49291ad3556dca6f69f79775bced7b896a3075fb4be7a49ebd06f"
        }
      ]
    }
  },
  "directory": {
    "keystore": "https://keystore.sandbox.directory.openbankingbrasil.org.br/"
  }
}
testName
fapi1-advanced-final-client-refresh-token-test
2022-01-26 12:00:56 SUCCESS
FAPIBrazilGenerateServerConfiguration
Created server configuration
server
{
  "issuer": "https://www.certification.openid.net/test/a/upp/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/upp/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/upp/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/upp/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/upp/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/upp/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true
}
issuer
https://www.certification.openid.net/test/a/upp/
discoveryUrl
https://www.certification.openid.net/test/a/upp/.well-known/openid-configuration
2022-01-26 12:00:56 SUCCESS
LoadServerJWKs
Parsed public and private JWK sets
server_jwks
{
  "keys": [
    {
      "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
      "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
      "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
      "kty": "RSA",
      "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
      "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
      "alg": "PS256"
    },
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
server_encryption_keys
{
  "keys": [
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
server_public_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "alg": "PS256",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "alg": "RSA-OAEP",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
2022-01-26 12:00:56 SUCCESS
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2022-01-26 12:00:56
SetServerSigningAlgToPS256
Successfully set signing algorithm to PS256
2022-01-26 12:00:56
FAPIBrazilSetGrantTypesSupportedInServerConfiguration
Successfully set grant_types_supported
server
{
  "issuer": "https://www.certification.openid.net/test/a/upp/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/upp/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/upp/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/upp/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/upp/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/upp/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ]
}
2022-01-26 12:00:56
AddClaimsParameterSupportedTrueToServerConfiguration
Successfully added claims_parameter_supported to server configuration
server
{
  "issuer": "https://www.certification.openid.net/test/a/upp/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/upp/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/upp/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/upp/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/upp/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/upp/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true
}
2022-01-26 12:00:56
FAPIBrazilAddBrazilSpecificSettingsToServerConfiguration
Added open banking Brazil specific server settings
server
{
  "issuer": "https://www.certification.openid.net/test/a/upp/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/upp/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/upp/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/upp/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/upp/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/upp/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ]
}
2022-01-26 12:00:56
SetTokenEndpointAuthMethodsSupportedToPrivateKeyJWTOnly
Changed token_endpoint_auth_methods_supported to private_key_jwt only in server configuration
server_configuration
{
  "issuer": "https://www.certification.openid.net/test/a/upp/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/upp/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/upp/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/upp/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/upp/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/upp/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ]
}
2022-01-26 12:00:56 SUCCESS
AddResponseTypeCodeToServerConfiguration
Added code as response type supported
response_types_supported
[
  "code"
]
2022-01-26 12:00:56 SUCCESS
AddJARMResponseModeToServerConfiguration
Added jwt as response_modes_supported
response_modes_supported
[
  "jwt"
]
2022-01-26 12:00:56 SUCCESS
AddAuthorizationSigningAlgValuesSupportedToServerConfiguration
Added authorization_signing_alg_values_supported to server configuration
alg_values
[
  "PS256"
]
2022-01-26 12:00:56 SUCCESS
FAPIBrazilAddTokenEndpointAuthSigningAlgValuesSupportedToServer
Set token_endpoint_auth_signing_alg_values_supported
values
[
  "PS256"
]
2022-01-26 12:00:56 SUCCESS
CheckServerConfiguration
Found required server configuration keys
required
[
  "authorization_endpoint",
  "token_endpoint",
  "issuer"
]
2022-01-26 12:00:56 SUCCESS
FAPIEnsureMinimumServerKeyLength
Validated minimum key lengths for server_jwks
server_jwks
{
  "keys": [
    {
      "d": "ZvivfZxJMbbdTQmxyE0lmE6ZuH8cMQOLyZxdaA5pNwm7ZEnPBEftZs8aR9ijhCDWMieui3h--rXwlXqbEm3g1sVgQ-WKTFV-NLKaJC1h-EU5HKdlOflstr7x57zhKp60ZIK69GyEXyJccUfzcD32u8raec9NplQ2MqS5MA1lnQFlocFoX1RNU4tSpEdJQq2UzqtX5WPhc88A6fTc1xu2fA5wyxzZu7fUjIETzLimcu-dDaEvvgm7c_A1ulm8EQuCN10k3FrIIe9RfuXHyxh9Rcd0aiIP9qwitxd5Cl0io7zby8MBIAaSei2co7y4tciBt4AfnzpBlGbtjgfr2gxD0Q",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "dp": "bQ9aXj8tHnj0qO8aAWapGokWX78OlvNzytYg4JSGyJ7pUQnRB4Ds2Lai6kgjniUiu5MX2kdceDbHykG5R-WDj0Ztv6UPV3jA3cOjDwVzwmiwBVmVQNRxzK31Ra8f4YJs9_o0bjmVvXQRchY9l9_Xkk_Hev2F2A540Fhk0tlbUBE",
      "dq": "XPYDZ_kxwZjtQb-XUBLBcvNV1jcDhba2stysXGv0SfvsxOg6G3qZ5xtsiyQxzAYen0LRttCBXkZXEtXXAodLRvJMwUXuYWtNCrBqxYDHkJogUDPnBXq-Hig6x8fsDJunH8JooCc-3WcFpHQcIZZdcwyXPVi59eAfWCwJlgHYYHk",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w",
      "p": "_QaFFuyZriEWtbiKexy7pIYicgU0ePMepvyNuiiFqlsUFQ24q9gp_iWECDhi8qqss__i1LW_eHQATKWfqUc6HdDY-ickJXvVktrQiT-buvJ24iTtK_NooPMKQW976NIX39_sEPJ6ceo9ZDFxTTCkmJus3eXDJmRZT2YzSZJcvcc",
      "kty": "RSA",
      "q": "3x1_dyovnWXSr7y7ufe6AHUV0kHBYVrGW2vdNZxKrrgBW5r2mm93NnHsrG-mJlzW7kG_jR41bWf74sucGdwXTx96riRVy8bov9SzPCDl9_QCHzPpqZOxjngfzQYq1L1qJA2BAie0Sq6YZhgLJ1fWPLutEO5soIYAkLXSJ9IVb00",
      "qi": "eHhOb5NUDfMGXwNscjEcMrMFS425qsoJAXfGJ10hm8svZOkNYgVpb7Hs7oT8XytanRl0Gk8gKH0yhvya65B5ipyby17uBMkikNN-EeYoY2AkvEfM_nO0dvHbDdF11rkM5Q_SEDlGmojxnx4_Euj8WeuSgcwiCQkR23aZlQGx1Mg",
      "alg": "PS256"
    },
    {
      "p": "6-RGunw1LGXpsGIabzcG8n_ITbahS9waTzjcwLkzjWjyR5hxnTSrCMas9EsOuIt3qvkdf02psgwi-J0ZX680ujaXdeiPAeuOUbsLPBOhRuu-ySXxMTT7uiwWJmF5LtBx8Qd3hRV2sd9zOhYzSohcmWp8w_uKTOYrFzGtWMvlGic",
      "kty": "RSA",
      "q": "vn3cUU9RFc7pB3fjiEPGwYGA_h8f2X6dOqy-JYIMIiuYhPq6cT8xIlE-sHs58kZzC1QbOBc4y-qRyqj1L4StPaYH4mtJU0s_6A_b9Cai96yzYYmMr92be2nCFMxBpmpBhN21AIdGc640OxgWMdz5OVo455v1uIEQGPr2aDpOzVs",
      "d": "QrIJ9tPG7pSrt1KKSU-9EbAq-hU92FzEV9GwzuG_dbBPyRLYNVfAz-Yb8ug3YLuqec_kcB5JCep7QkYHgpNdX5WXFxARCpXa-J7Xq50oBdiAS2ehLpnYHXpJI7HqOcH9ASZML_MXjI8e_EpsI7Yk6xJ9qxk8bXGupw0C6anwL3NBe232zA7I1FnwL9tpZVOLPupeok7HMRbFc6QSR3dA54zJmkyEbyOSqzRqCK_g7AB_RcMImN0SoCg0epxZjrculIXPG0Gl1T3TG3WY-CBUtAkI1chFMGCgYF_v-FMSun8N6igilPC5O683BMcJoTK745khMCv7FcSCSFVh0H5vKQ",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "qi": "W6TMI3L-Ob-Jx61TdYqN5gBoBsWF6KWuCmiE9ZiwJiMVCv5ddEbFafBuiIQgRnby1VpnH9j5KVb5PT_V78ohKFmpfL7ErXQerf_pJkEtvgK9lQta1EM1HMoShrJ4GdHPym_BZzDDmt6njvwTfSg95y28h-j5epuywcwu6TwAUA8",
      "dp": "a9rjD-8srNEoKVKhvYoObiBI6GeBllrb2K8qGCBV1ulOJbgo8nUbYpbci5Ip9-0k2RKwDv3mghcUglHqQRqt5BqD5BBiGsGmP-5is6RSEEhH4lar0hDkq_nuYrwcmXALOOZuGnZ239tIJx3xc7mnhSnwQ_emA4UV3LQFC12mse8",
      "alg": "RSA-OAEP",
      "dq": "Qk8TiyY-BoZg7Z2ZEYzuOdu3qD3zW0VMu-j3w5yyVo6wZ9HTZqplkxmO5eXvNNu7Hj1nwC2tMqZzm4UW3DSmDWinI_TOsHToSQKEQUfVwLtYMeKsm2dbwSj-SzkSvTgNmI-IeyebqZcBTXTD_RV7l7BFULIkZdZfYSKy9XMejTM",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
2022-01-26 12:00:56 SUCCESS
LoadUserInfo
Added user information
user_info
{
  "sub": "user-subject-1234531",
  "name": "Demo T. User",
  "email": "user@example.com",
  "email_verified": false
}
Verify configuration of first client
2022-01-26 12:00:56 SUCCESS
GetStaticClientConfiguration
Found a static client object
client_id
upp-bank
redirect_uri
https://www.upp.com.br/callback
jwks
{
  "keys": [
    {
      "kty": "RSA",
      "use": "sig",
      "alg": "PS256",
      "n": "z53jstIY3rvuuVH9i-f3yBpaCU16Tf5gptz_iY2t4nCzsd3oGXgP9nKNGvT8SZuU45nDWsqBAe6wCwkDP6O0nl24cLMQYwowryhUSBh7kdw7icjWbF_TYdG13LbwblKVkpO7kcDx-Ujrq4bLBtx-z-99EQRa4eXq2OmTGtgW18MqQ2V3rLWC8SpxF3DfGVXoL8L4z4YvkpPT0Wevdelflte8-9tIy3tZun95vXX7ZTc5YeHIuzCB_VohPI4LVLmUcXymWUUDceOggLzvCi9PGK2SET-Bu0Nk2cw0BMnZEaWM6bZ5XVryaDvQtyK89d98RRUQimvCA2ZFtr7MlO7aaQ",
      "e": "AQAB",
      "kid": "6f5b95d8afdfc69fe37e7bb8cb70342f13ad44fef1bb8424b958d9abc069a80d"
    },
    {
      "kty": "RSA",
      "use": "enc",
      "alg": "RSA-OAEP",
      "n": "rpy9RGoXXnwg72mtJtC25i8XnPlxZiUVR9Ss2r4wSBfxDGH2S2fu5qnB8W-R7zpKQfCEyNfWmnZpYIcIsY3HdRd_5POhGwaTRwXHpHKtpjZw-s6oImS66ENfbmafa8zNTYw39mue5H7xQIv1eByZMfzjdY13rwk121w8WbAQIAnP7TqYfj9in8l8wnR3NyHDfYmylo9NZdcim8ShXTBszCmSXK_8pRvT1wRES1R914Nhn1nx-2kSI11j5qUM1zESiRsqLlTU0us-5iK9UMlEl7XaPQ5-hscqag9Jp5vME67komisSAVjYgEeONsE-tTz68Hel29LFMRwmLDWntd6WQ",
      "e": "AQAB",
      "kid": "24c73a6a0cfd3277da5e3e83a44d4b2be60adc19d62aae14725e621453cb39e3"
    }
  ]
}
certificate
-----BEGIN CERTIFICATE-----
MIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw
MjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx
MDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv
bS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg
T3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB
ARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq
hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku
l2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97
ULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK
j9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv
C7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G
+cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC
zjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP
Y3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE
QDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu
a2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV
BgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK
BggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw
ggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg
Zm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg
cGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj
ZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw
dCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0
aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy
ZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw
cy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw
DQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj
ytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow
o5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese
7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq
eE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit
paZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4=
-----END CERTIFICATE-----
2022-01-26 12:00:56 SUCCESS
ValidateClientJWKsPublicPart
Valid client JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2022-01-26 12:00:56 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "use": "sig",
      "alg": "PS256",
      "n": "z53jstIY3rvuuVH9i-f3yBpaCU16Tf5gptz_iY2t4nCzsd3oGXgP9nKNGvT8SZuU45nDWsqBAe6wCwkDP6O0nl24cLMQYwowryhUSBh7kdw7icjWbF_TYdG13LbwblKVkpO7kcDx-Ujrq4bLBtx-z-99EQRa4eXq2OmTGtgW18MqQ2V3rLWC8SpxF3DfGVXoL8L4z4YvkpPT0Wevdelflte8-9tIy3tZun95vXX7ZTc5YeHIuzCB_VohPI4LVLmUcXymWUUDceOggLzvCi9PGK2SET-Bu0Nk2cw0BMnZEaWM6bZ5XVryaDvQtyK89d98RRUQimvCA2ZFtr7MlO7aaQ",
      "e": "AQAB",
      "kid": "6f5b95d8afdfc69fe37e7bb8cb70342f13ad44fef1bb8424b958d9abc069a80d"
    },
    {
      "kty": "RSA",
      "use": "enc",
      "alg": "RSA-OAEP",
      "n": "rpy9RGoXXnwg72mtJtC25i8XnPlxZiUVR9Ss2r4wSBfxDGH2S2fu5qnB8W-R7zpKQfCEyNfWmnZpYIcIsY3HdRd_5POhGwaTRwXHpHKtpjZw-s6oImS66ENfbmafa8zNTYw39mue5H7xQIv1eByZMfzjdY13rwk121w8WbAQIAnP7TqYfj9in8l8wnR3NyHDfYmylo9NZdcim8ShXTBszCmSXK_8pRvT1wRES1R914Nhn1nx-2kSI11j5qUM1zESiRsqLlTU0us-5iK9UMlEl7XaPQ5-hscqag9Jp5vME67komisSAVjYgEeONsE-tTz68Hel29LFMRwmLDWntd6WQ",
      "e": "AQAB",
      "kid": "24c73a6a0cfd3277da5e3e83a44d4b2be60adc19d62aae14725e621453cb39e3"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "6f5b95d8afdfc69fe37e7bb8cb70342f13ad44fef1bb8424b958d9abc069a80d",
      "alg": "PS256",
      "n": "z53jstIY3rvuuVH9i-f3yBpaCU16Tf5gptz_iY2t4nCzsd3oGXgP9nKNGvT8SZuU45nDWsqBAe6wCwkDP6O0nl24cLMQYwowryhUSBh7kdw7icjWbF_TYdG13LbwblKVkpO7kcDx-Ujrq4bLBtx-z-99EQRa4eXq2OmTGtgW18MqQ2V3rLWC8SpxF3DfGVXoL8L4z4YvkpPT0Wevdelflte8-9tIy3tZun95vXX7ZTc5YeHIuzCB_VohPI4LVLmUcXymWUUDceOggLzvCi9PGK2SET-Bu0Nk2cw0BMnZEaWM6bZ5XVryaDvQtyK89d98RRUQimvCA2ZFtr7MlO7aaQ"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "24c73a6a0cfd3277da5e3e83a44d4b2be60adc19d62aae14725e621453cb39e3",
      "alg": "RSA-OAEP",
      "n": "rpy9RGoXXnwg72mtJtC25i8XnPlxZiUVR9Ss2r4wSBfxDGH2S2fu5qnB8W-R7zpKQfCEyNfWmnZpYIcIsY3HdRd_5POhGwaTRwXHpHKtpjZw-s6oImS66ENfbmafa8zNTYw39mue5H7xQIv1eByZMfzjdY13rwk121w8WbAQIAnP7TqYfj9in8l8wnR3NyHDfYmylo9NZdcim8ShXTBszCmSXK_8pRvT1wRES1R914Nhn1nx-2kSI11j5qUM1zESiRsqLlTU0us-5iK9UMlEl7XaPQ5-hscqag9Jp5vME67komisSAVjYgEeONsE-tTz68Hel29LFMRwmLDWntd6WQ"
    }
  ]
}
2022-01-26 12:00:56 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2022-01-26 12:00:56 SUCCESS
EnsureClientJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2022-01-26 12:00:56 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "use": "sig",
      "alg": "PS256",
      "n": "z53jstIY3rvuuVH9i-f3yBpaCU16Tf5gptz_iY2t4nCzsd3oGXgP9nKNGvT8SZuU45nDWsqBAe6wCwkDP6O0nl24cLMQYwowryhUSBh7kdw7icjWbF_TYdG13LbwblKVkpO7kcDx-Ujrq4bLBtx-z-99EQRa4eXq2OmTGtgW18MqQ2V3rLWC8SpxF3DfGVXoL8L4z4YvkpPT0Wevdelflte8-9tIy3tZun95vXX7ZTc5YeHIuzCB_VohPI4LVLmUcXymWUUDceOggLzvCi9PGK2SET-Bu0Nk2cw0BMnZEaWM6bZ5XVryaDvQtyK89d98RRUQimvCA2ZFtr7MlO7aaQ",
      "e": "AQAB",
      "kid": "6f5b95d8afdfc69fe37e7bb8cb70342f13ad44fef1bb8424b958d9abc069a80d"
    },
    {
      "kty": "RSA",
      "use": "enc",
      "alg": "RSA-OAEP",
      "n": "rpy9RGoXXnwg72mtJtC25i8XnPlxZiUVR9Ss2r4wSBfxDGH2S2fu5qnB8W-R7zpKQfCEyNfWmnZpYIcIsY3HdRd_5POhGwaTRwXHpHKtpjZw-s6oImS66ENfbmafa8zNTYw39mue5H7xQIv1eByZMfzjdY13rwk121w8WbAQIAnP7TqYfj9in8l8wnR3NyHDfYmylo9NZdcim8ShXTBszCmSXK_8pRvT1wRES1R914Nhn1nx-2kSI11j5qUM1zESiRsqLlTU0us-5iK9UMlEl7XaPQ5-hscqag9Jp5vME67komisSAVjYgEeONsE-tTz68Hel29LFMRwmLDWntd6WQ",
      "e": "AQAB",
      "kid": "24c73a6a0cfd3277da5e3e83a44d4b2be60adc19d62aae14725e621453cb39e3"
    }
  ]
}
Verify configuration of second client
2022-01-26 12:00:56 SUCCESS
GetStaticClient2Configuration
Found a static second client object
client_id
upp-bank-two
redirect_uri
https://www.upp.com.br/callback
id_token_encrypted_response_alg
RSA-OAEP
id_token_encrypted_response_enc
A256GCM
certificate
-----BEGIN CERTIFICATE-----
MIIG3zCCBcegAwIBAgIUdF9ouib6iQhFg/iGea4kaMVLN98wDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMzEwMFoXDTIyMTEyNTAw
MzEwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx
MDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv
bS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg
T3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB
ARMkYjlhZDE4ZmEtZDRjNy00YWUyLWFkYmEtZjAxNmEyYzcyOWI0MIIBIjANBgkq
hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3hkfaGrPN4PJ+A9TjBTT/FjS2loGKhY4
Ao1T+YTUWZckSDQZf5IMxjIZ5ZD1RmFEUmVW6X2xaU4MHgWfiapSvBf+K/FEVkvR
9b6cCcgvANUUyKsA6gyNNQK5nvbhRf9bpY0hCeT2MysL4iXoC8mGvw9ai5/beUCi
42u3GkOg7wsW3KbAEBOxySHFArlKUFnl4484pR1ZfgYQTdcV8YKVzTu0pAc9dN+m
CYciZL81P6C0WWjCUc6B3qo3ARGXD2EzcVvZ/mmENjCzJUhOC54gCU3JiOAwxnMb
tAf5YLOfq1fi/pa2qqHkaoT3r4nWuvuhlJzqeZ0mL0TAhJKEy3QVgQIDAQABo4IC
zjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUc0f+UElsE0tnYmcFhKb90BPD
sGkwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE
QDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu
a2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV
BgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK
BggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw
ggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg
Zm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg
cGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj
ZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw
dCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0
aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy
ZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw
cy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw
DQYJKoZIhvcNAQELBQADggEBAJzH8RqR80cRXeyfHiRKJC/5Fm+U6jT5tR2qRYh9
b79bMtJaZg3DkT4s04Hq4OXtARLbCq6zKNR7EgR5BjqD6yrFgEvGe0R0AWDbjPju
oAduXV620rTnr6KmCcEwyR3d1ZQff7Q/RhV2NKsh1qcCQJzdMPhazKhKkjbglfuc
QVwu0ZAAf8ci2rZ3YsY6M4NuMq77wIHSfrPlmVq5oto+9j5BfOce7qa+ypcLsMJS
Uqo2cFCN3SAbyisJ9r4W0dXm0EIsJ3nJbkDq6v29jm7L9Lt/E8PvnDb95ZCiNrKB
0KmKWino3dfNqtjaCv/5K4GQe/3OOktsjyT6OAjxE/nGF+8=
-----END CERTIFICATE-----
jwks
{
  "keys": [
    {
      "kty": "RSA",
      "use": "sig",
      "alg": "PS256",
      "n": "7pqFiGchP3a61yP2IayP6hywX0-FKDz-JPCLz5eItq49_0YaIeVbhdHJe9B9cjuoyQ8uB8vNd6wii6dc4TMVbOWAo0nrZymAP5Cfp6zGOk1uSVyEOuDBUDRFlJEEJtNREknIX9lTou4-EtHu1o8gFFAJvKa22tMtUrC8A_jQNcdc6id-NNgZ3gL3pkUAobwax3ImOvhjT7TfZDLySANgww2OdOzkiVTq_abymxmSjxRXpGxJv_5Yc9Kltaj6a9_yqsbq8RvJImYGHv24p08hnkq5KvOXaqiFzBxJBrYf4_LyCEShFF9wrCoClUkhSRhMoNbZfln_oLAnFZ9JxQr-pQ",
      "e": "AQAB",
      "kid": "3e274b78e9b7779a570067ec0318234f28d5d921512e9f9500714a5915aa286e"
    },
    {
      "kty": "RSA",
      "use": "enc",
      "alg": "RSA-OAEP",
      "n": "rJ82cyRXhegVp9JJn9KX41J-U6j1keOY94B4geY81D0A5gQTovHUdkkk9lX9iQ-4Y12uDOTEhOBkNJTQZp_YoT1P8GfTgCBNiAM1HWN8RYIu8rJBaqfwncbuk0K7U6wAuYLGswnMDt2LoRIE4agtSMBH_8SstCbRhjmz29Nm349LZCN_KWWyKpOrl60_pLUVcUyKtzIxUdbpSR_xYZtLoGLud0TBucMeVgJTBuj4ZNRf49NfXscfY_yI1VK273oyIeyAZYIINxVqCY20CbUGup5T7gTvyMosoe1vXgEkYEBpmfSbEZ5ksaCYQ_i_vn9lJsqW5onvErzQTe1RvF9tWQ",
      "e": "AQAB",
      "kid": "8d22d327b8d49291ad3556dca6f69f79775bced7b896a3075fb4be7a49ebd06f"
    }
  ]
}
2022-01-26 12:00:56 SUCCESS
ValidateClientJWKsPublicPart
Valid client JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2022-01-26 12:00:56 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "use": "sig",
      "alg": "PS256",
      "n": "7pqFiGchP3a61yP2IayP6hywX0-FKDz-JPCLz5eItq49_0YaIeVbhdHJe9B9cjuoyQ8uB8vNd6wii6dc4TMVbOWAo0nrZymAP5Cfp6zGOk1uSVyEOuDBUDRFlJEEJtNREknIX9lTou4-EtHu1o8gFFAJvKa22tMtUrC8A_jQNcdc6id-NNgZ3gL3pkUAobwax3ImOvhjT7TfZDLySANgww2OdOzkiVTq_abymxmSjxRXpGxJv_5Yc9Kltaj6a9_yqsbq8RvJImYGHv24p08hnkq5KvOXaqiFzBxJBrYf4_LyCEShFF9wrCoClUkhSRhMoNbZfln_oLAnFZ9JxQr-pQ",
      "e": "AQAB",
      "kid": "3e274b78e9b7779a570067ec0318234f28d5d921512e9f9500714a5915aa286e"
    },
    {
      "kty": "RSA",
      "use": "enc",
      "alg": "RSA-OAEP",
      "n": "rJ82cyRXhegVp9JJn9KX41J-U6j1keOY94B4geY81D0A5gQTovHUdkkk9lX9iQ-4Y12uDOTEhOBkNJTQZp_YoT1P8GfTgCBNiAM1HWN8RYIu8rJBaqfwncbuk0K7U6wAuYLGswnMDt2LoRIE4agtSMBH_8SstCbRhjmz29Nm349LZCN_KWWyKpOrl60_pLUVcUyKtzIxUdbpSR_xYZtLoGLud0TBucMeVgJTBuj4ZNRf49NfXscfY_yI1VK273oyIeyAZYIINxVqCY20CbUGup5T7gTvyMosoe1vXgEkYEBpmfSbEZ5ksaCYQ_i_vn9lJsqW5onvErzQTe1RvF9tWQ",
      "e": "AQAB",
      "kid": "8d22d327b8d49291ad3556dca6f69f79775bced7b896a3075fb4be7a49ebd06f"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "3e274b78e9b7779a570067ec0318234f28d5d921512e9f9500714a5915aa286e",
      "alg": "PS256",
      "n": "7pqFiGchP3a61yP2IayP6hywX0-FKDz-JPCLz5eItq49_0YaIeVbhdHJe9B9cjuoyQ8uB8vNd6wii6dc4TMVbOWAo0nrZymAP5Cfp6zGOk1uSVyEOuDBUDRFlJEEJtNREknIX9lTou4-EtHu1o8gFFAJvKa22tMtUrC8A_jQNcdc6id-NNgZ3gL3pkUAobwax3ImOvhjT7TfZDLySANgww2OdOzkiVTq_abymxmSjxRXpGxJv_5Yc9Kltaj6a9_yqsbq8RvJImYGHv24p08hnkq5KvOXaqiFzBxJBrYf4_LyCEShFF9wrCoClUkhSRhMoNbZfln_oLAnFZ9JxQr-pQ"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "8d22d327b8d49291ad3556dca6f69f79775bced7b896a3075fb4be7a49ebd06f",
      "alg": "RSA-OAEP",
      "n": "rJ82cyRXhegVp9JJn9KX41J-U6j1keOY94B4geY81D0A5gQTovHUdkkk9lX9iQ-4Y12uDOTEhOBkNJTQZp_YoT1P8GfTgCBNiAM1HWN8RYIu8rJBaqfwncbuk0K7U6wAuYLGswnMDt2LoRIE4agtSMBH_8SstCbRhjmz29Nm349LZCN_KWWyKpOrl60_pLUVcUyKtzIxUdbpSR_xYZtLoGLud0TBucMeVgJTBuj4ZNRf49NfXscfY_yI1VK273oyIeyAZYIINxVqCY20CbUGup5T7gTvyMosoe1vXgEkYEBpmfSbEZ5ksaCYQ_i_vn9lJsqW5onvErzQTe1RvF9tWQ"
    }
  ]
}
2022-01-26 12:00:56 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2022-01-26 12:00:56 SUCCESS
EnsureClientJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2022-01-26 12:00:56 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "use": "sig",
      "alg": "PS256",
      "n": "7pqFiGchP3a61yP2IayP6hywX0-FKDz-JPCLz5eItq49_0YaIeVbhdHJe9B9cjuoyQ8uB8vNd6wii6dc4TMVbOWAo0nrZymAP5Cfp6zGOk1uSVyEOuDBUDRFlJEEJtNREknIX9lTou4-EtHu1o8gFFAJvKa22tMtUrC8A_jQNcdc6id-NNgZ3gL3pkUAobwax3ImOvhjT7TfZDLySANgww2OdOzkiVTq_abymxmSjxRXpGxJv_5Yc9Kltaj6a9_yqsbq8RvJImYGHv24p08hnkq5KvOXaqiFzBxJBrYf4_LyCEShFF9wrCoClUkhSRhMoNbZfln_oLAnFZ9JxQr-pQ",
      "e": "AQAB",
      "kid": "3e274b78e9b7779a570067ec0318234f28d5d921512e9f9500714a5915aa286e"
    },
    {
      "kty": "RSA",
      "use": "enc",
      "alg": "RSA-OAEP",
      "n": "rJ82cyRXhegVp9JJn9KX41J-U6j1keOY94B4geY81D0A5gQTovHUdkkk9lX9iQ-4Y12uDOTEhOBkNJTQZp_YoT1P8GfTgCBNiAM1HWN8RYIu8rJBaqfwncbuk0K7U6wAuYLGswnMDt2LoRIE4agtSMBH_8SstCbRhjmz29Nm349LZCN_KWWyKpOrl60_pLUVcUyKtzIxUdbpSR_xYZtLoGLud0TBucMeVgJTBuj4ZNRf49NfXscfY_yI1VK273oyIeyAZYIINxVqCY20CbUGup5T7gTvyMosoe1vXgEkYEBpmfSbEZ5ksaCYQ_i_vn9lJsqW5onvErzQTe1RvF9tWQ",
      "e": "AQAB",
      "kid": "8d22d327b8d49291ad3556dca6f69f79775bced7b896a3075fb4be7a49ebd06f"
    }
  ]
}
2022-01-26 12:00:56
fapi1-advanced-final-client-refresh-token-test
Setup Done
2022-01-26 12:00:58 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance GPpmgFZuyrqCeSS
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.7.4 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/upp/.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2022-01-26 12:00:58 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2022-01-26 12:00:58 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance GPpmgFZuyrqCeSS
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/upp/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/upp/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/upp/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/upp/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/upp/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/upp/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ],
  "response_types_supported": [
    "code"
  ],
  "response_modes_supported": [
    "jwt"
  ],
  "authorization_signing_alg_values_supported": [
    "PS256"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256"
  ]
}
outgoing_path
.well-known/openid-configuration
2022-01-26 12:00:58 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance GPpmgFZuyrqCeSS
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.7.4 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded",
  "accept-encoding": "gzip, deflate, br",
  "content-length": "1042",
  "connection": "close"
}
incoming_path
/test-mtls/a/upp/token
incoming_body_form_params
{
  "grant_type": "client_credentials",
  "scope": "consents",
  "client_id": "upp-bank",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjZmNWI5NWQ4YWZkZmM2OWZlMzdlN2JiOGNiNzAzNDJmMTNhZDQ0ZmVmMWJiODQyNGI5NThkOWFiYzA2OWE4MGQifQ.eyJpYXQiOjE2NDMxOTg0NTgsImV4cCI6MTY0MzE5ODUxOCwianRpIjoiOUNvOUM5VlZXRURPY1gxMVA1TS1Wdm45djBPVlR5SGdSUFdFWEpRUW9iRSIsImlzcyI6InVwcC1iYW5rIiwic3ViIjoidXBwLWJhbmsiLCJhdWQiOlsiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvdXBwL3Rva2VuIl19.ngJsjrAuJWJigYo9SMTR533lUDqqNDjSmcKDC1ySZK5iBiMA0OOZpQ-bH6GSMXk9wIQA4q-PRTQmBICOW7tyg1CsfqmX3_0T_0MMEUc2lUrHyIjixEqsm_PtXWOErHgp55bWfLkXY6H90cBw3i-eaoqtuTzj__VI0oDFrRPFEv8_GMlA9QhMzxuklFuDSOtD68tFMf7DXCvsnnDgbcE_eU-NbeuD_f2hw052rGCwn5_aeuBnnMZdGahlVx99IzDk8DZZqhgJLZvOm9VgDlenTPVOUr5QEz04s2jrjK9NZsAWiHf5j4wGjRtTHS-Wa7jbTSHUgbA151_rnaTUuuNWcg",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw MjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx MDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv bS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg T3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB ARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku l2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97 ULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK j9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv C7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G +cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC zjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP Y3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE QDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu a2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV BgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK BggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw ggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg Zm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg cGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw dCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0 aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy ZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw cy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw DQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj ytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow o5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese 7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq eE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit paZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
grant_type=client_credentials&scope=consents&client_id=upp-bank&client_assertion=eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjZmNWI5NWQ4YWZkZmM2OWZlMzdlN2JiOGNiNzAzNDJmMTNhZDQ0ZmVmMWJiODQyNGI5NThkOWFiYzA2OWE4MGQifQ.eyJpYXQiOjE2NDMxOTg0NTgsImV4cCI6MTY0MzE5ODUxOCwianRpIjoiOUNvOUM5VlZXRURPY1gxMVA1TS1Wdm45djBPVlR5SGdSUFdFWEpRUW9iRSIsImlzcyI6InVwcC1iYW5rIiwic3ViIjoidXBwLWJhbmsiLCJhdWQiOlsiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvdXBwL3Rva2VuIl19.ngJsjrAuJWJigYo9SMTR533lUDqqNDjSmcKDC1ySZK5iBiMA0OOZpQ-bH6GSMXk9wIQA4q-PRTQmBICOW7tyg1CsfqmX3_0T_0MMEUc2lUrHyIjixEqsm_PtXWOErHgp55bWfLkXY6H90cBw3i-eaoqtuTzj__VI0oDFrRPFEv8_GMlA9QhMzxuklFuDSOtD68tFMf7DXCvsnnDgbcE_eU-NbeuD_f2hw052rGCwn5_aeuBnnMZdGahlVx99IzDk8DZZqhgJLZvOm9VgDlenTPVOUr5QEz04s2jrjK9NZsAWiHf5j4wGjRtTHS-Wa7jbTSHUgbA151_rnaTUuuNWcg&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2022-01-26 12:00:58 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2022-01-26 12:00:58 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw MjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx MDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv bS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg T3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB ARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku l2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97 ULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK j9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv C7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G +cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC zjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP Y3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE QDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu a2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV BgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK BggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw ggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg Zm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg cGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw dCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0 aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy ZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw cy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw DQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj ytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow o5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese 7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq eE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit paZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw\nMjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx\nMDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv\nbS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg\nT3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB\nARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq\nhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku\nl2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97\nULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK\nj9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv\nC7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G\n+cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC\nzjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP\nY3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE\nQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu\na2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV\nBgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK\nBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw\nggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg\nZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg\ncGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj\nZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw\ndCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0\naGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy\nZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw\ncy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw\nDQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj\nytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow\no5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese\n7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq\neE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit\npaZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003da9767e7d-d0d6-4c9f-826a-6b5ac8bbd7d2,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3335393737303937303030313731,CN\u003dupp.com.br,OU\u003de5b51083-adc2-5775-b0fc-02b263b1c40d,O\u003dUP.P SEP S.A.,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "upp.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2022-01-26 12:00:58 SUCCESS
CheckForClientCertificate
Found client certificate
2022-01-26 12:00:58 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw
MjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx
MDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv
bS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg
T3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB
ARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq
hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku
l2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97
ULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK
j9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv
C7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G
+cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC
zjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP
Y3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE
QDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu
a2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV
BgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK
BggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw
ggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg
Zm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg
cGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj
ZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw
dCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0
aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy
ZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw
cy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw
DQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj
ytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow
o5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese
7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq
eE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit
paZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4=
-----END CERTIFICATE-----
2022-01-26 12:00:58 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjZmNWI5NWQ4YWZkZmM2OWZlMzdlN2JiOGNiNzAzNDJmMTNhZDQ0ZmVmMWJiODQyNGI5NThkOWFiYzA2OWE4MGQifQ.eyJpYXQiOjE2NDMxOTg0NTgsImV4cCI6MTY0MzE5ODUxOCwianRpIjoiOUNvOUM5VlZXRURPY1gxMVA1TS1Wdm45djBPVlR5SGdSUFdFWEpRUW9iRSIsImlzcyI6InVwcC1iYW5rIiwic3ViIjoidXBwLWJhbmsiLCJhdWQiOlsiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvdXBwL3Rva2VuIl19.ngJsjrAuJWJigYo9SMTR533lUDqqNDjSmcKDC1ySZK5iBiMA0OOZpQ-bH6GSMXk9wIQA4q-PRTQmBICOW7tyg1CsfqmX3_0T_0MMEUc2lUrHyIjixEqsm_PtXWOErHgp55bWfLkXY6H90cBw3i-eaoqtuTzj__VI0oDFrRPFEv8_GMlA9QhMzxuklFuDSOtD68tFMf7DXCvsnnDgbcE_eU-NbeuD_f2hw052rGCwn5_aeuBnnMZdGahlVx99IzDk8DZZqhgJLZvOm9VgDlenTPVOUr5QEz04s2jrjK9NZsAWiHf5j4wGjRtTHS-Wa7jbTSHUgbA151_rnaTUuuNWcg",
  "header": {
    "kid": "6f5b95d8afdfc69fe37e7bb8cb70342f13ad44fef1bb8424b958d9abc069a80d",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "upp-bank",
    "aud": [
      "https://www.certification.openid.net/test/a/upp/",
      "https://www.certification.openid.net/test/a/upp/token",
      "https://www.certification.openid.net/test-mtls/a/upp/token"
    ],
    "iss": "upp-bank",
    "exp": 1643198518,
    "iat": 1643198458,
    "jti": "9Co9C9VVWEDOcX11P5M-Vvn9v0OVTyHgRPWEXJQQobE"
  }
}
2022-01-26 12:00:58
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2022-01-26 12:00:58 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjZmNWI5NWQ4YWZkZmM2OWZlMzdlN2JiOGNiNzAzNDJmMTNhZDQ0ZmVmMWJiODQyNGI5NThkOWFiYzA2OWE4MGQifQ.eyJpYXQiOjE2NDMxOTg0NTgsImV4cCI6MTY0MzE5ODUxOCwianRpIjoiOUNvOUM5VlZXRURPY1gxMVA1TS1Wdm45djBPVlR5SGdSUFdFWEpRUW9iRSIsImlzcyI6InVwcC1iYW5rIiwic3ViIjoidXBwLWJhbmsiLCJhdWQiOlsiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvdXBwL3Rva2VuIl19.ngJsjrAuJWJigYo9SMTR533lUDqqNDjSmcKDC1ySZK5iBiMA0OOZpQ-bH6GSMXk9wIQA4q-PRTQmBICOW7tyg1CsfqmX3_0T_0MMEUc2lUrHyIjixEqsm_PtXWOErHgp55bWfLkXY6H90cBw3i-eaoqtuTzj__VI0oDFrRPFEv8_GMlA9QhMzxuklFuDSOtD68tFMf7DXCvsnnDgbcE_eU-NbeuD_f2hw052rGCwn5_aeuBnnMZdGahlVx99IzDk8DZZqhgJLZvOm9VgDlenTPVOUr5QEz04s2jrjK9NZsAWiHf5j4wGjRtTHS-Wa7jbTSHUgbA151_rnaTUuuNWcg
2022-01-26 12:00:58 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2022-01-26 12:00:58 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2022-01-26 12:00:58 SUCCESS
FAPIBrazilExtractRequestedScopeFromClientCredentialsGrant
Found 'consents' scope in request
actual
[
  "consents"
]
expected
consents
2022-01-26 12:00:58 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
OpScSZDmG0CkIgJq7pK8saRoCzFjvuHRhlnsrHlUBUrZLc7TTf
2022-01-26 12:00:58 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
OpScSZDmG0CkIgJq7pK8saRoCzFjvuHRhlnsrHlUBUrZLc7TTf
token_type
Bearer
2022-01-26 12:00:58
CopyAccessTokenToClientCredentialsField
Condition ran but did not log anything
2022-01-26 12:00:58 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance GPpmgFZuyrqCeSS
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "OpScSZDmG0CkIgJq7pK8saRoCzFjvuHRhlnsrHlUBUrZLc7TTf",
  "token_type": "Bearer"
}
outgoing_path
token
2022-01-26 12:00:58 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance GPpmgFZuyrqCeSS
incoming_headers
{
  "host": "www.certification.openid.net",
  "accept": "application/json, text/plain, */*",
  "content-type": "application/json",
  "authorization": "Bearer OpScSZDmG0CkIgJq7pK8saRoCzFjvuHRhlnsrHlUBUrZLc7TTf",
  "user-agent": "axios/0.24.0",
  "content-length": "1174",
  "connection": "close"
}
incoming_path
/test-mtls/a/upp/consents/v1/consents
incoming_body_form_params
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw MjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx MDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv bS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg T3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB ARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku l2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97 ULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK j9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv C7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G +cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC zjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP Y3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE QDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu a2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV BgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK BggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw ggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg Zm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg cGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw dCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0 aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy ZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw cy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw DQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj ytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow o5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese 7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq eE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit paZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4= -----END CERTIFICATE-----
incoming_body_json
{
  "data": {
    "loggedUser": {
      "document": {
        "identification": "57784518064",
        "rel": "CPF"
      }
    },
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_OVERDRAFT_LIMITS_READ",
      "ACCOUNTS_BALANCES_READ",
      "ACCOUNTS_TRANSACTIONS_READ",
      "CREDIT_CARDS_ACCOUNTS_BILLS_READ",
      "CREDIT_CARDS_ACCOUNTS_BILLS_TRANSACTIONS_READ",
      "CREDIT_CARDS_ACCOUNTS_LIMITS_READ",
      "CREDIT_CARDS_ACCOUNTS_READ",
      "CREDIT_CARDS_ACCOUNTS_TRANSACTIONS_READ",
      "CUSTOMERS_PERSONAL_ADITTIONALINFO_READ",
      "CUSTOMERS_PERSONAL_IDENTIFICATIONS_READ",
      "LOANS_READ",
      "LOANS_WARRANTIES_READ",
      "LOANS_SCHEDULED_INSTALMENTS_READ",
      "LOANS_PAYMENTS_READ",
      "FINANCINGS_READ",
      "FINANCINGS_WARRANTIES_READ",
      "FINANCINGS_SCHEDULED_INSTALMENTS_READ",
      "FINANCINGS_PAYMENTS_READ",
      "UNARRANGED_ACCOUNTS_OVERDRAFT_READ",
      "UNARRANGED_ACCOUNTS_OVERDRAFT_WARRANTIES_READ",
      "UNARRANGED_ACCOUNTS_OVERDRAFT_SCHEDULED_INSTALMENTS_READ",
      "UNARRANGED_ACCOUNTS_OVERDRAFT_PAYMENTS_READ",
      "INVOICE_FINANCINGS_READ",
      "INVOICE_FINANCINGS_WARRANTIES_READ",
      "INVOICE_FINANCINGS_SCHEDULED_INSTALMENTS_READ",
      "INVOICE_FINANCINGS_PAYMENTS_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2021-12-31T00:00:00Z",
    "transactionFromDateTime": "2021-08-10T00:00:00Z",
    "transactionToDateTime": "2021-12-31T23:59:59Z"
  }
}
incoming_query_string_params
{}
incoming_body
{"data":{"loggedUser":{"document":{"identification":"57784518064","rel":"CPF"}},"permissions":["ACCOUNTS_READ","ACCOUNTS_OVERDRAFT_LIMITS_READ","ACCOUNTS_BALANCES_READ","ACCOUNTS_TRANSACTIONS_READ","CREDIT_CARDS_ACCOUNTS_BILLS_READ","CREDIT_CARDS_ACCOUNTS_BILLS_TRANSACTIONS_READ","CREDIT_CARDS_ACCOUNTS_LIMITS_READ","CREDIT_CARDS_ACCOUNTS_READ","CREDIT_CARDS_ACCOUNTS_TRANSACTIONS_READ","CUSTOMERS_PERSONAL_ADITTIONALINFO_READ","CUSTOMERS_PERSONAL_IDENTIFICATIONS_READ","LOANS_READ","LOANS_WARRANTIES_READ","LOANS_SCHEDULED_INSTALMENTS_READ","LOANS_PAYMENTS_READ","FINANCINGS_READ","FINANCINGS_WARRANTIES_READ","FINANCINGS_SCHEDULED_INSTALMENTS_READ","FINANCINGS_PAYMENTS_READ","UNARRANGED_ACCOUNTS_OVERDRAFT_READ","UNARRANGED_ACCOUNTS_OVERDRAFT_WARRANTIES_READ","UNARRANGED_ACCOUNTS_OVERDRAFT_SCHEDULED_INSTALMENTS_READ","UNARRANGED_ACCOUNTS_OVERDRAFT_PAYMENTS_READ","INVOICE_FINANCINGS_READ","INVOICE_FINANCINGS_WARRANTIES_READ","INVOICE_FINANCINGS_SCHEDULED_INSTALMENTS_READ","INVOICE_FINANCINGS_PAYMENTS_READ","RESOURCES_READ"],"expirationDateTime":"2021-12-31T00:00:00Z","transactionFromDateTime":"2021-08-10T00:00:00Z","transactionToDateTime":"2021-12-31T23:59:59Z"}}
2022-01-26 12:00:58 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
New consent endpoint
2022-01-26 12:00:58 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw MjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx MDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv bS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg T3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB ARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku l2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97 ULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK j9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv C7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G +cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC zjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP Y3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE QDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu a2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV BgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK BggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw ggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg Zm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg cGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw dCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0 aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy ZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw cy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw DQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj ytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow o5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese 7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq eE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit paZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw\nMjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx\nMDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv\nbS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg\nT3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB\nARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq\nhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku\nl2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97\nULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK\nj9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv\nC7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G\n+cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC\nzjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP\nY3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE\nQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu\na2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV\nBgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK\nBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw\nggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg\nZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg\ncGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj\nZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw\ndCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0\naGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy\nZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw\ncy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw\nDQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj\nytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow\no5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese\n7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq\neE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit\npaZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003da9767e7d-d0d6-4c9f-826a-6b5ac8bbd7d2,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3335393737303937303030313731,CN\u003dupp.com.br,OU\u003de5b51083-adc2-5775-b0fc-02b263b1c40d,O\u003dUP.P SEP S.A.,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "upp.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2022-01-26 12:00:58 SUCCESS
CheckForClientCertificate
Found client certificate
2022-01-26 12:00:58 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw
MjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx
MDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv
bS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg
T3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB
ARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq
hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku
l2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97
ULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK
j9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv
C7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G
+cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC
zjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP
Y3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE
QDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu
a2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV
BgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK
BggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw
ggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg
Zm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg
cGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj
ZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw
dCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0
aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy
ZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw
cy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw
DQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj
ytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow
o5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese
7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq
eE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit
paZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4=
-----END CERTIFICATE-----
2022-01-26 12:00:58 SUCCESS
EnsureIncomingRequestMethodIsPost
Client correctly used http POST method
2022-01-26 12:00:58 SUCCESS
EnsureBearerAccessTokenNotInParams
Client correctly did not send access token in query parameters or form body
2022-01-26 12:00:58 SUCCESS
ExtractBearerAccessTokenFromHeader
Found access token on incoming request
access_token
OpScSZDmG0CkIgJq7pK8saRoCzFjvuHRhlnsrHlUBUrZLc7TTf
2022-01-26 12:00:58 SUCCESS
RequireBearerClientCredentialsAccessToken
Found access token in request
actual
OpScSZDmG0CkIgJq7pK8saRoCzFjvuHRhlnsrHlUBUrZLc7TTf
2022-01-26 12:00:58 INFO
ExtractFapiDateHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-auth-date
path
headers.x-fapi-auth-date
mapped
object
incoming_request
2022-01-26 12:00:58 INFO
ExtractFapiIpAddressHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-customer-ip-address
path
headers.x-fapi-customer-ip-address
mapped
object
incoming_request
2022-01-26 12:00:58 INFO
ExtractFapiInteractionIdHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-interaction-id
path
headers.x-fapi-interaction-id
mapped
object
incoming_request
2022-01-26 12:00:58 SUCCESS
FAPIBrazilEnsureClientCredentialsScopeContainedConsents
The token request which was used to obtain the access token contained 'consents' scope
actual
[
  "consents"
]
2022-01-26 12:00:58
FAPIBrazilExtractConsentRequest
Condition ran but did not log anything
2022-01-26 12:00:58 SUCCESS
CreateFapiInteractionIdIfNeeded
Created new FAPI interaction ID
fapi_interaction_id
f44819ab-57c3-4b55-8c7a-a65fc6893106
2022-01-26 12:00:58 SUCCESS
FAPIBrazilGenerateNewConsentResponse
Created consent response
headers
{
  "x-fapi-interaction-id": "f44819ab-57c3-4b55-8c7a-a65fc6893106"
}
consentId
urn:conformance.oidf:nBdEgirzZh
consent_response
{
  "data": {
    "consentId": "urn:conformance.oidf:nBdEgirzZh",
    "creationDateTime": "2022-01-26T12:00:58Z",
    "status": "AWAITING_AUTHORISATION",
    "statusUpdateDateTime": "2022-01-26T12:00:58Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2022-01-26T14:00:58Z",
    "transactionFromDateTime": "2022-01-26T11:55:58Z",
    "transactionToDateTime": "2022-01-26T14:00:58Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/uppconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2022-01-26T12:00:58Z"
  }
}
2022-01-26 12:00:58
ClearAccessTokenFromRequest
Condition ran but did not log anything
2022-01-26 12:00:58 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance GPpmgFZuyrqCeSS
outgoing_status_code
201
outgoing_headers
{
  "x-fapi-interaction-id": [
    "f44819ab-57c3-4b55-8c7a-a65fc6893106"
  ]
}
outgoing_body
{
  "data": {
    "consentId": "urn:conformance.oidf:nBdEgirzZh",
    "creationDateTime": "2022-01-26T12:00:58Z",
    "status": "AWAITING_AUTHORISATION",
    "statusUpdateDateTime": "2022-01-26T12:00:58Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2022-01-26T14:00:58Z",
    "transactionFromDateTime": "2022-01-26T11:55:58Z",
    "transactionToDateTime": "2022-01-26T14:00:58Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/uppconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2022-01-26T12:00:58Z"
  }
}
outgoing_path
consents/v1/consents
2022-01-26 12:00:58 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance GPpmgFZuyrqCeSS
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.7.4 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/upp/jwks
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2022-01-26 12:00:58 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2022-01-26 12:00:58 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance GPpmgFZuyrqCeSS
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "alg": "PS256",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "alg": "RSA-OAEP",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
outgoing_path
jwks
2022-01-26 12:00:59 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance GPpmgFZuyrqCeSS
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "PostmanRuntime/7.28.4",
  "accept": "*/*",
  "cache-control": "no-cache",
  "postman-token": "01d4b1b7-023e-45fc-8256-7a0cc53d0f27",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/upp/authorize
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{
  "client_id": "upp-bank",
  "scope": "openid consent:urn:conformance.oidf:nBdEgirzZh accounts resources",
  "response_type": "code",
  "redirect_uri": "https://www.upp.com.br/callback",
  "request": "eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZHQ00iLCJjdHkiOiJvYXV0aC1hdXRoei1yZXErand0Iiwia2lkIjoiMGZlNTAyZGQtMTRmMC00ZjQ1LTgwZjktZmViOWEyMTZmOTk2In0.PrBfpd4NGnl4KBE3mIyH2O31hkHueKsqXR847TxwU6HpY0bvpmIUxiK_Z__OnDX_GfFH-Rb9WvihpbXz1CyYCVtrg1-pAfE8jgasSpvT42hmekSwJ1w1aoeHpd1QaeQq_oyJmTYCJC0haVVtouVINNia2cTih9QFCRowlVatNrOdYaqcnmcJkwlbvJdduOSIGdoTJ3AEYxDKw02VppWJFVbM5jJy49lm6JJe3woSqwz6CK5aeLBQHNn59Fc3-DxnvnanvmAT9qLqM7F2bZCFPPns4nXP0P1YP8o4yLp_lnfSes3Sh3e7s6492kHHlPt829kcprkYgvqARadOXSR_GQ.2eIT0AZ1CDiFEZJ5.i7z5xsDvhh1hBa7-wN4przBCeWuion2L_GmJLDw00wjC-QkKPf5hLhhQ5t05romsaTYYvsib-K5Hj7GUQkrwzCc8-XMvaxUZlVRFTuLjNLQ3vjx2t_PZe0T16LbhDtJc6rQm9kRjPM3IAWAfPLezYavWZ5oY29ORMpnx7F2qaH71ufEMaIvZB-C0dcDgDoOuIfCFdL7h5Yg5CxwiJ6rjdrsxU5kdabIwwyHF3YoXn2iMXFajDA70JaARhhghYYkcwe-wU-vqVhCflHSBaNh4hKAcLCT7h41_EELLRaJBOIkSWD0npM2bOq3pArlJPneBYen4W-fPRfttG1PLH3E6sxU9P8UnDsxUvYchYarmR4CvdydU_cemuW_0XNZKFI5WsV_UGMan5ZM4b6fvwaKUI-LtdBp3MOZET4K7jcN_hZoag1N_OtD20psLQEvgZA8khoAYAXP8T_RU5u4ICsLsevnNAxauDb0wWeHmqqEae572nbzaJXrOQp8UGuQ5dSNm0UfJFRyxWAb6xvwy0Q-VhDDZXGfyJSFsTqX-gCupcCnrOLyVOsbfAoR32b1wiCILAzKGwnySgqcQMiugCj5HJEepdWzuWQM1ZjVWia4e2LwSPKFpWQqYzpCm8XDcpfPs5YO8WC25nY_LL7UmiT8HMv5MoJZFSyKs20fR3RxoJ9RkV25XbXB0YX-X7uTOwokBcP7BVXhgsPNBaDRzOvC1oTnQg-5kNcgUqfUdg1k8yD49iuJuahl3nWZiIS5pXfKePfBEdTWoe6V1stPFgq6ocsswCzn6sqQsWb2ENPG76fE5L1FfhKwtHtM9eMFi7fk4CaJJ4Z52j0AR8OqzQvH6wzDiacHeCT1191SRw-bK0LGmva0nWTn_ayQbq4SU-HP7Cs2YxbQjSTXUh9Ft6UYmjbbJQ2E3-jI43gUMq6Mc0KptmNkIf1E9JW2rUaXr6Obte7FqphE7PQ5WHGUTciqbSNeRHgIV2atb6o54LY8oRBP2bk-JZAmzmoNFSEtD0hAtAHrNmedn0OUkB7Imtuo1qYvDs45pXdprkBSOVysXhhrVvJuUzfDAYkySyWeCkCpN64-GtXyVlJyyMpIJ5yFPmyL530KBkCeKJ43zPaKZd8TPpNON86XIAf1UvZM82slq2S9WSWjSZYdRjCBwsJPbg4Xmg061RnPFvs3VLhgk2F-8ft5gPF236by5arZNxGzZYaV_kXyZv4gAkHjkGxvf96w_l2aByqhiuzQzLAa9anATMi40mDdnVCSqse1r_vpCe8GJF5q8aTgzBP16VzjYbluihhZ5fqAsNmLbBLJqk5lw479IuiOIvHsbcMUqZH1jtH-7KRcKThco7jeF4Yn4N6mBBakup_OqrFIxPaMN28HmzU41xBROF1x61cAgqobDEtc4-fcHIy6Nz-RESCeTDIRizvQ3jO0s7i6SnPGkC6DBN5LQuHlBhNhhC4GABb-BEZOQeyxaeRxUcMSxJT_kjxukoNPhAuM4EzmRS_166saKmIcJGnnAiGN7djcmLAuxu0ZCuZ8qcXPDtYYJp-pWHTTK9eH0H3ecbawx-Vdl5EC_i1KXViSzcK-GUkNL13L3porE56W-Kikdspmy2mKBUP18wHtYxFUo0Auwq7cP05sLMQhspYX7o-lVDO0SotAim03uTZnElp7SjQFd6Z_N2sEOOkzz6O8raK3EGdEjrrGG9tDP8U-p6WSIuMV5zrhzOaaNq57rr9PZ0D9OfuSCERYcfaMCQVzmpsn1dAJwGZycwqbikkmlavrSYXHuTnR_t_861iC6ZKf_6lXicXevuezVZ_jGJlkrFPkI8MZ--QU3r01mN7YcR5Q15RPhG9tyFrI.x7g1OSCOHqnz2-v8a5yN_A"
}
incoming_body
2022-01-26 12:00:59 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Authorization endpoint
2022-01-26 12:00:59 SUCCESS
ExtractRequestObject
Parsed request object
request_object
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6Im9hdXRoLWF1dGh6LXJlcStqd3QiLCJraWQiOiI2ZjViOTVkOGFmZGZjNjlmZTM3ZTdiYjhjYjcwMzQyZjEzYWQ0NGZlZjFiYjg0MjRiOTU4ZDlhYmMwNjlhODBkIn0.eyJub25jZSI6Ik1ScVpab2twZERFRlpDczRCU2lHZTZPaDM2N3JJTEN3WS1tNmZzN001dEEiLCJzdGF0ZSI6IjVoT3otbUtfQTZianhXQzIwcjlXV3pyaVNmQVBKV2VhR2dIRWlqOF9kVkkiLCJzY29wZSI6Im9wZW5pZCBjb25zZW50OnVybjpjb25mb3JtYW5jZS5vaWRmOm5CZEVnaXJ6WmggYWNjb3VudHMgcmVzb3VyY2VzIiwicmVzcG9uc2VfdHlwZSI6ImNvZGUiLCJyZWRpcmVjdF91cmkiOiJodHRwczovL3d3dy51cHAuY29tLmJyL2NhbGxiYWNrIiwiY2xhaW1zIjp7ImlkX3Rva2VuIjp7ImFjciI6eyJ2YWx1ZXMiOlsidXJuOmJyYXNpbDpvcGVuYmFua2luZzpsb2EyIiwidXJuOmJyYXNpbDpvcGVuYmFua2luZzpsb2EzIl0sImVzc2VudGlhbCI6dHJ1ZX19fSwiY29kZV9jaGFsbGVuZ2UiOiJWaTNsQXloNWd5VTlsZS1HelFnWnJWMTZaUHMzYjBOeWJZVFBJZEJBRlN3IiwiY29kZV9jaGFsbGVuZ2VfbWV0aG9kIjoiUzI1NiIsImlzcyI6InVwcC1iYW5rIiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvIiwiY2xpZW50X2lkIjoidXBwLWJhbmsiLCJqdGkiOiJlbHUwWExtaEZJR2RqYnV1TlhQVFVtcWJFNnItSGU3MmZUbV9GNzFTWXpNIiwiaWF0IjoxNjQzMTk4NDU4LCJleHAiOjE2NDMxOTg3NTgsIm5iZiI6MTY0MzE5ODQ1OH0.hTJVZYe-rNBcwi3QeVeGcnUD4dLShJcUHDlKiC1TI_DtLNtzSwS_IMpjlbZ1IMU-O8RQ5e3BYCC8I5P6yZfhCgZTJQQdQnSluc_TrWKtp3qUUefEcBR6lLt-hqqc_VgtOtqa9J95OmH8Xl-k7rZMy7F2kirrng42L5LnXVvVxk0yQDqbiRbW2zwNw_ka54bJKHo8MZ5b8o7dwWVN5-Wn7KjDCbVRoAc7T1-_GwZY_2PxCqTCe7U2rM9l9iZ2kdbzwWGi7_Ukk2-JxgTVnhC-3CBrP5h7-dPHwY0vfxt3iTSfym1o6mbo4KDVJwGqVO1AUii97MGBBwl1FuKIOi7r3g",
  "header": {
    "kid": "6f5b95d8afdfc69fe37e7bb8cb70342f13ad44fef1bb8424b958d9abc069a80d",
    "typ": "oauth-authz-req+jwt",
    "alg": "PS256"
  },
  "claims": {
    "iss": "upp-bank",
    "response_type": "code",
    "code_challenge_method": "S256",
    "nonce": "MRqZZokpdDEFZCs4BSiGe6Oh367rILCwY-m6fs7M5tA",
    "client_id": "upp-bank",
    "aud": "https://www.certification.openid.net/test/a/upp/",
    "nbf": 1643198458,
    "scope": "openid consent:urn:conformance.oidf:nBdEgirzZh accounts resources",
    "claims": {
      "id_token": {
        "acr": {
          "values": [
            "urn:brasil:openbanking:loa2",
            "urn:brasil:openbanking:loa3"
          ],
          "essential": true
        }
      }
    },
    "state": "5hOz-mK_A6bjxWC20r9WWzriSfAPJWeaGgHEij8_dVI",
    "redirect_uri": "https://www.upp.com.br/callback",
    "exp": 1643198758,
    "iat": 1643198458,
    "code_challenge": "Vi3lAyh5gyU9le-GzQgZrV16ZPs3b0NybYTPIdBAFSw",
    "jti": "elu0XLmhFIGdjbuuNXPTUmqbE6r-He72fTm_F71SYzM"
  },
  "jwe_header": {
    "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
    "cty": "oauth-authz-req+jwt",
    "enc": "A256GCM",
    "alg": "RSA-OAEP"
  }
}
2022-01-26 12:00:59 SUCCESS
EnsureRequestObjectWasEncrypted
Request object was encrypted
jwe_header
{
  "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
  "cty": "oauth-authz-req+jwt",
  "enc": "A256GCM",
  "alg": "RSA-OAEP"
}
2022-01-26 12:00:59 SUCCESS
FAPIBrazilEnsureRequestObjectEncryptedUsingRSAOAEPA256GCM
Request object was encrypted using RSA-OAEP and A256GCM
jwe_header
{
  "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
  "cty": "oauth-authz-req+jwt",
  "enc": "A256GCM",
  "alg": "RSA-OAEP"
}
2022-01-26 12:00:59 SUCCESS
ValidateEncryptedRequestObjectHasKid
kid was found in the encrypted request object header
kid
0fe502dd-14f0-4f45-80f9-feb9a216f996
2022-01-26 12:00:59 SUCCESS
CreateEffectiveAuthorizationRequestParameters
Merged http request parameters with request object claims
effective_authorization_endpoint_request
{
  "client_id": "upp-bank",
  "scope": "openid consent:urn:conformance.oidf:nBdEgirzZh accounts resources",
  "response_type": "code",
  "redirect_uri": "https://www.upp.com.br/callback",
  "request": "eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZHQ00iLCJjdHkiOiJvYXV0aC1hdXRoei1yZXErand0Iiwia2lkIjoiMGZlNTAyZGQtMTRmMC00ZjQ1LTgwZjktZmViOWEyMTZmOTk2In0.PrBfpd4NGnl4KBE3mIyH2O31hkHueKsqXR847TxwU6HpY0bvpmIUxiK_Z__OnDX_GfFH-Rb9WvihpbXz1CyYCVtrg1-pAfE8jgasSpvT42hmekSwJ1w1aoeHpd1QaeQq_oyJmTYCJC0haVVtouVINNia2cTih9QFCRowlVatNrOdYaqcnmcJkwlbvJdduOSIGdoTJ3AEYxDKw02VppWJFVbM5jJy49lm6JJe3woSqwz6CK5aeLBQHNn59Fc3-DxnvnanvmAT9qLqM7F2bZCFPPns4nXP0P1YP8o4yLp_lnfSes3Sh3e7s6492kHHlPt829kcprkYgvqARadOXSR_GQ.2eIT0AZ1CDiFEZJ5.i7z5xsDvhh1hBa7-wN4przBCeWuion2L_GmJLDw00wjC-QkKPf5hLhhQ5t05romsaTYYvsib-K5Hj7GUQkrwzCc8-XMvaxUZlVRFTuLjNLQ3vjx2t_PZe0T16LbhDtJc6rQm9kRjPM3IAWAfPLezYavWZ5oY29ORMpnx7F2qaH71ufEMaIvZB-C0dcDgDoOuIfCFdL7h5Yg5CxwiJ6rjdrsxU5kdabIwwyHF3YoXn2iMXFajDA70JaARhhghYYkcwe-wU-vqVhCflHSBaNh4hKAcLCT7h41_EELLRaJBOIkSWD0npM2bOq3pArlJPneBYen4W-fPRfttG1PLH3E6sxU9P8UnDsxUvYchYarmR4CvdydU_cemuW_0XNZKFI5WsV_UGMan5ZM4b6fvwaKUI-LtdBp3MOZET4K7jcN_hZoag1N_OtD20psLQEvgZA8khoAYAXP8T_RU5u4ICsLsevnNAxauDb0wWeHmqqEae572nbzaJXrOQp8UGuQ5dSNm0UfJFRyxWAb6xvwy0Q-VhDDZXGfyJSFsTqX-gCupcCnrOLyVOsbfAoR32b1wiCILAzKGwnySgqcQMiugCj5HJEepdWzuWQM1ZjVWia4e2LwSPKFpWQqYzpCm8XDcpfPs5YO8WC25nY_LL7UmiT8HMv5MoJZFSyKs20fR3RxoJ9RkV25XbXB0YX-X7uTOwokBcP7BVXhgsPNBaDRzOvC1oTnQg-5kNcgUqfUdg1k8yD49iuJuahl3nWZiIS5pXfKePfBEdTWoe6V1stPFgq6ocsswCzn6sqQsWb2ENPG76fE5L1FfhKwtHtM9eMFi7fk4CaJJ4Z52j0AR8OqzQvH6wzDiacHeCT1191SRw-bK0LGmva0nWTn_ayQbq4SU-HP7Cs2YxbQjSTXUh9Ft6UYmjbbJQ2E3-jI43gUMq6Mc0KptmNkIf1E9JW2rUaXr6Obte7FqphE7PQ5WHGUTciqbSNeRHgIV2atb6o54LY8oRBP2bk-JZAmzmoNFSEtD0hAtAHrNmedn0OUkB7Imtuo1qYvDs45pXdprkBSOVysXhhrVvJuUzfDAYkySyWeCkCpN64-GtXyVlJyyMpIJ5yFPmyL530KBkCeKJ43zPaKZd8TPpNON86XIAf1UvZM82slq2S9WSWjSZYdRjCBwsJPbg4Xmg061RnPFvs3VLhgk2F-8ft5gPF236by5arZNxGzZYaV_kXyZv4gAkHjkGxvf96w_l2aByqhiuzQzLAa9anATMi40mDdnVCSqse1r_vpCe8GJF5q8aTgzBP16VzjYbluihhZ5fqAsNmLbBLJqk5lw479IuiOIvHsbcMUqZH1jtH-7KRcKThco7jeF4Yn4N6mBBakup_OqrFIxPaMN28HmzU41xBROF1x61cAgqobDEtc4-fcHIy6Nz-RESCeTDIRizvQ3jO0s7i6SnPGkC6DBN5LQuHlBhNhhC4GABb-BEZOQeyxaeRxUcMSxJT_kjxukoNPhAuM4EzmRS_166saKmIcJGnnAiGN7djcmLAuxu0ZCuZ8qcXPDtYYJp-pWHTTK9eH0H3ecbawx-Vdl5EC_i1KXViSzcK-GUkNL13L3porE56W-Kikdspmy2mKBUP18wHtYxFUo0Auwq7cP05sLMQhspYX7o-lVDO0SotAim03uTZnElp7SjQFd6Z_N2sEOOkzz6O8raK3EGdEjrrGG9tDP8U-p6WSIuMV5zrhzOaaNq57rr9PZ0D9OfuSCERYcfaMCQVzmpsn1dAJwGZycwqbikkmlavrSYXHuTnR_t_861iC6ZKf_6lXicXevuezVZ_jGJlkrFPkI8MZ--QU3r01mN7YcR5Q15RPhG9tyFrI.x7g1OSCOHqnz2-v8a5yN_A",
  "iss": "upp-bank",
  "code_challenge_method": "S256",
  "nonce": "MRqZZokpdDEFZCs4BSiGe6Oh367rILCwY-m6fs7M5tA",
  "aud": "https://www.certification.openid.net/test/a/upp/",
  "nbf": 1643198458,
  "claims": {
    "id_token": {
      "acr": {
        "values": [
          "urn:brasil:openbanking:loa2",
          "urn:brasil:openbanking:loa3"
        ],
        "essential": true
      }
    }
  },
  "state": "5hOz-mK_A6bjxWC20r9WWzriSfAPJWeaGgHEij8_dVI",
  "exp": 1643198758,
  "iat": 1643198458,
  "code_challenge": "Vi3lAyh5gyU9le-GzQgZrV16ZPs3b0NybYTPIdBAFSw",
  "jti": "elu0XLmhFIGdjbuuNXPTUmqbE6r-He72fTm_F71SYzM"
}
2022-01-26 12:00:59 SUCCESS
FAPIValidateRequestObjectSigningAlg
Request object was signed with a permitted algorithm
alg
PS256
2022-01-26 12:00:59 SUCCESS
FAPIBrazilValidateRequestObjectIdTokenACRClaims
Acr value in request object is as expected
received
[
  "urn:brasil:openbanking:loa2",
  "urn:brasil:openbanking:loa3"
]
2022-01-26 12:00:59 SUCCESS
FAPIValidateRequestObjectExp
Request object contains a valid exp claim, expiry time
exp
"Jan 26, 2022, 12:05:58 PM"
2022-01-26 12:00:59 SUCCESS
FAPI1AdvancedValidateRequestObjectNBFClaim
nbf claim is valid
nbf
"Jan 26, 2022, 12:00:58 PM"
now
"Jan 26, 2022, 12:00:59 PM"
2022-01-26 12:00:59
ValidateRequestObjectClaims
Request object does not contain a max_age claim
2022-01-26 12:00:59 SUCCESS
ValidateRequestObjectClaims
Request object claims passed all validation checks
2022-01-26 12:00:59 SUCCESS
EnsureNumericRequestObjectClaimsAreNotNull
None of the claims expected to have numeric values, have null values
numeric_claims
[
  "max_age"
]
2022-01-26 12:00:59 SUCCESS
EnsureRequestObjectDoesNotContainRequestOrRequestUri
Request object does not contain request or request_uri
2022-01-26 12:00:59 SUCCESS
EnsureRequestObjectDoesNotContainSubWithClientId
Request object does not contain Client Id in sub
2022-01-26 12:00:59 SUCCESS
ValidateRequestObjectSignature
Request object signature validated using a key in the client's JWKS and using the client's registered request_object_signing_alg
request_object
eyJhbGciOiJQUzI1NiIsInR5cCI6Im9hdXRoLWF1dGh6LXJlcStqd3QiLCJraWQiOiI2ZjViOTVkOGFmZGZjNjlmZTM3ZTdiYjhjYjcwMzQyZjEzYWQ0NGZlZjFiYjg0MjRiOTU4ZDlhYmMwNjlhODBkIn0.eyJub25jZSI6Ik1ScVpab2twZERFRlpDczRCU2lHZTZPaDM2N3JJTEN3WS1tNmZzN001dEEiLCJzdGF0ZSI6IjVoT3otbUtfQTZianhXQzIwcjlXV3pyaVNmQVBKV2VhR2dIRWlqOF9kVkkiLCJzY29wZSI6Im9wZW5pZCBjb25zZW50OnVybjpjb25mb3JtYW5jZS5vaWRmOm5CZEVnaXJ6WmggYWNjb3VudHMgcmVzb3VyY2VzIiwicmVzcG9uc2VfdHlwZSI6ImNvZGUiLCJyZWRpcmVjdF91cmkiOiJodHRwczovL3d3dy51cHAuY29tLmJyL2NhbGxiYWNrIiwiY2xhaW1zIjp7ImlkX3Rva2VuIjp7ImFjciI6eyJ2YWx1ZXMiOlsidXJuOmJyYXNpbDpvcGVuYmFua2luZzpsb2EyIiwidXJuOmJyYXNpbDpvcGVuYmFua2luZzpsb2EzIl0sImVzc2VudGlhbCI6dHJ1ZX19fSwiY29kZV9jaGFsbGVuZ2UiOiJWaTNsQXloNWd5VTlsZS1HelFnWnJWMTZaUHMzYjBOeWJZVFBJZEJBRlN3IiwiY29kZV9jaGFsbGVuZ2VfbWV0aG9kIjoiUzI1NiIsImlzcyI6InVwcC1iYW5rIiwiYXVkIjoiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvIiwiY2xpZW50X2lkIjoidXBwLWJhbmsiLCJqdGkiOiJlbHUwWExtaEZJR2RqYnV1TlhQVFVtcWJFNnItSGU3MmZUbV9GNzFTWXpNIiwiaWF0IjoxNjQzMTk4NDU4LCJleHAiOjE2NDMxOTg3NTgsIm5iZiI6MTY0MzE5ODQ1OH0.hTJVZYe-rNBcwi3QeVeGcnUD4dLShJcUHDlKiC1TI_DtLNtzSwS_IMpjlbZ1IMU-O8RQ5e3BYCC8I5P6yZfhCgZTJQQdQnSluc_TrWKtp3qUUefEcBR6lLt-hqqc_VgtOtqa9J95OmH8Xl-k7rZMy7F2kirrng42L5LnXVvVxk0yQDqbiRbW2zwNw_ka54bJKHo8MZ5b8o7dwWVN5-Wn7KjDCbVRoAc7T1-_GwZY_2PxCqTCe7U2rM9l9iZ2kdbzwWGi7_Ukk2-JxgTVnhC-3CBrP5h7-dPHwY0vfxt3iTSfym1o6mbo4KDVJwGqVO1AUii97MGBBwl1FuKIOi7r3g
request_object_signing_alg
PS256
jwk
Sun RSA public key, 2048 bits
  params: null
  modulus: 26209187316270534456033699213267036038577328332991643835531519844623783324814538679401675444727386664417805841416441600811972966637356833516193074570358709672840913335701123820129356233132932042589954281752646149758647969873334467859355848316241495157845641470802378146769191155439360515150178981790383342019826659619756591874960315685926895668654700512608293206222385118218980734323885798381069631320128215099863150840448466552415731452665795634836178977613588767173155891760592246579683203551600268102701482873623532227785292156437089054856960718476772904396863387193750660388033972090457897899490669165334764640873
  public exponent: 65537
2022-01-26 12:00:59 SUCCESS
EnsureMatchingRedirectUriInRequestObject
Redirect URI matched
actual
https://www.upp.com.br/callback
2022-01-26 12:00:59 SUCCESS
EnsureRequiredAuthorizationRequestParametersMatchRequestObject
Required http request parameters match request object claims
response_type
code
client_id
upp-bank
2022-01-26 12:00:59 SUCCESS
EnsureOptionalAuthorizationRequestParametersMatchRequestObject
All http request parameters and request object claims match
2022-01-26 12:00:59 SUCCESS
ExtractRequestedScopes
Requested scopes
scope
openid consent:urn:conformance.oidf:nBdEgirzZh accounts resources
2022-01-26 12:00:59 SUCCESS
FAPIBrazilValidateConsentScope
Found consent scope in request
actual
[
  "openid",
  "consent:urn:conformance.oidf:nBdEgirzZh",
  "accounts",
  "resources"
]
expected
consent:urn:conformance.oidf:nBdEgirzZh
2022-01-26 12:00:59 SUCCESS
EnsureScopeContainsAccounts
Found accounts scope in request
actual
[
  "openid",
  "consent:urn:conformance.oidf:nBdEgirzZh",
  "accounts",
  "resources"
]
2022-01-26 12:00:59 SUCCESS
EnsureResponseTypeIsCode
Response type is expected value
expected
code
2022-01-26 12:00:59 SUCCESS
EnsureMatchingClientId
Client ID matched
client_id
upp-bank
2022-01-26 12:00:59 SUCCESS
CreateAuthorizationCode
Created authorization code
authorization_code
oK2PmSNm1s85UZbv1FYQC6T5YZaOaBI8
2022-01-26 12:00:59 SUCCESS
ExtractNonceFromAuthorizationRequest
Extracted nonce
nonce
MRqZZokpdDEFZCs4BSiGe6Oh367rILCwY-m6fs7M5tA
2022-01-26 12:00:59 SUCCESS
FAPIBrazilChangeConsentStatusToAuthorized
Changed consent status to AUTHORISED
consent
{
  "data": {
    "consentId": "urn:conformance.oidf:nBdEgirzZh",
    "creationDateTime": "2022-01-26T12:00:58Z",
    "status": "AUTHORISED",
    "statusUpdateDateTime": "2022-01-26T12:00:59Z",
    "permissions": [
      "ACCOUNTS_READ",
      "ACCOUNTS_BALANCES_READ",
      "RESOURCES_READ"
    ],
    "expirationDateTime": "2022-01-26T14:00:58Z",
    "transactionFromDateTime": "2022-01-26T11:55:58Z",
    "transactionToDateTime": "2022-01-26T14:00:58Z",
    "links": {
      "self": "https://www.certification.openid.net/test/a/uppconsents/v1/consents"
    }
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2022-01-26T12:00:58Z"
  }
}
2022-01-26 12:00:59 SUCCESS
CreateAuthorizationEndpointResponseParams
Added authorization_endpoint_response_params to environment
params
{
  "redirect_uri": "https://www.upp.com.br/callback",
  "state": "5hOz-mK_A6bjxWC20r9WWzriSfAPJWeaGgHEij8_dVI"
}
2022-01-26 12:00:59 SUCCESS
AddCodeToAuthorizationEndpointResponseParams
Added code to authorization endpoint response params
authorization_endpoint_response_params
{
  "redirect_uri": "https://www.upp.com.br/callback",
  "state": "5hOz-mK_A6bjxWC20r9WWzriSfAPJWeaGgHEij8_dVI",
  "code": "oK2PmSNm1s85UZbv1FYQC6T5YZaOaBI8"
}
2022-01-26 12:00:59
GenerateJARMResponseClaims
Created JARM response claims
iss
https://www.certification.openid.net/test/a/upp/
aud
upp-bank
code
oK2PmSNm1s85UZbv1FYQC6T5YZaOaBI8
state
5hOz-mK_A6bjxWC20r9WWzriSfAPJWeaGgHEij8_dVI
exp
1643199059
2022-01-26 12:00:59 SUCCESS
SignJARMResponse
Signed the JARM response
jarm_response
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdWQiOiJ1cHAtYmFuayIsImNvZGUiOiJvSzJQbVNObTFzODVVWmJ2MUZZUUM2VDVZWmFPYUJJOCIsImlzcyI6Imh0dHBzOlwvXC93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0XC90ZXN0XC9hXC91cHBcLyIsInN0YXRlIjoiNWhPei1tS19BNmJqeFdDMjByOVdXenJpU2ZBUEpXZWFHZ0hFaWo4X2RWSSIsImV4cCI6MTY0MzE5OTA1OX0.FZYM-Lx0IpNScjnrWrZA8c6YmrT7CoQxaRTHP5PC-F8MDCjTYKvBV76wPNDZCbkT-_azimE90hNmjxGkCFGMhie3UvMjSElq5Q-qWd3IJpYuJjA9F4fbQiHCNsgxwjeJiqgMiFiy3Md6yQToOJXGfzE3wq9RSmA1QWTp-ZOyAAMhXjr2uHpuiFhJlqqAd7YL2z5826bInuFZl0pQ540pCuojhuFZ7v3jSEsqYfrfreaUnEZcW-gI6fcSCBKEodjuZ9zymFzEjfiNppepUMyG_P10LW9uhPRC_Qs45b82PxAcPc1L6TZaEtjJKE1veKqSM8v5Bzx5h2I8LqQoOrJz8A
2022-01-26 12:00:59 INFO
EncryptJARMResponse
Skipped evaluation due to missing required element: client authorization_encrypted_response_alg
path
authorization_encrypted_response_alg
mapped
object
client
2022-01-26 12:00:59
SendJARMResponseWitResponseModeQuery
Redirecting back to client
uri
https://www.upp.com.br/callback?response=eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdWQiOiJ1cHAtYmFuayIsImNvZGUiOiJvSzJQbVNObTFzODVVWmJ2MUZZUUM2VDVZWmFPYUJJOCIsImlzcyI6Imh0dHBzOlwvXC93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0XC90ZXN0XC9hXC91cHBcLyIsInN0YXRlIjoiNWhPei1tS19BNmJqeFdDMjByOVdXenJpU2ZBUEpXZWFHZ0hFaWo4X2RWSSIsImV4cCI6MTY0MzE5OTA1OX0.FZYM-Lx0IpNScjnrWrZA8c6YmrT7CoQxaRTHP5PC-F8MDCjTYKvBV76wPNDZCbkT-_azimE90hNmjxGkCFGMhie3UvMjSElq5Q-qWd3IJpYuJjA9F4fbQiHCNsgxwjeJiqgMiFiy3Md6yQToOJXGfzE3wq9RSmA1QWTp-ZOyAAMhXjr2uHpuiFhJlqqAd7YL2z5826bInuFZl0pQ540pCuojhuFZ7v3jSEsqYfrfreaUnEZcW-gI6fcSCBKEodjuZ9zymFzEjfiNppepUMyG_P10LW9uhPRC_Qs45b82PxAcPc1L6TZaEtjJKE1veKqSM8v5Bzx5h2I8LqQoOrJz8A
2022-01-26 12:00:59 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance GPpmgFZuyrqCeSS
outgoing
org.springframework.web.servlet.view.RedirectView: [RedirectView]; URL [https://www.upp.com.br/callback?response=eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdWQiOiJ1cHAtYmFuayIsImNvZGUiOiJvSzJQbVNObTFzODVVWmJ2MUZZUUM2VDVZWmFPYUJJOCIsImlzcyI6Imh0dHBzOlwvXC93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0XC90ZXN0XC9hXC91cHBcLyIsInN0YXRlIjoiNWhPei1tS19BNmJqeFdDMjByOVdXenJpU2ZBUEpXZWFHZ0hFaWo4X2RWSSIsImV4cCI6MTY0MzE5OTA1OX0.FZYM-Lx0IpNScjnrWrZA8c6YmrT7CoQxaRTHP5PC-F8MDCjTYKvBV76wPNDZCbkT-_azimE90hNmjxGkCFGMhie3UvMjSElq5Q-qWd3IJpYuJjA9F4fbQiHCNsgxwjeJiqgMiFiy3Md6yQToOJXGfzE3wq9RSmA1QWTp-ZOyAAMhXjr2uHpuiFhJlqqAd7YL2z5826bInuFZl0pQ540pCuojhuFZ7v3jSEsqYfrfreaUnEZcW-gI6fcSCBKEodjuZ9zymFzEjfiNppepUMyG_P10LW9uhPRC_Qs45b82PxAcPc1L6TZaEtjJKE1veKqSM8v5Bzx5h2I8LqQoOrJz8A]
outgoing_path
authorize
2022-01-26 12:00:59 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance GPpmgFZuyrqCeSS
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.7.4 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/upp/.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2022-01-26 12:00:59 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2022-01-26 12:00:59 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance GPpmgFZuyrqCeSS
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/upp/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/upp/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/upp/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/upp/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/upp/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/upp/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ],
  "response_types_supported": [
    "code"
  ],
  "response_modes_supported": [
    "jwt"
  ],
  "authorization_signing_alg_values_supported": [
    "PS256"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256"
  ]
}
outgoing_path
.well-known/openid-configuration
2022-01-26 12:00:59 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance GPpmgFZuyrqCeSS
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.7.4 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/upp/jwks
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2022-01-26 12:00:59 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2022-01-26 12:00:59 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance GPpmgFZuyrqCeSS
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "X5d4vFYfLxaG1gg8_l3bFYFhUaUVmE6PaEsRWX2EYqM",
      "x5c": [
        "MIIGqzCCBZOgAwIBAgIUdUCw8bQZidnZ6uERKJuN9u4RGvcwDQYJKoZIhvcNAQELBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwxFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNBTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMDgxNjA5NTUwMFoXDTIyMDkxNTA5NTUwMFowgacxCzAJBgNVBAYTAkJSMRMwEQYDVQQKEwpJQ1AtQnJhc2lsMS8wDAYDVQQLEwUxMjM0NTAOBgNVBAsTB2NlcnRtYW4wDwYDVQQLEwhhZ29vZG9uZTEcMBoGA1UEAxMTT3BlbiBCYW5raW5nIEJyYXNpbDE0MDIGCgmSJomT8ixkAQETJDc0ZTkyOWQ5LTMzYjYtNGQ4NS04YmE3LWMxNDZjODY3YTgxNzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANyF1agPcwq5ms99Flo82XsXUroWoD/6FX4AfmOUu113h4VOLYaO3N8HDYbKxgii2En/+O61e/Ptjn4T2PVq0iVcqiF6Gp4sKE5w/bKZRfdCe8qIPS4D+JKpFpesJvIHUeQvlAuBp5dA9nGSpxOjGe5P2+ZzNGXwvux/2ztdweGmKbtOvbYe4RVhiu6bOubog8XEBmD96EnqmoROasH1Hn9kDJIclbTP51j/TlQMzhrSfJJuE3Qq6vWhe/DaPbtmELmlDiYHjp8CjAY5oBMHLmkHvQxEBV4cwbUZj5ZpdqU8tkA78XtR4DkzrJ4fYoBb1+9ABq6GNzxWPpSQMQuBXdsCAwEAAaOCAwIwggL+MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJwv7oHX2exZL304ru+4eGVypHlxMB8GA1UdIwQYMBaAFIZ/WK0X9YK2TrQFs/uwzhFD30y+MEwGCCsGAQUFBwEBBEAwPjA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6Ly9jcmwuc2FuZGJveC5wa2kub3BlbmJhbmtpbmdicmFzaWwub3JnLmJyL2lzc3Vlci5jcmwwXgYDVR0RBFcwVaAZBgVgTAEDAqAQDA5NaWNoYWVsIEZyYXNlcqAYBgVgTAEDA6APDA0xMzM1MzIzNjAwMTg5oA0GBWBMAQMEoAQMAm5voA8GBWBMAQMHoAYMBGFsb3QwDgYDVR0PAQH/BAQDAgbAMIIBoQYDVR0gBIIBmDCCAZQwggGQBgorBgEEAYO6L2QBMIIBgDCCATYGCCsGAQUFBwICMIIBKAyCASRUaGlzIENlcnRpZmljYXRlIGlzIHNvbGVseSBmb3IgdXNlIHdpdGggUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkIGFuZCBvdGhlciBwYXJ0aWNpcGF0aW5nIG9yZ2FuaXNhdGlvbnMgdXNpbmcgUmFpZGlhbSBTZXJ2aWNlcyBMaW1pdGVkcyBUcnVzdCBGcmFtZXdvcmsgU2VydmljZXMuIEl0cyByZWNlaXB0LCBwb3NzZXNzaW9uIG9yIHVzZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSYWlkaWFtIFNlcnZpY2VzIEx0ZCBDZXJ0aWNpY2F0ZSBQb2xpY3kgYW5kIHJlbGF0ZWQgZG9jdW1lbnRzIHRoZXJlaW4uMEQGCCsGAQUFBwIBFjhodHRwOi8vY3BzLnNhbmRib3gucGtpLm9wZW5iYW5raW5nYnJhc2lsLm9yZy5ici9wb2xpY2llczANBgkqhkiG9w0BAQsFAAOCAQEAtKn/QnJqKLp52YB14x+M21qwz67utFkWjhauQe0elXupjY5NWZb5wLrGYNOZQzRe2JRzcBbGN6P7lCweRfxMkSGh9YrXbrkBXLEPtLHpTVEy65v1tWl02lC+ooVPyQpSjAQL0L69OQ7s7rnIXyb3rkSUzuGSxsLU1AXpWj0oYFB4wdeIdPAVPs83frC5s4kz42JruSAE2vsbvQURTVPChh+hO6+R6Irz+ZEZ1NSgjQkxvOXHW53CkXZSjjHbAB/nbJYi7YyK7kck99r38Ba/WBfIfywdFVVYfiiW5TS6XbQeVeilmmt5MLxBz96FxR6E6WR+cQwybEe94Fb/jD6xHA\u003d\u003d"
      ],
      "alg": "PS256",
      "n": "3IXVqA9zCrmaz30WWjzZexdSuhagP_oVfgB-Y5S7XXeHhU4tho7c3wcNhsrGCKLYSf_47rV78-2OfhPY9WrSJVyqIXoaniwoTnD9splF90J7yog9LgP4kqkWl6wm8gdR5C-UC4Gnl0D2cZKnE6MZ7k_b5nM0ZfC-7H_bO13B4aYpu069th7hFWGK7ps65uiDxcQGYP3oSeqahE5qwfUef2QMkhyVtM_nWP9OVAzOGtJ8km4TdCrq9aF78No9u2YQuaUOJgeOnwKMBjmgEwcuaQe9DEQFXhzBtRmPlml2pTy2QDvxe1HgOTOsnh9igFvX70AGroY3PFY-lJAxC4Fd2w"
    },
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "enc",
      "kid": "0fe502dd-14f0-4f45-80f9-feb9a216f996",
      "alg": "RSA-OAEP",
      "n": "r4dl-ApW6c-fvDbfSVxHpdV8zi8VQW4b9-uHMRq7dzqCkvP8OAG1R3plSr1N6fL_YLiIr9y621XkyRiMEKR7-DeqGsLf2ZTaqrZ1LfYgjsc2i9o3NSOeSgBwKGmT7h1OgxZSbhLzo7Xaktu3CCUZCOWLzs7LKo_CvKkcTF7tPhK9jYjdTsdsnS0RJOPjYQe7JO83Mvhd1Ty3F-Qycd-cKKMSjcQRiHt9jKd09kA2fKVlFwbm2M1PM3NdtnMaOUw31-XC4ixay47XTMqnmX7-op7qYV9wXbeZmjTsAKFuTGwJiGJrOTfqciDLBW8IpGC2BzFJ5rYmRu0kAttpvkOG3Q"
    }
  ]
}
outgoing_path
jwks
2022-01-26 12:00:59 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance GPpmgFZuyrqCeSS
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.7.4 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded",
  "accept-encoding": "gzip, deflate, br",
  "content-length": "1176",
  "connection": "close"
}
incoming_path
/test-mtls/a/upp/token
incoming_body_form_params
{
  "grant_type": "authorization_code",
  "code": "oK2PmSNm1s85UZbv1FYQC6T5YZaOaBI8",
  "redirect_uri": "https://www.upp.com.br/callback",
  "code_verifier": "YVlDhgvfFVZ7PrFOfpeOou-l1JK9-nxbDhtO1yjAJQM",
  "client_id": "upp-bank",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjZmNWI5NWQ4YWZkZmM2OWZlMzdlN2JiOGNiNzAzNDJmMTNhZDQ0ZmVmMWJiODQyNGI5NThkOWFiYzA2OWE4MGQifQ.eyJpYXQiOjE2NDMxOTg0NTksImV4cCI6MTY0MzE5ODUxOSwianRpIjoiNjNQZWVhTUFleVp6RERYX1NHTGpLTHc4dW9kVFI4dVd4Y0pvQ0V6dHZBQSIsImlzcyI6InVwcC1iYW5rIiwic3ViIjoidXBwLWJhbmsiLCJhdWQiOlsiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvdXBwL3Rva2VuIl19.C7kz9uoEzUQR-aKZaNSnTf3ZeJ-wsJLUDZjIqFn8XULtjcd6DANUQ0qGtb9iv1PmXgxAZZoJLs4Q4gyp8K-VjzCvr1ZOIpYLDHJRzkFvcMKybtkmP1NbTkj-khe23vDphdABTjCLFK3S4kwqD3ZyaWurYQkW00W1OmGN7HWve6LJv5mRXfY4Fl6EgPRmX19ZUfY2bojMfRQyOUjG17_SHvk_z94QjJMI0rPZEsxWJz8BoFKDXz_7nBtP_Z4qO4pCANtQlKOmHa7IOYzDWBl5mZDIVI0-1VvN87ZzIE1wdqLznc2uaK2pnfVuMX_HTqrubXZX8T_-gI6S1cBgXokHxg",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw MjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx MDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv bS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg T3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB ARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku l2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97 ULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK j9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv C7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G +cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC zjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP Y3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE QDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu a2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV BgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK BggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw ggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg Zm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg cGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw dCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0 aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy ZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw cy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw DQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj ytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow o5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese 7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq eE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit paZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
grant_type=authorization_code&code=oK2PmSNm1s85UZbv1FYQC6T5YZaOaBI8&redirect_uri=https%3A%2F%2Fwww.upp.com.br%2Fcallback&code_verifier=YVlDhgvfFVZ7PrFOfpeOou-l1JK9-nxbDhtO1yjAJQM&client_id=upp-bank&client_assertion=eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjZmNWI5NWQ4YWZkZmM2OWZlMzdlN2JiOGNiNzAzNDJmMTNhZDQ0ZmVmMWJiODQyNGI5NThkOWFiYzA2OWE4MGQifQ.eyJpYXQiOjE2NDMxOTg0NTksImV4cCI6MTY0MzE5ODUxOSwianRpIjoiNjNQZWVhTUFleVp6RERYX1NHTGpLTHc4dW9kVFI4dVd4Y0pvQ0V6dHZBQSIsImlzcyI6InVwcC1iYW5rIiwic3ViIjoidXBwLWJhbmsiLCJhdWQiOlsiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvdXBwL3Rva2VuIl19.C7kz9uoEzUQR-aKZaNSnTf3ZeJ-wsJLUDZjIqFn8XULtjcd6DANUQ0qGtb9iv1PmXgxAZZoJLs4Q4gyp8K-VjzCvr1ZOIpYLDHJRzkFvcMKybtkmP1NbTkj-khe23vDphdABTjCLFK3S4kwqD3ZyaWurYQkW00W1OmGN7HWve6LJv5mRXfY4Fl6EgPRmX19ZUfY2bojMfRQyOUjG17_SHvk_z94QjJMI0rPZEsxWJz8BoFKDXz_7nBtP_Z4qO4pCANtQlKOmHa7IOYzDWBl5mZDIVI0-1VvN87ZzIE1wdqLznc2uaK2pnfVuMX_HTqrubXZX8T_-gI6S1cBgXokHxg&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2022-01-26 12:00:59 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2022-01-26 12:00:59 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw MjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx MDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv bS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg T3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB ARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku l2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97 ULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK j9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv C7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G +cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC zjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP Y3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE QDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu a2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV BgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK BggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw ggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg Zm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg cGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw dCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0 aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy ZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw cy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw DQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj ytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow o5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese 7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq eE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit paZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw\nMjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx\nMDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv\nbS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg\nT3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB\nARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq\nhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku\nl2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97\nULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK\nj9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv\nC7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G\n+cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC\nzjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP\nY3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE\nQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu\na2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV\nBgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK\nBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw\nggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg\nZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg\ncGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj\nZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw\ndCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0\naGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy\nZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw\ncy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw\nDQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj\nytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow\no5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese\n7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq\neE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit\npaZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003da9767e7d-d0d6-4c9f-826a-6b5ac8bbd7d2,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3335393737303937303030313731,CN\u003dupp.com.br,OU\u003de5b51083-adc2-5775-b0fc-02b263b1c40d,O\u003dUP.P SEP S.A.,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "upp.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2022-01-26 12:00:59 SUCCESS
CheckForClientCertificate
Found client certificate
2022-01-26 12:00:59 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw
MjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx
MDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv
bS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg
T3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB
ARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq
hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku
l2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97
ULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK
j9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv
C7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G
+cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC
zjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP
Y3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE
QDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu
a2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV
BgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK
BggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw
ggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg
Zm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg
cGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj
ZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw
dCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0
aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy
ZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw
cy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw
DQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj
ytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow
o5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese
7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq
eE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit
paZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4=
-----END CERTIFICATE-----
2022-01-26 12:00:59 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjZmNWI5NWQ4YWZkZmM2OWZlMzdlN2JiOGNiNzAzNDJmMTNhZDQ0ZmVmMWJiODQyNGI5NThkOWFiYzA2OWE4MGQifQ.eyJpYXQiOjE2NDMxOTg0NTksImV4cCI6MTY0MzE5ODUxOSwianRpIjoiNjNQZWVhTUFleVp6RERYX1NHTGpLTHc4dW9kVFI4dVd4Y0pvQ0V6dHZBQSIsImlzcyI6InVwcC1iYW5rIiwic3ViIjoidXBwLWJhbmsiLCJhdWQiOlsiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvdXBwL3Rva2VuIl19.C7kz9uoEzUQR-aKZaNSnTf3ZeJ-wsJLUDZjIqFn8XULtjcd6DANUQ0qGtb9iv1PmXgxAZZoJLs4Q4gyp8K-VjzCvr1ZOIpYLDHJRzkFvcMKybtkmP1NbTkj-khe23vDphdABTjCLFK3S4kwqD3ZyaWurYQkW00W1OmGN7HWve6LJv5mRXfY4Fl6EgPRmX19ZUfY2bojMfRQyOUjG17_SHvk_z94QjJMI0rPZEsxWJz8BoFKDXz_7nBtP_Z4qO4pCANtQlKOmHa7IOYzDWBl5mZDIVI0-1VvN87ZzIE1wdqLznc2uaK2pnfVuMX_HTqrubXZX8T_-gI6S1cBgXokHxg",
  "header": {
    "kid": "6f5b95d8afdfc69fe37e7bb8cb70342f13ad44fef1bb8424b958d9abc069a80d",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "upp-bank",
    "aud": [
      "https://www.certification.openid.net/test/a/upp/",
      "https://www.certification.openid.net/test/a/upp/token",
      "https://www.certification.openid.net/test-mtls/a/upp/token"
    ],
    "iss": "upp-bank",
    "exp": 1643198519,
    "iat": 1643198459,
    "jti": "63PeeaMAeyZzDDX_SGLjKLw8uodTR8uWxcJoCEztvAA"
  }
}
2022-01-26 12:00:59
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2022-01-26 12:00:59 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjZmNWI5NWQ4YWZkZmM2OWZlMzdlN2JiOGNiNzAzNDJmMTNhZDQ0ZmVmMWJiODQyNGI5NThkOWFiYzA2OWE4MGQifQ.eyJpYXQiOjE2NDMxOTg0NTksImV4cCI6MTY0MzE5ODUxOSwianRpIjoiNjNQZWVhTUFleVp6RERYX1NHTGpLTHc4dW9kVFI4dVd4Y0pvQ0V6dHZBQSIsImlzcyI6InVwcC1iYW5rIiwic3ViIjoidXBwLWJhbmsiLCJhdWQiOlsiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvdXBwL3Rva2VuIl19.C7kz9uoEzUQR-aKZaNSnTf3ZeJ-wsJLUDZjIqFn8XULtjcd6DANUQ0qGtb9iv1PmXgxAZZoJLs4Q4gyp8K-VjzCvr1ZOIpYLDHJRzkFvcMKybtkmP1NbTkj-khe23vDphdABTjCLFK3S4kwqD3ZyaWurYQkW00W1OmGN7HWve6LJv5mRXfY4Fl6EgPRmX19ZUfY2bojMfRQyOUjG17_SHvk_z94QjJMI0rPZEsxWJz8BoFKDXz_7nBtP_Z4qO4pCANtQlKOmHa7IOYzDWBl5mZDIVI0-1VvN87ZzIE1wdqLznc2uaK2pnfVuMX_HTqrubXZX8T_-gI6S1cBgXokHxg
2022-01-26 12:00:59 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2022-01-26 12:00:59 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2022-01-26 12:00:59 SUCCESS
ValidateAuthorizationCode
Found authorization code
authorization_code
oK2PmSNm1s85UZbv1FYQC6T5YZaOaBI8
2022-01-26 12:00:59 SUCCESS
ValidateRedirectUri
Found redirect uri
redirect_uri
https://www.upp.com.br/callback
2022-01-26 12:00:59 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
ZAwo04eNJkj4EclZJ7ylTbPEZ638yR9GV7g5Mea7PoHENOvZDi
2022-01-26 12:00:59 SUCCESS
CalculateAtHash
Successful at_hash encoding
at_hash
-D5Dxr63b-VAjbTjdP5zdg
2022-01-26 12:00:59
CreateRefreshToken
Created refresh token
refresh_token
ysUxmTyQTnBQAyqYpXybtxvoWSabZhrNSQQETsSDquqvYBMzOU0296628230(+.#-
2022-01-26 12:00:59 SUCCESS
GenerateIdTokenClaims
Created ID Token Claims
iss
https://www.certification.openid.net/test/a/upp/
sub
user-subject-1234531
aud
upp-bank
nonce
MRqZZokpdDEFZCs4BSiGe6Oh367rILCwY-m6fs7M5tA
iat
1643198459
exp
1643198759
2022-01-26 12:00:59 SUCCESS
FAPIBrazilAddCPFAndCPNJToIdTokenClaims
Added claims to id_token claims
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/upp/",
  "sub": "user-subject-1234531",
  "aud": "upp-bank",
  "nonce": "MRqZZokpdDEFZCs4BSiGe6Oh367rILCwY-m6fs7M5tA",
  "iat": 1643198459,
  "exp": 1643198759
}
2022-01-26 12:00:59 SUCCESS
AddAtHashToIdTokenClaims
Added at_hash to ID token claims
at_hash
-D5Dxr63b-VAjbTjdP5zdg
id_token_claims
{
  "iss": "https://www.certification.openid.net/test/a/upp/",
  "sub": "user-subject-1234531",
  "aud": "upp-bank",
  "nonce": "MRqZZokpdDEFZCs4BSiGe6Oh367rILCwY-m6fs7M5tA",
  "iat": 1643198459,
  "exp": 1643198759,
  "at_hash": "-D5Dxr63b-VAjbTjdP5zdg"
}
2022-01-26 12:00:59 SUCCESS
FAPIBrazilAddACRClaimToIdTokenClaims
Added acr value to id_token_claims
acr_value
urn:brasil:openbanking:loa2
claims
{
  "iss": "https://www.certification.openid.net/test/a/upp/",
  "sub": "user-subject-1234531",
  "aud": "upp-bank",
  "nonce": "MRqZZokpdDEFZCs4BSiGe6Oh367rILCwY-m6fs7M5tA",
  "iat": 1643198459,
  "exp": 1643198759,
  "at_hash": "-D5Dxr63b-VAjbTjdP5zdg",
  "acr": "urn:brasil:openbanking:loa2"
}
2022-01-26 12:00:59 SUCCESS
SignIdToken
Signed the ID token
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdF9oYXNoIjoiLUQ1RHhyNjNiLVZBamJUamRQNXpkZyIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoidXBwLWJhbmsiLCJhY3IiOiJ1cm46YnJhc2lsOm9wZW5iYW5raW5nOmxvYTIiLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvdXBwXC8iLCJleHAiOjE2NDMxOTg3NTksIm5vbmNlIjoiTVJxWlpva3BkREVGWkNzNEJTaUdlNk9oMzY3cklMQ3dZLW02ZnM3TTV0QSIsImlhdCI6MTY0MzE5ODQ1OX0.u_W-msSbPPRhp4TcVeRhg21lD9xiex1qGKdnqBr_bDTIG3-9NKsCM-27lh4LQ1IwJlljzDInK88YPNk4pZJfL-rth9k0VHMDfNcez5P9pV0kh82H8WG8QrJw3W7ROl6xDS5guT73a9JQbWaANwjTyS_wsv4be8lLzKWhxsD5AVGxslTz9j9jmUOldndeCC1_DzWB4b_GR4VpoHcH_eJuZrUiGJ-kP1jTO5jK0JS17B88iJq94LLcI7oIqzmbpgAJ374HeHyeI0lJrStvDJMQZyBOuY9E46eSjnrnt1kq0tYRxDYvw2jhARLNTXzauBMHwq3297ezVGvIy1jtGf8wXA
2022-01-26 12:00:59 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
ZAwo04eNJkj4EclZJ7ylTbPEZ638yR9GV7g5Mea7PoHENOvZDi
token_type
Bearer
id_token
eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdF9oYXNoIjoiLUQ1RHhyNjNiLVZBamJUamRQNXpkZyIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoidXBwLWJhbmsiLCJhY3IiOiJ1cm46YnJhc2lsOm9wZW5iYW5raW5nOmxvYTIiLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvdXBwXC8iLCJleHAiOjE2NDMxOTg3NTksIm5vbmNlIjoiTVJxWlpva3BkREVGWkNzNEJTaUdlNk9oMzY3cklMQ3dZLW02ZnM3TTV0QSIsImlhdCI6MTY0MzE5ODQ1OX0.u_W-msSbPPRhp4TcVeRhg21lD9xiex1qGKdnqBr_bDTIG3-9NKsCM-27lh4LQ1IwJlljzDInK88YPNk4pZJfL-rth9k0VHMDfNcez5P9pV0kh82H8WG8QrJw3W7ROl6xDS5guT73a9JQbWaANwjTyS_wsv4be8lLzKWhxsD5AVGxslTz9j9jmUOldndeCC1_DzWB4b_GR4VpoHcH_eJuZrUiGJ-kP1jTO5jK0JS17B88iJq94LLcI7oIqzmbpgAJ374HeHyeI0lJrStvDJMQZyBOuY9E46eSjnrnt1kq0tYRxDYvw2jhARLNTXzauBMHwq3297ezVGvIy1jtGf8wXA
refresh_token
ysUxmTyQTnBQAyqYpXybtxvoWSabZhrNSQQETsSDquqvYBMzOU0296628230(+.#-
scope
openid consent:urn:conformance.oidf:nBdEgirzZh accounts resources
2022-01-26 12:00:59
RemoveIssuedAccessTokenFromEnvironment
Removed access_token and token_type from environment
2022-01-26 12:00:59 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance GPpmgFZuyrqCeSS
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "ZAwo04eNJkj4EclZJ7ylTbPEZ638yR9GV7g5Mea7PoHENOvZDi",
  "token_type": "Bearer",
  "id_token": "eyJraWQiOiJYNWQ0dkZZZkx4YUcxZ2c4X2wzYkZZRmhVYVVWbUU2UGFFc1JXWDJFWXFNIiwiYWxnIjoiUFMyNTYifQ.eyJhdF9oYXNoIjoiLUQ1RHhyNjNiLVZBamJUamRQNXpkZyIsInN1YiI6InVzZXItc3ViamVjdC0xMjM0NTMxIiwiYXVkIjoidXBwLWJhbmsiLCJhY3IiOiJ1cm46YnJhc2lsOm9wZW5iYW5raW5nOmxvYTIiLCJpc3MiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvdXBwXC8iLCJleHAiOjE2NDMxOTg3NTksIm5vbmNlIjoiTVJxWlpva3BkREVGWkNzNEJTaUdlNk9oMzY3cklMQ3dZLW02ZnM3TTV0QSIsImlhdCI6MTY0MzE5ODQ1OX0.u_W-msSbPPRhp4TcVeRhg21lD9xiex1qGKdnqBr_bDTIG3-9NKsCM-27lh4LQ1IwJlljzDInK88YPNk4pZJfL-rth9k0VHMDfNcez5P9pV0kh82H8WG8QrJw3W7ROl6xDS5guT73a9JQbWaANwjTyS_wsv4be8lLzKWhxsD5AVGxslTz9j9jmUOldndeCC1_DzWB4b_GR4VpoHcH_eJuZrUiGJ-kP1jTO5jK0JS17B88iJq94LLcI7oIqzmbpgAJ374HeHyeI0lJrStvDJMQZyBOuY9E46eSjnrnt1kq0tYRxDYvw2jhARLNTXzauBMHwq3297ezVGvIy1jtGf8wXA",
  "refresh_token": "ysUxmTyQTnBQAyqYpXybtxvoWSabZhrNSQQETsSDquqvYBMzOU0296628230(+.#-",
  "scope": "openid consent:urn:conformance.oidf:nBdEgirzZh accounts resources"
}
outgoing_path
token
2022-01-26 12:01:00 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance GPpmgFZuyrqCeSS
incoming_headers
{
  "host": "www.certification.openid.net",
  "authorization": "Bearer ZAwo04eNJkj4EclZJ7ylTbPEZ638yR9GV7g5Mea7PoHENOvZDi",
  "user-agent": "PostmanRuntime/7.28.4",
  "accept": "*/*",
  "cache-control": "no-cache",
  "postman-token": "0ada860e-ffb8-4f38-a694-72e5fb5b6952",
  "accept-encoding": "gzip, deflate, br",
  "cookie": "JSESSIONID\u003d4C56BC2B47D767CFA1F7A812A43CD278",
  "connection": "close"
}
incoming_path
/test-mtls/a/upp/accounts/v1/accounts
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw MjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx MDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv bS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg T3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB ARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku l2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97 ULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK j9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv C7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G +cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC zjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP Y3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE QDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu a2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV BgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK BggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw ggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg Zm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg cGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw dCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0 aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy ZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw cy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw DQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj ytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow o5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese 7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq eE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit paZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
2022-01-26 12:01:00 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Accounts endpoint (always rejected)
2022-01-26 12:01:00 SUCCESS
LogAccessTokenAlwaysRejectedToForceARefreshGrant
This call will be always rejected. The client must obtain a new access token twice using the refresh_token
2022-01-26 12:01:00 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance GPpmgFZuyrqCeSS
outgoing_status_code
401
outgoing_headers
{
  "WWW-Authenticate": [
    "Bearer realm\u003d\"conformancesuite\", error\u003d\"invalid_token\", error_description\u003d\"Invalid access token. This test requires you to obtain a new access token twice using the refresh_token\""
  ]
}
outgoing_body
outgoing_path
accounts/v1/accounts
2022-01-26 12:01:00 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance GPpmgFZuyrqCeSS
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.7.4 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/upp/.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2022-01-26 12:01:00 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2022-01-26 12:01:00 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance GPpmgFZuyrqCeSS
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/upp/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/upp/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/upp/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/upp/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/upp/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/upp/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ],
  "response_types_supported": [
    "code"
  ],
  "response_modes_supported": [
    "jwt"
  ],
  "authorization_signing_alg_values_supported": [
    "PS256"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256"
  ]
}
outgoing_path
.well-known/openid-configuration
2022-01-26 12:01:00 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance GPpmgFZuyrqCeSS
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.7.4 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded",
  "accept-encoding": "gzip, deflate, br",
  "content-length": "1108",
  "connection": "close"
}
incoming_path
/test-mtls/a/upp/token
incoming_body_form_params
{
  "grant_type": "refresh_token",
  "refresh_token": "ysUxmTyQTnBQAyqYpXybtxvoWSabZhrNSQQETsSDquqvYBMzOU0296628230(+.#-",
  "client_id": "upp-bank",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjZmNWI5NWQ4YWZkZmM2OWZlMzdlN2JiOGNiNzAzNDJmMTNhZDQ0ZmVmMWJiODQyNGI5NThkOWFiYzA2OWE4MGQifQ.eyJpYXQiOjE2NDMxOTg0NjAsImV4cCI6MTY0MzE5ODUyMCwianRpIjoiX1B1RTNLUURfRmtKbEgxWjJDYTZuV05jUVZySVRXSUlrRVJWUzFic0V4dyIsImlzcyI6InVwcC1iYW5rIiwic3ViIjoidXBwLWJhbmsiLCJhdWQiOlsiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvdXBwL3Rva2VuIl19.qi0ZzHcGHXov5UTsHsq1F9TSWcXo7FCWJCFWIFblDePNK7jQJ-W9F1bZS3zHekwdMRzxMC_CGz3vna8dlmWZuIpR8GIyiY5CJEyWpHV6d6dd5kLFH_HO_5iDTlSR71lgBVC7Klw_Hep8QIdvgWSpXb1vJF5q7mBFhaHx17qwrROG9oLk1uDvIhg5fiJOzvkwR471m-DbQk7Iot2MXfn_o81NkO-sLcq3TWQVmdNOgCY2T4t_oVbz-WnDNnY1uImm57vpDQd1C3PbqJifB7dfSFPJI5yeBLSfab_iUg_hy0JDEKBGHVdHRe4iQUutHKha_SYOS0POPVkxXv1SnzhkdQ",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw MjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx MDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv bS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg T3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB ARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku l2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97 ULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK j9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv C7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G +cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC zjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP Y3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE QDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu a2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV BgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK BggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw ggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg Zm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg cGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw dCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0 aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy ZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw cy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw DQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj ytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow o5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese 7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq eE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit paZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
grant_type=refresh_token&refresh_token=ysUxmTyQTnBQAyqYpXybtxvoWSabZhrNSQQETsSDquqvYBMzOU0296628230%28%2B.%23-&client_id=upp-bank&client_assertion=eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjZmNWI5NWQ4YWZkZmM2OWZlMzdlN2JiOGNiNzAzNDJmMTNhZDQ0ZmVmMWJiODQyNGI5NThkOWFiYzA2OWE4MGQifQ.eyJpYXQiOjE2NDMxOTg0NjAsImV4cCI6MTY0MzE5ODUyMCwianRpIjoiX1B1RTNLUURfRmtKbEgxWjJDYTZuV05jUVZySVRXSUlrRVJWUzFic0V4dyIsImlzcyI6InVwcC1iYW5rIiwic3ViIjoidXBwLWJhbmsiLCJhdWQiOlsiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvdXBwL3Rva2VuIl19.qi0ZzHcGHXov5UTsHsq1F9TSWcXo7FCWJCFWIFblDePNK7jQJ-W9F1bZS3zHekwdMRzxMC_CGz3vna8dlmWZuIpR8GIyiY5CJEyWpHV6d6dd5kLFH_HO_5iDTlSR71lgBVC7Klw_Hep8QIdvgWSpXb1vJF5q7mBFhaHx17qwrROG9oLk1uDvIhg5fiJOzvkwR471m-DbQk7Iot2MXfn_o81NkO-sLcq3TWQVmdNOgCY2T4t_oVbz-WnDNnY1uImm57vpDQd1C3PbqJifB7dfSFPJI5yeBLSfab_iUg_hy0JDEKBGHVdHRe4iQUutHKha_SYOS0POPVkxXv1SnzhkdQ&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2022-01-26 12:01:00 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2022-01-26 12:01:00 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw MjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx MDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv bS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg T3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB ARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku l2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97 ULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK j9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv C7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G +cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC zjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP Y3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE QDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu a2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV BgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK BggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw ggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg Zm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg cGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw dCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0 aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy ZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw cy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw DQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj ytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow o5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese 7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq eE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit paZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw\nMjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx\nMDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv\nbS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg\nT3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB\nARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq\nhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku\nl2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97\nULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK\nj9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv\nC7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G\n+cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC\nzjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP\nY3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE\nQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu\na2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV\nBgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK\nBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw\nggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg\nZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg\ncGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj\nZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw\ndCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0\naGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy\nZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw\ncy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw\nDQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj\nytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow\no5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese\n7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq\neE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit\npaZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003da9767e7d-d0d6-4c9f-826a-6b5ac8bbd7d2,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3335393737303937303030313731,CN\u003dupp.com.br,OU\u003de5b51083-adc2-5775-b0fc-02b263b1c40d,O\u003dUP.P SEP S.A.,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "upp.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2022-01-26 12:01:00 SUCCESS
CheckForClientCertificate
Found client certificate
2022-01-26 12:01:00 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw
MjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx
MDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv
bS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg
T3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB
ARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq
hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku
l2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97
ULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK
j9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv
C7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G
+cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC
zjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP
Y3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE
QDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu
a2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV
BgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK
BggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw
ggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg
Zm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg
cGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj
ZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw
dCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0
aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy
ZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw
cy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw
DQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj
ytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow
o5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese
7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq
eE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit
paZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4=
-----END CERTIFICATE-----
2022-01-26 12:01:00 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjZmNWI5NWQ4YWZkZmM2OWZlMzdlN2JiOGNiNzAzNDJmMTNhZDQ0ZmVmMWJiODQyNGI5NThkOWFiYzA2OWE4MGQifQ.eyJpYXQiOjE2NDMxOTg0NjAsImV4cCI6MTY0MzE5ODUyMCwianRpIjoiX1B1RTNLUURfRmtKbEgxWjJDYTZuV05jUVZySVRXSUlrRVJWUzFic0V4dyIsImlzcyI6InVwcC1iYW5rIiwic3ViIjoidXBwLWJhbmsiLCJhdWQiOlsiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvdXBwL3Rva2VuIl19.qi0ZzHcGHXov5UTsHsq1F9TSWcXo7FCWJCFWIFblDePNK7jQJ-W9F1bZS3zHekwdMRzxMC_CGz3vna8dlmWZuIpR8GIyiY5CJEyWpHV6d6dd5kLFH_HO_5iDTlSR71lgBVC7Klw_Hep8QIdvgWSpXb1vJF5q7mBFhaHx17qwrROG9oLk1uDvIhg5fiJOzvkwR471m-DbQk7Iot2MXfn_o81NkO-sLcq3TWQVmdNOgCY2T4t_oVbz-WnDNnY1uImm57vpDQd1C3PbqJifB7dfSFPJI5yeBLSfab_iUg_hy0JDEKBGHVdHRe4iQUutHKha_SYOS0POPVkxXv1SnzhkdQ",
  "header": {
    "kid": "6f5b95d8afdfc69fe37e7bb8cb70342f13ad44fef1bb8424b958d9abc069a80d",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "upp-bank",
    "aud": [
      "https://www.certification.openid.net/test/a/upp/",
      "https://www.certification.openid.net/test/a/upp/token",
      "https://www.certification.openid.net/test-mtls/a/upp/token"
    ],
    "iss": "upp-bank",
    "exp": 1643198520,
    "iat": 1643198460,
    "jti": "_PuE3KQD_FkJlH1Z2Ca6nWNcQVrITWIIkERVS1bsExw"
  }
}
2022-01-26 12:01:00
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2022-01-26 12:01:00 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjZmNWI5NWQ4YWZkZmM2OWZlMzdlN2JiOGNiNzAzNDJmMTNhZDQ0ZmVmMWJiODQyNGI5NThkOWFiYzA2OWE4MGQifQ.eyJpYXQiOjE2NDMxOTg0NjAsImV4cCI6MTY0MzE5ODUyMCwianRpIjoiX1B1RTNLUURfRmtKbEgxWjJDYTZuV05jUVZySVRXSUlrRVJWUzFic0V4dyIsImlzcyI6InVwcC1iYW5rIiwic3ViIjoidXBwLWJhbmsiLCJhdWQiOlsiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvdXBwL3Rva2VuIl19.qi0ZzHcGHXov5UTsHsq1F9TSWcXo7FCWJCFWIFblDePNK7jQJ-W9F1bZS3zHekwdMRzxMC_CGz3vna8dlmWZuIpR8GIyiY5CJEyWpHV6d6dd5kLFH_HO_5iDTlSR71lgBVC7Klw_Hep8QIdvgWSpXb1vJF5q7mBFhaHx17qwrROG9oLk1uDvIhg5fiJOzvkwR471m-DbQk7Iot2MXfn_o81NkO-sLcq3TWQVmdNOgCY2T4t_oVbz-WnDNnY1uImm57vpDQd1C3PbqJifB7dfSFPJI5yeBLSfab_iUg_hy0JDEKBGHVdHRe4iQUutHKha_SYOS0POPVkxXv1SnzhkdQ
2022-01-26 12:01:00 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2022-01-26 12:01:00 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2022-01-26 12:01:00 SUCCESS
ValidateRefreshToken
refresh_token parameter matches the expected value.
refresh_token
ysUxmTyQTnBQAyqYpXybtxvoWSabZhrNSQQETsSDquqvYBMzOU0296628230(+.#-
2022-01-26 12:01:00 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
zoylvFb9ZMWph0vF0tI7z6QdBbaE7QwYrjoU069eUapE1IrHDf
2022-01-26 12:01:00 SUCCESS
CalculateAtHash
Successful at_hash encoding
at_hash
mWn_GHIXrEbRbihmmMeszw
2022-01-26 12:01:00
CreateRefreshToken
Created refresh token
refresh_token
mUHPDwFWlttelvUMivYqXgiFVqpxyLJPaMDDKdNJCTriXTHnRy7079599745>>$[>
2022-01-26 12:01:00 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
zoylvFb9ZMWph0vF0tI7z6QdBbaE7QwYrjoU069eUapE1IrHDf
token_type
Bearer
refresh_token
mUHPDwFWlttelvUMivYqXgiFVqpxyLJPaMDDKdNJCTriXTHnRy7079599745>>$[>
scope
openid consent:urn:conformance.oidf:nBdEgirzZh accounts resources
2022-01-26 12:01:00 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance GPpmgFZuyrqCeSS
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "zoylvFb9ZMWph0vF0tI7z6QdBbaE7QwYrjoU069eUapE1IrHDf",
  "token_type": "Bearer",
  "refresh_token": "mUHPDwFWlttelvUMivYqXgiFVqpxyLJPaMDDKdNJCTriXTHnRy7079599745\u003e\u003e$[\u003e",
  "scope": "openid consent:urn:conformance.oidf:nBdEgirzZh accounts resources"
}
outgoing_path
token
2022-01-26 12:01:01 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance GPpmgFZuyrqCeSS
incoming_headers
{
  "host": "www.certification.openid.net",
  "authorization": "Bearer zoylvFb9ZMWph0vF0tI7z6QdBbaE7QwYrjoU069eUapE1IrHDf",
  "user-agent": "PostmanRuntime/7.28.4",
  "accept": "*/*",
  "cache-control": "no-cache",
  "postman-token": "03c25a93-f114-47bc-87b6-304b14a3f451",
  "accept-encoding": "gzip, deflate, br",
  "cookie": "JSESSIONID\u003d4C56BC2B47D767CFA1F7A812A43CD278",
  "connection": "close"
}
incoming_path
/test-mtls/a/upp/accounts/v1/accounts
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw MjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx MDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv bS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg T3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB ARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku l2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97 ULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK j9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv C7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G +cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC zjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP Y3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE QDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu a2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV BgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK BggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw ggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg Zm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg cGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw dCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0 aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy ZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw cy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw DQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj ytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow o5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese 7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq eE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit paZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
2022-01-26 12:01:01 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Accounts endpoint (always rejected)
2022-01-26 12:01:01 SUCCESS
LogAccessTokenAlwaysRejectedToForceARefreshGrant
This call will be always rejected. The client must obtain a new access token twice using the refresh_token
2022-01-26 12:01:01 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance GPpmgFZuyrqCeSS
outgoing_status_code
401
outgoing_headers
{
  "WWW-Authenticate": [
    "Bearer realm\u003d\"conformancesuite\", error\u003d\"invalid_token\", error_description\u003d\"Invalid access token. This test requires you to obtain a new access token twice using the refresh_token\""
  ]
}
outgoing_body
outgoing_path
accounts/v1/accounts
2022-01-26 12:01:01 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance GPpmgFZuyrqCeSS
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.7.4 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "accept-encoding": "gzip, deflate, br",
  "connection": "close"
}
incoming_path
/test/a/upp/.well-known/openid-configuration
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
incoming_body_json
incoming_query_string_params
{}
incoming_body
2022-01-26 12:01:01 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
2022-01-26 12:01:01 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance GPpmgFZuyrqCeSS
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "issuer": "https://www.certification.openid.net/test/a/upp/",
  "authorization_endpoint": "https://www.certification.openid.net/test/a/upp/authorize",
  "token_endpoint": "https://www.certification.openid.net/test/a/upp/token",
  "jwks_uri": "https://www.certification.openid.net/test/a/upp/jwks",
  "registration_endpoint": "https://www.certification.openid.net/test/a/upp/register",
  "userinfo_endpoint": "https://www.certification.openid.net/test/a/upp/userinfo",
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/token",
    "registration_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/register",
    "userinfo_endpoint": "https://www.certification.openid.net/test-mtls/a/upp/userinfo"
  },
  "tls_client_certificate_bound_access_tokens": true,
  "request_parameter_supported": true,
  "grant_types_supported": [
    "authorization_code",
    "implicit",
    "client_credentials",
    "refresh_token"
  ],
  "claims_parameter_supported": true,
  "request_object_encryption_alg_values_supported": [
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A256GCM"
  ],
  "claims_supported": [
    "cpf",
    "cnpj",
    "acr"
  ],
  "acr_values_supported": [
    "urn:brasil:openbanking:loa2",
    "urn:brasil:openbanking:loa3"
  ],
  "id_token_signing_alg_values_supported": [
    "PS256"
  ],
  "request_object_signing_alg_values_supported": [
    "PS256"
  ],
  "scopes_supported": [
    "openid",
    "phone",
    "profile",
    "email",
    "address",
    "offline_access",
    "consents",
    "resources",
    "payments"
  ],
  "token_endpoint_auth_methods_supported": [
    "private_key_jwt"
  ],
  "response_types_supported": [
    "code"
  ],
  "response_modes_supported": [
    "jwt"
  ],
  "authorization_signing_alg_values_supported": [
    "PS256"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "PS256"
  ]
}
outgoing_path
.well-known/openid-configuration
2022-01-26 12:01:01 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance GPpmgFZuyrqCeSS
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "openid-client/4.7.4 (https://github.com/panva/node-openid-client)",
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded",
  "accept-encoding": "gzip, deflate, br",
  "content-length": "1112",
  "connection": "close"
}
incoming_path
/test-mtls/a/upp/token
incoming_body_form_params
{
  "grant_type": "refresh_token",
  "refresh_token": "mUHPDwFWlttelvUMivYqXgiFVqpxyLJPaMDDKdNJCTriXTHnRy7079599745\u003e\u003e$[\u003e",
  "client_id": "upp-bank",
  "client_assertion": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjZmNWI5NWQ4YWZkZmM2OWZlMzdlN2JiOGNiNzAzNDJmMTNhZDQ0ZmVmMWJiODQyNGI5NThkOWFiYzA2OWE4MGQifQ.eyJpYXQiOjE2NDMxOTg0NjEsImV4cCI6MTY0MzE5ODUyMSwianRpIjoiT01ydlhWS2k2YU82WC1CdnFON3dUOGdUclp2VEVhcEcxS3JMZEJLMGRSOCIsImlzcyI6InVwcC1iYW5rIiwic3ViIjoidXBwLWJhbmsiLCJhdWQiOlsiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvdXBwL3Rva2VuIl19.i_QZrLSIQDoeVkYmG-Abcs4qSU3QRFEkFDb8ROUfLHdQhD2hbvi2fBOjhAyypAmKeopVsJUYPheXa9PTYN70tliGhM25pNQ3kU7syBcIkuliS2Fm6K8nlMuK_aKri2Ihiwqodk3qEp2uYAHxkVoJRW2G0_O0NehNhhkuQWDk3wkplXlV_wXMgje9QdAUpgsDMCvvx-fEKtKyVNc9WGsuZnGKHZqn_1PM9Fyj-oO_A5O_q1zJ3WLZKtQ5U45aFaxN7Fu3sFdCmN9l_W1Vm4lNzLC-GLbqhQgllYeDPYeuWTV8ft31Zc7tsOSugpJ-dyyEU8NWz0dFh2y2EwtS99-1sw",
  "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer"
}
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw MjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx MDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv bS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg T3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB ARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku l2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97 ULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK j9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv C7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G +cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC zjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP Y3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE QDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu a2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV BgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK BggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw ggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg Zm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg cGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw dCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0 aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy ZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw cy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw DQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj ytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow o5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese 7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq eE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit paZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
grant_type=refresh_token&refresh_token=mUHPDwFWlttelvUMivYqXgiFVqpxyLJPaMDDKdNJCTriXTHnRy7079599745%3E%3E%24%5B%3E&client_id=upp-bank&client_assertion=eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjZmNWI5NWQ4YWZkZmM2OWZlMzdlN2JiOGNiNzAzNDJmMTNhZDQ0ZmVmMWJiODQyNGI5NThkOWFiYzA2OWE4MGQifQ.eyJpYXQiOjE2NDMxOTg0NjEsImV4cCI6MTY0MzE5ODUyMSwianRpIjoiT01ydlhWS2k2YU82WC1CdnFON3dUOGdUclp2VEVhcEcxS3JMZEJLMGRSOCIsImlzcyI6InVwcC1iYW5rIiwic3ViIjoidXBwLWJhbmsiLCJhdWQiOlsiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvdXBwL3Rva2VuIl19.i_QZrLSIQDoeVkYmG-Abcs4qSU3QRFEkFDb8ROUfLHdQhD2hbvi2fBOjhAyypAmKeopVsJUYPheXa9PTYN70tliGhM25pNQ3kU7syBcIkuliS2Fm6K8nlMuK_aKri2Ihiwqodk3qEp2uYAHxkVoJRW2G0_O0NehNhhkuQWDk3wkplXlV_wXMgje9QdAUpgsDMCvvx-fEKtKyVNc9WGsuZnGKHZqn_1PM9Fyj-oO_A5O_q1zJ3WLZKtQ5U45aFaxN7Fu3sFdCmN9l_W1Vm4lNzLC-GLbqhQgllYeDPYeuWTV8ft31Zc7tsOSugpJ-dyyEU8NWz0dFh2y2EwtS99-1sw&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2022-01-26 12:01:01 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Token endpoint
2022-01-26 12:01:01 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw MjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx MDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv bS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg T3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB ARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku l2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97 ULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK j9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv C7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G +cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC zjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP Y3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE QDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu a2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV BgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK BggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw ggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg Zm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg cGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw dCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0 aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy ZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw cy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw DQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj ytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow o5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese 7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq eE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit paZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw\nMjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx\nMDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv\nbS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg\nT3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB\nARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq\nhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku\nl2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97\nULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK\nj9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv\nC7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G\n+cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC\nzjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP\nY3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE\nQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu\na2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV\nBgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK\nBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw\nggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg\nZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg\ncGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj\nZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw\ndCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0\naGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy\nZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw\ncy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw\nDQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj\nytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow\no5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese\n7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq\neE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit\npaZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003da9767e7d-d0d6-4c9f-826a-6b5ac8bbd7d2,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3335393737303937303030313731,CN\u003dupp.com.br,OU\u003de5b51083-adc2-5775-b0fc-02b263b1c40d,O\u003dUP.P SEP S.A.,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "upp.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2022-01-26 12:01:01 SUCCESS
CheckForClientCertificate
Found client certificate
2022-01-26 12:01:01 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw
MjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx
MDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv
bS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg
T3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB
ARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq
hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku
l2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97
ULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK
j9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv
C7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G
+cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC
zjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP
Y3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE
QDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu
a2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV
BgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK
BggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw
ggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg
Zm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg
cGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj
ZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw
dCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0
aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy
ZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw
cy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw
DQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj
ytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow
o5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese
7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq
eE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit
paZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4=
-----END CERTIFICATE-----
2022-01-26 12:01:01 SUCCESS
ExtractClientAssertion
Parsed client assertion
client_assertion
{
  "value": "eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjZmNWI5NWQ4YWZkZmM2OWZlMzdlN2JiOGNiNzAzNDJmMTNhZDQ0ZmVmMWJiODQyNGI5NThkOWFiYzA2OWE4MGQifQ.eyJpYXQiOjE2NDMxOTg0NjEsImV4cCI6MTY0MzE5ODUyMSwianRpIjoiT01ydlhWS2k2YU82WC1CdnFON3dUOGdUclp2VEVhcEcxS3JMZEJLMGRSOCIsImlzcyI6InVwcC1iYW5rIiwic3ViIjoidXBwLWJhbmsiLCJhdWQiOlsiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvdXBwL3Rva2VuIl19.i_QZrLSIQDoeVkYmG-Abcs4qSU3QRFEkFDb8ROUfLHdQhD2hbvi2fBOjhAyypAmKeopVsJUYPheXa9PTYN70tliGhM25pNQ3kU7syBcIkuliS2Fm6K8nlMuK_aKri2Ihiwqodk3qEp2uYAHxkVoJRW2G0_O0NehNhhkuQWDk3wkplXlV_wXMgje9QdAUpgsDMCvvx-fEKtKyVNc9WGsuZnGKHZqn_1PM9Fyj-oO_A5O_q1zJ3WLZKtQ5U45aFaxN7Fu3sFdCmN9l_W1Vm4lNzLC-GLbqhQgllYeDPYeuWTV8ft31Zc7tsOSugpJ-dyyEU8NWz0dFh2y2EwtS99-1sw",
  "header": {
    "kid": "6f5b95d8afdfc69fe37e7bb8cb70342f13ad44fef1bb8424b958d9abc069a80d",
    "typ": "JWT",
    "alg": "PS256"
  },
  "claims": {
    "sub": "upp-bank",
    "aud": [
      "https://www.certification.openid.net/test/a/upp/",
      "https://www.certification.openid.net/test/a/upp/token",
      "https://www.certification.openid.net/test-mtls/a/upp/token"
    ],
    "iss": "upp-bank",
    "exp": 1643198521,
    "iat": 1643198461,
    "jti": "OMrvXVKi6aO6X-BvqN7wT8gTrZvTEapG1KrLdBK0dR8"
  }
}
2022-01-26 12:01:01
EnsureClientAssertionSignatureAlgorithmMatchesRegistered
token_endpoint_auth_signing_alg is not set for the client, any supported algorithm can be used
2022-01-26 12:01:01 SUCCESS
ValidateClientAssertionSignature
client_assertion signature validated
client_assertion
eyJhbGciOiJQUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjZmNWI5NWQ4YWZkZmM2OWZlMzdlN2JiOGNiNzAzNDJmMTNhZDQ0ZmVmMWJiODQyNGI5NThkOWFiYzA2OWE4MGQifQ.eyJpYXQiOjE2NDMxOTg0NjEsImV4cCI6MTY0MzE5ODUyMSwianRpIjoiT01ydlhWS2k2YU82WC1CdnFON3dUOGdUclp2VEVhcEcxS3JMZEJLMGRSOCIsImlzcyI6InVwcC1iYW5rIiwic3ViIjoidXBwLWJhbmsiLCJhdWQiOlsiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvIiwiaHR0cHM6Ly93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0L3Rlc3QvYS91cHAvdG9rZW4iLCJodHRwczovL3d3dy5jZXJ0aWZpY2F0aW9uLm9wZW5pZC5uZXQvdGVzdC1tdGxzL2EvdXBwL3Rva2VuIl19.i_QZrLSIQDoeVkYmG-Abcs4qSU3QRFEkFDb8ROUfLHdQhD2hbvi2fBOjhAyypAmKeopVsJUYPheXa9PTYN70tliGhM25pNQ3kU7syBcIkuliS2Fm6K8nlMuK_aKri2Ihiwqodk3qEp2uYAHxkVoJRW2G0_O0NehNhhkuQWDk3wkplXlV_wXMgje9QdAUpgsDMCvvx-fEKtKyVNc9WGsuZnGKHZqn_1PM9Fyj-oO_A5O_q1zJ3WLZKtQ5U45aFaxN7Fu3sFdCmN9l_W1Vm4lNzLC-GLbqhQgllYeDPYeuWTV8ft31Zc7tsOSugpJ-dyyEU8NWz0dFh2y2EwtS99-1sw
2022-01-26 12:01:01 SUCCESS
EnsureClientAssertionTypeIsJwt
Found JWT assertion type
assertion type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2022-01-26 12:01:01 SUCCESS
ValidateClientAssertionClaims
Client Assertion passed all validation checks
2022-01-26 12:01:01 SUCCESS
ValidateRefreshToken
refresh_token parameter matches the expected value.
refresh_token
mUHPDwFWlttelvUMivYqXgiFVqpxyLJPaMDDKdNJCTriXTHnRy7079599745>>$[>
2022-01-26 12:01:01 SUCCESS
GenerateBearerAccessToken
Generated access token
access_token
QP0v2fr2DPNa8NGUu8PlUy3Mg025hSLgpLbGvqtMEcOFPiKIOs
2022-01-26 12:01:01 SUCCESS
CalculateAtHash
Successful at_hash encoding
at_hash
oR7PAmClzL2P5qCV-s0L7A
2022-01-26 12:01:01
CreateRefreshToken
Created refresh token
refresh_token
sEOJJwHlkqYAARJcqbxBKmLFxytMAVbkecswRgYCVvHLDnaQHE5375332028;{?%_
2022-01-26 12:01:01 SUCCESS
CreateTokenEndpointResponse
Created token endpoint response
access_token
QP0v2fr2DPNa8NGUu8PlUy3Mg025hSLgpLbGvqtMEcOFPiKIOs
token_type
Bearer
refresh_token
sEOJJwHlkqYAARJcqbxBKmLFxytMAVbkecswRgYCVvHLDnaQHE5375332028;{?%_
scope
openid consent:urn:conformance.oidf:nBdEgirzZh accounts resources
2022-01-26 12:01:01 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance GPpmgFZuyrqCeSS
outgoing_status_code
200
outgoing_headers
{}
outgoing_body
{
  "access_token": "QP0v2fr2DPNa8NGUu8PlUy3Mg025hSLgpLbGvqtMEcOFPiKIOs",
  "token_type": "Bearer",
  "refresh_token": "sEOJJwHlkqYAARJcqbxBKmLFxytMAVbkecswRgYCVvHLDnaQHE5375332028;{?%_",
  "scope": "openid consent:urn:conformance.oidf:nBdEgirzZh accounts resources"
}
outgoing_path
token
2022-01-26 12:01:01 INCOMING
fapi1-advanced-final-client-refresh-token-test
Incoming HTTP request to test instance GPpmgFZuyrqCeSS
incoming_headers
{
  "host": "www.certification.openid.net",
  "authorization": "Bearer QP0v2fr2DPNa8NGUu8PlUy3Mg025hSLgpLbGvqtMEcOFPiKIOs",
  "user-agent": "PostmanRuntime/7.28.4",
  "accept": "*/*",
  "cache-control": "no-cache",
  "postman-token": "19ec9c1b-4565-4001-85c9-4e2cffc6179f",
  "accept-encoding": "gzip, deflate, br",
  "cookie": "JSESSIONID\u003d4C56BC2B47D767CFA1F7A812A43CD278",
  "connection": "close"
}
incoming_path
/test-mtls/a/upp/accounts/v1/accounts
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_tls_cert
-----BEGIN CERTIFICATE----- MIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw MjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx MDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv bS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg T3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB ARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku l2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97 ULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK j9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv C7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G +cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC zjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP Y3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE QDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu a2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV BgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK BggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw ggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg Zm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg cGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw dCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0 aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy ZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw cy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw DQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj ytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow o5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese 7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq eE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit paZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4= -----END CERTIFICATE-----
incoming_body_json
incoming_query_string_params
{}
incoming_body
2022-01-26 12:01:01 SUCCESS
EnsureIncomingTls12WithSecureCipherOrTls13
TLS 1.2 in use and cipher is one recommended by BCP195
actual
ECDHE-RSA-AES128-GCM-SHA256
recommended
[
  "DHE-RSA-AES128-GCM-SHA256",
  "ECDHE-RSA-AES128-GCM-SHA256",
  "DHE-RSA-AES256-GCM-SHA384",
  "ECDHE-RSA-AES256-GCM-SHA384"
]
Accounts endpoint
2022-01-26 12:01:01 SUCCESS
ExtractClientCertificateFromTokenEndpointRequestHeaders
Extracted client certificate
client_certificate
{
  "cert": "-----BEGIN CERTIFICATE----- MIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw MjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD o28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx MDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv bS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg T3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB ARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku l2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97 ULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK j9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv C7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G +cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC zjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP Y3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE QDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu a2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV BgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK BggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw ggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg Zm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg cGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj ZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw dCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0 aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy ZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw cy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw DQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj ytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow o5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese 7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq eE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit paZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4\u003d -----END CERTIFICATE-----",
  "pem": "-----BEGIN CERTIFICATE-----\nMIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL\nBQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx\nFTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB\nTkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw\nMjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD\no28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx\nMDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv\nbS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg\nT3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB\nARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq\nhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku\nl2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97\nULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK\nj9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv\nC7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G\n+cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC\nzjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP\nY3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE\nQDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu\na2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z\nYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV\nBgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK\nBggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw\nggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg\nZm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg\ncGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj\nZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw\ndCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0\naGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy\nZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw\ncy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw\nDQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj\nytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow\no5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese\n7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq\neE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit\npaZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4\u003d\n-----END CERTIFICATE-----",
  "subject": {
    "dn": "UID\u003da9767e7d-d0d6-4c9f-826a-6b5ac8bbd7d2,1.3.6.1.4.1.311.60.2.1.3\u003d#13024252,2.5.4.15\u003d#131450726976617465204f7267616e697a6174696f6e,2.5.4.5\u003d#130e3335393737303937303030313731,CN\u003dupp.com.br,OU\u003de5b51083-adc2-5775-b0fc-02b263b1c40d,O\u003dUP.P SEP S.A.,L\u003dSão Paulo,ST\u003dSP,C\u003dBR"
  },
  "sanDnsNames": [
    "upp.com.br"
  ],
  "sanUris": [],
  "sanIPs": [],
  "sanEmails": []
}
2022-01-26 12:01:01 SUCCESS
CheckForClientCertificate
Found client certificate
2022-01-26 12:01:01 SUCCESS
EnsureClientCertificateMatches
Presented certificate matches registered certificate
actual
-----BEGIN CERTIFICATE-----
MIIG3zCCBcegAwIBAgIUTrKPcyxmsJN8pipEtalpdFpxSmQwDQYJKoZIhvcNAQEL
BQAwcTELMAkGA1UEBhMCQlIxHDAaBgNVBAoTE09wZW4gQmFua2luZyBCcmFzaWwx
FTATBgNVBAsTDE9wZW4gQmFua2luZzEtMCsGA1UEAxMkT3BlbiBCYW5raW5nIFNB
TkRCT1ggSXNzdWluZyBDQSAtIEcxMB4XDTIxMTAyNjAwMjcwMFoXDTIyMTEyNTAw
MjcwMFowggEOMQswCQYDVQQGEwJCUjELMAkGA1UECBMCU1AxEzARBgNVBAcMClPD
o28gUGF1bG8xFjAUBgNVBAoTDVVQLlAgU0VQIFMuQS4xLTArBgNVBAsTJGU1YjUx
MDgzLWFkYzItNTc3NS1iMGZjLTAyYjI2M2IxYzQwZDETMBEGA1UEAxMKdXBwLmNv
bS5icjEXMBUGA1UEBRMOMzU5NzcwOTcwMDAxNzExHTAbBgNVBA8TFFByaXZhdGUg
T3JnYW5pemF0aW9uMRMwEQYLKwYBBAGCNzwCAQMTAkJSMTQwMgYKCZImiZPyLGQB
ARMkYTk3NjdlN2QtZDBkNi00YzlmLTgyNmEtNmI1YWM4YmJkN2QyMIIBIjANBgkq
hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw42kU9qat2iCpuOSM3NesGlIKeFx7wku
l2p2F18psHEIJCdteqxd7X0TPZyKTkQ/TwwBV3yrocjoz0TXTVEgEG3P5NLvvj97
ULcSxjdznyzMdPvVggA7FavgglBmACo9EGbN9I36AmPapxssDcwO0tzsuet3mGUK
j9uzI7E4mWcnd29ONzocBuJqNxedeviUuy0mvVtuaetIpaeD9FjK0RGS16LKC+Hv
C7eQ4p2d+m+6v98eiAoVOrmyDSxduTkiR+FjuyVgqIKF+NP/M2NtQ9oh5dpYuY/G
+cUVaRulBBpovw4PkpOB2WtheH5gQH5Z7zQt4G+TzRH8zXZNnW1bZQIDAQABo4IC
zjCCAsowDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU1mayPO/xnsUK2/4AgKBCLKgP
Y3AwHwYDVR0jBBgwFoAUhn9YrRf1grZOtAWz+7DOEUPfTL4wTAYIKwYBBQUHAQEE
QDA+MDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zYW5kYm94LnBraS5vcGVuYmFu
a2luZ2JyYXNpbC5vcmcuYnIwSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybC5z
YW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvaXNzdWVyLmNybDAV
BgNVHREEDjAMggp1cHAuY29tLmJyMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAK
BggrBgEFBQcDAjCCAaEGA1UdIASCAZgwggGUMIIBkAYKKwYBBAGDui9kATCCAYAw
ggE2BggrBgEFBQcCAjCCASgMggEkVGhpcyBDZXJ0aWZpY2F0ZSBpcyBzb2xlbHkg
Zm9yIHVzZSB3aXRoIFJhaWRpYW0gU2VydmljZXMgTGltaXRlZCBhbmQgb3RoZXIg
cGFydGljaXBhdGluZyBvcmdhbmlzYXRpb25zIHVzaW5nIFJhaWRpYW0gU2Vydmlj
ZXMgTGltaXRlZHMgVHJ1c3QgRnJhbWV3b3JrIFNlcnZpY2VzLiBJdHMgcmVjZWlw
dCwgcG9zc2Vzc2lvbiBvciB1c2UgY29uc3RpdHV0ZXMgYWNjZXB0YW5jZSBvZiB0
aGUgUmFpZGlhbSBTZXJ2aWNlcyBMdGQgQ2VydGljaWNhdGUgUG9saWN5IGFuZCBy
ZWxhdGVkIGRvY3VtZW50cyB0aGVyZWluLjBEBggrBgEFBQcCARY4aHR0cDovL2Nw
cy5zYW5kYm94LnBraS5vcGVuYmFua2luZ2JyYXNpbC5vcmcuYnIvcG9saWNpZXMw
DQYJKoZIhvcNAQELBQADggEBAGb7C6Rf6g0thATgsvrbnUCwxwJPnufirk0C9Gdj
ytyYLaZyeSBdufjhbKrZsslUMyqR02sYBVpdASv/eQafA/x3278dDVOY3jaMkmow
o5dYSrkKZ84+0bnEH39dzAuG6Wn7MTVhh5lcIQhypEFcT6UuheaphpGXYyFS+Ese
7yAzbWc909KOzIdvUmPUj/44pb6WrsBTnaVSEkBoeAO41tLI5EgkOn/rBLlwUnWq
eE5o+5BmqhrOqJ8CEl8Y11uk+LHQuVMKVizmHv2GWFxVJFr4M0Kpjbn8q7v6xjit
paZ/ex7kzt/MUEEGFumfW3URrkhV8cf3GgJzvmycGHzWpL4=
-----END CERTIFICATE-----
2022-01-26 12:01:01 SUCCESS
EnsureBearerAccessTokenNotInParams
Client correctly did not send access token in query parameters or form body
2022-01-26 12:01:01 SUCCESS
ExtractBearerAccessTokenFromHeader
Found access token on incoming request
access_token
QP0v2fr2DPNa8NGUu8PlUy3Mg025hSLgpLbGvqtMEcOFPiKIOs
2022-01-26 12:01:01 SUCCESS
RequireBearerAccessToken
Found access token in request
actual
QP0v2fr2DPNa8NGUu8PlUy3Mg025hSLgpLbGvqtMEcOFPiKIOs
2022-01-26 12:01:01 INFO
ExtractFapiDateHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-auth-date
path
headers.x-fapi-auth-date
mapped
object
incoming_request
2022-01-26 12:01:01 INFO
ExtractFapiIpAddressHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-customer-ip-address
path
headers.x-fapi-customer-ip-address
mapped
object
incoming_request
2022-01-26 12:01:01 INFO
ExtractFapiInteractionIdHeader
Skipped evaluation due to missing required element: incoming_request headers.x-fapi-interaction-id
path
headers.x-fapi-interaction-id
mapped
object
incoming_request
2022-01-26 12:01:01 SUCCESS
FAPIBrazilEnsureAuthorizationRequestScopesContainAccounts
'accounts' was included in authorization request scopes
actual
openid consent:urn:conformance.oidf:nBdEgirzZh accounts resources
expected
accounts
2022-01-26 12:01:01 INFO
CreateFapiInteractionIdIfNeeded
Found existing FAPI interaction ID
fapi_interaction_id
f44819ab-57c3-4b55-8c7a-a65fc6893106
2022-01-26 12:01:01 SUCCESS
CreateFAPIAccountEndpointResponse
Created account response object
accounts_endpoint_response
{
  "conformance-test-finished": "true"
}
accounts_endpoint_response_headers
{
  "x-fapi-interaction-id": "f44819ab-57c3-4b55-8c7a-a65fc6893106",
  "content-type": "application/json; charset\u003dUTF-8"
}
2022-01-26 12:01:01 SUCCESS
CreateBrazilAccountsEndpointResponse
Created Brazil accounts response (Please note that this is a hardcoded response copied from API documentation)
accounts_endpoint_response
{
  "data": [
    {
      "brandName": "Organização A",
      "companyCnpj": "21128159000166",
      "type": "CONTA_DEPOSITO_A_VISTA",
      "compeCode": "001",
      "branchCode": "6272",
      "number": "94088392",
      "checkDigit": "4",
      "accountId": "92792126019929279212650822221989319252576"
    }
  ],
  "links": {
    "self": "https://api.banco.com.br/open-banking/api/v1/resource",
    "first": "https://api.banco.com.br/open-banking/api/v1/resource",
    "prev": "https://api.banco.com.br/open-banking/api/v1/resource",
    "next": "https://api.banco.com.br/open-banking/api/v1/resource",
    "last": "https://api.banco.com.br/open-banking/api/v1/resource"
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2022-01-26T12:01:01Z"
  }
}
accounts_endpoint_response_headers
{
  "x-fapi-interaction-id": "f44819ab-57c3-4b55-8c7a-a65fc6893106",
  "content-type": "application/json"
}
2022-01-26 12:01:01
ClearAccessTokenFromRequest
Condition ran but did not log anything
2022-01-26 12:01:01 OUTGOING
fapi1-advanced-final-client-refresh-token-test
Response to HTTP request to test instance GPpmgFZuyrqCeSS
outgoing_status_code
200
outgoing_headers
{
  "x-fapi-interaction-id": [
    "f44819ab-57c3-4b55-8c7a-a65fc6893106"
  ],
  "content-type": [
    "application/json"
  ]
}
outgoing_body
{
  "data": [
    {
      "brandName": "Organização A",
      "companyCnpj": "21128159000166",
      "type": "CONTA_DEPOSITO_A_VISTA",
      "compeCode": "001",
      "branchCode": "6272",
      "number": "94088392",
      "checkDigit": "4",
      "accountId": "92792126019929279212650822221989319252576"
    }
  ],
  "links": {
    "self": "https://api.banco.com.br/open-banking/api/v1/resource",
    "first": "https://api.banco.com.br/open-banking/api/v1/resource",
    "prev": "https://api.banco.com.br/open-banking/api/v1/resource",
    "next": "https://api.banco.com.br/open-banking/api/v1/resource",
    "last": "https://api.banco.com.br/open-banking/api/v1/resource"
  },
  "meta": {
    "totalRecords": 1,
    "totalPages": 1,
    "requestDateTime": "2022-01-26T12:01:01Z"
  }
}
outgoing_path
accounts/v1/accounts
2022-01-26 12:01:01 FINISHED
fapi1-advanced-final-client-refresh-token-test
Test has run to completion
testmodule_result
PASSED
2022-01-26 12:01:04
TEST-RUNNER
Alias has now been claimed by another test
alias
upp
new_test_id
5BKVyk1WRNV3JlJ
Test Results