Test Summary

Test Results

Expand All Collapse All
All times are UTC
2022-07-11 17:30:40 INFO
TEST-RUNNER
Test instance B8TRFqRMwfiO4jF created
baseUrl
https://www.certification.openid.net/test/a/fapipoc_fapi_dev
variant
{
  "client_auth_type": "private_key_jwt",
  "fapi_auth_request_method": "by_value",
  "fapi_profile": "plain_fapi",
  "fapi_response_mode": "plain_response"
}
alias
fapipoc_fapi_dev
description
planId
ftQif3lh1AuRl
config
{
  "alias": "fapipoc_fapi_dev",
  "server": {
    "discoveryUrl": "https://fapipoc.tryverify.ibm.com/oauth2/.well-known/openid-configuration"
  },
  "client": {
    "client_id": "e6ccf44d-838d-4bec-9d7e-0c1bf6677b8c",
    "client_secret": "ZbBKKNhJPo",
    "scope": "openid email",
    "jwks": {
      "keys": [
        {
          "p": "-JkZq0-X1RAO2UtEohS_gpRIW6vXFq8f_4eldFP7qXQcHzsSfFrul14pXG7grNokcA5S3w7HSBXQXQ7WdVeN-nZSI_232NSyF3GRkiINenSUMoz8_7zKy2MUvo9gW8WkaOlMOv5l8H781ZDfQvMCNjmwb2zE4q8qNbv2ZnA_gfc",
          "kty": "RSA",
          "q": "tj8Ug4uHQnfJEXdNKCPPbUD4kPMNu4T0pAf7lUkZ4Aa56CxKds063qUvdtyPYSiTKlpdAVYibqSyLBauG_RjPDcD6zrziKO93o42mX2Fr4fZJaWFKqlAqA3fZycWyu-VDrjF14QmDUS4NPnnQ7_UuiKYr5o3hO8-iJrW8z4VQJc",
          "d": "j_TQo4CwQ9GHOy2hCJJJfV1rUVxQpWmljB4SNBcJ4cZWbMVc0qRTL9awlgIvFCYmO2H97q3CLJAjigPGNta-TCI1eEbuaTsGrLwsjUrycQz7EIZf_i9rdj3lRhJ-gLpgO2Fj6_hfQLMHQ0yhiHi09FPLpJfPpicqEHwwmwNLQGIwN88c-TDDX2D4Iw3geygigqRnWviDVMejuRL2Luordiw7XOJHzY2BGwqOZdgqYfVS6Dr6PjOaOwWDJ7w9pHT19zz3UEXiarzA-AZKSZtxOoNVSliltj0nIzhVN0fd7g0Ljt13LjrGuyLSrAoTCZdQpCZ0uX02leqFkCAOkCzWlQ",
          "e": "AQAB",
          "use": "sig",
          "kid": "fapips1",
          "qi": "sNIuSo-uVI0TrtcR_6ZdGkps2MIWmVRhqBCKDxJAm21RkW7Sv0buRD8KPSP7WA20KTgs3O9i1Hz6bD8U2Hkjt3rk6MP59JvQev1DxFD8yA_A6aaIHk6Z7BryX5QOJzj0tzIB1tVzrSViVdDg0LUOO5yZdm_IQSU4AN-aaxjrpvA",
          "dp": "NnHJVmRzGz2OEvbSDDFBFAcHpdQHojcuadc6XDS8bAs60Xgtf0Cm-k2r_0tlN1X7HvN0INfquxXT8V17iG1pcc4SBUHezsUeT9YWjIuaqhP4FO4dxqCBRXPoqidach7h9_wILu9iQf59vwQgcVgpRtjxlCWdJQw50VTeDOdOcVc",
          "alg": "PS256",
          "dq": "qwl0dShDnuvQdmXisaM6Dq0FGvQglTZoanFbeXWLpSZq3yyCDhD6CO46J3FD1sk_pGX-Fz0BP5mt5Za7fFzVrTNsqB1BZaFWlkIdl9un1V7HOn-nBKynk5DBc4vJ5lcHKzPZ6TOKirVNs9o9YuXr_Wxuo482P7pQk9_Nj6daRq0",
          "n": "sPoZ2M-WhvDJchlxahAPDtkSaRlXWIK17NF2qHn3RgWUw0Z4XyptMWi-HMwxwwwApCi_g7ytaJ4DBDo5DY-pumFZHdj4mcD8Nb2XhV5smMO3-XABBVAuNH6VW4sFeb6bvlVBNyoHpAA_4VyMCYTjZffxGIqXpyxIND1M5zwP8RaZc1_Yo4yakZa15wXirbwZkCArJaIROpKy5xXFPA_2p4w7PnTQshAqjJx2Jz8N5CKsEvUvHNEg7pfeL1hTqLk1KRpLRh8QZKwfEjuxg0KFIGmi45gAX8SCjjX-BBffN6C7VELESRzILSlCEbTL_hslQkSQNbmyqI--kWCgkTZosQ"
        }
      ]
    }
  },
  "client_secret_post": {
    "client_id": "3fec31b2-9e2a-4e2b-a72a-228a06e06729",
    "client_secret": "ZbBKKNhJPo"
  },
  "mtls": {
    "cert": "-----BEGIN CERTIFICATE-----\nMIID2TCCA36gAwIBAgIUKXA8+q3GoAhthdhhMdI7y02Mg+4wCgYIKoZIzj0EAwIw\ngYExCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhOZXcgWW9yazE0MDIGA1UECgwrSW50\nZXJuYXRpb25hbCBCdXNpbmVzcyBNYWNoaW5lcyBDb3Jwb3JhdGlvbjEpMCcGA1UE\nAwwgSUJNIFNlY3VyaXR5IFZlcmlmeSBEZXYtSVRFIENBLTEwHhcNMjIwMjEwMTU1\nODAwWhcNMjUwMjA5MTU1ODAwWjB0MQswCQYDVQQGEwJTRzETMBEGA1UECBMKa2Nh\nMmNzci1TVDESMBAGA1UEBxMJa2NhMmNzci1MMRIwEAYDVQQKEwlrY2EyY3NyLU8x\nEzARBgNVBAsTCmtjYTJjc3ItT1UxEzARBgNVBAMTCmtjYTJjc3ItQ04wggEiMA0G\nCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCV6uh9e1Z54rwv4amn0M10uJqPtxZH\n45MsDyjVafe/5p1N8M2Zl2LQfSWHOvXtFBZlr72bz1TrZf8cuXn9WetXDg7FqElT\nxgV75uGubd1RpUKkFnN8dBSq1oadvpmU+1Ov7mRKzh3cPlbYX7Dwr372ZVGuumwj\nwVVfszmwA2bKy+bN7JvN41vic3OnAm+uBq5sB4HN87x3+hN/Z4rkO8HEdVgEwzQS\nXprs52vnPAt41Jn/RPx5+Z5yIGKuS10GCT1e19Afh4hgZfCRTBLCGDldJwemhVD2\nMDET4qYyhW/BkLzc3+3OjiXU10+NpCP+SC88WQp3U8Z24qlyLHA9prKXAgMBAAGj\nggETMIIBDzAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwIwDAYD\nVR0TAQH/BAIwADAdBgNVHQ4EFgQUSKev5Wnf5dBO/838Jt87ZcwqXbIwHwYDVR0j\nBBgwFoAUVG35JNW6n95CIBrdXCkTvAi9lhAwgZkGA1UdEQSBkTCBjoIPd3d3LmV4\nYW1wbGUuY29tghB0ZXN0LmV4YW1wbGUuY29tghBtYWlsLmV4YW1wbGUuY29tgg93\nd3cuZXhhbXBsZS5uZXSBE3NoYW5rYXJ2QHNnLmlibS5jb22HBMAAAgGHBMYzZP6H\nECABDbgAAAAAAAAAAAAAAAGGE2h0dHBzOi8vamtlLmNvbS9mb28wCgYIKoZIzj0E\nAwIDSQAwRgIhALF8B38YTP3q+Bf1wrcCBSL/ssGhO6H1NaWUykHSxYQqAiEAgTeJ\nC+4FXvklUnjJEabkAeZU/oycGMPI/u0Z56fq984\u003d\n-----END CERTIFICATE-----",
    "key": "-----BEGIN RSA PRIVATE KEY-----\nMIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQCV6uh9e1Z54rwv\n4amn0M10uJqPtxZH45MsDyjVafe/5p1N8M2Zl2LQfSWHOvXtFBZlr72bz1TrZf8c\nuXn9WetXDg7FqElTxgV75uGubd1RpUKkFnN8dBSq1oadvpmU+1Ov7mRKzh3cPlbY\nX7Dwr372ZVGuumwjwVVfszmwA2bKy+bN7JvN41vic3OnAm+uBq5sB4HN87x3+hN/\nZ4rkO8HEdVgEwzQSXprs52vnPAt41Jn/RPx5+Z5yIGKuS10GCT1e19Afh4hgZfCR\nTBLCGDldJwemhVD2MDET4qYyhW/BkLzc3+3OjiXU10+NpCP+SC88WQp3U8Z24qly\nLHA9prKXAgMBAAECggEAQrpw6i1kU9M2hS9x9tarJHlonnBVVAE5CCLlP3yvwDRT\nLxZwRR2LZ5ZUhmkZfoFy6Kb9A+WYfECFeVEbOcf0xuZkb9kUblvVJA2jxSJ0oLso\nuuWdWLdIXbQn7f2g2Z22Zbf73wn4Y4hB2oRZOwA6SEzXuyiSKqYKrJKXKj+RWNET\njUt/7H4skIDafFhgo1+V7ZbuMJxdp4xVp98g3mxyUj1hthg3RNDpiapqElobSEKl\nUnYQVpRfBRIAFWtRvO4ZjwFFOgpTel3E6gm34miTN5Vp2Je+C02LAx04G5bCOPe6\nEwESZEPeVE6nbjvw1wM2Nl8GkwEGweDNM165y/8T1QKBgQDO7XHODYgmb1vA7Dk4\nXDQkqgvFpMqQTNvxgXarK9lDNaQBDoXZjp+PQ4ZG7UY9SZ82uPz/kZLlZJeXGg1C\nd3v2ErLQXWrq8IHY+IwgXt0/jForLnRihGwqKg7J801PPbOM4BCh3LpZwCoiVXCA\nOCSA++h8CBBffZ97eiiPAcO6lQKBgQC5eGVhLebWsrOgKqr7ouSeT0BuVb8rXt2M\naYTVwTFs+BsbUOnwYcXYBeV4mtgtLmf7C6m5NoTWOGsFdjmk51uHC5k/h9fXf1En\nQBbVjZDsIelCzAeWkwxDiDtuwChB3cLk64qtmLRy0rHAUJvfG93/UbaO/LxZwyPv\ntL9ylHWZewKBgBAUqcRujscV3laGxQeZOsAiqtmILem631jMS9GPjcnIUF94pnQ6\nvjGe+L9oTw4SO5pAFAE0aesDvzgR4TfqGysLVvQUXmu1lxGqdxFI7f6zRIqYiJjj\nW5iHPjD5hGeFDwACpag+hAjXgy653w1Hz6ZqbS2+Xq9dDtjErIQ4ieJlAoGBAIdv\njJB/RW8IhbTzE3K3y7xy4PjxMq1IE/6B21eAQUhykNDMsFgx/Zg3Dg+Y+z1bAuFG\n7gRq9Gu+PSB66bMqoyKlbJ4A47Pgq/E+kq4VN3vHc5+sf+oLrUvvQn8oYP1gI/6o\npdcIiNTEWLq34mr03ZKhJ++YTS47GpXjZl4UXR/bAoGARrRC3D0HNCw2dQZ8jXFo\nEfXU7lHuCOBFTZQz/mGlGdSXm9hoZkb1nOTVxJhj+WG35HQn4FWDQHLX1i9g4Qno\npJ7Ga80VNNdmq+ub9nEx9e1YmLlD5skazO8mwIOmAyyi2FBKYGtXhA9nYO4Adfcb\nG6ENTwoX/IjA62IG+5gNvoo\u003d\n-----END RSA PRIVATE KEY-----"
  },
  "client2": {
    "client_id": "58a92455-980a-424a-8be2-d9c77f4d6cd9",
    "scope": "openid email",
    "jwks": {
      "keys": [
        {
          "p": "_V4SSh_YdQH3_c3zAUQ4RgxImgnYHPRZuVcfRuVztq6fHs1xI5Qcri4wSyfmcQgu-Caos_5Htu6iOrrMnA0Si8s6rsU8lzGCgBF0clQeEdUGX1YKqsTw2OrdcFhjwZWO59uBcmUXw8xw-EMlA_9x82HVKwZcPW94fRJJeUC80Pk",
          "kty": "RSA",
          "q": "jt6KCTdVQV6MLruoTlKPN9MtlLZ16TR-5GUareWhr8GGn81mto_Ua0eCZHGCnleAYzI3il66PvF4ribDXXOHhn6iBiIHph2Oge1Q73gSjdClHGrTq7EHi_yEeoPxXXD8siEplKcREsWtby8XTUktG0GaIg2XgocVpj7AEn_QewM",
          "d": "JhMR3QAhmiyBWEFvYJF7t5ohNOrRa5DWJi1sBmq_baADjt_DuEGBX3mQ2ZCHdWGjIznlqg9NuewHu1RykRujwFImBJaK5XMIdQoDDHlja3jBg-cp6swoQUBrOv0Amq-Co-qmtn5D7gaEkO4cJD1AM_ZJSKYus9k1ra3mEGPPUKiSknjICvZ4zEd28mJG_ZTMa5y_G3NrqkkjeLoej86Ru0yHLjYo3ZpXvbRspnlmAqganHVo7CjeBqW8ov2fS6hyRxPRDHfyw-fKHBcLFVqGNTw9-vfqXWfTBB4kwHmSwfJ5jF19UBenKk77eyzOcdwQeSDUKUeS5Ni6_cpvDe9HEQ",
          "e": "AQAB",
          "use": "sig",
          "kid": "fapips2",
          "qi": "jRUHNAE9Rq9slhKVJaHTDc56L040JIlc92nS1lW5tXxwT1032yjOHqvxkUafFsRl2Y_HJhNMXiZH89zk8QIGgO_-o2sOhlVYReE9HZpXaZQegicuG8Oc7AuH78EbPjeBml2ph1B4UV1r1L9EDg6C5otTMvi7AxIG5SH1nDsB8LA",
          "dp": "7hq6y2g0DnnkKWOjS_xlegbPL9uyejt0GoZygTjezr46EUN2YL4vWc1UWzzLBkxvf4stHcIIeTS3xsOHx9tNI4zAwD_hWiEQB_TfXxYIEDAGxg9hBO0Bfojxw0N9tA4t91zEwNGaTMpTHCxVm_UyjEvTfZSDmMSqEbfezpF1IFk",
          "alg": "PS256",
          "dq": "XPniZyEFcKcxH3CslVwRLElYToF3tq6dLdHGTQk18gVFsVWg1IpBuRcuemOMl7NmMCgMERaYqkHHQb6kQXrf5d0fYFJhG-_8P_3LQCyqFnSEHzw-SGvK94T8Sib3utG_AcWnI8Cd0dOnjMXeqkNHAYft4N9rjFyQ8EHCCcf4SzU",
          "n": "jWZuVs7f3z7SVFMH9tggC-wbx_JIEy59aScoFGhb64IoKt886ftpFht6_WTwJJKkMxQiPDeHUmi7xAC5TWV1OmrGOv4QKQ2P-u3wvvkFTrOUFGCVRgZl8dJ8I85StneVZXbVaQ6sJBH3x_wgtAT_KWUOrgs4Asi1QoHU1Qs1m-_lf0nkL7aYJDOBYpY9LYtj8NuNLaKSJSTjkZIabDJzTboNvDarS3YLQiS-LVJSD9svfK3HwAq9XV3-LEpNkqT6xCe1TJiOT-4taXwRTjyoZ9z_ejgjnpPL1AD7TkXgxTIpCQ6vGgq9j4YyUy5QIf9QZnA71L4Xj41WddUdy-4V6w"
        }
      ]
    }
  },
  "mtls2": {
    "cert": "-----BEGIN CERTIFICATE-----\nMIID1zCCA36gAwIBAgIUUHDgxG3lPQuGjbIG+p3wWr7606YwCgYIKoZIzj0EAwIw\ngYExCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhOZXcgWW9yazE0MDIGA1UECgwrSW50\nZXJuYXRpb25hbCBCdXNpbmVzcyBNYWNoaW5lcyBDb3Jwb3JhdGlvbjEpMCcGA1UE\nAwwgSUJNIFNlY3VyaXR5IFZlcmlmeSBEZXYtSVRFIENBLTEwHhcNMjIwMzEyMTQz\nMzAwWhcNMjUwMzExMTQzMzAwWjB0MQswCQYDVQQGEwJTRzETMBEGA1UECBMKa2Nh\nMmNzci1TVDESMBAGA1UEBxMJa2NhMmNzci1MMRIwEAYDVQQKEwlrY2EyY3NyLU8x\nEzARBgNVBAsTCmtjYTJjc3ItT1UxEzARBgNVBAMTCmtjYTJjc3ItQ04wggEiMA0G\nCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDQSJq6kA1B0OlrFvgxfw61M3Fee4Nq\n9+ziUOAY+ffzybS0fhCJkjKwWG9f9p/CoJGSaqVzHoa13Sgw/3L186pyyFVnX2E9\nKTujNOkCVWuiyE99gHiI3fZPbYqbJwKsbb8RQuPQKoMGz22RTppshlrHJJmTn0VY\nUGlSRGZrcnvRXsl3eegcTiQ1/jwnLQRoJ96FA3Tl0KCy6qsGNWF2wq7qIboBDb/i\nrgqHAwX9Lb5wL+idsill1m9gpK7PKkjTJjvdRcKIH3B3G+zNdEZeB5y/S1JnID/c\nLUFwF8IeSDWjqZDi4KJckZXxvI2pl1L5wAqaWFuGHCvE/Cmvdw7oyYnHAgMBAAGj\nggETMIIBDzAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwIwDAYD\nVR0TAQH/BAIwADAdBgNVHQ4EFgQUecSZVVi1AFZBn1qATTpubMpMEVMwHwYDVR0j\nBBgwFoAUVG35JNW6n95CIBrdXCkTvAi9lhAwgZkGA1UdEQSBkTCBjoIPd3d3LmV4\nYW1wbGUuY29tghB0ZXN0LmV4YW1wbGUuY29tghBtYWlsLmV4YW1wbGUuY29tgg93\nd3cuZXhhbXBsZS5uZXSBE3NoYW5rYXJ2QHNnLmlibS5jb22HBMAAAgGHBMYzZP6H\nECABDbgAAAAAAAAAAAAAAAGGE2h0dHBzOi8vamtlLmNvbS9mb28wCgYIKoZIzj0E\nAwIDRwAwRAIgOsqCg6PJbj5rIh67VUxJEcBiQChb5D8+cd5e7zJhojUCID2AHsLH\nHqHtuXRQUVikneUewh4sFYU8xhWKjvHSqp4a\n-----END CERTIFICATE-----",
    "key": "-----BEGIN RSA PRIVATE KEY-----\nMIIEpAIBAAKCAQEA0EiaupANQdDpaxb4MX8OtTNxXnuDavfs4lDgGPn388m0tH4Q\niZIysFhvX/afwqCRkmqlcx6Gtd0oMP9y9fOqcshVZ19hPSk7ozTpAlVroshPfYB4\niN32T22KmycCrG2/EULj0CqDBs9tkU6abIZaxySZk59FWFBpUkRma3J70V7Jd3no\nHE4kNf48Jy0EaCfehQN05dCgsuqrBjVhdsKu6iG6AQ2/4q4KhwMF/S2+cC/onbIp\nZdZvYKSuzypI0yY73UXCiB9wdxvszXRGXgecv0tSZyA/3C1BcBfCHkg1o6mQ4uCi\nXJGV8byNqZdS+cAKmlhbhhwrxPwpr3cO6MmJxwIDAQABAoIBAG7VU9DW+tb9Dli4\nHlZoYDE4MKmwXBw91cYQd0+TJMiLmyc4tiAete51AL82A4mT3CLnsSbzJYf9KXf5\nVvleMmNmC1w4uwvKtzt/2kYtols68GG+TWW3h2x4w/sP5TJQLA5JY+TP2m1zT8C0\n7SO20vOJnFebt1DpaUInt8CRaSXdriQhnkFXHhIyw2eh9w0u0T1Tq5ng9MgxgVsR\ng/ZRm9l72j/tR6+Y9P+12wkqH8FuE5E/CIzMlMBzUF4Ng6G08TNxSYaTHiGZXNhZ\ni/zbVCYKsuZsE7qWmvXCysjQ9RYyPl9xH+rP1CiuA5TBmXDGUw5jt7gpxgGnCgQs\nHd9ffnECgYEA+ZfN75eUGXswIldvVl3czeol0TDKGXPfCerHre7RisM8nzKLino8\nrz4Hpcl6llUKu/vXde9XFIx1a0SYlkYx+SMCH8hHRgRyV03SOG3WozW9Dlu8OAAt\nKwsbYRtJKNEBP/TRdlFbE/mpyvfwd16dWh77LJdhtjAWQSp8hCRO8Y0CgYEA1aFW\nESHWVlvW6Z/IBnU/lLUUgweTNy4WFfeR8TG4mhCrYRpbN7TenIJ/Wzerg/xUg736\nwIfT89TBuD+i0X12BeoQNttLP5G3pUD8CM+8VpA+hilRqcLgwrjr3367tQT9hd+a\nDGBd9tgYiwfwxwFVqh6dokzPhqGH9tqz2cWg8aMCgYEAy3cd0O//MhqDLaubPou7\nwTzcYUDlr4QO0TXMW5Twyq7Hj3uT12o4aB8n+tVZEo329zGg/ioDEeRCoBRGU1Kb\n0F3ikGgi+ggL8fGlqoyXyWq4WKkdsYUrTQh75Fhq9lQTMcDwtAQ0O/9tk+E07Qp7\nOYlB9qLda7idm7f3030Jwc0CgYEAqtmd2JPENEq8xRkJQsjwcYCkh+o9/Wp5NVZK\nvKf0KBrexQjsHNAlHOxs6EnMfQEHolkEuoempiHoT+9syrfY9P/tucGGG6/xPFON\nfYqN6Hjx2CAhdHAriu+TjKlxe2MjUrayH+XOIEVQ05glIzLZDPXxQcTGT7jN4Uml\nfqvEfJsCgYAe9MXCus1wBNBeI0tYivXZoX7ewwQv0aTg4oDyFk2mx50FMEdV+AEu\nq4hWiyaQYewMWPjQr3nSTpmX3DfXm2kOcfXko7mpK9Twzzrv+TRkaH7ECtaoL31w\nolwePSwtvwPS77OOoBUHO5UKDVyYmZprH4r7gnCpGzGcH140lZv3UQ\u003d\u003d\n-----END RSA PRIVATE KEY-----"
  },
  "resource": {
    "resourceUrl": "https://fapiresource.dev.vanitytst.cloudidentity.ibm.com/oauth2/open-banking/v3.1/aisp/accounts"
  }
}
testName
fapi1-advanced-final-ensure-request-object-with-long-nonce
2022-07-11 17:30:40 SUCCESS
CreateRedirectUri
Created redirect URI
redirect_uri
https://www.certification.openid.net/test/a/fapipoc_fapi_dev/callback
2022-07-11 17:30:40
GetDynamicServerConfiguration
HTTP request
request_uri
https://fapipoc.tryverify.ibm.com/oauth2/.well-known/openid-configuration
request_method
GET
request_headers
{
  "accept": "text/plain, application/json, application/*+json, */*",
  "content-length": "0"
}
request_body

                                
2022-07-11 17:30:40 RESPONSE
GetDynamicServerConfiguration
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-4c3df1d2-a407-4df2-8392-fac7298e0be3",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "1ad190f862cc5e402cea3b51",
  "vary": "Accept-Encoding",
  "date": "Mon, 11 Jul 2022 17:30:40 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:8PosxvQ/++TY0vASTqDEXTLZDEz3QCfjRnM7PsDY6Tk\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDPR02A\u003dPBC5YS:2425902924; Path\u003d/; Domain\u003dverify.ibm.com; Secure; HttpOnly"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d27",
    "origin; dur\u003d42"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"issuer":"https://fapipoc.tryverify.ibm.com/oauth2","authorization_endpoint":"https://fapipoc.tryverify.ibm.com/oauth2/authorize","token_endpoint":"https://fapipoc.tryverify.ibm.com/oauth2/token","introspection_endpoint":"https://fapipoc.tryverify.ibm.com/oauth2/introspect","userinfo_endpoint":"https://fapipoc.tryverify.ibm.com/oauth2/userinfo","revocation_endpoint":"https://fapipoc.tryverify.ibm.com/oauth2/revoke","pushed_authorization_request_endpoint":"https://fapipoc.tryverify.ibm.com/oauth2/par","registration_endpoint":"https://fapipoc.tryverify.ibm.com/oauth2/client_registration","jwks_uri":"https://fapipoc.tryverify.ibm.com/oauth2/jwks","response_types_supported":["none","code","token","id_token","code token","code id_token","token id_token","code token id_token"],"response_modes_supported":["query","fragment","form_post"],"grant_types_supported":["authorization_code","implicit","password","refresh_token","client_credentials"],"token_endpoint_auth_methods_supported":["client_secret_basic","client_secret_post","private_key_jwt","tls_client_auth"],"id_token_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"id_token_encryption_alg_values_supported":["none","RSA-OAEP","RSA-OAEP-256"],"id_token_encryption_enc_values_supported":["none","A128GCM","A256GCM"],"userinfo_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"userinfo_encryption_alg_values_supported":["none","RSA-OAEP","RSA-OAEP-256"],"userinfo_encryption_enc_values_supported":["none","A128GCM","A256GCM"],"token_endpoint_auth_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"request_object_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"request_object_encryption_alg_values_supported":["none"],"request_object_encryption_enc_values_supported":["none"],"subject_types_supported":["public"],"scopes_supported":["openid","profile","email","phone","address"],"claims_supported":["groupIds","family_name","tenantId","preferred_username","realmName","email","employee_id","mobile_number","upn","uid","name","job_title","given_name","department","iss"],"claim_types_supported":["normal"],"claims_parameter_supported":true,"request_parameter_supported":true,"request_uri_parameter_supported":false,"tls_client_certificate_bound_access_tokens":true,"mtls_endpoint_aliases":{"introspection_endpoint":"https://fapipoc.tryverify.ibm.com/oauth2/introspect","pushed_authorization_request_endpoint":"https://fapipoc.tryverify.ibm.com/oauth2/par","revocation_endpoint":"https://fapipoc.tryverify.ibm.com/oauth2/revoke","token_endpoint":"https://fapipoc.tryverify.ibm.com/oauth2/token"}}
2022-07-11 17:30:40 SUCCESS
GetDynamicServerConfiguration
Successfully parsed server configuration
issuer
https://fapipoc.tryverify.ibm.com/oauth2
authorization_endpoint
https://fapipoc.tryverify.ibm.com/oauth2/authorize
token_endpoint
https://fapipoc.tryverify.ibm.com/oauth2/token
introspection_endpoint
https://fapipoc.tryverify.ibm.com/oauth2/introspect
userinfo_endpoint
https://fapipoc.tryverify.ibm.com/oauth2/userinfo
revocation_endpoint
https://fapipoc.tryverify.ibm.com/oauth2/revoke
pushed_authorization_request_endpoint
https://fapipoc.tryverify.ibm.com/oauth2/par
registration_endpoint
https://fapipoc.tryverify.ibm.com/oauth2/client_registration
jwks_uri
https://fapipoc.tryverify.ibm.com/oauth2/jwks
response_types_supported
[
  "none",
  "code",
  "token",
  "id_token",
  "code token",
  "code id_token",
  "token id_token",
  "code token id_token"
]
response_modes_supported
[
  "query",
  "fragment",
  "form_post"
]
grant_types_supported
[
  "authorization_code",
  "implicit",
  "password",
  "refresh_token",
  "client_credentials"
]
token_endpoint_auth_methods_supported
[
  "client_secret_basic",
  "client_secret_post",
  "private_key_jwt",
  "tls_client_auth"
]
id_token_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
id_token_encryption_alg_values_supported
[
  "none",
  "RSA-OAEP",
  "RSA-OAEP-256"
]
id_token_encryption_enc_values_supported
[
  "none",
  "A128GCM",
  "A256GCM"
]
userinfo_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
userinfo_encryption_alg_values_supported
[
  "none",
  "RSA-OAEP",
  "RSA-OAEP-256"
]
userinfo_encryption_enc_values_supported
[
  "none",
  "A128GCM",
  "A256GCM"
]
token_endpoint_auth_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
request_object_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
request_object_encryption_alg_values_supported
[
  "none"
]
request_object_encryption_enc_values_supported
[
  "none"
]
subject_types_supported
[
  "public"
]
scopes_supported
[
  "openid",
  "profile",
  "email",
  "phone",
  "address"
]
claims_supported
[
  "groupIds",
  "family_name",
  "tenantId",
  "preferred_username",
  "realmName",
  "email",
  "employee_id",
  "mobile_number",
  "upn",
  "uid",
  "name",
  "job_title",
  "given_name",
  "department",
  "iss"
]
claim_types_supported
[
  "normal"
]
claims_parameter_supported
true
request_parameter_supported
true
request_uri_parameter_supported
false
tls_client_certificate_bound_access_tokens
true
mtls_endpoint_aliases
{
  "introspection_endpoint": "https://fapipoc.tryverify.ibm.com/oauth2/introspect",
  "pushed_authorization_request_endpoint": "https://fapipoc.tryverify.ibm.com/oauth2/par",
  "revocation_endpoint": "https://fapipoc.tryverify.ibm.com/oauth2/revoke",
  "token_endpoint": "https://fapipoc.tryverify.ibm.com/oauth2/token"
}
2022-07-11 17:30:40 SUCCESS
AddMTLSEndpointAliasesToEnvironment
Added mtls_endpoint_aliases to environment
2022-07-11 17:30:40 SUCCESS
CheckServerConfiguration
Found required server configuration keys
required
[
  "authorization_endpoint",
  "token_endpoint",
  "issuer"
]
2022-07-11 17:30:40
FetchServerKeys
Fetching server key
jwks_uri
https://fapipoc.tryverify.ibm.com/oauth2/jwks
2022-07-11 17:30:40
FetchServerKeys
HTTP request
request_uri
https://fapipoc.tryverify.ibm.com/oauth2/jwks
request_method
GET
request_headers
{
  "accept": "text/plain, application/json, application/*+json, */*",
  "content-length": "0"
}
request_body

                                
2022-07-11 17:30:40 RESPONSE
FetchServerKeys
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-116e3ef7-355e-4cfb-aa39-2c5d1bbf9508",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "1ad190f862cc5e4035552e63",
  "vary": "Accept-Encoding",
  "date": "Mon, 11 Jul 2022 17:30:40 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:XXocx2gs/fcIDcAYN5cecOPzaYy6YE4ws8p37GFgv5k\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDPR02A\u003dPBC5YS:2452117324; Path\u003d/; Domain\u003dverify.ibm.com; Secure; HttpOnly"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d18",
    "origin; dur\u003d44"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"keys":[{"kid":"server","kty":"RSA","use":"sig","x5c":["MIIDLDCCAhSgAwIBAgIEXCMj+jANBgkqhkiG9w0BAQsFADBYMQkwBwYDVQQGEwAxCTAHBgNVBAgTADEJMAcGA1UEBxMAMQkwBwYDVQQKEwAxCTAHBgNVBAsTADEfMB0GA1UEAxMWZmFwaXBvYy52ZXJpZnkuaWJtLmNvbTAeFw0yMjA2MDYwNTI3MzRaFw0zMjA2MDMwNTI3MzRaMFgxCTAHBgNVBAYTADEJMAcGA1UECBMAMQkwBwYDVQQHEwAxCTAHBgNVBAoTADEJMAcGA1UECxMAMR8wHQYDVQQDExZmYXBpcG9jLnZlcmlmeS5pYm0uY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsFPq+elUjVDaEYBgoTsIyy1qLJnDSi0MUA0qMZi4TE9+ouS792ID0+yJDgVnm1GvC1mxI2stSKm3t9fjMzDbL84LCy/lcKgyEjI1LZIf40pVZVJB4OLdcAxjC6ICMWU7bRTCw1KhG0nqyCfhACxE+2/TYnWZ1FgAgo/dBPkw8E8dFLaNUuKWKRTtaYUH8qjMrw+5ah+zL0/7DmVt63o6dOoAP7oOVid+tfMVX/zudUB3ol6kAcKbKIBqYtZXK2IqfJK16bXt7OncM9JXH2Mp/ksOmxqVx7mwWqFqxTkHvME+8H1vUWHOO1Y5B9jQCFqvf9uNRm11akTARt0oBC/vgQIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQADj97RFNHJSr9VsfY89V0fh+afTloloZLinYrCftHGXZYTFwkm4u7djNb5pnagpIeI0KRY4Z9L4CaQFG9yWPuvc6J+Djmm1T3hzwTQSbcQlAQPi0G/++hmbHNDY0cW7v4h7bV+fHiKMReurg8P0C27TOC9PjkWOgd9xyJt67xX/w/yM4plc8vE+E9WJ293EDQoO72BUxwJPAvmsmBxCotusJhVHqfhaI23CZVEtHmhtav+K9y7HfyGOjCQg8a+P9BLxAltJc/fgfNXNSNVUUMvgEWB9VTPJEZ+CbXoNXwHbTkQ9hh0pVexKlfz2cWavBOCp86XCbpWZSHzSh+7Fjvn"],"x5t#S256":"6SIMvPp5sYE80UhE8MhmtPrYj_5WgsX7u31MZceUc6k","n":"sFPq-elUjVDaEYBgoTsIyy1qLJnDSi0MUA0qMZi4TE9-ouS792ID0-yJDgVnm1GvC1mxI2stSKm3t9fjMzDbL84LCy_lcKgyEjI1LZIf40pVZVJB4OLdcAxjC6ICMWU7bRTCw1KhG0nqyCfhACxE-2_TYnWZ1FgAgo_dBPkw8E8dFLaNUuKWKRTtaYUH8qjMrw-5ah-zL0_7DmVt63o6dOoAP7oOVid-tfMVX_zudUB3ol6kAcKbKIBqYtZXK2IqfJK16bXt7OncM9JXH2Mp_ksOmxqVx7mwWqFqxTkHvME-8H1vUWHOO1Y5B9jQCFqvf9uNRm11akTARt0oBC_vgQ","e":"AQAB"}]}
2022-07-11 17:30:40
FetchServerKeys
Found JWK set string
jwk_string
{"keys":[{"kid":"server","kty":"RSA","use":"sig","x5c":["MIIDLDCCAhSgAwIBAgIEXCMj+jANBgkqhkiG9w0BAQsFADBYMQkwBwYDVQQGEwAxCTAHBgNVBAgTADEJMAcGA1UEBxMAMQkwBwYDVQQKEwAxCTAHBgNVBAsTADEfMB0GA1UEAxMWZmFwaXBvYy52ZXJpZnkuaWJtLmNvbTAeFw0yMjA2MDYwNTI3MzRaFw0zMjA2MDMwNTI3MzRaMFgxCTAHBgNVBAYTADEJMAcGA1UECBMAMQkwBwYDVQQHEwAxCTAHBgNVBAoTADEJMAcGA1UECxMAMR8wHQYDVQQDExZmYXBpcG9jLnZlcmlmeS5pYm0uY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsFPq+elUjVDaEYBgoTsIyy1qLJnDSi0MUA0qMZi4TE9+ouS792ID0+yJDgVnm1GvC1mxI2stSKm3t9fjMzDbL84LCy/lcKgyEjI1LZIf40pVZVJB4OLdcAxjC6ICMWU7bRTCw1KhG0nqyCfhACxE+2/TYnWZ1FgAgo/dBPkw8E8dFLaNUuKWKRTtaYUH8qjMrw+5ah+zL0/7DmVt63o6dOoAP7oOVid+tfMVX/zudUB3ol6kAcKbKIBqYtZXK2IqfJK16bXt7OncM9JXH2Mp/ksOmxqVx7mwWqFqxTkHvME+8H1vUWHOO1Y5B9jQCFqvf9uNRm11akTARt0oBC/vgQIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQADj97RFNHJSr9VsfY89V0fh+afTloloZLinYrCftHGXZYTFwkm4u7djNb5pnagpIeI0KRY4Z9L4CaQFG9yWPuvc6J+Djmm1T3hzwTQSbcQlAQPi0G/++hmbHNDY0cW7v4h7bV+fHiKMReurg8P0C27TOC9PjkWOgd9xyJt67xX/w/yM4plc8vE+E9WJ293EDQoO72BUxwJPAvmsmBxCotusJhVHqfhaI23CZVEtHmhtav+K9y7HfyGOjCQg8a+P9BLxAltJc/fgfNXNSNVUUMvgEWB9VTPJEZ+CbXoNXwHbTkQ9hh0pVexKlfz2cWavBOCp86XCbpWZSHzSh+7Fjvn"],"x5t#S256":"6SIMvPp5sYE80UhE8MhmtPrYj_5WgsX7u31MZceUc6k","n":"sFPq-elUjVDaEYBgoTsIyy1qLJnDSi0MUA0qMZi4TE9-ouS792ID0-yJDgVnm1GvC1mxI2stSKm3t9fjMzDbL84LCy_lcKgyEjI1LZIf40pVZVJB4OLdcAxjC6ICMWU7bRTCw1KhG0nqyCfhACxE-2_TYnWZ1FgAgo_dBPkw8E8dFLaNUuKWKRTtaYUH8qjMrw-5ah-zL0_7DmVt63o6dOoAP7oOVid-tfMVX_zudUB3ol6kAcKbKIBqYtZXK2IqfJK16bXt7OncM9JXH2Mp_ksOmxqVx7mwWqFqxTkHvME-8H1vUWHOO1Y5B9jQCFqvf9uNRm11akTARt0oBC_vgQ","e":"AQAB"}]}
2022-07-11 17:30:40 SUCCESS
FetchServerKeys
Found server JWK set
server_jwks
{
  "keys": [
    {
      "kid": "server",
      "kty": "RSA",
      "use": "sig",
      "x5c": [
        "MIIDLDCCAhSgAwIBAgIEXCMj+jANBgkqhkiG9w0BAQsFADBYMQkwBwYDVQQGEwAxCTAHBgNVBAgTADEJMAcGA1UEBxMAMQkwBwYDVQQKEwAxCTAHBgNVBAsTADEfMB0GA1UEAxMWZmFwaXBvYy52ZXJpZnkuaWJtLmNvbTAeFw0yMjA2MDYwNTI3MzRaFw0zMjA2MDMwNTI3MzRaMFgxCTAHBgNVBAYTADEJMAcGA1UECBMAMQkwBwYDVQQHEwAxCTAHBgNVBAoTADEJMAcGA1UECxMAMR8wHQYDVQQDExZmYXBpcG9jLnZlcmlmeS5pYm0uY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsFPq+elUjVDaEYBgoTsIyy1qLJnDSi0MUA0qMZi4TE9+ouS792ID0+yJDgVnm1GvC1mxI2stSKm3t9fjMzDbL84LCy/lcKgyEjI1LZIf40pVZVJB4OLdcAxjC6ICMWU7bRTCw1KhG0nqyCfhACxE+2/TYnWZ1FgAgo/dBPkw8E8dFLaNUuKWKRTtaYUH8qjMrw+5ah+zL0/7DmVt63o6dOoAP7oOVid+tfMVX/zudUB3ol6kAcKbKIBqYtZXK2IqfJK16bXt7OncM9JXH2Mp/ksOmxqVx7mwWqFqxTkHvME+8H1vUWHOO1Y5B9jQCFqvf9uNRm11akTARt0oBC/vgQIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQADj97RFNHJSr9VsfY89V0fh+afTloloZLinYrCftHGXZYTFwkm4u7djNb5pnagpIeI0KRY4Z9L4CaQFG9yWPuvc6J+Djmm1T3hzwTQSbcQlAQPi0G/++hmbHNDY0cW7v4h7bV+fHiKMReurg8P0C27TOC9PjkWOgd9xyJt67xX/w/yM4plc8vE+E9WJ293EDQoO72BUxwJPAvmsmBxCotusJhVHqfhaI23CZVEtHmhtav+K9y7HfyGOjCQg8a+P9BLxAltJc/fgfNXNSNVUUMvgEWB9VTPJEZ+CbXoNXwHbTkQ9hh0pVexKlfz2cWavBOCp86XCbpWZSHzSh+7Fjvn"
      ],
      "x5t#S256": "6SIMvPp5sYE80UhE8MhmtPrYj_5WgsX7u31MZceUc6k",
      "n": "sFPq-elUjVDaEYBgoTsIyy1qLJnDSi0MUA0qMZi4TE9-ouS792ID0-yJDgVnm1GvC1mxI2stSKm3t9fjMzDbL84LCy_lcKgyEjI1LZIf40pVZVJB4OLdcAxjC6ICMWU7bRTCw1KhG0nqyCfhACxE-2_TYnWZ1FgAgo_dBPkw8E8dFLaNUuKWKRTtaYUH8qjMrw-5ah-zL0_7DmVt63o6dOoAP7oOVid-tfMVX_zudUB3ol6kAcKbKIBqYtZXK2IqfJK16bXt7OncM9JXH2Mp_ksOmxqVx7mwWqFqxTkHvME-8H1vUWHOO1Y5B9jQCFqvf9uNRm11akTARt0oBC_vgQ",
      "e": "AQAB"
    }
  ]
}
2022-07-11 17:30:40 SUCCESS
CheckServerKeysIsValid
Server JWKs is valid
server_jwks
{
  "keys": [
    {
      "kid": "server",
      "kty": "RSA",
      "use": "sig",
      "x5c": [
        "MIIDLDCCAhSgAwIBAgIEXCMj+jANBgkqhkiG9w0BAQsFADBYMQkwBwYDVQQGEwAxCTAHBgNVBAgTADEJMAcGA1UEBxMAMQkwBwYDVQQKEwAxCTAHBgNVBAsTADEfMB0GA1UEAxMWZmFwaXBvYy52ZXJpZnkuaWJtLmNvbTAeFw0yMjA2MDYwNTI3MzRaFw0zMjA2MDMwNTI3MzRaMFgxCTAHBgNVBAYTADEJMAcGA1UECBMAMQkwBwYDVQQHEwAxCTAHBgNVBAoTADEJMAcGA1UECxMAMR8wHQYDVQQDExZmYXBpcG9jLnZlcmlmeS5pYm0uY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsFPq+elUjVDaEYBgoTsIyy1qLJnDSi0MUA0qMZi4TE9+ouS792ID0+yJDgVnm1GvC1mxI2stSKm3t9fjMzDbL84LCy/lcKgyEjI1LZIf40pVZVJB4OLdcAxjC6ICMWU7bRTCw1KhG0nqyCfhACxE+2/TYnWZ1FgAgo/dBPkw8E8dFLaNUuKWKRTtaYUH8qjMrw+5ah+zL0/7DmVt63o6dOoAP7oOVid+tfMVX/zudUB3ol6kAcKbKIBqYtZXK2IqfJK16bXt7OncM9JXH2Mp/ksOmxqVx7mwWqFqxTkHvME+8H1vUWHOO1Y5B9jQCFqvf9uNRm11akTARt0oBC/vgQIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQADj97RFNHJSr9VsfY89V0fh+afTloloZLinYrCftHGXZYTFwkm4u7djNb5pnagpIeI0KRY4Z9L4CaQFG9yWPuvc6J+Djmm1T3hzwTQSbcQlAQPi0G/++hmbHNDY0cW7v4h7bV+fHiKMReurg8P0C27TOC9PjkWOgd9xyJt67xX/w/yM4plc8vE+E9WJ293EDQoO72BUxwJPAvmsmBxCotusJhVHqfhaI23CZVEtHmhtav+K9y7HfyGOjCQg8a+P9BLxAltJc/fgfNXNSNVUUMvgEWB9VTPJEZ+CbXoNXwHbTkQ9hh0pVexKlfz2cWavBOCp86XCbpWZSHzSh+7Fjvn"
      ],
      "x5t#S256": "6SIMvPp5sYE80UhE8MhmtPrYj_5WgsX7u31MZceUc6k",
      "n": "sFPq-elUjVDaEYBgoTsIyy1qLJnDSi0MUA0qMZi4TE9-ouS792ID0-yJDgVnm1GvC1mxI2stSKm3t9fjMzDbL84LCy_lcKgyEjI1LZIf40pVZVJB4OLdcAxjC6ICMWU7bRTCw1KhG0nqyCfhACxE-2_TYnWZ1FgAgo_dBPkw8E8dFLaNUuKWKRTtaYUH8qjMrw-5ah-zL0_7DmVt63o6dOoAP7oOVid-tfMVX_zudUB3ol6kAcKbKIBqYtZXK2IqfJK16bXt7OncM9JXH2Mp_ksOmxqVx7mwWqFqxTkHvME-8H1vUWHOO1Y5B9jQCFqvf9uNRm11akTARt0oBC_vgQ",
      "e": "AQAB"
    }
  ]
}
2022-07-11 17:30:40 SUCCESS
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2022-07-11 17:30:40 SUCCESS
CheckForKeyIdInServerJWKs
All keys contain kids
2022-07-11 17:30:40 SUCCESS
EnsureServerJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2022-07-11 17:30:40 SUCCESS
FAPIEnsureMinimumServerKeyLength
Validated minimum key lengths for server_jwks
server_jwks
{
  "keys": [
    {
      "kid": "server",
      "kty": "RSA",
      "use": "sig",
      "x5c": [
        "MIIDLDCCAhSgAwIBAgIEXCMj+jANBgkqhkiG9w0BAQsFADBYMQkwBwYDVQQGEwAxCTAHBgNVBAgTADEJMAcGA1UEBxMAMQkwBwYDVQQKEwAxCTAHBgNVBAsTADEfMB0GA1UEAxMWZmFwaXBvYy52ZXJpZnkuaWJtLmNvbTAeFw0yMjA2MDYwNTI3MzRaFw0zMjA2MDMwNTI3MzRaMFgxCTAHBgNVBAYTADEJMAcGA1UECBMAMQkwBwYDVQQHEwAxCTAHBgNVBAoTADEJMAcGA1UECxMAMR8wHQYDVQQDExZmYXBpcG9jLnZlcmlmeS5pYm0uY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsFPq+elUjVDaEYBgoTsIyy1qLJnDSi0MUA0qMZi4TE9+ouS792ID0+yJDgVnm1GvC1mxI2stSKm3t9fjMzDbL84LCy/lcKgyEjI1LZIf40pVZVJB4OLdcAxjC6ICMWU7bRTCw1KhG0nqyCfhACxE+2/TYnWZ1FgAgo/dBPkw8E8dFLaNUuKWKRTtaYUH8qjMrw+5ah+zL0/7DmVt63o6dOoAP7oOVid+tfMVX/zudUB3ol6kAcKbKIBqYtZXK2IqfJK16bXt7OncM9JXH2Mp/ksOmxqVx7mwWqFqxTkHvME+8H1vUWHOO1Y5B9jQCFqvf9uNRm11akTARt0oBC/vgQIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQADj97RFNHJSr9VsfY89V0fh+afTloloZLinYrCftHGXZYTFwkm4u7djNb5pnagpIeI0KRY4Z9L4CaQFG9yWPuvc6J+Djmm1T3hzwTQSbcQlAQPi0G/++hmbHNDY0cW7v4h7bV+fHiKMReurg8P0C27TOC9PjkWOgd9xyJt67xX/w/yM4plc8vE+E9WJ293EDQoO72BUxwJPAvmsmBxCotusJhVHqfhaI23CZVEtHmhtav+K9y7HfyGOjCQg8a+P9BLxAltJc/fgfNXNSNVUUMvgEWB9VTPJEZ+CbXoNXwHbTkQ9hh0pVexKlfz2cWavBOCp86XCbpWZSHzSh+7Fjvn"
      ],
      "x5t#S256": "6SIMvPp5sYE80UhE8MhmtPrYj_5WgsX7u31MZceUc6k",
      "n": "sFPq-elUjVDaEYBgoTsIyy1qLJnDSi0MUA0qMZi4TE9-ouS792ID0-yJDgVnm1GvC1mxI2stSKm3t9fjMzDbL84LCy_lcKgyEjI1LZIf40pVZVJB4OLdcAxjC6ICMWU7bRTCw1KhG0nqyCfhACxE-2_TYnWZ1FgAgo_dBPkw8E8dFLaNUuKWKRTtaYUH8qjMrw-5ah-zL0_7DmVt63o6dOoAP7oOVid-tfMVX_zudUB3ol6kAcKbKIBqYtZXK2IqfJK16bXt7OncM9JXH2Mp_ksOmxqVx7mwWqFqxTkHvME-8H1vUWHOO1Y5B9jQCFqvf9uNRm11akTARt0oBC_vgQ",
      "e": "AQAB"
    }
  ]
}
2022-07-11 17:30:40 SUCCESS
GetStaticClientConfiguration
Found a static client object
client_id
e6ccf44d-838d-4bec-9d7e-0c1bf6677b8c
client_secret
ZbBKKNhJPo
scope
openid email
jwks
{
  "keys": [
    {
      "p": "-JkZq0-X1RAO2UtEohS_gpRIW6vXFq8f_4eldFP7qXQcHzsSfFrul14pXG7grNokcA5S3w7HSBXQXQ7WdVeN-nZSI_232NSyF3GRkiINenSUMoz8_7zKy2MUvo9gW8WkaOlMOv5l8H781ZDfQvMCNjmwb2zE4q8qNbv2ZnA_gfc",
      "kty": "RSA",
      "q": "tj8Ug4uHQnfJEXdNKCPPbUD4kPMNu4T0pAf7lUkZ4Aa56CxKds063qUvdtyPYSiTKlpdAVYibqSyLBauG_RjPDcD6zrziKO93o42mX2Fr4fZJaWFKqlAqA3fZycWyu-VDrjF14QmDUS4NPnnQ7_UuiKYr5o3hO8-iJrW8z4VQJc",
      "d": "j_TQo4CwQ9GHOy2hCJJJfV1rUVxQpWmljB4SNBcJ4cZWbMVc0qRTL9awlgIvFCYmO2H97q3CLJAjigPGNta-TCI1eEbuaTsGrLwsjUrycQz7EIZf_i9rdj3lRhJ-gLpgO2Fj6_hfQLMHQ0yhiHi09FPLpJfPpicqEHwwmwNLQGIwN88c-TDDX2D4Iw3geygigqRnWviDVMejuRL2Luordiw7XOJHzY2BGwqOZdgqYfVS6Dr6PjOaOwWDJ7w9pHT19zz3UEXiarzA-AZKSZtxOoNVSliltj0nIzhVN0fd7g0Ljt13LjrGuyLSrAoTCZdQpCZ0uX02leqFkCAOkCzWlQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "fapips1",
      "qi": "sNIuSo-uVI0TrtcR_6ZdGkps2MIWmVRhqBCKDxJAm21RkW7Sv0buRD8KPSP7WA20KTgs3O9i1Hz6bD8U2Hkjt3rk6MP59JvQev1DxFD8yA_A6aaIHk6Z7BryX5QOJzj0tzIB1tVzrSViVdDg0LUOO5yZdm_IQSU4AN-aaxjrpvA",
      "dp": "NnHJVmRzGz2OEvbSDDFBFAcHpdQHojcuadc6XDS8bAs60Xgtf0Cm-k2r_0tlN1X7HvN0INfquxXT8V17iG1pcc4SBUHezsUeT9YWjIuaqhP4FO4dxqCBRXPoqidach7h9_wILu9iQf59vwQgcVgpRtjxlCWdJQw50VTeDOdOcVc",
      "alg": "PS256",
      "dq": "qwl0dShDnuvQdmXisaM6Dq0FGvQglTZoanFbeXWLpSZq3yyCDhD6CO46J3FD1sk_pGX-Fz0BP5mt5Za7fFzVrTNsqB1BZaFWlkIdl9un1V7HOn-nBKynk5DBc4vJ5lcHKzPZ6TOKirVNs9o9YuXr_Wxuo482P7pQk9_Nj6daRq0",
      "n": "sPoZ2M-WhvDJchlxahAPDtkSaRlXWIK17NF2qHn3RgWUw0Z4XyptMWi-HMwxwwwApCi_g7ytaJ4DBDo5DY-pumFZHdj4mcD8Nb2XhV5smMO3-XABBVAuNH6VW4sFeb6bvlVBNyoHpAA_4VyMCYTjZffxGIqXpyxIND1M5zwP8RaZc1_Yo4yakZa15wXirbwZkCArJaIROpKy5xXFPA_2p4w7PnTQshAqjJx2Jz8N5CKsEvUvHNEg7pfeL1hTqLk1KRpLRh8QZKwfEjuxg0KFIGmi45gAX8SCjjX-BBffN6C7VELESRzILSlCEbTL_hslQkSQNbmyqI--kWCgkTZosQ"
    }
  ]
}
2022-07-11 17:30:40
ValidateMTLSCertificatesHeader
No certificate authority found for MTLS
2022-07-11 17:30:40 SUCCESS
ValidateMTLSCertificatesHeader
MTLS certificates header is valid
2022-07-11 17:30:40
ExtractMTLSCertificatesFromConfiguration
No certificate authority found for MTLS
2022-07-11 17:30:40 SUCCESS
ExtractMTLSCertificatesFromConfiguration
Mutual TLS authentication credentials loaded
cert
MIID2TCCA36gAwIBAgIUKXA8+q3GoAhthdhhMdI7y02Mg+4wCgYIKoZIzj0EAwIwgYExCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhOZXcgWW9yazE0MDIGA1UECgwrSW50ZXJuYXRpb25hbCBCdXNpbmVzcyBNYWNoaW5lcyBDb3Jwb3JhdGlvbjEpMCcGA1UEAwwgSUJNIFNlY3VyaXR5IFZlcmlmeSBEZXYtSVRFIENBLTEwHhcNMjIwMjEwMTU1ODAwWhcNMjUwMjA5MTU1ODAwWjB0MQswCQYDVQQGEwJTRzETMBEGA1UECBMKa2NhMmNzci1TVDESMBAGA1UEBxMJa2NhMmNzci1MMRIwEAYDVQQKEwlrY2EyY3NyLU8xEzARBgNVBAsTCmtjYTJjc3ItT1UxEzARBgNVBAMTCmtjYTJjc3ItQ04wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCV6uh9e1Z54rwv4amn0M10uJqPtxZH45MsDyjVafe/5p1N8M2Zl2LQfSWHOvXtFBZlr72bz1TrZf8cuXn9WetXDg7FqElTxgV75uGubd1RpUKkFnN8dBSq1oadvpmU+1Ov7mRKzh3cPlbYX7Dwr372ZVGuumwjwVVfszmwA2bKy+bN7JvN41vic3OnAm+uBq5sB4HN87x3+hN/Z4rkO8HEdVgEwzQSXprs52vnPAt41Jn/RPx5+Z5yIGKuS10GCT1e19Afh4hgZfCRTBLCGDldJwemhVD2MDET4qYyhW/BkLzc3+3OjiXU10+NpCP+SC88WQp3U8Z24qlyLHA9prKXAgMBAAGjggETMIIBDzAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwIwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUSKev5Wnf5dBO/838Jt87ZcwqXbIwHwYDVR0jBBgwFoAUVG35JNW6n95CIBrdXCkTvAi9lhAwgZkGA1UdEQSBkTCBjoIPd3d3LmV4YW1wbGUuY29tghB0ZXN0LmV4YW1wbGUuY29tghBtYWlsLmV4YW1wbGUuY29tgg93d3cuZXhhbXBsZS5uZXSBE3NoYW5rYXJ2QHNnLmlibS5jb22HBMAAAgGHBMYzZP6HECABDbgAAAAAAAAAAAAAAAGGE2h0dHBzOi8vamtlLmNvbS9mb28wCgYIKoZIzj0EAwIDSQAwRgIhALF8B38YTP3q+Bf1wrcCBSL/ssGhO6H1NaWUykHSxYQqAiEAgTeJC+4FXvklUnjJEabkAeZU/oycGMPI/u0Z56fq984=
key
MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQCV6uh9e1Z54rwv4amn0M10uJqPtxZH45MsDyjVafe/5p1N8M2Zl2LQfSWHOvXtFBZlr72bz1TrZf8cuXn9WetXDg7FqElTxgV75uGubd1RpUKkFnN8dBSq1oadvpmU+1Ov7mRKzh3cPlbYX7Dwr372ZVGuumwjwVVfszmwA2bKy+bN7JvN41vic3OnAm+uBq5sB4HN87x3+hN/Z4rkO8HEdVgEwzQSXprs52vnPAt41Jn/RPx5+Z5yIGKuS10GCT1e19Afh4hgZfCRTBLCGDldJwemhVD2MDET4qYyhW/BkLzc3+3OjiXU10+NpCP+SC88WQp3U8Z24qlyLHA9prKXAgMBAAECggEAQrpw6i1kU9M2hS9x9tarJHlonnBVVAE5CCLlP3yvwDRTLxZwRR2LZ5ZUhmkZfoFy6Kb9A+WYfECFeVEbOcf0xuZkb9kUblvVJA2jxSJ0oLsouuWdWLdIXbQn7f2g2Z22Zbf73wn4Y4hB2oRZOwA6SEzXuyiSKqYKrJKXKj+RWNETjUt/7H4skIDafFhgo1+V7ZbuMJxdp4xVp98g3mxyUj1hthg3RNDpiapqElobSEKlUnYQVpRfBRIAFWtRvO4ZjwFFOgpTel3E6gm34miTN5Vp2Je+C02LAx04G5bCOPe6EwESZEPeVE6nbjvw1wM2Nl8GkwEGweDNM165y/8T1QKBgQDO7XHODYgmb1vA7Dk4XDQkqgvFpMqQTNvxgXarK9lDNaQBDoXZjp+PQ4ZG7UY9SZ82uPz/kZLlZJeXGg1Cd3v2ErLQXWrq8IHY+IwgXt0/jForLnRihGwqKg7J801PPbOM4BCh3LpZwCoiVXCAOCSA++h8CBBffZ97eiiPAcO6lQKBgQC5eGVhLebWsrOgKqr7ouSeT0BuVb8rXt2MaYTVwTFs+BsbUOnwYcXYBeV4mtgtLmf7C6m5NoTWOGsFdjmk51uHC5k/h9fXf1EnQBbVjZDsIelCzAeWkwxDiDtuwChB3cLk64qtmLRy0rHAUJvfG93/UbaO/LxZwyPvtL9ylHWZewKBgBAUqcRujscV3laGxQeZOsAiqtmILem631jMS9GPjcnIUF94pnQ6vjGe+L9oTw4SO5pAFAE0aesDvzgR4TfqGysLVvQUXmu1lxGqdxFI7f6zRIqYiJjjW5iHPjD5hGeFDwACpag+hAjXgy653w1Hz6ZqbS2+Xq9dDtjErIQ4ieJlAoGBAIdvjJB/RW8IhbTzE3K3y7xy4PjxMq1IE/6B21eAQUhykNDMsFgx/Zg3Dg+Y+z1bAuFG7gRq9Gu+PSB66bMqoyKlbJ4A47Pgq/E+kq4VN3vHc5+sf+oLrUvvQn8oYP1gI/6opdcIiNTEWLq34mr03ZKhJ++YTS47GpXjZl4UXR/bAoGARrRC3D0HNCw2dQZ8jXFoEfXU7lHuCOBFTZQz/mGlGdSXm9hoZkb1nOTVxJhj+WG35HQn4FWDQHLX1i9g4QnopJ7Ga80VNNdmq+ub9nEx9e1YmLlD5skazO8mwIOmAyyi2FBKYGtXhA9nYO4AdfcbG6ENTwoX/IjA62IG+5gNvoo=
2022-07-11 17:30:40 SUCCESS
ValidateClientJWKsPrivatePart
Valid client JWKs: keys are valid JSON, contain the required fields, the private/public exponents match and are correctly encoded using unpadded base64url
2022-07-11 17:30:40 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "p": "-JkZq0-X1RAO2UtEohS_gpRIW6vXFq8f_4eldFP7qXQcHzsSfFrul14pXG7grNokcA5S3w7HSBXQXQ7WdVeN-nZSI_232NSyF3GRkiINenSUMoz8_7zKy2MUvo9gW8WkaOlMOv5l8H781ZDfQvMCNjmwb2zE4q8qNbv2ZnA_gfc",
      "kty": "RSA",
      "q": "tj8Ug4uHQnfJEXdNKCPPbUD4kPMNu4T0pAf7lUkZ4Aa56CxKds063qUvdtyPYSiTKlpdAVYibqSyLBauG_RjPDcD6zrziKO93o42mX2Fr4fZJaWFKqlAqA3fZycWyu-VDrjF14QmDUS4NPnnQ7_UuiKYr5o3hO8-iJrW8z4VQJc",
      "d": "j_TQo4CwQ9GHOy2hCJJJfV1rUVxQpWmljB4SNBcJ4cZWbMVc0qRTL9awlgIvFCYmO2H97q3CLJAjigPGNta-TCI1eEbuaTsGrLwsjUrycQz7EIZf_i9rdj3lRhJ-gLpgO2Fj6_hfQLMHQ0yhiHi09FPLpJfPpicqEHwwmwNLQGIwN88c-TDDX2D4Iw3geygigqRnWviDVMejuRL2Luordiw7XOJHzY2BGwqOZdgqYfVS6Dr6PjOaOwWDJ7w9pHT19zz3UEXiarzA-AZKSZtxOoNVSliltj0nIzhVN0fd7g0Ljt13LjrGuyLSrAoTCZdQpCZ0uX02leqFkCAOkCzWlQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "fapips1",
      "qi": "sNIuSo-uVI0TrtcR_6ZdGkps2MIWmVRhqBCKDxJAm21RkW7Sv0buRD8KPSP7WA20KTgs3O9i1Hz6bD8U2Hkjt3rk6MP59JvQev1DxFD8yA_A6aaIHk6Z7BryX5QOJzj0tzIB1tVzrSViVdDg0LUOO5yZdm_IQSU4AN-aaxjrpvA",
      "dp": "NnHJVmRzGz2OEvbSDDFBFAcHpdQHojcuadc6XDS8bAs60Xgtf0Cm-k2r_0tlN1X7HvN0INfquxXT8V17iG1pcc4SBUHezsUeT9YWjIuaqhP4FO4dxqCBRXPoqidach7h9_wILu9iQf59vwQgcVgpRtjxlCWdJQw50VTeDOdOcVc",
      "alg": "PS256",
      "dq": "qwl0dShDnuvQdmXisaM6Dq0FGvQglTZoanFbeXWLpSZq3yyCDhD6CO46J3FD1sk_pGX-Fz0BP5mt5Za7fFzVrTNsqB1BZaFWlkIdl9un1V7HOn-nBKynk5DBc4vJ5lcHKzPZ6TOKirVNs9o9YuXr_Wxuo482P7pQk9_Nj6daRq0",
      "n": "sPoZ2M-WhvDJchlxahAPDtkSaRlXWIK17NF2qHn3RgWUw0Z4XyptMWi-HMwxwwwApCi_g7ytaJ4DBDo5DY-pumFZHdj4mcD8Nb2XhV5smMO3-XABBVAuNH6VW4sFeb6bvlVBNyoHpAA_4VyMCYTjZffxGIqXpyxIND1M5zwP8RaZc1_Yo4yakZa15wXirbwZkCArJaIROpKy5xXFPA_2p4w7PnTQshAqjJx2Jz8N5CKsEvUvHNEg7pfeL1hTqLk1KRpLRh8QZKwfEjuxg0KFIGmi45gAX8SCjjX-BBffN6C7VELESRzILSlCEbTL_hslQkSQNbmyqI--kWCgkTZosQ"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "fapips1",
      "alg": "PS256",
      "n": "sPoZ2M-WhvDJchlxahAPDtkSaRlXWIK17NF2qHn3RgWUw0Z4XyptMWi-HMwxwwwApCi_g7ytaJ4DBDo5DY-pumFZHdj4mcD8Nb2XhV5smMO3-XABBVAuNH6VW4sFeb6bvlVBNyoHpAA_4VyMCYTjZffxGIqXpyxIND1M5zwP8RaZc1_Yo4yakZa15wXirbwZkCArJaIROpKy5xXFPA_2p4w7PnTQshAqjJx2Jz8N5CKsEvUvHNEg7pfeL1hTqLk1KRpLRh8QZKwfEjuxg0KFIGmi45gAX8SCjjX-BBffN6C7VELESRzILSlCEbTL_hslQkSQNbmyqI--kWCgkTZosQ"
    }
  ]
}
2022-07-11 17:30:40 SUCCESS
CheckForKeyIdInClientJWKs
All keys contain kids
2022-07-11 17:30:40 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2022-07-11 17:30:40 SUCCESS
FAPICheckKeyAlgInClientJWKs
Keys in client JWKS all have permitted 'alg'
permitted
[
  "PS256",
  "ES256"
]
2022-07-11 17:30:40 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "p": "-JkZq0-X1RAO2UtEohS_gpRIW6vXFq8f_4eldFP7qXQcHzsSfFrul14pXG7grNokcA5S3w7HSBXQXQ7WdVeN-nZSI_232NSyF3GRkiINenSUMoz8_7zKy2MUvo9gW8WkaOlMOv5l8H781ZDfQvMCNjmwb2zE4q8qNbv2ZnA_gfc",
      "kty": "RSA",
      "q": "tj8Ug4uHQnfJEXdNKCPPbUD4kPMNu4T0pAf7lUkZ4Aa56CxKds063qUvdtyPYSiTKlpdAVYibqSyLBauG_RjPDcD6zrziKO93o42mX2Fr4fZJaWFKqlAqA3fZycWyu-VDrjF14QmDUS4NPnnQ7_UuiKYr5o3hO8-iJrW8z4VQJc",
      "d": "j_TQo4CwQ9GHOy2hCJJJfV1rUVxQpWmljB4SNBcJ4cZWbMVc0qRTL9awlgIvFCYmO2H97q3CLJAjigPGNta-TCI1eEbuaTsGrLwsjUrycQz7EIZf_i9rdj3lRhJ-gLpgO2Fj6_hfQLMHQ0yhiHi09FPLpJfPpicqEHwwmwNLQGIwN88c-TDDX2D4Iw3geygigqRnWviDVMejuRL2Luordiw7XOJHzY2BGwqOZdgqYfVS6Dr6PjOaOwWDJ7w9pHT19zz3UEXiarzA-AZKSZtxOoNVSliltj0nIzhVN0fd7g0Ljt13LjrGuyLSrAoTCZdQpCZ0uX02leqFkCAOkCzWlQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "fapips1",
      "qi": "sNIuSo-uVI0TrtcR_6ZdGkps2MIWmVRhqBCKDxJAm21RkW7Sv0buRD8KPSP7WA20KTgs3O9i1Hz6bD8U2Hkjt3rk6MP59JvQev1DxFD8yA_A6aaIHk6Z7BryX5QOJzj0tzIB1tVzrSViVdDg0LUOO5yZdm_IQSU4AN-aaxjrpvA",
      "dp": "NnHJVmRzGz2OEvbSDDFBFAcHpdQHojcuadc6XDS8bAs60Xgtf0Cm-k2r_0tlN1X7HvN0INfquxXT8V17iG1pcc4SBUHezsUeT9YWjIuaqhP4FO4dxqCBRXPoqidach7h9_wILu9iQf59vwQgcVgpRtjxlCWdJQw50VTeDOdOcVc",
      "alg": "PS256",
      "dq": "qwl0dShDnuvQdmXisaM6Dq0FGvQglTZoanFbeXWLpSZq3yyCDhD6CO46J3FD1sk_pGX-Fz0BP5mt5Za7fFzVrTNsqB1BZaFWlkIdl9un1V7HOn-nBKynk5DBc4vJ5lcHKzPZ6TOKirVNs9o9YuXr_Wxuo482P7pQk9_Nj6daRq0",
      "n": "sPoZ2M-WhvDJchlxahAPDtkSaRlXWIK17NF2qHn3RgWUw0Z4XyptMWi-HMwxwwwApCi_g7ytaJ4DBDo5DY-pumFZHdj4mcD8Nb2XhV5smMO3-XABBVAuNH6VW4sFeb6bvlVBNyoHpAA_4VyMCYTjZffxGIqXpyxIND1M5zwP8RaZc1_Yo4yakZa15wXirbwZkCArJaIROpKy5xXFPA_2p4w7PnTQshAqjJx2Jz8N5CKsEvUvHNEg7pfeL1hTqLk1KRpLRh8QZKwfEjuxg0KFIGmi45gAX8SCjjX-BBffN6C7VELESRzILSlCEbTL_hslQkSQNbmyqI--kWCgkTZosQ"
    }
  ]
}
2022-07-11 17:30:40 SUCCESS
ValidateMTLSCertificatesAsX509
Mutual TLS authentication cert validated as X.509
Verify configuration of second client
2022-07-11 17:30:40 SUCCESS
GetStaticClient2Configuration
Found a static second client object
client_id
58a92455-980a-424a-8be2-d9c77f4d6cd9
scope
openid email
jwks
{
  "keys": [
    {
      "p": "_V4SSh_YdQH3_c3zAUQ4RgxImgnYHPRZuVcfRuVztq6fHs1xI5Qcri4wSyfmcQgu-Caos_5Htu6iOrrMnA0Si8s6rsU8lzGCgBF0clQeEdUGX1YKqsTw2OrdcFhjwZWO59uBcmUXw8xw-EMlA_9x82HVKwZcPW94fRJJeUC80Pk",
      "kty": "RSA",
      "q": "jt6KCTdVQV6MLruoTlKPN9MtlLZ16TR-5GUareWhr8GGn81mto_Ua0eCZHGCnleAYzI3il66PvF4ribDXXOHhn6iBiIHph2Oge1Q73gSjdClHGrTq7EHi_yEeoPxXXD8siEplKcREsWtby8XTUktG0GaIg2XgocVpj7AEn_QewM",
      "d": "JhMR3QAhmiyBWEFvYJF7t5ohNOrRa5DWJi1sBmq_baADjt_DuEGBX3mQ2ZCHdWGjIznlqg9NuewHu1RykRujwFImBJaK5XMIdQoDDHlja3jBg-cp6swoQUBrOv0Amq-Co-qmtn5D7gaEkO4cJD1AM_ZJSKYus9k1ra3mEGPPUKiSknjICvZ4zEd28mJG_ZTMa5y_G3NrqkkjeLoej86Ru0yHLjYo3ZpXvbRspnlmAqganHVo7CjeBqW8ov2fS6hyRxPRDHfyw-fKHBcLFVqGNTw9-vfqXWfTBB4kwHmSwfJ5jF19UBenKk77eyzOcdwQeSDUKUeS5Ni6_cpvDe9HEQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "fapips2",
      "qi": "jRUHNAE9Rq9slhKVJaHTDc56L040JIlc92nS1lW5tXxwT1032yjOHqvxkUafFsRl2Y_HJhNMXiZH89zk8QIGgO_-o2sOhlVYReE9HZpXaZQegicuG8Oc7AuH78EbPjeBml2ph1B4UV1r1L9EDg6C5otTMvi7AxIG5SH1nDsB8LA",
      "dp": "7hq6y2g0DnnkKWOjS_xlegbPL9uyejt0GoZygTjezr46EUN2YL4vWc1UWzzLBkxvf4stHcIIeTS3xsOHx9tNI4zAwD_hWiEQB_TfXxYIEDAGxg9hBO0Bfojxw0N9tA4t91zEwNGaTMpTHCxVm_UyjEvTfZSDmMSqEbfezpF1IFk",
      "alg": "PS256",
      "dq": "XPniZyEFcKcxH3CslVwRLElYToF3tq6dLdHGTQk18gVFsVWg1IpBuRcuemOMl7NmMCgMERaYqkHHQb6kQXrf5d0fYFJhG-_8P_3LQCyqFnSEHzw-SGvK94T8Sib3utG_AcWnI8Cd0dOnjMXeqkNHAYft4N9rjFyQ8EHCCcf4SzU",
      "n": "jWZuVs7f3z7SVFMH9tggC-wbx_JIEy59aScoFGhb64IoKt886ftpFht6_WTwJJKkMxQiPDeHUmi7xAC5TWV1OmrGOv4QKQ2P-u3wvvkFTrOUFGCVRgZl8dJ8I85StneVZXbVaQ6sJBH3x_wgtAT_KWUOrgs4Asi1QoHU1Qs1m-_lf0nkL7aYJDOBYpY9LYtj8NuNLaKSJSTjkZIabDJzTboNvDarS3YLQiS-LVJSD9svfK3HwAq9XV3-LEpNkqT6xCe1TJiOT-4taXwRTjyoZ9z_ejgjnpPL1AD7TkXgxTIpCQ6vGgq9j4YyUy5QIf9QZnA71L4Xj41WddUdy-4V6w"
    }
  ]
}
2022-07-11 17:30:40
ValidateMTLSCertificates2Header
No certificate authority found for MTLS
2022-07-11 17:30:40 SUCCESS
ValidateMTLSCertificates2Header
MTLS certificates header is valid
2022-07-11 17:30:40
ExtractMTLSCertificates2FromConfiguration
No certificate authority found for MTLS
2022-07-11 17:30:40 SUCCESS
ExtractMTLSCertificates2FromConfiguration
Mutual TLS authentication credentials loaded
cert
MIID1zCCA36gAwIBAgIUUHDgxG3lPQuGjbIG+p3wWr7606YwCgYIKoZIzj0EAwIwgYExCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhOZXcgWW9yazE0MDIGA1UECgwrSW50ZXJuYXRpb25hbCBCdXNpbmVzcyBNYWNoaW5lcyBDb3Jwb3JhdGlvbjEpMCcGA1UEAwwgSUJNIFNlY3VyaXR5IFZlcmlmeSBEZXYtSVRFIENBLTEwHhcNMjIwMzEyMTQzMzAwWhcNMjUwMzExMTQzMzAwWjB0MQswCQYDVQQGEwJTRzETMBEGA1UECBMKa2NhMmNzci1TVDESMBAGA1UEBxMJa2NhMmNzci1MMRIwEAYDVQQKEwlrY2EyY3NyLU8xEzARBgNVBAsTCmtjYTJjc3ItT1UxEzARBgNVBAMTCmtjYTJjc3ItQ04wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDQSJq6kA1B0OlrFvgxfw61M3Fee4Nq9+ziUOAY+ffzybS0fhCJkjKwWG9f9p/CoJGSaqVzHoa13Sgw/3L186pyyFVnX2E9KTujNOkCVWuiyE99gHiI3fZPbYqbJwKsbb8RQuPQKoMGz22RTppshlrHJJmTn0VYUGlSRGZrcnvRXsl3eegcTiQ1/jwnLQRoJ96FA3Tl0KCy6qsGNWF2wq7qIboBDb/irgqHAwX9Lb5wL+idsill1m9gpK7PKkjTJjvdRcKIH3B3G+zNdEZeB5y/S1JnID/cLUFwF8IeSDWjqZDi4KJckZXxvI2pl1L5wAqaWFuGHCvE/Cmvdw7oyYnHAgMBAAGjggETMIIBDzAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwIwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUecSZVVi1AFZBn1qATTpubMpMEVMwHwYDVR0jBBgwFoAUVG35JNW6n95CIBrdXCkTvAi9lhAwgZkGA1UdEQSBkTCBjoIPd3d3LmV4YW1wbGUuY29tghB0ZXN0LmV4YW1wbGUuY29tghBtYWlsLmV4YW1wbGUuY29tgg93d3cuZXhhbXBsZS5uZXSBE3NoYW5rYXJ2QHNnLmlibS5jb22HBMAAAgGHBMYzZP6HECABDbgAAAAAAAAAAAAAAAGGE2h0dHBzOi8vamtlLmNvbS9mb28wCgYIKoZIzj0EAwIDRwAwRAIgOsqCg6PJbj5rIh67VUxJEcBiQChb5D8+cd5e7zJhojUCID2AHsLHHqHtuXRQUVikneUewh4sFYU8xhWKjvHSqp4a
key
MIIEpAIBAAKCAQEA0EiaupANQdDpaxb4MX8OtTNxXnuDavfs4lDgGPn388m0tH4QiZIysFhvX/afwqCRkmqlcx6Gtd0oMP9y9fOqcshVZ19hPSk7ozTpAlVroshPfYB4iN32T22KmycCrG2/EULj0CqDBs9tkU6abIZaxySZk59FWFBpUkRma3J70V7Jd3noHE4kNf48Jy0EaCfehQN05dCgsuqrBjVhdsKu6iG6AQ2/4q4KhwMF/S2+cC/onbIpZdZvYKSuzypI0yY73UXCiB9wdxvszXRGXgecv0tSZyA/3C1BcBfCHkg1o6mQ4uCiXJGV8byNqZdS+cAKmlhbhhwrxPwpr3cO6MmJxwIDAQABAoIBAG7VU9DW+tb9Dli4HlZoYDE4MKmwXBw91cYQd0+TJMiLmyc4tiAete51AL82A4mT3CLnsSbzJYf9KXf5VvleMmNmC1w4uwvKtzt/2kYtols68GG+TWW3h2x4w/sP5TJQLA5JY+TP2m1zT8C07SO20vOJnFebt1DpaUInt8CRaSXdriQhnkFXHhIyw2eh9w0u0T1Tq5ng9MgxgVsRg/ZRm9l72j/tR6+Y9P+12wkqH8FuE5E/CIzMlMBzUF4Ng6G08TNxSYaTHiGZXNhZi/zbVCYKsuZsE7qWmvXCysjQ9RYyPl9xH+rP1CiuA5TBmXDGUw5jt7gpxgGnCgQsHd9ffnECgYEA+ZfN75eUGXswIldvVl3czeol0TDKGXPfCerHre7RisM8nzKLino8rz4Hpcl6llUKu/vXde9XFIx1a0SYlkYx+SMCH8hHRgRyV03SOG3WozW9Dlu8OAAtKwsbYRtJKNEBP/TRdlFbE/mpyvfwd16dWh77LJdhtjAWQSp8hCRO8Y0CgYEA1aFWESHWVlvW6Z/IBnU/lLUUgweTNy4WFfeR8TG4mhCrYRpbN7TenIJ/Wzerg/xUg736wIfT89TBuD+i0X12BeoQNttLP5G3pUD8CM+8VpA+hilRqcLgwrjr3367tQT9hd+aDGBd9tgYiwfwxwFVqh6dokzPhqGH9tqz2cWg8aMCgYEAy3cd0O//MhqDLaubPou7wTzcYUDlr4QO0TXMW5Twyq7Hj3uT12o4aB8n+tVZEo329zGg/ioDEeRCoBRGU1Kb0F3ikGgi+ggL8fGlqoyXyWq4WKkdsYUrTQh75Fhq9lQTMcDwtAQ0O/9tk+E07Qp7OYlB9qLda7idm7f3030Jwc0CgYEAqtmd2JPENEq8xRkJQsjwcYCkh+o9/Wp5NVZKvKf0KBrexQjsHNAlHOxs6EnMfQEHolkEuoempiHoT+9syrfY9P/tucGGG6/xPFONfYqN6Hjx2CAhdHAriu+TjKlxe2MjUrayH+XOIEVQ05glIzLZDPXxQcTGT7jN4UmlfqvEfJsCgYAe9MXCus1wBNBeI0tYivXZoX7ewwQv0aTg4oDyFk2mx50FMEdV+AEuq4hWiyaQYewMWPjQr3nSTpmX3DfXm2kOcfXko7mpK9Twzzrv+TRkaH7ECtaoL31wolwePSwtvwPS77OOoBUHO5UKDVyYmZprH4r7gnCpGzGcH140lZv3UQ==
2022-07-11 17:30:40 SUCCESS
ValidateClientJWKsPrivatePart
Valid client JWKs: keys are valid JSON, contain the required fields, the private/public exponents match and are correctly encoded using unpadded base64url
2022-07-11 17:30:40 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "p": "_V4SSh_YdQH3_c3zAUQ4RgxImgnYHPRZuVcfRuVztq6fHs1xI5Qcri4wSyfmcQgu-Caos_5Htu6iOrrMnA0Si8s6rsU8lzGCgBF0clQeEdUGX1YKqsTw2OrdcFhjwZWO59uBcmUXw8xw-EMlA_9x82HVKwZcPW94fRJJeUC80Pk",
      "kty": "RSA",
      "q": "jt6KCTdVQV6MLruoTlKPN9MtlLZ16TR-5GUareWhr8GGn81mto_Ua0eCZHGCnleAYzI3il66PvF4ribDXXOHhn6iBiIHph2Oge1Q73gSjdClHGrTq7EHi_yEeoPxXXD8siEplKcREsWtby8XTUktG0GaIg2XgocVpj7AEn_QewM",
      "d": "JhMR3QAhmiyBWEFvYJF7t5ohNOrRa5DWJi1sBmq_baADjt_DuEGBX3mQ2ZCHdWGjIznlqg9NuewHu1RykRujwFImBJaK5XMIdQoDDHlja3jBg-cp6swoQUBrOv0Amq-Co-qmtn5D7gaEkO4cJD1AM_ZJSKYus9k1ra3mEGPPUKiSknjICvZ4zEd28mJG_ZTMa5y_G3NrqkkjeLoej86Ru0yHLjYo3ZpXvbRspnlmAqganHVo7CjeBqW8ov2fS6hyRxPRDHfyw-fKHBcLFVqGNTw9-vfqXWfTBB4kwHmSwfJ5jF19UBenKk77eyzOcdwQeSDUKUeS5Ni6_cpvDe9HEQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "fapips2",
      "qi": "jRUHNAE9Rq9slhKVJaHTDc56L040JIlc92nS1lW5tXxwT1032yjOHqvxkUafFsRl2Y_HJhNMXiZH89zk8QIGgO_-o2sOhlVYReE9HZpXaZQegicuG8Oc7AuH78EbPjeBml2ph1B4UV1r1L9EDg6C5otTMvi7AxIG5SH1nDsB8LA",
      "dp": "7hq6y2g0DnnkKWOjS_xlegbPL9uyejt0GoZygTjezr46EUN2YL4vWc1UWzzLBkxvf4stHcIIeTS3xsOHx9tNI4zAwD_hWiEQB_TfXxYIEDAGxg9hBO0Bfojxw0N9tA4t91zEwNGaTMpTHCxVm_UyjEvTfZSDmMSqEbfezpF1IFk",
      "alg": "PS256",
      "dq": "XPniZyEFcKcxH3CslVwRLElYToF3tq6dLdHGTQk18gVFsVWg1IpBuRcuemOMl7NmMCgMERaYqkHHQb6kQXrf5d0fYFJhG-_8P_3LQCyqFnSEHzw-SGvK94T8Sib3utG_AcWnI8Cd0dOnjMXeqkNHAYft4N9rjFyQ8EHCCcf4SzU",
      "n": "jWZuVs7f3z7SVFMH9tggC-wbx_JIEy59aScoFGhb64IoKt886ftpFht6_WTwJJKkMxQiPDeHUmi7xAC5TWV1OmrGOv4QKQ2P-u3wvvkFTrOUFGCVRgZl8dJ8I85StneVZXbVaQ6sJBH3x_wgtAT_KWUOrgs4Asi1QoHU1Qs1m-_lf0nkL7aYJDOBYpY9LYtj8NuNLaKSJSTjkZIabDJzTboNvDarS3YLQiS-LVJSD9svfK3HwAq9XV3-LEpNkqT6xCe1TJiOT-4taXwRTjyoZ9z_ejgjnpPL1AD7TkXgxTIpCQ6vGgq9j4YyUy5QIf9QZnA71L4Xj41WddUdy-4V6w"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "fapips2",
      "alg": "PS256",
      "n": "jWZuVs7f3z7SVFMH9tggC-wbx_JIEy59aScoFGhb64IoKt886ftpFht6_WTwJJKkMxQiPDeHUmi7xAC5TWV1OmrGOv4QKQ2P-u3wvvkFTrOUFGCVRgZl8dJ8I85StneVZXbVaQ6sJBH3x_wgtAT_KWUOrgs4Asi1QoHU1Qs1m-_lf0nkL7aYJDOBYpY9LYtj8NuNLaKSJSTjkZIabDJzTboNvDarS3YLQiS-LVJSD9svfK3HwAq9XV3-LEpNkqT6xCe1TJiOT-4taXwRTjyoZ9z_ejgjnpPL1AD7TkXgxTIpCQ6vGgq9j4YyUy5QIf9QZnA71L4Xj41WddUdy-4V6w"
    }
  ]
}
2022-07-11 17:30:40 SUCCESS
CheckForKeyIdInClientJWKs
All keys contain kids
2022-07-11 17:30:40 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2022-07-11 17:30:40 SUCCESS
FAPICheckKeyAlgInClientJWKs
Keys in client JWKS all have permitted 'alg'
permitted
[
  "PS256",
  "ES256"
]
2022-07-11 17:30:40 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "p": "_V4SSh_YdQH3_c3zAUQ4RgxImgnYHPRZuVcfRuVztq6fHs1xI5Qcri4wSyfmcQgu-Caos_5Htu6iOrrMnA0Si8s6rsU8lzGCgBF0clQeEdUGX1YKqsTw2OrdcFhjwZWO59uBcmUXw8xw-EMlA_9x82HVKwZcPW94fRJJeUC80Pk",
      "kty": "RSA",
      "q": "jt6KCTdVQV6MLruoTlKPN9MtlLZ16TR-5GUareWhr8GGn81mto_Ua0eCZHGCnleAYzI3il66PvF4ribDXXOHhn6iBiIHph2Oge1Q73gSjdClHGrTq7EHi_yEeoPxXXD8siEplKcREsWtby8XTUktG0GaIg2XgocVpj7AEn_QewM",
      "d": "JhMR3QAhmiyBWEFvYJF7t5ohNOrRa5DWJi1sBmq_baADjt_DuEGBX3mQ2ZCHdWGjIznlqg9NuewHu1RykRujwFImBJaK5XMIdQoDDHlja3jBg-cp6swoQUBrOv0Amq-Co-qmtn5D7gaEkO4cJD1AM_ZJSKYus9k1ra3mEGPPUKiSknjICvZ4zEd28mJG_ZTMa5y_G3NrqkkjeLoej86Ru0yHLjYo3ZpXvbRspnlmAqganHVo7CjeBqW8ov2fS6hyRxPRDHfyw-fKHBcLFVqGNTw9-vfqXWfTBB4kwHmSwfJ5jF19UBenKk77eyzOcdwQeSDUKUeS5Ni6_cpvDe9HEQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "fapips2",
      "qi": "jRUHNAE9Rq9slhKVJaHTDc56L040JIlc92nS1lW5tXxwT1032yjOHqvxkUafFsRl2Y_HJhNMXiZH89zk8QIGgO_-o2sOhlVYReE9HZpXaZQegicuG8Oc7AuH78EbPjeBml2ph1B4UV1r1L9EDg6C5otTMvi7AxIG5SH1nDsB8LA",
      "dp": "7hq6y2g0DnnkKWOjS_xlegbPL9uyejt0GoZygTjezr46EUN2YL4vWc1UWzzLBkxvf4stHcIIeTS3xsOHx9tNI4zAwD_hWiEQB_TfXxYIEDAGxg9hBO0Bfojxw0N9tA4t91zEwNGaTMpTHCxVm_UyjEvTfZSDmMSqEbfezpF1IFk",
      "alg": "PS256",
      "dq": "XPniZyEFcKcxH3CslVwRLElYToF3tq6dLdHGTQk18gVFsVWg1IpBuRcuemOMl7NmMCgMERaYqkHHQb6kQXrf5d0fYFJhG-_8P_3LQCyqFnSEHzw-SGvK94T8Sib3utG_AcWnI8Cd0dOnjMXeqkNHAYft4N9rjFyQ8EHCCcf4SzU",
      "n": "jWZuVs7f3z7SVFMH9tggC-wbx_JIEy59aScoFGhb64IoKt886ftpFht6_WTwJJKkMxQiPDeHUmi7xAC5TWV1OmrGOv4QKQ2P-u3wvvkFTrOUFGCVRgZl8dJ8I85StneVZXbVaQ6sJBH3x_wgtAT_KWUOrgs4Asi1QoHU1Qs1m-_lf0nkL7aYJDOBYpY9LYtj8NuNLaKSJSTjkZIabDJzTboNvDarS3YLQiS-LVJSD9svfK3HwAq9XV3-LEpNkqT6xCe1TJiOT-4taXwRTjyoZ9z_ejgjnpPL1AD7TkXgxTIpCQ6vGgq9j4YyUy5QIf9QZnA71L4Xj41WddUdy-4V6w"
    }
  ]
}
2022-07-11 17:30:40 SUCCESS
ValidateMTLSCertificatesAsX509
Mutual TLS authentication cert validated as X.509
2022-07-11 17:30:40 SUCCESS
ValidateClientPrivateKeysAreDifferent
Client signing JWKs have different thumbprints
jwk1
{
  "p": "-JkZq0-X1RAO2UtEohS_gpRIW6vXFq8f_4eldFP7qXQcHzsSfFrul14pXG7grNokcA5S3w7HSBXQXQ7WdVeN-nZSI_232NSyF3GRkiINenSUMoz8_7zKy2MUvo9gW8WkaOlMOv5l8H781ZDfQvMCNjmwb2zE4q8qNbv2ZnA_gfc",
  "kty": "RSA",
  "q": "tj8Ug4uHQnfJEXdNKCPPbUD4kPMNu4T0pAf7lUkZ4Aa56CxKds063qUvdtyPYSiTKlpdAVYibqSyLBauG_RjPDcD6zrziKO93o42mX2Fr4fZJaWFKqlAqA3fZycWyu-VDrjF14QmDUS4NPnnQ7_UuiKYr5o3hO8-iJrW8z4VQJc",
  "d": "j_TQo4CwQ9GHOy2hCJJJfV1rUVxQpWmljB4SNBcJ4cZWbMVc0qRTL9awlgIvFCYmO2H97q3CLJAjigPGNta-TCI1eEbuaTsGrLwsjUrycQz7EIZf_i9rdj3lRhJ-gLpgO2Fj6_hfQLMHQ0yhiHi09FPLpJfPpicqEHwwmwNLQGIwN88c-TDDX2D4Iw3geygigqRnWviDVMejuRL2Luordiw7XOJHzY2BGwqOZdgqYfVS6Dr6PjOaOwWDJ7w9pHT19zz3UEXiarzA-AZKSZtxOoNVSliltj0nIzhVN0fd7g0Ljt13LjrGuyLSrAoTCZdQpCZ0uX02leqFkCAOkCzWlQ",
  "e": "AQAB",
  "use": "sig",
  "kid": "fapips1",
  "qi": "sNIuSo-uVI0TrtcR_6ZdGkps2MIWmVRhqBCKDxJAm21RkW7Sv0buRD8KPSP7WA20KTgs3O9i1Hz6bD8U2Hkjt3rk6MP59JvQev1DxFD8yA_A6aaIHk6Z7BryX5QOJzj0tzIB1tVzrSViVdDg0LUOO5yZdm_IQSU4AN-aaxjrpvA",
  "dp": "NnHJVmRzGz2OEvbSDDFBFAcHpdQHojcuadc6XDS8bAs60Xgtf0Cm-k2r_0tlN1X7HvN0INfquxXT8V17iG1pcc4SBUHezsUeT9YWjIuaqhP4FO4dxqCBRXPoqidach7h9_wILu9iQf59vwQgcVgpRtjxlCWdJQw50VTeDOdOcVc",
  "alg": "PS256",
  "dq": "qwl0dShDnuvQdmXisaM6Dq0FGvQglTZoanFbeXWLpSZq3yyCDhD6CO46J3FD1sk_pGX-Fz0BP5mt5Za7fFzVrTNsqB1BZaFWlkIdl9un1V7HOn-nBKynk5DBc4vJ5lcHKzPZ6TOKirVNs9o9YuXr_Wxuo482P7pQk9_Nj6daRq0",
  "n": "sPoZ2M-WhvDJchlxahAPDtkSaRlXWIK17NF2qHn3RgWUw0Z4XyptMWi-HMwxwwwApCi_g7ytaJ4DBDo5DY-pumFZHdj4mcD8Nb2XhV5smMO3-XABBVAuNH6VW4sFeb6bvlVBNyoHpAA_4VyMCYTjZffxGIqXpyxIND1M5zwP8RaZc1_Yo4yakZa15wXirbwZkCArJaIROpKy5xXFPA_2p4w7PnTQshAqjJx2Jz8N5CKsEvUvHNEg7pfeL1hTqLk1KRpLRh8QZKwfEjuxg0KFIGmi45gAX8SCjjX-BBffN6C7VELESRzILSlCEbTL_hslQkSQNbmyqI--kWCgkTZosQ"
}
jwk2
{
  "p": "_V4SSh_YdQH3_c3zAUQ4RgxImgnYHPRZuVcfRuVztq6fHs1xI5Qcri4wSyfmcQgu-Caos_5Htu6iOrrMnA0Si8s6rsU8lzGCgBF0clQeEdUGX1YKqsTw2OrdcFhjwZWO59uBcmUXw8xw-EMlA_9x82HVKwZcPW94fRJJeUC80Pk",
  "kty": "RSA",
  "q": "jt6KCTdVQV6MLruoTlKPN9MtlLZ16TR-5GUareWhr8GGn81mto_Ua0eCZHGCnleAYzI3il66PvF4ribDXXOHhn6iBiIHph2Oge1Q73gSjdClHGrTq7EHi_yEeoPxXXD8siEplKcREsWtby8XTUktG0GaIg2XgocVpj7AEn_QewM",
  "d": "JhMR3QAhmiyBWEFvYJF7t5ohNOrRa5DWJi1sBmq_baADjt_DuEGBX3mQ2ZCHdWGjIznlqg9NuewHu1RykRujwFImBJaK5XMIdQoDDHlja3jBg-cp6swoQUBrOv0Amq-Co-qmtn5D7gaEkO4cJD1AM_ZJSKYus9k1ra3mEGPPUKiSknjICvZ4zEd28mJG_ZTMa5y_G3NrqkkjeLoej86Ru0yHLjYo3ZpXvbRspnlmAqganHVo7CjeBqW8ov2fS6hyRxPRDHfyw-fKHBcLFVqGNTw9-vfqXWfTBB4kwHmSwfJ5jF19UBenKk77eyzOcdwQeSDUKUeS5Ni6_cpvDe9HEQ",
  "e": "AQAB",
  "use": "sig",
  "kid": "fapips2",
  "qi": "jRUHNAE9Rq9slhKVJaHTDc56L040JIlc92nS1lW5tXxwT1032yjOHqvxkUafFsRl2Y_HJhNMXiZH89zk8QIGgO_-o2sOhlVYReE9HZpXaZQegicuG8Oc7AuH78EbPjeBml2ph1B4UV1r1L9EDg6C5otTMvi7AxIG5SH1nDsB8LA",
  "dp": "7hq6y2g0DnnkKWOjS_xlegbPL9uyejt0GoZygTjezr46EUN2YL4vWc1UWzzLBkxvf4stHcIIeTS3xsOHx9tNI4zAwD_hWiEQB_TfXxYIEDAGxg9hBO0Bfojxw0N9tA4t91zEwNGaTMpTHCxVm_UyjEvTfZSDmMSqEbfezpF1IFk",
  "alg": "PS256",
  "dq": "XPniZyEFcKcxH3CslVwRLElYToF3tq6dLdHGTQk18gVFsVWg1IpBuRcuemOMl7NmMCgMERaYqkHHQb6kQXrf5d0fYFJhG-_8P_3LQCyqFnSEHzw-SGvK94T8Sib3utG_AcWnI8Cd0dOnjMXeqkNHAYft4N9rjFyQ8EHCCcf4SzU",
  "n": "jWZuVs7f3z7SVFMH9tggC-wbx_JIEy59aScoFGhb64IoKt886ftpFht6_WTwJJKkMxQiPDeHUmi7xAC5TWV1OmrGOv4QKQ2P-u3wvvkFTrOUFGCVRgZl8dJ8I85StneVZXbVaQ6sJBH3x_wgtAT_KWUOrgs4Asi1QoHU1Qs1m-_lf0nkL7aYJDOBYpY9LYtj8NuNLaKSJSTjkZIabDJzTboNvDarS3YLQiS-LVJSD9svfK3HwAq9XV3-LEpNkqT6xCe1TJiOT-4taXwRTjyoZ9z_ejgjnpPL1AD7TkXgxTIpCQ6vGgq9j4YyUy5QIf9QZnA71L4Xj41WddUdy-4V6w"
}
2022-07-11 17:30:40 SUCCESS
GetResourceEndpointConfiguration
Found a resource endpoint object
resourceUrl
https://fapiresource.dev.vanitytst.cloudidentity.ibm.com/oauth2/open-banking/v3.1/aisp/accounts
2022-07-11 17:30:40 SUCCESS
SetProtectedResourceUrlToSingleResourceEndpoint
Set protected resource URL
protected_resource_url
https://fapiresource.dev.vanitytst.cloudidentity.ibm.com/oauth2/open-banking/v3.1/aisp/accounts
2022-07-11 17:30:40 SUCCESS
ExtractTLSTestValuesFromResourceConfiguration
Extracted TLS information from resource endpoint
resource_endpoint
{
  "testHost": "fapiresource.dev.vanitytst.cloudidentity.ibm.com",
  "testPort": 443
}
2022-07-11 17:30:40 SUCCESS
ExtractTLSTestValuesFromOBResourceConfiguration
Extracted TLS information from resource endpoint
accounts_resource_endpoint
{
  "testHost": "fapiresource.dev.vanitytst.cloudidentity.ibm.com",
  "testPort": 443
}
accounts_request_endpoint
{
  "testHost": "fapiresource.dev.vanitytst.cloudidentity.ibm.com",
  "testPort": 443
}
2022-07-11 17:30:40
fapi1-advanced-final-ensure-request-object-with-long-nonce
Setup Done
Make request to authorization endpoint
2022-07-11 17:30:40 SUCCESS
CreateAuthorizationEndpointRequestFromClientInformation
Created authorization endpoint request
client_id
e6ccf44d-838d-4bec-9d7e-0c1bf6677b8c
redirect_uri
https://www.certification.openid.net/test/a/fapipoc_fapi_dev/callback
scope
openid email
2022-07-11 17:30:40 SUCCESS
AddAcrClaimToAuthorizationEndpointRequest
Added acr claim to authorization_endpoint_request
authorization_endpoint_request
{
  "client_id": "e6ccf44d-838d-4bec-9d7e-0c1bf6677b8c",
  "redirect_uri": "https://www.certification.openid.net/test/a/fapipoc_fapi_dev/callback",
  "scope": "openid email",
  "claims": {
    "id_token": {
      "acr": {
        "value": "urn:mace:incommon:iap:silver",
        "essential": true
      }
    }
  }
}
2022-07-11 17:30:40
CreateRandomStateValue
Created state value
requested_state_length
10
state
exLNNBJ7M2
2022-07-11 17:30:40 SUCCESS
AddStateToAuthorizationEndpointRequest
Added state parameter to request
client_id
e6ccf44d-838d-4bec-9d7e-0c1bf6677b8c
redirect_uri
https://www.certification.openid.net/test/a/fapipoc_fapi_dev/callback
scope
openid email
claims
{
  "id_token": {
    "acr": {
      "value": "urn:mace:incommon:iap:silver",
      "essential": true
    }
  }
}
state
exLNNBJ7M2
2022-07-11 17:30:40
CreateRandomNonceValue
Created nonce value
requested_nonce_length
384
nonce
ekEoPDgSgbL9FmimAk7AuXbjqopqUd5z6wmqTxeE4JpeiTXT7v7yQup7zC5eQJoDSbjTvyxa4Dxn4pcf0c208nAXKgpLkF6c0SOycjW5NyekXOgrUKyW7VirTCRVq02TgP4ENJ9Lhhb3nQxA27iiOxvQUrfEV7eg1apUOJ4nnLq8kOohrwZVhVVywCsnufby6tSCZBFNtsj7cVXHf8viKLHtPku186cfB3romDbvrvTjTLnnlPCqXEgbwglRmwWF6lARdX4uNA9IKA8Ic7hO7E9wFeBrGC3FzlQN8N4uvO1GChXZILrbmRPxNLQbzYPqrP4iuUGpqp6NrnTQS1f0ZsQs4BdcDzGTTosdABJz5O1D4FdPauVUlR1nEilhWvz5
2022-07-11 17:30:40 SUCCESS
AddNonceToAuthorizationEndpointRequest
Added nonce parameter to request
client_id
e6ccf44d-838d-4bec-9d7e-0c1bf6677b8c
redirect_uri
https://www.certification.openid.net/test/a/fapipoc_fapi_dev/callback
scope
openid email
claims
{
  "id_token": {
    "acr": {
      "value": "urn:mace:incommon:iap:silver",
      "essential": true
    }
  }
}
state
exLNNBJ7M2
nonce
ekEoPDgSgbL9FmimAk7AuXbjqopqUd5z6wmqTxeE4JpeiTXT7v7yQup7zC5eQJoDSbjTvyxa4Dxn4pcf0c208nAXKgpLkF6c0SOycjW5NyekXOgrUKyW7VirTCRVq02TgP4ENJ9Lhhb3nQxA27iiOxvQUrfEV7eg1apUOJ4nnLq8kOohrwZVhVVywCsnufby6tSCZBFNtsj7cVXHf8viKLHtPku186cfB3romDbvrvTjTLnnlPCqXEgbwglRmwWF6lARdX4uNA9IKA8Ic7hO7E9wFeBrGC3FzlQN8N4uvO1GChXZILrbmRPxNLQbzYPqrP4iuUGpqp6NrnTQS1f0ZsQs4BdcDzGTTosdABJz5O1D4FdPauVUlR1nEilhWvz5
2022-07-11 17:30:40 SUCCESS
SetAuthorizationEndpointRequestResponseTypeToCodeIdtoken
Added response_type parameter to request
client_id
e6ccf44d-838d-4bec-9d7e-0c1bf6677b8c
redirect_uri
https://www.certification.openid.net/test/a/fapipoc_fapi_dev/callback
scope
openid email
claims
{
  "id_token": {
    "acr": {
      "value": "urn:mace:incommon:iap:silver",
      "essential": true
    }
  }
}
state
exLNNBJ7M2
nonce
ekEoPDgSgbL9FmimAk7AuXbjqopqUd5z6wmqTxeE4JpeiTXT7v7yQup7zC5eQJoDSbjTvyxa4Dxn4pcf0c208nAXKgpLkF6c0SOycjW5NyekXOgrUKyW7VirTCRVq02TgP4ENJ9Lhhb3nQxA27iiOxvQUrfEV7eg1apUOJ4nnLq8kOohrwZVhVVywCsnufby6tSCZBFNtsj7cVXHf8viKLHtPku186cfB3romDbvrvTjTLnnlPCqXEgbwglRmwWF6lARdX4uNA9IKA8Ic7hO7E9wFeBrGC3FzlQN8N4uvO1GChXZILrbmRPxNLQbzYPqrP4iuUGpqp6NrnTQS1f0ZsQs4BdcDzGTTosdABJz5O1D4FdPauVUlR1nEilhWvz5
response_type
code id_token
2022-07-11 17:30:40 SUCCESS
ConvertAuthorizationEndpointRequestToRequestObject
Created request object claims
request_object_claims
{
  "client_id": "e6ccf44d-838d-4bec-9d7e-0c1bf6677b8c",
  "redirect_uri": "https://www.certification.openid.net/test/a/fapipoc_fapi_dev/callback",
  "scope": "openid email",
  "claims": {
    "id_token": {
      "acr": {
        "value": "urn:mace:incommon:iap:silver",
        "essential": true
      }
    }
  },
  "state": "exLNNBJ7M2",
  "nonce": "ekEoPDgSgbL9FmimAk7AuXbjqopqUd5z6wmqTxeE4JpeiTXT7v7yQup7zC5eQJoDSbjTvyxa4Dxn4pcf0c208nAXKgpLkF6c0SOycjW5NyekXOgrUKyW7VirTCRVq02TgP4ENJ9Lhhb3nQxA27iiOxvQUrfEV7eg1apUOJ4nnLq8kOohrwZVhVVywCsnufby6tSCZBFNtsj7cVXHf8viKLHtPku186cfB3romDbvrvTjTLnnlPCqXEgbwglRmwWF6lARdX4uNA9IKA8Ic7hO7E9wFeBrGC3FzlQN8N4uvO1GChXZILrbmRPxNLQbzYPqrP4iuUGpqp6NrnTQS1f0ZsQs4BdcDzGTTosdABJz5O1D4FdPauVUlR1nEilhWvz5",
  "response_type": "code id_token"
}
2022-07-11 17:30:40 SUCCESS
AddNbfToRequestObject
Added nbf to request object claims
nbf
1.65756064E9
2022-07-11 17:30:40 SUCCESS
AddExpToRequestObject
Added exp to request object claims
exp
1.65756094E9
2022-07-11 17:30:40 SUCCESS
AddAudToRequestObject
Added aud to request object claims
aud
https://fapipoc.tryverify.ibm.com/oauth2
2022-07-11 17:30:40 SUCCESS
AddIssToRequestObject
Added iss to request object claims
iss
e6ccf44d-838d-4bec-9d7e-0c1bf6677b8c
2022-07-11 17:30:40 SUCCESS
AddClientIdToRequestObject
Added client_id to request object claims
client_id
e6ccf44d-838d-4bec-9d7e-0c1bf6677b8c
2022-07-11 17:30:40 SUCCESS
SignRequestObject
Signed the request object
claims
{
  "aud": "https://fapipoc.tryverify.ibm.com/oauth2",
  "nbf": 1657560640,
  "scope": "openid email",
  "claims": {
    "id_token": {
      "acr": {
        "value": "urn:mace:incommon:iap:silver",
        "essential": true
      }
    }
  },
  "iss": "e6ccf44d-838d-4bec-9d7e-0c1bf6677b8c",
  "response_type": "code id_token",
  "redirect_uri": "https://www.certification.openid.net/test/a/fapipoc_fapi_dev/callback",
  "state": "exLNNBJ7M2",
  "exp": 1657560940,
  "nonce": "ekEoPDgSgbL9FmimAk7AuXbjqopqUd5z6wmqTxeE4JpeiTXT7v7yQup7zC5eQJoDSbjTvyxa4Dxn4pcf0c208nAXKgpLkF6c0SOycjW5NyekXOgrUKyW7VirTCRVq02TgP4ENJ9Lhhb3nQxA27iiOxvQUrfEV7eg1apUOJ4nnLq8kOohrwZVhVVywCsnufby6tSCZBFNtsj7cVXHf8viKLHtPku186cfB3romDbvrvTjTLnnlPCqXEgbwglRmwWF6lARdX4uNA9IKA8Ic7hO7E9wFeBrGC3FzlQN8N4uvO1GChXZILrbmRPxNLQbzYPqrP4iuUGpqp6NrnTQS1f0ZsQs4BdcDzGTTosdABJz5O1D4FdPauVUlR1nEilhWvz5",
  "client_id": "e6ccf44d-838d-4bec-9d7e-0c1bf6677b8c"
}
header
{
  "kid": "fapips1",
  "alg": "PS256"
}
request_object
eyJraWQiOiJmYXBpcHMxIiwiYWxnIjoiUFMyNTYifQ.eyJhdWQiOiJodHRwczpcL1wvZmFwaXBvYy50cnl2ZXJpZnkuaWJtLmNvbVwvb2F1dGgyIiwibmJmIjoxNjU3NTYwNjQwLCJzY29wZSI6Im9wZW5pZCBlbWFpbCIsImNsYWltcyI6eyJpZF90b2tlbiI6eyJhY3IiOnsidmFsdWUiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiZXNzZW50aWFsIjp0cnVlfX19LCJpc3MiOiJlNmNjZjQ0ZC04MzhkLTRiZWMtOWQ3ZS0wYzFiZjY2NzdiOGMiLCJyZXNwb25zZV90eXBlIjoiY29kZSBpZF90b2tlbiIsInJlZGlyZWN0X3VyaSI6Imh0dHBzOlwvXC93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0XC90ZXN0XC9hXC9mYXBpcG9jX2ZhcGlfZGV2XC9jYWxsYmFjayIsInN0YXRlIjoiZXhMTk5CSjdNMiIsImV4cCI6MTY1NzU2MDk0MCwibm9uY2UiOiJla0VvUERnU2diTDlGbWltQWs3QXVYYmpxb3BxVWQ1ejZ3bXFUeGVFNEpwZWlUWFQ3djd5UXVwN3pDNWVRSm9EU2JqVHZ5eGE0RHhuNHBjZjBjMjA4bkFYS2dwTGtGNmMwU095Y2pXNU55ZWtYT2dyVUt5VzdWaXJUQ1JWcTAyVGdQNEVOSjlMaGhiM25ReEEyN2lpT3h2UVVyZkVWN2VnMWFwVU9KNG5uTHE4a09vaHJ3WlZoVlZ5d0NzbnVmYnk2dFNDWkJGTnRzajdjVlhIZjh2aUtMSHRQa3UxODZjZkIzcm9tRGJ2cnZUalRMbm5sUENxWEVnYndnbFJtd1dGNmxBUmRYNHVOQTlJS0E4SWM3aE83RTl3RmVCckdDM0Z6bFFOOE40dXZPMUdDaFhaSUxyYm1SUHhOTFFiellQcXJQNGl1VUdwcXA2TnJuVFFTMWYwWnNRczRCZGNEekdUVG9zZEFCSno1TzFENEZkUGF1VlVsUjFuRWlsaFd2ejUiLCJjbGllbnRfaWQiOiJlNmNjZjQ0ZC04MzhkLTRiZWMtOWQ3ZS0wYzFiZjY2NzdiOGMifQ.f6jID35JM69EVqIAbn_0W5pQfRzS-3R3AyO6nD-dLdsdioUUYkQu75ib2rDZO1wGDMCSuox0MCwh2DGLKWPk4MVZAYtPl6q4GEjUdlJELpIzh-kOLjEofY9aZ0B96RU6CxkYpj3biZLSE2ySLD43NaSW0lpb2ZN6mDgvznz7oGO6aqAvUoOvDOLEwTanWFtHCVNZwRFxa6bVSBnC2rBOyJ5nPPMCNTYha2pl0G_psRnUwzgHMDjW8IqKj9BOGD5jPSx2Ee5aAf_MVwTnGrPFXLRmk06M0da4-3PNDXNGsLilxYaAIdfqMvYl0KpczPjQQ0tCnzQcUD9wxce1AdM1Sg
key
{
  "p": "-JkZq0-X1RAO2UtEohS_gpRIW6vXFq8f_4eldFP7qXQcHzsSfFrul14pXG7grNokcA5S3w7HSBXQXQ7WdVeN-nZSI_232NSyF3GRkiINenSUMoz8_7zKy2MUvo9gW8WkaOlMOv5l8H781ZDfQvMCNjmwb2zE4q8qNbv2ZnA_gfc",
  "kty": "RSA",
  "q": "tj8Ug4uHQnfJEXdNKCPPbUD4kPMNu4T0pAf7lUkZ4Aa56CxKds063qUvdtyPYSiTKlpdAVYibqSyLBauG_RjPDcD6zrziKO93o42mX2Fr4fZJaWFKqlAqA3fZycWyu-VDrjF14QmDUS4NPnnQ7_UuiKYr5o3hO8-iJrW8z4VQJc",
  "d": "j_TQo4CwQ9GHOy2hCJJJfV1rUVxQpWmljB4SNBcJ4cZWbMVc0qRTL9awlgIvFCYmO2H97q3CLJAjigPGNta-TCI1eEbuaTsGrLwsjUrycQz7EIZf_i9rdj3lRhJ-gLpgO2Fj6_hfQLMHQ0yhiHi09FPLpJfPpicqEHwwmwNLQGIwN88c-TDDX2D4Iw3geygigqRnWviDVMejuRL2Luordiw7XOJHzY2BGwqOZdgqYfVS6Dr6PjOaOwWDJ7w9pHT19zz3UEXiarzA-AZKSZtxOoNVSliltj0nIzhVN0fd7g0Ljt13LjrGuyLSrAoTCZdQpCZ0uX02leqFkCAOkCzWlQ",
  "e": "AQAB",
  "use": "sig",
  "kid": "fapips1",
  "qi": "sNIuSo-uVI0TrtcR_6ZdGkps2MIWmVRhqBCKDxJAm21RkW7Sv0buRD8KPSP7WA20KTgs3O9i1Hz6bD8U2Hkjt3rk6MP59JvQev1DxFD8yA_A6aaIHk6Z7BryX5QOJzj0tzIB1tVzrSViVdDg0LUOO5yZdm_IQSU4AN-aaxjrpvA",
  "dp": "NnHJVmRzGz2OEvbSDDFBFAcHpdQHojcuadc6XDS8bAs60Xgtf0Cm-k2r_0tlN1X7HvN0INfquxXT8V17iG1pcc4SBUHezsUeT9YWjIuaqhP4FO4dxqCBRXPoqidach7h9_wILu9iQf59vwQgcVgpRtjxlCWdJQw50VTeDOdOcVc",
  "alg": "PS256",
  "dq": "qwl0dShDnuvQdmXisaM6Dq0FGvQglTZoanFbeXWLpSZq3yyCDhD6CO46J3FD1sk_pGX-Fz0BP5mt5Za7fFzVrTNsqB1BZaFWlkIdl9un1V7HOn-nBKynk5DBc4vJ5lcHKzPZ6TOKirVNs9o9YuXr_Wxuo482P7pQk9_Nj6daRq0",
  "n": "sPoZ2M-WhvDJchlxahAPDtkSaRlXWIK17NF2qHn3RgWUw0Z4XyptMWi-HMwxwwwApCi_g7ytaJ4DBDo5DY-pumFZHdj4mcD8Nb2XhV5smMO3-XABBVAuNH6VW4sFeb6bvlVBNyoHpAA_4VyMCYTjZffxGIqXpyxIND1M5zwP8RaZc1_Yo4yakZa15wXirbwZkCArJaIROpKy5xXFPA_2p4w7PnTQshAqjJx2Jz8N5CKsEvUvHNEg7pfeL1hTqLk1KRpLRh8QZKwfEjuxg0KFIGmi45gAX8SCjjX-BBffN6C7VELESRzILSlCEbTL_hslQkSQNbmyqI--kWCgkTZosQ"
}
2022-07-11 17:30:40 SUCCESS
BuildRequestObjectByValueRedirectToAuthorizationEndpoint
Sending to authorization endpoint
redirect_to_authorization_endpoint
https://fapipoc.tryverify.ibm.com/oauth2/authorize?request=eyJraWQiOiJmYXBpcHMxIiwiYWxnIjoiUFMyNTYifQ.eyJhdWQiOiJodHRwczpcL1wvZmFwaXBvYy50cnl2ZXJpZnkuaWJtLmNvbVwvb2F1dGgyIiwibmJmIjoxNjU3NTYwNjQwLCJzY29wZSI6Im9wZW5pZCBlbWFpbCIsImNsYWltcyI6eyJpZF90b2tlbiI6eyJhY3IiOnsidmFsdWUiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiZXNzZW50aWFsIjp0cnVlfX19LCJpc3MiOiJlNmNjZjQ0ZC04MzhkLTRiZWMtOWQ3ZS0wYzFiZjY2NzdiOGMiLCJyZXNwb25zZV90eXBlIjoiY29kZSBpZF90b2tlbiIsInJlZGlyZWN0X3VyaSI6Imh0dHBzOlwvXC93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0XC90ZXN0XC9hXC9mYXBpcG9jX2ZhcGlfZGV2XC9jYWxsYmFjayIsInN0YXRlIjoiZXhMTk5CSjdNMiIsImV4cCI6MTY1NzU2MDk0MCwibm9uY2UiOiJla0VvUERnU2diTDlGbWltQWs3QXVYYmpxb3BxVWQ1ejZ3bXFUeGVFNEpwZWlUWFQ3djd5UXVwN3pDNWVRSm9EU2JqVHZ5eGE0RHhuNHBjZjBjMjA4bkFYS2dwTGtGNmMwU095Y2pXNU55ZWtYT2dyVUt5VzdWaXJUQ1JWcTAyVGdQNEVOSjlMaGhiM25ReEEyN2lpT3h2UVVyZkVWN2VnMWFwVU9KNG5uTHE4a09vaHJ3WlZoVlZ5d0NzbnVmYnk2dFNDWkJGTnRzajdjVlhIZjh2aUtMSHRQa3UxODZjZkIzcm9tRGJ2cnZUalRMbm5sUENxWEVnYndnbFJtd1dGNmxBUmRYNHVOQTlJS0E4SWM3aE83RTl3RmVCckdDM0Z6bFFOOE40dXZPMUdDaFhaSUxyYm1SUHhOTFFiellQcXJQNGl1VUdwcXA2TnJuVFFTMWYwWnNRczRCZGNEekdUVG9zZEFCSno1TzFENEZkUGF1VlVsUjFuRWlsaFd2ejUiLCJjbGllbnRfaWQiOiJlNmNjZjQ0ZC04MzhkLTRiZWMtOWQ3ZS0wYzFiZjY2NzdiOGMifQ.f6jID35JM69EVqIAbn_0W5pQfRzS-3R3AyO6nD-dLdsdioUUYkQu75ib2rDZO1wGDMCSuox0MCwh2DGLKWPk4MVZAYtPl6q4GEjUdlJELpIzh-kOLjEofY9aZ0B96RU6CxkYpj3biZLSE2ySLD43NaSW0lpb2ZN6mDgvznz7oGO6aqAvUoOvDOLEwTanWFtHCVNZwRFxa6bVSBnC2rBOyJ5nPPMCNTYha2pl0G_psRnUwzgHMDjW8IqKj9BOGD5jPSx2Ee5aAf_MVwTnGrPFXLRmk06M0da4-3PNDXNGsLilxYaAIdfqMvYl0KpczPjQQ0tCnzQcUD9wxce1AdM1Sg&client_id=e6ccf44d-838d-4bec-9d7e-0c1bf6677b8c&redirect_uri=https://www.certification.openid.net/test/a/fapipoc_fapi_dev/callback&scope=openid%20email&response_type=code%20id_token
2022-07-11 17:30:40 REDIRECT
fapi1-advanced-final-ensure-request-object-with-long-nonce
Redirecting to authorization endpoint
redirect_to
https://fapipoc.tryverify.ibm.com/oauth2/authorize?request=eyJraWQiOiJmYXBpcHMxIiwiYWxnIjoiUFMyNTYifQ.eyJhdWQiOiJodHRwczpcL1wvZmFwaXBvYy50cnl2ZXJpZnkuaWJtLmNvbVwvb2F1dGgyIiwibmJmIjoxNjU3NTYwNjQwLCJzY29wZSI6Im9wZW5pZCBlbWFpbCIsImNsYWltcyI6eyJpZF90b2tlbiI6eyJhY3IiOnsidmFsdWUiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiZXNzZW50aWFsIjp0cnVlfX19LCJpc3MiOiJlNmNjZjQ0ZC04MzhkLTRiZWMtOWQ3ZS0wYzFiZjY2NzdiOGMiLCJyZXNwb25zZV90eXBlIjoiY29kZSBpZF90b2tlbiIsInJlZGlyZWN0X3VyaSI6Imh0dHBzOlwvXC93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0XC90ZXN0XC9hXC9mYXBpcG9jX2ZhcGlfZGV2XC9jYWxsYmFjayIsInN0YXRlIjoiZXhMTk5CSjdNMiIsImV4cCI6MTY1NzU2MDk0MCwibm9uY2UiOiJla0VvUERnU2diTDlGbWltQWs3QXVYYmpxb3BxVWQ1ejZ3bXFUeGVFNEpwZWlUWFQ3djd5UXVwN3pDNWVRSm9EU2JqVHZ5eGE0RHhuNHBjZjBjMjA4bkFYS2dwTGtGNmMwU095Y2pXNU55ZWtYT2dyVUt5VzdWaXJUQ1JWcTAyVGdQNEVOSjlMaGhiM25ReEEyN2lpT3h2UVVyZkVWN2VnMWFwVU9KNG5uTHE4a09vaHJ3WlZoVlZ5d0NzbnVmYnk2dFNDWkJGTnRzajdjVlhIZjh2aUtMSHRQa3UxODZjZkIzcm9tRGJ2cnZUalRMbm5sUENxWEVnYndnbFJtd1dGNmxBUmRYNHVOQTlJS0E4SWM3aE83RTl3RmVCckdDM0Z6bFFOOE40dXZPMUdDaFhaSUxyYm1SUHhOTFFiellQcXJQNGl1VUdwcXA2TnJuVFFTMWYwWnNRczRCZGNEekdUVG9zZEFCSno1TzFENEZkUGF1VlVsUjFuRWlsaFd2ejUiLCJjbGllbnRfaWQiOiJlNmNjZjQ0ZC04MzhkLTRiZWMtOWQ3ZS0wYzFiZjY2NzdiOGMifQ.f6jID35JM69EVqIAbn_0W5pQfRzS-3R3AyO6nD-dLdsdioUUYkQu75ib2rDZO1wGDMCSuox0MCwh2DGLKWPk4MVZAYtPl6q4GEjUdlJELpIzh-kOLjEofY9aZ0B96RU6CxkYpj3biZLSE2ySLD43NaSW0lpb2ZN6mDgvznz7oGO6aqAvUoOvDOLEwTanWFtHCVNZwRFxa6bVSBnC2rBOyJ5nPPMCNTYha2pl0G_psRnUwzgHMDjW8IqKj9BOGD5jPSx2Ee5aAf_MVwTnGrPFXLRmk06M0da4-3PNDXNGsLilxYaAIdfqMvYl0KpczPjQQ0tCnzQcUD9wxce1AdM1Sg&client_id=e6ccf44d-838d-4bec-9d7e-0c1bf6677b8c&redirect_uri=https://www.certification.openid.net/test/a/fapipoc_fapi_dev/callback&scope=openid%20email&response_type=code%20id_token
2022-07-11 17:30:40 REVIEW
ExpectRequestObjectWithLongNonceErrorPage
If the server does not return an invalid_request error back to the client, it must show an error page (saying server rejects long nonce at authorization endpoint - upload a screenshot of the error page) or must successfully authenticate and return the nonce correctly.
image_no_longer_required
true
2022-07-11 17:32:45 INCOMING
fapi1-advanced-final-ensure-request-object-with-long-nonce
Incoming HTTP request to /test/a/fapipoc_fapi_dev/callback
incoming_headers
{
  "host": "www.certification.openid.net",
  "upgrade-insecure-requests": "1",
  "dnt": "1",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "cross-site",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "sec-ch-ua": "\".Not/A)Brand\";v\u003d\"99\", \"Google Chrome\";v\u003d\"103\", \"Chromium\";v\u003d\"103\"",
  "sec-ch-ua-mobile": "?0",
  "sec-ch-ua-platform": "\"Windows\"",
  "referer": "https://www.certification.openid.net/",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9",
  "cookie": "JSESSIONID\u003dCA52312C52900FB3D9553E7F56BAFDC3",
  "connection": "close"
}
incoming_path
/test/a/fapipoc_fapi_dev/callback
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cert
incoming_query_string_params
{}
incoming_body
incoming_tls_chain
[
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL"
]
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_body_json
2022-07-11 17:32:45 SUCCESS
CreateRandomImplicitSubmitUrl
Created random implicit submission URL
implicit_submit
{
  "path": "implicit/ODWv1eRVrHK6ztC5M8Zc",
  "fullUrl": "https://www.certification.openid.net/test/a/fapipoc_fapi_dev/implicit/ODWv1eRVrHK6ztC5M8Zc"
}
2022-07-11 17:32:45 OUTGOING
fapi1-advanced-final-ensure-request-object-with-long-nonce
Response to HTTP request to test instance B8TRFqRMwfiO4jF
outgoing
ModelAndView [view="implicitCallback"; model={implicitSubmitUrl=https://www.certification.openid.net/test/a/fapipoc_fapi_dev/implicit/ODWv1eRVrHK6ztC5M8Zc, returnUrl=/log-detail.html?log=B8TRFqRMwfiO4jF}]
outgoing_path
callback
2022-07-11 17:32:46 INCOMING
fapi1-advanced-final-ensure-request-object-with-long-nonce
Incoming HTTP request to /test/a/fapipoc_fapi_dev/implicit/ODWv1eRVrHK6ztC5M8Zc
incoming_headers
{
  "host": "www.certification.openid.net",
  "sec-ch-ua": "\".Not/A)Brand\";v\u003d\"99\", \"Google Chrome\";v\u003d\"103\", \"Chromium\";v\u003d\"103\"",
  "dnt": "1",
  "sec-ch-ua-mobile": "?0",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36",
  "content-type": "text/plain",
  "accept": "*/*",
  "x-requested-with": "XMLHttpRequest",
  "sec-ch-ua-platform": "\"Windows\"",
  "origin": "https://www.certification.openid.net",
  "sec-fetch-site": "same-origin",
  "sec-fetch-mode": "cors",
  "sec-fetch-dest": "empty",
  "referer": "https://www.certification.openid.net/test/a/fapipoc_fapi_dev/callback",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9",
  "cookie": "JSESSIONID\u003dCA52312C52900FB3D9553E7F56BAFDC3",
  "connection": "close",
  "content-length": "1706"
}
incoming_path
/test/a/fapipoc_fapi_dev/implicit/ODWv1eRVrHK6ztC5M8Zc
incoming_body_form_params
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cert
incoming_query_string_params
{}
incoming_body
#code=4JdRcxARXn-wZTSEAQtIWZSF2cKR2cihARIs-_gFiKc.FoWCnYwS1O7u2fPTPu5Xb1pHF2FSHBxyeuaBZXAGuvxj9RNVF-Xq9XmQSDL4dPnTkw_3WqSeW1p92glbaITSJg&id_token=eyJhbGciOiJQUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYW1yIjpbInBhc3N3b3JkIl0sImF1ZCI6WyJlNmNjZjQ0ZC04MzhkLTRiZWMtOWQ3ZS0wYzFiZjY2NzdiOGMiXSwiYXV0aF90aW1lIjoxNjU3NTU4MDI4LCJjX2hhc2giOiJ0amJBNTJuemN3dXdDQXI2TDFxMklBIiwiZW1haWwiOiJqaGFsbEBtYWlsaW5hdG9yLmNvbSIsImV4cCI6MTY1NzU2Nzk2NSwiaWF0IjoxNjU3NTYwNzY1LCJpc3MiOiJodHRwczovL2ZhcGlwb2MudHJ5dmVyaWZ5LmlibS5jb20vb2F1dGgyIiwianRpIjoiOGY0YjdiZmYtNWVjYy00YjBkLThhMzItNTM4MDUzYTMxNTYwIiwibmFtZSI6Ikplc3NpY2EgSGFsbCIsIm5vbmNlIjoiZWtFb1BEZ1NnYkw5Rm1pbUFrN0F1WGJqcW9wcVVkNXo2d21xVHhlRTRKcGVpVFhUN3Y3eVF1cDd6QzVlUUpvRFNialR2eXhhNER4bjRwY2YwYzIwOG5BWEtncExrRjZjMFNPeWNqVzVOeWVrWE9nclVLeVc3VmlyVENSVnEwMlRnUDRFTko5TGhoYjNuUXhBMjdpaU94dlFVcmZFVjdlZzFhcFVPSjRubkxxOGtPb2hyd1pWaFZWeXdDc251ZmJ5NnRTQ1pCRk50c2o3Y1ZYSGY4dmlLTEh0UGt1MTg2Y2ZCM3JvbURidnJ2VGpUTG5ubFBDcVhFZ2J3Z2xSbXdXRjZsQVJkWDR1TkE5SUtBOEljN2hPN0U5d0ZlQnJHQzNGemxRTjhONHV2TzFHQ2hYWklMcmJtUlB4TkxRYnpZUHFyUDRpdVVHcHFwNk5yblRRUzFmMFpzUXM0QmRjRHpHVFRvc2RBQkp6NU8xRDRGZFBhdVZVbFIxbkVpbGhXdno1IiwicHJlZmVycmVkX3VzZXJuYW1lIjoiamhhbGwiLCJyYXQiOjE2NTc1NjA3NjUsInJlYWxtTmFtZSI6ImNsb3VkSWRlbnRpdHlSZWFsbSIsInNfaGFzaCI6IjVjcVluZ1NSVFN4T3JCNEh6Smt2UVEiLCJzdWIiOiI2NjIwMDNQV1ZGIn0.i5QjVWhXj9C9brE3PmJSv4DS5MhzgrmbeyUQbAioLcCVwOVwo-ImBi_6N2uX3iIilqhUUAPU7Uah_YgfszFfa0VnCvG4mjtJ8Nbg8Kz4CvTpskxGTUuFfn90wsLlPSNvoKwlv0EkhENfJr9UHs01nlHN8XlvSWcu8R8cBlUvBGSKDZgx0D3n6wrGhPkZm4-v1yBmrNrKzB5zocTfu2kIycRqjUl7X2U_DTYiGwrisB67dGkIhBXnkq3kKjwLZvNdWmMRo3UTd-yklajFaUO1lZI5IBDutg3z6K649n2k3H7Gg8qAqJsujTcG5AjFTJTdoeSnXaAqTysjWKMl40wi6g&state=exLNNBJ7M2
incoming_tls_chain
[
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL"
]
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_body_json
2022-07-11 17:32:46 OUTGOING
fapi1-advanced-final-ensure-request-object-with-long-nonce
Response to HTTP request to test instance B8TRFqRMwfiO4jF
outgoing_status_code
204
outgoing_headers
{}
outgoing_body

                                
outgoing_path
implicit/ODWv1eRVrHK6ztC5M8Zc
2022-07-11 17:32:46
ExtractImplicitHashToCallbackResponse
Extracted response from URL fragment
parameters
[
  {
    "name": "code",
    "value": "4JdRcxARXn-wZTSEAQtIWZSF2cKR2cihARIs-_gFiKc.FoWCnYwS1O7u2fPTPu5Xb1pHF2FSHBxyeuaBZXAGuvxj9RNVF-Xq9XmQSDL4dPnTkw_3WqSeW1p92glbaITSJg"
  },
  {
    "name": "id_token",
    "value": "eyJhbGciOiJQUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYW1yIjpbInBhc3N3b3JkIl0sImF1ZCI6WyJlNmNjZjQ0ZC04MzhkLTRiZWMtOWQ3ZS0wYzFiZjY2NzdiOGMiXSwiYXV0aF90aW1lIjoxNjU3NTU4MDI4LCJjX2hhc2giOiJ0amJBNTJuemN3dXdDQXI2TDFxMklBIiwiZW1haWwiOiJqaGFsbEBtYWlsaW5hdG9yLmNvbSIsImV4cCI6MTY1NzU2Nzk2NSwiaWF0IjoxNjU3NTYwNzY1LCJpc3MiOiJodHRwczovL2ZhcGlwb2MudHJ5dmVyaWZ5LmlibS5jb20vb2F1dGgyIiwianRpIjoiOGY0YjdiZmYtNWVjYy00YjBkLThhMzItNTM4MDUzYTMxNTYwIiwibmFtZSI6Ikplc3NpY2EgSGFsbCIsIm5vbmNlIjoiZWtFb1BEZ1NnYkw5Rm1pbUFrN0F1WGJqcW9wcVVkNXo2d21xVHhlRTRKcGVpVFhUN3Y3eVF1cDd6QzVlUUpvRFNialR2eXhhNER4bjRwY2YwYzIwOG5BWEtncExrRjZjMFNPeWNqVzVOeWVrWE9nclVLeVc3VmlyVENSVnEwMlRnUDRFTko5TGhoYjNuUXhBMjdpaU94dlFVcmZFVjdlZzFhcFVPSjRubkxxOGtPb2hyd1pWaFZWeXdDc251ZmJ5NnRTQ1pCRk50c2o3Y1ZYSGY4dmlLTEh0UGt1MTg2Y2ZCM3JvbURidnJ2VGpUTG5ubFBDcVhFZ2J3Z2xSbXdXRjZsQVJkWDR1TkE5SUtBOEljN2hPN0U5d0ZlQnJHQzNGemxRTjhONHV2TzFHQ2hYWklMcmJtUlB4TkxRYnpZUHFyUDRpdVVHcHFwNk5yblRRUzFmMFpzUXM0QmRjRHpHVFRvc2RBQkp6NU8xRDRGZFBhdVZVbFIxbkVpbGhXdno1IiwicHJlZmVycmVkX3VzZXJuYW1lIjoiamhhbGwiLCJyYXQiOjE2NTc1NjA3NjUsInJlYWxtTmFtZSI6ImNsb3VkSWRlbnRpdHlSZWFsbSIsInNfaGFzaCI6IjVjcVluZ1NSVFN4T3JCNEh6Smt2UVEiLCJzdWIiOiI2NjIwMDNQV1ZGIn0.i5QjVWhXj9C9brE3PmJSv4DS5MhzgrmbeyUQbAioLcCVwOVwo-ImBi_6N2uX3iIilqhUUAPU7Uah_YgfszFfa0VnCvG4mjtJ8Nbg8Kz4CvTpskxGTUuFfn90wsLlPSNvoKwlv0EkhENfJr9UHs01nlHN8XlvSWcu8R8cBlUvBGSKDZgx0D3n6wrGhPkZm4-v1yBmrNrKzB5zocTfu2kIycRqjUl7X2U_DTYiGwrisB67dGkIhBXnkq3kKjwLZvNdWmMRo3UTd-yklajFaUO1lZI5IBDutg3z6K649n2k3H7Gg8qAqJsujTcG5AjFTJTdoeSnXaAqTysjWKMl40wi6g"
  },
  {
    "name": "state",
    "value": "exLNNBJ7M2"
  }
]
2022-07-11 17:32:46 SUCCESS
ExtractImplicitHashToCallbackResponse
Extracted the hash values
code
4JdRcxARXn-wZTSEAQtIWZSF2cKR2cihARIs-_gFiKc.FoWCnYwS1O7u2fPTPu5Xb1pHF2FSHBxyeuaBZXAGuvxj9RNVF-Xq9XmQSDL4dPnTkw_3WqSeW1p92glbaITSJg
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYW1yIjpbInBhc3N3b3JkIl0sImF1ZCI6WyJlNmNjZjQ0ZC04MzhkLTRiZWMtOWQ3ZS0wYzFiZjY2NzdiOGMiXSwiYXV0aF90aW1lIjoxNjU3NTU4MDI4LCJjX2hhc2giOiJ0amJBNTJuemN3dXdDQXI2TDFxMklBIiwiZW1haWwiOiJqaGFsbEBtYWlsaW5hdG9yLmNvbSIsImV4cCI6MTY1NzU2Nzk2NSwiaWF0IjoxNjU3NTYwNzY1LCJpc3MiOiJodHRwczovL2ZhcGlwb2MudHJ5dmVyaWZ5LmlibS5jb20vb2F1dGgyIiwianRpIjoiOGY0YjdiZmYtNWVjYy00YjBkLThhMzItNTM4MDUzYTMxNTYwIiwibmFtZSI6Ikplc3NpY2EgSGFsbCIsIm5vbmNlIjoiZWtFb1BEZ1NnYkw5Rm1pbUFrN0F1WGJqcW9wcVVkNXo2d21xVHhlRTRKcGVpVFhUN3Y3eVF1cDd6QzVlUUpvRFNialR2eXhhNER4bjRwY2YwYzIwOG5BWEtncExrRjZjMFNPeWNqVzVOeWVrWE9nclVLeVc3VmlyVENSVnEwMlRnUDRFTko5TGhoYjNuUXhBMjdpaU94dlFVcmZFVjdlZzFhcFVPSjRubkxxOGtPb2hyd1pWaFZWeXdDc251ZmJ5NnRTQ1pCRk50c2o3Y1ZYSGY4dmlLTEh0UGt1MTg2Y2ZCM3JvbURidnJ2VGpUTG5ubFBDcVhFZ2J3Z2xSbXdXRjZsQVJkWDR1TkE5SUtBOEljN2hPN0U5d0ZlQnJHQzNGemxRTjhONHV2TzFHQ2hYWklMcmJtUlB4TkxRYnpZUHFyUDRpdVVHcHFwNk5yblRRUzFmMFpzUXM0QmRjRHpHVFRvc2RBQkp6NU8xRDRGZFBhdVZVbFIxbkVpbGhXdno1IiwicHJlZmVycmVkX3VzZXJuYW1lIjoiamhhbGwiLCJyYXQiOjE2NTc1NjA3NjUsInJlYWxtTmFtZSI6ImNsb3VkSWRlbnRpdHlSZWFsbSIsInNfaGFzaCI6IjVjcVluZ1NSVFN4T3JCNEh6Smt2UVEiLCJzdWIiOiI2NjIwMDNQV1ZGIn0.i5QjVWhXj9C9brE3PmJSv4DS5MhzgrmbeyUQbAioLcCVwOVwo-ImBi_6N2uX3iIilqhUUAPU7Uah_YgfszFfa0VnCvG4mjtJ8Nbg8Kz4CvTpskxGTUuFfn90wsLlPSNvoKwlv0EkhENfJr9UHs01nlHN8XlvSWcu8R8cBlUvBGSKDZgx0D3n6wrGhPkZm4-v1yBmrNrKzB5zocTfu2kIycRqjUl7X2U_DTYiGwrisB67dGkIhBXnkq3kKjwLZvNdWmMRo3UTd-yklajFaUO1lZI5IBDutg3z6K649n2k3H7Gg8qAqJsujTcG5AjFTJTdoeSnXaAqTysjWKMl40wi6g
state
exLNNBJ7M2
2022-07-11 17:32:46 REDIRECT-IN
fapi1-advanced-final-ensure-request-object-with-long-nonce
Authorization endpoint response captured
url_query
{}
headers
{
  "host": "www.certification.openid.net",
  "upgrade-insecure-requests": "1",
  "dnt": "1",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "cross-site",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "sec-ch-ua": "\".Not/A)Brand\";v\u003d\"99\", \"Google Chrome\";v\u003d\"103\", \"Chromium\";v\u003d\"103\"",
  "sec-ch-ua-mobile": "?0",
  "sec-ch-ua-platform": "\"Windows\"",
  "referer": "https://www.certification.openid.net/",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9",
  "cookie": "JSESSIONID\u003dCA52312C52900FB3D9553E7F56BAFDC3",
  "x-ssl-cipher": "ECDHE-RSA-AES128-GCM-SHA256",
  "x-ssl-protocol": "TLSv1.2",
  "x-forwarded-proto": "https",
  "x-forwarded-port": "443",
  "connection": "close",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net"
}
http_method
GET
url_fragment
{
  "code": "4JdRcxARXn-wZTSEAQtIWZSF2cKR2cihARIs-_gFiKc.FoWCnYwS1O7u2fPTPu5Xb1pHF2FSHBxyeuaBZXAGuvxj9RNVF-Xq9XmQSDL4dPnTkw_3WqSeW1p92glbaITSJg",
  "id_token": "eyJhbGciOiJQUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYW1yIjpbInBhc3N3b3JkIl0sImF1ZCI6WyJlNmNjZjQ0ZC04MzhkLTRiZWMtOWQ3ZS0wYzFiZjY2NzdiOGMiXSwiYXV0aF90aW1lIjoxNjU3NTU4MDI4LCJjX2hhc2giOiJ0amJBNTJuemN3dXdDQXI2TDFxMklBIiwiZW1haWwiOiJqaGFsbEBtYWlsaW5hdG9yLmNvbSIsImV4cCI6MTY1NzU2Nzk2NSwiaWF0IjoxNjU3NTYwNzY1LCJpc3MiOiJodHRwczovL2ZhcGlwb2MudHJ5dmVyaWZ5LmlibS5jb20vb2F1dGgyIiwianRpIjoiOGY0YjdiZmYtNWVjYy00YjBkLThhMzItNTM4MDUzYTMxNTYwIiwibmFtZSI6Ikplc3NpY2EgSGFsbCIsIm5vbmNlIjoiZWtFb1BEZ1NnYkw5Rm1pbUFrN0F1WGJqcW9wcVVkNXo2d21xVHhlRTRKcGVpVFhUN3Y3eVF1cDd6QzVlUUpvRFNialR2eXhhNER4bjRwY2YwYzIwOG5BWEtncExrRjZjMFNPeWNqVzVOeWVrWE9nclVLeVc3VmlyVENSVnEwMlRnUDRFTko5TGhoYjNuUXhBMjdpaU94dlFVcmZFVjdlZzFhcFVPSjRubkxxOGtPb2hyd1pWaFZWeXdDc251ZmJ5NnRTQ1pCRk50c2o3Y1ZYSGY4dmlLTEh0UGt1MTg2Y2ZCM3JvbURidnJ2VGpUTG5ubFBDcVhFZ2J3Z2xSbXdXRjZsQVJkWDR1TkE5SUtBOEljN2hPN0U5d0ZlQnJHQzNGemxRTjhONHV2TzFHQ2hYWklMcmJtUlB4TkxRYnpZUHFyUDRpdVVHcHFwNk5yblRRUzFmMFpzUXM0QmRjRHpHVFRvc2RBQkp6NU8xRDRGZFBhdVZVbFIxbkVpbGhXdno1IiwicHJlZmVycmVkX3VzZXJuYW1lIjoiamhhbGwiLCJyYXQiOjE2NTc1NjA3NjUsInJlYWxtTmFtZSI6ImNsb3VkSWRlbnRpdHlSZWFsbSIsInNfaGFzaCI6IjVjcVluZ1NSVFN4T3JCNEh6Smt2UVEiLCJzdWIiOiI2NjIwMDNQV1ZGIn0.i5QjVWhXj9C9brE3PmJSv4DS5MhzgrmbeyUQbAioLcCVwOVwo-ImBi_6N2uX3iIilqhUUAPU7Uah_YgfszFfa0VnCvG4mjtJ8Nbg8Kz4CvTpskxGTUuFfn90wsLlPSNvoKwlv0EkhENfJr9UHs01nlHN8XlvSWcu8R8cBlUvBGSKDZgx0D3n6wrGhPkZm4-v1yBmrNrKzB5zocTfu2kIycRqjUl7X2U_DTYiGwrisB67dGkIhBXnkq3kKjwLZvNdWmMRo3UTd-yklajFaUO1lZI5IBDutg3z6K649n2k3H7Gg8qAqJsujTcG5AjFTJTdoeSnXaAqTysjWKMl40wi6g",
  "state": "exLNNBJ7M2"
}
post_body
Verify authorization endpoint response
2022-07-11 17:32:46 SUCCESS
RejectErrorInUrlQuery
'error' is not present in URL query returned from authorization endpoint
2022-07-11 17:32:46 SUCCESS
RejectAuthCodeInUrlQuery
Authorization code is not present in URL query returned from authorization endpoint
2022-07-11 17:32:46 SUCCESS
CheckMatchingCallbackParameters
Callback parameters successfully verified
2022-07-11 17:32:46 SUCCESS
RejectStateInUrlQueryForHybridFlow
state is correctly not present in URL query returned from authorization endpoint (as in the hybrid flow it must be returned in the URL fragment/hash only)
2022-07-11 17:32:46 SUCCESS
CheckIfAuthorizationEndpointError
No error from authorization endpoint
2022-07-11 17:32:46 SUCCESS
ValidateSuccessfulHybridResponseFromAuthorizationEndpoint
authorization endpoint response does not include unexpected parameters
code
4JdRcxARXn-wZTSEAQtIWZSF2cKR2cihARIs-_gFiKc.FoWCnYwS1O7u2fPTPu5Xb1pHF2FSHBxyeuaBZXAGuvxj9RNVF-Xq9XmQSDL4dPnTkw_3WqSeW1p92glbaITSJg
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYW1yIjpbInBhc3N3b3JkIl0sImF1ZCI6WyJlNmNjZjQ0ZC04MzhkLTRiZWMtOWQ3ZS0wYzFiZjY2NzdiOGMiXSwiYXV0aF90aW1lIjoxNjU3NTU4MDI4LCJjX2hhc2giOiJ0amJBNTJuemN3dXdDQXI2TDFxMklBIiwiZW1haWwiOiJqaGFsbEBtYWlsaW5hdG9yLmNvbSIsImV4cCI6MTY1NzU2Nzk2NSwiaWF0IjoxNjU3NTYwNzY1LCJpc3MiOiJodHRwczovL2ZhcGlwb2MudHJ5dmVyaWZ5LmlibS5jb20vb2F1dGgyIiwianRpIjoiOGY0YjdiZmYtNWVjYy00YjBkLThhMzItNTM4MDUzYTMxNTYwIiwibmFtZSI6Ikplc3NpY2EgSGFsbCIsIm5vbmNlIjoiZWtFb1BEZ1NnYkw5Rm1pbUFrN0F1WGJqcW9wcVVkNXo2d21xVHhlRTRKcGVpVFhUN3Y3eVF1cDd6QzVlUUpvRFNialR2eXhhNER4bjRwY2YwYzIwOG5BWEtncExrRjZjMFNPeWNqVzVOeWVrWE9nclVLeVc3VmlyVENSVnEwMlRnUDRFTko5TGhoYjNuUXhBMjdpaU94dlFVcmZFVjdlZzFhcFVPSjRubkxxOGtPb2hyd1pWaFZWeXdDc251ZmJ5NnRTQ1pCRk50c2o3Y1ZYSGY4dmlLTEh0UGt1MTg2Y2ZCM3JvbURidnJ2VGpUTG5ubFBDcVhFZ2J3Z2xSbXdXRjZsQVJkWDR1TkE5SUtBOEljN2hPN0U5d0ZlQnJHQzNGemxRTjhONHV2TzFHQ2hYWklMcmJtUlB4TkxRYnpZUHFyUDRpdVVHcHFwNk5yblRRUzFmMFpzUXM0QmRjRHpHVFRvc2RBQkp6NU8xRDRGZFBhdVZVbFIxbkVpbGhXdno1IiwicHJlZmVycmVkX3VzZXJuYW1lIjoiamhhbGwiLCJyYXQiOjE2NTc1NjA3NjUsInJlYWxtTmFtZSI6ImNsb3VkSWRlbnRpdHlSZWFsbSIsInNfaGFzaCI6IjVjcVluZ1NSVFN4T3JCNEh6Smt2UVEiLCJzdWIiOiI2NjIwMDNQV1ZGIn0.i5QjVWhXj9C9brE3PmJSv4DS5MhzgrmbeyUQbAioLcCVwOVwo-ImBi_6N2uX3iIilqhUUAPU7Uah_YgfszFfa0VnCvG4mjtJ8Nbg8Kz4CvTpskxGTUuFfn90wsLlPSNvoKwlv0EkhENfJr9UHs01nlHN8XlvSWcu8R8cBlUvBGSKDZgx0D3n6wrGhPkZm4-v1yBmrNrKzB5zocTfu2kIycRqjUl7X2U_DTYiGwrisB67dGkIhBXnkq3kKjwLZvNdWmMRo3UTd-yklajFaUO1lZI5IBDutg3z6K649n2k3H7Gg8qAqJsujTcG5AjFTJTdoeSnXaAqTysjWKMl40wi6g
state
exLNNBJ7M2
2022-07-11 17:32:46 SUCCESS
CheckStateInAuthorizationResponse
State in response correctly returned
state
exLNNBJ7M2
2022-07-11 17:32:46
ValidateIssInAuthorizationResponse
No 'iss' value in authorization response.
2022-07-11 17:32:46 SUCCESS
ExtractAuthorizationCodeFromAuthorizationResponse
Found authorization code
code
4JdRcxARXn-wZTSEAQtIWZSF2cKR2cihARIs-_gFiKc.FoWCnYwS1O7u2fPTPu5Xb1pHF2FSHBxyeuaBZXAGuvxj9RNVF-Xq9XmQSDL4dPnTkw_3WqSeW1p92glbaITSJg
2022-07-11 17:32:46 SUCCESS
EnsureMinimumAuthorizationCodeLength
Authorization code is of sufficient length
actual
1040
required
128
2022-07-11 17:32:46 SUCCESS
EnsureMinimumAuthorizationCodeEntropy
Calculated shannon entropy seems sufficient
actual
727.3687597900239
expected
96.0
value
4JdRcxARXn-wZTSEAQtIWZSF2cKR2cihARIs-_gFiKc.FoWCnYwS1O7u2fPTPu5Xb1pHF2FSHBxyeuaBZXAGuvxj9RNVF-Xq9XmQSDL4dPnTkw_3WqSeW1p92glbaITSJg
2022-07-11 17:32:46 SUCCESS
ExtractIdTokenFromAuthorizationResponse
Found and parsed the id_token from authorization_endpoint_response
value
eyJhbGciOiJQUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYW1yIjpbInBhc3N3b3JkIl0sImF1ZCI6WyJlNmNjZjQ0ZC04MzhkLTRiZWMtOWQ3ZS0wYzFiZjY2NzdiOGMiXSwiYXV0aF90aW1lIjoxNjU3NTU4MDI4LCJjX2hhc2giOiJ0amJBNTJuemN3dXdDQXI2TDFxMklBIiwiZW1haWwiOiJqaGFsbEBtYWlsaW5hdG9yLmNvbSIsImV4cCI6MTY1NzU2Nzk2NSwiaWF0IjoxNjU3NTYwNzY1LCJpc3MiOiJodHRwczovL2ZhcGlwb2MudHJ5dmVyaWZ5LmlibS5jb20vb2F1dGgyIiwianRpIjoiOGY0YjdiZmYtNWVjYy00YjBkLThhMzItNTM4MDUzYTMxNTYwIiwibmFtZSI6Ikplc3NpY2EgSGFsbCIsIm5vbmNlIjoiZWtFb1BEZ1NnYkw5Rm1pbUFrN0F1WGJqcW9wcVVkNXo2d21xVHhlRTRKcGVpVFhUN3Y3eVF1cDd6QzVlUUpvRFNialR2eXhhNER4bjRwY2YwYzIwOG5BWEtncExrRjZjMFNPeWNqVzVOeWVrWE9nclVLeVc3VmlyVENSVnEwMlRnUDRFTko5TGhoYjNuUXhBMjdpaU94dlFVcmZFVjdlZzFhcFVPSjRubkxxOGtPb2hyd1pWaFZWeXdDc251ZmJ5NnRTQ1pCRk50c2o3Y1ZYSGY4dmlLTEh0UGt1MTg2Y2ZCM3JvbURidnJ2VGpUTG5ubFBDcVhFZ2J3Z2xSbXdXRjZsQVJkWDR1TkE5SUtBOEljN2hPN0U5d0ZlQnJHQzNGemxRTjhONHV2TzFHQ2hYWklMcmJtUlB4TkxRYnpZUHFyUDRpdVVHcHFwNk5yblRRUzFmMFpzUXM0QmRjRHpHVFRvc2RBQkp6NU8xRDRGZFBhdVZVbFIxbkVpbGhXdno1IiwicHJlZmVycmVkX3VzZXJuYW1lIjoiamhhbGwiLCJyYXQiOjE2NTc1NjA3NjUsInJlYWxtTmFtZSI6ImNsb3VkSWRlbnRpdHlSZWFsbSIsInNfaGFzaCI6IjVjcVluZ1NSVFN4T3JCNEh6Smt2UVEiLCJzdWIiOiI2NjIwMDNQV1ZGIn0.i5QjVWhXj9C9brE3PmJSv4DS5MhzgrmbeyUQbAioLcCVwOVwo-ImBi_6N2uX3iIilqhUUAPU7Uah_YgfszFfa0VnCvG4mjtJ8Nbg8Kz4CvTpskxGTUuFfn90wsLlPSNvoKwlv0EkhENfJr9UHs01nlHN8XlvSWcu8R8cBlUvBGSKDZgx0D3n6wrGhPkZm4-v1yBmrNrKzB5zocTfu2kIycRqjUl7X2U_DTYiGwrisB67dGkIhBXnkq3kKjwLZvNdWmMRo3UTd-yklajFaUO1lZI5IBDutg3z6K649n2k3H7Gg8qAqJsujTcG5AjFTJTdoeSnXaAqTysjWKMl40wi6g
header
{
  "kid": "server",
  "alg": "PS256"
}
claims
{
  "sub": "662003PWVF",
  "rat": 1657560765,
  "realmName": "cloudIdentityRealm",
  "amr": [
    "password"
  ],
  "iss": "https://fapipoc.tryverify.ibm.com/oauth2",
  "preferred_username": "jhall",
  "nonce": "ekEoPDgSgbL9FmimAk7AuXbjqopqUd5z6wmqTxeE4JpeiTXT7v7yQup7zC5eQJoDSbjTvyxa4Dxn4pcf0c208nAXKgpLkF6c0SOycjW5NyekXOgrUKyW7VirTCRVq02TgP4ENJ9Lhhb3nQxA27iiOxvQUrfEV7eg1apUOJ4nnLq8kOohrwZVhVVywCsnufby6tSCZBFNtsj7cVXHf8viKLHtPku186cfB3romDbvrvTjTLnnlPCqXEgbwglRmwWF6lARdX4uNA9IKA8Ic7hO7E9wFeBrGC3FzlQN8N4uvO1GChXZILrbmRPxNLQbzYPqrP4iuUGpqp6NrnTQS1f0ZsQs4BdcDzGTTosdABJz5O1D4FdPauVUlR1nEilhWvz5",
  "acr": "urn:mace:incommon:iap:silver",
  "aud": "e6ccf44d-838d-4bec-9d7e-0c1bf6677b8c",
  "c_hash": "tjbA52nzcwuwCAr6L1q2IA",
  "s_hash": "5cqYngSRTSxOrB4HzJkvQQ",
  "auth_time": 1657558028,
  "name": "Jessica Hall",
  "exp": 1657567965,
  "iat": 1657560765,
  "email": "jhall@mailinator.com",
  "jti": "8f4b7bff-5ecc-4b0d-8a32-538053a31560"
}
2022-07-11 17:32:46 SUCCESS
ValidateIdToken
ID token iss, aud, exp, iat, auth_time, acr & nbf claims passed validation checks
2022-07-11 17:32:46
ValidateIdTokenStandardClaims
sub is a string with content
2022-07-11 17:32:46
ValidateIdTokenStandardClaims
Skipping unknown claim: rat
2022-07-11 17:32:46
ValidateIdTokenStandardClaims
Skipping unknown claim: realmName
2022-07-11 17:32:46
ValidateIdTokenStandardClaims
preferred_username is a string with content
2022-07-11 17:32:46
ValidateIdTokenStandardClaims
name is a string with content
2022-07-11 17:32:46
ValidateIdTokenStandardClaims
email is a string with content
2022-07-11 17:32:46 SUCCESS
ValidateIdTokenStandardClaims
id_token claims are valid
2022-07-11 17:32:46 SUCCESS
ValidateIdTokenNonce
Nonce values match
nonce
ekEoPDgSgbL9FmimAk7AuXbjqopqUd5z6wmqTxeE4JpeiTXT7v7yQup7zC5eQJoDSbjTvyxa4Dxn4pcf0c208nAXKgpLkF6c0SOycjW5NyekXOgrUKyW7VirTCRVq02TgP4ENJ9Lhhb3nQxA27iiOxvQUrfEV7eg1apUOJ4nnLq8kOohrwZVhVVywCsnufby6tSCZBFNtsj7cVXHf8viKLHtPku186cfB3romDbvrvTjTLnnlPCqXEgbwglRmwWF6lARdX4uNA9IKA8Ic7hO7E9wFeBrGC3FzlQN8N4uvO1GChXZILrbmRPxNLQbzYPqrP4iuUGpqp6NrnTQS1f0ZsQs4BdcDzGTTosdABJz5O1D4FdPauVUlR1nEilhWvz5
2022-07-11 17:32:46 SUCCESS
ValidateIdTokenACRClaimAgainstRequest
acr value in id_token is (one of) the requested values
actual
urn:mace:incommon:iap:silver
requested
[
  "urn:mace:incommon:iap:silver"
]
2022-07-11 17:32:46 SUCCESS
ValidateIdTokenSignature
id_token signature validated
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYW1yIjpbInBhc3N3b3JkIl0sImF1ZCI6WyJlNmNjZjQ0ZC04MzhkLTRiZWMtOWQ3ZS0wYzFiZjY2NzdiOGMiXSwiYXV0aF90aW1lIjoxNjU3NTU4MDI4LCJjX2hhc2giOiJ0amJBNTJuemN3dXdDQXI2TDFxMklBIiwiZW1haWwiOiJqaGFsbEBtYWlsaW5hdG9yLmNvbSIsImV4cCI6MTY1NzU2Nzk2NSwiaWF0IjoxNjU3NTYwNzY1LCJpc3MiOiJodHRwczovL2ZhcGlwb2MudHJ5dmVyaWZ5LmlibS5jb20vb2F1dGgyIiwianRpIjoiOGY0YjdiZmYtNWVjYy00YjBkLThhMzItNTM4MDUzYTMxNTYwIiwibmFtZSI6Ikplc3NpY2EgSGFsbCIsIm5vbmNlIjoiZWtFb1BEZ1NnYkw5Rm1pbUFrN0F1WGJqcW9wcVVkNXo2d21xVHhlRTRKcGVpVFhUN3Y3eVF1cDd6QzVlUUpvRFNialR2eXhhNER4bjRwY2YwYzIwOG5BWEtncExrRjZjMFNPeWNqVzVOeWVrWE9nclVLeVc3VmlyVENSVnEwMlRnUDRFTko5TGhoYjNuUXhBMjdpaU94dlFVcmZFVjdlZzFhcFVPSjRubkxxOGtPb2hyd1pWaFZWeXdDc251ZmJ5NnRTQ1pCRk50c2o3Y1ZYSGY4dmlLTEh0UGt1MTg2Y2ZCM3JvbURidnJ2VGpUTG5ubFBDcVhFZ2J3Z2xSbXdXRjZsQVJkWDR1TkE5SUtBOEljN2hPN0U5d0ZlQnJHQzNGemxRTjhONHV2TzFHQ2hYWklMcmJtUlB4TkxRYnpZUHFyUDRpdVVHcHFwNk5yblRRUzFmMFpzUXM0QmRjRHpHVFRvc2RBQkp6NU8xRDRGZFBhdVZVbFIxbkVpbGhXdno1IiwicHJlZmVycmVkX3VzZXJuYW1lIjoiamhhbGwiLCJyYXQiOjE2NTc1NjA3NjUsInJlYWxtTmFtZSI6ImNsb3VkSWRlbnRpdHlSZWFsbSIsInNfaGFzaCI6IjVjcVluZ1NSVFN4T3JCNEh6Smt2UVEiLCJzdWIiOiI2NjIwMDNQV1ZGIn0.i5QjVWhXj9C9brE3PmJSv4DS5MhzgrmbeyUQbAioLcCVwOVwo-ImBi_6N2uX3iIilqhUUAPU7Uah_YgfszFfa0VnCvG4mjtJ8Nbg8Kz4CvTpskxGTUuFfn90wsLlPSNvoKwlv0EkhENfJr9UHs01nlHN8XlvSWcu8R8cBlUvBGSKDZgx0D3n6wrGhPkZm4-v1yBmrNrKzB5zocTfu2kIycRqjUl7X2U_DTYiGwrisB67dGkIhBXnkq3kKjwLZvNdWmMRo3UTd-yklajFaUO1lZI5IBDutg3z6K649n2k3H7Gg8qAqJsujTcG5AjFTJTdoeSnXaAqTysjWKMl40wi6g
2022-07-11 17:32:46 SUCCESS
ValidateIdTokenSignatureUsingKid
id_token signature validated
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYW1yIjpbInBhc3N3b3JkIl0sImF1ZCI6WyJlNmNjZjQ0ZC04MzhkLTRiZWMtOWQ3ZS0wYzFiZjY2NzdiOGMiXSwiYXV0aF90aW1lIjoxNjU3NTU4MDI4LCJjX2hhc2giOiJ0amJBNTJuemN3dXdDQXI2TDFxMklBIiwiZW1haWwiOiJqaGFsbEBtYWlsaW5hdG9yLmNvbSIsImV4cCI6MTY1NzU2Nzk2NSwiaWF0IjoxNjU3NTYwNzY1LCJpc3MiOiJodHRwczovL2ZhcGlwb2MudHJ5dmVyaWZ5LmlibS5jb20vb2F1dGgyIiwianRpIjoiOGY0YjdiZmYtNWVjYy00YjBkLThhMzItNTM4MDUzYTMxNTYwIiwibmFtZSI6Ikplc3NpY2EgSGFsbCIsIm5vbmNlIjoiZWtFb1BEZ1NnYkw5Rm1pbUFrN0F1WGJqcW9wcVVkNXo2d21xVHhlRTRKcGVpVFhUN3Y3eVF1cDd6QzVlUUpvRFNialR2eXhhNER4bjRwY2YwYzIwOG5BWEtncExrRjZjMFNPeWNqVzVOeWVrWE9nclVLeVc3VmlyVENSVnEwMlRnUDRFTko5TGhoYjNuUXhBMjdpaU94dlFVcmZFVjdlZzFhcFVPSjRubkxxOGtPb2hyd1pWaFZWeXdDc251ZmJ5NnRTQ1pCRk50c2o3Y1ZYSGY4dmlLTEh0UGt1MTg2Y2ZCM3JvbURidnJ2VGpUTG5ubFBDcVhFZ2J3Z2xSbXdXRjZsQVJkWDR1TkE5SUtBOEljN2hPN0U5d0ZlQnJHQzNGemxRTjhONHV2TzFHQ2hYWklMcmJtUlB4TkxRYnpZUHFyUDRpdVVHcHFwNk5yblRRUzFmMFpzUXM0QmRjRHpHVFRvc2RBQkp6NU8xRDRGZFBhdVZVbFIxbkVpbGhXdno1IiwicHJlZmVycmVkX3VzZXJuYW1lIjoiamhhbGwiLCJyYXQiOjE2NTc1NjA3NjUsInJlYWxtTmFtZSI6ImNsb3VkSWRlbnRpdHlSZWFsbSIsInNfaGFzaCI6IjVjcVluZ1NSVFN4T3JCNEh6Smt2UVEiLCJzdWIiOiI2NjIwMDNQV1ZGIn0.i5QjVWhXj9C9brE3PmJSv4DS5MhzgrmbeyUQbAioLcCVwOVwo-ImBi_6N2uX3iIilqhUUAPU7Uah_YgfszFfa0VnCvG4mjtJ8Nbg8Kz4CvTpskxGTUuFfn90wsLlPSNvoKwlv0EkhENfJr9UHs01nlHN8XlvSWcu8R8cBlUvBGSKDZgx0D3n6wrGhPkZm4-v1yBmrNrKzB5zocTfu2kIycRqjUl7X2U_DTYiGwrisB67dGkIhBXnkq3kKjwLZvNdWmMRo3UTd-yklajFaUO1lZI5IBDutg3z6K649n2k3H7Gg8qAqJsujTcG5AjFTJTdoeSnXaAqTysjWKMl40wi6g
2022-07-11 17:32:46 SUCCESS
CheckForSubjectInIdToken
Found 'sub' in id_token
sub
662003PWVF
2022-07-11 17:32:46
EnsureIdTokenUpdatedAtValid
id_token response does not contain 'updated_at'
2022-07-11 17:32:46 INFO
ValidateEncryptedIdTokenHasKid
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2022-07-11 17:32:46 SUCCESS
EnsureIdTokenContainsKid
kid was found in the ID token header
kid
server
2022-07-11 17:32:46 SUCCESS
FAPIValidateIdTokenSigningAlg
id_token was signed with a permitted algorithm
permitted
[
  "PS256",
  "ES256"
]
alg
PS256
2022-07-11 17:32:46 INFO
FAPIValidateIdTokenEncryptionAlg
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2022-07-11 17:32:46 SUCCESS
ExtractSHash
Extracted s_hash from ID Token
s_hash
5cqYngSRTSxOrB4HzJkvQQ
alg
PS256
2022-07-11 17:32:46 SUCCESS
ValidateSHash
s_hash validated successfully
expected_hash
5cqYngSRTSxOrB4HzJkvQQ
unhashed_value
exLNNBJ7M2
id_token_hash
5cqYngSRTSxOrB4HzJkvQQ
2022-07-11 17:32:46 SUCCESS
ExtractCHash
Extracted c_hash from ID Token
c_hash
tjbA52nzcwuwCAr6L1q2IA
alg
PS256
2022-07-11 17:32:46 SUCCESS
ValidateCHash
c_hash validated successfully
expected_hash
tjbA52nzcwuwCAr6L1q2IA
unhashed_value
4JdRcxARXn-wZTSEAQtIWZSF2cKR2cihARIs-_gFiKc.FoWCnYwS1O7u2fPTPu5Xb1pHF2FSHBxyeuaBZXAGuvxj9RNVF-Xq9XmQSDL4dPnTkw_3WqSeW1p92glbaITSJg
id_token_hash
tjbA52nzcwuwCAr6L1q2IA
Call token endpoint
2022-07-11 17:32:46 SUCCESS
CreateTokenEndpointRequestForAuthorizationCodeGrant
Created token endpoint request
grant_type
authorization_code
code
4JdRcxARXn-wZTSEAQtIWZSF2cKR2cihARIs-_gFiKc.FoWCnYwS1O7u2fPTPu5Xb1pHF2FSHBxyeuaBZXAGuvxj9RNVF-Xq9XmQSDL4dPnTkw_3WqSeW1p92glbaITSJg
redirect_uri
https://www.certification.openid.net/test/a/fapipoc_fapi_dev/callback
2022-07-11 17:32:46 SUCCESS
CreateClientAuthenticationAssertionClaims
Created client assertion claims
iss
e6ccf44d-838d-4bec-9d7e-0c1bf6677b8c
sub
e6ccf44d-838d-4bec-9d7e-0c1bf6677b8c
aud
https://fapipoc.tryverify.ibm.com/oauth2/token
jti
DbbI5T4iIeVy81Ubgwrz
iat
1657560766
exp
1657560826
2022-07-11 17:32:46 SUCCESS
SignClientAuthenticationAssertion
Signed the client assertion
client_assertion
eyJraWQiOiJmYXBpcHMxIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJlNmNjZjQ0ZC04MzhkLTRiZWMtOWQ3ZS0wYzFiZjY2NzdiOGMiLCJhdWQiOiJodHRwczpcL1wvZmFwaXBvYy50cnl2ZXJpZnkuaWJtLmNvbVwvb2F1dGgyXC90b2tlbiIsImlzcyI6ImU2Y2NmNDRkLTgzOGQtNGJlYy05ZDdlLTBjMWJmNjY3N2I4YyIsImV4cCI6MTY1NzU2MDgyNiwiaWF0IjoxNjU3NTYwNzY2LCJqdGkiOiJEYmJJNVQ0aUllVnk4MVViZ3dyeiJ9.ib96tMs9qENz8iZwMAc1h4rNS-4Uvv_OHPm7gphQRMIU8TpoFVrn7aoew7oTfYStvCLF_YUXpX1zeQxZpxIoDYV3T16a5asTOhowHa6n2voIKDM6olBF6-WL-jaG_3jmXpR5qdow2397mX5SJ8eD4Iczq_WWQPxcS6_nX9q7vs266TzSXCUB7UabR-ca-xXAKHlKkTwDtgPjwhZw3e5FZX7j7LBkmW81Unko46hRQlXlzt-bnpZjVmxCwbR9EUhJns7HqON9cmZsdMFsopOSGJ2EI_GcLaGbQiQjWWzXtlLPtlkgLDFy92x4z6DEjQADzMAJW86DOVH3P-lyEEq62A
2022-07-11 17:32:46
AddClientAssertionToTokenEndpointRequest
Added client assertion
grant_type
authorization_code
code
4JdRcxARXn-wZTSEAQtIWZSF2cKR2cihARIs-_gFiKc.FoWCnYwS1O7u2fPTPu5Xb1pHF2FSHBxyeuaBZXAGuvxj9RNVF-Xq9XmQSDL4dPnTkw_3WqSeW1p92glbaITSJg
redirect_uri
https://www.certification.openid.net/test/a/fapipoc_fapi_dev/callback
client_assertion
eyJraWQiOiJmYXBpcHMxIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJlNmNjZjQ0ZC04MzhkLTRiZWMtOWQ3ZS0wYzFiZjY2NzdiOGMiLCJhdWQiOiJodHRwczpcL1wvZmFwaXBvYy50cnl2ZXJpZnkuaWJtLmNvbVwvb2F1dGgyXC90b2tlbiIsImlzcyI6ImU2Y2NmNDRkLTgzOGQtNGJlYy05ZDdlLTBjMWJmNjY3N2I4YyIsImV4cCI6MTY1NzU2MDgyNiwiaWF0IjoxNjU3NTYwNzY2LCJqdGkiOiJEYmJJNVQ0aUllVnk4MVViZ3dyeiJ9.ib96tMs9qENz8iZwMAc1h4rNS-4Uvv_OHPm7gphQRMIU8TpoFVrn7aoew7oTfYStvCLF_YUXpX1zeQxZpxIoDYV3T16a5asTOhowHa6n2voIKDM6olBF6-WL-jaG_3jmXpR5qdow2397mX5SJ8eD4Iczq_WWQPxcS6_nX9q7vs266TzSXCUB7UabR-ca-xXAKHlKkTwDtgPjwhZw3e5FZX7j7LBkmW81Unko46hRQlXlzt-bnpZjVmxCwbR9EUhJns7HqON9cmZsdMFsopOSGJ2EI_GcLaGbQiQjWWzXtlLPtlkgLDFy92x4z6DEjQADzMAJW86DOVH3P-lyEEq62A
client_assertion_type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2022-07-11 17:32:46
CallTokenEndpoint
HTTP request
request_uri
https://fapipoc.tryverify.ibm.com/oauth2/token
request_method
POST
request_headers
{
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "1037"
}
request_body
grant_type=authorization_code&code=4JdRcxARXn-wZTSEAQtIWZSF2cKR2cihARIs-_gFiKc.FoWCnYwS1O7u2fPTPu5Xb1pHF2FSHBxyeuaBZXAGuvxj9RNVF-Xq9XmQSDL4dPnTkw_3WqSeW1p92glbaITSJg&redirect_uri=https%3A%2F%2Fwww.certification.openid.net%2Ftest%2Fa%2Ffapipoc_fapi_dev%2Fcallback&client_assertion=eyJraWQiOiJmYXBpcHMxIiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJlNmNjZjQ0ZC04MzhkLTRiZWMtOWQ3ZS0wYzFiZjY2NzdiOGMiLCJhdWQiOiJodHRwczpcL1wvZmFwaXBvYy50cnl2ZXJpZnkuaWJtLmNvbVwvb2F1dGgyXC90b2tlbiIsImlzcyI6ImU2Y2NmNDRkLTgzOGQtNGJlYy05ZDdlLTBjMWJmNjY3N2I4YyIsImV4cCI6MTY1NzU2MDgyNiwiaWF0IjoxNjU3NTYwNzY2LCJqdGkiOiJEYmJJNVQ0aUllVnk4MVViZ3dyeiJ9.ib96tMs9qENz8iZwMAc1h4rNS-4Uvv_OHPm7gphQRMIU8TpoFVrn7aoew7oTfYStvCLF_YUXpX1zeQxZpxIoDYV3T16a5asTOhowHa6n2voIKDM6olBF6-WL-jaG_3jmXpR5qdow2397mX5SJ8eD4Iczq_WWQPxcS6_nX9q7vs266TzSXCUB7UabR-ca-xXAKHlKkTwDtgPjwhZw3e5FZX7j7LBkmW81Unko46hRQlXlzt-bnpZjVmxCwbR9EUhJns7HqON9cmZsdMFsopOSGJ2EI_GcLaGbQiQjWWzXtlLPtlkgLDFy92x4z6DEjQADzMAJW86DOVH3P-lyEEq62A&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
request_mutual_tls
{
  "cert": "MIID2TCCA36gAwIBAgIUKXA8+q3GoAhthdhhMdI7y02Mg+4wCgYIKoZIzj0EAwIwgYExCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhOZXcgWW9yazE0MDIGA1UECgwrSW50ZXJuYXRpb25hbCBCdXNpbmVzcyBNYWNoaW5lcyBDb3Jwb3JhdGlvbjEpMCcGA1UEAwwgSUJNIFNlY3VyaXR5IFZlcmlmeSBEZXYtSVRFIENBLTEwHhcNMjIwMjEwMTU1ODAwWhcNMjUwMjA5MTU1ODAwWjB0MQswCQYDVQQGEwJTRzETMBEGA1UECBMKa2NhMmNzci1TVDESMBAGA1UEBxMJa2NhMmNzci1MMRIwEAYDVQQKEwlrY2EyY3NyLU8xEzARBgNVBAsTCmtjYTJjc3ItT1UxEzARBgNVBAMTCmtjYTJjc3ItQ04wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCV6uh9e1Z54rwv4amn0M10uJqPtxZH45MsDyjVafe/5p1N8M2Zl2LQfSWHOvXtFBZlr72bz1TrZf8cuXn9WetXDg7FqElTxgV75uGubd1RpUKkFnN8dBSq1oadvpmU+1Ov7mRKzh3cPlbYX7Dwr372ZVGuumwjwVVfszmwA2bKy+bN7JvN41vic3OnAm+uBq5sB4HN87x3+hN/Z4rkO8HEdVgEwzQSXprs52vnPAt41Jn/RPx5+Z5yIGKuS10GCT1e19Afh4hgZfCRTBLCGDldJwemhVD2MDET4qYyhW/BkLzc3+3OjiXU10+NpCP+SC88WQp3U8Z24qlyLHA9prKXAgMBAAGjggETMIIBDzAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwIwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUSKev5Wnf5dBO/838Jt87ZcwqXbIwHwYDVR0jBBgwFoAUVG35JNW6n95CIBrdXCkTvAi9lhAwgZkGA1UdEQSBkTCBjoIPd3d3LmV4YW1wbGUuY29tghB0ZXN0LmV4YW1wbGUuY29tghBtYWlsLmV4YW1wbGUuY29tgg93d3cuZXhhbXBsZS5uZXSBE3NoYW5rYXJ2QHNnLmlibS5jb22HBMAAAgGHBMYzZP6HECABDbgAAAAAAAAAAAAAAAGGE2h0dHBzOi8vamtlLmNvbS9mb28wCgYIKoZIzj0EAwIDSQAwRgIhALF8B38YTP3q+Bf1wrcCBSL/ssGhO6H1NaWUykHSxYQqAiEAgTeJC+4FXvklUnjJEabkAeZU/oycGMPI/u0Z56fq984\u003d",
  "key": "MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQCV6uh9e1Z54rwv4amn0M10uJqPtxZH45MsDyjVafe/5p1N8M2Zl2LQfSWHOvXtFBZlr72bz1TrZf8cuXn9WetXDg7FqElTxgV75uGubd1RpUKkFnN8dBSq1oadvpmU+1Ov7mRKzh3cPlbYX7Dwr372ZVGuumwjwVVfszmwA2bKy+bN7JvN41vic3OnAm+uBq5sB4HN87x3+hN/Z4rkO8HEdVgEwzQSXprs52vnPAt41Jn/RPx5+Z5yIGKuS10GCT1e19Afh4hgZfCRTBLCGDldJwemhVD2MDET4qYyhW/BkLzc3+3OjiXU10+NpCP+SC88WQp3U8Z24qlyLHA9prKXAgMBAAECggEAQrpw6i1kU9M2hS9x9tarJHlonnBVVAE5CCLlP3yvwDRTLxZwRR2LZ5ZUhmkZfoFy6Kb9A+WYfECFeVEbOcf0xuZkb9kUblvVJA2jxSJ0oLsouuWdWLdIXbQn7f2g2Z22Zbf73wn4Y4hB2oRZOwA6SEzXuyiSKqYKrJKXKj+RWNETjUt/7H4skIDafFhgo1+V7ZbuMJxdp4xVp98g3mxyUj1hthg3RNDpiapqElobSEKlUnYQVpRfBRIAFWtRvO4ZjwFFOgpTel3E6gm34miTN5Vp2Je+C02LAx04G5bCOPe6EwESZEPeVE6nbjvw1wM2Nl8GkwEGweDNM165y/8T1QKBgQDO7XHODYgmb1vA7Dk4XDQkqgvFpMqQTNvxgXarK9lDNaQBDoXZjp+PQ4ZG7UY9SZ82uPz/kZLlZJeXGg1Cd3v2ErLQXWrq8IHY+IwgXt0/jForLnRihGwqKg7J801PPbOM4BCh3LpZwCoiVXCAOCSA++h8CBBffZ97eiiPAcO6lQKBgQC5eGVhLebWsrOgKqr7ouSeT0BuVb8rXt2MaYTVwTFs+BsbUOnwYcXYBeV4mtgtLmf7C6m5NoTWOGsFdjmk51uHC5k/h9fXf1EnQBbVjZDsIelCzAeWkwxDiDtuwChB3cLk64qtmLRy0rHAUJvfG93/UbaO/LxZwyPvtL9ylHWZewKBgBAUqcRujscV3laGxQeZOsAiqtmILem631jMS9GPjcnIUF94pnQ6vjGe+L9oTw4SO5pAFAE0aesDvzgR4TfqGysLVvQUXmu1lxGqdxFI7f6zRIqYiJjjW5iHPjD5hGeFDwACpag+hAjXgy653w1Hz6ZqbS2+Xq9dDtjErIQ4ieJlAoGBAIdvjJB/RW8IhbTzE3K3y7xy4PjxMq1IE/6B21eAQUhykNDMsFgx/Zg3Dg+Y+z1bAuFG7gRq9Gu+PSB66bMqoyKlbJ4A47Pgq/E+kq4VN3vHc5+sf+oLrUvvQn8oYP1gI/6opdcIiNTEWLq34mr03ZKhJ++YTS47GpXjZl4UXR/bAoGARrRC3D0HNCw2dQZ8jXFoEfXU7lHuCOBFTZQz/mGlGdSXm9hoZkb1nOTVxJhj+WG35HQn4FWDQHLX1i9g4QnopJ7Ga80VNNdmq+ub9nEx9e1YmLlD5skazO8mwIOmAyyi2FBKYGtXhA9nYO4AdfcbG6ENTwoX/IjA62IG+5gNvoo\u003d"
}
2022-07-11 17:32:46 RESPONSE
CallTokenEndpoint
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-content-type-options": "nosniff",
  "cache-control": "no-store",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-c24538ad-f5ee-477d-9d24-fafe4b25712d",
  "pragma": "no-cache",
  "x-global-transaction-id": "1ad190f862cc5ebe2ced6c41",
  "content-length": "2008",
  "date": "Mon, 11 Jul 2022 17:32:46 GMT",
  "connection": "close",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:coXb+gTrYETARE295XGpw6iN2naWyuraOc2FQxIyev4\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDPR02A\u003dPBC5YS:2452117324; Path\u003d/; Domain\u003dverify.ibm.com; Secure; HttpOnly"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d21",
    "origin; dur\u003d93"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"access_token":"Sqlk3fM3Qow8H4aVElOm0mry33OTdvsVlOhWP8H7Vhc.G5vfcFoxEsMGzkd4sE6CXx7fKwBHR-tqT7qag2ewMgI1zad1kiy7gdkjG9MWCYnwIcAVWQNtAXk_0Njm2JRFuA.M18xNjU3NTYwNzY2XzMy","expires_in":3600,"id_token":"eyJhbGciOiJQUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJsbDNGSE1YTnEtdXIzeDE2dXFpNVlnIiwiYXVkIjpbImU2Y2NmNDRkLTgzOGQtNGJlYy05ZDdlLTBjMWJmNjY3N2I4YyJdLCJhdXRoX3RpbWUiOjE2NTc1NTgwMjgsImVtYWlsIjoiamhhbGxAbWFpbGluYXRvci5jb20iLCJleHAiOjE2NTc1Njc5NjYsImlhdCI6MTY1NzU2MDc2NiwiaXNzIjoiaHR0cHM6Ly9mYXBpcG9jLnRyeXZlcmlmeS5pYm0uY29tL29hdXRoMiIsImp0aSI6IjU2ODI0NGFiLWZlYTEtNDBjZS04NDc2LTU2YmM0YTJlOGZhYiIsIm5hbWUiOiJKZXNzaWNhIEhhbGwiLCJub25jZSI6ImVrRW9QRGdTZ2JMOUZtaW1BazdBdVhianFvcHFVZDV6NndtcVR4ZUU0SnBlaVRYVDd2N3lRdXA3ekM1ZVFKb0RTYmpUdnl4YTREeG40cGNmMGMyMDhuQVhLZ3BMa0Y2YzBTT3ljalc1Tnlla1hPZ3JVS3lXN1ZpclRDUlZxMDJUZ1A0RU5KOUxoaGIzblF4QTI3aWlPeHZRVXJmRVY3ZWcxYXBVT0o0bm5McThrT29ocndaVmhWVnl3Q3NudWZieTZ0U0NaQkZOdHNqN2NWWEhmOHZpS0xIdFBrdTE4NmNmQjNyb21EYnZydlRqVExubmxQQ3FYRWdid2dsUm13V0Y2bEFSZFg0dU5BOUlLQThJYzdoTzdFOXdGZUJyR0MzRnpsUU44TjR1dk8xR0NoWFpJTHJibVJQeE5MUWJ6WVBxclA0aXVVR3BxcDZOcm5UUVMxZjBac1FzNEJkY0R6R1RUb3NkQUJKejVPMUQ0RmRQYXVWVWxSMW5FaWxoV3Z6NSIsInByZWZlcnJlZF91c2VybmFtZSI6ImpoYWxsIiwicmF0IjoxNjU3NTYwNzY1LCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJydF9oYXNoIjoidE5EYkNlMXQ0MHk0Y3FJMXR2emVVUSIsInNfaGFzaCI6IjVjcVluZ1NSVFN4T3JCNEh6Smt2UVEiLCJzdWIiOiI2NjIwMDNQV1ZGIn0.FYi_wZa_h47mgkIo2jdEDxZAfnHGAINWeTgD7Pnnm3Xe-H1fJeanjlDcPcJy4_p--pnxEe1vdUr8plY07wfNJsJxZ4Wm9hZXWtvypBh2HCSDhsulihnXRVUJjgDJwdfWQCMAtu9pMXeS6CN0R8RaW2E-se7AqELMPyaO1vV3AfaUA2HgaVvPxkpjrumIYJg8jmL9aiC7wZfuORcnL385w87obeQQ9bGy1MgcVFeOmo1pGs_xWYvkZjuSrGdRHXgjo1vJC9I4k6-2pXQkWNyZFXvcoXFekIUQCJ4mmUpxqspYao0lvm-etjAbVnFMz3pEnJVOqre9cnsHU29dVfLiDg","refresh_token":"zO8CbKXUx_LxkXMUw3MVKr3k-oglXSg5mCBJC48R_qk.lrS_xpLMWmHT4g8EJgByPsMNn0pV6KXgrY7Ceg3dc0YMVGPB40cjrIL3gnPudC5V-_XaWMHBxtz2T3Wv9rPwOA.M18xNjU3NTYwNzY2XzMy","scope":"openid email","token_type":"bearer"}
2022-07-11 17:32:46 SUCCESS
CallTokenEndpoint
Parsed token endpoint response
access_token
Sqlk3fM3Qow8H4aVElOm0mry33OTdvsVlOhWP8H7Vhc.G5vfcFoxEsMGzkd4sE6CXx7fKwBHR-tqT7qag2ewMgI1zad1kiy7gdkjG9MWCYnwIcAVWQNtAXk_0Njm2JRFuA.M18xNjU3NTYwNzY2XzMy
expires_in
3600
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJsbDNGSE1YTnEtdXIzeDE2dXFpNVlnIiwiYXVkIjpbImU2Y2NmNDRkLTgzOGQtNGJlYy05ZDdlLTBjMWJmNjY3N2I4YyJdLCJhdXRoX3RpbWUiOjE2NTc1NTgwMjgsImVtYWlsIjoiamhhbGxAbWFpbGluYXRvci5jb20iLCJleHAiOjE2NTc1Njc5NjYsImlhdCI6MTY1NzU2MDc2NiwiaXNzIjoiaHR0cHM6Ly9mYXBpcG9jLnRyeXZlcmlmeS5pYm0uY29tL29hdXRoMiIsImp0aSI6IjU2ODI0NGFiLWZlYTEtNDBjZS04NDc2LTU2YmM0YTJlOGZhYiIsIm5hbWUiOiJKZXNzaWNhIEhhbGwiLCJub25jZSI6ImVrRW9QRGdTZ2JMOUZtaW1BazdBdVhianFvcHFVZDV6NndtcVR4ZUU0SnBlaVRYVDd2N3lRdXA3ekM1ZVFKb0RTYmpUdnl4YTREeG40cGNmMGMyMDhuQVhLZ3BMa0Y2YzBTT3ljalc1Tnlla1hPZ3JVS3lXN1ZpclRDUlZxMDJUZ1A0RU5KOUxoaGIzblF4QTI3aWlPeHZRVXJmRVY3ZWcxYXBVT0o0bm5McThrT29ocndaVmhWVnl3Q3NudWZieTZ0U0NaQkZOdHNqN2NWWEhmOHZpS0xIdFBrdTE4NmNmQjNyb21EYnZydlRqVExubmxQQ3FYRWdid2dsUm13V0Y2bEFSZFg0dU5BOUlLQThJYzdoTzdFOXdGZUJyR0MzRnpsUU44TjR1dk8xR0NoWFpJTHJibVJQeE5MUWJ6WVBxclA0aXVVR3BxcDZOcm5UUVMxZjBac1FzNEJkY0R6R1RUb3NkQUJKejVPMUQ0RmRQYXVWVWxSMW5FaWxoV3Z6NSIsInByZWZlcnJlZF91c2VybmFtZSI6ImpoYWxsIiwicmF0IjoxNjU3NTYwNzY1LCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJydF9oYXNoIjoidE5EYkNlMXQ0MHk0Y3FJMXR2emVVUSIsInNfaGFzaCI6IjVjcVluZ1NSVFN4T3JCNEh6Smt2UVEiLCJzdWIiOiI2NjIwMDNQV1ZGIn0.FYi_wZa_h47mgkIo2jdEDxZAfnHGAINWeTgD7Pnnm3Xe-H1fJeanjlDcPcJy4_p--pnxEe1vdUr8plY07wfNJsJxZ4Wm9hZXWtvypBh2HCSDhsulihnXRVUJjgDJwdfWQCMAtu9pMXeS6CN0R8RaW2E-se7AqELMPyaO1vV3AfaUA2HgaVvPxkpjrumIYJg8jmL9aiC7wZfuORcnL385w87obeQQ9bGy1MgcVFeOmo1pGs_xWYvkZjuSrGdRHXgjo1vJC9I4k6-2pXQkWNyZFXvcoXFekIUQCJ4mmUpxqspYao0lvm-etjAbVnFMz3pEnJVOqre9cnsHU29dVfLiDg
refresh_token
zO8CbKXUx_LxkXMUw3MVKr3k-oglXSg5mCBJC48R_qk.lrS_xpLMWmHT4g8EJgByPsMNn0pV6KXgrY7Ceg3dc0YMVGPB40cjrIL3gnPudC5V-_XaWMHBxtz2T3Wv9rPwOA.M18xNjU3NTYwNzY2XzMy
scope
openid email
token_type
bearer
Verify token endpoint response
2022-07-11 17:32:46 SUCCESS
CheckIfTokenEndpointResponseError
No error from token endpoint
2022-07-11 17:32:46 SUCCESS
CheckForAccessTokenValue
Found an access token
access_token
Sqlk3fM3Qow8H4aVElOm0mry33OTdvsVlOhWP8H7Vhc.G5vfcFoxEsMGzkd4sE6CXx7fKwBHR-tqT7qag2ewMgI1zad1kiy7gdkjG9MWCYnwIcAVWQNtAXk_0Njm2JRFuA.M18xNjU3NTYwNzY2XzMy
2022-07-11 17:32:46 SUCCESS
ExtractAccessTokenFromTokenResponse
Extracted the access token
value
Sqlk3fM3Qow8H4aVElOm0mry33OTdvsVlOhWP8H7Vhc.G5vfcFoxEsMGzkd4sE6CXx7fKwBHR-tqT7qag2ewMgI1zad1kiy7gdkjG9MWCYnwIcAVWQNtAXk_0Njm2JRFuA.M18xNjU3NTYwNzY2XzMy
type
bearer
2022-07-11 17:32:46 SUCCESS
ExtractExpiresInFromTokenEndpointResponse
Extracted 'expires_in'
expires_in
3600
2022-07-11 17:32:46 SUCCESS
ValidateExpiresIn
expires_in passed all validation checks
expires_in
3600
2022-07-11 17:32:46 SUCCESS
CheckForRefreshTokenValue
Found a refresh token
refresh_token
zO8CbKXUx_LxkXMUw3MVKr3k-oglXSg5mCBJC48R_qk.lrS_xpLMWmHT4g8EJgByPsMNn0pV6KXgrY7Ceg3dc0YMVGPB40cjrIL3gnPudC5V-_XaWMHBxtz2T3Wv9rPwOA.M18xNjU3NTYwNzY2XzMy
2022-07-11 17:32:46 SUCCESS
EnsureMinimumRefreshTokenLength
Refresh token is of sufficient length
actual
1208
required
128
2022-07-11 17:32:46 SUCCESS
EnsureMinimumRefreshTokenEntropy
Calculated shannon entropy seems sufficient
actual
844.7051722322478
expected
96.0
value
zO8CbKXUx_LxkXMUw3MVKr3k-oglXSg5mCBJC48R_qk.lrS_xpLMWmHT4g8EJgByPsMNn0pV6KXgrY7Ceg3dc0YMVGPB40cjrIL3gnPudC5V-_XaWMHBxtz2T3Wv9rPwOA.M18xNjU3NTYwNzY2XzMy
2022-07-11 17:32:46 SUCCESS
EnsureMinimumAccessTokenLength
Access token is of sufficient length
actual
1208
required
128
2022-07-11 17:32:46 SUCCESS
EnsureMinimumAccessTokenEntropy
Calculated shannon entropy seems sufficient
actual
865.6883661862531
expected
96.0
value
Sqlk3fM3Qow8H4aVElOm0mry33OTdvsVlOhWP8H7Vhc.G5vfcFoxEsMGzkd4sE6CXx7fKwBHR-tqT7qag2ewMgI1zad1kiy7gdkjG9MWCYnwIcAVWQNtAXk_0Njm2JRFuA.M18xNjU3NTYwNzY2XzMy
2022-07-11 17:32:46 SUCCESS
ExtractIdTokenFromTokenResponse
Found and parsed the id_token from token_endpoint_response
value
eyJhbGciOiJQUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJsbDNGSE1YTnEtdXIzeDE2dXFpNVlnIiwiYXVkIjpbImU2Y2NmNDRkLTgzOGQtNGJlYy05ZDdlLTBjMWJmNjY3N2I4YyJdLCJhdXRoX3RpbWUiOjE2NTc1NTgwMjgsImVtYWlsIjoiamhhbGxAbWFpbGluYXRvci5jb20iLCJleHAiOjE2NTc1Njc5NjYsImlhdCI6MTY1NzU2MDc2NiwiaXNzIjoiaHR0cHM6Ly9mYXBpcG9jLnRyeXZlcmlmeS5pYm0uY29tL29hdXRoMiIsImp0aSI6IjU2ODI0NGFiLWZlYTEtNDBjZS04NDc2LTU2YmM0YTJlOGZhYiIsIm5hbWUiOiJKZXNzaWNhIEhhbGwiLCJub25jZSI6ImVrRW9QRGdTZ2JMOUZtaW1BazdBdVhianFvcHFVZDV6NndtcVR4ZUU0SnBlaVRYVDd2N3lRdXA3ekM1ZVFKb0RTYmpUdnl4YTREeG40cGNmMGMyMDhuQVhLZ3BMa0Y2YzBTT3ljalc1Tnlla1hPZ3JVS3lXN1ZpclRDUlZxMDJUZ1A0RU5KOUxoaGIzblF4QTI3aWlPeHZRVXJmRVY3ZWcxYXBVT0o0bm5McThrT29ocndaVmhWVnl3Q3NudWZieTZ0U0NaQkZOdHNqN2NWWEhmOHZpS0xIdFBrdTE4NmNmQjNyb21EYnZydlRqVExubmxQQ3FYRWdid2dsUm13V0Y2bEFSZFg0dU5BOUlLQThJYzdoTzdFOXdGZUJyR0MzRnpsUU44TjR1dk8xR0NoWFpJTHJibVJQeE5MUWJ6WVBxclA0aXVVR3BxcDZOcm5UUVMxZjBac1FzNEJkY0R6R1RUb3NkQUJKejVPMUQ0RmRQYXVWVWxSMW5FaWxoV3Z6NSIsInByZWZlcnJlZF91c2VybmFtZSI6ImpoYWxsIiwicmF0IjoxNjU3NTYwNzY1LCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJydF9oYXNoIjoidE5EYkNlMXQ0MHk0Y3FJMXR2emVVUSIsInNfaGFzaCI6IjVjcVluZ1NSVFN4T3JCNEh6Smt2UVEiLCJzdWIiOiI2NjIwMDNQV1ZGIn0.FYi_wZa_h47mgkIo2jdEDxZAfnHGAINWeTgD7Pnnm3Xe-H1fJeanjlDcPcJy4_p--pnxEe1vdUr8plY07wfNJsJxZ4Wm9hZXWtvypBh2HCSDhsulihnXRVUJjgDJwdfWQCMAtu9pMXeS6CN0R8RaW2E-se7AqELMPyaO1vV3AfaUA2HgaVvPxkpjrumIYJg8jmL9aiC7wZfuORcnL385w87obeQQ9bGy1MgcVFeOmo1pGs_xWYvkZjuSrGdRHXgjo1vJC9I4k6-2pXQkWNyZFXvcoXFekIUQCJ4mmUpxqspYao0lvm-etjAbVnFMz3pEnJVOqre9cnsHU29dVfLiDg
header
{
  "kid": "server",
  "alg": "PS256"
}
claims
{
  "at_hash": "ll3FHMXNq-ur3x16uqi5Yg",
  "sub": "662003PWVF",
  "rat": 1657560765,
  "realmName": "cloudIdentityRealm",
  "amr": [
    "password"
  ],
  "iss": "https://fapipoc.tryverify.ibm.com/oauth2",
  "preferred_username": "jhall",
  "nonce": "ekEoPDgSgbL9FmimAk7AuXbjqopqUd5z6wmqTxeE4JpeiTXT7v7yQup7zC5eQJoDSbjTvyxa4Dxn4pcf0c208nAXKgpLkF6c0SOycjW5NyekXOgrUKyW7VirTCRVq02TgP4ENJ9Lhhb3nQxA27iiOxvQUrfEV7eg1apUOJ4nnLq8kOohrwZVhVVywCsnufby6tSCZBFNtsj7cVXHf8viKLHtPku186cfB3romDbvrvTjTLnnlPCqXEgbwglRmwWF6lARdX4uNA9IKA8Ic7hO7E9wFeBrGC3FzlQN8N4uvO1GChXZILrbmRPxNLQbzYPqrP4iuUGpqp6NrnTQS1f0ZsQs4BdcDzGTTosdABJz5O1D4FdPauVUlR1nEilhWvz5",
  "rt_hash": "tNDbCe1t40y4cqI1tvzeUQ",
  "acr": "urn:mace:incommon:iap:silver",
  "aud": "e6ccf44d-838d-4bec-9d7e-0c1bf6677b8c",
  "s_hash": "5cqYngSRTSxOrB4HzJkvQQ",
  "auth_time": 1657558028,
  "name": "Jessica Hall",
  "exp": 1657567966,
  "iat": 1657560766,
  "email": "jhall@mailinator.com",
  "jti": "568244ab-fea1-40ce-8476-56bc4a2e8fab"
}
2022-07-11 17:32:46 SUCCESS
ValidateIdToken
ID token iss, aud, exp, iat, auth_time, acr & nbf claims passed validation checks
2022-07-11 17:32:46
ValidateIdTokenStandardClaims
sub is a string with content
2022-07-11 17:32:46
ValidateIdTokenStandardClaims
Skipping unknown claim: rat
2022-07-11 17:32:46
ValidateIdTokenStandardClaims
Skipping unknown claim: realmName
2022-07-11 17:32:46
ValidateIdTokenStandardClaims
preferred_username is a string with content
2022-07-11 17:32:46
ValidateIdTokenStandardClaims
Skipping unknown claim: rt_hash
2022-07-11 17:32:46
ValidateIdTokenStandardClaims
name is a string with content
2022-07-11 17:32:46
ValidateIdTokenStandardClaims
email is a string with content
2022-07-11 17:32:46 SUCCESS
ValidateIdTokenStandardClaims
id_token claims are valid
2022-07-11 17:32:46 SUCCESS
ValidateIdTokenNonce
Nonce values match
nonce
ekEoPDgSgbL9FmimAk7AuXbjqopqUd5z6wmqTxeE4JpeiTXT7v7yQup7zC5eQJoDSbjTvyxa4Dxn4pcf0c208nAXKgpLkF6c0SOycjW5NyekXOgrUKyW7VirTCRVq02TgP4ENJ9Lhhb3nQxA27iiOxvQUrfEV7eg1apUOJ4nnLq8kOohrwZVhVVywCsnufby6tSCZBFNtsj7cVXHf8viKLHtPku186cfB3romDbvrvTjTLnnlPCqXEgbwglRmwWF6lARdX4uNA9IKA8Ic7hO7E9wFeBrGC3FzlQN8N4uvO1GChXZILrbmRPxNLQbzYPqrP4iuUGpqp6NrnTQS1f0ZsQs4BdcDzGTTosdABJz5O1D4FdPauVUlR1nEilhWvz5
2022-07-11 17:32:46 SUCCESS
ValidateIdTokenACRClaimAgainstRequest
acr value in id_token is (one of) the requested values
actual
urn:mace:incommon:iap:silver
requested
[
  "urn:mace:incommon:iap:silver"
]
2022-07-11 17:32:46 SUCCESS
ValidateIdTokenSignature
id_token signature validated
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJsbDNGSE1YTnEtdXIzeDE2dXFpNVlnIiwiYXVkIjpbImU2Y2NmNDRkLTgzOGQtNGJlYy05ZDdlLTBjMWJmNjY3N2I4YyJdLCJhdXRoX3RpbWUiOjE2NTc1NTgwMjgsImVtYWlsIjoiamhhbGxAbWFpbGluYXRvci5jb20iLCJleHAiOjE2NTc1Njc5NjYsImlhdCI6MTY1NzU2MDc2NiwiaXNzIjoiaHR0cHM6Ly9mYXBpcG9jLnRyeXZlcmlmeS5pYm0uY29tL29hdXRoMiIsImp0aSI6IjU2ODI0NGFiLWZlYTEtNDBjZS04NDc2LTU2YmM0YTJlOGZhYiIsIm5hbWUiOiJKZXNzaWNhIEhhbGwiLCJub25jZSI6ImVrRW9QRGdTZ2JMOUZtaW1BazdBdVhianFvcHFVZDV6NndtcVR4ZUU0SnBlaVRYVDd2N3lRdXA3ekM1ZVFKb0RTYmpUdnl4YTREeG40cGNmMGMyMDhuQVhLZ3BMa0Y2YzBTT3ljalc1Tnlla1hPZ3JVS3lXN1ZpclRDUlZxMDJUZ1A0RU5KOUxoaGIzblF4QTI3aWlPeHZRVXJmRVY3ZWcxYXBVT0o0bm5McThrT29ocndaVmhWVnl3Q3NudWZieTZ0U0NaQkZOdHNqN2NWWEhmOHZpS0xIdFBrdTE4NmNmQjNyb21EYnZydlRqVExubmxQQ3FYRWdid2dsUm13V0Y2bEFSZFg0dU5BOUlLQThJYzdoTzdFOXdGZUJyR0MzRnpsUU44TjR1dk8xR0NoWFpJTHJibVJQeE5MUWJ6WVBxclA0aXVVR3BxcDZOcm5UUVMxZjBac1FzNEJkY0R6R1RUb3NkQUJKejVPMUQ0RmRQYXVWVWxSMW5FaWxoV3Z6NSIsInByZWZlcnJlZF91c2VybmFtZSI6ImpoYWxsIiwicmF0IjoxNjU3NTYwNzY1LCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJydF9oYXNoIjoidE5EYkNlMXQ0MHk0Y3FJMXR2emVVUSIsInNfaGFzaCI6IjVjcVluZ1NSVFN4T3JCNEh6Smt2UVEiLCJzdWIiOiI2NjIwMDNQV1ZGIn0.FYi_wZa_h47mgkIo2jdEDxZAfnHGAINWeTgD7Pnnm3Xe-H1fJeanjlDcPcJy4_p--pnxEe1vdUr8plY07wfNJsJxZ4Wm9hZXWtvypBh2HCSDhsulihnXRVUJjgDJwdfWQCMAtu9pMXeS6CN0R8RaW2E-se7AqELMPyaO1vV3AfaUA2HgaVvPxkpjrumIYJg8jmL9aiC7wZfuORcnL385w87obeQQ9bGy1MgcVFeOmo1pGs_xWYvkZjuSrGdRHXgjo1vJC9I4k6-2pXQkWNyZFXvcoXFekIUQCJ4mmUpxqspYao0lvm-etjAbVnFMz3pEnJVOqre9cnsHU29dVfLiDg
2022-07-11 17:32:46 SUCCESS
ValidateIdTokenSignatureUsingKid
id_token signature validated
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJsbDNGSE1YTnEtdXIzeDE2dXFpNVlnIiwiYXVkIjpbImU2Y2NmNDRkLTgzOGQtNGJlYy05ZDdlLTBjMWJmNjY3N2I4YyJdLCJhdXRoX3RpbWUiOjE2NTc1NTgwMjgsImVtYWlsIjoiamhhbGxAbWFpbGluYXRvci5jb20iLCJleHAiOjE2NTc1Njc5NjYsImlhdCI6MTY1NzU2MDc2NiwiaXNzIjoiaHR0cHM6Ly9mYXBpcG9jLnRyeXZlcmlmeS5pYm0uY29tL29hdXRoMiIsImp0aSI6IjU2ODI0NGFiLWZlYTEtNDBjZS04NDc2LTU2YmM0YTJlOGZhYiIsIm5hbWUiOiJKZXNzaWNhIEhhbGwiLCJub25jZSI6ImVrRW9QRGdTZ2JMOUZtaW1BazdBdVhianFvcHFVZDV6NndtcVR4ZUU0SnBlaVRYVDd2N3lRdXA3ekM1ZVFKb0RTYmpUdnl4YTREeG40cGNmMGMyMDhuQVhLZ3BMa0Y2YzBTT3ljalc1Tnlla1hPZ3JVS3lXN1ZpclRDUlZxMDJUZ1A0RU5KOUxoaGIzblF4QTI3aWlPeHZRVXJmRVY3ZWcxYXBVT0o0bm5McThrT29ocndaVmhWVnl3Q3NudWZieTZ0U0NaQkZOdHNqN2NWWEhmOHZpS0xIdFBrdTE4NmNmQjNyb21EYnZydlRqVExubmxQQ3FYRWdid2dsUm13V0Y2bEFSZFg0dU5BOUlLQThJYzdoTzdFOXdGZUJyR0MzRnpsUU44TjR1dk8xR0NoWFpJTHJibVJQeE5MUWJ6WVBxclA0aXVVR3BxcDZOcm5UUVMxZjBac1FzNEJkY0R6R1RUb3NkQUJKejVPMUQ0RmRQYXVWVWxSMW5FaWxoV3Z6NSIsInByZWZlcnJlZF91c2VybmFtZSI6ImpoYWxsIiwicmF0IjoxNjU3NTYwNzY1LCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJydF9oYXNoIjoidE5EYkNlMXQ0MHk0Y3FJMXR2emVVUSIsInNfaGFzaCI6IjVjcVluZ1NSVFN4T3JCNEh6Smt2UVEiLCJzdWIiOiI2NjIwMDNQV1ZGIn0.FYi_wZa_h47mgkIo2jdEDxZAfnHGAINWeTgD7Pnnm3Xe-H1fJeanjlDcPcJy4_p--pnxEe1vdUr8plY07wfNJsJxZ4Wm9hZXWtvypBh2HCSDhsulihnXRVUJjgDJwdfWQCMAtu9pMXeS6CN0R8RaW2E-se7AqELMPyaO1vV3AfaUA2HgaVvPxkpjrumIYJg8jmL9aiC7wZfuORcnL385w87obeQQ9bGy1MgcVFeOmo1pGs_xWYvkZjuSrGdRHXgjo1vJC9I4k6-2pXQkWNyZFXvcoXFekIUQCJ4mmUpxqspYao0lvm-etjAbVnFMz3pEnJVOqre9cnsHU29dVfLiDg
2022-07-11 17:32:46 SUCCESS
CheckForSubjectInIdToken
Found 'sub' in id_token
sub
662003PWVF
2022-07-11 17:32:46
EnsureIdTokenUpdatedAtValid
id_token response does not contain 'updated_at'
2022-07-11 17:32:46 INFO
ValidateEncryptedIdTokenHasKid
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2022-07-11 17:32:46 SUCCESS
EnsureIdTokenContainsKid
kid was found in the ID token header
kid
server
2022-07-11 17:32:46 SUCCESS
FAPIValidateIdTokenSigningAlg
id_token was signed with a permitted algorithm
permitted
[
  "PS256",
  "ES256"
]
alg
PS256
2022-07-11 17:32:46 INFO
FAPIValidateIdTokenEncryptionAlg
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2022-07-11 17:32:46 INFO
ExtractCHash
Couldn't find c_hash in ID token
2022-07-11 17:32:46 SUCCESS
ExtractSHash
Extracted s_hash from ID Token
s_hash
5cqYngSRTSxOrB4HzJkvQQ
alg
PS256
2022-07-11 17:32:46 SUCCESS
ExtractAtHash
Extracted at_hash from ID Token
at_hash
ll3FHMXNq-ur3x16uqi5Yg
alg
PS256
2022-07-11 17:32:46 INFO
ValidateCHash
Skipped evaluation due to missing required object: c_hash
expected
c_hash
mapped
2022-07-11 17:32:46 SUCCESS
ValidateSHash
s_hash validated successfully
expected_hash
5cqYngSRTSxOrB4HzJkvQQ
unhashed_value
exLNNBJ7M2
id_token_hash
5cqYngSRTSxOrB4HzJkvQQ
2022-07-11 17:32:46 SUCCESS
ValidateAtHash
at_hash validated successfully
expected_hash
ll3FHMXNq-ur3x16uqi5Yg
unhashed_value
Sqlk3fM3Qow8H4aVElOm0mry33OTdvsVlOhWP8H7Vhc.G5vfcFoxEsMGzkd4sE6CXx7fKwBHR-tqT7qag2ewMgI1zad1kiy7gdkjG9MWCYnwIcAVWQNtAXk_0Njm2JRFuA.M18xNjU3NTYwNzY2XzMy
id_token_hash
ll3FHMXNq-ur3x16uqi5Yg
Verify at_hash in the authorization endpoint id_token
2022-07-11 17:32:46 INFO
ExtractAtHash
Couldn't find at_hash in ID token
2022-07-11 17:32:46 INFO
ValidateAtHash
Skipped evaluation due to missing required object: at_hash
expected
at_hash
mapped
Resource server endpoint tests
2022-07-11 17:32:46
CreateEmptyResourceEndpointRequestHeaders
Created empty headers
resource_endpoint_request_headers
{}
2022-07-11 17:32:46 SUCCESS
AddFAPIAuthDateToResourceEndpointRequest
Added x-fapi-auth-date to resource endpoint request headers
resource_endpoint_request_headers
{
  "x-fapi-auth-date": "Mon, 11 Jul 2022 17:32:46 GMT"
}
2022-07-11 17:32:46
AddIpV4FapiCustomerIpAddressToResourceEndpointRequest
Added x-fapi-customer-ip-address containing IPv4 address to resource endpoint request headers
resource_endpoint_request_headers
{
  "x-fapi-auth-date": "Mon, 11 Jul 2022 17:32:46 GMT",
  "x-fapi-customer-ip-address": "198.51.100.119"
}
2022-07-11 17:32:46
CreateRandomFAPIInteractionId
Created interaction ID
fapi_interaction_id
b1ac41e2-4677-40e8-908f-e68f0deeedc1
2022-07-11 17:32:46 SUCCESS
AddFAPIInteractionIdToResourceEndpointRequest
Added x-fapi-interaction-id to resource endpoint request headers
resource_endpoint_request_headers
{
  "x-fapi-auth-date": "Mon, 11 Jul 2022 17:32:46 GMT",
  "x-fapi-customer-ip-address": "198.51.100.119",
  "x-fapi-interaction-id": "b1ac41e2-4677-40e8-908f-e68f0deeedc1"
}
2022-07-11 17:32:46
CallProtectedResource
HTTP request
request_uri
https://fapiresource.dev.vanitytst.cloudidentity.ibm.com/oauth2/open-banking/v3.1/aisp/accounts
request_method
GET
request_headers
{
  "accept": "application/json",
  "authorization": "Bearer Sqlk3fM3Qow8H4aVElOm0mry33OTdvsVlOhWP8H7Vhc.G5vfcFoxEsMGzkd4sE6CXx7fKwBHR-tqT7qag2ewMgI1zad1kiy7gdkjG9MWCYnwIcAVWQNtAXk_0Njm2JRFuA.M18xNjU3NTYwNzY2XzMy",
  "x-fapi-auth-date": "Mon, 11 Jul 2022 17:32:46 GMT",
  "x-fapi-customer-ip-address": "198.51.100.119",
  "x-fapi-interaction-id": "b1ac41e2-4677-40e8-908f-e68f0deeedc1",
  "content-length": "0"
}
request_body

                                
request_mutual_tls
{
  "cert": "MIID2TCCA36gAwIBAgIUKXA8+q3GoAhthdhhMdI7y02Mg+4wCgYIKoZIzj0EAwIwgYExCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhOZXcgWW9yazE0MDIGA1UECgwrSW50ZXJuYXRpb25hbCBCdXNpbmVzcyBNYWNoaW5lcyBDb3Jwb3JhdGlvbjEpMCcGA1UEAwwgSUJNIFNlY3VyaXR5IFZlcmlmeSBEZXYtSVRFIENBLTEwHhcNMjIwMjEwMTU1ODAwWhcNMjUwMjA5MTU1ODAwWjB0MQswCQYDVQQGEwJTRzETMBEGA1UECBMKa2NhMmNzci1TVDESMBAGA1UEBxMJa2NhMmNzci1MMRIwEAYDVQQKEwlrY2EyY3NyLU8xEzARBgNVBAsTCmtjYTJjc3ItT1UxEzARBgNVBAMTCmtjYTJjc3ItQ04wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCV6uh9e1Z54rwv4amn0M10uJqPtxZH45MsDyjVafe/5p1N8M2Zl2LQfSWHOvXtFBZlr72bz1TrZf8cuXn9WetXDg7FqElTxgV75uGubd1RpUKkFnN8dBSq1oadvpmU+1Ov7mRKzh3cPlbYX7Dwr372ZVGuumwjwVVfszmwA2bKy+bN7JvN41vic3OnAm+uBq5sB4HN87x3+hN/Z4rkO8HEdVgEwzQSXprs52vnPAt41Jn/RPx5+Z5yIGKuS10GCT1e19Afh4hgZfCRTBLCGDldJwemhVD2MDET4qYyhW/BkLzc3+3OjiXU10+NpCP+SC88WQp3U8Z24qlyLHA9prKXAgMBAAGjggETMIIBDzAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwIwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUSKev5Wnf5dBO/838Jt87ZcwqXbIwHwYDVR0jBBgwFoAUVG35JNW6n95CIBrdXCkTvAi9lhAwgZkGA1UdEQSBkTCBjoIPd3d3LmV4YW1wbGUuY29tghB0ZXN0LmV4YW1wbGUuY29tghBtYWlsLmV4YW1wbGUuY29tgg93d3cuZXhhbXBsZS5uZXSBE3NoYW5rYXJ2QHNnLmlibS5jb22HBMAAAgGHBMYzZP6HECABDbgAAAAAAAAAAAAAAAGGE2h0dHBzOi8vamtlLmNvbS9mb28wCgYIKoZIzj0EAwIDSQAwRgIhALF8B38YTP3q+Bf1wrcCBSL/ssGhO6H1NaWUykHSxYQqAiEAgTeJC+4FXvklUnjJEabkAeZU/oycGMPI/u0Z56fq984\u003d",
  "key": "MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQCV6uh9e1Z54rwv4amn0M10uJqPtxZH45MsDyjVafe/5p1N8M2Zl2LQfSWHOvXtFBZlr72bz1TrZf8cuXn9WetXDg7FqElTxgV75uGubd1RpUKkFnN8dBSq1oadvpmU+1Ov7mRKzh3cPlbYX7Dwr372ZVGuumwjwVVfszmwA2bKy+bN7JvN41vic3OnAm+uBq5sB4HN87x3+hN/Z4rkO8HEdVgEwzQSXprs52vnPAt41Jn/RPx5+Z5yIGKuS10GCT1e19Afh4hgZfCRTBLCGDldJwemhVD2MDET4qYyhW/BkLzc3+3OjiXU10+NpCP+SC88WQp3U8Z24qlyLHA9prKXAgMBAAECggEAQrpw6i1kU9M2hS9x9tarJHlonnBVVAE5CCLlP3yvwDRTLxZwRR2LZ5ZUhmkZfoFy6Kb9A+WYfECFeVEbOcf0xuZkb9kUblvVJA2jxSJ0oLsouuWdWLdIXbQn7f2g2Z22Zbf73wn4Y4hB2oRZOwA6SEzXuyiSKqYKrJKXKj+RWNETjUt/7H4skIDafFhgo1+V7ZbuMJxdp4xVp98g3mxyUj1hthg3RNDpiapqElobSEKlUnYQVpRfBRIAFWtRvO4ZjwFFOgpTel3E6gm34miTN5Vp2Je+C02LAx04G5bCOPe6EwESZEPeVE6nbjvw1wM2Nl8GkwEGweDNM165y/8T1QKBgQDO7XHODYgmb1vA7Dk4XDQkqgvFpMqQTNvxgXarK9lDNaQBDoXZjp+PQ4ZG7UY9SZ82uPz/kZLlZJeXGg1Cd3v2ErLQXWrq8IHY+IwgXt0/jForLnRihGwqKg7J801PPbOM4BCh3LpZwCoiVXCAOCSA++h8CBBffZ97eiiPAcO6lQKBgQC5eGVhLebWsrOgKqr7ouSeT0BuVb8rXt2MaYTVwTFs+BsbUOnwYcXYBeV4mtgtLmf7C6m5NoTWOGsFdjmk51uHC5k/h9fXf1EnQBbVjZDsIelCzAeWkwxDiDtuwChB3cLk64qtmLRy0rHAUJvfG93/UbaO/LxZwyPvtL9ylHWZewKBgBAUqcRujscV3laGxQeZOsAiqtmILem631jMS9GPjcnIUF94pnQ6vjGe+L9oTw4SO5pAFAE0aesDvzgR4TfqGysLVvQUXmu1lxGqdxFI7f6zRIqYiJjjW5iHPjD5hGeFDwACpag+hAjXgy653w1Hz6ZqbS2+Xq9dDtjErIQ4ieJlAoGBAIdvjJB/RW8IhbTzE3K3y7xy4PjxMq1IE/6B21eAQUhykNDMsFgx/Zg3Dg+Y+z1bAuFG7gRq9Gu+PSB66bMqoyKlbJ4A47Pgq/E+kq4VN3vHc5+sf+oLrUvvQn8oYP1gI/6opdcIiNTEWLq34mr03ZKhJ++YTS47GpXjZl4UXR/bAoGARrRC3D0HNCw2dQZ8jXFoEfXU7lHuCOBFTZQz/mGlGdSXm9hoZkb1nOTVxJhj+WG35HQn4FWDQHLX1i9g4QnopJ7Ga80VNNdmq+ub9nEx9e1YmLlD5skazO8mwIOmAyyi2FBKYGtXhA9nYO4AdfcbG6ENTwoX/IjA62IG+5gNvoo\u003d"
}
2022-07-11 17:32:47 RESPONSE
CallProtectedResource
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK6fb513e9-3142-4fc1-af92-dd94467a377b",
  "x-fapi-interaction-id": "b1ac41e2-4677-40e8-908f-e68f0deeedc1",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "1acff1be62cc5ebe10bb4825",
  "content-length": "39",
  "date": "Mon, 11 Jul 2022 17:32:47 GMT",
  "connection": "close",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:YqlREemBHtSKz+c72yD+si/XZPFuZeN6tJa+BcRQx+s\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDDEV02A\u003dPBC5YS:677917772; Path\u003d/; Domain\u003ddev.vanitytst.cloudidentity.ibm.com; Secure; HttpOnly",
    "_abck\u003dD2841197B255468600D6B32D079FC4D2~-1~YAAQCt7aF0dj6a6BAQAA6RtS7giq0SwUE5qG5QDKLLocuBIbUR6YJ1RKRPq6ViwwS0TqUkUVCSwt5X6W1xPdQbSz3OW5iYflukcDRVX8o/I0oe6mIwnZfoDoVloo/AlmvzkluOZd3xkJVW0i2/cYJlytot8rbPhHKK2Kul9srC/6sL6IEwwBUVKQC9wEna+eoXWKrKnK5QnlDM4qU2V29VUMOzPS0zdwheX4YrVvh3o+ku/EtCi6NdSSMB0MUuasar3vpdpz2imDQ8WeVxDzDYNKDcOKxMgzE2r8TOFIoPMUFMMAG7VHTR7Y0WJ4sJDO5RctXCN7mVK++mXkdhbc1L1USaZ8UbPZlAxMvPjJ0VMnLrgJ8w1vrA\u003d\u003d~-1~-1~-1; Domain\u003d.ibm.com; Path\u003d/; Expires\u003dTue, 11 Jul 2023 17:32:47 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003dE77A512F8F0366A841DD8B6BDE5B0CCB~YAAQCt7aF0hj6a6BAQAA6RtS7hDgO7bfWZGBxA1k/H7O4CbF1j1bgCyohdzU73ew24/J1EWz3H6SiqcoYt+BUDbz3cOePeA4h9IttDrA/5rL2b4gbqK3QlOt4hg8yN4devtD4WTjxmXbbO69RPaRYyJSdqP8OS5nghoiP+WEwUSFGFRS1LZv/hL7dsr81DaRvSVonduN+1mKzdsPBT8eIOcVrqcmG6fhpKfIsnihjvbHu4us7b1tX5tp+I0centFgvMNQKAUJ3Kk53QBJaKugy5bp1qhJwNrjbLvasFpt7s\u003d~3290181~4470577; Domain\u003d.ibm.com; Path\u003d/; Expires\u003dMon, 11 Jul 2022 21:32:46 GMT; Max-Age\u003d14399"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d53",
    "origin; dur\u003d540"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"content":"This is a sample resource"}
2022-07-11 17:32:47 SUCCESS
CallProtectedResource
Got a response from the resource endpoint
status
200
endpoint_name
resource
headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK6fb513e9-3142-4fc1-af92-dd94467a377b",
  "x-fapi-interaction-id": "b1ac41e2-4677-40e8-908f-e68f0deeedc1",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "1acff1be62cc5ebe10bb4825",
  "content-length": "39",
  "date": "Mon, 11 Jul 2022 17:32:47 GMT",
  "connection": "close",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:YqlREemBHtSKz+c72yD+si/XZPFuZeN6tJa+BcRQx+s\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDDEV02A\u003dPBC5YS:677917772; Path\u003d/; Domain\u003ddev.vanitytst.cloudidentity.ibm.com; Secure; HttpOnly",
    "_abck\u003dD2841197B255468600D6B32D079FC4D2~-1~YAAQCt7aF0dj6a6BAQAA6RtS7giq0SwUE5qG5QDKLLocuBIbUR6YJ1RKRPq6ViwwS0TqUkUVCSwt5X6W1xPdQbSz3OW5iYflukcDRVX8o/I0oe6mIwnZfoDoVloo/AlmvzkluOZd3xkJVW0i2/cYJlytot8rbPhHKK2Kul9srC/6sL6IEwwBUVKQC9wEna+eoXWKrKnK5QnlDM4qU2V29VUMOzPS0zdwheX4YrVvh3o+ku/EtCi6NdSSMB0MUuasar3vpdpz2imDQ8WeVxDzDYNKDcOKxMgzE2r8TOFIoPMUFMMAG7VHTR7Y0WJ4sJDO5RctXCN7mVK++mXkdhbc1L1USaZ8UbPZlAxMvPjJ0VMnLrgJ8w1vrA\u003d\u003d~-1~-1~-1; Domain\u003d.ibm.com; Path\u003d/; Expires\u003dTue, 11 Jul 2023 17:32:47 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003dE77A512F8F0366A841DD8B6BDE5B0CCB~YAAQCt7aF0hj6a6BAQAA6RtS7hDgO7bfWZGBxA1k/H7O4CbF1j1bgCyohdzU73ew24/J1EWz3H6SiqcoYt+BUDbz3cOePeA4h9IttDrA/5rL2b4gbqK3QlOt4hg8yN4devtD4WTjxmXbbO69RPaRYyJSdqP8OS5nghoiP+WEwUSFGFRS1LZv/hL7dsr81DaRvSVonduN+1mKzdsPBT8eIOcVrqcmG6fhpKfIsnihjvbHu4us7b1tX5tp+I0centFgvMNQKAUJ3Kk53QBJaKugy5bp1qhJwNrjbLvasFpt7s\u003d~3290181~4470577; Domain\u003d.ibm.com; Path\u003d/; Expires\u003dMon, 11 Jul 2022 21:32:46 GMT; Max-Age\u003d14399"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d53",
    "origin; dur\u003d540"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
body
{"content":"This is a sample resource"}
2022-07-11 17:32:47 SUCCESS
EnsureHttpStatusCodeIs200or201
resource endpoint http status code was 200
2022-07-11 17:32:47 SUCCESS
CheckForDateHeaderInResourceResponse
Date header present and validated
date
Mon, 11 Jul 2022 17:32:47 GMT
skew
479
2022-07-11 17:32:47 SUCCESS
CheckForFAPIInteractionIdInResourceResponse
Found x-fapi-interaction-id
interaction_id
b1ac41e2-4677-40e8-908f-e68f0deeedc1
2022-07-11 17:32:47 SUCCESS
EnsureMatchingFAPIInteractionId
Interaction ID matched
fapi_interaction_id
b1ac41e2-4677-40e8-908f-e68f0deeedc1
2022-07-11 17:32:47 SUCCESS
EnsureResourceResponseReturnedJsonContentType
Response content type is json
content_type
application/json;charset=UTF-8
2022-07-11 17:32:47 FINISHED
fapi1-advanced-final-ensure-request-object-with-long-nonce
Test has run to completion
testmodule_result
PASSED
2022-07-11 17:32:52
TEST-RUNNER
Alias has now been claimed by another test
alias
fapipoc_fapi_dev
new_test_id
LDTCRVDuSjQwtzU
Test Results